File name:

SecuriteInfo.com.W64.Agent.KHK.gen.Eldorado.25308.13156

Full analysis: https://app.any.run/tasks/c194c3dc-fd25-439f-a6b9-19931e0ab119
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: June 03, 2025, 14:53:08
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
telegram
vidar
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections
MD5:

DD06655302265C1E0C82717C0DF1C02C

SHA1:

14826DF64FBDC3E7523E0E7F8C9E47B184F67349

SHA256:

376AB51F457C02B5F62E5DB07BF6DAC178AED99BB339FA58C1AD6DD405B6AB52

SSDEEP:

98304:HCTGXmCpizK/x10auQBCPN7GHy1Q2NTknTdwosOHsHId32SM0peB9EhcBQnT9Mow:VLJAn3Jqm00

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • VIDAR mutex has been found

      • AppLaunch.exe (PID: 5344)
    • VIDAR has been detected (SURICATA)

      • AppLaunch.exe (PID: 5344)
    • Actions looks like stealing of personal data

      • AppLaunch.exe (PID: 5344)
    • Steals credentials from Web Browsers

      • AppLaunch.exe (PID: 5344)
    • VIDAR has been detected (YARA)

      • AppLaunch.exe (PID: 5344)
  • SUSPICIOUS

    • Process communicates with Telegram (possibly using it as an attacker's C2 server)

      • AppLaunch.exe (PID: 5344)
    • Reads security settings of Internet Explorer

      • AppLaunch.exe (PID: 5344)
    • Process drops legitimate windows executable

      • SecuriteInfo.com.W64.Agent.KHK.gen.Eldorado.25308.13156.exe (PID: 5968)
    • The process drops C-runtime libraries

      • SecuriteInfo.com.W64.Agent.KHK.gen.Eldorado.25308.13156.exe (PID: 5968)
    • Executable content was dropped or overwritten

      • SecuriteInfo.com.W64.Agent.KHK.gen.Eldorado.25308.13156.exe (PID: 5968)
      • csc.exe (PID: 8144)
      • csc.exe (PID: 924)
      • csc.exe (PID: 4572)
      • csc.exe (PID: 7744)
      • csc.exe (PID: 4976)
      • csc.exe (PID: 1168)
      • csc.exe (PID: 6060)
      • csc.exe (PID: 7312)
      • csc.exe (PID: 3896)
      • csc.exe (PID: 7956)
      • csc.exe (PID: 7928)
      • csc.exe (PID: 7864)
    • Searches for installed software

      • AppLaunch.exe (PID: 5344)
    • The process bypasses the loading of PowerShell profile settings

      • AppLaunch.exe (PID: 5344)
    • Starts POWERSHELL.EXE for commands execution

      • AppLaunch.exe (PID: 5344)
    • Gets content of a file (POWERSHELL)

      • powershell.exe (PID: 5984)
      • powershell.exe (PID: 5560)
      • powershell.exe (PID: 1348)
      • powershell.exe (PID: 8144)
      • powershell.exe (PID: 4468)
    • Uses base64 encoding (POWERSHELL)

      • powershell.exe (PID: 5984)
      • powershell.exe (PID: 5560)
      • powershell.exe (PID: 1348)
      • powershell.exe (PID: 8144)
      • powershell.exe (PID: 4468)
    • CSC.EXE is used to compile C# code

      • csc.exe (PID: 8144)
      • csc.exe (PID: 924)
      • csc.exe (PID: 4572)
      • csc.exe (PID: 7744)
      • csc.exe (PID: 4976)
      • csc.exe (PID: 6060)
      • csc.exe (PID: 7312)
      • csc.exe (PID: 3896)
      • csc.exe (PID: 7956)
      • csc.exe (PID: 7928)
      • csc.exe (PID: 7864)
      • csc.exe (PID: 1168)
    • The process hide an interactive prompt from the user

      • AppLaunch.exe (PID: 5344)
    • Base64-obfuscated command line is found

      • AppLaunch.exe (PID: 5344)
    • BASE64 encoded PowerShell command has been detected

      • AppLaunch.exe (PID: 5344)
    • There is functionality for taking screenshot (YARA)

      • AppLaunch.exe (PID: 5344)
    • Multiple wallet extension IDs have been found

      • AppLaunch.exe (PID: 5344)
  • INFO

    • The sample compiled with english language support

      • SecuriteInfo.com.W64.Agent.KHK.gen.Eldorado.25308.13156.exe (PID: 5968)
    • Checks proxy server information

      • AppLaunch.exe (PID: 5344)
    • Reads the machine GUID from the registry

      • AppLaunch.exe (PID: 5344)
      • csc.exe (PID: 8144)
      • csc.exe (PID: 4572)
      • csc.exe (PID: 924)
      • csc.exe (PID: 4976)
      • AddInProcess32.exe (PID: 6384)
      • csc.exe (PID: 7744)
    • Creates files or folders in the user directory

      • AppLaunch.exe (PID: 5344)
    • Checks supported languages

      • SecuriteInfo.com.W64.Agent.KHK.gen.Eldorado.25308.13156.exe (PID: 5968)
      • nextspecialist.exe (PID: 7388)
      • cvtres.exe (PID: 8148)
      • csc.exe (PID: 8144)
      • cvtres.exe (PID: 2616)
      • csc.exe (PID: 924)
      • csc.exe (PID: 4572)
      • cvtres.exe (PID: 236)
      • csc.exe (PID: 7744)
      • csc.exe (PID: 4976)
      • AddInProcess32.exe (PID: 6384)
      • AppLaunch.exe (PID: 5344)
      • cvtres.exe (PID: 7592)
      • cvtres.exe (PID: 4892)
    • Create files in a temporary directory

      • SecuriteInfo.com.W64.Agent.KHK.gen.Eldorado.25308.13156.exe (PID: 5968)
      • AppLaunch.exe (PID: 5344)
      • powershell.exe (PID: 5984)
      • csc.exe (PID: 8144)
      • powershell.exe (PID: 5560)
      • cvtres.exe (PID: 2616)
      • csc.exe (PID: 924)
      • powershell.exe (PID: 1348)
      • cvtres.exe (PID: 236)
      • csc.exe (PID: 4572)
      • powershell.exe (PID: 8144)
      • csc.exe (PID: 7744)
      • cvtres.exe (PID: 7592)
      • powershell.exe (PID: 4468)
      • csc.exe (PID: 4976)
      • cvtres.exe (PID: 4892)
    • Reads the computer name

      • AddInProcess32.exe (PID: 6384)
      • AppLaunch.exe (PID: 5344)
    • Reads the software policy settings

      • AppLaunch.exe (PID: 5344)
      • powershell.exe (PID: 5984)
      • powershell.exe (PID: 5560)
      • powershell.exe (PID: 1348)
      • powershell.exe (PID: 8144)
      • powershell.exe (PID: 4468)
    • Reads product name

      • AppLaunch.exe (PID: 5344)
    • Reads CPU info

      • AppLaunch.exe (PID: 5344)
    • Reads Environment values

      • AppLaunch.exe (PID: 5344)
    • Reads security settings of Internet Explorer

      • powershell.exe (PID: 5984)
      • powershell.exe (PID: 5560)
      • powershell.exe (PID: 1348)
      • powershell.exe (PID: 8144)
      • powershell.exe (PID: 4468)
    • Application launched itself

      • chrome.exe (PID: 7968)
      • chrome.exe (PID: 6676)
      • chrome.exe (PID: 4408)
      • chrome.exe (PID: 7508)
      • chrome.exe (PID: 444)
      • chrome.exe (PID: 3140)
      • chrome.exe (PID: 4192)
      • chrome.exe (PID: 5024)
      • chrome.exe (PID: 2868)
      • chrome.exe (PID: 5020)
      • chrome.exe (PID: 236)
      • chrome.exe (PID: 7720)
    • Manual execution by a user

      • AppLaunch.exe (PID: 5344)
    • Creates files in the program directory

      • AppLaunch.exe (PID: 5344)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Vidar

(PID) Process(5344) AppLaunch.exe
C2https://t.me/eom25t
URLhttps://steamcommunity.com/profiles/76561199855598339
RC43333333333333333UUUUUUUUUUUUUUUU
Strings (1)
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2062:07:25 12:18:00+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.2
CodeSize: 31744
InitializedDataSize: 6246400
UninitializedDataSize: -
EntryPoint: 0x8200
OSVersion: 10
ImageVersion: 10
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 3.4.5.10
ProductVersionNumber: 3.4.5.10
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Grabr
FileDescription: Stellar is an open platform for building financial products
FileVersion: 3.4.5.10
InternalName: aloneinstruction
ProductName: Maintain Instruction
ProductVersion: 3.4.5.10
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
314
Monitored processes
190
Malicious processes
1
Suspicious processes
5

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
232"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Google\Chrome\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Google\Chrome\User Data\Crashpad" --url=https://clients2.google.com/cr/report --annotation=channel= --annotation=plat=Win64 --annotation=prod=Chrome --annotation=ver=122.0.6261.70 --initial-client-data=0x228,0x22c,0x230,0x204,0x234,0x7ffc895bdc40,0x7ffc895bdc4c,0x7ffc895bdc58C:\Program Files\Google\Chrome\Application\chrome.exe—chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
236C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES97C4.tmp" "c:\Users\admin\AppData\Local\Temp\CSC775BC53E3E4B43B3998231835C93F43.TMP"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe—csc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
14.32.31326.0
Modules
Images
c:\windows\microsoft.net\framework64\v4.0.30319\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase_clr0400.dll
236"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=chrome.mojom.ProcessorMetrics --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=4220 --field-trial-handle=1984,i,6442127915599876686,1709075522361447380,262144 --variations-seed-version /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exe—chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
236"C:\Program Files\Google\Chrome\Application\chrome.exe"C:\Program Files\Google\Chrome\Application\chrome.exe
AppLaunch.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
404C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES1001.tmp" "c:\Users\admin\AppData\Local\Temp\CSC7DE71CD7BCC64D41846F12F7A76BC5A1.TMP"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe—csc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
14.32.31326.0
Modules
Images
c:\windows\microsoft.net\framework64\v4.0.30319\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\vcruntime140_clr0400.dll
444"C:\Program Files\Google\Chrome\Application\chrome.exe"C:\Program Files\Google\Chrome\Application\chrome.exe
AppLaunch.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
496\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe—powershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
632C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe—svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
780"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --no-appcompat-clear --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=8 --mojo-platform-channel-handle=4380 --field-trial-handle=1980,i,16922616753342477549,13612895671574918040,262144 --variations-seed-version /prefetch:1C:\Program Files\Google\Chrome\Application\chrome.exe—chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
856"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --disable-quic --no-appcompat-clear --mojo-platform-channel-handle=2140 --field-trial-handle=2100,i,4557504183853759680,7301006406802216415,262144 --variations-seed-version /prefetch:3C:\Program Files\Google\Chrome\Application\chrome.exe
chrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
MEDIUM
Description:
Google Chrome
Exit code:
0
Version:
122.0.6261.70
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
99 692
Read events
99 631
Write events
61
Delete events
0

Modification events

(PID) Process:(5344) AppLaunch.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(5344) AppLaunch.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(5344) AppLaunch.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7968) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(7968) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(7968) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(7968) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(7968) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(6676) chrome.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Google\Update\ClientStateMedium\{8A69D345-D564-463C-AFF1-A69D9E530F96}
Operation:writeName:usagestats
Value:
0
(PID) Process:(6676) chrome.exeKey:HKEY_CURRENT_USER\SOFTWARE\Google\Chrome\BLBeacon
Operation:writeName:failed_count
Value:
0
Executable files
15
Suspicious files
62
Text files
305
Unknown types
89

Dropped files

PID
Process
Filename
Type
7968chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old~RF1242ce.TMP —
MD5:—
SHA256:—
7968chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old~RF1242ce.TMP —
MD5:—
SHA256:—
7968chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\parcel_tracking_db\LOG.old —
MD5:—
SHA256:—
7968chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old~RF12429f.TMP —
MD5:—
SHA256:—
7968chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\discounts_db\LOG.old —
MD5:—
SHA256:—
7968chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\PersistentOriginTrials\LOG.old —
MD5:—
SHA256:—
7968chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old~RF1242dd.TMP —
MD5:—
SHA256:—
7968chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\chrome_cart_db\LOG.old —
MD5:—
SHA256:—
7968chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old~RF1242dd.TMP —
MD5:—
SHA256:—
7968chrome.exeC:\Users\admin\AppData\Local\Google\Chrome\User Data\Default\coupon_db\LOG.old —
MD5:—
SHA256:—
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
136
DNS requests
153
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
7568
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
QA
binary
419 b
whitelisted
472
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
868 b
whitelisted
7568
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
QA
binary
408 b
whitelisted
—
—
GET
200
2.20.245.139:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
SE
binary
825 b
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
868 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
—
—
—
whitelisted
—
—
20.73.194.208:443
—
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
—
—
2.20.245.139:80
crl.microsoft.com
Akamai International B.V.
SE
whitelisted
5496
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
472
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
8184
RUXIMICS.exe
20.73.194.208:443
—
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
—
—
—
whitelisted
472
svchost.exe
20.73.194.208:443
—
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
40.126.32.134:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.184.206
whitelisted
crl.microsoft.com
  • 2.20.245.139
  • 2.20.245.137
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 2.23.246.101
whitelisted
login.live.com
  • 40.126.32.134
  • 20.190.160.130
  • 40.126.32.76
  • 20.190.160.128
  • 20.190.160.132
  • 40.126.32.72
  • 20.190.160.17
  • 20.190.160.22
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
t.me
  • 149.154.167.99
whitelisted
xx.7.4t.com
  • —
unknown
steamcommunity.com
  • 104.102.49.106
whitelisted
clientservices.googleapis.com
  • 216.58.212.131
  • 142.250.186.35
whitelisted

Threats

PID
Process
Class
Message
5344
AppLaunch.exe
Misc activity
ET INFO Observed Telegram Domain (t .me in TLS SNI)
5344
AppLaunch.exe
A Network Trojan was detected
STEALER [ANY.RUN] Vidar TLS Connection Attempt
5344
AppLaunch.exe
A Network Trojan was detected
STEALER [ANY.RUN] Vidar TLS Connection Attempt
No debug info