File name:

script.bat

Full analysis: https://app.any.run/tasks/bdec8aa7-9d0e-45d0-b544-2fc68f3dda76
Verdict: Malicious activity
Analysis date: July 31, 2025, 19:48:00
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: text/plain
File info: ASCII text, with no line terminators
MD5:

22624B4D31744E4C84B314B1B2391242

SHA1:

6CEA6048A23DB14302123472D98D7E01A2E2F029

SHA256:

285878A4FE5395AD4CEC6A9A28CD3BED46931068A574693AEE8C5C7E61F5CD8D

SSDEEP:

3:rMNS4iIDtNeMMeLB56r54WuFKu0mM/J:YvhR4QLL6r51uz0JB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 2468)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 2468)
      • msiexec.exe (PID: 1100)
    • Process drops legitimate windows executable

      • msiexec.exe (PID: 2468)
      • 7z.exe (PID: 6860)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 2468)
      • 7z.exe (PID: 6860)
    • Drops 7-zip archiver for unpacking

      • msiexec.exe (PID: 2468)
    • Executing commands from a ".bat" file

      • msiexec.exe (PID: 2468)
    • Starts CMD.EXE for commands execution

      • msiexec.exe (PID: 2468)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 4228)
    • Executable content was dropped or overwritten

      • 7z.exe (PID: 6860)
  • INFO

    • Reads the computer name

      • msiexec.exe (PID: 2468)
      • msiexec.exe (PID: 1100)
      • 7z.exe (PID: 6860)
      • clipx.exe (PID: 2464)
    • Checks supported languages

      • msiexec.exe (PID: 2468)
      • msiexec.exe (PID: 1100)
      • rawshark.exe (PID: 2504)
      • clipx.exe (PID: 2464)
      • 7z.exe (PID: 6860)
    • Reads the software policy settings

      • msiexec.exe (PID: 2468)
      • msiexec.exe (PID: 1100)
    • The sample compiled with english language support

      • msiexec.exe (PID: 2468)
      • 7z.exe (PID: 6860)
    • Checks proxy server information

      • msiexec.exe (PID: 1100)
    • Reads the machine GUID from the registry

      • msiexec.exe (PID: 1100)
    • Reads Environment values

      • msiexec.exe (PID: 1100)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 2468)
    • Creates files or folders in the user directory

      • msiexec.exe (PID: 1100)
      • msiexec.exe (PID: 2468)
      • clipx.exe (PID: 2464)
      • 7z.exe (PID: 6860)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 2468)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
149
Monitored processes
14
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start cmd.exe no specs conhost.exe no specs msiexec.exe no specs msiexec.exe msiexec.exe clipx.exe cmd.exe no specs conhost.exe no specs timeout.exe no specs 7z.exe conhost.exe no specs rawshark.exe conhost.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1100C:\Windows\syswow64\MsiExec.exe -Embedding 65B19717CBEEE1473084757BCC893AD8C:\Windows\SysWOW64\msiexec.exe
msiexec.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Exit code:
0
Version:
5.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1216C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2032timeout 1C:\Windows\System32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2140\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2464"C:\Users\admin\AppData\Roaming\Rafioj Corp Sols\Koaie Quaos Moon\clipx.exe"C:\Users\admin\AppData\Roaming\Rafioj Corp Sols\Koaie Quaos Moon\clipx.exe
msiexec.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\roaming\rafioj corp sols\koaie quaos moon\clipx.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2468C:\WINDOWS\system32\msiexec.exe /VC:\Windows\System32\msiexec.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Version:
5.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2504"C:\Users\admin\AppData\Roaming\Rafioj Corp Sols\Koaie Quaos Moon\rawshark.exe" 3990953191194e2bb72149dc82035a23C:\Users\admin\AppData\Roaming\Rafioj Corp Sols\Koaie Quaos Moon\rawshark.exe
msiexec.exe
User:
admin
Company:
The Wireshark developer community
Integrity Level:
MEDIUM
Description:
Rawshark
Version:
4.4.7
Modules
Images
c:\users\admin\appdata\roaming\rafioj corp sols\koaie quaos moon\rawshark.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3148C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\script.bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
c:\windows\system32\advapi32.dll
3640\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe7z.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4160\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
3 579
Read events
3 344
Write events
226
Delete events
9

Modification events

(PID) Process:(2468) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2468) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2468) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2468) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2468) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
A409000096880B085402DC01
(PID) Process:(2468) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
C53606AA46187FEAA17E60EE05AAA574D48810BEA8B658D49A3E957EEE3C04C1
(PID) Process:(2468) msiexec.exeKey:HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(1100) msiexec.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(1100) msiexec.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(1100) msiexec.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
130
Suspicious files
11
Text files
6
Unknown types
6

Dropped files

PID
Process
Filename
Type
2468msiexec.exeC:\Windows\Installer\MSIC9E2.tmp
MD5:
SHA256:
2468msiexec.exeC:\Windows\Temp\~DF22F3D9DFD5C24749.TMPgmc
MD5:BF619EAC0CDF3F68D496EA9344137E8B
SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560
2468msiexec.exeC:\Users\admin\AppData\Roaming\Rafioj Corp Sols\Koaie Quaos Moon\vcruntime140.dllexecutable
MD5:CAF9EDDED91C1F6C0022B278C16679AA
SHA256:02C6AA0E6E624411A9F19B0360A7865AB15908E26024510E5C38A9C08362C35A
2468msiexec.exeC:\Windows\Installer\MSIE6F4.tmpexecutable
MD5:5209BA1F48C19C8D255B91A13ADBDD3D
SHA256:98911811A173883C729791A5D57E16533BFD8703D340F71DA80C3E5996AECF17
2468msiexec.exeC:\Windows\Installer\MSIE5E7.tmpexecutable
MD5:5209BA1F48C19C8D255B91A13ADBDD3D
SHA256:98911811A173883C729791A5D57E16533BFD8703D340F71DA80C3E5996AECF17
2468msiexec.exeC:\Windows\Installer\MSIE685.tmpexecutable
MD5:5209BA1F48C19C8D255B91A13ADBDD3D
SHA256:98911811A173883C729791A5D57E16533BFD8703D340F71DA80C3E5996AECF17
2468msiexec.exeC:\Windows\Installer\MSIE6B4.tmpexecutable
MD5:5209BA1F48C19C8D255B91A13ADBDD3D
SHA256:98911811A173883C729791A5D57E16533BFD8703D340F71DA80C3E5996AECF17
2468msiexec.exeC:\Windows\Installer\MSIF6F3.tmpexecutable
MD5:D6E11F7578D699D267CB13E2C7129E2B
SHA256:9DD561D7FAC0256B3EC2C999AC3E846108DEE25C0D0717C32743A5E2D1AF6CB6
1100msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\50C9BD3C07EBF00E34B88B6B34928BB2binary
MD5:4466821A9A7B277512530E2F7ED5FEC6
SHA256:755A9D85867C4128D3C50177B021B07DCA10652F31A9AF1D6AE60563EE4BBADF
1100msiexec.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\50C9BD3C07EBF00E34B88B6B34928BB2binary
MD5:6CAF59B8B1875A832940F4AA41C36046
SHA256:007765DB8A9222D90F28B16CDC50B03F61213B827EC40D2DC17A4625B2CA1C21
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
29
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1100
msiexec.exe
GET
200
104.18.20.213:80
http://r10.c.lencr.org/113.crl
unknown
binary
121 Kb
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
23.216.77.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
814 b
whitelisted
3872
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
NL
binary
420 b
whitelisted
3872
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
NL
binary
408 b
whitelisted
4880
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5944
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5460
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2468
msiexec.exe
172.67.131.31:443
vericloudly.com
CLOUDFLARENET
US
unknown
4
System
192.168.100.255:138
whitelisted
1100
msiexec.exe
185.111.111.154:443
conjetpro.com
PRO-ZETA a.s.
CZ
unknown
4880
svchost.exe
20.190.160.65:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4880
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
1100
msiexec.exe
104.18.20.213:80
r10.c.lencr.org
CLOUDFLARENET
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
google.com
  • 216.58.206.46
whitelisted
vericloudly.com
  • 172.67.131.31
  • 104.21.3.192
unknown
conjetpro.com
  • 185.111.111.154
unknown
login.live.com
  • 20.190.160.65
  • 20.190.160.14
  • 40.126.32.133
  • 20.190.160.64
  • 20.190.160.4
  • 20.190.160.131
  • 20.190.160.17
  • 40.126.32.76
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
r10.c.lencr.org
  • 104.18.20.213
  • 104.18.21.213
whitelisted
crl.microsoft.com
  • 23.216.77.19
  • 23.216.77.11
  • 23.216.77.13
  • 23.216.77.18
  • 23.216.77.15
  • 23.216.77.20
  • 23.216.77.25
  • 23.216.77.21
  • 23.216.77.22
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
slscr.update.microsoft.com
  • 20.165.94.63
whitelisted

Threats

No threats detected
Process
Message
clipx.exe
>
clipx.exe
>
clipx.exe
>>>
clipx.exe
>>>
clipx.exe
Auto-initializing 0 services (system pass)
clipx.exe
Auto-initializing 2 services (user pass)
rawshark.exe
xcnjvsoigsheguesh
rawshark.exe
Eaoijfjaoifaeji