Detected Threats
Arrow Process Create process
Create process ""C:\Windows\Microsoft.NET\Framework64\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\aETAdzjz\AppData\Local\Temp\91rxrejg.cmdline"".
Create process "C:\Windows\System32\mshta.exe".
Create process "C:\Windows\SYSteM32\windowspOweRSHeLL\V1.0\PoWErSHELL.Exe".
Create process ""C:\Windows\system32\taskkill.exe" /f /im winword.exe".
Arrow Process Execute encoded PowerShell script
Execute encoded PowerShell script to possibly hide malicious payload.
Arrow Network Download data
URL "www.samyrai777m.p-host.in/t/tp.php?thread=0".
Arrow Network Perform DNS request
Resolve host name "www.samyrai777m.p-host.in".
Arrow Device Monitor keyboard input
Frequently read the state of a keyboard key by API.
Arrow Network Connect to remote host
Outgoing TCP connection to host "".
Arrow Network Connect to HTTP server
URL "www.samyrai777m.p-host.in/t/tp.php?thread=0".
Arrow Process Create system object
Create mutex with name "Global\.net clr networking".
Create mutex with name "Local\!PrivacIE!SharedMemory!Mutex".
