URL:

benefits-us.com/ssa/statement/

Full analysis: https://app.any.run/tasks/24779f9b-c4ff-4724-bc6b-83657b753b29
Verdict: Malicious activity
Threats:

AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.

Analysis date: October 03, 2025, 16:27:53
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
pdqconnect
rmm-tool
anti-evasion
websocket
screenconnect
remote
rat
asyncrat
stealer
rust
purecrypter
Indicators:
MD5:

4D29830DB006E4ACC9EBB0137A566BAD

SHA1:

694A438C3BFD5DA15029331615EB9378B89682A0

SHA256:

49039BF094CC63ABFFF436688A8B23D1CAAAC520883BDBAAA21489CB67F5B124

SSDEEP:

3:oyMGBW+IuRK:oABvRK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Bypass execution policy to execute commands

      • powershell.exe (PID: 9344)
      • powershell.exe (PID: 4948)
      • powershell.exe (PID: 9568)
      • powershell.exe (PID: 7736)
      • powershell.exe (PID: 3644)
      • powershell.exe (PID: 5040)
      • powershell.exe (PID: 10232)
      • powershell.exe (PID: 2416)
      • powershell.exe (PID: 9928)
      • powershell.exe (PID: 8452)
      • powershell.exe (PID: 10080)
      • powershell.exe (PID: 8664)
      • powershell.exe (PID: 8936)
      • powershell.exe (PID: 5552)
      • powershell.exe (PID: 8892)
      • powershell.exe (PID: 8100)
      • powershell.exe (PID: 6456)
      • powershell.exe (PID: 1132)
      • powershell.exe (PID: 9416)
      • powershell.exe (PID: 9964)
      • powershell.exe (PID: 8652)
      • powershell.exe (PID: 9432)
      • powershell.exe (PID: 10384)
      • powershell.exe (PID: 2900)
      • powershell.exe (PID: 8820)
      • powershell.exe (PID: 8448)
      • powershell.exe (PID: 9324)
      • powershell.exe (PID: 10688)
      • powershell.exe (PID: 6132)
      • powershell.exe (PID: 9316)
      • powershell.exe (PID: 7136)
      • powershell.exe (PID: 5548)
      • powershell.exe (PID: 3644)
      • powershell.exe (PID: 10668)
      • powershell.exe (PID: 8200)
      • powershell.exe (PID: 7140)
      • powershell.exe (PID: 9416)
      • powershell.exe (PID: 10284)
    • Changes powershell execution policy (Bypass)

      • pdq-connect-agent.exe (PID: 4432)
      • wscript.exe (PID: 10700)
      • wscript.exe (PID: 10180)
      • wscript.exe (PID: 7776)
    • Collects BIOS Properties (Win32_BIOS) (SCRIPT)

      • powershell.exe (PID: 7736)
    • SCREENCONNECT has been detected (SURICATA)

      • ScreenConnect.ClientService.exe (PID: 9540)
    • Actions looks like stealing of personal data

      • powershell.exe (PID: 6132)
      • aspnet_compiler.exe (PID: 10444)
    • Steals credentials from Web Browsers

      • powershell.exe (PID: 6132)
      • aspnet_compiler.exe (PID: 10444)
    • ASYNCRAT has been detected (SURICATA)

      • powershell.exe (PID: 6132)
    • Accesses installed system drivers(Win32_SystemDriver) (SCRIPT)

      • powershell.exe (PID: 10376)
      • powershell.exe (PID: 10504)
    • Accesses system services(Win32_Service) (SCRIPT)

      • powershell.exe (PID: 9484)
      • powershell.exe (PID: 10724)
    • PURECRYPTER has been detected (SURICATA)

      • aspnet_compiler.exe (PID: 10444)
    • Scans artifacts that could help determine the target

      • aspnet_compiler.exe (PID: 10444)
    • Connects to the CnC server

      • aspnet_compiler.exe (PID: 10444)
  • SUSPICIOUS

    • Application launched itself

      • msiexec.exe (PID: 9596)
      • powershell.exe (PID: 9964)
      • ScreenConnect.WindowsClient.exe (PID: 9364)
      • powershell.exe (PID: 3644)
    • Uses RUNDLL32.EXE to load library

      • msiexec.exe (PID: 10176)
      • msiexec.exe (PID: 6936)
      • msiexec.exe (PID: 8084)
    • Executable content was dropped or overwritten

      • rundll32.exe (PID: 10216)
      • rundll32.exe (PID: 9336)
      • rundll32.exe (PID: 9416)
      • rundll32.exe (PID: 9432)
      • rundll32.exe (PID: 6924)
      • pdq-connect-agent.exe (PID: 4432)
      • rundll32.exe (PID: 9928)
      • rundll32.exe (PID: 3644)
      • ConnectWiseControl.ClientSetup.exe (PID: 9160)
      • rundll32.exe (PID: 932)
      • csc.exe (PID: 10168)
      • powershell.exe (PID: 8664)
      • powershell.exe (PID: 2900)
      • csc.exe (PID: 9864)
    • Starts SC.EXE for service management

      • rundll32.exe (PID: 6924)
    • Executes as Windows Service

      • pdq-connect-agent.exe (PID: 4432)
      • pdq-connect-updater.exe (PID: 10148)
      • ScreenConnect.ClientService.exe (PID: 9540)
      • WmiApSrv.exe (PID: 8680)
    • Windows service management via SC.EXE

      • sc.exe (PID: 9760)
    • PDQConnect is probably used for system patching and software deployment

      • sc.exe (PID: 9760)
    • The process bypasses the loading of PowerShell profile settings

      • pdq-connect-agent.exe (PID: 4432)
      • powershell.exe (PID: 9964)
      • powershell.exe (PID: 3644)
    • The process hide an interactive prompt from the user

      • pdq-connect-agent.exe (PID: 4432)
    • The process hides Powershell's copyright startup banner

      • pdq-connect-agent.exe (PID: 4432)
      • powershell.exe (PID: 9964)
      • powershell.exe (PID: 3644)
    • Starts POWERSHELL.EXE for commands execution

      • pdq-connect-agent.exe (PID: 4432)
      • powershell.exe (PID: 9964)
      • wscript.exe (PID: 7776)
      • powershell.exe (PID: 3644)
      • wscript.exe (PID: 10700)
      • wscript.exe (PID: 10180)
    • Creates new GUID (POWERSHELL)

      • powershell.exe (PID: 9344)
      • powershell.exe (PID: 8664)
      • powershell.exe (PID: 2900)
    • Enumerates operating system information (Win32_OperatingSystem) (SCRIPT)

      • powershell.exe (PID: 9568)
      • powershell.exe (PID: 10232)
      • powershell.exe (PID: 8452)
      • powershell.exe (PID: 8664)
      • powershell.exe (PID: 2900)
      • powershell.exe (PID: 10408)
      • powershell.exe (PID: 9776)
    • Reads security settings of Internet Explorer

      • ConnectWiseControl.ClientSetup.exe (PID: 9160)
      • ScreenConnect.WindowsClient.exe (PID: 9364)
      • ScreenConnect.ClientService.exe (PID: 9540)
      • ScreenConnect.WindowsClient.exe (PID: 10136)
      • ScreenConnect.WindowsClient.exe (PID: 4092)
    • Screenconnect has been detected

      • msiexec.exe (PID: 9596)
    • SCREENCONNECT mutex has been found

      • ScreenConnect.ClientService.exe (PID: 9540)
    • Reads the Windows owner or organization settings

      • msiexec.exe (PID: 9596)
    • Potential Corporate Privacy Violation

      • ScreenConnect.ClientService.exe (PID: 9540)
    • Connects to unusual port

      • ScreenConnect.ClientService.exe (PID: 9540)
      • powershell.exe (PID: 6132)
      • aspnet_compiler.exe (PID: 10444)
    • CSC.EXE is used to compile C# code

      • csc.exe (PID: 10168)
      • csc.exe (PID: 9864)
    • The process creates files with name similar to system file names

      • powershell.exe (PID: 8664)
      • powershell.exe (PID: 2900)
    • Detected use of alternative data streams (AltDS)

      • powershell.exe (PID: 8664)
      • powershell.exe (PID: 2900)
    • Process drops legitimate windows executable

      • powershell.exe (PID: 8664)
      • powershell.exe (PID: 2900)
    • Starts a Microsoft application from unusual location

      • DismHost.exe (PID: 8716)
      • DismHost.exe (PID: 9276)
    • There is functionality for taking screenshot (YARA)

      • ScreenConnect.ClientService.exe (PID: 9540)
      • ScreenConnect.WindowsClient.exe (PID: 9364)
    • Detects ScreenConnect RAT (YARA)

      • ScreenConnect.ClientService.exe (PID: 9540)
      • ScreenConnect.WindowsClient.exe (PID: 9364)
    • Reads the date of Windows installation

      • ScreenConnect.WindowsClient.exe (PID: 9364)
      • ScreenConnect.WindowsClient.exe (PID: 4092)
    • Manipulates environment variables

      • powershell.exe (PID: 6132)
      • powershell.exe (PID: 9416)
      • powershell.exe (PID: 10284)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 7776)
      • wscript.exe (PID: 10700)
      • wscript.exe (PID: 10180)
    • The process executes VB scripts

      • ScreenConnect.WindowsClient.exe (PID: 4092)
    • Probably obfuscated PowerShell command line is found

      • wscript.exe (PID: 7776)
      • wscript.exe (PID: 10700)
      • wscript.exe (PID: 10180)
    • Contacting a server suspected of hosting an CnC

      • powershell.exe (PID: 6132)
    • The process executes via Task Scheduler

      • wscript.exe (PID: 10700)
      • wscript.exe (PID: 10180)
  • INFO

    • Reads Environment values

      • identity_helper.exe (PID: 9212)
      • pdq-connect-agent.exe (PID: 4432)
      • ScreenConnect.WindowsClient.exe (PID: 9364)
      • ScreenConnect.WindowsClient.exe (PID: 10136)
      • DismHost.exe (PID: 8716)
      • DismHost.exe (PID: 9276)
      • ScreenConnect.WindowsClient.exe (PID: 4092)
    • Reads Microsoft Office registry keys

      • msedge.exe (PID: 6176)
      • ScreenConnect.WindowsClient.exe (PID: 4092)
      • aspnet_compiler.exe (PID: 10444)
    • Application launched itself

      • msedge.exe (PID: 6176)
      • chrome.exe (PID: 8616)
      • msedge.exe (PID: 4216)
    • Checks supported languages

      • identity_helper.exe (PID: 9212)
      • msiexec.exe (PID: 10176)
      • msiexec.exe (PID: 9596)
      • pdq-connect-agent.exe (PID: 4432)
      • msiexec.exe (PID: 6936)
      • msiexec.exe (PID: 8084)
      • pdq-connect-updater.exe (PID: 10148)
      • ConnectWiseControl.ClientSetup.exe (PID: 9160)
      • msiexec.exe (PID: 9200)
      • ScreenConnect.WindowsClient.exe (PID: 9364)
      • ScreenConnect.ClientService.exe (PID: 9540)
      • ScreenConnect.WindowsClient.exe (PID: 10136)
      • csc.exe (PID: 10168)
      • cvtres.exe (PID: 2396)
      • DismHost.exe (PID: 8716)
      • DismHost.exe (PID: 9276)
      • ScreenConnect.WindowsClient.exe (PID: 4092)
      • csc.exe (PID: 9864)
      • cvtres.exe (PID: 4852)
      • aspnet_compiler.exe (PID: 10444)
    • Reads the computer name

      • msiexec.exe (PID: 10176)
      • identity_helper.exe (PID: 9212)
      • msiexec.exe (PID: 6936)
      • pdq-connect-agent.exe (PID: 4432)
      • msiexec.exe (PID: 8084)
      • pdq-connect-updater.exe (PID: 10148)
      • ConnectWiseControl.ClientSetup.exe (PID: 9160)
      • msiexec.exe (PID: 9200)
      • ScreenConnect.ClientService.exe (PID: 9540)
      • ScreenConnect.WindowsClient.exe (PID: 9364)
      • msiexec.exe (PID: 9596)
      • ScreenConnect.WindowsClient.exe (PID: 10136)
      • DismHost.exe (PID: 8716)
      • DismHost.exe (PID: 9276)
      • ScreenConnect.WindowsClient.exe (PID: 4092)
      • aspnet_compiler.exe (PID: 10444)
    • Create files in a temporary directory

      • rundll32.exe (PID: 10216)
      • rundll32.exe (PID: 9336)
    • Reads security settings of Internet Explorer

      • msiexec.exe (PID: 9528)
    • Reads the software policy settings

      • msiexec.exe (PID: 9528)
      • pdq-connect-agent.exe (PID: 4432)
      • pdq-connect-updater.exe (PID: 10148)
      • msiexec.exe (PID: 9596)
      • slui.exe (PID: 9752)
    • The sample compiled with english language support

      • msiexec.exe (PID: 9596)
      • powershell.exe (PID: 8664)
      • powershell.exe (PID: 2900)
    • PDQCONNECT has been detected

      • msiexec.exe (PID: 6936)
      • rundll32.exe (PID: 6924)
      • pdq-connect-agent.exe (PID: 4432)
      • powershell.exe (PID: 2416)
    • Creates files in the program directory

      • rundll32.exe (PID: 9432)
      • pdq-connect-agent.exe (PID: 4432)
      • msiexec.exe (PID: 6112)
      • powershell.exe (PID: 6132)
    • Creates a software uninstall entry

      • msiexec.exe (PID: 9596)
    • Uses string replace method (POWERSHELL)

      • powershell.exe (PID: 9344)
      • powershell.exe (PID: 9928)
      • powershell.exe (PID: 8664)
      • powershell.exe (PID: 2900)
      • powershell.exe (PID: 6132)
      • powershell.exe (PID: 5548)
      • powershell.exe (PID: 9872)
      • powershell.exe (PID: 788)
    • Process checks computer location settings

      • pdq-connect-agent.exe (PID: 4432)
      • ScreenConnect.WindowsClient.exe (PID: 4092)
      • ScreenConnect.WindowsClient.exe (PID: 9364)
    • Application based on Rust

      • pdq-connect-agent.exe (PID: 4432)
      • pdq-connect-updater.exe (PID: 10148)
    • Reads the machine GUID from the registry

      • ConnectWiseControl.ClientSetup.exe (PID: 9160)
      • ScreenConnect.ClientService.exe (PID: 9540)
      • ScreenConnect.WindowsClient.exe (PID: 9364)
      • msiexec.exe (PID: 9596)
      • ScreenConnect.WindowsClient.exe (PID: 10136)
      • csc.exe (PID: 10168)
      • ScreenConnect.WindowsClient.exe (PID: 4092)
      • csc.exe (PID: 9864)
      • aspnet_compiler.exe (PID: 10444)
    • CONNECTWISE has been detected

      • msiexec.exe (PID: 9596)
      • ScreenConnect.ClientService.exe (PID: 9540)
      • ScreenConnect.WindowsClient.exe (PID: 9364)
      • ScreenConnect.WindowsClient.exe (PID: 10136)
      • powershell.exe (PID: 8652)
      • powershell.exe (PID: 9972)
      • powershell.exe (PID: 8820)
      • ScreenConnect.WindowsClient.exe (PID: 4092)
      • powershell.exe (PID: 8980)
    • SCREENCONNECT has been detected

      • msiexec.exe (PID: 9596)
    • Manages system restore points

      • SrTasks.exe (PID: 10020)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 9596)
    • Reads CPU info

      • ScreenConnect.WindowsClient.exe (PID: 10136)
    • Reads product name

      • ScreenConnect.WindowsClient.exe (PID: 10136)
    • Uses string split method (POWERSHELL)

      • powershell.exe (PID: 9928)
      • powershell.exe (PID: 6132)
      • powershell.exe (PID: 5548)
      • powershell.exe (PID: 9416)
      • powershell.exe (PID: 10284)
    • Reads Windows Product ID

      • powershell.exe (PID: 8664)
      • powershell.exe (PID: 2900)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 9416)
      • powershell.exe (PID: 8664)
      • powershell.exe (PID: 2900)
      • powershell.exe (PID: 8668)
      • powershell.exe (PID: 11168)
      • powershell.exe (PID: 8200)
      • powershell.exe (PID: 9132)
      • powershell.exe (PID: 10264)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 9416)
    • Gets data length (POWERSHELL)

      • powershell.exe (PID: 2900)
      • powershell.exe (PID: 8664)
    • Checks proxy server information

      • slui.exe (PID: 9752)
      • powershell.exe (PID: 6132)
    • Gets or sets the time when the file was last written to (POWERSHELL)

      • powershell.exe (PID: 6132)
    • Disables trace logs

      • powershell.exe (PID: 6132)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
415
Monitored processes
238
Malicious processes
11
Suspicious processes
16

Behavior graph

Click at the process to see the details
start iexplore.exe no specs msedge.exe msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msiexec.exe no specs msiexec.exe srtasks.exe no specs conhost.exe no specs msiexec.exe no specs rundll32.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs rundll32.exe msiexec.exe no specs rundll32.exe rundll32.exe rundll32.exe sc.exe no specs conhost.exe no specs pdq-connect-agent.exe msiexec.exe no specs msiexec.exe no specs rundll32.exe rundll32.exe pdq-connect-updater.exe powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs slui.exe powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs msedge.exe no specs connectwisecontrol.clientsetup.exe msiexec.exe no specs msiexec.exe no specs rundll32.exe #SCREENCONNECT screenconnect.clientservice.exe #SCREENCONNECT screenconnect.windowsclient.exe no specs screenconnect.windowsclient.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe conhost.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs csc.exe cvtres.exe no specs powershell.exe no specs powershell.exe no specs conhost.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs dsregcmd.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs tiworker.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs dismhost.exe powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe conhost.exe no specs powershell.exe no specs conhost.exe no specs wmiapsrv.exe no specs powershell.exe no specs conhost.exe no specs msedge.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs dismhost.exe powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs screenconnect.windowsclient.exe no specs wscript.exe no specs #ASYNCRAT powershell.exe conhost.exe no specs msedge.exe no specs powershell.exe no specs conhost.exe no specs dsregcmd.exe no specs msedge.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs csc.exe cvtres.exe no specs powershell.exe no specs conhost.exe no specs svchost.exe powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs wscript.exe no specs powershell.exe no specs conhost.exe no specs msedge.exe no specs wscript.exe no specs powershell.exe no specs conhost.exe no specs msedge.exe no specs #PURECRYPTER aspnet_compiler.exe chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
756"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --user-data-dir="C:\Users\admin\AppData\Local\Temp\mccn2vza.ivt" --no-sandbox --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=15 --always-read-main-dll --field-trial-handle=3828,i,3435161596936312966,7248103920568448287,262144 --variations-seed-version --mojo-platform-channel-handle=3856 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
788"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -Version 5.1 -s -NoLogo -NoProfileC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exepowershell.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows PowerShell
Exit code:
4294967295
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
932rundll32.exe "C:\WINDOWS\Installer\MSI53B9.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_1594375 86 ScreenConnect.InstallerActions!ScreenConnect.ClientInstallerActions.FixupServiceArgumentsC:\Windows\SysWOW64\rundll32.exe
msiexec.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
1048\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1132"powershell.exe" -NoLogo -NonInteractive -NoProfile -ExecutionPolicy Bypass -Command -C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exepdq-connect-agent.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows PowerShell
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2008\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2008\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2124"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6984,i,6320865298885709099,2697078541980689935,262144 --variations-seed-version --mojo-platform-channel-handle=6900 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2128\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2152\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
132 715
Read events
132 311
Write events
367
Delete events
37

Modification events

(PID) Process:(7000) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\UrlBlock
Operation:writeName:L1WatermarkLowPart
Value:
0
(PID) Process:(7000) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\UrlBlock
Operation:writeName:L1WatermarkHighPart
Value:
0
(PID) Process:(7000) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\UrlBlock
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
0
(PID) Process:(7000) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\UrlBlock
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
0
(PID) Process:(7000) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\UrlBlock
Operation:writeName:NextCheckForUpdateLowDateTime
Value:
(PID) Process:(7000) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\UrlBlock
Operation:writeName:NextCheckForUpdateHighDateTime
Value:
31208578
(PID) Process:(7000) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7000) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7000) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7000) iexplore.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
Executable files
181
Suspicious files
637
Text files
323
Unknown types
0

Dropped files

PID
Process
Filename
Type
6176msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF171174.TMP
MD5:
SHA256:
6176msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old~RF171174.TMP
MD5:
SHA256:
6176msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old~RF171174.TMP
MD5:
SHA256:
6176msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old
MD5:
SHA256:
6176msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\PersistentOriginTrials\LOG.old
MD5:
SHA256:
6176msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\parcel_tracking_db\LOG.old
MD5:
SHA256:
6176msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old~RF171165.TMP
MD5:
SHA256:
6176msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\ClientCertificates\LOG.old
MD5:
SHA256:
6176msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF171184.TMP
MD5:
SHA256:
6176msedge.exeC:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
32
TCP/UDP connections
153
DNS requests
161
Threats
68

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2840
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
8704
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
313 b
whitelisted
6176
msedge.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D
US
binary
471 b
whitelisted
6176
msedge.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D
US
binary
727 b
whitelisted
6176
msedge.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEAZ4BOCrCqbwPVOB48I4p0g%3D
US
binary
727 b
whitelisted
9140
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
whitelisted
7088
svchost.exe
HEAD
200
185.160.60.100:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/ddbf4492-d475-4fe4-bcde-6cbac56f6034?P1=1759842019&P2=404&P3=2&P4=e4uLVnuN6oQRdnaILYClhL6p52dDbqrhmwvfiz6%2fpe2QGP70dwhZmr25KiRHqXltVfBrrg0rWY2Z3g5f8CUgpA%3d%3d
UA
whitelisted
7088
svchost.exe
GET
206
185.160.60.100:80
http://msedge.b.tlu.dl.delivery.mp.microsoft.com/filestreamingservice/files/ddbf4492-d475-4fe4-bcde-6cbac56f6034?P1=1759842019&P2=404&P3=2&P4=e4uLVnuN6oQRdnaILYClhL6p52dDbqrhmwvfiz6%2fpe2QGP70dwhZmr25KiRHqXltVfBrrg0rWY2Z3g5f8CUgpA%3d%3d
UA
binary
1.09 Kb
whitelisted
2840
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
796
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6016
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
992
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5224
SearchApp.exe
2.16.241.204:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4176
msedge.exe
150.171.27.11:80
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4176
msedge.exe
150.171.22.17:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4176
msedge.exe
150.171.27.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4176
msedge.exe
104.26.8.137:443
benefits-us.com
CLOUDFLARENET
US
unknown
4176
msedge.exe
2.16.241.224:443
copilot.microsoft.com
Akamai International B.V.
DE
whitelisted
4176
msedge.exe
35.190.80.1:443
a.nel.cloudflare.com
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
www.bing.com
  • 2.16.241.204
  • 2.16.241.205
  • 2.16.241.207
  • 2.16.241.218
  • 2.16.241.201
  • 2.16.241.222
  • 2.16.241.206
  • 95.100.100.130
  • 95.100.100.129
  • 95.100.100.113
  • 95.100.100.107
whitelisted
google.com
  • 172.217.18.110
whitelisted
edge.microsoft.com
  • 150.171.27.11
  • 150.171.28.11
whitelisted
config.edge.skype.com
  • 150.171.22.17
whitelisted
benefits-us.com
  • 104.26.8.137
  • 172.67.74.75
  • 104.26.9.137
unknown
copilot.microsoft.com
  • 2.16.241.224
  • 2.16.241.220
  • 95.100.100.115
  • 95.100.100.123
whitelisted
a.nel.cloudflare.com
  • 35.190.80.1
whitelisted
challenges.cloudflare.com
  • 104.18.94.41
  • 104.18.95.41
whitelisted
update.googleapis.com
  • 142.250.186.67
whitelisted

Threats

PID
Process
Class
Message
4176
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
4176
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
4176
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge
Potentially Bad Traffic
SUSPICIOUS [ANY.RUN] Challenge-Platform Page Request to cdn-cgi
4176
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare turnstile CAPTCHA challenge
Potentially Bad Traffic
SUSPICIOUS [ANY.RUN] Challenge-Platform Page Request to cdn-cgi
Potentially Bad Traffic
ET INFO Possible Chrome Plugin install
2428
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare R2 Storage (r2 .cloudflarestorage .com)
A Network Trojan was detected
ET INFO PDQ Remote Management HTTP Header Observed (x-pdq-key-ids)
A Network Trojan was detected
ET INFO PDQ Remote Management User-Agent Observed (PDQ rover)
Process
Message
powershell.exe
PID=8664 TID=9324 DismApi.dll: - DismInitializeInternal
powershell.exe
PID=8664 TID=9324 DismApi.dll: <----- Starting DismApi.dll session -----> - DismInitializeInternal
powershell.exe
PID=8664 TID=9324 DismApi.dll: - DismInitializeInternal
powershell.exe
PID=8664 TID=9324 DismApi.dll: Host machine information: OS Version=10.0.19045, Running architecture=amd64, Number of processors=6 - DismInitializeInternal
powershell.exe
PID=8664 TID=9324 DismApi.dll: API Version 10.0.19041.3758 - DismInitializeInternal
powershell.exe
PID=8664 TID=9324 DismApi.dll: Parent process command line: "powershell.exe" -NoLogo -NonInteractive -NoProfile -ExecutionPolicy Bypass -Command - - DismInitializeInternal
powershell.exe
PID=8664 TID=9324 Enter DismInitializeInternal - DismInitializeInternal
powershell.exe
PID=8664 TID=9324 Input parameters: LogLevel: 2, LogFilePath: C:\WINDOWS\Logs\DISM\dism.log, ScratchDirectory: (null) - DismInitializeInternal
powershell.exe
PID=8664 TID=9324 Initialized GlobalConfig - DismInitializeInternal
powershell.exe
PID=8664 TID=9324 Initialized SessionTable - DismInitializeInternal