| File name: | MaryWatters.wsf |
| Full analysis: | https://app.any.run/tasks/35fd18dd-4478-43d6-a6aa-c88dfeb1d6fe |
| Verdict: | Malicious activity |
| Analysis date: | May 15, 2025, 13:02:37 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | text/html |
| File info: | HTML document, ASCII text, with CRLF line terminators |
| MD5: | 3CD511CE2A070946739C55B8A3DAEC98 |
| SHA1: | 41B5B46C8035CFD26EDAFFD16A32DEAF93E316DD |
| SHA256: | 4ADDDED66ED92FA76BAE32CFC577FC892B4B34E115C8B116D60C9340B382DD92 |
| SSDEEP: | 1536:iIzbJeeGUJIgg2/A+ZfukgKo9kNxyJ3OOjll68fef0qu7iE5ToGauKTYL7TBHQ/m:iIzbJXGUJtL/A+ZfUl6yqfs80 |
| .html | | | HyperText Markup Language (100) |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 300 | certutil -v -store -silent root | C:\Windows\System32\certutil.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: CertUtil.exe Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 684 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 780 | reg export "HKLM\SOFTWARE\Policies\Microsoft\Windows\Wireless\GPTWirelessPolicy" C:\Users\admin\AppData\Local\Temp\Reg\GPT.reg.txt /y | C:\Windows\System32\reg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Console Tool Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 780 | "C:\Windows\System32\cmd.exe" /c netsh advfirewall firewall show rule name=all verbose >> C:\Users\admin\AppData\Local\Temp\WindowsFirewallConfig.txt | C:\Windows\System32\cmd.exe | — | wscript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 856 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 920 | "C:\Windows\System32\cmd.exe" /c netsh lan show settings >> C:\Users\admin\AppData\Local\Temp\envinfo.txt | C:\Windows\System32\cmd.exe | — | wscript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1020 | "C:\Windows\System32\cmd.exe" /c echo ------------------------------------------------------------------------ >> C:\Users\admin\AppData\Local\Temp\WindowsFirewallConfig.txt | C:\Windows\System32\cmd.exe | — | wscript.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1040 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1072 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1096 | netsh wlan show device | C:\Windows\System32\netsh.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Network Command Shell Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (2852) TiWorker.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing |
| Operation: | write | Name: | SessionIdHigh |
Value: 31180185 | |||
| (PID) Process: | (2852) TiWorker.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing |
| Operation: | write | Name: | SessionIdLow |
Value: | |||
| (PID) Process: | (3032) dxdiag.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\DirectX Diagnostic Tool |
| Operation: | write | Name: | DxDiag In SystemInfo |
Value: 1 | |||
| (PID) Process: | (3032) dxdiag.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\DirectX Diagnostic Tool |
| Operation: | delete value | Name: | DxDiag In DirectDraw |
Value: | |||
| (PID) Process: | (3032) dxdiag.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\DirectX Diagnostic Tool |
| Operation: | write | Name: | DxDiag In DirectSound |
Value: 1 | |||
| (PID) Process: | (3032) dxdiag.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\DirectX Diagnostic Tool |
| Operation: | delete value | Name: | DxDiag In DirectSound |
Value: | |||
| (PID) Process: | (3032) dxdiag.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\DirectX Diagnostic Tool |
| Operation: | write | Name: | DxDiag In VideoCapture |
Value: 1 | |||
| (PID) Process: | (3032) dxdiag.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\DirectX Diagnostic Tool |
| Operation: | delete value | Name: | DxDiag In SystemInfo |
Value: | |||
| (PID) Process: | (3032) dxdiag.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\DirectX Diagnostic Tool |
| Operation: | write | Name: | DxDiag In DirectDraw |
Value: 1 | |||
| (PID) Process: | (3032) dxdiag.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\DirectX Diagnostic Tool |
| Operation: | delete value | Name: | DxDiag In VideoCapture |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7752 | reg.exe | C:\Users\admin\AppData\Local\Temp\REGC3EE.tmp | text | |
MD5:9B854EFE8795D80357D5515CC1D4186F | SHA256:AA7CFB6E102C4D6E38EB3DCA4F3DF416B9657C808B8DDFC4D284627BE9C14803 | |||
| 7752 | reg.exe | C:\Users\admin\AppData\Local\Temp\Reg\Notif.reg.txt | text | |
MD5:9B854EFE8795D80357D5515CC1D4186F | SHA256:AA7CFB6E102C4D6E38EB3DCA4F3DF416B9657C808B8DDFC4D284627BE9C14803 | |||
| 7972 | reg.exe | C:\Users\admin\AppData\Local\Temp\Reg\AllCredFilter.reg.txt | text | |
MD5:9A5A295EFDC30925C631166A5D041BD3 | SHA256:88275B3C833910726328D29FB29F50FF6E5D357E8D3F316362C6D709D5FA5EF5 | |||
| 7860 | reg.exe | C:\Users\admin\AppData\Local\Temp\REGC526.tmp | text | |
MD5:C64DC9068CE4ECC37DBD1F7EC4C18466 | SHA256:FFA3724BE323FBDA2358F7902FEB0DF35D7A9F8C4B817D4430776D666996938C | |||
| 7860 | reg.exe | C:\Users\admin\AppData\Local\Temp\Reg\AllCred.reg.txt | text | |
MD5:C64DC9068CE4ECC37DBD1F7EC4C18466 | SHA256:FFA3724BE323FBDA2358F7902FEB0DF35D7A9F8C4B817D4430776D666996938C | |||
| 5392 | reg.exe | C:\Users\admin\AppData\Local\Temp\Reg\HKLMWlanSvc.reg.txt | text | |
MD5:87F2A9E5A4192112D2E96CAE2B4254AA | SHA256:9D3B9148E6377CB110B6BD989846BC6574C90BF65E0095A998731490235B13B7 | |||
| 7972 | reg.exe | C:\Users\admin\AppData\Local\Temp\REGC94D.tmp | text | |
MD5:9A5A295EFDC30925C631166A5D041BD3 | SHA256:88275B3C833910726328D29FB29F50FF6E5D357E8D3F316362C6D709D5FA5EF5 | |||
| 2852 | TiWorker.exe | C:\Windows\Logs\CBS\CBS.log | text | |
MD5:D9EE67AB81B7A1A19F527F69FB8B1E1D | SHA256:141DB977921BE02AC7C9244402F8F3D7EFA4FA60C2BF7E570026DADCF0E99C16 | |||
| 5392 | reg.exe | C:\Users\admin\AppData\Local\Temp\REGCD64.tmp | text | |
MD5:87F2A9E5A4192112D2E96CAE2B4254AA | SHA256:9D3B9148E6377CB110B6BD989846BC6574C90BF65E0095A998731490235B13B7 | |||
| 2040 | cmd.exe | C:\Users\admin\AppData\Local\Temp\envinfo.txt | text | |
MD5:5AC753CCED8259823D9C2215B210156D | SHA256:698234E927A731661284FE17D8C8EC5C0ED19D47A9D2C9F124E9C5B2DC6DE8ED | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6148 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
1328 | SIHClient.exe | GET | 200 | 23.48.23.169:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1328 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.1.crl | unknown | — | — | whitelisted |
6148 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
1328 | SIHClient.exe | GET | 200 | 23.48.23.169:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl | unknown | — | — | whitelisted |
1328 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
1328 | SIHClient.exe | GET | 200 | 23.48.23.169:80 | http://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl | unknown | — | — | whitelisted |
1328 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.1.crl | unknown | — | — | whitelisted |
1328 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.2.crl | unknown | — | — | whitelisted |
1328 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.2.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2104 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5496 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3216 | svchost.exe | 172.211.123.250:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6148 | firefox.exe | 34.107.221.82:80 | detectportal.firefox.com | GOOGLE | US | whitelisted |
6544 | svchost.exe | 20.190.160.3:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2104 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5496 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
example.org |
| whitelisted |
ipv4only.arpa |
| whitelisted |
login.live.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
5308 | curl.exe | Potentially Bad Traffic | ET HUNTING curl User-Agent to Dotted Quad |