What is c65561-110ea1-d0de4124-8536d0-66e0.rs?

c65561-110ea1-d0de4124-8536d0-66e0.rs is part of Version control copyright telecommunications card reader jquery query and developed by Webcam esata servlet windows vista social media voip windows xp according to the c65561-110ea1-d0de4124-8536d0-66e0.rs version information.

c65561-110ea1-d0de4124-8536d0-66e0.rs's description is "Data type cad plug and play nat secondary memory laser printer"

c65561-110ea1-d0de4124-8536d0-66e0.rs is usually located in the 'c:\users\%USERNAME%\appdata\roaming\microsoft\protect\' folder.

Some of the anti-virus scanners at VirusTotal detected c65561-110ea1-d0de4124-8536d0-66e0.rs.

If you have additional information about the file, please share it with the FreeFixer users by posting a comment at the bottom of this page.

Vendor and version information [?]

The following is the available information on c65561-110ea1-d0de4124-8536d0-66e0.rs:

PropertyValue
Product nameVersion control copyright telecommunications card reader jquery query
Company nameWebcam esata servlet windows vista social media voip windows xp
File descriptionData type cad plug and play nat secondary memory laser printer
Internal nameThunderbolt hyperlink nosql qwerty micron handshake
Original filenameDesktop publishing gpu server thread base station paste payload platform sla
Legal copyrightStack domain myspace soft token trackball enterprise drive
Product version136.204.191.249
File version177.149.146.129

Here's a screenshot of the file properties when displayed by Windows Explorer:

Product nameVersion control copyright telecommun..
Company nameWebcam esata servlet windows vista s..
File descriptionData type cad plug and play nat seco..
Internal nameThunderbolt hyperlink nosql qwerty m..
Original filenameDesktop publishing gpu server thread..
Legal copyrightStack domain myspace soft token trac..
Product version136.204.191.249
File version177.149.146.129

Digital signatures [?]

c65561-110ea1-d0de4124-8536d0-66e0.rs is not signed.

VirusTotal report

49 of the 72 anti-virus programs at VirusTotal detected the c65561-110ea1-d0de4124-8536d0-66e0.rs file. That's a 68% detection rate.

ScannerDetection Name
Ad-Aware Trojan.GenericKD.42209980
AegisLab Trojan.Win32.Generic.4!c
Alibaba TrojanDownloader:Win32/Blocrypt.2bbc1f85
ALYac Trojan.GenericKD.42209980
Antiy-AVL Trojan/Win32.Persistence
Arcabit Trojan.Generic.D28412BC
Avast Win64:Trojan-gen
AVG Win64:Trojan-gen
Avira HEUR/AGEN.1045533
BitDefender Trojan.GenericKD.42209980
CAT-QuickHeal Trojan.Generic
Comodo Malware@#9ah78l0ve50h
Cylance Unsafe
Cyren W64/Trojan.ZMYG-1146
DrWeb Trojan.DownLoader32.42951
Emsisoft Trojan.GenericKD.42209980 (B)
Endgame malicious (high confidence)
ESET-NOD32 a variant of Win64/TrojanDownloader.Blocrypt.T
F-Secure Heuristic.HEUR/AGEN.1045533
FireEye Generic.mg.d11f81c2869536f1
Fortinet W64/Blocrypt.S!tr.dldr
GData Trojan.GenericKD.42209980
Ikarus Trojan-Downloader.Win64.Blocrypt
Jiangmin Trojan.Generic.ekoyf
K7AntiVirus Trojan-Downloader ( 00529a6e1 )
K7GW Trojan-Downloader ( 00529a6e1 )
Kaspersky HEUR:Trojan.Win32.Generic
MAX malware (ai score=88)
MaxSecure Trojan.Malware.7164915.susgen
McAfee RDN/Generic Downloader.x
McAfee-GW-Edition RDN/Generic Downloader.x
Microsoft Trojan:Win32/Persistence!rfn
MicroWorld-eScan Trojan.GenericKD.42209980
NANO-Antivirus Trojan.Win64.Dwn.gryrbd
Paloalto generic.ml
Panda Trj/CI.A
Qihoo-360 Win64/Trojan.4b0
Rising Downloader.Blocrypt!8.D73 (CLOUD)
Sophos Mal/Generic-S
Symantec Trojan.Gen.MBT
Tencent Win32.Trojan.Generic.Wnch
TrendMicro TROJ_GEN.R067C0GA820
TrendMicro-HouseCall TROJ_GEN.R067C0GA820
VBA32 Trojan.Wacatac
VIPRE Trojan.Win32.Generic!BT
Webroot W32.Trojan.Gen
Yandex Trojan.Agent!TF0/JvjH1Yc
Zillya Downloader.Blocrypt.Win64.55
ZoneAlarm HEUR:Trojan.Win32.Generic
49 of the 72 anti-virus programs detected the c65561-110ea1-d0de4124-8536d0-66e0.rs file.

Sandbox Report

The following information was gathered by executing the file inside Cuckoo Sandbox.

Summary

Successfully executed process in sandbox.

Summary

{
    "file_created": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.tpl.rs",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.tpl"
    ],
    "directory_created": [
        "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Protect\\"
    ],
    "dll_loaded": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.dll",
        "dnsapi.dll",
        "kernel32.dll",
        "Shell32.dll",
        "psapi.dll",
        "Ws2_32.dll",
        "imm32.dll"
    ],
    "file_opened": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.dll"
    ],
    "command_line": [
        "\"C:\\Windows\\System32\\rundll32.exe\" C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.dll,DllMain"
    ],
    "file_written": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.tpl"
    ],
    "file_exists": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.dll.manifest",
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.dll"
    ],
    "file_read": [
        "C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.dll"
    ],
    "regkey_read": [
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE\\PageAllocatorSystemHeapIsPrivate",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
        "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE\\PageAllocatorUseSystemHeap"
    ],
    "regkey_written": [
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\WinResSync",
        "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\WinResSync"
    ]
}

Dropped

[
    {
        "yara": [],
        "sha1": "f8fb1666e9b822723fa75391b12f7ed57c0722f1",
        "name": "439fa23c9dcc2891_69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.tpl",
        "filepath": "C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.tpl",
        "type": "data",
        "sha256": "439fa23c9dcc289108c2b23f9c60d768e35d20d0392c93b5bfa835bd03e954f7",
        "urls": [],
        "crc32": "E7ABB4E8",
        "path": "\/home\/hpuser\/.cuckoo\/storage\/analyses\/6469\/files\/439fa23c9dcc2891_69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.tpl",
        "ssdeep": null,
        "size": 32,
        "sha512": "032401f40e3aaf8f5c24207a3a0394a7b0ae03e03ed3d820701b098089fe18c83faa088f78603989dd2062d117e59622d56c963ad73a6f3362c5775fa5b1e574",
        "pids": [
            2828
        ],
        "md5": "35d4de210af1597bf384ee6b3d2ddc0d"
    }
]

Generic

[
    {
        "process_path": "C:\\Windows\\System32\\csrss.exe",
        "process_name": "csrss.exe",
        "pid": 328,
        "summary": {},
        "first_seen": 1585597989.046499,
        "ppid": 312
    },
    {
        "process_path": "C:\\Windows\\System32\\csrss.exe",
        "process_name": "csrss.exe",
        "pid": 384,
        "summary": {},
        "first_seen": 1585597990.684195,
        "ppid": 368
    },
    {
        "process_path": "C:\\Windows\\SysWOW64\\rundll32.exe",
        "process_name": "rundll32.exe",
        "pid": 2924,
        "summary": {
            "dll_loaded": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.dll"
            ],
            "file_opened": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.dll"
            ],
            "command_line": [
                "\"C:\\Windows\\System32\\rundll32.exe\" C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.dll,DllMain"
            ],
            "file_exists": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.dll.manifest",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.dll"
            ],
            "file_read": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.dll"
            ],
            "regkey_read": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles"
            ]
        },
        "first_seen": 1585597985.625,
        "ppid": 2732
    },
    {
        "process_path": "C:\\Windows\\System32\\lsass.exe",
        "process_name": "lsass.exe",
        "pid": 476,
        "summary": {},
        "first_seen": 1585597985.328125,
        "ppid": 376
    },
    {
        "process_path": "C:\\Windows\\System32\\rundll32.exe",
        "process_name": "rundll32.exe",
        "pid": 2828,
        "summary": {
            "file_created": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.tpl.rs",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.tpl"
            ],
            "directory_created": [
                "C:\\Users\\cuck\\AppData\\Roaming\\Microsoft\\Protect\\"
            ],
            "dll_loaded": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.dll",
                "dnsapi.dll",
                "kernel32.dll",
                "Shell32.dll",
                "psapi.dll",
                "Ws2_32.dll",
                "imm32.dll"
            ],
            "file_opened": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\"
            ],
            "file_written": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.tpl"
            ],
            "file_exists": [
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.dll.manifest",
                "C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.dll"
            ],
            "regkey_read": [
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE\\PageAllocatorSystemHeapIsPrivate",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\GRE_Initialize\\DisableMetaFiles",
                "HKEY_LOCAL_MACHINE\\SOFTWARE\\Microsoft\\OLE\\PageAllocatorUseSystemHeap"
            ],
            "regkey_written": [
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\WinResSync",
                "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\WinResSync"
            ]
        },
        "first_seen": 1585597985.78125,
        "ppid": 2924
    }
]

Signatures

[
    {
        "markcount": 1,
        "families": [],
        "description": "The executable contains unknown PE section names indicative of a packer (could be a false positive)",
        "severity": 1,
        "marks": [
            {
                "category": "section",
                "ioc": ".dat",
                "type": "ioc",
                "description": null
            }
        ],
        "references": [],
        "name": "pe_features"
    },
    {
        "markcount": 11,
        "families": [],
        "description": "Checks for the Locally Unique Identifier on the system for a suspicious privilege",
        "severity": 2,
        "marks": [
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeCreateGlobalPrivilege"
                    },
                    "time": 1585597986.10925,
                    "tid": 2856,
                    "flags": {}
                },
                "pid": 2828,
                "type": "call",
                "cid": 192
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeDebugPrivilege"
                    },
                    "time": 1585597986.25025,
                    "tid": 2584,
                    "flags": {}
                },
                "pid": 2828,
                "type": "call",
                "cid": 249
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeDebugPrivilege"
                    },
                    "time": 1585597986.25025,
                    "tid": 2584,
                    "flags": {}
                },
                "pid": 2828,
                "type": "call",
                "cid": 255
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeDebugPrivilege"
                    },
                    "time": 1585597986.26525,
                    "tid": 2584,
                    "flags": {}
                },
                "pid": 2828,
                "type": "call",
                "cid": 379
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeDebugPrivilege"
                    },
                    "time": 1585597986.32825,
                    "tid": 2576,
                    "flags": {}
                },
                "pid": 2828,
                "type": "call",
                "cid": 469
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeDebugPrivilege"
                    },
                    "time": 1585597986.40625,
                    "tid": 2468,
                    "flags": {}
                },
                "pid": 2828,
                "type": "call",
                "cid": 552
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeDebugPrivilege"
                    },
                    "time": 1585597986.56225,
                    "tid": 300,
                    "flags": {}
                },
                "pid": 2828,
                "type": "call",
                "cid": 973
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeDebugPrivilege"
                    },
                    "time": 1585597986.56225,
                    "tid": 2860,
                    "flags": {}
                },
                "pid": 2828,
                "type": "call",
                "cid": 975
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeDebugPrivilege"
                    },
                    "time": 1585597989.14025,
                    "tid": 1616,
                    "flags": {}
                },
                "pid": 2828,
                "type": "call",
                "cid": 1013
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeDebugPrivilege"
                    },
                    "time": 1585597989.14025,
                    "tid": 816,
                    "flags": {}
                },
                "pid": 2828,
                "type": "call",
                "cid": 1014
            },
            {
                "call": {
                    "category": "system",
                    "status": 1,
                    "stacktrace": [],
                    "api": "LookupPrivilegeValueW",
                    "return_value": 1,
                    "arguments": {
                        "system_name": "",
                        "privilege_name": "SeDebugPrivilege"
                    },
                    "time": 1585597990.60925,
                    "tid": 1556,
                    "flags": {}
                },
                "pid": 2828,
                "type": "call",
                "cid": 3263
            }
        ],
        "references": [],
        "name": "privilege_luid_check"
    },
    {
        "markcount": 4,
        "families": [],
        "description": "Installs itself for autorun at Windows startup",
        "severity": 3,
        "marks": [
            {
                "type": "generic",
                "reg_key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\WinResSync",
                "reg_value": "C:\\Windows\\system32\\regsvr32.exe \/s \"C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.dll\""
            },
            {
                "type": "generic",
                "reg_key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\WinResSync",
                "reg_value": "C:\\Windows\\system32\\regsvr32.exe \/s \"C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.dll\""
            },
            {
                "type": "generic",
                "reg_key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\Run\\WinResSync",
                "reg_value": "C:\\Windows\\system32\\regsvr32.exe \/s \"C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.dll\""
            },
            {
                "type": "generic",
                "reg_key": "HKEY_CURRENT_USER\\Software\\Microsoft\\Windows\\CurrentVersion\\RunOnce\\WinResSync",
                "reg_value": "C:\\Windows\\system32\\regsvr32.exe \/s \"C:\\Users\\cuck\\AppData\\Local\\Temp\\69ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c.bin.dll\""
            }
        ],
        "references": [],
        "name": "persistence_autorun"
    },
    {
        "markcount": 4,
        "families": [],
        "description": "Creates a thread using CreateRemoteThread in a non-child process indicative of process injection",
        "severity": 3,
        "marks": [
            {
                "category": "Process injection",
                "ioc": "Process 2828 created a remote thread in non-child process 328",
                "type": "ioc",
                "description": null
            },
            {
                "call": {
                    "category": "process",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 8,
                    "nt_status": -1073741801,
                    "api": "CreateRemoteThread",
                    "return_value": 0,
                    "arguments": {
                        "thread_identifier": 0,
                        "process_identifier": 328,
                        "function_address": "0x00000000777a6f80",
                        "flags": 0,
                        "process_handle": "0x0000000000000168",
                        "parameter": "0x0000000000ec0000",
                        "stack_size": 0
                    },
                    "time": 1585597990.12525,
                    "tid": 2468,
                    "flags": {}
                },
                "pid": 2828,
                "type": "call",
                "cid": 2193
            },
            {
                "category": "Process injection",
                "ioc": "Process 2828 created a remote thread in non-child process 252",
                "type": "ioc",
                "description": null
            },
            {
                "call": {
                    "category": "process",
                    "status": 0,
                    "stacktrace": [],
                    "last_error": 8,
                    "nt_status": -1073741801,
                    "api": "CreateRemoteThread",
                    "return_value": 0,
                    "arguments": {
                        "thread_identifier": 0,
                        "process_identifier": 252,
                        "function_address": "0x00000000777a6f80",
                        "flags": 0,
                        "process_handle": "0x000000000000015c",
                        "parameter": "0x0000000000110000",
                        "stack_size": 0
                    },
                    "time": 1585597990.60925,
                    "tid": 2576,
                    "flags": {}
                },
                "pid": 2828,
                "type": "call",
                "cid": 3218
            }
        ],
        "references": [
            "www.endgame.com\/blog\/technical-blog\/ten-process-injection-techniques-technical-survey-common-and-trending-process"
        ],
        "name": "injection_createremotethread"
    },
    {
        "markcount": 10,
        "families": [],
        "description": "Manipulates memory of a non-child process indicative of process injection",
        "severity": 3,
        "marks": [
            {
                "category": "Process injection",
                "ioc": "Process 2828 manipulating memory of non-child process 252",
                "type": "ioc",
                "description": null
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtAllocateVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 252,
                        "region_size": 4096,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "protection": 4,
                        "process_handle": "0x000000000000015c",
                        "allocation_type": 12288,
                        "base_address": "0x0000000000110000"
                    },
                    "time": 1585597986.40625,
                    "tid": 2576,
                    "flags": {
                        "protection": "PAGE_READWRITE",
                        "allocation_type": "MEM_COMMIT|MEM_RESERVE"
                    }
                },
                "pid": 2828,
                "type": "call",
                "cid": 519
            },
            {
                "category": "Process injection",
                "ioc": "Process 2828 manipulating memory of non-child process 328",
                "type": "ioc",
                "description": null
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtAllocateVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 328,
                        "region_size": 4096,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "protection": 4,
                        "process_handle": "0x0000000000000168",
                        "allocation_type": 12288,
                        "base_address": "0x0000000000ec0000"
                    },
                    "time": 1585597986.42225,
                    "tid": 2468,
                    "flags": {
                        "protection": "PAGE_READWRITE",
                        "allocation_type": "MEM_COMMIT|MEM_RESERVE"
                    }
                },
                "pid": 2828,
                "type": "call",
                "cid": 777
            },
            {
                "category": "Process injection",
                "ioc": "Process 2828 manipulating memory of non-child process 384",
                "type": "ioc",
                "description": null
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtAllocateVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 384,
                        "region_size": 4096,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "protection": 4,
                        "process_handle": "0x0000000000000170",
                        "allocation_type": 12288,
                        "base_address": "0x0000000000c20000"
                    },
                    "time": 1585597989.46925,
                    "tid": 2860,
                    "flags": {
                        "protection": "PAGE_READWRITE",
                        "allocation_type": "MEM_COMMIT|MEM_RESERVE"
                    }
                },
                "pid": 2828,
                "type": "call",
                "cid": 1342
            },
            {
                "category": "Process injection",
                "ioc": "Process 2828 manipulating memory of non-child process 376",
                "type": "ioc",
                "description": null
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtAllocateVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 376,
                        "region_size": 4096,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "protection": 4,
                        "process_handle": "0x000000000000016c",
                        "allocation_type": 12288,
                        "base_address": "0x0000000000190000"
                    },
                    "time": 1585597990.17225,
                    "tid": 300,
                    "flags": {
                        "protection": "PAGE_READWRITE",
                        "allocation_type": "MEM_COMMIT|MEM_RESERVE"
                    }
                },
                "pid": 2828,
                "type": "call",
                "cid": 2474
            },
            {
                "category": "Process injection",
                "ioc": "Process 2828 manipulating memory of non-child process 424",
                "type": "ioc",
                "description": null
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "NtAllocateVirtualMemory",
                    "return_value": 0,
                    "arguments": {
                        "process_identifier": 424,
                        "region_size": 4096,
                        "stack_dep_bypass": 0,
                        "stack_pivoted": 0,
                        "heap_dep_bypass": 0,
                        "protection": 4,
                        "process_handle": "0x0000000000000174",
                        "allocation_type": 12288,
                        "base_address": "0x0000000000530000"
                    },
                    "time": 1585597990.60925,
                    "tid": 1616,
                    "flags": {
                        "protection": "PAGE_READWRITE",
                        "allocation_type": "MEM_COMMIT|MEM_RESERVE"
                    }
                },
                "pid": 2828,
                "type": "call",
                "cid": 3257
            }
        ],
        "references": [
            "www.endgame.com\/blog\/technical-blog\/ten-process-injection-techniques-technical-survey-common-and-trending-process"
        ],
        "name": "injection_modifies_memory"
    },
    {
        "markcount": 10,
        "families": [],
        "description": "Potential code injection by writing to the memory of another process",
        "severity": 3,
        "marks": [
            {
                "category": "Process injection",
                "ioc": "Process 2828 injected into non-child 328",
                "type": "ioc",
                "description": null
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 328,
                        "buffer": "C\u0000:\u0000\\\u0000U\u0000s\u0000e\u0000r\u0000s\u0000\\\u0000c\u0000u\u0000c\u0000k\u0000\\\u0000A\u0000p\u0000p\u0000D\u0000a\u0000t\u0000a\u0000\\\u0000L\u0000o\u0000c\u0000a\u0000l\u0000\\\u0000T\u0000e\u0000m\u0000p\u0000\\\u00006\u00009\u0000e\u0000e\u00003\u00000\u00008\u00005\u00006\u0000a\u00004\u00005\u00001\u00000\u0000f\u0000f\u00006\u00004\u0000c\u00005\u00000\u0000a\u00002\u0000c\u00002\u00004\u00001\u00009\u00001\u00009\u00005\u0000f\u0000d\u00005\u00002\u00006\u0000b\u00006\u0000b\u00002\u0000c\u0000a\u0000e\u0000a\u00005\u00000\u0000b\u0000f\u00001\u0000c\u00009\u0000d\u00008\u00008\u0000d\u0000f\u00006\u00009\u0000e\u00007\u0000c\u00009\u00003\u0000c\u0000.\u0000b\u0000i\u0000n\u0000.\u0000d\u0000l\u0000l\u0000\u0000\u0000",
                        "process_handle": "0x0000000000000168",
                        "base_address": "0x0000000000ec0000"
                    },
                    "time": 1585597986.43725,
                    "tid": 2468,
                    "flags": {}
                },
                "pid": 2828,
                "type": "call",
                "cid": 818
            },
            {
                "category": "Process injection",
                "ioc": "Process 2828 injected into non-child 252",
                "type": "ioc",
                "description": null
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 252,
                        "buffer": "C\u0000:\u0000\\\u0000U\u0000s\u0000e\u0000r\u0000s\u0000\\\u0000c\u0000u\u0000c\u0000k\u0000\\\u0000A\u0000p\u0000p\u0000D\u0000a\u0000t\u0000a\u0000\\\u0000L\u0000o\u0000c\u0000a\u0000l\u0000\\\u0000T\u0000e\u0000m\u0000p\u0000\\\u00006\u00009\u0000e\u0000e\u00003\u00000\u00008\u00005\u00006\u0000a\u00004\u00005\u00001\u00000\u0000f\u0000f\u00006\u00004\u0000c\u00005\u00000\u0000a\u00002\u0000c\u00002\u00004\u00001\u00009\u00001\u00009\u00005\u0000f\u0000d\u00005\u00002\u00006\u0000b\u00006\u0000b\u00002\u0000c\u0000a\u0000e\u0000a\u00005\u00000\u0000b\u0000f\u00001\u0000c\u00009\u0000d\u00008\u00008\u0000d\u0000f\u00006\u00009\u0000e\u00007\u0000c\u00009\u00003\u0000c\u0000.\u0000b\u0000i\u0000n\u0000.\u0000d\u0000l\u0000l\u0000\u0000\u0000",
                        "process_handle": "0x000000000000015c",
                        "base_address": "0x0000000000110000"
                    },
                    "time": 1585597986.43725,
                    "tid": 2576,
                    "flags": {}
                },
                "pid": 2828,
                "type": "call",
                "cid": 820
            },
            {
                "category": "Process injection",
                "ioc": "Process 2828 injected into non-child 384",
                "type": "ioc",
                "description": null
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 384,
                        "buffer": "C\u0000:\u0000\\\u0000U\u0000s\u0000e\u0000r\u0000s\u0000\\\u0000c\u0000u\u0000c\u0000k\u0000\\\u0000A\u0000p\u0000p\u0000D\u0000a\u0000t\u0000a\u0000\\\u0000L\u0000o\u0000c\u0000a\u0000l\u0000\\\u0000T\u0000e\u0000m\u0000p\u0000\\\u00006\u00009\u0000e\u0000e\u00003\u00000\u00008\u00005\u00006\u0000a\u00004\u00005\u00001\u00000\u0000f\u0000f\u00006\u00004\u0000c\u00005\u00000\u0000a\u00002\u0000c\u00002\u00004\u00001\u00009\u00001\u00009\u00005\u0000f\u0000d\u00005\u00002\u00006\u0000b\u00006\u0000b\u00002\u0000c\u0000a\u0000e\u0000a\u00005\u00000\u0000b\u0000f\u00001\u0000c\u00009\u0000d\u00008\u00008\u0000d\u0000f\u00006\u00009\u0000e\u00007\u0000c\u00009\u00003\u0000c\u0000.\u0000b\u0000i\u0000n\u0000.\u0000d\u0000l\u0000l\u0000\u0000\u0000",
                        "process_handle": "0x0000000000000170",
                        "base_address": "0x0000000000c20000"
                    },
                    "time": 1585597989.46925,
                    "tid": 2860,
                    "flags": {}
                },
                "pid": 2828,
                "type": "call",
                "cid": 1421
            },
            {
                "category": "Process injection",
                "ioc": "Process 2828 injected into non-child 376",
                "type": "ioc",
                "description": null
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 376,
                        "buffer": "C\u0000:\u0000\\\u0000U\u0000s\u0000e\u0000r\u0000s\u0000\\\u0000c\u0000u\u0000c\u0000k\u0000\\\u0000A\u0000p\u0000p\u0000D\u0000a\u0000t\u0000a\u0000\\\u0000L\u0000o\u0000c\u0000a\u0000l\u0000\\\u0000T\u0000e\u0000m\u0000p\u0000\\\u00006\u00009\u0000e\u0000e\u00003\u00000\u00008\u00005\u00006\u0000a\u00004\u00005\u00001\u00000\u0000f\u0000f\u00006\u00004\u0000c\u00005\u00000\u0000a\u00002\u0000c\u00002\u00004\u00001\u00009\u00001\u00009\u00005\u0000f\u0000d\u00005\u00002\u00006\u0000b\u00006\u0000b\u00002\u0000c\u0000a\u0000e\u0000a\u00005\u00000\u0000b\u0000f\u00001\u0000c\u00009\u0000d\u00008\u00008\u0000d\u0000f\u00006\u00009\u0000e\u00007\u0000c\u00009\u00003\u0000c\u0000.\u0000b\u0000i\u0000n\u0000.\u0000d\u0000l\u0000l\u0000\u0000\u0000",
                        "process_handle": "0x000000000000016c",
                        "base_address": "0x0000000000190000"
                    },
                    "time": 1585597990.17225,
                    "tid": 300,
                    "flags": {}
                },
                "pid": 2828,
                "type": "call",
                "cid": 2475
            },
            {
                "category": "Process injection",
                "ioc": "Process 2828 injected into non-child 424",
                "type": "ioc",
                "description": null
            },
            {
                "call": {
                    "category": "process",
                    "status": 1,
                    "stacktrace": [],
                    "api": "WriteProcessMemory",
                    "return_value": 1,
                    "arguments": {
                        "process_identifier": 424,
                        "buffer": "C\u0000:\u0000\\\u0000U\u0000s\u0000e\u0000r\u0000s\u0000\\\u0000c\u0000u\u0000c\u0000k\u0000\\\u0000A\u0000p\u0000p\u0000D\u0000a\u0000t\u0000a\u0000\\\u0000L\u0000o\u0000c\u0000a\u0000l\u0000\\\u0000T\u0000e\u0000m\u0000p\u0000\\\u00006\u00009\u0000e\u0000e\u00003\u00000\u00008\u00005\u00006\u0000a\u00004\u00005\u00001\u00000\u0000f\u0000f\u00006\u00004\u0000c\u00005\u00000\u0000a\u00002\u0000c\u00002\u00004\u00001\u00009\u00001\u00009\u00005\u0000f\u0000d\u00005\u00002\u00006\u0000b\u00006\u0000b\u00002\u0000c\u0000a\u0000e\u0000a\u00005\u00000\u0000b\u0000f\u00001\u0000c\u00009\u0000d\u00008\u00008\u0000d\u0000f\u00006\u00009\u0000e\u00007\u0000c\u00009\u00003\u0000c\u0000.\u0000b\u0000i\u0000n\u0000.\u0000d\u0000l\u0000l\u0000\u0000\u0000",
                        "process_handle": "0x0000000000000174",
                        "base_address": "0x0000000000530000"
                    },
                    "time": 1585597990.60925,
                    "tid": 1616,
                    "flags": {}
                },
                "pid": 2828,
                "type": "call",
                "cid": 3258
            }
        ],
        "references": [],
        "name": "injection_write_memory"
    }
]

Yara

The Yara rules did not detect anything in the file.

Network

{
    "tls": [],
    "udp": [
        {
            "src": "192.168.56.101",
            "dst": "192.168.56.255",
            "offset": 546,
            "time": 3.2949891090393066,
            "dport": 137,
            "sport": 137
        },
        {
            "src": "192.168.56.101",
            "dst": "192.168.56.255",
            "offset": 5226,
            "time": 9.379903078079224,
            "dport": 138,
            "sport": 138
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 7070,
            "time": 3.0578651428222656,
            "dport": 5355,
            "sport": 51001
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 7398,
            "time": 1.0537171363830566,
            "dport": 5355,
            "sport": 53595
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 7726,
            "time": 3.141848087310791,
            "dport": 5355,
            "sport": 53848
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 8054,
            "time": 1.5649709701538086,
            "dport": 5355,
            "sport": 54255
        },
        {
            "src": "192.168.56.101",
            "dst": "224.0.0.252",
            "offset": 8382,
            "time": -0.09843707084655762,
            "dport": 5355,
            "sport": 55314
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 8710,
            "time": 1.578861951828003,
            "dport": 1900,
            "sport": 1900
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 28120,
            "time": 1.0816569328308105,
            "dport": 3702,
            "sport": 49152
        },
        {
            "src": "192.168.56.101",
            "dst": "239.255.255.250",
            "offset": 36504,
            "time": 3.1441500186920166,
            "dport": 1900,
            "sport": 53598
        }
    ],
    "dns_servers": [],
    "http": [],
    "icmp": [],
    "smtp": [],
    "tcp": [],
    "smtp_ex": [],
    "mitm": [],
    "hosts": [],
    "pcap_sha256": "5910dbc0273ab23e88c65d7bc391f66728f39903fb393559aca11ceb3e51275c",
    "dns": [],
    "http_ex": [],
    "domains": [],
    "dead_hosts": [],
    "sorted_pcap_sha256": "36d86e8be5f576b5f21a66abeeaddfb88dcbf2a6008eb83eadd420ef57dbd3b3",
    "irc": [],
    "https_ex": []
}

Screenshots

Screenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandboxScreenshot from the sandbox

c65561-110ea1-d0de4124-8536d0-66e0.rs removal instructions

The instructions below shows how to remove c65561-110ea1-d0de4124-8536d0-66e0.rs with help from the FreeFixer removal tool. Basically, you install FreeFixer, scan your computer, check the c65561-110ea1-d0de4124-8536d0-66e0.rs file for removal, restart your computer and scan it again to verify that c65561-110ea1-d0de4124-8536d0-66e0.rs has been successfully removed. Here are the removal instructions in more detail:

  1. Download and install FreeFixer: http://www.freefixer.com/download.html
  2. Start FreeFixer and press the Start Scan button. The scan will finish in approximately five minutes.
    Screenshot of Start Scan button
  3. When the scan is finished, locate c65561-110ea1-d0de4124-8536d0-66e0.rs in the scan result and tick the checkbox next to the c65561-110ea1-d0de4124-8536d0-66e0.rs file. Do not check any other file for removal unless you are 100% sure you want to delete it. Tip: Press CTRL-F to open up FreeFixer's search dialog to quickly locate c65561-110ea1-d0de4124-8536d0-66e0.rs in the scan result.
    Red arrow point on the unwanted file
    c:\users\%USERNAME%\appdata\ro..ft\protect\c65561-110ea1-d0de4124-8536d0-66e0.rs
  4. Scroll down to the bottom of the scan result and press the Fix button. FreeFixer will now delete the c65561-110ea1-d0de4124-8536d0-66e0.rs file.
    Screenshot of Fix button
  5. Restart your computer.
  6. Start FreeFixer and scan your computer again. If c65561-110ea1-d0de4124-8536d0-66e0.rs still remains in the scan result, proceed with the next step. If c65561-110ea1-d0de4124-8536d0-66e0.rs is gone from the scan result you're done.
  7. If c65561-110ea1-d0de4124-8536d0-66e0.rs still remains in the scan result, check its checkbox again in the scan result and click Fix.
  8. Restart your computer.
  9. Start FreeFixer and scan your computer again. Verify that c65561-110ea1-d0de4124-8536d0-66e0.rs no longer appear in the scan result.
Please select the option that best describe your thoughts on the removal instructions given above








Free Questionnaires

Hashes [?]

PropertyValue
MD5d11f81c2869536f1919a8553633f2f51
SHA25669ee30856a4510ff64c50a2c2419195fd526b6b2caea50bf1c9d88df69e7c93c

What will you do with the file?

To help other users, please let us know what you will do with the file:



Comments

Please share with the other users what you think about this file. What does this file do? Is it legitimate or something that your computer is better without? Do you know how it was installed on your system? Did you install it yourself or did it come bundled with some other software? Is it running smoothly or do you get some error message? Any information that will help to document this file is welcome. Thank you for your contributions.

I'm reading all new comments so don't hesitate to post a question about the file. If I don't have the answer perhaps another user can help you.

No comments posted yet.

Leave a reply