File name:

55c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exe

Full analysis: https://app.any.run/tasks/7e361eed-b6b7-4b0f-97f7-f9e88f651bdf
Verdict: Malicious activity
Analysis date: October 03, 2025, 17:31:44
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
m0yv
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 6 sections
MD5:

06288B4CF76D49EA27AF44F5D1B7A8B4

SHA1:

CF4EA3D206685E39D69AF8DBC8A56519CB2B8A5F

SHA256:

55C0030280B7A9480B660E77F036F68703E4474E338A02B784F1D84BC3C70223

SSDEEP:

49152:b6JuX1F4SpdjARBZfUg79ggts8Poo71k1C/xH0lWV0rgtPtsvIhgd9jeWRn1:b4+Pdj89ggtsFo71k12PV3Ftvgd9/n

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • M0YV mutex has been found

      • 55c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exe (PID: 5904)
      • FlashPlayerUpdateService.exe (PID: 6080)
      • AppVClient.exe (PID: 7792)
      • DiagnosticsHub.StandardCollector.Service.exe (PID: 576)
      • armsvc.exe (PID: 2652)
      • MicrosoftEdgeUpdate.exe (PID: 6780)
      • GameInputSvc.exe (PID: 6344)
      • elevation_service.exe (PID: 5292)
      • updater.exe (PID: 1588)
      • updater.exe (PID: 5796)
      • updater.exe (PID: 3136)
      • elevation_service.exe (PID: 5944)
      • GameInputSvc.exe (PID: 6340)
      • updater.exe (PID: 5696)
      • maintenanceservice.exe (PID: 3420)
      • updater.exe (PID: 3264)
      • updater.exe (PID: 1924)
      • PerceptionSimulationService.exe (PID: 8296)
      • PSEXESVC.exe (PID: 8440)
      • perfhost.exe (PID: 8396)
      • Spectrum.exe (PID: 8656)
      • ssh-agent.exe (PID: 8708)
    • Connects to the CnC server

      • svchost.exe (PID: 2428)
    • M0YV has been detected (SURICATA)

      • svchost.exe (PID: 2428)
    • M0YV has been detected (YARA)

      • armsvc.exe (PID: 2652)
      • 55c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exe (PID: 5904)
      • GameInputSvc.exe (PID: 6340)
      • DiagnosticsHub.StandardCollector.Service.exe (PID: 576)
      • alg.exe (PID: 708)
      • elevation_service.exe (PID: 5292)
      • GameInputSvc.exe (PID: 6344)
      • elevation_service.exe (PID: 5944)
      • PerceptionSimulationService.exe (PID: 8296)
      • perfhost.exe (PID: 8396)
      • msdtc.exe (PID: 6720)
      • PSEXESVC.exe (PID: 8440)
      • snmptrap.exe (PID: 8608)
      • Locator.exe (PID: 8540)
  • SUSPICIOUS

    • Executes as Windows Service

      • armsvc.exe (PID: 2652)
      • alg.exe (PID: 708)
      • FlashPlayerUpdateService.exe (PID: 6080)
      • DiagnosticsHub.StandardCollector.Service.exe (PID: 576)
      • AppVClient.exe (PID: 7792)
      • MicrosoftEdgeUpdate.exe (PID: 6780)
      • GameInputSvc.exe (PID: 6340)
      • updater.exe (PID: 5796)
      • FXSSVC.exe (PID: 2532)
      • maintenanceservice.exe (PID: 3420)
      • updater.exe (PID: 1924)
      • msdtc.exe (PID: 6720)
      • perfhost.exe (PID: 8396)
      • PerceptionSimulationService.exe (PID: 8296)
      • PSEXESVC.exe (PID: 8440)
      • SensorDataService.exe (PID: 8576)
      • snmptrap.exe (PID: 8608)
      • Spectrum.exe (PID: 8656)
      • TieringEngineService.exe (PID: 8788)
      • ssh-agent.exe (PID: 8708)
      • wbengine.exe (PID: 8924)
      • AgentService.exe (PID: 8860)
      • vds.exe (PID: 8888)
      • WmiApSrv.exe (PID: 8968)
      • Locator.exe (PID: 8540)
    • Process drops legitimate windows executable

      • 55c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exe (PID: 5904)
    • Executable content was dropped or overwritten

      • 55c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exe (PID: 5904)
    • Application launched itself

      • GameInputSvc.exe (PID: 6340)
  • INFO

    • The sample compiled with english language support

      • 55c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exe (PID: 5904)
    • Checks supported languages

      • 55c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exe (PID: 5904)
      • armsvc.exe (PID: 2652)
      • FlashPlayerUpdateService.exe (PID: 6080)
      • MicrosoftEdgeUpdate.exe (PID: 6780)
      • elevation_service.exe (PID: 5292)
      • maintenanceservice.exe (PID: 3420)
      • ssh-agent.exe (PID: 8708)
      • PSEXESVC.exe (PID: 8440)
    • Creates files or folders in the user directory

      • 55c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exe (PID: 5904)
    • Reads the computer name

      • FlashPlayerUpdateService.exe (PID: 6080)
      • 55c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exe (PID: 5904)
      • armsvc.exe (PID: 2652)
      • MicrosoftEdgeUpdate.exe (PID: 6780)
      • elevation_service.exe (PID: 5292)
      • maintenanceservice.exe (PID: 3420)
      • PSEXESVC.exe (PID: 8440)
      • ssh-agent.exe (PID: 8708)
    • Creates files in the program directory

      • FXSSVC.exe (PID: 2532)
      • maintenanceservice.exe (PID: 3420)
      • SearchIndexer.exe (PID: 9012)
    • Reads the software policy settings

      • GameInputSvc.exe (PID: 6344)
      • slui.exe (PID: 9772)
    • Executes as Windows Service

      • elevation_service.exe (PID: 5292)
      • SearchIndexer.exe (PID: 9012)
    • Checks proxy server information

      • 55c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exe (PID: 5904)
      • slui.exe (PID: 9772)
    • Reads the time zone

      • TieringEngineService.exe (PID: 8788)
    • The sample compiled with bulgarian language support

      • 55c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exe (PID: 5904)
    • Reads security settings of Internet Explorer

      • SearchProtocolHost.exe (PID: 9288)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2020:06:25 10:38:12+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14
CodeSize: 134656
InitializedDataSize: 301056
UninitializedDataSize: -
EntryPoint: 0xc440
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 5.91.0.0
ProductVersionNumber: 5.91.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
ProductName: WinRAR
CompanyName: Alexander Roshal
FileDescription: Uninstall WinRAR
FileVersion: 5.91.0
ProductVersion: 5.91.0
InternalName: Uninstall WinRAR
LegalCopyright: Copyright © Alexander Roshal 1993-2020
OriginalFileName: Uninstall.exe
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
209
Monitored processes
39
Malicious processes
27
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
576C:\WINDOWS\system32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exeC:\Windows\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft (R) Diagnostics Hub Standard Collector
Version:
11.00.19041.3930 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\diagsvcs\diagnosticshub.standardcollector.service.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\sechost.dll
708C:\WINDOWS\System32\alg.exeC:\Windows\System32\alg.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Application Layer Gateway Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\alg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
1588"C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe" --wake --systemC:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe
updater.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Updater
Exit code:
0
Version:
134.0.6985.0
Modules
Images
c:\program files (x86)\google\googleupdater\134.0.6985.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
1924"C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe" --system --windows-service --service=update-internalC:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe
services.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Updater
Exit code:
0
Version:
134.0.6985.0
Modules
Images
c:\program files (x86)\google\googleupdater\134.0.6985.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
2428C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2532C:\WINDOWS\system32\fxssvc.exeC:\Windows\System32\FXSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Fax Service
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\fxssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shlwapi.dll
2652"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe"C:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exe
services.exe
User:
SYSTEM
Company:
Adobe Inc.
Integrity Level:
SYSTEM
Description:
Acrobat Update Service
Version:
1.824.460.1042
Modules
Images
c:\program files (x86)\common files\adobe\arm\1.0\armsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
3136"C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=134.0.6985.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x2f4,0x2f8,0x2fc,0x2f0,0x300,0x8bc460,0x8bc46c,0x8bc478C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe
updater.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Updater
Exit code:
0
Version:
134.0.6985.0
Modules
Images
c:\program files (x86)\google\googleupdater\134.0.6985.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
3264"C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe" --crash-handler --system "--database=C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\Crashpad" --url=https://clients2.google.com/cr/report --annotation=prod=Update4 --annotation=ver=134.0.6985.0 "--attachment=C:\Program Files (x86)\Google\GoogleUpdater\updater.log" --initial-client-data=0x2f4,0x2f8,0x2fc,0x2f0,0x300,0x8bc460,0x8bc46c,0x8bc478C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe
updater.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Updater
Exit code:
0
Version:
134.0.6985.0
Modules
Images
c:\program files (x86)\google\googleupdater\134.0.6985.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
3420"C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe"C:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exe
services.exe
User:
SYSTEM
Company:
Mozilla Foundation
Integrity Level:
SYSTEM
Exit code:
0
Version:
136.0
Modules
Images
c:\program files (x86)\mozilla maintenance service\maintenanceservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shlwapi.dll
Total events
51 225
Read events
51 110
Write events
91
Delete events
24

Modification events

(PID) Process:(2532) FXSSVC.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fax
Operation:writeName:RedirectionGuard
Value:
1
(PID) Process:(2532) FXSSVC.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fax\Receipts
Operation:writeName:Password
Value:
00
(PID) Process:(2532) FXSSVC.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fax\Receipts
Operation:delete valueName:Password
Value:
(PID) Process:(2532) FXSSVC.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fax\Receipts
Operation:writeName:Server
Value:
(PID) Process:(2532) FXSSVC.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fax\Receipts
Operation:writeName:From
Value:
(PID) Process:(2532) FXSSVC.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fax\Receipts
Operation:writeName:User
Value:
(PID) Process:(2652) armsvc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Adobe\Adobe ARM\1.0\ARM
Operation:writeName:iLastSvcSuccess
Value:
1514875
(PID) Process:(8656) Spectrum.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\PerceptionSimulationExtensions
Operation:writeName:DeviceId
Value:
{9DFBC949-BF64-4C87-866C-AD2904CA35C3}
(PID) Process:(8708) ssh-agent.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\OpenSSH\Agent
Operation:writeName:ProcessID
Value:
8708
(PID) Process:(8656) Spectrum.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Spectrum
Operation:writeName:HeadCenterOfRotationFloat3
Value:
000000000AD7A3BD0AD7A33D
Executable files
140
Suspicious files
5
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
590455c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exeC:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exeexecutable
MD5:B7DDDCAA33724B82F9557A4B1D983F84
SHA256:469024BBDCA7AB528AF21A2C7ACFBDB0F28F273609C968C9C97F5E022AD53F00
590455c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exeC:\Windows\System32\alg.exeexecutable
MD5:274AD5CBA2471B6C08387718BE7C12FF
SHA256:4315078B651B2B18AEA414A3196FF24E9ED007230984334ECAB8CB949861DD55
2652armsvc.exeC:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\26b799fa89ba8c8f.binbinary
MD5:3897046E1F6B1A3F8CA011F6C7CA058F
SHA256:51B3B710AA270EA823D5DE8F249CBE492DCE19B3596504545AE7107C5015E157
590455c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exeC:\Program Files (x86)\Microsoft\EdgeUpdate\MicrosoftEdgeUpdate.exeexecutable
MD5:38E968359ADAE0893BD54A4E2015D82D
SHA256:3C9FF557D6F774176CD101342D4816568CF40F827D72B3A9F49A96AD0EB23695
590455c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exeC:\Program Files\Google\Chrome\Application\133.0.6943.127\elevation_service.exeexecutable
MD5:F650053ADABC19025BA6241BA0BEF290
SHA256:7391527EED9A6C954AA05C125D9138206E7FCF0BBC00DDA4A459DA40BE5F4D42
590455c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exeC:\Windows\System32\AppVClient.exeexecutable
MD5:6C4308545488AF162F42EA9BD1E07EDB
SHA256:312BB4E48EFF9AA7568DFF978ECCAE0B40A59A91A00E52D369A4A3104514E7B1
590455c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exeC:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\elevation_service.exeexecutable
MD5:20155959E242DEECB12B4180896677BD
SHA256:AEACBB5CB106B57E226B105C43A0959C10EA6CDF6170223BBF296692B0CD93CE
590455c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exeC:\Windows\System32\DiagSvcs\DiagnosticsHub.StandardCollector.Service.exeexecutable
MD5:B9E17D3F8871F54512294653A6FB1225
SHA256:8CCBCE442B33DAD78C6FD501531A8C2E82F7B24A584FE4B7CECC998BF401047E
590455c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exeC:\Windows\System32\FXSSVC.exeexecutable
MD5:4E3E20DB54589A456831CAA5A1E3B76D
SHA256:1282310805C0AC1D84EF9401F324E73E633D2C70512A14FBD031EAAA6BAF83CC
590455c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exeC:\Windows\System32\PerceptionSimulation\PerceptionSimulationService.exeexecutable
MD5:30F9446A6BC98994EBCF0321A92A77FC
SHA256:494C067FFEAA09A108E4920056B2A4D7D4121F81F422E496D67673BB2E4E5266
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
95
TCP/UDP connections
103
DNS requests
77
Threats
8

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5904
55c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exe
POST
200
3.229.117.57:80
http://npukfztj.biz/qqnhmcrmrvwv
US
malicious
5904
55c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exe
POST
200
44.244.22.128:80
http://cvgrf.biz/nu
US
malicious
2652
armsvc.exe
POST
200
44.244.22.128:80
http://cvgrf.biz/bnhyrjvbqujv
US
malicious
5904
55c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exe
POST
200
50.16.27.236:80
http://ssbzmoy.biz/mbf
US
unknown
2652
armsvc.exe
POST
200
44.244.22.128:80
http://pywolwnvd.biz/xhvxfuydvm
US
malicious
5904
55c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exe
POST
200
44.244.22.128:80
http://pywolwnvd.biz/pbbshrabagb
US
malicious
2652
armsvc.exe
POST
200
172.237.146.8:80
http://przvgke.biz/bofnskofci
US
binary
4.33 Kb
unknown
5904
55c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exe
POST
200
50.16.27.236:80
http://knjghuig.biz/yxday
US
malicious
5904
55c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exe
POST
200
172.237.146.8:80
http://przvgke.biz/utjfjkbiqjrwixfd
US
binary
4.34 Kb
unknown
2652
armsvc.exe
POST
200
50.16.27.236:80
http://ssbzmoy.biz/ienwkcvdh
US
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6016
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2280
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5904
55c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exe
44.244.22.128:80
pywolwnvd.biz
AMAZON-02
US
malicious
2652
armsvc.exe
44.244.22.128:80
pywolwnvd.biz
AMAZON-02
US
malicious
6016
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5904
55c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exe
50.16.27.236:80
ssbzmoy.biz
AMAZON-AES
US
malicious
2652
armsvc.exe
50.16.27.236:80
ssbzmoy.biz
AMAZON-AES
US
malicious
5948
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
whitelisted
google.com
  • 142.250.186.142
whitelisted
pywolwnvd.biz
  • 44.244.22.128
malicious
ssbzmoy.biz
  • 50.16.27.236
unknown
cvgrf.biz
  • 44.244.22.128
malicious
npukfztj.biz
  • 3.229.117.57
malicious
przvgke.biz
  • 172.237.146.8
  • 172.237.146.38
  • 172.237.146.25
  • 172.233.219.123
  • 172.233.219.78
  • 172.233.219.49
unknown
zlenh.biz
unknown
knjghuig.biz
  • 50.16.27.236
malicious
uhxqin.biz
malicious

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
2428
svchost.exe
A Network Trojan was detected
ET MALWARE DNS Query to Expiro Related Domain (knjghuig .biz)
2428
svchost.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/m0yv CnC related domain (zlenh .biz)
2428
svchost.exe
A Network Trojan was detected
ET MALWARE DNS Query to Expiro Related Domain (knjghuig .biz)
5904
55c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exe
Misc activity
ET INFO Namecheap URL Forward
2652
armsvc.exe
Misc activity
ET INFO Namecheap URL Forward
2652
armsvc.exe
Misc activity
ET INFO Namecheap URL Forward
5904
55c0030280b7a9480b660e77f036f68703e4474e338a02b784f1d84bc3c70223.exe
Misc activity
ET INFO Namecheap URL Forward
No debug info