Source: Yara match |
File source: 27.0.explorer.exe.140000000.6.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.11.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.10.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 21.2.conhost.exe.224e8d2d308.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.7.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.9.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.2.conhost.exe.2019125ca38.11.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.3.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.10.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.2.explorer.exe.140000000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.8.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.3.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.12.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.7.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.2.explorer.exe.140000000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.2.conhost.exe.20190d5ca00.10.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.13.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.12.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.12.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.5.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.13.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.2.explorer.exe.140000000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 21.2.conhost.exe.224e882d2d0.7.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.2.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.3.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.9.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 21.2.conhost.exe.224e8d2d308.8.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.13.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.10.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.9.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.6.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.9.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.4.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.0.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.1.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.5.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.2.explorer.exe.140000000.0.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.4.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.5.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.11.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.8.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.2.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.12.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.10.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.8.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 21.2.conhost.exe.224e882d2d0.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.11.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.2.conhost.exe.20190d5ca00.10.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 28.0.explorer.exe.140000000.6.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.4.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.7.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.13.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 27.0.explorer.exe.140000000.11.raw.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 17.2.conhost.exe.2019125ca38.11.unpack, type: UNPACKEDPE |
Source: Yara match |
File source: 0000001B.00000000.799518871.0000000140753000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001C.00000002.927622766.0000000140752000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000015.00000002.810205943.00000224D7AD1000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001C.00000000.819000457.0000000140753000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001B.00000002.927522845.0000000140752000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000002.821033223.0000020180001000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001C.00000000.801221568.0000000140753000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001B.00000000.796871079.0000000140753000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001C.00000000.798724965.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.768854155.00000201F4E40000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001B.00000000.804927838.0000000140753000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001B.00000000.792450012.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000015.00000002.818855585.00000224E8755000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001C.00000000.784200823.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000002.833907322.000002019125C000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001C.00000000.796296289.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001B.00000002.925771817.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001C.00000002.918136554.00000000004BA000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001C.00000000.780903437.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001C.00000000.774089554.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001B.00000000.775205927.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001C.00000000.816102106.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001C.00000000.814593137.0000000140753000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001B.00000000.781428125.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001C.00000000.810219805.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001B.00000000.795242519.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001B.00000002.917920684.000000000130B000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001B.00000000.794400216.0000000140753000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000015.00000002.812013124.00000224E7AD9000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001C.00000000.793171664.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000015.00000002.821696567.00000224E8D2D000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001B.00000000.797423384.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001C.00000002.925901333.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001C.00000000.812542531.0000000140753000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000002.822124457.0000020190009000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001C.00000000.787529097.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001B.00000000.800236371.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001C.00000000.813277906.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001B.00000000.787692374.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001C.00000000.779272197.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001B.00000000.789535375.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001B.00000000.784425223.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001B.00000000.773135705.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001C.00000000.789706786.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000003.802096834.00000201F4E40000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001B.00000000.779800649.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 00000011.00000002.829515499.0000020190C84000.00000004.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: 0000001B.00000000.769582384.0000000140000000.00000040.00000001.sdmp, type: MEMORY |
Source: Yara match |
File source: Process Memory Space: conhost.exe PID: 6012, type: MEMORYSTR |
Source: Yara match |
File source: Process Memory Space: conhost.exe PID: 6840, type: MEMORYSTR |
Source: Yara match |
File source: Process Memory Space: explorer.exe PID: 4876, type: MEMORYSTR |
Source: global traffic |
TCP traffic: 192.168.2.4:49816 -> 157.90.156.89:6004 payload: {"id":1,"jsonrpc":"2.0","method":"login","params":{"login":"6059336","pass":"myminer","agent":"xmrig/6.15.2 (windows nt 10.0; win64; x64) libuv/1.38.0 msvc/2019","rigid":"","algo":["rx/0","cn/2","cn/r","cn/fast","cn/half","cn/xao","cn/rto","cn/rwz","cn/zls","cn/double","cn/ccx","cn-lite/1","cn-heavy/0","cn-heavy/tube","cn-heavy/xhv","cn-pico","cn-pico/tlo","cn/upx2","cn/1","rx/wow","rx/arq","rx/graft","rx/sfx","rx/keva","argon2/chukwa","argon2/chukwav2","argon2/ninja","astrobwt"]}}. |
Source: global traffic |
TCP traffic: 192.168.2.4:49822 -> 157.90.156.89:6004 payload: {"id":1,"jsonrpc":"2.0","method":"login","params":{"login":"6059336","pass":"myminer","agent":"xmrig/6.15.2 (windows nt 10.0; win64; x64) libuv/1.38.0 msvc/2019","rigid":"","algo":["rx/0","cn/2","cn/r","cn/fast","cn/half","cn/xao","cn/rto","cn/rwz","cn/zls","cn/double","cn/ccx","cn-lite/1","cn-heavy/0","cn-heavy/tube","cn-heavy/xhv","cn-pico","cn-pico/tlo","cn/upx2","cn/1","rx/wow","rx/arq","rx/graft","rx/sfx","rx/keva","argon2/chukwa","argon2/chukwav2","argon2/ninja","astrobwt"]}}. |