File name:

2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid

Full analysis: https://app.any.run/tasks/f6ece773-9417-47f7-a287-b085c4bef1f2
Verdict: Malicious activity
Threats:

A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices.

Analysis date: April 26, 2025, 20:28:17
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
purplefox
backdoor
upx
nitol
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

243AAAC13872E437ED9D9B4B923FB2DB

SHA1:

5618EE959CA9947751604ACEFCC6F8F44E1CB15A

SHA256:

0635004DBD152317462A1EF368F8AF622370EFE30503CF53D6BD7D1E580D33C6

SSDEEP:

98304:N2MlkOphS+YS6S85r47SBk66oYPxS8NSYfxYf5IxX7Nr0LVkY39:xZxEV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Connects to the CnC server

      • ysplij.exe (PID: 6132)
    • PURPLEFOX has been detected (SURICATA)

      • ysplij.exe (PID: 6132)
    • NITOL has been detected (YARA)

      • ysplij.exe (PID: 6132)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 4180)
      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
      • ysplij.exe (PID: 6132)
    • Process drops legitimate windows executable

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 4180)
      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
    • Reads security settings of Internet Explorer

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 4180)
      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
    • Application launched itself

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 4180)
    • Connects to unusual port

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
      • ysplij.exe (PID: 6132)
    • Creates or modifies Windows services

      • ysplij.exe (PID: 6132)
    • Contacting a server suspected of hosting an CnC

      • ysplij.exe (PID: 6132)
    • Connects to the server without a host name

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
    • Adds/modifies Windows certificates

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
    • Executes application which crashes

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 4180)
  • INFO

    • Checks supported languages

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 4180)
      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
      • ysplij.exe (PID: 6132)
    • The sample compiled with english language support

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 4180)
      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
    • Process checks computer location settings

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 4180)
    • Reads the computer name

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 4180)
      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
      • ysplij.exe (PID: 6132)
    • Reads the machine GUID from the registry

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 4180)
    • Checks proxy server information

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
      • slui.exe (PID: 1912)
    • Reads CPU info

      • ysplij.exe (PID: 6132)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 6112)
      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
    • UPX packer has been detected

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
      • ysplij.exe (PID: 6132)
    • Reads the software policy settings

      • slui.exe (PID: 1912)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (24.4)
.exe | Win64 Executable (generic) (21.6)
.exe | UPX compressed Win32 Executable (21.2)
.exe | Win32 EXE Yoda's Crypter (20.8)
.dll | Win32 Dynamic Link Library (generic) (5.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:04:15 07:00:27+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 741376
InitializedDataSize: 3330048
UninitializedDataSize: -
EntryPoint: 0x95d98
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe werfault.exe no specs #PURPLEFOX ysplij.exe slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
1912C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4180"C:\Users\admin\Desktop\2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe" C:\Users\admin\Desktop\2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3762504530
Modules
Images
c:\users\admin\desktop\2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ws2_32.dll
6112C:\WINDOWS\SysWOW64\WerFault.exe -u -p 4180 -s 2188C:\Windows\SysWOW64\WerFault.exe2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
6132C:\Users\admin\Desktop\ysplij.exeC:\Users\admin\Desktop\ysplij.exe
2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\ysplij.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6972"C:\Users\admin\Desktop\2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe" C:\Users\admin\Desktop\2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe
2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ws2_32.dll
Total events
30 000
Read events
29 986
Write events
9
Delete events
5

Modification events

(PID) Process:(4180) 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Script\Settings
Operation:writeName:JITDebug
Value:
0
(PID) Process:(4180) 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Script\Settings\Telemetry\2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe
Operation:writeName:JScriptSetScriptStateStarted
Value:
C4BD100000000000
(PID) Process:(4180) 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates
Operation:delete valueName:396E8BA1E16F37200D3409F73730E25CCAB64101
Value:
(PID) Process:(6972) 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates
Operation:delete valueName:2BD7C62275C38B7CD7F2B4299409C6B49A13EBF9
Value:
(PID) Process:(6972) 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2BD7C62275C38B7CD7F2B4299409C6B49A13EBF9
Operation:writeName:Blob
Value:
0300000001000000140000002BD7C62275C38B7CD7F2B4299409C6B49A13EBF92000000001000000A7030000308203A33082028BA0030201020210009230B4604BFA0DE549106C388C2E41300D06092A864886F70D01010B0500306A312B3029060355040B0C224372656174656420627920687474703A2F2F7777772E666964646C6572322E636F6D31183016060355040A0C0F444F5F4E4F545F54525553545F42433121301F06035504030C18444F5F4E4F545F54525553545F466964646C6572526F6F74301E170D3235303431393030303030305A170D3335303432363230323832395A306A312B3029060355040B0C224372656174656420627920687474703A2F2F7777772E666964646C6572322E636F6D31183016060355040A0C0F444F5F4E4F545F54525553545F42433121301F06035504030C18444F5F4E4F545F54525553545F466964646C6572526F6F7430820122300D06092A864886F70D01010105000382010F003082010A0282010100839402D9E61481BC8437FFC9701F2D349DB13B83CD9B750937D3B837E5406645CCE8229B2A552FEE2871A758BB77BDE3719E94765B0BF6622BACB3BBD635A999A634DBB62DA10F53FA7A5F243F39DC9AA8704F556D4C17992157F9A5DD3B9951EA45C0B6944160B2E3D81F63031E129B27BC3306E935FE8A1CEAF8D0A1C58447DB84CCAF24DE1D80A06617C75223C0B336600FBDEAA79CF7244D156128817ABA2170CAC80D92C872A0B3AF8A9F4268610C77C9CFE09E4445F2D3C9BB54D8F241807156FD83B42564449F13892F82FF09271BFAED50D6B825FF51CA460ADD5E745F627456A111A840A024EE81B6C6F7B5980B10F54212ABEE5F7FF3F99CE995B30203010001A345304330120603551D130101FF040830060101FF020100300E0603551D0F0101FF040403020204301D0603551D0E041604147534F6652FC2B16113BC0D96B78297EE9638B47F300D06092A864886F70D01010B050003820101005A6E64095E018BC563833926F06EEA59E2B1078AE48ECCB32966A1C2E595E2C9784FF52D0A8BB25CD7B26FBF8D31C1E868B106E6F1ED25950797ACC19C4C4B08FF2FA74DD05B7E230E01D7E76ED5B9225E22B27E71E284900F40289BDD18BECFF734A7C937D49E6F74B8A9A20367FA40E5B024E0268A2A2138DBB9AB1E7EB2EF562C90EDB5AE7237EB074FADC354DE464B0B08C6ED8581448D14617D08FB36CF6B7719489521BEBCAC3D014C0154D9770684D7A751048D90771405725E9B15D82496D125F65FDF0A6DC123F4C913D5FF8839C6FF6D96A5EE0D31EA91B73D84E4A6091D77E1F86C9AC24C4858601F31565A44ECAF13632282A5CA3117FD285D77
(PID) Process:(4180) 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates
Operation:delete valueName:396E8BA1E16F37200D3409F73730E25CCAB64101
Value:
(PID) Process:(6132) ysplij.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Rskwqy qyyiucie
Operation:writeName:MarkTime
Value:
2025-04-26
(PID) Process:(6972) 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6972) 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6972) 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
10
Suspicious files
2
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
6112WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_PARPWICSKL2YAUSK_9ba152ba45594313616ffe1fd33101a48263b_b48d3c1b_d6640f5d-ba6e-4257-bb76-114cbb3a0c7e\Report.wer
MD5:
SHA256:
6112WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe.4180.dmp
MD5:
SHA256:
41802025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeC:\Users\admin\Desktop\libeay32.dllexecutable
MD5:406FA233756D1A3496E33EDC0C7B4E9F
SHA256:EEDE376250E8771B7991FDA51A60BB389F413E5D16888F695ADFBBDD412F2CA2
6112WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERDA35.tmp.dmpbinary
MD5:9D1F5D2F51104104141F4F8A58AC3F80
SHA256:BCAD0FD80F990141EF2BEC68DFC6E695140D87BAE3F7103501295274D386E91B
41802025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeC:\Users\admin\Desktop\ssleay32.dllexecutable
MD5:B1A5E529CF54784B8D9C74EEDCDCAAE0
SHA256:525F4D750E774E95BCDD2E059FA1EBFEE2FA81AC68684B98D5153D413DCF7E4D
41802025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeC:\Users\admin\Desktop\makecert.exeexecutable
MD5:3DA54BD90C1A4EF9A12270102C047FC5
SHA256:61D76327DE227AE8F15AFBB0F99C1DF6152061855DF7B35DBD6FF7329FC1BA4D
6112WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERDD06.tmp.xmlxml
MD5:96BA62420503A14577958279E3624393
SHA256:8EC738C9ADC7BA7C0F499A7B42EB7E57CFE61B6C3C08AEAD44A9DDA9870D1449
69722025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeC:\Users\admin\Desktop\ysplij.exeexecutable
MD5:65EBFC9294A9193E95233731D03D0820
SHA256:6032F8E3D7F184FD93952F4D67D2F78382725F0E8CA523941DEA91B38663B288
6112WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERDCD6.tmp.WERInternalMetadata.xmlbinary
MD5:293589AD171371615CCAAD81EDEEA923
SHA256:2F73D0E3730B6CB58AEB0042A8CD8B3B175706522D17686C0A682E4C7FC33421
69722025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\s15[1].htmtext
MD5:CF7D48006C755420EC730D03E5E0411D
SHA256:2AC2881B8BC435210A6BDA81315890E78AF3544D910E2C460E2EC244D80BB7F3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
47
TCP/UDP connections
52
DNS requests
18
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2104
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1912
RUXIMICS.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2104
svchost.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1912
RUXIMICS.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1568
SIHClient.exe
GET
200
23.207.61.138:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6972
2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe
POST
200
202.61.87.53:8099
http://202.61.87.53:8099/s15.asp?id=B4:FA:73:A8:13:4E
unknown
unknown
6972
2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe
GET
200
202.61.87.53:80
http://202.61.87.53/config.txt
unknown
unknown
GET
304
4.175.87.197:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
unknown
6972
2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe
GET
200
202.61.87.53:80
http://202.61.87.53/config.txt
unknown
unknown
1568
SIHClient.exe
GET
200
23.207.61.138:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1912
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2104
svchost.exe
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1912
RUXIMICS.exe
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2104
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
1912
RUXIMICS.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
6544
svchost.exe
20.190.159.129:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.78
whitelisted
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
  • 92.122.244.42
  • 92.122.244.32
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 23.207.61.138
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 20.73.194.208
whitelisted
login.live.com
  • 20.190.159.129
  • 40.126.31.128
  • 40.126.31.69
  • 40.126.31.0
  • 40.126.31.130
  • 40.126.31.2
  • 20.190.159.68
  • 20.190.159.131
whitelisted
client.wns.windows.com
  • 172.211.123.250
  • 172.211.123.249
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
  • 40.91.76.224
whitelisted
nexusrules.officeapps.live.com
  • 52.111.227.13
whitelisted

Threats

PID
Process
Class
Message
6132
ysplij.exe
Malware Command and Control Activity Detected
MALWARE [ANY.RUN] PurpleFox Backdoor CnC Communication
6132
ysplij.exe
Malware Command and Control Activity Detected
MALWARE [ANY.RUN] PurpleFox Backdoor CnC Communication
No debug info