File name:

French Group.7z

Full analysis: https://app.any.run/tasks/1dda1cf7-72e7-422b-bb28-22e1d1b807c7
Verdict: Malicious activity
Threats:

A keylogger is a type of spyware that infects a system and has the ability to record every keystroke made on the device. This lets attackers collect personal information of victims, which may include their online banking credentials, as well as personal conversations. The most widespread vector of attack leading to a keylogger infection begins with a phishing email or link. Keylogging is also often present in remote access trojans as part of an extended set of malicious tools.

Analysis date: August 29, 2024, 11:14:40
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
pastebin
rat
remcos
stealer
keylogger
evasion
api-base64
mpress
Indicators:
MIME: application/x-rar
File info: RAR archive data, v5
MD5:

1395B44FBE11C3C1F71ADEFA2246E115

SHA1:

62D731F7CD0317101D378258E5430F4A90455119

SHA256:

4337017371A7454E3CBF23E650A5FA45A751315AB4261453E66476FAB22C6E1B

SSDEEP:

96:0FOMRhuZQfkIpQzeq6DlVBHYd3ZqDzhi8wcsVpB:0gMRh6Iqze9A0hZOPB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates internet connection object (SCRIPT)

      • wscript.exe (PID: 2700)
    • Sends HTTP request (SCRIPT)

      • wscript.exe (PID: 2700)
    • Opens an HTTP connection (SCRIPT)

      • wscript.exe (PID: 2700)
    • Detects the decoding of a binary file from Base64 (SCRIPT)

      • wscript.exe (PID: 2700)
    • REMCOS has been detected

      • RegAsm.exe (PID: 6652)
      • RegAsm.exe (PID: 6652)
      • RegAsm.exe (PID: 6652)
    • Actions looks like stealing of personal data

      • RegAsm.exe (PID: 6344)
      • RegAsm.exe (PID: 4064)
      • RegAsm.exe (PID: 6604)
      • RegAsm.exe (PID: 6684)
      • RegAsm.exe (PID: 6752)
      • RegAsm.exe (PID: 6600)
      • RegAsm.exe (PID: 6336)
      • RegAsm.exe (PID: 2796)
      • RegAsm.exe (PID: 6728)
      • RegAsm.exe (PID: 1780)
    • Scans artifacts that could help determine the target

      • RegAsm.exe (PID: 6344)
      • RegAsm.exe (PID: 6752)
      • RegAsm.exe (PID: 2796)
    • Steals credentials from Web Browsers

      • RegAsm.exe (PID: 4064)
      • RegAsm.exe (PID: 6336)
      • RegAsm.exe (PID: 6728)
      • RegAsm.exe (PID: 1780)
    • Uses NirSoft utilities to collect credentials

      • RegAsm.exe (PID: 4064)
      • RegAsm.exe (PID: 6336)
      • RegAsm.exe (PID: 6728)
    • Connects to the CnC server

      • RegAsm.exe (PID: 6652)
    • REMCOS has been detected (SURICATA)

      • RegAsm.exe (PID: 6652)
    • REMCOS has been detected (YARA)

      • RegAsm.exe (PID: 6652)
  • SUSPICIOUS

    • The process executes JS scripts

      • WinRAR.exe (PID: 7164)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 7164)
      • RegAsm.exe (PID: 6652)
    • Gets full path of the running script (SCRIPT)

      • wscript.exe (PID: 2700)
    • Uses base64 encoding (POWERSHELL)

      • powershell.exe (PID: 6696)
    • Starts POWERSHELL.EXE for commands execution

      • wscript.exe (PID: 2700)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 2700)
    • Base64-obfuscated command line is found

      • wscript.exe (PID: 2700)
    • Application launched itself

      • RegAsm.exe (PID: 6652)
    • Contacting a server suspected of hosting an CnC

      • RegAsm.exe (PID: 6652)
    • Writes files like Keylogger logs

      • RegAsm.exe (PID: 6652)
    • Checks for external IP

      • RegAsm.exe (PID: 6652)
    • Connects to unusual port

      • RegAsm.exe (PID: 6652)
    • There is functionality for taking screenshot (YARA)

      • RegAsm.exe (PID: 6652)
  • INFO

    • Reads Microsoft Office registry keys

      • WinRAR.exe (PID: 7164)
      • RegAsm.exe (PID: 6344)
      • RegAsm.exe (PID: 6752)
      • RegAsm.exe (PID: 2796)
    • The process uses the downloaded file

      • WinRAR.exe (PID: 7164)
      • wscript.exe (PID: 2700)
      • powershell.exe (PID: 6696)
    • Disables trace logs

      • powershell.exe (PID: 6696)
    • Checks proxy server information

      • powershell.exe (PID: 6696)
      • RegAsm.exe (PID: 6652)
      • slui.exe (PID: 6236)
    • Checks supported languages

      • RegAsm.exe (PID: 6652)
      • RegAsm.exe (PID: 6604)
      • RegAsm.exe (PID: 4064)
      • RegAsm.exe (PID: 6344)
      • RegAsm.exe (PID: 6336)
      • RegAsm.exe (PID: 6752)
      • RegAsm.exe (PID: 6684)
      • RegAsm.exe (PID: 6728)
      • RegAsm.exe (PID: 2796)
      • RegAsm.exe (PID: 6600)
      • RegAsm.exe (PID: 1780)
    • Reads Environment values

      • RegAsm.exe (PID: 6652)
    • Checks current location (POWERSHELL)

      • powershell.exe (PID: 6696)
    • Creates files or folders in the user directory

      • RegAsm.exe (PID: 6652)
    • Reads the computer name

      • RegAsm.exe (PID: 6604)
      • RegAsm.exe (PID: 6344)
      • RegAsm.exe (PID: 6652)
      • RegAsm.exe (PID: 4064)
      • RegAsm.exe (PID: 6752)
      • RegAsm.exe (PID: 6684)
      • RegAsm.exe (PID: 6600)
      • RegAsm.exe (PID: 2796)
      • RegAsm.exe (PID: 6336)
      • RegAsm.exe (PID: 6728)
    • Create files in a temporary directory

      • RegAsm.exe (PID: 6344)
      • RegAsm.exe (PID: 6604)
      • RegAsm.exe (PID: 4064)
      • RegAsm.exe (PID: 6752)
      • RegAsm.exe (PID: 6684)
      • RegAsm.exe (PID: 6600)
      • RegAsm.exe (PID: 6336)
      • RegAsm.exe (PID: 6728)
      • RegAsm.exe (PID: 2796)
      • RegAsm.exe (PID: 1780)
    • Potential remote process memory reading (Base64 Encoded 'ReadProcessMemory')

      • powershell.exe (PID: 6696)
    • Creates files in the program directory

      • RegAsm.exe (PID: 6652)
    • Potential remote process memory interaction (Base64 Encoded 'VirtualAllocEx')

      • powershell.exe (PID: 6696)
    • Potential remote process memory writing (Base64 Encoded 'WriteProcessMemory')

      • powershell.exe (PID: 6696)
    • Potential modification of remote process state (Base64 Encoded 'SetThreadContext')

      • powershell.exe (PID: 6696)
    • Reads the machine GUID from the registry

      • RegAsm.exe (PID: 6604)
      • RegAsm.exe (PID: 4064)
      • RegAsm.exe (PID: 6684)
      • RegAsm.exe (PID: 6336)
      • RegAsm.exe (PID: 6728)
      • RegAsm.exe (PID: 6600)
    • Potential library load (Base64 Encoded 'LoadLibrary')

      • powershell.exe (PID: 6696)
    • Potential access to remote process (Base64 Encoded 'OpenProcess')

      • powershell.exe (PID: 6696)
    • Potential dynamic function import (Base64 Encoded 'GetProcAddress')

      • powershell.exe (PID: 6696)
    • Reads the software policy settings

      • slui.exe (PID: 964)
      • slui.exe (PID: 6236)
    • Mpress packer has been detected

      • RegAsm.exe (PID: 6652)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Remcos

(PID) Process(6652) RegAsm.exe
C2 (1)closen.kozow.com:2404
BotnetIDEMILI
Options
Connect_interval1
Install_flagFalse
Install_HKCU\RunTrue
Install_HKLM\RunTrue
Install_HKLM\Explorer\Run1
Install_HKLM\Winlogon\Shell100000
Setup_path%LOCALAPPDATA%
Copy_fileremcos.exe
Startup_valueFalse
Hide_fileFalse
Mutex_nameRmc-O4UMCG
Keylog_flag1
Keylog_path%LOCALAPPDATA%
Keylog_filelogs.dat
Keylog_cryptFalse
Hide_keylogFalse
Screenshot_flagFalse
Screenshot_time5
Take_ScreenshotFalse
Screenshot_path%APPDATA%
Screenshot_fileScreenshots
Screenshot_cryptFalse
Mouse_optionFalse
Delete_fileFalse
Audio_record_time5
Audio_path%ProgramFiles%
Audio_dirMicRecords
Connect_delay0
Copy_dirRemcos
Keylog_dirremcos
No Malware configuration.

TRiD

.rar | RAR compressed archive (v5.0) (61.5)
.rar | RAR compressed archive (gen) (38.4)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
21
Malicious processes
14
Suspicious processes
0

Behavior graph

Click at the process to see the details
start winrar.exe no specs wscript.exe THREAT powershell.exe conhost.exe no specs sppextcomobj.exe no specs slui.exe #REMCOS regasm.exe svchost.exe regasm.exe regasm.exe no specs regasm.exe regasm.exe regasm.exe no specs regasm.exe regasm.exe regasm.exe slui.exe regasm.exe regasm.exe regasm.exe regasm.exe

Process information

PID
CMD
Path
Indicators
Parent process
752\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
964"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1764C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
1780C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe /sort "Visit Time" /stext "C:\Users\admin\AppData\Local\Temp\cgvrstyjjkfvsijbqsnpktvatkcjl"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
RegAsm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Assembly Registration Utility
Exit code:
0
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regasm.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2256C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2700"C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\Rar$DIa7164.40693\French Group.js" C:\Windows\System32\wscript.exe
WinRAR.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2796C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe /stext "C:\Users\admin\AppData\Local\Temp\rvyldvuzvruuxxffsmlbxymlbhjenp"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
RegAsm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Assembly Registration Utility
Exit code:
0
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regasm.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
2992C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe /stext "C:\Users\admin\AppData\Local\Temp\dlaqrsenwwwugurxzgqltk"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeRegAsm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Assembly Registration Utility
Exit code:
0
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regasm.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4064C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe /stext "C:\Users\admin\AppData\Local\Temp\trufqztlioepwodlqve"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe
RegAsm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Assembly Registration Utility
Exit code:
0
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regasm.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6016C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe /stext "C:\Users\admin\AppData\Local\Temp\lnggkpvcluea"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeRegAsm.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Assembly Registration Utility
Exit code:
0
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regasm.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
16 647
Read events
16 574
Write events
73
Delete events
0

Modification events

(PID) Process:(7164) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(7164) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(7164) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\GoogleChromeEnterpriseBundle64.zip
(PID) Process:(7164) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\French Group.7z.rar
(PID) Process:(7164) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(7164) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(7164) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(7164) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
(PID) Process:(7164) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.js\OpenWithProgids
Operation:writeName:JSFile
Value:
(PID) Process:(7164) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
Executable files
0
Suspicious files
6
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
4064RegAsm.exeC:\Users\admin\AppData\Local\Temp\bhvEC0E.tmp
MD5:
SHA256:
6336RegAsm.exeC:\Users\admin\AppData\Local\Microsoft\Windows\WebCache\WebCacheV01.dat
MD5:
SHA256:
6336RegAsm.exeC:\Users\admin\AppData\Local\Temp\bhv6E1F.tmp
MD5:
SHA256:
6728RegAsm.exeC:\Users\admin\AppData\Local\Temp\bhvE0DE.tmp
MD5:
SHA256:
1780RegAsm.exeC:\Users\admin\AppData\Local\Temp\bhv4768.tmp
MD5:
SHA256:
1780RegAsm.exeC:\Users\admin\AppData\Local\Temp\sqp47D6.tmp
MD5:
SHA256:
7164WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa7164.40693\French Group.jsbinary
MD5:188D120C10353E5EAF51B67F4A3F83FF
SHA256:5E14D3A393D05AC394BAAECF1D47AE21AD959180BD20FF439B8D9CCCC9A34DE4
6336RegAsm.exeC:\Users\admin\AppData\Local\Temp\lnggkpvclueatext
MD5:73AFEF57A57FF8285682E59AEBA8FE4A
SHA256:9081F636845E9A6B7D781F2F35A28B33B7FDF5373075B435C5B373119D0934A3
4064RegAsm.exeC:\Users\admin\AppData\Local\Temp\trufqztlioepwodlqvetext
MD5:73AFEF57A57FF8285682E59AEBA8FE4A
SHA256:9081F636845E9A6B7D781F2F35A28B33B7FDF5373075B435C5B373119D0934A3
6696powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_vjk40y1z.5fo.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
41
DNS requests
19
Threats
14

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2036
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3176
SIHClient.exe
GET
200
23.218.209.163:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6652
RegAsm.exe
GET
200
178.237.33.50:80
http://geoplugin.net/json.gp
unknown
whitelisted
3176
SIHClient.exe
GET
200
23.218.209.163:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6056
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2120
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
3260
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2036
svchost.exe
20.190.159.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2036
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
6056
svchost.exe
52.140.118.28:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IN
whitelisted
2700
wscript.exe
104.20.3.235:443
pastebin.com
CLOUDFLARENET
shared

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 52.140.118.28
  • 51.104.136.2
  • 51.124.78.146
whitelisted
google.com
  • 172.217.18.14
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
login.live.com
  • 20.190.159.68
  • 20.190.159.23
  • 20.190.159.4
  • 20.190.159.2
  • 20.190.159.73
  • 40.126.31.67
  • 20.190.159.0
  • 20.190.159.71
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
pastebin.com
  • 104.20.3.235
  • 172.67.19.24
  • 104.20.4.235
shared
firebasestorage.googleapis.com
  • 142.250.186.42
  • 142.250.186.170
  • 142.250.186.138
  • 142.250.185.106
  • 142.250.181.234
  • 142.250.185.74
  • 172.217.18.106
  • 142.250.185.234
  • 142.250.185.202
  • 142.250.185.170
  • 142.250.186.106
  • 142.250.185.138
  • 172.217.18.10
  • 142.250.184.234
  • 172.217.16.138
  • 142.250.186.74
whitelisted
closen.kozow.com
  • 192.3.101.17
malicious
geoplugin.net
  • 178.237.33.50
malicious
slscr.update.microsoft.com
  • 20.114.59.183
whitelisted

Threats

PID
Process
Class
Message
2256
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Online Pastebin Text Storage
2700
wscript.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to connect to TLS FireBase Storage
6696
powershell.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to connect to TLS FireBase Storage
2256
svchost.exe
Potentially Bad Traffic
ET INFO DYNAMIC_DNS Query to a *.kozow .com Domain
6652
RegAsm.exe
Malware Command and Control Activity Detected
ET MALWARE Remcos 3.x Unencrypted Checkin
6652
RegAsm.exe
Malware Command and Control Activity Detected
ET MALWARE Remcos 3.x Unencrypted Server Response
6652
RegAsm.exe
Malware Command and Control Activity Detected
ET MALWARE Remcos 3.x Unencrypted Server Response
7 ETPRO signatures available at the full report
No debug info