| File name: | script.bat |
| Full analysis: | https://app.any.run/tasks/bdec8aa7-9d0e-45d0-b544-2fc68f3dda76 |
| Verdict: | Malicious activity |
| Analysis date: | July 31, 2025, 19:48:00 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with no line terminators |
| MD5: | 22624B4D31744E4C84B314B1B2391242 |
| SHA1: | 6CEA6048A23DB14302123472D98D7E01A2E2F029 |
| SHA256: | 285878A4FE5395AD4CEC6A9A28CD3BED46931068A574693AEE8C5C7E61F5CD8D |
| SSDEEP: | 3:rMNS4iIDtNeMMeLB56r54WuFKu0mM/J:YvhR4QLL6r51uz0JB |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1100 | C:\Windows\syswow64\MsiExec.exe -Embedding 65B19717CBEEE1473084757BCC893AD8 | C:\Windows\SysWOW64\msiexec.exe | msiexec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1216 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2032 | timeout 1 | C:\Windows\System32\timeout.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: timeout - pauses command processing Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2140 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2464 | "C:\Users\admin\AppData\Roaming\Rafioj Corp Sols\Koaie Quaos Moon\clipx.exe" | C:\Users\admin\AppData\Roaming\Rafioj Corp Sols\Koaie Quaos Moon\clipx.exe | msiexec.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 2468 | C:\WINDOWS\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2504 | "C:\Users\admin\AppData\Roaming\Rafioj Corp Sols\Koaie Quaos Moon\rawshark.exe" 3990953191194e2bb72149dc82035a23 | C:\Users\admin\AppData\Roaming\Rafioj Corp Sols\Koaie Quaos Moon\rawshark.exe | msiexec.exe | ||||||||||||
User: admin Company: The Wireshark developer community Integrity Level: MEDIUM Description: Rawshark Version: 4.4.7 Modules
| |||||||||||||||
| 3148 | C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\script.bat" " | C:\Windows\System32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3640 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | 7z.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4160 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (2468) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2468) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2468) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2468) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2468) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: A409000096880B085402DC01 | |||
| (PID) Process: | (2468) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: C53606AA46187FEAA17E60EE05AAA574D48810BEA8B658D49A3E957EEE3C04C1 | |||
| (PID) Process: | (2468) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (1100) msiexec.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (1100) msiexec.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (1100) msiexec.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2468 | msiexec.exe | C:\Windows\Installer\MSIC9E2.tmp | — | |
MD5:— | SHA256:— | |||
| 2468 | msiexec.exe | C:\Windows\Temp\~DF22F3D9DFD5C24749.TMP | gmc | |
MD5:BF619EAC0CDF3F68D496EA9344137E8B | SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560 | |||
| 2468 | msiexec.exe | C:\Users\admin\AppData\Roaming\Rafioj Corp Sols\Koaie Quaos Moon\vcruntime140.dll | executable | |
MD5:CAF9EDDED91C1F6C0022B278C16679AA | SHA256:02C6AA0E6E624411A9F19B0360A7865AB15908E26024510E5C38A9C08362C35A | |||
| 2468 | msiexec.exe | C:\Windows\Installer\MSIE6F4.tmp | executable | |
MD5:5209BA1F48C19C8D255B91A13ADBDD3D | SHA256:98911811A173883C729791A5D57E16533BFD8703D340F71DA80C3E5996AECF17 | |||
| 2468 | msiexec.exe | C:\Windows\Installer\MSIE5E7.tmp | executable | |
MD5:5209BA1F48C19C8D255B91A13ADBDD3D | SHA256:98911811A173883C729791A5D57E16533BFD8703D340F71DA80C3E5996AECF17 | |||
| 2468 | msiexec.exe | C:\Windows\Installer\MSIE685.tmp | executable | |
MD5:5209BA1F48C19C8D255B91A13ADBDD3D | SHA256:98911811A173883C729791A5D57E16533BFD8703D340F71DA80C3E5996AECF17 | |||
| 2468 | msiexec.exe | C:\Windows\Installer\MSIE6B4.tmp | executable | |
MD5:5209BA1F48C19C8D255B91A13ADBDD3D | SHA256:98911811A173883C729791A5D57E16533BFD8703D340F71DA80C3E5996AECF17 | |||
| 2468 | msiexec.exe | C:\Windows\Installer\MSIF6F3.tmp | executable | |
MD5:D6E11F7578D699D267CB13E2C7129E2B | SHA256:9DD561D7FAC0256B3EC2C999AC3E846108DEE25C0D0717C32743A5E2D1AF6CB6 | |||
| 1100 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\50C9BD3C07EBF00E34B88B6B34928BB2 | binary | |
MD5:4466821A9A7B277512530E2F7ED5FEC6 | SHA256:755A9D85867C4128D3C50177B021B07DCA10652F31A9AF1D6AE60563EE4BBADF | |||
| 1100 | msiexec.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\50C9BD3C07EBF00E34B88B6B34928BB2 | binary | |
MD5:6CAF59B8B1875A832940F4AA41C36046 | SHA256:007765DB8A9222D90F28B16CDC50B03F61213B827EC40D2DC17A4625B2CA1C21 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1100 | msiexec.exe | GET | 200 | 104.18.20.213:80 | http://r10.c.lencr.org/113.crl | unknown | binary | 121 Kb | whitelisted |
5944 | MoUsoCoreWorker.exe | GET | 200 | 23.216.77.19:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | DE | binary | 825 b | whitelisted |
5944 | MoUsoCoreWorker.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | NL | binary | 814 b | whitelisted |
3872 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | NL | binary | 420 b | whitelisted |
3872 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | NL | binary | 408 b | whitelisted |
4880 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | US | binary | 471 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1268 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5944 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5460 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2468 | msiexec.exe | 172.67.131.31:443 | vericloudly.com | CLOUDFLARENET | US | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1100 | msiexec.exe | 185.111.111.154:443 | conjetpro.com | PRO-ZETA a.s. | CZ | unknown |
4880 | svchost.exe | 20.190.160.65:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4880 | svchost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
1100 | msiexec.exe | 104.18.20.213:80 | r10.c.lencr.org | CLOUDFLARENET | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
vericloudly.com |
| unknown |
conjetpro.com |
| unknown |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
r10.c.lencr.org |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
clipx.exe | >
|
clipx.exe | >
|
clipx.exe | >>>
|
clipx.exe | >>>
|
clipx.exe | Auto-initializing 0 services (system pass)
|
clipx.exe | Auto-initializing 2 services (user pass)
|
rawshark.exe | xcnjvsoigsheguesh |
rawshark.exe | Eaoijfjaoifaeji |