File name:

2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid

Full analysis: https://app.any.run/tasks/f6ece773-9417-47f7-a287-b085c4bef1f2
Verdict: Malicious activity
Threats:

A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices.

Analysis date: April 26, 2025, 20:28:17
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
purplefox
backdoor
upx
nitol
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

243AAAC13872E437ED9D9B4B923FB2DB

SHA1:

5618EE959CA9947751604ACEFCC6F8F44E1CB15A

SHA256:

0635004DBD152317462A1EF368F8AF622370EFE30503CF53D6BD7D1E580D33C6

SSDEEP:

98304:N2MlkOphS+YS6S85r47SBk66oYPxS8NSYfxYf5IxX7Nr0LVkY39:xZxEV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Connects to the CnC server

      • ysplij.exe (PID: 6132)
    • NITOL has been detected (YARA)

      • ysplij.exe (PID: 6132)
    • PURPLEFOX has been detected (SURICATA)

      • ysplij.exe (PID: 6132)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 4180)
      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
      • ysplij.exe (PID: 6132)
    • Process drops legitimate windows executable

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 4180)
      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
    • Reads security settings of Internet Explorer

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 4180)
      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
    • Application launched itself

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 4180)
    • Adds/modifies Windows certificates

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
    • Executes application which crashes

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 4180)
    • Creates or modifies Windows services

      • ysplij.exe (PID: 6132)
    • Connects to unusual port

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
      • ysplij.exe (PID: 6132)
    • Contacting a server suspected of hosting an CnC

      • ysplij.exe (PID: 6132)
    • Connects to the server without a host name

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
  • INFO

    • The sample compiled with english language support

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 4180)
      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
    • Reads the computer name

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 4180)
      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
      • ysplij.exe (PID: 6132)
    • Process checks computer location settings

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 4180)
    • Checks supported languages

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 4180)
      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
      • ysplij.exe (PID: 6132)
    • Reads the machine GUID from the registry

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 4180)
      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
    • Checks proxy server information

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
      • slui.exe (PID: 1912)
    • Reads CPU info

      • ysplij.exe (PID: 6132)
    • UPX packer has been detected

      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
      • ysplij.exe (PID: 6132)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 6112)
      • 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe (PID: 6972)
    • Reads the software policy settings

      • slui.exe (PID: 1912)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (24.4)
.exe | Win64 Executable (generic) (21.6)
.exe | UPX compressed Win32 Executable (21.2)
.exe | Win32 EXE Yoda's Crypter (20.8)
.dll | Win32 Dynamic Link Library (generic) (5.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:04:15 07:00:27+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 741376
InitializedDataSize: 3330048
UninitializedDataSize: -
EntryPoint: 0x95d98
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe werfault.exe no specs #PURPLEFOX ysplij.exe slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
1912C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4180"C:\Users\admin\Desktop\2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe" C:\Users\admin\Desktop\2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3762504530
Modules
Images
c:\users\admin\desktop\2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ws2_32.dll
6112C:\WINDOWS\SysWOW64\WerFault.exe -u -p 4180 -s 2188C:\Windows\SysWOW64\WerFault.exe2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
6132C:\Users\admin\Desktop\ysplij.exeC:\Users\admin\Desktop\ysplij.exe
2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\ysplij.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6972"C:\Users\admin\Desktop\2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe" C:\Users\admin\Desktop\2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe
2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ws2_32.dll
Total events
30 000
Read events
29 986
Write events
9
Delete events
5

Modification events

(PID) Process:(4180) 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Script\Settings
Operation:writeName:JITDebug
Value:
0
(PID) Process:(4180) 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Script\Settings\Telemetry\2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe
Operation:writeName:JScriptSetScriptStateStarted
Value:
C4BD100000000000
(PID) Process:(4180) 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates
Operation:delete valueName:396E8BA1E16F37200D3409F73730E25CCAB64101
Value:
(PID) Process:(6972) 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates
Operation:delete valueName:2BD7C62275C38B7CD7F2B4299409C6B49A13EBF9
Value:
(PID) Process:(6972) 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\2BD7C62275C38B7CD7F2B4299409C6B49A13EBF9
Operation:writeName:Blob
Value:
0300000001000000140000002BD7C62275C38B7CD7F2B4299409C6B49A13EBF92000000001000000A7030000308203A33082028BA0030201020210009230B4604BFA0DE549106C388C2E41300D06092A864886F70D01010B0500306A312B3029060355040B0C224372656174656420627920687474703A2F2F7777772E666964646C6572322E636F6D31183016060355040A0C0F444F5F4E4F545F54525553545F42433121301F06035504030C18444F5F4E4F545F54525553545F466964646C6572526F6F74301E170D3235303431393030303030305A170D3335303432363230323832395A306A312B3029060355040B0C224372656174656420627920687474703A2F2F7777772E666964646C6572322E636F6D31183016060355040A0C0F444F5F4E4F545F54525553545F42433121301F06035504030C18444F5F4E4F545F54525553545F466964646C6572526F6F7430820122300D06092A864886F70D01010105000382010F003082010A0282010100839402D9E61481BC8437FFC9701F2D349DB13B83CD9B750937D3B837E5406645CCE8229B2A552FEE2871A758BB77BDE3719E94765B0BF6622BACB3BBD635A999A634DBB62DA10F53FA7A5F243F39DC9AA8704F556D4C17992157F9A5DD3B9951EA45C0B6944160B2E3D81F63031E129B27BC3306E935FE8A1CEAF8D0A1C58447DB84CCAF24DE1D80A06617C75223C0B336600FBDEAA79CF7244D156128817ABA2170CAC80D92C872A0B3AF8A9F4268610C77C9CFE09E4445F2D3C9BB54D8F241807156FD83B42564449F13892F82FF09271BFAED50D6B825FF51CA460ADD5E745F627456A111A840A024EE81B6C6F7B5980B10F54212ABEE5F7FF3F99CE995B30203010001A345304330120603551D130101FF040830060101FF020100300E0603551D0F0101FF040403020204301D0603551D0E041604147534F6652FC2B16113BC0D96B78297EE9638B47F300D06092A864886F70D01010B050003820101005A6E64095E018BC563833926F06EEA59E2B1078AE48ECCB32966A1C2E595E2C9784FF52D0A8BB25CD7B26FBF8D31C1E868B106E6F1ED25950797ACC19C4C4B08FF2FA74DD05B7E230E01D7E76ED5B9225E22B27E71E284900F40289BDD18BECFF734A7C937D49E6F74B8A9A20367FA40E5B024E0268A2A2138DBB9AB1E7EB2EF562C90EDB5AE7237EB074FADC354DE464B0B08C6ED8581448D14617D08FB36CF6B7719489521BEBCAC3D014C0154D9770684D7A751048D90771405725E9B15D82496D125F65FDF0A6DC123F4C913D5FF8839C6FF6D96A5EE0D31EA91B73D84E4A6091D77E1F86C9AC24C4858601F31565A44ECAF13632282A5CA3117FD285D77
(PID) Process:(4180) 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates
Operation:delete valueName:396E8BA1E16F37200D3409F73730E25CCAB64101
Value:
(PID) Process:(6132) ysplij.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Rskwqy qyyiucie
Operation:writeName:MarkTime
Value:
2025-04-26
(PID) Process:(6972) 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6972) 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6972) 2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
10
Suspicious files
2
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
6112WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_PARPWICSKL2YAUSK_9ba152ba45594313616ffe1fd33101a48263b_b48d3c1b_d6640f5d-ba6e-4257-bb76-114cbb3a0c7e\Report.wer
MD5:
SHA256:
6112WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe.4180.dmp
MD5:
SHA256:
41802025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeC:\Users\admin\Desktop\BCMakeCert.dllexecutable
MD5:5D895D1C6CEE56D206B6CD973479638D
SHA256:BCFC362B42422CEDE445C8A119D454484B3842EB808B7DDF1B5AEB7242E06ABB
41802025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeC:\Users\admin\Desktop\makecert.exeexecutable
MD5:3DA54BD90C1A4EF9A12270102C047FC5
SHA256:61D76327DE227AE8F15AFBB0F99C1DF6152061855DF7B35DBD6FF7329FC1BA4D
41802025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeC:\Users\admin\Desktop\FiddlerCore4.dllexecutable
MD5:79FE5228B7CCDC88CF7DDBA2893EA71F
SHA256:5850D403352D76E7F7EBDA93A7BFF5AB1EA57C91A54A2F6C2CFAF1C9D356D55F
69722025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\s15[1].htmtext
MD5:CF7D48006C755420EC730D03E5E0411D
SHA256:2AC2881B8BC435210A6BDA81315890E78AF3544D910E2C460E2EC244D80BB7F3
41802025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeC:\Users\admin\Desktop\efd.dllexecutable
MD5:1D5B8FF63AE7882CC6C8CA61921D8707
SHA256:472A47CCA297EE3801CF2AAF75CEB1D7782061AFED2EA6882A57C39E2F580169
41802025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeC:\Users\admin\Desktop\ssleay32.dllexecutable
MD5:B1A5E529CF54784B8D9C74EEDCDCAAE0
SHA256:525F4D750E774E95BCDD2E059FA1EBFEE2FA81AC68684B98D5153D413DCF7E4D
41802025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exeC:\Users\admin\Desktop\CertMaker.dllexecutable
MD5:ECCC93A46C56DA30635AAB9946D3773A
SHA256:476A9A6CCF39353CA004118829DDA91FF771906EA18F5DB7DB9A73044DDA3BD8
6112WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERDA35.tmp.dmpbinary
MD5:9D1F5D2F51104104141F4F8A58AC3F80
SHA256:BCAD0FD80F990141EF2BEC68DFC6E695140D87BAE3F7103501295274D386E91B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
47
TCP/UDP connections
52
DNS requests
18
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2104
svchost.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6972
2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe
POST
200
202.61.87.53:8099
http://202.61.87.53:8099/s15.asp?id=B4:FA:73:A8:13:4E
unknown
unknown
6972
2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe
GET
200
202.61.87.53:80
http://202.61.87.53/config.txt
unknown
unknown
1912
RUXIMICS.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2104
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6972
2025-04-26_243aaac13872e437ed9d9b4b923fb2db_elex_icedid.exe
GET
200
202.61.87.53:80
http://202.61.87.53/config.txt
unknown
unknown
GET
304
4.175.87.197:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
unknown
unknown
1568
SIHClient.exe
GET
200
23.207.61.138:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.1.crl
unknown
whitelisted
1568
SIHClient.exe
GET
200
92.122.244.42:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
unknown
whitelisted
1568
SIHClient.exe
GET
200
92.122.244.42:80
http://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1912
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2104
svchost.exe
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1912
RUXIMICS.exe
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2104
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
1912
RUXIMICS.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
6544
svchost.exe
20.190.159.129:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.78
whitelisted
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
  • 92.122.244.42
  • 92.122.244.32
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 23.207.61.138
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 20.73.194.208
whitelisted
login.live.com
  • 20.190.159.129
  • 40.126.31.128
  • 40.126.31.69
  • 40.126.31.0
  • 40.126.31.130
  • 40.126.31.2
  • 20.190.159.68
  • 20.190.159.131
whitelisted
client.wns.windows.com
  • 172.211.123.250
  • 172.211.123.249
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
  • 40.91.76.224
whitelisted
nexusrules.officeapps.live.com
  • 52.111.227.13
whitelisted

Threats

PID
Process
Class
Message
6132
ysplij.exe
Malware Command and Control Activity Detected
MALWARE [ANY.RUN] PurpleFox Backdoor CnC Communication
6132
ysplij.exe
Malware Command and Control Activity Detected
MALWARE [ANY.RUN] PurpleFox Backdoor CnC Communication
No debug info