File name:

ezyZip.zip

Full analysis: https://app.any.run/tasks/3d1e259d-e3ae-4205-a891-19c00078e797
Verdict: Malicious activity
Threats:

Crypto mining malware is a resource-intensive threat that infiltrates computers with the purpose of mining cryptocurrencies. This type of threat can be deployed either on an infected machine or a compromised website. In both cases the miner will utilize the computing power of the device and its network bandwidth.

Analysis date: October 03, 2025, 18:00:25
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto
lcryx
ransomware
arch-scr
anti-evasion
miner
lcryptorx
xmrig
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=deflate
MD5:

44E86B623984E4F546FA30B338EE6D2A

SHA1:

DF94CFEE03ECC2A2765CCC61BD624B3C96FAE109

SHA256:

66D574770A0ECAB893BEB08E164D9DA7999390FD798E918D53839EA0A6033670

SSDEEP:

192:ziRQJaD3Yu/BnvLIHIS9q1vJOxCgAYv8CqpnwVwrejii5mTF:AQhu/NgIJYkXmqF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • LCRYX has been found (auto)

      • WinRAR.exe (PID: 1992)
    • Creates a new registry key or changes the value of an existing one (SCRIPT)

      • wscript.exe (PID: 1688)
    • Changes image file execution options

      • wscript.exe (PID: 1688)
    • UAC/LUA settings modification

      • wscript.exe (PID: 1688)
    • Disables the Run the Start menu

      • wscript.exe (PID: 1688)
    • Gets a file object corresponding to the file in a specified path (SCRIPT)

      • wscript.exe (PID: 1688)
    • Changes Windows Defender settings

      • wscript.exe (PID: 1688)
    • Changes settings for real-time protection

      • powershell.exe (PID: 8196)
    • Disables task manager

      • wscript.exe (PID: 1688)
    • Changes the login/logoff helper path in the registry

      • wscript.exe (PID: 1688)
    • Gets %windir% folder path (SCRIPT)

      • wscript.exe (PID: 1688)
    • Accesses environment variables (SCRIPT)

      • wscript.exe (PID: 1688)
    • Gets %appdata% folder path (SCRIPT)

      • wscript.exe (PID: 1688)
    • Gets path to any of the special folders (SCRIPT)

      • wscript.exe (PID: 1688)
    • Gets startup folder path (SCRIPT)

      • wscript.exe (PID: 1688)
    • Opens an HTTP connection (SCRIPT)

      • wscript.exe (PID: 1688)
      • wscript.exe (PID: 6344)
    • Creates internet connection object (SCRIPT)

      • wscript.exe (PID: 1688)
      • wscript.exe (PID: 6344)
    • Sends HTTP request (SCRIPT)

      • wscript.exe (PID: 1688)
      • wscript.exe (PID: 6344)
    • Modifies registry startup key (SCRIPT)

      • wscript.exe (PID: 1688)
    • Opens a text file (SCRIPT)

      • wscript.exe (PID: 1688)
    • Checks whether a specified folder exists (SCRIPT)

      • wscript.exe (PID: 1688)
    • Queries network adapter information (Win32_NetworkAdapter) (SCRIPT)

      • wscript.exe (PID: 6344)
    • Antivirus name has been found in the command line (generic signature)

      • taskkill.exe (PID: 9160)
      • taskkill.exe (PID: 7520)
      • taskkill.exe (PID: 8872)
      • taskkill.exe (PID: 8544)
      • taskkill.exe (PID: 8452)
      • taskkill.exe (PID: 992)
      • taskkill.exe (PID: 8476)
      • taskkill.exe (PID: 8632)
      • taskkill.exe (PID: 576)
      • taskkill.exe (PID: 2164)
      • taskkill.exe (PID: 8456)
      • taskkill.exe (PID: 3420)
      • taskkill.exe (PID: 8900)
      • taskkill.exe (PID: 7172)
      • taskkill.exe (PID: 9184)
      • taskkill.exe (PID: 4208)
      • taskkill.exe (PID: 9036)
      • taskkill.exe (PID: 1740)
      • taskkill.exe (PID: 8116)
      • taskkill.exe (PID: 7548)
      • taskkill.exe (PID: 4676)
      • taskkill.exe (PID: 8836)
      • taskkill.exe (PID: 6408)
      • taskkill.exe (PID: 7416)
      • taskkill.exe (PID: 8280)
      • taskkill.exe (PID: 8236)
      • taskkill.exe (PID: 8936)
      • taskkill.exe (PID: 9036)
    • Uses TASKKILL.EXE to kill antiviruses

      • wscript.exe (PID: 9076)
    • XMRig has been detected

      • WindowsUpdateService.exe (PID: 9080)
    • Deleting the backup catalog via wbadmin

      • cmd.exe (PID: 6196)
    • Deletes shadow copies

      • cmd.exe (PID: 6196)
      • cmd.exe (PID: 8848)
    • Using BCDEDIT.EXE to modify recovery options

      • cmd.exe (PID: 4660)
      • cmd.exe (PID: 9164)
    • Uses sleep, probably for evasion detection (SCRIPT)

      • wscript.exe (PID: 8824)
      • wscript.exe (PID: 9076)
    • LCRYPTORX has been detected

      • notepad.exe (PID: 4320)
      • wscript.exe (PID: 1688)
      • notepad.exe (PID: 9080)
      • notepad.exe (PID: 9152)
      • notepad.exe (PID: 2108)
      • notepad.exe (PID: 8216)
      • notepad.exe (PID: 5648)
      • notepad.exe (PID: 5360)
      • notepad.exe (PID: 8904)
      • notepad.exe (PID: 8544)
      • notepad.exe (PID: 8776)
      • notepad.exe (PID: 8640)
      • notepad.exe (PID: 9180)
      • notepad.exe (PID: 5636)
      • notepad.exe (PID: 8788)
      • notepad.exe (PID: 360)
      • notepad.exe (PID: 8200)
      • notepad.exe (PID: 4800)
      • notepad.exe (PID: 2168)
      • notepad.exe (PID: 6988)
      • notepad.exe (PID: 8528)
      • notepad.exe (PID: 364)
      • notepad.exe (PID: 7728)
      • notepad.exe (PID: 5372)
      • notepad.exe (PID: 9188)
      • notepad.exe (PID: 6320)
      • notepad.exe (PID: 7784)
      • notepad.exe (PID: 4660)
      • notepad.exe (PID: 7572)
      • notepad.exe (PID: 8100)
      • notepad.exe (PID: 8936)
      • notepad.exe (PID: 392)
      • notepad.exe (PID: 3160)
      • notepad.exe (PID: 1052)
    • Deletes a file (SCRIPT)

      • wscript.exe (PID: 1688)
  • SUSPICIOUS

    • Application launched itself

      • wscript.exe (PID: 8112)
      • wscript.exe (PID: 1688)
    • The process executes VB scripts

      • wscript.exe (PID: 8112)
      • WinRAR.exe (PID: 1992)
      • wscript.exe (PID: 1688)
    • Executes WMI query (SCRIPT)

      • wscript.exe (PID: 1688)
      • wscript.exe (PID: 6344)
      • wscript.exe (PID: 8824)
    • Reads security settings of Internet Explorer

      • WinRAR.exe (PID: 1992)
    • Gets full path of the running script (SCRIPT)

      • wscript.exe (PID: 8112)
      • wscript.exe (PID: 1688)
      • wscript.exe (PID: 8532)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • wscript.exe (PID: 1688)
      • wscript.exe (PID: 8532)
    • Uses WMI to retrieve WMI-managed resources (SCRIPT)

      • wscript.exe (PID: 1688)
      • wscript.exe (PID: 6344)
      • wscript.exe (PID: 8532)
      • wscript.exe (PID: 8824)
    • Script disables Windows Defender's real-time protection

      • wscript.exe (PID: 1688)
    • Starts POWERSHELL.EXE for commands execution

      • wscript.exe (PID: 1688)
    • Found strings related to reading or modifying Windows Defender settings

      • wscript.exe (PID: 1688)
    • Starts CMD.EXE for commands execution

      • wscript.exe (PID: 1688)
    • The process verifies whether the antivirus software is installed

      • cmd.exe (PID: 5484)
      • cmd.exe (PID: 9144)
    • Uses NETSH.EXE to change the status of the firewall

      • cmd.exe (PID: 2572)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 1688)
      • wscript.exe (PID: 8112)
      • wscript.exe (PID: 9076)
      • wscript.exe (PID: 6344)
    • Accesses current user name via WMI (SCRIPT)

      • wscript.exe (PID: 1688)
    • Writes binary data to a Stream object (SCRIPT)

      • wscript.exe (PID: 1688)
    • Creates file in the systems drive root

      • wscript.exe (PID: 1688)
    • Saves data to a binary file (SCRIPT)

      • wscript.exe (PID: 1688)
    • Uses RUNDLL32.EXE to load library

      • wscript.exe (PID: 1688)
    • Changes the desktop background image

      • wscript.exe (PID: 1688)
    • Executing commands from a ".bat" file

      • wscript.exe (PID: 1688)
    • Checks whether a specific file exists (SCRIPT)

      • wscript.exe (PID: 1688)
    • Modifies hosts file to alter network resolution

      • wscript.exe (PID: 1688)
    • Accesses default IP gateways via WMI (SCRIPT)

      • wscript.exe (PID: 6344)
    • Hides command output

      • PING.EXE (PID: 8788)
      • PING.EXE (PID: 8776)
      • PING.EXE (PID: 5552)
      • PING.EXE (PID: 2900)
    • Uses TASKKILL.EXE to kill process

      • wscript.exe (PID: 9076)
    • Adds, changes, or deletes HTTP request header (SCRIPT)

      • wscript.exe (PID: 6344)
    • Crypto Currency Mining Activity Detected

      • wscript.exe (PID: 1688)
    • Potential Corporate Privacy Violation

      • wscript.exe (PID: 1688)
    • Executable content was dropped or overwritten

      • wscript.exe (PID: 1688)
    • Executes as Windows Service

      • vds.exe (PID: 8636)
      • wbengine.exe (PID: 8508)
    • System recovery suppression via bcdedit.exe

      • cmd.exe (PID: 9164)
      • wscript.exe (PID: 1688)
    • Reads data from a binary Stream object (SCRIPT)

      • wscript.exe (PID: 1688)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 8496)
    • Creates a Stream, which may work with files, input/output devices, pipes, or TCP/IP sockets (SCRIPT)

      • wscript.exe (PID: 1688)
    • Access the System.Security .NET namespace (SCRIPT)

      • wscript.exe (PID: 1688)
  • INFO

    • Reads Microsoft Office registry keys

      • WinRAR.exe (PID: 1992)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 8792)
      • BackgroundTransferHost.exe (PID: 9064)
      • BackgroundTransferHost.exe (PID: 8872)
      • notepad.exe (PID: 7220)
      • BackgroundTransferHost.exe (PID: 8244)
      • BackgroundTransferHost.exe (PID: 4660)
      • notepad.exe (PID: 4320)
      • notepad.exe (PID: 9080)
      • notepad.exe (PID: 9152)
      • notepad.exe (PID: 2108)
      • notepad.exe (PID: 8216)
      • notepad.exe (PID: 5648)
      • notepad.exe (PID: 5360)
      • notepad.exe (PID: 8788)
      • notepad.exe (PID: 8544)
      • notepad.exe (PID: 8776)
      • notepad.exe (PID: 8640)
      • notepad.exe (PID: 9180)
      • notepad.exe (PID: 5636)
      • notepad.exe (PID: 2168)
      • notepad.exe (PID: 8904)
      • notepad.exe (PID: 8200)
      • notepad.exe (PID: 360)
      • notepad.exe (PID: 6988)
      • notepad.exe (PID: 364)
      • notepad.exe (PID: 8528)
      • notepad.exe (PID: 7728)
      • notepad.exe (PID: 5372)
      • notepad.exe (PID: 4800)
      • notepad.exe (PID: 9188)
      • notepad.exe (PID: 7784)
      • notepad.exe (PID: 8100)
      • notepad.exe (PID: 4660)
      • notepad.exe (PID: 392)
      • notepad.exe (PID: 7572)
      • notepad.exe (PID: 8936)
      • notepad.exe (PID: 6320)
      • notepad.exe (PID: 3160)
      • notepad.exe (PID: 1052)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 8196)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 8196)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 9064)
    • Reads the software policy settings

      • BackgroundTransferHost.exe (PID: 9064)
    • Checks proxy server information

      • BackgroundTransferHost.exe (PID: 9064)
    • Checks supported languages

      • WindowsUpdateService.exe (PID: 9080)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0802
ZipCompression: Deflated
ZipModifyDate: 2025:10:03 13:59:42
ZipCRC: 0x01a7529a
ZipCompressedSize: 6768
ZipUncompressedSize: 30847
ZipFileName: mydocs.vbs
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
501
Monitored processes
330
Malicious processes
43
Suspicious processes
2

Behavior graph

Click at the process to see the details
start #LCRYX winrar.exe no specs wscript.exe no specs #LCRYPTORX wscript.exe shellexperiencehost.exe no specs powershell.exe no specs conhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs notepad.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs rundll32.exe no specs backgroundtransferhost.exe no specs cmd.exe no specs conhost.exe no specs wscript.exe wscript.exe no specs wscript.exe no specs wscript.exe no specs ping.exe no specs taskkill.exe no specs conhost.exe no specs ping.exe no specs ping.exe no specs conhost.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs #XMRIG windowsupdateservice.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs vssadmin.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wbadmin.exe wbengine.exe no specs vdsldr.exe no specs vds.exe no specs cmd.exe no specs conhost.exe no specs bcdedit.exe no specs cmd.exe no specs conhost.exe no specs bcdedit.exe no specs cmd.exe no specs conhost.exe no specs bcdedit.exe no specs cmd.exe no specs conhost.exe no specs reg.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs #LCRYPTORX notepad.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs taskkill.exe no specs conhost.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs #LCRYPTORX notepad.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs slui.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs ping.exe no specs ping.exe no specs conhost.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
360"C:\Windows\System32\notepad.exe" "C:\Users\admin\Documents\Database1.accdb.lcryptx"C:\Windows\System32\notepad.exe
wscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
360\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
360\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
364"C:\Windows\System32\notepad.exe" "C:\Users\admin\Documents\requirementspolicies.rtf.lcryptx"C:\Windows\System32\notepad.exe
wscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
368bcdedit /set {default} safeboot minimalC:\Windows\System32\bcdedit.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Boot Configuration Data Editor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\bcdedit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cryptsp.dll
368\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
372\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
376\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
392"C:\Windows\System32\taskkill.exe" /IM AvastSvc.exe /FC:\Windows\System32\taskkill.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
392\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
43 579
Read events
43 446
Write events
99
Delete events
34

Modification events

(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\ezyZip.zip
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(1992) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
1
Suspicious files
39
Text files
14
Unknown types
0

Dropped files

PID
Process
Filename
Type
9064BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\34879117-ac5e-4ea1-86a2-41259415aa52.down_data
MD5:
SHA256:
8196powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_r0ymjtj1.2na.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
9064BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:A2459D8C15651BB81784468BC907C939
SHA256:E6360479BE8038E7443DA1855F01EC552F1B602A656A2BF713C1CD760B7CB6C8
9064BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\34879117-ac5e-4ea1-86a2-41259415aa52.fd30b6e8-d330-44d5-9bf3-e3590d5323da.down_metabinary
MD5:25DE6530289CE72C5828E31E988BAFF6
SHA256:D3ADB868CE0D2F916710718A2B39BDBA29B9062DFA21D85CC0FD2E5B13519950
9064BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\f8b770f0-b54d-40fd-ab5a-782d4f3843f2.fd30b6e8-d330-44d5-9bf3-e3590d5323da.down_metabinary
MD5:25DE6530289CE72C5828E31E988BAFF6
SHA256:D3ADB868CE0D2F916710718A2B39BDBA29B9062DFA21D85CC0FD2E5B13519950
1688wscript.exeC:\PLEASEREADME.txttext
MD5:BDB08C40728C362E252ED25FD3A24F2B
SHA256:FE86632850D4A90FA22A0B1682D2923E3108049704063E827BC0ADC4F603614A
9064BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:B51EECA54BA20240362B15511194D296
SHA256:4169F1B780CD11750985226B3695653F17EE307FB1B278BF2C130D9F23D0E70C
1688wscript.exeC:\Users\admin\Downloads\PLEASEREADME.txttext
MD5:BDB08C40728C362E252ED25FD3A24F2B
SHA256:FE86632850D4A90FA22A0B1682D2923E3108049704063E827BC0ADC4F603614A
1688wscript.exeC:\Windows\System32\systemconfig.exe.vbstext
MD5:B0515ECBD6FBA4F40661FCACFD40E66C
SHA256:135626BE7A1B58094DB1A5E4603E4BCB1CBE90AC0F17D65C6AE1779B107EB1FB
1688wscript.exeC:\Windows\advapi32_ext.vbstext
MD5:339EE75C44FAE8527AD654DE9AA5FF23
SHA256:BD5DADC7A7BED806F5B05BC9B74438A156251160983BAACAD97C97B3E17E8A82
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
44
DNS requests
20
Threats
9

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5320
svchost.exe
GET
200
162.159.142.9:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
whitelisted
6936
backgroundTaskHost.exe
GET
200
162.159.142.9:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
binary
313 b
whitelisted
1688
wscript.exe
GET
200
172.217.16.196:80
http://www.google.com/
US
html
31.0 Kb
whitelisted
9064
BackgroundTransferHost.exe
GET
200
162.159.142.9:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
binary
313 b
whitelisted
1688
wscript.exe
GET
200
172.217.16.196:80
http://www.google.com/
US
html
31.0 Kb
whitelisted
1688
wscript.exe
GET
78.153.140.66:80
http://78.153.140.66/xmrig.exe
RU
unknown
5424
backgroundTaskHost.exe
GET
200
162.159.142.9:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
binary
471 b
whitelisted
5320
svchost.exe
GET
200
162.159.142.9:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
whitelisted
588
backgroundTaskHost.exe
GET
200
162.159.142.9:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
binary
471 b
whitelisted
1688
wscript.exe
GET
200
172.217.16.196:80
http://www.google.com/
US
html
31.0 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6016
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4212
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5224
SearchApp.exe
2.16.241.207:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
5320
svchost.exe
40.126.31.129:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5320
svchost.exe
162.159.142.9:80
ocsp.digicert.com
CLOUDFLARENET
whitelisted
6936
backgroundTaskHost.exe
2.16.241.205:443
www.bing.com
Akamai International B.V.
DE
whitelisted
6936
backgroundTaskHost.exe
162.159.142.9:80
ocsp.digicert.com
CLOUDFLARENET
whitelisted
3464
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
whitelisted
www.bing.com
  • 2.16.241.207
  • 2.16.241.205
  • 2.16.241.218
  • 2.16.241.201
whitelisted
google.com
  • 142.250.186.174
whitelisted
login.live.com
  • 40.126.31.129
  • 20.190.159.129
  • 40.126.31.128
  • 20.190.159.2
  • 40.126.31.69
  • 20.190.159.75
  • 40.126.31.0
  • 40.126.31.2
whitelisted
ocsp.digicert.com
  • 162.159.142.9
  • 172.66.2.5
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted
www.google.com
  • 172.217.16.196
whitelisted
i.ibb.co
  • 45.43.142.2
  • 45.43.142.4
  • 45.43.142.6
  • 45.43.142.5
  • 45.43.142.3
  • 45.43.142.7
shared

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
1688
wscript.exe
Not Suspicious Traffic
INFO [ANY.RUN] Image hosting service ImgBB
1688
wscript.exe
Potentially Bad Traffic
ET HUNTING Request for EXE via WinHTTP M1
1688
wscript.exe
Potentially Bad Traffic
ET INFO Executable Download from dotted-quad Host
1688
wscript.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 9
1688
wscript.exe
Crypto Currency Mining Activity Detected
MINER [ANY.RUN] Request Coinminer Xmrig
1688
wscript.exe
Potentially Bad Traffic
ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response
1688
wscript.exe
Misc activity
ET INFO WinHttpRequest Downloading EXE
1688
wscript.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
Process
Message
wbadmin.exe
Invalid parameter passed to C runtime function.