File name:

VER_110355510_2025-24-05-415751134_8060ERJE09.vbs

Full analysis: https://app.any.run/tasks/92f2053b-324c-461a-9809-8823e60fdb43
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: March 25, 2025, 07:58:54
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
evasion
delphi
stealer
Indicators:
MIME: text/plain
File info: ASCII text, with very long lines (4690), with CRLF line terminators
MD5:

E6735AC22414993E3B3E3AA500D784E5

SHA1:

8807170F3ABEA88B67C8D512DE908E567B2EA8C1

SHA256:

6FF42B85D2B9745C6D4EDCFC129A522690627AA7A66C4540A899538E5CF3B34E

SSDEEP:

49152:4TGFBGuiOrPSuOAB0bc3TgEockwIcRj23S2Wd3T8G:INmHr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Uses base64 encoding (SCRIPT)

      • wscript.exe (PID: 7344)
    • Deletes a file (SCRIPT)

      • wscript.exe (PID: 7344)
    • Actions looks like stealing of personal data

      • PRiJGVxiSWVstUyidB.exe (PID: 7496)
  • SUSPICIOUS

    • Creates FileSystem object to access computer's file system (SCRIPT)

      • wscript.exe (PID: 7344)
    • Sets XML DOM element text (SCRIPT)

      • wscript.exe (PID: 7344)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 7344)
    • Writes binary data to a Stream object (SCRIPT)

      • wscript.exe (PID: 7344)
    • Saves data to a binary file (SCRIPT)

      • wscript.exe (PID: 7344)
    • Creates a Stream, which may work with files, input/output devices, pipes, or TCP/IP sockets (SCRIPT)

      • wscript.exe (PID: 7344)
    • Likely accesses (executes) a file from the Public directory

      • PRiJGVxiSWVstUyidB.exe (PID: 7496)
    • Read disk information to detect sandboxing environments

      • PRiJGVxiSWVstUyidB.exe (PID: 7496)
    • Reads the date of Windows installation

      • PRiJGVxiSWVstUyidB.exe (PID: 7496)
    • Checks for external IP

      • PRiJGVxiSWVstUyidB.exe (PID: 7496)
      • svchost.exe (PID: 2196)
    • Connects to unusual port

      • PRiJGVxiSWVstUyidB.exe (PID: 7496)
    • There is functionality for taking screenshot (YARA)

      • PRiJGVxiSWVstUyidB.exe (PID: 7496)
    • There is functionality for communication over UDP network (YARA)

      • PRiJGVxiSWVstUyidB.exe (PID: 7496)
  • INFO

    • The sample compiled with english language support

      • wscript.exe (PID: 7344)
    • Reads the computer name

      • PRiJGVxiSWVstUyidB.exe (PID: 7496)
    • Reads Environment values

      • PRiJGVxiSWVstUyidB.exe (PID: 7496)
    • Checks proxy server information

      • BackgroundTransferHost.exe (PID: 3888)
      • PRiJGVxiSWVstUyidB.exe (PID: 7496)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 7212)
      • BackgroundTransferHost.exe (PID: 3888)
      • BackgroundTransferHost.exe (PID: 7764)
      • BackgroundTransferHost.exe (PID: 7204)
      • BackgroundTransferHost.exe (PID: 8068)
    • Compiled with Borland Delphi (YARA)

      • PRiJGVxiSWVstUyidB.exe (PID: 7496)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 3888)
    • Reads the software policy settings

      • BackgroundTransferHost.exe (PID: 3888)
      • slui.exe (PID: 7560)
      • PRiJGVxiSWVstUyidB.exe (PID: 7496)
    • Checks supported languages

      • PRiJGVxiSWVstUyidB.exe (PID: 7496)
    • Reads product name

      • PRiJGVxiSWVstUyidB.exe (PID: 7496)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.cnt | Help File Contents (100)
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
148
Monitored processes
11
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wscript.exe no specs prijgvxiswvstuyidb.exe sppextcomobj.exe no specs slui.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs slui.exe no specs svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
2196C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
3888"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\kernel.appcore.dll
6228C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7204"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
7212"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
7344"C:\WINDOWS\System32\WScript.exe" C:\Users\admin\AppData\Local\Temp\VER_110355510_2025-24-05-415751134_8060ERJE09.vbsC:\Windows\System32\wscript.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7496"C:\Users\Public\PRiJGVxiSWVstUyidB.exe" C:\Users\Public\PRiJGVxiSWVstUyidB.exe
wscript.exe
User:
admin
Company:
CloudBridge Solutions 8730826 Inc.
Integrity Level:
MEDIUM
Description:
Advanced Data Protection Management 8730826, 23070.15646.35332.54123, R885.
Exit code:
0
Version:
23070.15646.35332.54123
Modules
Images
c:\users\public\prijgvxiswvstuyidb.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\shell32.dll
c:\windows\syswow64\msvcp_win.dll
7528C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7560"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7764"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
Total events
4 379
Read events
4 363
Write events
16
Delete events
0

Modification events

(PID) Process:(7344) wscript.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{2781761E-28E0-4109-99FE-B9D127C57AFE} {56FFCC30-D398-11D0-B2AE-00A0C908FA49} 0xFFFF
Value:
0100000000000000964260C65B9DDB01
(PID) Process:(7212) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7212) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7212) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3888) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3888) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3888) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7204) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7204) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7204) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
0
Suspicious files
7
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
7344wscript.exeC:\Users\Public\ZRPYUvsmmu2K38B7H161EBEYAJAFSUbifigu.htf
MD5:
SHA256:
7344wscript.exeC:\Users\Public\PRiJGVxiSWVstUyidB.exe
MD5:
SHA256:
3888BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\f92a002e-34c9-4cd5-a66c-35d44b549f23.down_data
MD5:
SHA256:
7344wscript.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\AutomaticDestinations\f01b4d95cf55d32a.automaticDestinations-msbinary
MD5:4B6ECDC11DC53A3DF3A5F14073FED9BE
SHA256:81CB5B91B9CC1D1EDEDBE749FF4D30DA11802819DA2F2CA8C630F4F42D861E6F
7344wscript.exeC:\Users\Public\PRiJGVxiSWVstUyidB.zipcompressed
MD5:B739F1D6A1C19C3B7850B654B71AE37C
SHA256:ED5F8DFC679C1E5B6B4C9E5F2DBF7F2AC9315AE0E66001EA0283C578908AE7E3
3888BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\f92a002e-34c9-4cd5-a66c-35d44b549f23.9a287cdb-b623-49b3-88a2-62f8b459af6c.down_metabinary
MD5:4DD52F4CCAF172CBE671B060A4C0C425
SHA256:B10DBF39EF9ABFF221F121A8B31B5BAF5A67592C30F9C2899175749ED97F0214
7344wscript.exeC:\Users\Public\FuNDoh.txttext
MD5:CAA07D42AFBE5F5D07095A6785028DF0
SHA256:F1E12A7BE06CA95C4D639E44B8A177E999544BB6325FA0E47E8E54874DEA2400
3888BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:4872BABAF39AA62B8D32695EBB7E9173
SHA256:2EE85DF86EE29BBEB3DCA81AA29B6DE204F605A2769B84C728A329178A2D0999
3888BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:4FF20C2E4412E089996C6C61D71BC5AE
SHA256:CA20A5BE1C40CE7AFA14A0DE4EF9AF99715CE1807B726E4CC1643A0533352975
3888BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\50b9e818-005f-4218-910a-d9c6f53ad632.up_meta_securebinary
MD5:9B5E1BD58E77C9D2634D9271E4ADF86B
SHA256:F247CA9DB3BABAC1E82A37A132172C67088800D53D56EBE7AAB9EA3F6F66B6D5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
35
DNS requests
19
Threats
16

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2104
svchost.exe
GET
200
23.53.40.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7496
PRiJGVxiSWVstUyidB.exe
GET
200
208.95.112.1:80
http://ip-api.com/json
unknown
whitelisted
7496
PRiJGVxiSWVstUyidB.exe
GET
200
208.95.112.1:80
http://ip-api.com/json
unknown
whitelisted
7496
PRiJGVxiSWVstUyidB.exe
GET
200
208.95.112.1:80
http://ip-api.com/json
unknown
whitelisted
7496
PRiJGVxiSWVstUyidB.exe
GET
200
208.95.112.1:80
http://ip-api.com/json
unknown
whitelisted
7496
PRiJGVxiSWVstUyidB.exe
GET
200
208.95.112.1:80
http://ip-api.com/json
unknown
whitelisted
7496
PRiJGVxiSWVstUyidB.exe
GET
200
208.95.112.1:80
http://ip-api.com/json
unknown
whitelisted
7440
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
3888
BackgroundTransferHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
23.53.40.176:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
20.190.159.131:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7000
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7496
PRiJGVxiSWVstUyidB.exe
208.95.112.1:80
ip-api.com
TUT-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 23.53.40.176
  • 23.53.40.178
whitelisted
google.com
  • 216.58.206.46
whitelisted
client.wns.windows.com
  • 40.113.103.199
  • 20.197.71.89
whitelisted
login.live.com
  • 20.190.159.131
  • 40.126.31.128
  • 40.126.31.71
  • 40.126.31.0
  • 20.190.159.129
  • 20.190.159.130
  • 20.190.159.64
  • 40.126.31.1
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
ip-api.com
  • 208.95.112.1
whitelisted
dns.google
  • 8.8.4.4
  • 8.8.8.8
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted
www.bing.com
  • 2.23.227.221
  • 2.23.227.202
  • 2.23.227.215
  • 2.23.227.208
whitelisted

Threats

PID
Process
Class
Message
2196
svchost.exe
Device Retrieving External IP Address Detected
INFO [ANY.RUN] External IP Check (ip-api .com)
7496
PRiJGVxiSWVstUyidB.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup ip-api.com
7496
PRiJGVxiSWVstUyidB.exe
A Network Trojan was detected
ET USER_AGENTS Suspicious User-Agent (Clever Internet Suite)
7496
PRiJGVxiSWVstUyidB.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup ip-api.com
7496
PRiJGVxiSWVstUyidB.exe
A Network Trojan was detected
ET USER_AGENTS Suspicious User-Agent (Clever Internet Suite)
7496
PRiJGVxiSWVstUyidB.exe
A Network Trojan was detected
ET USER_AGENTS Suspicious User-Agent (Clever Internet Suite)
7496
PRiJGVxiSWVstUyidB.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup ip-api.com
7496
PRiJGVxiSWVstUyidB.exe
A Network Trojan was detected
ET USER_AGENTS Suspicious User-Agent (Clever Internet Suite)
2196
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com)
7496
PRiJGVxiSWVstUyidB.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup ip-api.com
No debug info