File name:

run.ps1

Full analysis: https://app.any.run/tasks/1ac1b454-2c8e-4b53-b330-511227f71401
Verdict: Malicious activity
Analysis date: April 11, 2025, 20:13:04
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
github
Indicators:
MIME: text/plain
File info: ASCII text
MD5:

4D7BA313A8E7F3856DBBC16A69DA43A6

SHA1:

8A92A93B9A5D743CB5BF8A6B2C4ACC24BDBA875C

SHA256:

A0BE3873AAAC715D1C6F083DF7BA1C6AF062E9076507CB542279D17A14BA55A3

SSDEEP:

24:g5eIfX0sRzfr7MGjYLz/XCs3/YbxG14/dTIdzAvvrBfI9hk:gI9UroVCsQbogjve9hk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Bypass execution policy to execute commands

      • powershell.exe (PID: 3020)
  • SUSPICIOUS

    • Gets or sets the security protocol (POWERSHELL)

      • powershell.exe (PID: 3020)
    • Explorer used for Indirect Command Execution

      • explorer.exe (PID: 2552)
    • Process drops legitimate windows executable

      • SpotifySetup.exe (PID: 6872)
    • Creates a software uninstall entry

      • SpotifySetup.exe (PID: 6872)
    • Executable content was dropped or overwritten

      • SpotifySetup.exe (PID: 6872)
  • INFO

    • Disables trace logs

      • powershell.exe (PID: 3020)
    • Reads the computer name

      • curl.exe (PID: 1348)
      • curl.exe (PID: 4112)
      • SpotifySetup.exe (PID: 6872)
      • Spotify.exe (PID: 5328)
    • Execution of CURL command

      • powershell.exe (PID: 3020)
    • Checks proxy server information

      • powershell.exe (PID: 3020)
    • Checks supported languages

      • curl.exe (PID: 1348)
      • curl.exe (PID: 2852)
      • curl.exe (PID: 4112)
      • SpotifySetup.exe (PID: 6872)
      • Spotify.exe (PID: 5328)
    • Create files in a temporary directory

      • curl.exe (PID: 4112)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 208)
    • Creates files or folders in the user directory

      • SpotifySetup.exe (PID: 6872)
    • The sample compiled with english language support

      • SpotifySetup.exe (PID: 6872)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
11
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start powershell.exe conhost.exe no specs sppextcomobj.exe no specs slui.exe no specs curl.exe no specs curl.exe curl.exe explorer.exe no specs explorer.exe no specs spotifysetup.exe spotify.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
208C:\WINDOWS\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\shcore.dll
1348"C:\WINDOWS\system32\curl.exe" -Is -w "%{http_code} \n" -o /dev/null -k https://download.scdn.co/upgrade/client/win32-x86_64/spotify_installer-1.2.61.443.gc51c574b-2143.exe --retry 2 --ssl-no-revokeC:\Windows\System32\curl.exe
powershell.exe
User:
admin
Company:
curl, https://curl.se/
Integrity Level:
MEDIUM
Description:
The curl executable
Exit code:
23
Version:
8.4.0
Modules
Images
c:\windows\system32\curl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\cryptsp.dll
2552"C:\WINDOWS\explorer.exe" C:\Users\admin\AppData\Local\Temp\SpotX_Temp-2025-04-11_20-13-21\SpotifySetup.exe C:\Windows\explorer.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\aepic.dll
2852"C:\WINDOWS\system32\curl.exe" -VC:\Windows\System32\curl.exepowershell.exe
User:
admin
Company:
curl, https://curl.se/
Integrity Level:
MEDIUM
Description:
The curl executable
Exit code:
0
Version:
8.4.0
Modules
Images
c:\windows\system32\curl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\cryptsp.dll
3020"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ep bypass C:\Users\admin\AppData\Local\Temp\run.ps1C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4112"C:\WINDOWS\system32\curl.exe" -q -k https://download.scdn.co/upgrade/client/win32-x86_64/spotify_installer-1.2.61.443.gc51c574b-2143.exe -o C:\Users\admin\AppData\Local\Temp\SpotX_Temp-2025-04-11_20-13-21\SpotifySetup.exe --progress-bar --retry 3 --ssl-no-revokeC:\Windows\System32\curl.exe
powershell.exe
User:
admin
Company:
curl, https://curl.se/
Integrity Level:
MEDIUM
Description:
The curl executable
Exit code:
0
Version:
8.4.0
Modules
Images
c:\windows\system32\curl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\cryptsp.dll
5328Spotify.exeC:\Users\admin\AppData\Roaming\Spotify\Spotify.exeSpotifySetup.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
Spotify
Exit code:
4294967295
Version:
1.2.61.443
Modules
Images
c:\users\admin\appdata\roaming\spotify\spotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
5428\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6712C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6872"C:\Users\admin\AppData\Local\Temp\SpotX_Temp-2025-04-11_20-13-21\SpotifySetup.exe" C:\Users\admin\AppData\Local\Temp\SpotX_Temp-2025-04-11_20-13-21\SpotifySetup.exe
explorer.exe
User:
admin
Company:
Spotify Ltd
Integrity Level:
MEDIUM
Description:
SpotifyInstaller
Exit code:
0
Version:
0,0,0,0
Modules
Images
c:\users\admin\appdata\local\temp\spotx_temp-2025-04-11_20-13-21\spotifysetup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.19041.3636_none_60b6a03d71f818d5\comctl32.dll
c:\windows\system32\msvcrt.dll
Total events
9 317
Read events
9 304
Write events
12
Delete events
1

Modification events

(PID) Process:(208) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(6872) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:Spotify Web Helper
Value:
(PID) Process:(6872) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Roaming\Spotify\Spotify.exe
(PID) Process:(6872) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:DisplayName
Value:
Spotify
(PID) Process:(6872) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:DisplayVersion
Value:
1.2.61.443.gc51c574b
(PID) Process:(6872) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:Version
Value:
1.2.61.443.gc51c574b
(PID) Process:(6872) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:InstallDate
Value:
20250411
(PID) Process:(6872) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Roaming\Spotify
(PID) Process:(6872) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:NoModify
Value:
1
(PID) Process:(6872) SpotifySetup.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Spotify
Operation:writeName:NoRepair
Value:
1
Executable files
14
Suspicious files
165
Text files
2
Unknown types
8

Dropped files

PID
Process
Filename
Type
4112curl.exeC:\Users\admin\AppData\Local\Temp\SpotX_Temp-2025-04-11_20-13-21\SpotifySetup.exe
MD5:
SHA256:
3020powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_hs5ygcsz.cpy.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
3020powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-msbinary
MD5:E4CAE3A2850B332EA1EAC7D3857127C0
SHA256:559E7A0308441FD2328E0AADB52C0E48705B63BC3939202A4E09487390E2BF31
6872SpotifySetup.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_6872_6_~binary
MD5:7A8835F72D1328BE060C4E4060BD72E5
SHA256:55555D8A2C2175305330BADA0C7A79B67B0CE7BD3E1FE5C7F6A784B10F7A26E6
6872SpotifySetup.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_6872_4_~binary
MD5:08C6CA419FA8D19A56A39776D7C7EC95
SHA256:469FED3B4F159631F5B11E85D33EBB92F5E4C1ABD5D5012B1FCD23D877A08032
6872SpotifySetup.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_6872_8_~gmo
MD5:F774C61DBF4CBF171DFBD8B6F5EB152B
SHA256:EB76D12996E22D3EB5D429B9BBAAF7FF9BCEEA924A480BD589ED157A583E93D5
6872SpotifySetup.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_6872_0_~compressed
MD5:0E974B9347F75E0AA3B00889E6AC5B88
SHA256:51955B5FF76AA3B7C4A8921BFDE37891F1CA88314A867B66E772A456A4C0AABC
6872SpotifySetup.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_6872_12_~binary
MD5:84090FE7F890D22FCE237E9E227CD2A6
SHA256:93B44D4FE094C4CF35CF318389601FFAD29CA24B1C27C113E23F26E79DB18002
6872SpotifySetup.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_6872_16_~binary
MD5:017ACFCF49364437E9349E284265E6FA
SHA256:ABA11A95E4C38E157D7217F026EB53A3A3611BDB5702839A5BDF403EACB5534C
6872SpotifySetup.exeC:\Users\admin\AppData\Roaming\Spotify\~TMP_6872_18_~binary
MD5:3FE8F1206F6D9A9673D4A1E00B3F31A6
SHA256:A8F4E33DD4BBC493C35D1191CEB7F9548852CEBA972CF955A8E91556FF91FFF8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
20
DNS requests
15
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5384
SIHClient.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
GET
200
23.48.23.173:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5384
SIHClient.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
23.48.23.173:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
3020
powershell.exe
185.199.108.133:443
raw.githubusercontent.com
FASTLY
US
whitelisted
6544
svchost.exe
20.190.159.129:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1348
curl.exe
199.232.210.248:443
download.scdn.co
FASTLY
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.48.23.173
  • 23.48.23.169
  • 23.48.23.158
  • 23.48.23.162
  • 23.48.23.159
  • 23.48.23.177
  • 23.48.23.190
  • 23.48.23.176
  • 23.48.23.156
whitelisted
google.com
  • 142.250.186.46
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
raw.githubusercontent.com
  • 185.199.108.133
  • 185.199.110.133
  • 185.199.109.133
  • 185.199.111.133
whitelisted
login.live.com
  • 20.190.159.129
  • 20.190.159.64
  • 40.126.31.73
  • 40.126.31.0
  • 20.190.159.4
  • 20.190.159.2
  • 40.126.31.2
  • 20.190.159.75
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
download.scdn.co
  • 199.232.210.248
  • 199.232.214.248
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
www.microsoft.com
  • 69.192.161.161
whitelisted

Threats

PID
Process
Class
Message
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
No debug info