File name:

prestige-1.21.jar

Full analysis: https://app.any.run/tasks/4065dbfc-e70c-417c-896b-50ac7f36b7c2
Verdict: Malicious activity
Threats:

Adware is a form of malware that targets users with unwanted advertisements, often disrupting their browsing experience. It typically infiltrates systems through software bundling, malicious websites, or deceptive downloads. Once installed, it may track user activity, collect sensitive data, and display intrusive ads, including pop-ups or banners. Some advanced adware variants can bypass security measures and establish persistence on devices, making removal challenging. Additionally, adware can create vulnerabilities that other malware can exploit, posing a significant risk to user privacy and system security.

Analysis date: May 20, 2026, 07:47:40
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
etherhiding
stealer
weedhack
evasion
auto-reg
auto-sch
pua
adware
auto
websocket
loader
netreactor
purehvnc
Indicators:
MIME: application/java-archive
File info: Java archive data (JAR)
MD5:

D9A4AB8CD89789C6A966654DCA46D5FC

SHA1:

514DF5A496E709421F22099426F427CA22FE18A5

SHA256:

A030CF2D0D67065E2126B879EEE0AE0A05B98D67DD1528DA04C2C9167FBC2FAB

SSDEEP:

6144:5xBfmyH19xvufnXZW1i06NNEE+s0WRd6YfhYe6MwEYH7XQsuI3l23Ktfc7yVV:bvH9So1i06NNEUHjhYcYzT3rrVV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Stealers network behavior

      • javaw.exe (PID: 2876)
      • javaw.exe (PID: 7856)
      • javaw.exe (PID: 1652)
      • javaw.exe (PID: 2956)
    • WEEDHACK has been detected (SURICATA)

      • javaw.exe (PID: 2876)
      • javaw.exe (PID: 7856)
      • javaw.exe (PID: 1652)
      • javaw.exe (PID: 2956)
    • Known privilege escalation attack

      • dllhost.exe (PID: 2792)
    • Adds process to the Windows Defender exclusion list

      • cmd.exe (PID: 7248)
    • Run PowerShell with an invisible window

      • powershell.exe (PID: 7708)
      • powershell.exe (PID: 6112)
      • powershell.exe (PID: 4968)
      • powershell.exe (PID: 7876)
    • Changes Windows Defender settings

      • cmd.exe (PID: 7248)
      • javaw.exe (PID: 1652)
    • Changes powershell execution policy (Bypass)

      • javaw.exe (PID: 7856)
      • Telemetry.exe (PID: 7324)
    • Enumerates physical memory (Win32_PhysicalMemory) (SCRIPT)

      • powershell.exe (PID: 1980)
    • Steals credentials from Web Browsers

      • javaw.exe (PID: 7856)
    • Actions looks like stealing of personal data

      • javaw.exe (PID: 7856)
    • Changes the autorun value in the registry

      • javaw.exe (PID: 1652)
    • WEEDHACK has been detected

      • javaw.exe (PID: 1652)
    • Uses Task Scheduler to autorun other applications

      • cmd.exe (PID: 7232)
    • WEEDHACK has been found (auto)

      • javaw.exe (PID: 7856)
    • Adds path to the Windows Defender exclusion list

      • javaw.exe (PID: 1652)
    • ETHERHIDING has been detected (SURICATA)

      • AntiMalwareServiceExecutable.exe (PID: 4212)
    • PUREHVNC has been detected (YARA)

      • Telemetry.exe (PID: 7324)
    • Uses Task Scheduler to run other applications

      • javaw.exe (PID: 2956)
  • SUSPICIOUS

    • Application launched itself

      • javaw.exe (PID: 6432)
      • javaw.exe (PID: 7856)
      • javaw.exe (PID: 6500)
      • javaw.exe (PID: 1652)
    • There is functionality for VM detection VMWare (YARA)

      • javaw.exe (PID: 2876)
      • javaw.exe (PID: 7856)
      • javaw.exe (PID: 1652)
    • There is functionality for VM detection VirtualBox (YARA)

      • javaw.exe (PID: 2876)
      • javaw.exe (PID: 7856)
      • javaw.exe (PID: 1652)
    • Executable content was dropped or overwritten

      • javaw.exe (PID: 2876)
      • javaw.exe (PID: 7856)
      • javaw.exe (PID: 1652)
      • javaw.exe (PID: 6500)
      • javaw.exe (PID: 7708)
      • javaw.exe (PID: 2956)
    • There is functionality for VM detection antiVM strings (YARA)

      • javaw.exe (PID: 2876)
      • javaw.exe (PID: 7856)
      • javaw.exe (PID: 1652)
    • Used cmstp for execute code hidden within an inf file

      • javaw.exe (PID: 2876)
    • The process executes VB scripts

      • wscript.exe (PID: 6856)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 7248)
      • cmd.exe (PID: 2428)
      • cmd.exe (PID: 7976)
      • cmd.exe (PID: 7232)
      • cmd.exe (PID: 2684)
      • cmd.exe (PID: 7464)
      • cmd.exe (PID: 7388)
      • cmd.exe (PID: 5632)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 6856)
    • Executing commands from ".cmd" file

      • javaw.exe (PID: 7856)
    • Script adds exclusion process to Windows Defender

      • cmd.exe (PID: 7248)
    • Starts POWERSHELL.EXE for commands execution

      • cmd.exe (PID: 7248)
      • javaw.exe (PID: 7856)
      • javaw.exe (PID: 1652)
      • Telemetry.exe (PID: 7324)
      • javaw.exe (PID: 2956)
    • Adds exclusion path to Windows Defender (POWERSHELL)

      • cmd.exe (PID: 7248)
      • javaw.exe (PID: 1652)
    • Suspicious use of NETSH.EXE

      • javaw.exe (PID: 7856)
      • cmd.exe (PID: 7388)
    • Bypass execution policy to execute commands

      • powershell.exe (PID: 1980)
      • powershell.exe (PID: 6936)
      • powershell.exe (PID: 3136)
    • The process bypasses the loading of PowerShell profile settings

      • javaw.exe (PID: 7856)
      • Telemetry.exe (PID: 7324)
      • javaw.exe (PID: 2956)
    • Get Video Controller Information (POWERSHELL)

      • javaw.exe (PID: 7856)
    • Checks RAM size (probably for evasion)

      • javaw.exe (PID: 7856)
    • Possible stealing from browsers

      • javaw.exe (PID: 7856)
    • Possible stealing of messenger data

      • javaw.exe (PID: 7856)
    • Loads DLL from Mozilla Firefox

      • javaw.exe (PID: 7856)
    • Uses NETSH.EXE to obtain data on the network

      • javaw.exe (PID: 7856)
    • Possible stealing from crypto wallets

      • javaw.exe (PID: 7856)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 7196)
    • Creates scheduled task with highest privileges

      • cmd.exe (PID: 7232)
      • schtasks.exe (PID: 5008)
      • schtasks.exe (PID: 8000)
    • Creates scheduled task with ONLOGON parameter

      • cmd.exe (PID: 7232)
      • javaw.exe (PID: 1652)
    • The executable file from the user directory is run by the CMD process

      • Telemetry.exe (PID: 7324)
    • Reads the date of Windows installation

      • javaw.exe (PID: 6500)
    • Base64-obfuscated command line is found

      • Telemetry.exe (PID: 7324)
    • BASE64 encoded PowerShell command has been detected

      • Telemetry.exe (PID: 7324)
    • Starts process via Powershell

      • powershell.exe (PID: 4968)
      • powershell.exe (PID: 7876)
    • Access to an unwanted program domain was detected

      • svchost.exe (PID: 2232)
      • javaw.exe (PID: 2956)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • javaw.exe (PID: 2956)
      • cmd.exe (PID: 5632)
      • cmd.exe (PID: 7464)
    • Uses TASKKILL.EXE to kill process

      • javaw.exe (PID: 2956)
    • Multiple wallet extension IDs have been found

      • Telemetry.exe (PID: 7324)
  • INFO

    • Create files in a temporary directory

      • javaw.exe (PID: 6432)
      • javaw.exe (PID: 2876)
      • javaw.exe (PID: 7856)
      • javaw.exe (PID: 1652)
      • javaw.exe (PID: 6500)
      • javaw.exe (PID: 7708)
      • javaw.exe (PID: 2956)
    • Reads Environment values

      • javaw.exe (PID: 6432)
      • javaw.exe (PID: 2876)
      • javaw.exe (PID: 7856)
      • javaw.exe (PID: 1652)
      • javaw.exe (PID: 6500)
      • javaw.exe (PID: 7708)
      • javaw.exe (PID: 2956)
    • Reads CPU info

      • javaw.exe (PID: 6432)
      • javaw.exe (PID: 2876)
      • javaw.exe (PID: 7856)
      • javaw.exe (PID: 1652)
      • javaw.exe (PID: 6500)
      • javaw.exe (PID: 7708)
      • AntiMalwareServiceExecutable.exe (PID: 4212)
      • javaw.exe (PID: 2956)
    • Checks supported languages

      • javaw.exe (PID: 6432)
      • javaw.exe (PID: 2876)
      • javaw.exe (PID: 7856)
      • javaw.exe (PID: 1652)
      • Telemetry.exe (PID: 7324)
      • javaw.exe (PID: 6500)
      • javaw.exe (PID: 7708)
      • AntiMalwareServiceExecutable.exe (PID: 4212)
      • javaw.exe (PID: 2956)
      • RuntimeBroker.exe (PID: 7836)
    • Reads the machine GUID from the registry

      • javaw.exe (PID: 2876)
      • javaw.exe (PID: 7856)
      • javaw.exe (PID: 1652)
      • javaw.exe (PID: 6500)
      • Telemetry.exe (PID: 7324)
      • javaw.exe (PID: 7708)
      • AntiMalwareServiceExecutable.exe (PID: 4212)
      • javaw.exe (PID: 2956)
      • RuntimeBroker.exe (PID: 7836)
    • Reads the computer name

      • javaw.exe (PID: 2876)
      • javaw.exe (PID: 7856)
      • Telemetry.exe (PID: 7324)
      • javaw.exe (PID: 6500)
      • AntiMalwareServiceExecutable.exe (PID: 4212)
      • javaw.exe (PID: 1652)
      • javaw.exe (PID: 2956)
      • RuntimeBroker.exe (PID: 7836)
    • Creates files or folders in the user directory

      • javaw.exe (PID: 2876)
      • javaw.exe (PID: 7856)
      • javaw.exe (PID: 1652)
      • Telemetry.exe (PID: 7324)
      • javaw.exe (PID: 2956)
    • Disables trace logs

      • cmstp.exe (PID: 6936)
      • dllhost.exe (PID: 2792)
    • Checks transactions between databases Windows and Oracle

      • cmstp.exe (PID: 6936)
    • Process checks computer location settings

      • javaw.exe (PID: 7856)
      • javaw.exe (PID: 6500)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 7708)
      • powershell.exe (PID: 3136)
      • powershell.exe (PID: 6112)
    • Launching a file from a Registry key

      • javaw.exe (PID: 1652)
    • Manual execution by a user

      • javaw.exe (PID: 6500)
      • schtasks.exe (PID: 2268)
    • Reads security settings of Internet Explorer

      • javaw.exe (PID: 6500)
    • The executable file from the user directory is run by the Powershell process

      • AntiMalwareServiceExecutable.exe (PID: 4212)
      • RuntimeBroker.exe (PID: 7836)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 6112)
    • .NET Reactor protector has been detected

      • Telemetry.exe (PID: 7324)
    • Launching a file from Task Scheduler

      • javaw.exe (PID: 2956)
    • Attempting to connect via WebSocket

      • RuntimeBroker.exe (PID: 7836)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.jar | Java Archive (78.3)
.zip | ZIP compressed archive (21.6)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0808
ZipCompression: Deflated
ZipModifyDate: 2026:04:30 22:36:02
ZipCRC: 0xb4d31181
ZipCompressedSize: 228
ZipUncompressedSize: 290
ZipFileName: ps76/rxl/ζεθυψσο.class
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
210
Monitored processes
73
Malicious processes
13
Suspicious processes
6

Behavior graph

Click at the process to see the details
start javaw.exe no specs #WEEDHACK javaw.exe slui.exe cmstp.exe no specs CMSTPLUA wscript.exe no specs #WEEDHACK javaw.exe cmd.exe no specs conhost.exe no specs powershell.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs chrome.exe no specs msedge.exe no specs netsh.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs #WEEDHACK javaw.exe cmd.exe no specs conhost.exe no specs schtasks.exe no specs cmd.exe conhost.exe no specs schtasks.exe no specs javaw.exe cmd.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs #PUREHVNC telemetry.exe javaw.exe powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs #ETHERHIDING antimalwareserviceexecutable.exe #WEEDHACK javaw.exe netsh.exe no specs netsh.exe no specs conhost.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs svchost.exe powershell.exe no specs schtasks.exe no specs conhost.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs runtimebroker.exe cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs cmd.exe no specs conhost.exe no specs netsh.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
680"C:\Program Files\Google\Chrome\Application\chrome.exe"C:\Program Files\Google\Chrome\Application\chrome.exejavaw.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome
Exit code:
1
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1032netsh advfirewall firewall add rule name=\"RuntimeBroker\" dir=in action=allow program=\"C:\Users\admin\AppData\Roaming\RuntimeBroker.exe\" enable=yes profile=anyC:\Windows\System32\netsh.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1284\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1404\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1652"C:\Program Files\Java\jdk-25.0.2\bin\javaw.exe" -cp C:\Users\admin\AppData\Roaming\Microsoft\SecurityUpdates\SecurityManager.jar dev.majanito.security.Main --dont-elevate --add-to-registryC:\Program Files\Java\jdk-25.0.2\bin\javaw.exe
javaw.exe
User:
admin
Company:
N/A
Integrity Level:
HIGH
Description:
Java(TM) Platform SE binary
Version:
25.0.2.0
Modules
Images
c:\program files\java\jdk-25.0.2\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\java\jdk-25.0.2\bin\jli.dll
c:\windows\system32\ucrtbase.dll
c:\program files\java\jdk-25.0.2\bin\vcruntime140.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
1980powershell.exe -NoProfile -ExecutionPolicy Bypass -Command "& { (Get-CimInstance -ClassName Win32_ComputerSystem).TotalPhysicalMemory }"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\atl.dll
c:\windows\system32\combase.dll
2232C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2268schtasks /run /tnC:\Windows\System32\schtasks.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Scheduler Configuration Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2340\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2428cmd.exe /c "schtasks /Delete /TN "JavaSecurityUpdater" /F"C:\Windows\System32\cmd.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
Total events
0
Read events
0
Write events
0
Delete events
0

Modification events

No data
Executable files
21
Suspicious files
9
Text files
41
Unknown types
2

Dropped files

PID
Process
Filename
Type
2876javaw.exeC:\Users\admin\AppData\Local\Temp\jna-1779263277032\jnidispatch.dllexecutable
MD5:2D2475F1F026DD54E9F3E787AE4F81DA
SHA256:5A7FF949F6D93D86491EB5B26B1CFC60051168A60622650224B89995AC420023
2876javaw.exeC:\Users\admin\AppData\Local\Temp\lib7040214032857107556.tmpexecutable
MD5:3FE0E561EE3DE87C8A786DCB2B0C3D79
SHA256:B3E8C2DC252BF68E47EC2AB052592D159468F11CE9851B3DE9951D17AA24104A
2876javaw.exeC:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1693682860-607145093-2874071422-1001\83aa4cc77f591dfc2374580bbd95f6ba_bb926e54-e3ca-40fd-ae90-2764341e7792binary
MD5:C8366AE350E7019AEFC9D1E6E6A498C6
SHA256:11E6ACA8E682C046C83B721EEB5C72C5EF03CB5936C60DF6F4993511DDC61238
2876javaw.exeC:\Users\admin\AppData\Local\Temp\elv.vbstext
MD5:B31039B4157F1A447B0150BE6CBEC370
SHA256:322924421F8F1054199E8EA511E84442C38ABF1934B6499FF8DDC4F74C19F64E
2876javaw.exeC:\Users\admin\AppData\Local\Temp\elevator.jarcompressed
MD5:92D04D6BD8A0235843240BBA30D2F091
SHA256:566AD1A80220026D05099562645CE968FF0E7C36CDE22634332605BB34CC3EFF
2876javaw.exeC:\Users\admin\AppData\Local\Temp\jsadcmzpzn.acdmtext
MD5:A18FB0BBE3E67074CA6D0134C0B7D5F7
SHA256:FDCEAFE4DCF9CF6D23B2033824275C08EC73D6B01ADC644416E43ECCA94C89C9
7856javaw.exeC:\Users\admin\AppData\Local\Temp\lib12493507403996226419.tmpexecutable
MD5:F8C312605C1C695B45C459953AE01B8E
SHA256:499CF4818267FE2384C4C9DFC72BB65A2562560CFE2237CD2EF49471141DE8DA
7856javaw.exeC:\Users\admin\AppData\Local\Temp\jna-1779263285331\jnidispatch.dllexecutable
MD5:2D2475F1F026DD54E9F3E787AE4F81DA
SHA256:5A7FF949F6D93D86491EB5B26B1CFC60051168A60622650224B89995AC420023
7856javaw.exeC:\Users\admin\AppData\Local\Temp\WinDefConfig.cmdtext
MD5:B47079E54B7D1B2D8C4245991C933147
SHA256:95BA820E7D0405B2E496C6F1AF93414F425179A6E44746C7868D8CEDA6E3087A
7856javaw.exeC:\Users\admin\AppData\Roaming\debug.logtext
MD5:1F16F04C45692E0908AF8A6F6E551AFB
SHA256:9EB3FF68144B304F48C0FFEA5001678961492EE5988AB94DCC3A06EF4D78470F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
105
TCP/UDP connections
144
DNS requests
9
Threats
84

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5276
MoUsoCoreWorker.exe
GET
304
48.209.138.189:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
6260
svchost.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
2876
javaw.exe
GET
200
1.0.0.1:443
https://cloudflare-dns.com/dns-query?name=eth.llamarpc.com&type=A
AU
264 b
7588
SIHClient.exe
GET
304
74.178.240.61:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
2876
javaw.exe
GET
200
1.0.0.1:443
https://cloudflare-dns.com/dns-query?name=eth.api.onfinality.io&type=A
AU
text
288 b
unknown
2876
javaw.exe
POST
200
142.215.53.55:443
https://eth.api.onfinality.io/public
CA
text
934 b
malicious
2876
javaw.exe
GET
200
1.0.0.1:443
https://cloudflare-dns.com/dns-query?name=fucktermedfir.st&type=A
AU
text
198 b
unknown
6060
slui.exe
POST
500
48.192.1.65:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
xml
512 b
whitelisted
6260
svchost.exe
GET
200
23.52.181.212:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
GET
200
1.0.0.1:443
https://cloudflare-dns.com/dns-query?name=eth.llamarpc.com&type=A
AU
text
266 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5276
MoUsoCoreWorker.exe
48.209.138.189:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
8152
slui.exe
48.192.1.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
92.123.104.17:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
6260
svchost.exe
48.209.138.189:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
2876
javaw.exe
104.16.248.249:443
cloudflare-dns.com
CLOUDFLARENET
US
whitelisted
6260
svchost.exe
2.16.164.49:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
6260
svchost.exe
23.52.181.212:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
2876
javaw.exe
172.67.167.200:443
CLOUDFLARENET
US
whitelisted

DNS requests

Domain
IP
Reputation
activation-v2.sls.microsoft.com
  • 48.192.1.65
whitelisted
www.bing.com
  • 92.123.104.17
  • 92.123.104.21
  • 92.123.104.19
  • 92.123.104.16
  • 92.123.104.18
  • 92.123.104.13
  • 92.123.104.22
  • 92.123.104.14
  • 92.123.104.15
whitelisted
google.com
  • 142.251.13.113
  • 142.251.13.139
  • 142.251.13.102
  • 142.251.13.101
  • 142.251.13.100
  • 142.251.13.138
whitelisted
cloudflare-dns.com
  • 104.16.248.249
  • 104.16.249.249
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.72
whitelisted
www.microsoft.com
  • 23.52.181.212
whitelisted
settings-win.data.microsoft.com
  • 48.209.138.189
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted

Threats

PID
Process
Class
Message
2232
svchost.exe
Misc activity
INFO [ANY.RUN] Cloudflare DNS-over-HTTPS service requested (cloudflare-dns .com)
2876
javaw.exe
Misc activity
ET INFO Observed Cloudflare DNS over HTTPS Domain (cloudflare-dns .com in TLS SNI)
2876
javaw.exe
A Network Trojan was detected
STEALER WeedHack TLS activity observed
A Network Trojan was detected
ET MALWARE EtherHiding Exfil M2
6260
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
A Network Trojan was detected
ET MALWARE EtherHiding Exfil M2
Misc activity
INFO [ANY.RUN] DDoS-Guard Hosted Web Content observed
A Network Trojan was detected
ET MALWARE EtherHiding Exfil M2
A Network Trojan was detected
ET MALWARE EtherHiding Exfil M2
2232
svchost.exe
Misc activity
INFO [ANY.RUN] Cloudflare DNS-over-HTTPS service requested (cloudflare-dns .com)
No debug info