file | C:\Program Files\Google\Chrome\Application\chrome.exe |
section | .ndata |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\OpenCL\OpenCL.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\NHMCore.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\msvcp120.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\ManagedNvml.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\NHM.DeviceMonitoring.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\common\cudart32_80.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\common\libcurl.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\runnhmasadmin.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\log4net.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\MinerPlugin.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\miner_plugins\59bba2c0-b1ef-11e9-8e4e-bb1e2c6e76b4\MiniZ.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\common\msvcr120.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\common\msvcr110.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\miner_plugins\1b7019d0-7237-11e9-b20c-f9f12eb6d835\GMiner.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\SharpCompress.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\runnhmasadmin.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\MinerProcessCounter.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsu6609.tmp\StdUtils.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsu6609.tmp\System.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\NHM.Common.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\Newtonsoft.Json.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\NHM.UUID.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\common\msvcp140.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\opencl_device_detection.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\cuda_device_detection.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\device_detection_test.bat |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\AddWindowsDefenderExclusion.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\common\cudart64_91.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\NVIDIA\nvml.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\Ethlargement.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NiceHash Miner.lnk |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\OpenCL\OpenCL.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\common\cudart64_80.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\miner_plugins\f5d4a470-e360-11e9-a914-497feefbdfc8\Phoenix.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsu6609.tmp\UAC.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\MinerPluginToolkitV1.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\miner_plugins\abc3e2a0-7237-11e9-b20c-f9f12eb6d835\TeamRedMiner.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\CreateLogReport.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\NHM.DeviceDetection.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\miner_plugins\2257f160-7236-11e9-b20c-f9f12eb6d835\CCMinerTpruvot.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\CreateLogReport.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\RigIDPrinter.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\miner_plugins\70984aa0-7236-11e9-b20c-f9f12eb6d835\ClaymoreDual14.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\MyDownloader.Core.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\FirewallRules.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\Hardcodet.Wpf.TaskbarNotification.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\common\vcruntime140.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsu6609.tmp\WinShell.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\miner_plugins\6c07f7a0-7237-11e9-b20c-f9f12eb6d835\NBMiner.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\miner_plugins\d47d9b00-7237-11e9-b20c-f9f12eb6d835\TRex.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\miner_plugins\1046ea50-c261-11e9-8e4e-bb1e2c6e76b4\XMRig.dll |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Snipping Tool.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Welcome Center.lnk |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\NiceHash Miner.lnk |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk |
file | C:\Users\Administrator.Oskar-PC\Desktop\NiceHash Miner.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Remote Desktop Connection.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Media Center.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Calculator.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Paint.lnk |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Accessories\Accessibility\Magnify.lnk |
file | C:\Users\Public\Desktop\Google Chrome.lnk |
file | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\Accessories\Sticky Notes.lnk |
file | C:\Users\Administrator.Oskar-PC\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Windows Explorer.lnk |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\ManagedNvml.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\Newtonsoft.Json.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsu6609.tmp\StdUtils.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\runnhmasadmin.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\MegaApiClient.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\miner_plugins\1b7019d0-7237-11e9-b20c-f9f12eb6d835\GMiner.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\NHMCore.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsu6609.tmp\nsDialogs.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\log4net.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsu6609.tmp\nsis7z.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsu6609.tmp\System.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\common\cudart32_80.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\MinerPluginLoader.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\MinerPluginToolkitV1.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\FirewallRules.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsu6609.tmp\nsProcess.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\LolMiner.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\miner_plugins\70984aa0-7236-11e9-b20c-f9f12eb6d835\ClaymoreDual14.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\common\msvcp120.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\MinerProcessCounter.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\System.ValueTuple.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\NHM.UUID.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\miner_plugins\6c07f7a0-7237-11e9-b20c-f9f12eb6d835\NBMiner.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\common\msvcr120.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\Ethlargement.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\NHM.DeviceDetection.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\Hardcodet.Wpf.TaskbarNotification.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\BouncyCastle.Crypto.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\miner_plugins\f5d4a470-e360-11e9-a914-497feefbdfc8\Phoenix.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\miner_plugins\abc3e2a0-7237-11e9-b20c-f9f12eb6d835\TeamRedMiner.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\miner_plugins\2257f160-7236-11e9-b20c-f9f12eb6d835\CCMinerTpruvot.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\NHM.DeviceMonitoring.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\RigIDPrinter.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\AddWindowsDefenderExclusion.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\NHM.Common.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\miner_plugins\1046ea50-c261-11e9-8e4e-bb1e2c6e76b4\XMRig.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsu6609.tmp\WinShell.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\MyDownloader.Extension.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\nvidiasetp0state.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\CreateLogReport.exe |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\miner_plugins\d47d9b00-7237-11e9-b20c-f9f12eb6d835\TRex.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\MyDownloader.Core.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\miner_plugins\5532d300-7238-11e9-b20c-f9f12eb6d835\ZEnemy.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\websocket-sharp.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\SharpCompress.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\MinerPlugin.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Temp\nsu6609.tmp\UAC.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\NHM.MinersDownloader.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\miner_plugins\59bba2c0-b1ef-11e9-8e4e-bb1e2c6e76b4\MiniZ.dll |
file | C:\Users\Administrator.Oskar-PC\AppData\Local\Programs\NiceHash Miner\app_3.0.0.3\AmdComputeModeSwitcher.exe |
process | b7b7dcdf80d1da439198c306cdefdba1.exe |
host | 172.217.24.14 |
dead_host | 172.217.27.142:443 |
No hosts contacted.
Name | Response | Post-Analysis Lookup |
---|---|---|
dns.msftncsi.com | A 131.107.255.255 | 131.107.255.255 |
time.windows.com |
A 20.189.79.72
CNAME time.microsoft.akadns.net |
|
clients2.google.com |
CNAME clients.l.google.com
A 172.217.27.142 |
172.217.27.142 |
dns.msftncsi.com | AAAA fd3e:4f5a:5b81::1 | 131.107.255.255 |
teredo.ipv6.microsoft.com |
No TCP connections recorded.
Source | Source Port | Destination | Destination Port |
---|---|---|---|
192.168.56.101 | 49235 | 114.114.114.114 | 53 |
192.168.56.101 | 50534 | 114.114.114.114 | 53 |
192.168.56.101 | 51378 | 114.114.114.114 | 53 |
192.168.56.101 | 56539 | 114.114.114.114 | 53 |
192.168.56.101 | 58367 | 114.114.114.114 | 53 |
192.168.56.101 | 65004 | 114.114.114.114 | 53 |
192.168.56.101 | 137 | 192.168.56.255 | 137 |
192.168.56.101 | 138 | 192.168.56.255 | 138 |
192.168.56.101 | 123 | 20.189.79.72 time.windows.com | 123 |
192.168.56.101 | 53657 | 224.0.0.252 | 5355 |
192.168.56.101 | 55368 | 224.0.0.252 | 5355 |
192.168.56.101 | 56804 | 224.0.0.252 | 5355 |
192.168.56.101 | 60123 | 224.0.0.252 | 5355 |
192.168.56.101 | 62191 | 224.0.0.252 | 5355 |
192.168.56.101 | 1900 | 239.255.255.250 | 1900 |
192.168.56.101 | 56807 | 239.255.255.250 | 1900 |
192.168.56.101 | 58368 | 239.255.255.250 | 3702 |
192.168.56.101 | 58370 | 239.255.255.250 | 3702 |
192.168.56.101 | 58707 | 239.255.255.250 | 3702 |
192.168.56.101 | 62192 | 239.255.255.250 | 3702 |
No HTTP requests performed.
No ICMP traffic performed.
No IRC requests performed.
No Suricata Alerts
No Suricata TLS
No Snort Alerts