File name:

b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df

Full analysis: https://app.any.run/tasks/d94d2041-332b-45f6-9f70-fb96e4431bda
Verdict: Malicious activity
Threats:

Agent Tesla is spyware that collects information about the actions of its victims by recording keystrokes and user interactions. It is falsely marketed as a legitimate software on the dedicated website where this malware is sold.

Analysis date: September 03, 2025, 17:27:04
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto-sch-xml
stealer
evasion
ultravnc
rmm-tool
telegram
exfiltration
agenttesla
ims-api
generic
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

080829053664C4EF0128C3B048DF6880

SHA1:

46827F4E141081C08C5B782905440598803DDFC8

SHA256:

B146EE56F4EA9BE0D7A80FDFE9B030FEBF1BF40F901D00760231A35990B6A3DF

SSDEEP:

24576:SIpbfOmoQXhIndjmMuMRHi5kuqj6K60Wpwb0agEQ/gJTj:SIpbfOmoQXhIndjduMRHi5Bqj6K60WpU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Uses Task Scheduler to run other applications

      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 4948)
    • Changes the autorun value in the registry

      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 6392)
    • Steals credentials from Web Browsers

      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 6392)
    • AGENTTESLA has been detected (YARA)

      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 6392)
    • Actions looks like stealing of personal data

      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 6392)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 4948)
    • Executable content was dropped or overwritten

      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 4948)
      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 6392)
    • Application launched itself

      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 4948)
    • Checks for external IP

      • svchost.exe (PID: 2200)
      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 6392)
    • The process connected to a server suspected of theft

      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 6392)
    • Process communicates with Telegram (possibly using it as an attacker's C2 server)

      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 6392)
    • Possible usage of Discord/Telegram API has been detected (YARA)

      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 6392)
  • INFO

    • Create files in a temporary directory

      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 4948)
    • Process checks computer location settings

      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 4948)
    • Creates files or folders in the user directory

      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 4948)
      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 6392)
    • Reads the machine GUID from the registry

      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 4948)
      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 6392)
    • Checks supported languages

      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 4948)
      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 6392)
    • Reads the computer name

      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 4948)
      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 6392)
    • Disables trace logs

      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 6392)
    • Checks proxy server information

      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 6392)
    • Reads the software policy settings

      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 6392)
    • Launching a file from a Registry key

      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 6392)
    • ULTRAVNC has been detected

      • b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe (PID: 6392)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

ims-api

(PID) Process(6392) b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe
Telegram-Tokens (1)7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8
Telegram-Info-Links
7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8
Get info about bothttps://api.telegram.org/bot7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8/getMe
Get incoming updateshttps://api.telegram.org/bot7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8/getUpdates
Get webhookhttps://api.telegram.org/bot7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8/deleteWebhook?drop_pending_updates=true
Telegram-Tokens (1)7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8
Telegram-Info-Links
7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8
Get info about bothttps://api.telegram.org/bot7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8/getMe
Get incoming updateshttps://api.telegram.org/bot7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8/getUpdates
Get webhookhttps://api.telegram.org/bot7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8/deleteWebhook?drop_pending_updates=true
Telegram-Requests
Token7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8
End-PointsendDocument
Args
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (56.7)
.exe | Win64 Executable (generic) (21.3)
.scr | Windows screen saver (10.1)
.dll | Win32 Dynamic Link Library (generic) (5)
.exe | Win32 Executable (generic) (3.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:04:17 02:44:20+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 738304
InitializedDataSize: 6656
UninitializedDataSize: -
EntryPoint: 0xb629a
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: VideoSplit
CompanyName: -
FileDescription: VideoSplit
FileVersion: 1.0.0.0
InternalName: zckx.exe
LegalCopyright: -
LegalTrademarks: -
OriginalFileName: zckx.exe
ProductName: VideoSplit
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
140
Monitored processes
6
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
1192"C:\Windows\System32\schtasks.exe" /Create /TN "Updates\RehrUBQ" /XML "C:\Users\admin\AppData\Local\Temp\tmpF335.tmp"C:\Windows\SysWOW64\schtasks.exeb146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Scheduler Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2192C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2200C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
3112\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4948"C:\Users\admin\AppData\Local\Temp\b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe" C:\Users\admin\AppData\Local\Temp\b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
VideoSplit
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
6392"C:\Users\admin\AppData\Local\Temp\b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe"C:\Users\admin\AppData\Local\Temp\b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe
b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe
User:
admin
Integrity Level:
MEDIUM
Description:
VideoSplit
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
ims-api
(PID) Process(6392) b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe
Telegram-Tokens (1)7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8
Telegram-Info-Links
7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8
Get info about bothttps://api.telegram.org/bot7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8/getMe
Get incoming updateshttps://api.telegram.org/bot7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8/getUpdates
Get webhookhttps://api.telegram.org/bot7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8/deleteWebhook?drop_pending_updates=true
(PID) Process(6392) b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe
Telegram-Tokens (1)7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8
Telegram-Info-Links
7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8
Get info about bothttps://api.telegram.org/bot7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8/getMe
Get incoming updateshttps://api.telegram.org/bot7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8/getUpdates
Get webhookhttps://api.telegram.org/bot7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8/getWebhookInfo
Delete webhookhttps://api.telegram.org/bot7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8/deleteWebhook
Drop incoming updateshttps://api.telegram.org/bot7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8/deleteWebhook?drop_pending_updates=true
Telegram-Requests
Token7073565778:AAGqDKr6IeAOqEYc-VifRRUBCR56bVCdyF8
End-PointsendDocument
Args
Total events
2 106
Read events
2 090
Write events
16
Delete events
0

Modification events

(PID) Process:(6392) b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:bAOca
Value:
C:\Users\admin\AppData\Roaming\bAOca\bAOca.exe
(PID) Process:(6392) b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run
Operation:writeName:bAOca
Value:
020000000000000000000000
(PID) Process:(6392) b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6392) b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6392) b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6392) b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(6392) b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(6392) b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(6392) b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(6392) b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
Executable files
2
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
4948b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exeC:\Users\admin\AppData\Local\Temp\tmpF335.tmpxml
MD5:CCF7319D81FCF61FA36135119C8F2A98
SHA256:14C45D0F8C8FAEF0855578A2C543BCAF9D3642D62B23E8013F4CD4E7B7CBBA85
4948b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exeC:\Users\admin\AppData\Roaming\RehrUBQ.exeexecutable
MD5:080829053664C4EF0128C3B048DF6880
SHA256:B146EE56F4EA9BE0D7A80FDFE9B030FEBF1BF40F901D00760231A35990B6A3DF
6392b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exeC:\Users\admin\AppData\Roaming\bAOca\bAOca.exeexecutable
MD5:080829053664C4EF0128C3B048DF6880
SHA256:B146EE56F4EA9BE0D7A80FDFE9B030FEBF1BF40F901D00760231A35990B6A3DF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
25
DNS requests
20
Threats
12

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
2064
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
6392
b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe
GET
200
208.95.112.1:80
http://ip-api.com/line/?fields=hosting
US
text
6 b
whitelisted
1268
svchost.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
814 b
whitelisted
4228
SIHClient.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
419 b
whitelisted
4228
SIHClient.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
407 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4700
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
69.192.161.161:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
6392
b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe
172.67.74.152:443
api.ipify.org
CLOUDFLARENET
US
shared
6392
b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe
208.95.112.1:80
ip-api.com
TUT-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
  • 40.127.240.158
  • 51.104.136.2
whitelisted
google.com
  • 142.250.186.174
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 69.192.161.161
whitelisted
api.ipify.org
  • 172.67.74.152
  • 104.26.12.205
  • 104.26.13.205
shared
ip-api.com
  • 208.95.112.1
whitelisted
api.telegram.org
  • 149.154.167.220
whitelisted
login.live.com
  • 40.126.32.74
  • 20.190.160.20
  • 20.190.160.17
  • 20.190.160.130
  • 20.190.160.65
  • 20.190.160.128
  • 40.126.32.136
  • 20.190.160.3
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted

Threats

PID
Process
Class
Message
2200
svchost.exe
Misc activity
ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup
6392
b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe
Misc activity
ET INFO External IP Address Lookup Domain (ipify .org) in TLS SNI
2200
svchost.exe
Device Retrieving External IP Address Detected
INFO [ANY.RUN] External IP Check (ip-api .com)
6392
b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe
A Network Trojan was detected
ET MALWARE Common Stealer Behavior - Source IP Associated with Hosting Provider Check via ip.api .com
6392
b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe
Device Retrieving External IP Address Detected
POLICY [ANY.RUN] External Hosting Lookup by ip-api
6392
b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup ip-api.com
2200
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ip-api .com)
2200
svchost.exe
Misc activity
SUSPICIOUS [ANY.RUN] Possible sending an external IP address to Telegram
6392
b146ee56f4ea9be0d7a80fdfe9b030febf1bf40f901d00760231a35990b6a3df.exe
Misc activity
ET HUNTING Observed Telegram API Domain (api .telegram .org in TLS SNI)
2200
svchost.exe
Misc activity
ET HUNTING Telegram API Domain in DNS Lookup
No debug info