File name:

2025-12-14_9a0f1c9e8a79b6f1fc43ac6d2725fc2b_coinminer_elex_frostygoop_glassworm_poet-rat_sliver_snatch.exe

Full analysis: https://app.any.run/tasks/7b090e06-f3e5-405c-94d5-a1a885f2223d
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: January 19, 2026, 22:08:54
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
ms-smartcard
salatstealer
stealer
auto-reg
susp-powershell
golang
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

9A0F1C9E8A79B6F1FC43AC6D2725FC2B

SHA1:

0108ED8CBC22B60B7ACD25686B083844411B66A6

SHA256:

12E7D8F52867D8C02718581C4DE46E9B4E76A826140182D43FC9DBDCFA1152DB

SSDEEP:

98304:vr/1gpi7GVW58z4m8YVD4hIvBwDX5GzcIE:1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • SALATSTEALER mutex has been found

      • dasHost.exe (PID: 7408)
      • 7b090e06-f3e5-405c-94d5-a1a885f2223d.exe (PID: 7940)
      • dllhost.exe (PID: 7708)
      • dasHost.exe (PID: 2144)
      • StartMenuExperienceHost.exe (PID: 8040)
    • Steals credentials from Web Browsers

      • dasHost.exe (PID: 7408)
    • Actions looks like stealing of personal data

      • dasHost.exe (PID: 7408)
    • Starts REAGENTC.EXE to disable the Windows Recovery Environment

      • ReAgentc.exe (PID: 7808)
    • Changes the autorun value in the registry

      • 7b090e06-f3e5-405c-94d5-a1a885f2223d.exe (PID: 7940)
    • SALATSTEALER has been detected (YARA)

      • dasHost.exe (PID: 7408)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • 7b090e06-f3e5-405c-94d5-a1a885f2223d.exe (PID: 7940)
      • dasHost.exe (PID: 7408)
    • Starts itself from another location

      • 7b090e06-f3e5-405c-94d5-a1a885f2223d.exe (PID: 7940)
      • dasHost.exe (PID: 7408)
    • Executable content was dropped or overwritten

      • 7b090e06-f3e5-405c-94d5-a1a885f2223d.exe (PID: 7940)
      • dasHost.exe (PID: 7408)
    • Possible stealing of messenger data

      • dasHost.exe (PID: 7408)
    • Starts POWERSHELL.EXE for commands execution

      • dasHost.exe (PID: 7408)
    • Possible stealing from crypto wallets

      • dasHost.exe (PID: 7408)
    • Gets path to any of the special folders (POWERSHELL)

      • powershell.exe (PID: 1568)
    • Application launched itself

      • 7b090e06-f3e5-405c-94d5-a1a885f2223d.exe (PID: 7684)
    • There is functionality for taking screenshot (YARA)

      • dasHost.exe (PID: 7408)
    • Multiple wallet extension IDs have been found

      • dasHost.exe (PID: 7408)
  • INFO

    • Reads security settings of Internet Explorer

      • 7b090e06-f3e5-405c-94d5-a1a885f2223d.exe (PID: 7684)
    • Reads the computer name

      • 7b090e06-f3e5-405c-94d5-a1a885f2223d.exe (PID: 7684)
      • dasHost.exe (PID: 7408)
      • dasHost.exe (PID: 7172)
      • dasHost.exe (PID: 6084)
      • 7b090e06-f3e5-405c-94d5-a1a885f2223d.exe (PID: 7940)
    • Creates files in the program directory

      • 7b090e06-f3e5-405c-94d5-a1a885f2223d.exe (PID: 7940)
      • dasHost.exe (PID: 7408)
    • Launching a file from a Registry key

      • 7b090e06-f3e5-405c-94d5-a1a885f2223d.exe (PID: 7940)
    • Checks supported languages

      • dasHost.exe (PID: 7408)
      • 7b090e06-f3e5-405c-94d5-a1a885f2223d.exe (PID: 7684)
      • dasHost.exe (PID: 7172)
      • dasHost.exe (PID: 6084)
      • dllhost.exe (PID: 7708)
      • 7b090e06-f3e5-405c-94d5-a1a885f2223d.exe (PID: 7940)
      • dasHost.exe (PID: 2144)
      • StartMenuExperienceHost.exe (PID: 8040)
    • Reads the machine GUID from the registry

      • dasHost.exe (PID: 7408)
      • 7b090e06-f3e5-405c-94d5-a1a885f2223d.exe (PID: 7684)
      • 7b090e06-f3e5-405c-94d5-a1a885f2223d.exe (PID: 7940)
      • dasHost.exe (PID: 7172)
      • dasHost.exe (PID: 6084)
      • dasHost.exe (PID: 2144)
      • StartMenuExperienceHost.exe (PID: 8040)
      • dllhost.exe (PID: 7708)
    • Process checks computer location settings

      • 7b090e06-f3e5-405c-94d5-a1a885f2223d.exe (PID: 7684)
    • Drops script file

      • dasHost.exe (PID: 7408)
      • powershell.exe (PID: 1568)
    • Create files in a temporary directory

      • dasHost.exe (PID: 7408)
    • Drops encrypted JS script (Microsoft Script Encoder)

      • dasHost.exe (PID: 7408)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 1568)
    • Manual execution by a user

      • dllhost.exe (PID: 7708)
      • dasHost.exe (PID: 2144)
      • StartMenuExperienceHost.exe (PID: 8040)
    • Creates files or folders in the user directory

      • 7b090e06-f3e5-405c-94d5-a1a885f2223d.exe (PID: 7940)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 1568)
    • Checks current location (POWERSHELL)

      • powershell.exe (PID: 1568)
    • Checks proxy server information

      • powershell.exe (PID: 1568)
      • slui.exe (PID: 8132)
    • Disables trace logs

      • powershell.exe (PID: 1568)
    • Application based on Golang

      • dasHost.exe (PID: 7408)
    • Found Base64 encoded file access via PowerShell (YARA)

      • dasHost.exe (PID: 7408)
    • Found Base64 encoded access to environment variables via PowerShell (YARA)

      • dasHost.exe (PID: 7408)
    • Detects GO elliptic curve encryption (YARA)

      • dasHost.exe (PID: 7408)
    • Found Base64 encoded access to Windows Defender via PowerShell (YARA)

      • dasHost.exe (PID: 7408)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (41)
.exe | Win64 Executable (generic) (36.3)
.dll | Win32 Dynamic Link Library (generic) (8.6)
.exe | Win32 Executable (generic) (5.9)
.exe | Win16/32 Executable Delphi generic (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 0000:00:00 00:00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 3
CodeSize: 4889088
InitializedDataSize: 342016
UninitializedDataSize: -
EntryPoint: 0x6e610
OSVersion: 6.1
ImageVersion: 1
SubsystemVersion: 6.1
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
160
Monitored processes
12
Malicious processes
6
Suspicious processes
2

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
1568powershell.exeC:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
dasHost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2144"C:\Program Files (x86)\Microsoft\dasHost.exe"C:\Program Files (x86)\Microsoft\dasHost.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\program files (x86)\microsoft\dashost.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\bcryptprimitives.dll
c:\windows\syswow64\winmm.dll
3976\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6084"C:\Program Files (x86)\Microsoft\Edge\Application\dasHost.exe" -C:\Program Files (x86)\Microsoft\Edge\Application\dasHost.exedasHost.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files (x86)\microsoft\edge\application\dashost.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\bcryptprimitives.dll
7172"C:\Program Files\Google\Chrome\Application\dasHost.exe" -C:\Program Files\Google\Chrome\Application\dasHost.exedasHost.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\google\chrome\application\dashost.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\bcryptprimitives.dll
7408"C:\Program Files (x86)\Microsoft\dasHost.exe"C:\Program Files (x86)\Microsoft\dasHost.exe
7b090e06-f3e5-405c-94d5-a1a885f2223d.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\program files (x86)\microsoft\dashost.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\bcryptprimitives.dll
7684"C:\Users\admin\Desktop\7b090e06-f3e5-405c-94d5-a1a885f2223d.exe" C:\Users\admin\Desktop\7b090e06-f3e5-405c-94d5-a1a885f2223d.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
2
Modules
Images
c:\users\admin\desktop\7b090e06-f3e5-405c-94d5-a1a885f2223d.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\bcryptprimitives.dll
7708"C:\Program Files (x86)\Mozilla Maintenance Service\dllhost.exe"C:\Program Files (x86)\Mozilla Maintenance Service\dllhost.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\program files (x86)\mozilla maintenance service\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\bcryptprimitives.dll
7808"C:\WINDOWS\system32\ReAgentc.exe" /disableC:\Windows\SysWOW64\ReAgentc.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Windows Recovery Agent
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\reagentc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
7940"C:\Users\admin\Desktop\7b090e06-f3e5-405c-94d5-a1a885f2223d.exe" C:\Users\admin\Desktop\7b090e06-f3e5-405c-94d5-a1a885f2223d.exe
7b090e06-f3e5-405c-94d5-a1a885f2223d.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\7b090e06-f3e5-405c-94d5-a1a885f2223d.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\bcryptprimitives.dll
Total events
13 906
Read events
13 819
Write events
27
Delete events
60

Modification events

(PID) Process:(7940) 7b090e06-f3e5-405c-94d5-a1a885f2223d.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:StartMenuExperienceHost
Value:
C:\Users\admin\AppData\Local\PlaceholderTileLogoFolder\StartMenuExperienceHost.exe
(PID) Process:(7940) 7b090e06-f3e5-405c-94d5-a1a885f2223d.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:dllhost
Value:
C:\Program Files (x86)\Mozilla Maintenance Service\dllhost.exe
(PID) Process:(7940) 7b090e06-f3e5-405c-94d5-a1a885f2223d.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:dasHost
Value:
C:\Program Files (x86)\Microsoft\dasHost.exe
(PID) Process:(7808) ReAgentc.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:delete keyName:(default)
Value:
(PID) Process:(7808) ReAgentc.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\11000001
Operation:writeName:Element
Value:
0000000000000000000000000000000006000000000000004800000000000000715E5C2FA985EB1190A89A9B763584210000000000000000745E5C2FA985EB1190A89A9B7635842100000000000000000000000000000000
(PID) Process:(7808) ReAgentc.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\12000002
Operation:delete keyName:(default)
Value:
(PID) Process:(7808) ReAgentc.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{9dea862c-5cdd-4e70-acc1-f32b344d4795}\Elements\12000002
Operation:writeName:Element
Value:
\EFI\Microsoft\Boot\bootmgfw.efi
(PID) Process:(7808) ReAgentc.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{872a075f-9aa9-11f0-b4fb-806e6f6e6963}\Elements\11000001
Operation:delete keyName:(default)
Value:
(PID) Process:(7808) ReAgentc.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{872a075f-9aa9-11f0-b4fb-806e6f6e6963}\Elements\11000001
Operation:writeName:Element
Value:
0000000000000000000000000000000006000000000000004800000000000000715E5C2FA985EB1190A89A9B763584210000000000000000745E5C2FA985EB1190A89A9B7635842100000000000000000000000000000000
(PID) Process:(7808) ReAgentc.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{872a075f-9aa9-11f0-b4fb-806e6f6e6963}\Elements\12000002
Operation:delete keyName:(default)
Value:
Executable files
5
Suspicious files
2
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
7808ReAgentc.exeC:\Windows\SysWOW64\Recovery\Winre.wim
MD5:
SHA256:
79407b090e06-f3e5-405c-94d5-a1a885f2223d.exeC:\Users\admin\AppData\Local\PlaceholderTileLogoFolder\StartMenuExperienceHost.exeexecutable
MD5:9A0F1C9E8A79B6F1FC43AC6D2725FC2B
SHA256:12E7D8F52867D8C02718581C4DE46E9B4E76A826140182D43FC9DBDCFA1152DB
79407b090e06-f3e5-405c-94d5-a1a885f2223d.exeC:\Program Files (x86)\Mozilla Maintenance Service\dllhost.exeexecutable
MD5:9A0F1C9E8A79B6F1FC43AC6D2725FC2B
SHA256:12E7D8F52867D8C02718581C4DE46E9B4E76A826140182D43FC9DBDCFA1152DB
1568powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_ni1auq2i.3tr.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
7408dasHost.exeC:\Program Files\Google\Chrome\Application\dasHost.exeexecutable
MD5:9A0F1C9E8A79B6F1FC43AC6D2725FC2B
SHA256:12E7D8F52867D8C02718581C4DE46E9B4E76A826140182D43FC9DBDCFA1152DB
1568powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_w5wec4j1.h3z.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
1568powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_ebqiihab.bcc.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
7408dasHost.exeC:\Program Files (x86)\Microsoft\Edge\Application\dasHost.exeexecutable
MD5:9A0F1C9E8A79B6F1FC43AC6D2725FC2B
SHA256:12E7D8F52867D8C02718581C4DE46E9B4E76A826140182D43FC9DBDCFA1152DB
1568powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_ub1c3nwh.k01.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
79407b090e06-f3e5-405c-94d5-a1a885f2223d.exeC:\Program Files (x86)\Microsoft\dasHost.exeexecutable
MD5:9A0F1C9E8A79B6F1FC43AC6D2725FC2B
SHA256:12E7D8F52867D8C02718581C4DE46E9B4E76A826140182D43FC9DBDCFA1152DB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
71
TCP/UDP connections
55
DNS requests
20
Threats
11

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6768
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
4632
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
6768
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
POST
200
20.190.160.65:443
https://login.live.com/RST2.srf
US
xml
11.1 Kb
unknown
POST
200
20.190.160.65:443
https://login.live.com/RST2.srf
US
xml
10.3 Kb
unknown
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
POST
403
23.210.18.103:443
https://go.microsoft.com/fwlink/?LinkID=2257403&clcid=0x409
NL
html
384 b
unknown
POST
403
23.210.18.103:443
https://go.microsoft.com/fwlink/?LinkID=2257403&clcid=0x409
NL
html
384 b
unknown
816
svchost.exe
POST
200
20.190.160.64:443
https://login.live.com/RST2.srf
US
xml
11.1 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4632
svchost.exe
23.216.77.6:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
6768
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
23.216.77.6:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
4632
svchost.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
6768
MoUsoCoreWorker.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
google.com
  • 216.58.206.78
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
  • 2.16.241.12
  • 2.16.241.19
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
dns.google
  • 8.8.4.4
  • 8.8.8.8
whitelisted
login.live.com
  • 20.190.160.64
  • 40.126.32.138
  • 20.190.160.128
  • 20.190.160.3
  • 20.190.160.131
  • 20.190.160.17
  • 40.126.32.133
  • 20.190.160.2
whitelisted
go.microsoft.com
  • 23.52.181.141
whitelisted
gitlab.com
  • 172.65.251.78
whitelisted
slscr.update.microsoft.com
  • 74.179.77.204
whitelisted

Threats

PID
Process
Class
Message
2292
svchost.exe
Misc activity
INFO [ANY.RUN] Google DNS-over-HTTPS service requested (dns. google)
7940
7b090e06-f3e5-405c-94d5-a1a885f2223d.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/Salatstealer JA3 hash observed
7940
7b090e06-f3e5-405c-94d5-a1a885f2223d.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/Salatstealer JA3 hash observed
7940
7b090e06-f3e5-405c-94d5-a1a885f2223d.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/Salatstealer JA3 hash observed
7940
7b090e06-f3e5-405c-94d5-a1a885f2223d.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Salatstealer related domain (salator .es)
7940
7b090e06-f3e5-405c-94d5-a1a885f2223d.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/Salatstealer JA3 hash observed
7408
dasHost.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/Salatstealer JA3 hash observed
7408
dasHost.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/Salatstealer JA3 hash observed
7408
dasHost.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/Salatstealer JA3 hash observed
7408
dasHost.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/Salatstealer JA3 hash observed
No debug info