File name:

aws.bat

Full analysis: https://app.any.run/tasks/6116b90a-afc8-4ce1-8440-189062e08b39
Verdict: Malicious activity
Analysis date: June 07, 2025, 20:58:06
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
uac
Indicators:
MIME: text/x-msdos-batch
File info: DOS batch file, ASCII text, with CRLF line terminators
MD5:

E6363B058FA5656647FFB629B1A0D660

SHA1:

9566DFCD444807ECEF6739970F2C387CEDBA391B

SHA256:

22EA1342595396A876B98648F97CF2FF7121D0EDC28C665199D4A46F1FF729A6

SSDEEP:

12:DHW98XItFHDmDkB+pUqLZvOL5OHk3Y2S2rJkVTxohAvq:0FmHp3LZvI5OCY9ooTPq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Bypass User Account Control (ComputerDefaults)

      • ComputerDefaults.exe (PID: 7804)
    • Execute application with conhost.exe as parent process

      • cmd.exe (PID: 1132)
    • Bypass User Account Control (fodhelper)

      • fodhelper.exe (PID: 10480)
  • SUSPICIOUS

    • Starts POWERSHELL.EXE for commands execution

      • cmd.exe (PID: 2616)
    • The process bypasses the loading of PowerShell profile settings

      • cmd.exe (PID: 2616)
    • Uses ATTRIB.EXE to modify file attributes

      • cmd.exe (PID: 2616)
    • Uses ICACLS.EXE to modify access control lists

      • cmd.exe (PID: 2616)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 2616)
      • conhost.exe (PID: 924)
      • forfiles.exe (PID: 10676)
    • Application launched itself

      • cmd.exe (PID: 2616)
      • ClipUp.exe (PID: 7728)
    • Executes as Windows Service

      • msdtc.exe (PID: 9692)
      • dllhost.exe (PID: 8820)
      • vds.exe (PID: 8292)
      • FXSSVC.exe (PID: 11288)
    • Uses DRIVERQUERY.EXE to obtain a list of installed device drivers

      • cmd.exe (PID: 2616)
    • Using 'findstr.exe' to search for text patterns in files and output

      • cmd.exe (PID: 2616)
    • Executes application which crashes

      • hvix64.exe (PID: 11648)
      • hvax64.exe (PID: 11604)
    • Process uses IPCONFIG to get network configuration information

      • cmd.exe (PID: 2616)
    • Searches and executes a command on selected files

      • forfiles.exe (PID: 10676)
    • Executing commands from a ".bat" file

      • forfiles.exe (PID: 10676)
  • INFO

    • Reads the computer name

      • agentactivationruntimestarter.exe (PID: 7376)
    • Checks proxy server information

      • AppHostRegistrationVerifier.exe (PID: 7420)
    • Checks supported languages

      • appidtel.exe (PID: 7000)
      • agentactivationruntimestarter.exe (PID: 7376)
      • AggregatorHost.exe (PID: 4180)
      • DataStoreCacheDumpTool.exe (PID: 4980)
      • curl.exe (PID: 5304)
    • Reads security settings of Internet Explorer

      • AppHostRegistrationVerifier.exe (PID: 7420)
      • OpenWith.exe (PID: 7152)
      • calc.exe (PID: 6840)
      • certreq.exe (PID: 8104)
      • cleanmgr.exe (PID: 6516)
      • ComputerDefaults.exe (PID: 7804)
      • mmc.exe (PID: 1676)
      • CompMgmtLauncher.exe (PID: 7304)
    • Uses BITSADMIN.EXE

      • cmd.exe (PID: 2616)
    • Disables trace logs

      • cmdl32.exe (PID: 7804)
      • cmmon32.exe (PID: 5548)
      • cmstp.exe (PID: 1672)
    • Create files in a temporary directory

      • ClipUp.exe (PID: 5416)
    • Execution of CURL command

      • cmd.exe (PID: 2616)
    • Displays MAC addresses of computer network adapters

      • getmac.exe (PID: 536)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
638
Monitored processes
456
Malicious processes
3
Suspicious processes
3

Behavior graph

Click at the process to see the details
start cmd.exe no specs conhost.exe no specs powershell.exe no specs agentactivationruntimestarter.exe no specs agentservice.exe no specs aggregatorhost.exe no specs aitstatic.exe no specs alg.exe no specs conhost.exe no specs apphostregistrationverifier.exe no specs appidcertstorecheck.exe no specs conhost.exe no specs appidpolicyconverter.exe no specs appidtel.exe no specs applicationframehost.exe no specs applysettingstemplatecatalog.exe no specs conhost.exe no specs applytrustoffline.exe no specs conhost.exe no specs approvechildrequest.exe no specs conhost.exe no specs appvclient.exe no specs appvdllsurrogate.exe no specs appvnice.exe no specs appvshnotify.exe no specs appvstreamingux.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs arp.exe no specs conhost.exe no specs assignedaccessguard.exe no specs at.exe no specs atbroker.exe no specs attrib.exe no specs conhost.exe no specs conhost.exe no specs audiodg.exe no specs conhost.exe no specs auditpol.exe no specs authhost.exe no specs autochk.exe no specs conhost.exe no specs autoconv.exe no specs autofmt.exe no specs axinstui.exe no specs baaupdate.exe no specs backgroundtaskhost.exe no specs backgroundtransferhost.exe no specs bcdboot.exe no specs conhost.exe no specs bcdedit.exe no specs conhost.exe no specs bdechangepin.exe no specs bdehdcfg.exe no specs conhost.exe no specs bdeuisrv.exe no specs bdeunlock.exe no specs bioiso.exe no specs bitlockerdeviceencryption.exe no specs bitlockerdeviceencryption.exe no specs bitlockerdeviceencryption.exe bitlockerwizard.exe no specs bitlockerwizardelev.exe no specs bitlockerwizardelev.exe no specs bitlockerwizardelev.exe bitsadmin.exe no specs bootcfg.exe no specs bootim.exe no specs conhost.exe no specs conhost.exe no specs bootsect.exe no specs bridgeunattend.exe no specs conhost.exe no specs browserexport.exe no specs conhost.exe no specs browser_broker.exe no specs bthudtask.exe no specs bthudtask.exe no specs bthudtask.exe bytecodegenerator.exe no specs conhost.exe no specs conhost.exe no specs cacls.exe no specs conhost.exe no specs calc.exe no specs camerasettingsuihost.exe no specs castsrv.exe no specs certenrollctrl.exe no specs certreq.exe no specs certutil.exe no specs change.exe no specs conhost.exe no specs changepk.exe no specs conhost.exe no specs conhost.exe no specs changepk.exe no specs openwith.exe no specs changepk.exe charmap.exe no specs checknetisolation.exe no specs chglogon.exe no specs chgport.exe no specs conhost.exe no specs chgusr.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs chkdsk.exe no specs conhost.exe no specs chkntfs.exe no specs conhost.exe no specs choice.exe no specs conhost.exe no specs cidiag.exe no specs conhost.exe no specs cipher.exe no specs cleanmgr.exe no specs conhost.exe no specs cliconfg.exe no specs cliconfg.exe no specs cliconfg.exe clip.exe no specs conhost.exe no specs cliprenew.exe no specs clipup.exe no specs cloudexperiencehostbroker.exe no specs conhost.exe no specs cloudnotifications.exe no specs cmd.exe no specs cmdkey.exe no specs cmdl32.exe no specs conhost.exe no specs cmmon32.exe no specs cmstp.exe no specs cofire.exe no specs conhost.exe no specs colorcpl.exe no specs comp.exe no specs conhost.exe no specs compact.exe no specs conhost.exe no specs compattelrunner.exe no specs conhost.exe no specs compmgmtlauncher.exe no specs conhost.exe no specs comppkgsrv.exe no specs computerdefaults.exe no specs computerdefaults.exe no specs clipup.exe no specs conhost.exe no specs computerdefaults.exe conhost.exe no specs consent.exe no specs cmd.exe no specs control.exe no specs convert.exe no specs convertvhd.exe no specs conhost.exe no specs coredpussvr.exe no specs credentialenrollmentmanager.exe no specs credentialuibroker.exe no specs credwiz.exe no specs cscript.exe no specs conhost.exe no specs csrss.exe no specs ctfmon.exe no specs mmc.exe no specs explorer.exe no specs ctfmon.exe no specs ctfmon.exe cttune.exe no specs cttunesvr.exe no specs curl.exe no specs conhost.exe no specs custominstallexec.exe no specs customshellhost.exe no specs dashost.exe no specs dataexchangehost.exe no specs mmc.exe conhost.exe no specs datastorecachedumptool.exe no specs conhost.exe no specs datausagelivetiletask.exe no specs dccw.exe no specs explorer.exe no specs dccw.exe no specs COpenControlPanel no specs dccw.exe dcomcnfg.exe no specs dcomcnfg.exe no specs dcomcnfg.exe mmc.exe no specs ddodiag.exe no specs defrag.exe no specs deploymentcsphelper.exe no specs conhost.exe no specs desktopimgdownldr.exe no specs conhost.exe no specs devicecensus.exe devicecredentialdeployment.exe no specs conhost.exe no specs deviceeject.exe no specs deviceeject.exe no specs deviceeject.exe deviceenroller.exe no specs devicepairingwizard.exe no specs deviceproperties.exe no specs deviceproperties.exe no specs deviceproperties.exe dfdwiz.exe no specs dfrgui.exe no specs dialer.exe no specs directxdatabaseupdater.exe no specs diskpart.exe no specs diskpart.exe no specs dllhost.exe no specs diskpart.exe conhost.exe no specs diskperf.exe no specs conhost.exe no specs diskraid.exe no specs diskraid.exe no specs vdsldr.exe no specs vds.exe no specs diskraid.exe conhost.exe no specs disksnapshot.exe no specs conhost.exe no specs dism.exe no specs dispdiag.exe no specs conhost.exe no specs displayswitch.exe no specs conhost.exe no specs djoin.exe no specs dllhost.exe no specs conhost.exe no specs dllhst3g.exe no specs dmcertinst.exe no specs dmcfghost.exe no specs dmclient.exe no specs conhost.exe no specs dmnotificationbroker.exe no specs msdtc.exe no specs dmomacpmo.exe no specs dnscacheugc.exe no specs doskey.exe no specs conhost.exe no specs conhost.exe no specs dpapimig.exe no specs dpiscaling.exe no specs driverquery.exe no specs conhost.exe no specs drvinst.exe no specs dsmusertask.exe no specs conhost.exe no specs dsregcmd.exe no specs conhost.exe no specs dstokenclean.exe no specs conhost.exe no specs dtuhandler.exe no specs dusmtask.exe no specs dvdplay.exe no specs dwm.exe no specs wmplayer.exe no specs explorer.exe no specs dwwin.exe no specs dxdiag.exe no specs dxgiadaptercache.exe no specs dxpserver.exe no specs eap3host.exe no specs easeofaccessdialog.exe no specs setup_wm.exe no specs unregmp2.exe no specs easeofaccessdialog.exe no specs explorer.exe no specs shellexperiencehost.exe no specs unregmp2.exe no specs easeofaccessdialog.exe easinvoker.exe no specs easinvoker.exe no specs easinvoker.exe easpolicymanagerbrokerhost.exe no specs easpolicymanagerbrokerhost.exe no specs easpolicymanagerbrokerhost.exe edpcleanup.exe no specs edpnotify.exe no specs eduprintprov.exe no specs efsui.exe no specs ehstorauthn.exe no specs em.exe no specs eoaexperiences.exe no specs conhost.exe no specs eoaexperiences.exe no specs eoaexperiences.exe esentutl.exe no specs eudcedit.exe no specs conhost.exe no specs eudcedit.exe no specs eudcedit.exe eventcreate.exe no specs conhost.exe no specs eventvwr.exe no specs eventvwr.exe no specs eventvwr.exe expand.exe no specs mmc.exe no specs conhost.exe no specs extrac32.exe no specs fc.exe no specs conhost.exe no specs fclip.exe no specs fhmanagew.exe no specs filehistory.exe no specs find.exe no specs conhost.exe no specs findstr.exe no specs finger.exe no specs conhost.exe no specs fixmapi.exe no specs fltmc.exe no specs conhost.exe no specs conhost.exe no specs fodhelper.exe no specs fodhelper.exe no specs fodhelper.exe fondue.exe no specs fontdrvhost.exe no specs fontview.exe no specs forfiles.exe no specs fsavailux.exe no specs conhost.exe no specs fsavailux.exe no specs cmd.exe no specs fsavailux.exe fsiso.exe no specs fsquirt.exe no specs cmd.exe no specs fsutil.exe no specs ftp.exe no specs conhost.exe no specs conhost.exe no specs fvenotify.exe no specs fveprompt.exe no specs cmd.exe no specs fxscover.exe no specs fxssvc.exe no specs fxsunatd.exe no specs conhost.exe no specs fxsunatd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs fxsunatd.exe conhost.exe no specs cmd.exe no specs gamebarpresencewriter.exe no specs cmd.exe no specs gameinputsvc.exe no specs gamepanel.exe no specs genvalobj.exe no specs getmac.exe no specs cmd.exe no specs conhost.exe no specs gpresult.exe no specs gpscript.exe no specs conhost.exe no specs gpupdate.exe no specs grpconv.exe no specs conhost.exe no specs hdwwiz.exe no specs hdwwiz.exe no specs cmd.exe no specs fxssvc.exe no specs hdwwiz.exe help.exe no specs hostname.exe no specs conhost.exe no specs hvax64.exe conhost.exe no specs conhost.exe no specs hvix64.exe hvsievaluator.exe no specs conhost.exe no specs icacls.exe no specs conhost.exe no specs conhost.exe no specs icsentitlementhost.exe no specs conhost.exe no specs icsunattend.exe no specs ie4uinit.exe no specs conhost.exe no specs ie4ushowie.exe no specs iesettingsync.exe no specs ieunatt.exe no specs iexpress.exe no specs conhost.exe no specs immersivetpmvscmgrsvr.exe no specs immersivetpmvscmgrsvr.exe no specs werfault.exe no specs tiworker.exe no specs immersivetpmvscmgrsvr.exe infdefaultinstall.exe no specs infdefaultinstall.exe no specs werfault.exe no specs Delivery Optimization Managment no specs infdefaultinstall.exe inputswitchtoasthandler.exe no specs iotstartup.exe no specs conhost.exe no specs conhost.exe no specs ipconfig.exe no specs conhost.exe no specs iscsicli.exe no specs iscsicli.exe no specs iscsicli.exe conhost.exe no specs iscsicpl.exe no specs iscsicpl.exe no specs iscsicpl.exe isoburn.exe no specs klist.exe no specs ksetup.exe no specs conhost.exe no specs conhost.exe no specs ktmutil.exe no specs conhost.exe no specs label.exe no specs languagecomponentsinstallercomhandler.exe no specs conhost.exe no specs launchtm.exe no specs launchwinapp.exe no specs legacynetuxhost.exe no specs licensemanagershellext.exe no specs licensingdiag.exe no specs licensingui.exe no specs conhost.exe no specs locationnotificationwindows.exe no specs locator.exe no specs taskmgr.exe no specs lockapphost.exe no specs conhost.exe no specs lockscreencontentserver.exe no specs lodctr.exe no specs logagent.exe no specs conhost.exe no specs logman.exe no specs logoff.exe no specs conhost.exe no specs logonui.exe no specs conhost.exe no specs lpkinstall.exe no specs lpkinstall.exe no specs taskmgr.exe

Process information

PID
CMD
Path
Indicators
Parent process
236\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeClipUp.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
472\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmdkey.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
536"C:\WINDOWS\System32\getmac.exe" C:\Windows\System32\getmac.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Displays NIC MAC information
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\getmac.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
656"C:\WINDOWS\System32\CompPkgSrv.exe" C:\Windows\System32\CompPkgSrv.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Component Package Support Server
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\comppkgsrv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
660"C:\WINDOWS\System32\appidpolicyconverter.exe" C:\Windows\System32\appidpolicyconverter.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
AppID Policy Converter Task
Exit code:
5
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\appidpolicyconverter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
716\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeAggregatorHost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
856\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeattrib.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
900\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeAppVClient.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
900\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execertreq.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
924"C:\WINDOWS\System32\conhost.exe" C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
61 392
Read events
61 098
Write events
278
Delete events
16

Modification events

(PID) Process:(7420) AppHostRegistrationVerifier.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7420) AppHostRegistrationVerifier.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1676) AtBroker.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility
Operation:writeName:Configuration
Value:
(PID) Process:(1676) AtBroker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility\Session5
Operation:writeName:SecureConfiguration
Value:
(PID) Process:(1676) AtBroker.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Accessibility
Operation:writeName:NarratorAfterSigninResetCompleted
Value:
1
(PID) Process:(7420) AppHostRegistrationVerifier.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7420) AppHostRegistrationVerifier.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe\AppUriHandlers\mediaredirect.microsoft.com
Operation:writeName:LastValidationAttemptTime
Value:
40E0D7E5EED7DB01
(PID) Process:(7420) AppHostRegistrationVerifier.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppModel\SystemAppData\Microsoft.ZuneMusic_8wekyb3d8bbwe\AppUriHandlers\mediaredirect.microsoft.com
Operation:writeName:FailedValiationCount
Value:
2
(PID) Process:(6540) BitLockerWizardElev.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:BitLockerWizard
Value:
(PID) Process:(6540) BitLockerWizardElev.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Operation:delete valueName:BitLockerWizard
Value:
Executable files
1
Suspicious files
13
Text files
22
Unknown types
0

Dropped files

PID
Process
Filename
Type
6516cleanmgr.exeC:\Windows\System32\LogFiles\setupcln\setupact.log
MD5:
SHA256:
7152powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_aqo4nver.zgs.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
7152powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivebinary
MD5:1BA824D040CFBC0DEE352EDB918CC243
SHA256:3B20FDE2599349018F249FE98CB8AD8F81FF5654955F324E99AA580B1DB99357
7152powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_p31ttklb.y05.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
6516cleanmgr.exeC:\Users\admin\AppData\Local\D3DSCache\d3fe7cdcb51a5ef5\F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.locktext
MD5:F49655F856ACB8884CC0ACE29216F511
SHA256:7852FCE59C67DDF1D6B8B997EAA1ADFAC004A9F3A91C37295DE9223674011FBA
6516cleanmgr.exeC:\Users\admin\AppData\Local\D3DSCache\3534848bb9f4cb71\F4EB2D6C-ED2B-4BDD-AD9D-F913287E6768.locktext
MD5:F49655F856ACB8884CC0ACE29216F511
SHA256:7852FCE59C67DDF1D6B8B997EAA1ADFAC004A9F3A91C37295DE9223674011FBA
8580unregmp2.exeC:\Users\admin\AppData\Local\Temp\wmsetup.logtext
MD5:789D32CBDF7139D95A665E59C0F6D812
SHA256:54B2DDD86CC6C58259064965A8664447A94C812676FAB04E958EA09DFC165D3C
8820dllhost.exeC:\Windows\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{8A5722A3-207F-4F9E-9393-10E46600F2F9}.crmlogbinary
MD5:942963A9503E59E39F33D6CEFD468C41
SHA256:6CD2A172810F8DFE63720DC990DAACC1CF471BD84F1DD9D9DA8333F9ABCF3E9B
9236dispdiag.exeC:\Users\admin\Desktop\DispDiag-20250607-205832-9236-9240.datbinary
MD5:E31A6606A8E228AD6468006A6F79D8C7
SHA256:8D3A8809CE36491EBB9A1036C46E89DF65E4C9540CC325161CA9CEBEE132D6DB
9356unregmp2.exeC:\Users\admin\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.DTDxml
MD5:90BE2701C8112BEBC6BD58A7DE19846E
SHA256:644FBCDC20086E16D57F31C5BAD98BE68D02B1C061938D2F5F91CBE88C871FBF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
32
DNS requests
12
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
POST
200
2.16.204.136:443
https://www.bing.com/RelatedSearch?addfeaturesnoexpansion=relatedsearch&mkt=en-US
unknown
binary
740 b
whitelisted
GET
404
104.86.148.134:443
https://cxcs.microsoft.net/api/settings/en-US/xml/settings-tipset?release=20h1&sku=Professional&platform=desktop
unknown
html
26 b
whitelisted
POST
200
2.16.204.145:443
https://www.bing.com/RelatedSearch?addfeaturesnoexpansion=relatedsearch&mkt=en-US
unknown
whitelisted
GET
404
104.86.148.134:443
https://cxcs.microsoft.net/api/settings/en-US/xml/settings-tipset?release=20h1&sku=Professional&platform=desktop
unknown
html
26 b
whitelisted
POST
404
2.16.204.145:443
https://www.bing.com/RelatedSearch?addfeaturesnoexpansion=relatedsearch&mkt=en-US
unknown
whitelisted
GET
404
104.86.148.134:443
https://cxcs.microsoft.net/api/settings/en-US/xml/settings-tipset?release=20h1&sku=Professional&platform=desktop
unknown
html
26 b
whitelisted
POST
500
40.91.76.224:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
unknown
xml
512 b
whitelisted
GET
200
23.48.23.195:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1660
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4156
SystemSettings.exe
2.16.204.136:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4156
SystemSettings.exe
104.86.148.134:443
cxcs.microsoft.net
AKAMAI-AS
DE
whitelisted
8968
DeviceCensus.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3812
svchost.exe
239.255.255.250:1900
whitelisted
2196
svchost.exe
224.0.0.251:5353
unknown
3012
dasHost.exe
239.255.255.250:3702
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.174
whitelisted
mediaredirect.microsoft.com
whitelisted
cxcs.microsoft.net
  • 104.86.148.134
whitelisted
www.bing.com
  • 2.16.204.136
  • 2.16.204.137
  • 2.16.204.141
  • 2.16.204.142
  • 2.16.204.158
  • 2.16.204.153
  • 2.16.204.161
  • 2.16.204.143
  • 2.16.204.134
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted
crl.microsoft.com
  • 23.48.23.195
  • 23.48.23.136
  • 23.48.23.135
  • 23.48.23.146
  • 23.48.23.191
  • 23.48.23.148
  • 23.48.23.137
  • 23.48.23.192
  • 23.48.23.138
whitelisted
www.microsoft.com
  • 2.23.181.156
whitelisted
self.events.data.microsoft.com
  • 20.189.173.14
whitelisted

Threats

No threats detected
No debug info