| File name: | aws.bat |
| Full analysis: | https://app.any.run/tasks/6116b90a-afc8-4ce1-8440-189062e08b39 |
| Verdict: | Malicious activity |
| Analysis date: | June 07, 2025, 20:58:06 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | text/x-msdos-batch |
| File info: | DOS batch file, ASCII text, with CRLF line terminators |
| MD5: | E6363B058FA5656647FFB629B1A0D660 |
| SHA1: | 9566DFCD444807ECEF6739970F2C387CEDBA391B |
| SHA256: | 22EA1342595396A876B98648F97CF2FF7121D0EDC28C665199D4A46F1FF729A6 |
| SSDEEP: | 12:DHW98XItFHDmDkB+pUqLZvOL5OHk3Y2S2rJkVTxohAvq:0FmHp3LZvI5OCY9ooTPq |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 236 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | ClipUp.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 472 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmdkey.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 536 | "C:\WINDOWS\System32\getmac.exe" | C:\Windows\System32\getmac.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Displays NIC MAC information Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 656 | "C:\WINDOWS\System32\CompPkgSrv.exe" | C:\Windows\System32\CompPkgSrv.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Component Package Support Server Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 660 | "C:\WINDOWS\System32\appidpolicyconverter.exe" | C:\Windows\System32\appidpolicyconverter.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: AppID Policy Converter Task Exit code: 5 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 716 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | AggregatorHost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 856 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | attrib.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 900 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | AppVClient.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 900 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | certreq.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 924 | "C:\WINDOWS\System32\conhost.exe" | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (7420) AppHostRegistrationVerifier.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (7420) AppHostRegistrationVerifier.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (1676) AtBroker.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility |
| Operation: | write | Name: | Configuration |
Value: | |||
| (PID) Process: | (1676) AtBroker.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Session5 |
| Operation: | write | Name: | SecureConfiguration |
Value: | |||
| (PID) Process: | (1676) AtBroker.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility |
| Operation: | write | Name: | NarratorAfterSigninResetCompleted |
Value: 1 | |||
| (PID) Process: | (7420) AppHostRegistrationVerifier.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (7420) AppHostRegistrationVerifier.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe\AppUriHandlers\mediaredirect.microsoft.com |
| Operation: | write | Name: | LastValidationAttemptTime |
Value: 40E0D7E5EED7DB01 | |||
| (PID) Process: | (7420) AppHostRegistrationVerifier.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe\AppUriHandlers\mediaredirect.microsoft.com |
| Operation: | write | Name: | FailedValiationCount |
Value: 2 | |||
| (PID) Process: | (6540) BitLockerWizardElev.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | delete value | Name: | BitLockerWizard |
Value: | |||
| (PID) Process: | (6540) BitLockerWizardElev.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce |
| Operation: | delete value | Name: | BitLockerWizard |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6516 | cleanmgr.exe | C:\Windows\System32\LogFiles\setupcln\setupact.log | — | |
MD5:— | SHA256:— | |||
| 7152 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_aqo4nver.zgs.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 7152 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive | binary | |
MD5:1BA824D040CFBC0DEE352EDB918CC243 | SHA256:3B20FDE2599349018F249FE98CB8AD8F81FF5654955F324E99AA580B1DB99357 | |||
| 7152 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_p31ttklb.y05.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 6516 | cleanmgr.exe | C:\Users\admin\AppData\Local\D3DSCache\d3fe7cdcb51a5ef5\F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.lock | text | |
MD5:F49655F856ACB8884CC0ACE29216F511 | SHA256:7852FCE59C67DDF1D6B8B997EAA1ADFAC004A9F3A91C37295DE9223674011FBA | |||
| 6516 | cleanmgr.exe | C:\Users\admin\AppData\Local\D3DSCache\3534848bb9f4cb71\F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.lock | text | |
MD5:F49655F856ACB8884CC0ACE29216F511 | SHA256:7852FCE59C67DDF1D6B8B997EAA1ADFAC004A9F3A91C37295DE9223674011FBA | |||
| 8580 | unregmp2.exe | C:\Users\admin\AppData\Local\Temp\wmsetup.log | text | |
MD5:789D32CBDF7139D95A665E59C0F6D812 | SHA256:54B2DDD86CC6C58259064965A8664447A94C812676FAB04E958EA09DFC165D3C | |||
| 8820 | dllhost.exe | C:\Windows\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{8A5722A3-207F-4F9E-9393-10E46600F2F9}.crmlog | binary | |
MD5:942963A9503E59E39F33D6CEFD468C41 | SHA256:6CD2A172810F8DFE63720DC990DAACC1CF471BD84F1DD9D9DA8333F9ABCF3E9B | |||
| 9236 | dispdiag.exe | C:\Users\admin\Desktop\DispDiag-20250607-205832-9236-9240.dat | binary | |
MD5:E31A6606A8E228AD6468006A6F79D8C7 | SHA256:8D3A8809CE36491EBB9A1036C46E89DF65E4C9540CC325161CA9CEBEE132D6DB | |||
| 9356 | unregmp2.exe | C:\Users\admin\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.DTD | xml | |
MD5:90BE2701C8112BEBC6BD58A7DE19846E | SHA256:644FBCDC20086E16D57F31C5BAD98BE68D02B1C061938D2F5F91CBE88C871FBF | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | POST | 200 | 2.16.204.136:443 | https://www.bing.com/RelatedSearch?addfeaturesnoexpansion=relatedsearch&mkt=en-US | unknown | binary | 740 b | whitelisted |
— | — | GET | 404 | 104.86.148.134:443 | https://cxcs.microsoft.net/api/settings/en-US/xml/settings-tipset?release=20h1&sku=Professional&platform=desktop | unknown | html | 26 b | whitelisted |
— | — | POST | 200 | 2.16.204.145:443 | https://www.bing.com/RelatedSearch?addfeaturesnoexpansion=relatedsearch&mkt=en-US | unknown | — | — | whitelisted |
— | — | GET | 404 | 104.86.148.134:443 | https://cxcs.microsoft.net/api/settings/en-US/xml/settings-tipset?release=20h1&sku=Professional&platform=desktop | unknown | html | 26 b | whitelisted |
— | — | POST | 404 | 2.16.204.145:443 | https://www.bing.com/RelatedSearch?addfeaturesnoexpansion=relatedsearch&mkt=en-US | unknown | — | — | whitelisted |
— | — | GET | 404 | 104.86.148.134:443 | https://cxcs.microsoft.net/api/settings/en-US/xml/settings-tipset?release=20h1&sku=Professional&platform=desktop | unknown | html | 26 b | whitelisted |
— | — | POST | 500 | 40.91.76.224:443 | https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail | unknown | xml | 512 b | whitelisted |
— | — | GET | 200 | 23.48.23.195:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1660 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4156 | SystemSettings.exe | 2.16.204.136:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
4156 | SystemSettings.exe | 104.86.148.134:443 | cxcs.microsoft.net | AKAMAI-AS | DE | whitelisted |
8968 | DeviceCensus.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3812 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
2196 | svchost.exe | 224.0.0.251:5353 | — | — | — | unknown |
3012 | dasHost.exe | 239.255.255.250:3702 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
mediaredirect.microsoft.com |
| whitelisted |
cxcs.microsoft.net |
| whitelisted |
www.bing.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |