File name:

4E-Client.jar

Full analysis: https://app.any.run/tasks/d218d650-58cb-45c3-aa9d-991f5eea2e0e
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: April 30, 2026, 12:05:45
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
stealer
weedhack
anti-evasion
rat
pua
adware
auto
rustystealer
Indicators:
MIME: application/java-archive
File info: Java archive data (JAR)
MD5:

F2D8FABC84054FCB7A1E0B6A679A31BF

SHA1:

5BC5CC9058F88A622F2811BF97F3BCEA9DE8F736

SHA256:

7E476F0FC826A0AE24AAEA89AFD93EEC3E8B6260ADCD17E7B50C8A71AA6CA002

SSDEEP:

98304:YJddEvnLEgC4+IIsk/iwHWLU+wWFeZNTtkKiWoXIFdotqXrKMZhjHMwXZ5dZVJ8k:PK4k

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Stealers network behavior

      • javaw.exe (PID: 8020)
      • javaw.exe (PID: 4276)
    • WEEDHACK has been detected (SURICATA)

      • javaw.exe (PID: 8020)
      • javaw.exe (PID: 4276)
    • Known privilege escalation attack

      • dllhost.exe (PID: 5752)
    • Adds process to the Windows Defender exclusion list

      • cmd.exe (PID: 7964)
    • Run PowerShell with an invisible window

      • powershell.exe (PID: 4348)
      • powershell.exe (PID: 5884)
      • powershell.exe (PID: 5264)
    • Changes Windows Defender settings

      • cmd.exe (PID: 7964)
      • javaw.exe (PID: 2164)
    • Changes powershell execution policy (Bypass)

      • javaw.exe (PID: 4276)
      • Telemetry.exe (PID: 4336)
    • Steals credentials from Web Browsers

      • javaw.exe (PID: 4276)
    • Actions looks like stealing of personal data

      • javaw.exe (PID: 4276)
      • Telemetry.exe (PID: 4336)
    • Enumerates physical memory (Win32_PhysicalMemory) (SCRIPT)

      • powershell.exe (PID: 7116)
    • WEEDHACK has been detected

      • javaw.exe (PID: 2164)
    • Changes the autorun value in the registry

      • javaw.exe (PID: 2164)
    • Uses Task Scheduler to autorun other applications

      • cmd.exe (PID: 6856)
    • Adds path to the Windows Defender exclusion list

      • javaw.exe (PID: 2164)
    • WEEDHACK has been found (auto)

      • javaw.exe (PID: 2164)
    • Uses Task Scheduler to run other applications

      • javaw.exe (PID: 6884)
    • RUSTYSTEALER has been found (auto)

      • javaw.exe (PID: 6884)
  • SUSPICIOUS

    • Application launched itself

      • javaw.exe (PID: 8100)
      • javaw.exe (PID: 4276)
      • javaw.exe (PID: 2164)
    • Executable content was dropped or overwritten

      • javaw.exe (PID: 8020)
      • javaw.exe (PID: 4276)
      • javaw.exe (PID: 2164)
      • Telemetry.exe (PID: 4336)
      • javaw.exe (PID: 6884)
    • Used cmstp for execute code hidden within an inf file

      • javaw.exe (PID: 8020)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 6632)
    • Adds exclusion path to Windows Defender (POWERSHELL)

      • cmd.exe (PID: 7964)
      • javaw.exe (PID: 2164)
    • Executing commands from ".cmd" file

      • javaw.exe (PID: 4276)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 7964)
      • cmd.exe (PID: 2452)
      • cmd.exe (PID: 680)
      • cmd.exe (PID: 6856)
      • cmd.exe (PID: 7888)
    • Starts POWERSHELL.EXE for commands execution

      • cmd.exe (PID: 7964)
      • javaw.exe (PID: 4276)
      • javaw.exe (PID: 2164)
      • Telemetry.exe (PID: 4336)
      • javaw.exe (PID: 6884)
    • Script adds exclusion process to Windows Defender

      • cmd.exe (PID: 7964)
    • The process bypasses the loading of PowerShell profile settings

      • javaw.exe (PID: 4276)
      • Telemetry.exe (PID: 4336)
      • javaw.exe (PID: 6884)
    • Bypass execution policy to execute commands

      • powershell.exe (PID: 6936)
      • powershell.exe (PID: 7116)
      • powershell.exe (PID: 7224)
    • Possible stealing of messenger data

      • javaw.exe (PID: 4276)
    • Possible stealing from browsers

      • javaw.exe (PID: 4276)
    • Uses NETSH.EXE to obtain data on the network

      • javaw.exe (PID: 4276)
    • Loads DLL from Mozilla Firefox

      • javaw.exe (PID: 4276)
    • Possible stealing from crypto wallets

      • javaw.exe (PID: 4276)
      • Telemetry.exe (PID: 4336)
    • Creates scheduled task with highest privileges

      • cmd.exe (PID: 6856)
      • schtasks.exe (PID: 5724)
      • schtasks.exe (PID: 5616)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 488)
    • Creates scheduled task with ONLOGON parameter

      • javaw.exe (PID: 2164)
      • cmd.exe (PID: 6856)
    • The executable file from the user directory is run by the CMD process

      • Telemetry.exe (PID: 4336)
    • Base64-obfuscated command line is found

      • Telemetry.exe (PID: 4336)
    • BASE64 encoded PowerShell command has been detected

      • Telemetry.exe (PID: 4336)
    • Access to an unwanted program domain was detected

      • svchost.exe (PID: 2232)
      • javaw.exe (PID: 6884)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • javaw.exe (PID: 6884)
      • RuntimeBroker.exe (PID: 5784)
    • Starts process via Powershell

      • powershell.exe (PID: 5264)
    • Uses TASKKILL.EXE to kill process

      • javaw.exe (PID: 6884)
    • Suspicious use of NETSH.EXE

      • RuntimeBroker.exe (PID: 5784)
  • INFO

    • Reads Environment values

      • javaw.exe (PID: 8100)
      • javaw.exe (PID: 8020)
      • javaw.exe (PID: 4276)
      • javaw.exe (PID: 2164)
      • javaw.exe (PID: 6884)
    • Checks supported languages

      • javaw.exe (PID: 8020)
      • javaw.exe (PID: 8100)
      • javaw.exe (PID: 4276)
      • javaw.exe (PID: 2164)
      • Telemetry.exe (PID: 4336)
      • javaw.exe (PID: 6884)
      • RuntimeBroker.exe (PID: 5784)
    • Reads CPU info

      • javaw.exe (PID: 8100)
      • javaw.exe (PID: 8020)
      • javaw.exe (PID: 4276)
      • javaw.exe (PID: 2164)
      • javaw.exe (PID: 6884)
    • Create files in a temporary directory

      • javaw.exe (PID: 8020)
      • javaw.exe (PID: 8100)
      • javaw.exe (PID: 4276)
      • javaw.exe (PID: 2164)
      • javaw.exe (PID: 6884)
    • Reads the machine GUID from the registry

      • javaw.exe (PID: 8020)
      • javaw.exe (PID: 4276)
      • javaw.exe (PID: 2164)
      • Telemetry.exe (PID: 4336)
      • javaw.exe (PID: 6884)
    • Reads the computer name

      • javaw.exe (PID: 8020)
      • javaw.exe (PID: 4276)
      • Telemetry.exe (PID: 4336)
      • javaw.exe (PID: 2164)
      • javaw.exe (PID: 6884)
      • RuntimeBroker.exe (PID: 5784)
    • Creates files or folders in the user directory

      • javaw.exe (PID: 8020)
      • javaw.exe (PID: 4276)
      • javaw.exe (PID: 2164)
      • Telemetry.exe (PID: 4336)
      • javaw.exe (PID: 6884)
    • Disables trace logs

      • cmstp.exe (PID: 1280)
      • dllhost.exe (PID: 5752)
    • Checks transactions between databases Windows and Oracle

      • cmstp.exe (PID: 1280)
    • Process checks computer location settings

      • javaw.exe (PID: 4276)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 4348)
      • powershell.exe (PID: 5884)
      • powershell.exe (PID: 7224)
    • Launching a file from a Registry key

      • javaw.exe (PID: 2164)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 5884)
    • Launching a file from Task Scheduler

      • javaw.exe (PID: 6884)
    • The executable file from the user directory is run by the Powershell process

      • RuntimeBroker.exe (PID: 5784)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.jar | Java Archive (78.3)
.zip | ZIP compressed archive (21.6)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0808
ZipCompression: Deflated
ZipModifyDate: 2026:04:24 19:22:36
ZipCRC: 0x5ba151b3
ZipCompressedSize: 350
ZipUncompressedSize: 617
ZipFileName: dev/FORE/event/events/PacketReceiveEvent.class
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
193
Monitored processes
57
Malicious processes
10
Suspicious processes
5

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
488schtasks /Delete /TN "JavaSecurityUpdater" /FC:\Windows\System32\schtasks.exe—cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Scheduler Configuration Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
672\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe—cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
680cmd.exe /c "schtasks /Delete /TN "JavaSecurityUpdater" /F"C:\Windows\System32\cmd.exe—javaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
1280cmstp.exe /au "C:\Users\admin\AppData\Local\Temp\\pcyyyehreo.acdm"C:\Windows\System32\cmstp.exe—javaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Connection Manager Profile Installer
Exit code:
0
Version:
7.2.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmstp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1280powershell.exe -NoProfile -Command "& { Get-CimInstance Win32_Processor | Select-Object -ExpandProperty Name }"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe—javaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1776\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe—powershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1904powershell.exe -NoProfile -Command "& { (Get-CimInstance Win32_OperatingSystem | Select-Object -ExpandProperty Caption) }"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe—javaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\atl.dll
2000"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe—javaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Edge
Exit code:
1
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2000"netsh" advfirewall firewall add rule "name=Runtime Broker" dir=in action=allow program=C:\Users\admin\AppData\Roaming\RuntimeBroker.exe enable=yes profile=anyC:\Windows\System32\netsh.exe—RuntimeBroker.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2116netsh advfirewall firewall add rule name=JavaRuntime dir=out action=allow "program=C:\Program Files\Java\jdk-25.0.2\bin\javaw.exe" enable=yes profile=anyC:\Windows\System32\netsh.exe—javaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
0
Read events
0
Write events
0
Delete events
0

Modification events

No data
Executable files
17
Suspicious files
12
Text files
39
Unknown types
0

Dropped files

PID
Process
Filename
Type
8020javaw.exeC:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1693682860-607145093-2874071422-1001\83aa4cc77f591dfc2374580bbd95f6ba_bb926e54-e3ca-40fd-ae90-2764341e7792binary
MD5:C8366AE350E7019AEFC9D1E6E6A498C6
SHA256:11E6ACA8E682C046C83B721EEB5C72C5EF03CB5936C60DF6F4993511DDC61238
8020javaw.exeC:\Users\admin\AppData\Local\Temp\jna-1777550757051\jnidispatch.dllexecutable
MD5:2D2475F1F026DD54E9F3E787AE4F81DA
SHA256:5A7FF949F6D93D86491EB5B26B1CFC60051168A60622650224B89995AC420023
8020javaw.exeC:\Users\admin\AppData\Local\Temp\elevator.jarcompressed
MD5:AF5AC1A090A2A697C9BAD0E2664D4CC0
SHA256:D047A0EE8B0D3BB82092FDD0B975E30A7884A5517FC4546A4A3EE4362E744F0E
4276javaw.exeC:\Users\admin\AppData\Local\Temp\jna-1777550760131\jnidispatch.dllexecutable
MD5:2D2475F1F026DD54E9F3E787AE4F81DA
SHA256:5A7FF949F6D93D86491EB5B26B1CFC60051168A60622650224B89995AC420023
8020javaw.exeC:\Users\admin\AppData\Local\Temp\elv.vbstext
MD5:207759F1B81BA1D11EBFF80B544F3116
SHA256:69BEDFE9EE3E16DDD889AE414102EBBDF60AC1F4F313EC23A3C6EC29C8FF3D6B
8020javaw.exeC:\Users\admin\AppData\Local\Temp\lib6287677254473759961.tmpexecutable
MD5:DE07C8272A7903D533077CCF34EEE3F1
SHA256:E00B9A815F9272610487A32A99555D23238D906DCFDDF266FA75D9081DA3DFBF
4276javaw.exeC:\Users\admin\AppData\Local\Temp\lib9016885302958222793.tmpexecutable
MD5:B3873855183FA7FCF9C8EDA1F75210BE
SHA256:B583EBC33DD5772C3FA6677E0CFA665FADD6A8E9BBCB3904E74B2BAE81A5100A
4276javaw.exeC:\Users\admin\AppData\Local\Temp\WinDefConfig.cmdtext
MD5:C925DCFC4CDBDBED3465824646A660FB
SHA256:1B5CA4D2B5EB23041DA0F6EFFDC408D50768701D4140A21C9FBD244F9458D720
4348powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_shrgqe2l.swr.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
4348powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivebinary
MD5:E9D8FD78F9B936E538F8CD91FD2B5566
SHA256:0E4002370B7418A74A85584B27072E1F845754A969FAC6437E1053B0B9B4741C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
63
DNS requests
25
Threats
19

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5276
MoUsoCoreWorker.exe
GET
304
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
—
—
whitelisted
1400
SIHClient.exe
GET
304
74.178.240.61:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
—
—
whitelisted
1400
SIHClient.exe
GET
200
20.165.94.54:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
—
—
whitelisted
1400
SIHClient.exe
GET
200
74.178.240.61:443
https://slscr.update.microsoft.com/sls/ping
US
—
—
whitelisted
1400
SIHClient.exe
GET
304
74.178.240.61:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
—
—
whitelisted
5392
svchost.exe
GET
304
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
—
—
whitelisted
5392
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
5392
svchost.exe
GET
200
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/WaaSAssessment?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&ring=Retail&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=10.0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=WaaSAssessment&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&ServicingBranch=CB&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&HonorWUfBDeferrals=1&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
text
5.80 Kb
whitelisted
5316
svchost.exe
GET
200
23.11.41.157:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAz1vQYrVgL0erhQLCPM8GY%3D
NL
binary
471 b
whitelisted
5392
svchost.exe
GET
200
23.52.181.212:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
—
Not routed
—
whitelisted
5392
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5276
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7352
slui.exe
48.192.1.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
—
Not routed
—
whitelisted
8020
javaw.exe
104.16.248.249:443
cloudflare-dns.com
CLOUDFLARENET
US
whitelisted
8020
javaw.exe
172.67.167.200:443
eth.llamarpc.com
CLOUDFLARENET
US
whitelisted
8020
javaw.exe
142.215.53.55:443
eth.api.onfinality.io
EQUINIX
NL
malicious
8020
javaw.exe
185.178.208.129:443
whpayment.ru
DDOS-GUARD
RU
malicious
8020
javaw.exe
104.21.67.22:443
eth.llamarpc.com
CLOUDFLARENET
US
whitelisted

DNS requests

Domain
IP
Reputation
activation-v2.sls.microsoft.com
  • 48.192.1.64
whitelisted
google.com
  • 142.251.20.139
  • 142.251.20.100
  • 142.251.20.101
  • 142.251.20.138
  • 142.251.20.113
  • 142.251.20.102
whitelisted
cloudflare-dns.com
  • 104.16.248.249
  • 104.16.249.249
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 23.52.181.212
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.160.66
  • 20.190.160.14
  • 20.190.160.128
  • 40.126.32.68
  • 20.190.160.131
  • 20.190.160.17
  • 40.126.32.74
  • 40.126.32.138
whitelisted
ocsp.digicert.com
  • 23.11.41.157
whitelisted
repo1.maven.org
  • 104.18.18.12
  • 104.18.19.12
whitelisted

Threats

PID
Process
Class
Message
2232
svchost.exe
Misc activity
INFO [ANY.RUN] Cloudflare DNS-over-HTTPS service requested (cloudflare-dns .com)
8020
javaw.exe
Misc activity
ET INFO Observed Cloudflare DNS over HTTPS Domain (cloudflare-dns .com in TLS SNI)
8020
javaw.exe
A Network Trojan was detected
STEALER WeedHack TLS activity observed
8020
javaw.exe
A Network Trojan was detected
STEALER WeedHack TLS activity observed
4276
javaw.exe
A Network Trojan was detected
STEALER WeedHack TLS activity observed
5392
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
4336
Telemetry.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/Common RAT related JA3 hash observed
4336
Telemetry.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/Common RAT related JA3S hash observed
4336
Telemetry.exe
Misc activity
HUNTING [ANY.RUN] TLS cert too long-lived (>2029-12-31)
2232
svchost.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Observed DNS Query to Bandwidth Sharing Tool Domain (earn .fm)
No debug info