File name:

ezyZip.zip

Full analysis: https://app.any.run/tasks/3d1e259d-e3ae-4205-a891-19c00078e797
Verdict: Malicious activity
Threats:

Crypto mining malware is a resource-intensive threat that infiltrates computers with the purpose of mining cryptocurrencies. This type of threat can be deployed either on an infected machine or a compromised website. In both cases the miner will utilize the computing power of the device and its network bandwidth.

Analysis date: October 03, 2025, 18:00:25
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto
lcryx
ransomware
arch-scr
anti-evasion
miner
lcryptorx
xmrig
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

44E86B623984E4F546FA30B338EE6D2A

SHA1:

DF94CFEE03ECC2A2765CCC61BD624B3C96FAE109

SHA256:

66D574770A0ECAB893BEB08E164D9DA7999390FD798E918D53839EA0A6033670

SSDEEP:

192:ziRQJaD3Yu/BnvLIHIS9q1vJOxCgAYv8CqpnwVwrejii5mTF:AQhu/NgIJYkXmqF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • LCRYX has been found (auto)

      • WinRAR.exe (PID: 1992)
    • Creates a new registry key or changes the value of an existing one (SCRIPT)

      • wscript.exe (PID: 1688)
    • UAC/LUA settings modification

      • wscript.exe (PID: 1688)
    • Disables the Run the Start menu

      • wscript.exe (PID: 1688)
    • Disables task manager

      • wscript.exe (PID: 1688)
    • Changes image file execution options

      • wscript.exe (PID: 1688)
    • Changes the login/logoff helper path in the registry

      • wscript.exe (PID: 1688)
    • Gets a file object corresponding to the file in a specified path (SCRIPT)

      • wscript.exe (PID: 1688)
    • Changes settings for real-time protection

      • powershell.exe (PID: 8196)
    • Changes Windows Defender settings

      • wscript.exe (PID: 1688)
    • Gets %appdata% folder path (SCRIPT)

      • wscript.exe (PID: 1688)
    • Gets %windir% folder path (SCRIPT)

      • wscript.exe (PID: 1688)
    • Accesses environment variables (SCRIPT)

      • wscript.exe (PID: 1688)
    • Gets path to any of the special folders (SCRIPT)

      • wscript.exe (PID: 1688)
    • Creates internet connection object (SCRIPT)

      • wscript.exe (PID: 1688)
      • wscript.exe (PID: 6344)
    • Sends HTTP request (SCRIPT)

      • wscript.exe (PID: 1688)
      • wscript.exe (PID: 6344)
    • Modifies registry startup key (SCRIPT)

      • wscript.exe (PID: 1688)
    • Gets startup folder path (SCRIPT)

      • wscript.exe (PID: 1688)
    • Opens an HTTP connection (SCRIPT)

      • wscript.exe (PID: 1688)
      • wscript.exe (PID: 6344)
    • Checks whether a specified folder exists (SCRIPT)

      • wscript.exe (PID: 1688)
    • Queries network adapter information (Win32_NetworkAdapter) (SCRIPT)

      • wscript.exe (PID: 6344)
    • Opens a text file (SCRIPT)

      • wscript.exe (PID: 1688)
    • Antivirus name has been found in the command line (generic signature)

      • taskkill.exe (PID: 7520)
      • taskkill.exe (PID: 9160)
      • taskkill.exe (PID: 8544)
      • taskkill.exe (PID: 8872)
      • taskkill.exe (PID: 8456)
      • taskkill.exe (PID: 992)
      • taskkill.exe (PID: 576)
      • taskkill.exe (PID: 8476)
      • taskkill.exe (PID: 8632)
      • taskkill.exe (PID: 3420)
      • taskkill.exe (PID: 2164)
      • taskkill.exe (PID: 8452)
      • taskkill.exe (PID: 9184)
      • taskkill.exe (PID: 8900)
      • taskkill.exe (PID: 7172)
      • taskkill.exe (PID: 4208)
      • taskkill.exe (PID: 1740)
      • taskkill.exe (PID: 9036)
      • taskkill.exe (PID: 8116)
      • taskkill.exe (PID: 8836)
      • taskkill.exe (PID: 8236)
      • taskkill.exe (PID: 6408)
      • taskkill.exe (PID: 7416)
      • taskkill.exe (PID: 8280)
      • taskkill.exe (PID: 9036)
      • taskkill.exe (PID: 4676)
      • taskkill.exe (PID: 7548)
      • taskkill.exe (PID: 8936)
    • Uses TASKKILL.EXE to kill antiviruses

      • wscript.exe (PID: 9076)
    • Deletes shadow copies

      • cmd.exe (PID: 8848)
      • cmd.exe (PID: 6196)
    • XMRig has been detected

      • WindowsUpdateService.exe (PID: 9080)
    • Deleting the backup catalog via wbadmin

      • cmd.exe (PID: 6196)
    • Using BCDEDIT.EXE to modify recovery options

      • cmd.exe (PID: 9164)
      • cmd.exe (PID: 4660)
    • Uses sleep, probably for evasion detection (SCRIPT)

      • wscript.exe (PID: 8824)
      • wscript.exe (PID: 9076)
    • LCRYPTORX has been detected

      • notepad.exe (PID: 4320)
      • wscript.exe (PID: 1688)
      • notepad.exe (PID: 9080)
      • notepad.exe (PID: 9152)
      • notepad.exe (PID: 2108)
      • notepad.exe (PID: 8216)
      • notepad.exe (PID: 8544)
      • notepad.exe (PID: 8904)
      • notepad.exe (PID: 8776)
      • notepad.exe (PID: 8640)
      • notepad.exe (PID: 9180)
      • notepad.exe (PID: 5648)
      • notepad.exe (PID: 5360)
      • notepad.exe (PID: 8788)
      • notepad.exe (PID: 360)
      • notepad.exe (PID: 5636)
      • notepad.exe (PID: 2168)
      • notepad.exe (PID: 6988)
      • notepad.exe (PID: 364)
      • notepad.exe (PID: 8528)
      • notepad.exe (PID: 7728)
      • notepad.exe (PID: 5372)
      • notepad.exe (PID: 8200)
      • notepad.exe (PID: 4800)
      • notepad.exe (PID: 9188)
      • notepad.exe (PID: 6320)
      • notepad.exe (PID: 7784)
      • notepad.exe (PID: 4660)
      • notepad.exe (PID: 7572)
      • notepad.exe (PID: 392)
      • notepad.exe (PID: 8936)
      • notepad.exe (PID: 8100)
      • notepad.exe (PID: 3160)
      • notepad.exe (PID: 1052)
    • Deletes a file (SCRIPT)

      • wscript.exe (PID: 1688)
  • SUSPICIOUS

    • Gets full path of the running script (SCRIPT)

      • wscript.exe (PID: 8112)
      • wscript.exe (PID: 1688)
      • wscript.exe (PID: 8532)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 1992)
    • The process executes VB scripts

      • WinRAR.exe (PID: 1992)
      • wscript.exe (PID: 8112)
      • wscript.exe (PID: 1688)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 8112)
      • wscript.exe (PID: 1688)
      • wscript.exe (PID: 6344)
      • wscript.exe (PID: 9076)
    • Application launched itself

      • wscript.exe (PID: 8112)
      • wscript.exe (PID: 1688)
    • Uses WMI to retrieve WMI-managed resources (SCRIPT)

      • wscript.exe (PID: 1688)
      • wscript.exe (PID: 8532)
      • wscript.exe (PID: 8824)
      • wscript.exe (PID: 6344)
    • Executes WMI query (SCRIPT)

      • wscript.exe (PID: 1688)
      • wscript.exe (PID: 6344)
      • wscript.exe (PID: 8824)
    • Script disables Windows Defender's real-time protection

      • wscript.exe (PID: 1688)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • wscript.exe (PID: 1688)
      • wscript.exe (PID: 8532)
    • Starts POWERSHELL.EXE for commands execution

      • wscript.exe (PID: 1688)
    • The process verifies whether the antivirus software is installed

      • cmd.exe (PID: 5484)
      • cmd.exe (PID: 9144)
    • Found strings related to reading or modifying Windows Defender settings

      • wscript.exe (PID: 1688)
    • Starts CMD.EXE for commands execution

      • wscript.exe (PID: 1688)
    • Uses NETSH.EXE to change the status of the firewall

      • cmd.exe (PID: 2572)
    • Accesses current user name via WMI (SCRIPT)

      • wscript.exe (PID: 1688)
    • Writes binary data to a Stream object (SCRIPT)

      • wscript.exe (PID: 1688)
    • Saves data to a binary file (SCRIPT)

      • wscript.exe (PID: 1688)
    • Creates a Stream, which may work with files, input/output devices, pipes, or TCP/IP sockets (SCRIPT)

      • wscript.exe (PID: 1688)
    • Changes the desktop background image

      • wscript.exe (PID: 1688)
    • Uses RUNDLL32.EXE to load library

      • wscript.exe (PID: 1688)
    • Executing commands from a ".bat" file

      • wscript.exe (PID: 1688)
    • Creates file in the systems drive root

      • wscript.exe (PID: 1688)
    • Modifies hosts file to alter network resolution

      • wscript.exe (PID: 1688)
    • Accesses default IP gateways via WMI (SCRIPT)

      • wscript.exe (PID: 6344)
    • Hides command output

      • PING.EXE (PID: 8788)
      • PING.EXE (PID: 8776)
      • PING.EXE (PID: 2900)
      • PING.EXE (PID: 5552)
    • Checks whether a specific file exists (SCRIPT)

      • wscript.exe (PID: 1688)
    • Executable content was dropped or overwritten

      • wscript.exe (PID: 1688)
    • Uses TASKKILL.EXE to kill process

      • wscript.exe (PID: 9076)
    • Potential Corporate Privacy Violation

      • wscript.exe (PID: 1688)
    • Executes as Windows Service

      • wbengine.exe (PID: 8508)
      • vds.exe (PID: 8636)
    • Adds, changes, or deletes HTTP request header (SCRIPT)

      • wscript.exe (PID: 6344)
    • Crypto Currency Mining Activity Detected

      • wscript.exe (PID: 1688)
    • System recovery suppression via bcdedit.exe

      • cmd.exe (PID: 9164)
      • wscript.exe (PID: 1688)
    • Reads data from a binary Stream object (SCRIPT)

      • wscript.exe (PID: 1688)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 8496)
    • Access the System.Security .NET namespace (SCRIPT)

      • wscript.exe (PID: 1688)
  • INFO

    • Reads Microsoft Office registry keys

      • WinRAR.exe (PID: 1992)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 8792)
      • BackgroundTransferHost.exe (PID: 9064)
      • BackgroundTransferHost.exe (PID: 8872)
      • notepad.exe (PID: 7220)
      • BackgroundTransferHost.exe (PID: 8244)
      • BackgroundTransferHost.exe (PID: 4660)
      • notepad.exe (PID: 9080)
      • notepad.exe (PID: 4320)
      • notepad.exe (PID: 9152)
      • notepad.exe (PID: 2108)
      • notepad.exe (PID: 8216)
      • notepad.exe (PID: 8904)
      • notepad.exe (PID: 8776)
      • notepad.exe (PID: 8640)
      • notepad.exe (PID: 5636)
      • notepad.exe (PID: 5648)
      • notepad.exe (PID: 5360)
      • notepad.exe (PID: 8788)
      • notepad.exe (PID: 8544)
      • notepad.exe (PID: 9180)
      • notepad.exe (PID: 360)
      • notepad.exe (PID: 8200)
      • notepad.exe (PID: 2168)
      • notepad.exe (PID: 6988)
      • notepad.exe (PID: 7728)
      • notepad.exe (PID: 364)
      • notepad.exe (PID: 5372)
      • notepad.exe (PID: 4800)
      • notepad.exe (PID: 9188)
      • notepad.exe (PID: 8528)
      • notepad.exe (PID: 8936)
      • notepad.exe (PID: 6320)
      • notepad.exe (PID: 7784)
      • notepad.exe (PID: 4660)
      • notepad.exe (PID: 7572)
      • notepad.exe (PID: 8100)
      • notepad.exe (PID: 392)
      • notepad.exe (PID: 3160)
      • notepad.exe (PID: 1052)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 8196)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 9064)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 8196)
    • Checks proxy server information

      • BackgroundTransferHost.exe (PID: 9064)
    • Reads the software policy settings

      • BackgroundTransferHost.exe (PID: 9064)
    • Checks supported languages

      • WindowsUpdateService.exe (PID: 9080)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0802
ZipCompression: Deflated
ZipModifyDate: 2025:10:03 13:59:42
ZipCRC: 0x01a7529a
ZipCompressedSize: 6768
ZipUncompressedSize: 30847
ZipFileName: mydocs.vbs
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
501
Monitored processes
330
Malicious processes
43
Suspicious processes
2

Behavior graph

Click at the process to see the details
start #LCRYX winrar.exe no specs wscript.exe no specs #LCRYPTORX wscript.exe shellexperiencehost.exe no specs powershell.exe no specs conhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs notepad.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs rundll32.exe no specs backgroundtransferhost.exe no specs cmd.exe no specs conhost.exe no specs wscript.exe wscript.exe no specs wscript.exe no specs wscript.exe no specs ping.exe no specs taskkill.exe no specs conhost.exe no specs ping.exe no specs ping.exe no specs conhost.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs #XMRIG windowsupdateservice.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs vssadmin.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wbadmin.exe wbengine.exe no specs vdsldr.exe no specs vds.exe no specs cmd.exe no specs conhost.exe no specs bcdedit.exe no specs cmd.exe no specs conhost.exe no specs bcdedit.exe no specs cmd.exe no specs conhost.exe no specs bcdedit.exe no specs cmd.exe no specs conhost.exe no specs reg.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs #LCRYPTORX notepad.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs taskkill.exe no specs conhost.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs slui.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs ping.exe no specs ping.exe no specs conhost.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
360"C:\Windows\System32\notepad.exe" "C:\Users\admin\Documents\Database1.accdb.lcryptx"C:\Windows\System32\notepad.exe
wscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
360\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
360\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
364"C:\Windows\System32\notepad.exe" "C:\Users\admin\Documents\requirementspolicies.rtf.lcryptx"C:\Windows\System32\notepad.exe
wscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
368bcdedit /set {default} safeboot minimalC:\Windows\System32\bcdedit.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Boot Configuration Data Editor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\bcdedit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cryptsp.dll
368\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
372\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
376\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
392"C:\Windows\System32\taskkill.exe" /IM AvastSvc.exe /FC:\Windows\System32\taskkill.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
392\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
43 579
Read events
43 446
Write events
99
Delete events
34

Modification events

(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\ezyZip.zip
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
1
Suspicious files
39
Text files
14
Unknown types
0

Dropped files

PID
Process
Filename
Type
9064BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\34879117-ac5e-4ea1-86a2-41259415aa52.down_data
MD5:
SHA256:
9064BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:A2459D8C15651BB81784468BC907C939
SHA256:E6360479BE8038E7443DA1855F01EC552F1B602A656A2BF713C1CD760B7CB6C8
8196powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivebinary
MD5:1E3E4FD1B21C7F9731E1C26068E0BC38
SHA256:A90CF15B9218B7AC18944DD7B86F2F6E4AD571FDD819C2DA00986A91FABA4258
8196powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_r0ymjtj1.2na.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
8196powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_wf3qjo4q.nfx.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
1992WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$DIa1992.8197\mydocs.vbstext
MD5:BD9B33D87C168387B1D3532266C8CCE1
SHA256:E8CAFD32F61D2F4DC1775B3B491C2AE67DC99EAFAB5E65D82228FC1D9CABBB9E
9064BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:B51EECA54BA20240362B15511194D296
SHA256:4169F1B780CD11750985226B3695653F17EE307FB1B278BF2C130D9F23D0E70C
1992WinRAR.exeC:\Users\admin\AppData\Local\Temp\ezyZip\mydocs.vbstext
MD5:BD9B33D87C168387B1D3532266C8CCE1
SHA256:E8CAFD32F61D2F4DC1775B3B491C2AE67DC99EAFAB5E65D82228FC1D9CABBB9E
1688wscript.exeC:\Windows\System32\systemconfig.exe.vbstext
MD5:B0515ECBD6FBA4F40661FCACFD40E66C
SHA256:135626BE7A1B58094DB1A5E4603E4BCB1CBE90AC0F17D65C6AE1779B107EB1FB
1688wscript.exeC:\Users\admin\Desktop\gcrybground.pngimage
MD5:929BDA26083CA8E10CE5DBCD34C8D43D
SHA256:4A3FED3D76DDB7257D9FC985FE2B4C5FFD5B0F7D0808B5D8A054DF053F40FC56
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
44
DNS requests
20
Threats
9

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5320
svchost.exe
GET
200
162.159.142.9:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
whitelisted
6936
backgroundTaskHost.exe
GET
200
162.159.142.9:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
binary
313 b
whitelisted
5424
backgroundTaskHost.exe
GET
200
162.159.142.9:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
binary
471 b
whitelisted
9064
BackgroundTransferHost.exe
GET
200
162.159.142.9:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
binary
313 b
whitelisted
588
backgroundTaskHost.exe
GET
200
162.159.142.9:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
binary
471 b
whitelisted
1688
wscript.exe
GET
200
172.217.16.196:80
http://www.google.com/
US
html
31.0 Kb
whitelisted
1688
wscript.exe
GET
200
172.217.16.196:80
http://www.google.com/
US
html
31.0 Kb
whitelisted
1688
wscript.exe
GET
78.153.140.66:80
http://78.153.140.66/xmrig.exe
RU
unknown
5320
svchost.exe
GET
200
162.159.142.9:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
whitelisted
1688
wscript.exe
GET
200
172.217.16.196:80
http://www.google.com/
US
html
31.0 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6016
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4212
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5224
SearchApp.exe
2.16.241.207:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
5320
svchost.exe
40.126.31.129:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5320
svchost.exe
162.159.142.9:80
ocsp.digicert.com
CLOUDFLARENET
whitelisted
6936
backgroundTaskHost.exe
2.16.241.205:443
www.bing.com
Akamai International B.V.
DE
whitelisted
6936
backgroundTaskHost.exe
162.159.142.9:80
ocsp.digicert.com
CLOUDFLARENET
whitelisted
3464
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
whitelisted
www.bing.com
  • 2.16.241.207
  • 2.16.241.205
  • 2.16.241.218
  • 2.16.241.201
whitelisted
google.com
  • 142.250.186.174
whitelisted
login.live.com
  • 40.126.31.129
  • 20.190.159.129
  • 40.126.31.128
  • 20.190.159.2
  • 40.126.31.69
  • 20.190.159.75
  • 40.126.31.0
  • 40.126.31.2
whitelisted
ocsp.digicert.com
  • 162.159.142.9
  • 172.66.2.5
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted
www.google.com
  • 172.217.16.196
whitelisted
i.ibb.co
  • 45.43.142.2
  • 45.43.142.4
  • 45.43.142.6
  • 45.43.142.5
  • 45.43.142.3
  • 45.43.142.7
shared

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
1688
wscript.exe
Not Suspicious Traffic
INFO [ANY.RUN] Image hosting service ImgBB
1688
wscript.exe
Potentially Bad Traffic
ET HUNTING Request for EXE via WinHTTP M1
1688
wscript.exe
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
1688
wscript.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 9
1688
wscript.exe
Crypto Currency Mining Activity Detected
MINER [ANY.RUN] Request Coinminer Xmrig
1688
wscript.exe
Potentially Bad Traffic
ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response
1688
wscript.exe
Misc activity
ET INFO WinHttpRequest Downloading EXE
1688
wscript.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
Process
Message
wbadmin.exe
Invalid parameter passed to C runtime function.