File name:

π™³πšŽπšπšŠπš•πš•πšŽ π™°πšπš“πšžπš—πšπš˜_318_240.zip

Full analysis: https://app.any.run/tasks/6cf1ef6e-bcff-4d4a-adec-f357037d4802
Verdict: Malicious activity
Analysis date: October 03, 2025, 16:55:54
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
anti-evasion
Indicators:
MIME: application/zip
File info: Zip archive data, at least v2.0 to extract, compression method=store
MD5:

BFEEECB19FE06FF62A7C0E5FA25CD99B

SHA1:

83A7843F7CD58D254B12917F6EF42EAD5604A6FF

SHA256:

92809A2153E33EB3E323341A09ED6D46D93C13D6448328D97128144CE4C35035

SSDEEP:

96:6lzXjI0CXxYwPVGX8J1Ei3iExGaWAXr9W/mtJZVcvnFV/vVA:000CuW3VxtWujrIvr/va

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Gets username (SCRIPT)

      • mshta.exe (PID: 8456)
    • Accesses environment variables (SCRIPT)

      • mshta.exe (PID: 8456)
    • Checks whether a specified folder exists (SCRIPT)

      • mshta.exe (PID: 8456)
    • Collects BIOS Properties (Win32_BIOS) (SCRIPT)

      • mshta.exe (PID: 8456)
  • SUSPICIOUS

    • Accesses current user name via WMI (SCRIPT)

      • mshta.exe (PID: 8456)
    • Gets computer name (SCRIPT)

      • mshta.exe (PID: 8456)
    • Accesses computer name via WMI (SCRIPT)

      • mshta.exe (PID: 8456)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • mshta.exe (PID: 8456)
    • Executes WMI query (SCRIPT)

      • mshta.exe (PID: 8456)
    • Accesses language version of the operating system installed via WMI (SCRIPT)

      • mshta.exe (PID: 8456)
    • Accesses WMI object, sets custom ImpersonationLevel (SCRIPT)

      • mshta.exe (PID: 8456)
    • Enumerates operating system information (Win32_OperatingSystem) (SCRIPT)

      • mshta.exe (PID: 8456)
  • INFO

    • Manual execution by a user

      • mshta.exe (PID: 8456)
      • notepad++.exe (PID: 8900)
    • Reads Internet Explorer settings

      • mshta.exe (PID: 8456)
    • Checks proxy server information

      • mshta.exe (PID: 8456)
Find more information about signature artifacts and mapping to MITRE ATT&CKβ„’ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: None
ZipModifyDate: 2025:10:03 11:43:06
ZipCRC: 0x00000000
ZipCompressedSize: -
ZipUncompressedSize: -
ZipFileName: /\s/OB9BOl84/ XVLGBFRXJTP
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
171
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
2428C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2944"C:\Program Files\WinRAR\WinRAR.exe" "C:\Users\admin\AppData\Local\Temp\π™³πšŽπšπšŠπš•πš•πšŽ π™°πšπš“πšžπš—πšπš˜_318_240.zip"C:\Program Files\WinRAR\WinRAR.exeβ€”explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Exit code:
0
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
8456"C:\Windows\SysWOW64\mshta.exe" "C:\Users\admin\Desktop\π™³πšŽπšπšŠπš•πš•πšŽ π™°πšπš“πšžπš—πšπš˜_318395.hta" {1E460BD7-F1C3-4B2E-88BF-4E770A288AF5}{1E460BD7-F1C3-4B2E-88BF-4E770A288AF5} C:\Windows\SysWOW64\mshta.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft (R) HTML Application host
Exit code:
0
Version:
11.00.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\mshta.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\advapi32.dll
8900"C:\Program Files\Notepad++\notepad++.exe" "C:\Users\admin\Desktop\π™³πšŽπšπšŠπš•πš•πšŽ π™°πšπš“πšžπš—πšπš˜_318395.hta"C:\Program Files\Notepad++\notepad++.exe
explorer.exe
User:
admin
Company:
Don HO don.h@free.fr
Integrity Level:
MEDIUM
Description:
Notepad++ : a free (GNU) source code editor
Exit code:
0
Version:
7.91
Modules
Images
c:\program files\notepad++\notepad++.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\comctl32.dll
9132C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exeβ€”svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
6Β 960
Read events
6Β 919
Write events
28
Delete events
13

Modification events

(PID) Process:(2944)Β WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2944)Β WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2944)Β WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(2944)Β WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(2944)Β WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2944)Β WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\π™³πšŽπšπšŠπš•πš•πšŽ π™°πšπš“πšžπš—πšπš˜_318_240.zip
(PID) Process:(2944)Β WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2944)Β WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2944)Β WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2944)Β WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
0
Suspicious files
7
Text files
10
Unknown types
0

Dropped files

PID
Process
Filename
Type
8456mshta.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\83D863F495E7D991917B3ABB3E1EB382_552A1FD08486B486377D3C2208603584binary
MD5:D42FE64ACC33CF08CF1E8F276D2D3C9A
SHA256:83B5DA8BAD9FB442D70D1D9357430460F79B96192A14E90C3C3FADCE71FF7889
8456mshta.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517binary
MD5:6AB9279647E6795D3A6FDA750A0439A9
SHA256:87F175790FFB7613BC7802FC4369F39FFECD5819A36E8082493041E3AD9E4B69
8456mshta.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751binary
MD5:7F924EAEA21BB91214FF7B4525F3BD29
SHA256:E718475014C8F51A8F2746FBE90A7BFF516B65BEF36EE6340A5FC746BC5DFC32
8456mshta.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_645BC4A49DCDC40FE5917FA45C6D4517binary
MD5:0015D6FCC975215B9120C26282A51E56
SHA256:EB42C80C8C7F6B0D9BB7166675A2B9F94291F7E329037BA8D92CD2B6961863D5
8456mshta.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\3F23679C268B8B3767EE301A5B644533binary
MD5:14E3674B472EA814EFE4012904F5A525
SHA256:40B84981AB38761210CE149747B60A3A6B45FFDB33E140D6434FBFE337285156
8456mshta.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\E4DJRUXW\cid[1].htmxml
MD5:E2F9F0D69A6B63EA3786F1F485ED1368
SHA256:9A48031E7932B6630C071D1FEFC4CF3424D586C085076BF6E1D69B145CA3B997
8456mshta.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\83D863F495E7D991917B3ABB3E1EB382_552A1FD08486B486377D3C2208603584binary
MD5:30A2052779DBA3CC76098CB1A6DA2868
SHA256:CCA533F2670E7E947037BE4A05FA8A9066A5A245E41C840CEA109487FBC3F5AF
8900notepad++.exeC:\Users\admin\AppData\Roaming\Notepad++\langs.xmlxml
MD5:FE22EC5755BC98988F9656F73B2E6FB8
SHA256:F972C425CE176E960F6347F1CA2F64A8CE2B95A375C33A03E57538052BA0624D
8900notepad++.exeC:\Users\admin\AppData\Roaming\Notepad++\session.xmltext
MD5:4B813EFBA08D0D9FA75BE69199C94B1B
SHA256:5ECE8B3798811E258683A24F25ED067C578CCAF14881F598BD89CA09E4519314
8456mshta.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\3F23679C268B8B3767EE301A5B644533binary
MD5:1B4FF19077F1152B74B6802AD8ABD5CE
SHA256:C8EB6B17E14E7E90C4FBCDDDD951D954233EA6F30CABF631ED224E7FA4716C35
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
38
DNS requests
20
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
8456
mshta.exe
GET
200
18.173.208.27:80
http://ocsp.r2m03.amazontrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQqHI%2BsdmapawQncL1rpCEZZ8gTSAQUVdkYX9IczAHhWLS%2Bq9lVQgHXLgICEASSLs8bivtMtQSolDXxm6c%3D
US
binary
471 b
whitelisted
2380
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
whitelisted
8456
mshta.exe
GET
200
104.18.20.213:80
http://r13.c.lencr.org/17.crl
unknown
binary
83.3 Kb
whitelisted
4068
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
whitelisted
7072
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
313 b
whitelisted
4076
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
8456
mshta.exe
GET
200
18.245.38.235:80
http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkzUBtJnwJkc3SmanzgxeYU%3D
US
binary
1.40 Kb
whitelisted
4076
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
β€”
β€”
β€”
whitelisted
6016
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7160
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
β€”
β€”
β€”
whitelisted
5224
SearchApp.exe
95.101.136.194:443
www.bing.com
Akamai International B.V.
GB
whitelisted
4076
svchost.exe
20.190.160.17:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4076
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
7072
backgroundTaskHost.exe
95.101.136.194:443
www.bing.com
Akamai International B.V.
GB
whitelisted
7072
backgroundTaskHost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
3464
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.78
whitelisted
www.bing.com
  • 95.101.136.194
  • 95.101.136.201
whitelisted
login.live.com
  • 20.190.160.17
  • 20.190.160.65
  • 40.126.32.136
  • 20.190.160.130
  • 40.126.32.68
  • 40.126.32.138
  • 40.126.32.74
  • 20.190.160.2
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
fd.api.iris.microsoft.com
  • 20.31.169.57
whitelisted
club-ui-static-files.cb.hotmart.com
  • 99.84.152.39
  • 99.84.152.30
  • 99.84.152.107
  • 99.84.152.14
unknown
filesprocesomxs.cotilandiasolutions.com
  • 68.178.207.114
unknown

Threats

PID
Process
Class
Message
β€”
β€”
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
β€”
β€”
Misc activity
SUSPICIOUS [ANY.RUN] JavaScript Obfuscation (ParseInt)
β€”
β€”
A Network Trojan was detected
ET MALWARE Likely Malicious Windows SCT Download MSXMLHTTP AX M2
β€”
β€”
Misc activity
ET HUNTING [TW] Likely Javascript-Obfuscator Usage Observed M1
β€”
β€”
Misc activity
ET HUNTING [TW] Likely Javascript-Obfuscator Usage Observed M2
β€”
β€”
Misc activity
ET HUNTING [TW] Likely Javascript-Obfuscator Usage Observed M3
Process
Message
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\SciLexer.dll
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: error while getting certificate informations