File name:

if.ps1

Full analysis: https://app.any.run/tasks/89f60cd1-d4ff-4fa1-9e0c-dcde4b1241d8
Verdict: Malicious activity
Threats:

Crypto mining malware is a resource-intensive threat that infiltrates computers with the purpose of mining cryptocurrencies. This type of threat can be deployed either on an infected machine or a compromised website. In both cases the miner will utilize the computing power of the device and its network bandwidth.

Analysis date: May 30, 2020, 12:06:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
trojan
miner
lemon_duck
Indicators:
MIME: text/plain
File info: ASCII text, with very long lines, with CRLF line terminators
MD5:

28B80843B13FAB0986479B54310C8053

SHA1:

1D69F9ED65A20CF37B2BD8ABED676A2306F455D8

SHA256:

2520779DBAA8EEBFDE61AA4193BF75A44A89F8A7A8DCCE12072F7FEA1956B53D

SSDEEP:

6144:znABB6Q4u7Nk2CgafwxWoFkkD82JjR2CyYGPzaX61ER4BqA0sTXzSU+CHpzembkn:znUl4sK2CfEBd2uX6+iqQzf+CHp/bG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Starts Visual C# compiler

      • powershell.exe (PID: 2788)
      • powershell.exe (PID: 2960)
    • Loads the Task Scheduler COM API

      • schtasks.exe (PID: 3016)
      • schtasks.exe (PID: 2500)
      • schtasks.exe (PID: 2832)
      • schtasks.exe (PID: 2652)
      • schtasks.exe (PID: 2976)
      • schtasks.exe (PID: 3556)
      • schtasks.exe (PID: 3844)
      • schtasks.exe (PID: 2940)
      • schtasks.exe (PID: 3360)
      • schtasks.exe (PID: 3424)
      • schtasks.exe (PID: 3464)
      • schtasks.exe (PID: 4076)
      • schtasks.exe (PID: 2076)
      • schtasks.exe (PID: 3180)
      • schtasks.exe (PID: 2432)
      • schtasks.exe (PID: 3252)
      • schtasks.exe (PID: 2388)
      • schtasks.exe (PID: 2664)
      • schtasks.exe (PID: 3336)
      • schtasks.exe (PID: 3636)
      • schtasks.exe (PID: 2380)
      • schtasks.exe (PID: 2420)
      • schtasks.exe (PID: 2416)
      • schtasks.exe (PID: 3004)
      • schtasks.exe (PID: 2560)
      • schtasks.exe (PID: 2576)
      • schtasks.exe (PID: 3708)
      • schtasks.exe (PID: 2372)
      • schtasks.exe (PID: 3216)
      • schtasks.exe (PID: 3412)
      • schtasks.exe (PID: 2376)
      • schtasks.exe (PID: 2528)
      • schtasks.exe (PID: 3108)
      • schtasks.exe (PID: 3164)
      • schtasks.exe (PID: 3936)
      • schtasks.exe (PID: 3400)
      • schtasks.exe (PID: 2532)
      • schtasks.exe (PID: 3848)
      • schtasks.exe (PID: 3144)
      • schtasks.exe (PID: 2280)
      • schtasks.exe (PID: 3136)
      • schtasks.exe (PID: 3268)
      • schtasks.exe (PID: 3480)
      • schtasks.exe (PID: 2936)
      • schtasks.exe (PID: 3272)
      • schtasks.exe (PID: 2260)
      • schtasks.exe (PID: 3276)
      • schtasks.exe (PID: 2628)
      • schtasks.exe (PID: 1660)
      • schtasks.exe (PID: 2632)
      • schtasks.exe (PID: 3816)
      • schtasks.exe (PID: 3172)
      • schtasks.exe (PID: 1404)
      • schtasks.exe (PID: 3464)
      • schtasks.exe (PID: 3996)
      • schtasks.exe (PID: 3568)
      • schtasks.exe (PID: 2488)
      • schtasks.exe (PID: 2608)
      • schtasks.exe (PID: 2272)
      • schtasks.exe (PID: 780)
      • schtasks.exe (PID: 892)
      • schtasks.exe (PID: 2520)
      • schtasks.exe (PID: 3052)
      • schtasks.exe (PID: 3168)
      • schtasks.exe (PID: 3884)
      • schtasks.exe (PID: 1404)
      • schtasks.exe (PID: 2428)
      • schtasks.exe (PID: 3932)
      • schtasks.exe (PID: 2128)
      • schtasks.exe (PID: 2476)
      • schtasks.exe (PID: 892)
      • schtasks.exe (PID: 1452)
      • schtasks.exe (PID: 3772)
      • schtasks.exe (PID: 2016)
      • schtasks.exe (PID: 180)
      • schtasks.exe (PID: 308)
      • schtasks.exe (PID: 2188)
      • schtasks.exe (PID: 2248)
      • schtasks.exe (PID: 3908)
      • schtasks.exe (PID: 3352)
      • schtasks.exe (PID: 3296)
      • schtasks.exe (PID: 2432)
      • schtasks.exe (PID: 1448)
      • schtasks.exe (PID: 288)
      • schtasks.exe (PID: 532)
      • schtasks.exe (PID: 3680)
      • schtasks.exe (PID: 2836)
      • schtasks.exe (PID: 2384)
      • schtasks.exe (PID: 2128)
      • schtasks.exe (PID: 2704)
      • schtasks.exe (PID: 3476)
      • schtasks.exe (PID: 2084)
      • schtasks.exe (PID: 3556)
      • schtasks.exe (PID: 536)
      • schtasks.exe (PID: 3228)
      • schtasks.exe (PID: 3276)
      • schtasks.exe (PID: 876)
      • schtasks.exe (PID: 1452)
      • schtasks.exe (PID: 3772)
      • schtasks.exe (PID: 3788)
      • schtasks.exe (PID: 372)
      • schtasks.exe (PID: 556)
      • schtasks.exe (PID: 2732)
      • schtasks.exe (PID: 3424)
      • schtasks.exe (PID: 2296)
      • schtasks.exe (PID: 2504)
      • schtasks.exe (PID: 2860)
      • schtasks.exe (PID: 2312)
      • schtasks.exe (PID: 4000)
      • schtasks.exe (PID: 572)
      • schtasks.exe (PID: 2072)
      • schtasks.exe (PID: 3384)
      • schtasks.exe (PID: 2536)
      • schtasks.exe (PID: 3720)
      • schtasks.exe (PID: 2616)
      • schtasks.exe (PID: 3404)
      • schtasks.exe (PID: 1884)
      • schtasks.exe (PID: 2160)
      • schtasks.exe (PID: 3836)
      • schtasks.exe (PID: 3844)
      • schtasks.exe (PID: 3364)
      • schtasks.exe (PID: 4016)
      • schtasks.exe (PID: 3244)
      • schtasks.exe (PID: 972)
      • schtasks.exe (PID: 3928)
      • schtasks.exe (PID: 1472)
      • schtasks.exe (PID: 2084)
      • schtasks.exe (PID: 2408)
      • schtasks.exe (PID: 4008)
      • schtasks.exe (PID: 3684)
      • schtasks.exe (PID: 3220)
      • schtasks.exe (PID: 3256)
      • schtasks.exe (PID: 2440)
      • schtasks.exe (PID: 3432)
      • schtasks.exe (PID: 948)
      • schtasks.exe (PID: 3820)
      • schtasks.exe (PID: 3704)
      • schtasks.exe (PID: 3140)
      • schtasks.exe (PID: 3680)
      • schtasks.exe (PID: 2440)
      • schtasks.exe (PID: 984)
      • schtasks.exe (PID: 444)
      • schtasks.exe (PID: 3068)
      • schtasks.exe (PID: 2872)
      • schtasks.exe (PID: 4024)
      • schtasks.exe (PID: 3876)
      • schtasks.exe (PID: 2672)
      • schtasks.exe (PID: 3256)
      • schtasks.exe (PID: 2324)
      • schtasks.exe (PID: 2644)
      • schtasks.exe (PID: 3124)
      • schtasks.exe (PID: 3152)
      • schtasks.exe (PID: 2860)
      • schtasks.exe (PID: 2148)
      • schtasks.exe (PID: 4056)
      • schtasks.exe (PID: 1468)
      • schtasks.exe (PID: 680)
      • schtasks.exe (PID: 3352)
      • schtasks.exe (PID: 1616)
      • schtasks.exe (PID: 3780)
      • schtasks.exe (PID: 4012)
      • schtasks.exe (PID: 2992)
      • schtasks.exe (PID: 2672)
      • schtasks.exe (PID: 3612)
      • schtasks.exe (PID: 4020)
      • schtasks.exe (PID: 944)
      • schtasks.exe (PID: 1476)
      • schtasks.exe (PID: 3968)
      • schtasks.exe (PID: 1888)
      • schtasks.exe (PID: 1848)
      • schtasks.exe (PID: 948)
      • schtasks.exe (PID: 2972)
      • schtasks.exe (PID: 748)
      • schtasks.exe (PID: 2408)
      • schtasks.exe (PID: 1728)
      • schtasks.exe (PID: 3348)
      • schtasks.exe (PID: 4028)
      • schtasks.exe (PID: 180)
      • schtasks.exe (PID: 3204)
      • schtasks.exe (PID: 3500)
      • schtasks.exe (PID: 2768)
      • schtasks.exe (PID: 2368)
      • schtasks.exe (PID: 3200)
      • schtasks.exe (PID: 2804)
      • schtasks.exe (PID: 3988)
      • schtasks.exe (PID: 1656)
      • schtasks.exe (PID: 3716)
      • schtasks.exe (PID: 1664)
      • schtasks.exe (PID: 3828)
      • schtasks.exe (PID: 2372)
      • schtasks.exe (PID: 2856)
      • schtasks.exe (PID: 3428)
      • schtasks.exe (PID: 4016)
      • schtasks.exe (PID: 1016)
      • schtasks.exe (PID: 2068)
    • LEMON_DUCK was detected

      • powershell.exe (PID: 2788)
    • Uses Task Scheduler to run other applications

      • powershell.exe (PID: 3540)
  • SUSPICIOUS

    • Application launched itself

      • powershell.exe (PID: 2788)
    • Executes PowerShell scripts

      • powershell.exe (PID: 2788)
    • Creates files in the user directory

      • powershell.exe (PID: 2960)
      • powershell.exe (PID: 2788)
      • powershell.exe (PID: 3540)
    • PowerShell script executed

      • powershell.exe (PID: 2788)
    • Starts SC.EXE for service management

      • powershell.exe (PID: 3540)
    • Executable content was dropped or overwritten

      • powershell.exe (PID: 2788)
    • Uses NETSTAT.EXE to discover network connections

      • powershell.exe (PID: 3540)
      • powershell.exe (PID: 2788)
    • Uses IPCONFIG.EXE to discover IP address

      • powershell.exe (PID: 2788)
  • INFO

    • Reads settings of System Certificates

      • powershell.exe (PID: 2788)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
1 020
Monitored processes
983
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #LEMON_DUCK powershell.exe csc.exe cvtres.exe no specs csc.exe cvtres.exe no specs powershell.exe powershell.exe csc.exe cvtres.exe no specs csc.exe cvtres.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs netstat.exe no specs taskmgr.exe no specs ipconfig.exe no specs ipconfig.exe no specs netstat.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs netstat.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs netstat.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs sc.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs netstat.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
180"C:\Windows\system32\schtasks.exe" /Delete /TN Update_windows /FC:\Windows\system32\schtasks.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
180"C:\Windows\system32\schtasks.exe" /Delete /TN "Microsoft Telemetry" /FC:\Windows\system32\schtasks.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskschd.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\kernelbase.dll
252"C:\Windows\system32\sc.exe" Config Microsoft Start= DisabledC:\Windows\system32\sc.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
A tool to aid in developing services for WindowsNT
Exit code:
1060
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
252"C:\Windows\system32\sc.exe" Stop WmdnPnSNC:\Windows\system32\sc.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
A tool to aid in developing services for WindowsNT
Exit code:
1060
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\sc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
276"C:\Windows\system32\sc.exe" Stop "Sncryption Media Playeq"C:\Windows\system32\sc.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
A tool to aid in developing services for WindowsNT
Exit code:
1060
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
280"C:\Windows\system32\sc.exe" Stop XtfyaC:\Windows\system32\sc.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
A tool to aid in developing services for WindowsNT
Exit code:
1060
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
288"C:\Windows\system32\sc.exe" Stop WinHasdadelp32C:\Windows\system32\sc.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
A tool to aid in developing services for WindowsNT
Exit code:
1060
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
288"C:\Windows\system32\schtasks.exe" /Delete /TN IIS /FC:\Windows\system32\schtasks.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\sc.exe
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
308"C:\Windows\system32\sc.exe" Stop NationalC:\Windows\system32\sc.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
A tool to aid in developing services for WindowsNT
Exit code:
1060
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskschd.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msctf.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\kernelbase.dll
308"C:\Windows\system32\schtasks.exe" /Delete /TN WindowsUpdate2 /FC:\Windows\system32\schtasks.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
Total events
874
Read events
674
Write events
200
Delete events
0

Modification events

(PID) Process:(2788) powershell.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2788) powershell.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2788) powershell.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2960) powershell.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3540) powershell.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2788) powershell.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2788) powershell.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2788) powershell.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(2788) powershell.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
4294901760
(PID) Process:(2788) powershell.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\powershell_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
Executable files
1
Suspicious files
11
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
2788powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\3521JOPM7RRP3P92W2X3.temp
MD5:
SHA256:
3996csc.exeC:\Users\admin\AppData\Local\Temp\CSC32A2.tmp
MD5:
SHA256:
3996csc.exeC:\Users\admin\AppData\Local\Temp\onzvtr2g.pdb
MD5:
SHA256:
2884cvtres.exeC:\Users\admin\AppData\Local\Temp\RES32A3.tmp
MD5:
SHA256:
3996csc.exeC:\Users\admin\AppData\Local\Temp\onzvtr2g.dll
MD5:
SHA256:
3996csc.exeC:\Users\admin\AppData\Local\Temp\onzvtr2g.out
MD5:
SHA256:
3452csc.exeC:\Users\admin\AppData\Local\Temp\CSC3551.tmp
MD5:
SHA256:
3452csc.exeC:\Users\admin\AppData\Local\Temp\fwvkfjng.pdb
MD5:
SHA256:
2268cvtres.exeC:\Users\admin\AppData\Local\Temp\RES3552.tmp
MD5:
SHA256:
3452csc.exeC:\Users\admin\AppData\Local\Temp\fwvkfjng.dll
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
5 619
DNS requests
3
Threats
18

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2788
powershell.exe
GET
304
2.21.78.185:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
unknown
compressed
57.0 Kb
whitelisted
2788
powershell.exe
GET
200
2.21.78.185:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
unknown
compressed
57.0 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2788
powershell.exe
192.168.1.2:3389
suspicious
10.0.0.0:445
unknown
2788
powershell.exe
167.99.154.202:80
d.ackng.com
US
malicious
2788
powershell.exe
204.236.231.159:443
api.ipify.org
Amazon.com, Inc.
US
malicious
10.0.0.0:1433
unknown
10.0.0.1:445
unknown
10.0.0.4:445
unknown
10.0.0.3:445
unknown
10.0.0.2:445
unknown
10.0.0.7:445
unknown

DNS requests

Domain
IP
Reputation
d.ackng.com
  • 167.99.154.202
malicious
api.ipify.org
  • 204.236.231.159
  • 50.19.115.217
  • 23.21.213.140
  • 54.225.178.192
  • 54.225.182.172
  • 23.21.59.179
  • 54.221.234.156
  • 23.21.153.210
shared
www.download.windowsupdate.com
  • 2.21.78.185
  • 2.21.78.252
whitelisted

Threats

PID
Process
Class
Message
2788
powershell.exe
Misc activity
ET POLICY EXE Base64 Encoded potential malware
2788
powershell.exe
Misc activity
SUSPICIOUS [PTsecurity] Executable base64 Payload
2788
powershell.exe
Misc activity
SUSPICIOUS [PTsecurity] ipify.org External IP Check
2788
powershell.exe
Misc activity
SUSPICIOUS [PTsecurity] ipify.org External IP Check
2788
powershell.exe
Misc activity
ET SCAN Behavioral Unusual Port 445 traffic Potential Scan or Infection
2788
powershell.exe
Misc activity
ET SCAN Behavioral Unusual Port 1433 traffic Potential Scan or Infection
2788
powershell.exe
Misc activity
ET SCAN Behavioral Unusual Port 445 traffic Potential Scan or Infection
2788
powershell.exe
Misc activity
ET SCAN Behavioral Unusual Port 1433 traffic Potential Scan or Infection
Misc activity
ET SCAN Behavioral Unusual Port 445 traffic Potential Scan or Infection
Misc activity
ET SCAN Behavioral Unusual Port 1433 traffic Potential Scan or Infection
6 ETPRO signatures available at the full report
Process
Message
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
csc.exe
*** HR originated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\copyout.cpp, line 1302
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144
csc.exe
*** HR propagated: -2147024774 *** Source File: d:\iso_whid\x86fre\base\isolation\com\enumidentityattribute.cpp, line 144