File name:

AstraWare-v4-.jar

Full analysis: https://app.any.run/tasks/cdefda77-d7d6-48cb-a479-d2bafbf1ba4f
Verdict: Malicious activity
Analysis date: May 16, 2026, 10:19:15
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
etherhiding
arch-exec
arch-doc
python
arch-scr
Indicators:
MIME: application/java-archive
File info: Java archive data (JAR)
MD5:

96EA1572F30D9784AA2380F47EF6A29A

SHA1:

17189D2616F7009B272549C807212A5E6057B858

SHA256:

C51BBBDA2EC5870A2DEECBF52148DB3B094617A024878F04E57AF7D4020EAD41

SSDEEP:

98304:DlbADop72QEeUOZQMoVrKkTGFoneCQnUhLbN3E31D2COUh/ijgDms+hZNM3Wy2/B:uwxOFRXVPIZD40i

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • javaw.exe (PID: 7704)
      • python.exe (PID: 5288)
      • python.exe (PID: 4968)
    • Process drops python dynamic module

      • javaw.exe (PID: 7704)
      • python.exe (PID: 4968)
    • The process drops C-runtime libraries

      • javaw.exe (PID: 7704)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 2032)
      • cmd.exe (PID: 5864)
    • Loads Python modules

      • python.exe (PID: 5288)
      • python.exe (PID: 4968)
    • Application launched itself

      • javaw.exe (PID: 7368)
    • The process executes JS scripts

      • wscript.exe (PID: 3560)
  • INFO

    • Create files in a temporary directory

      • javaw.exe (PID: 7368)
      • javaw.exe (PID: 7704)
      • python.exe (PID: 5288)
      • python.exe (PID: 4968)
    • Checks supported languages

      • javaw.exe (PID: 7704)
      • javaw.exe (PID: 7368)
      • python.exe (PID: 5288)
      • python.exe (PID: 4968)
    • Reads the machine GUID from the registry

      • javaw.exe (PID: 7704)
      • python.exe (PID: 4968)
      • python.exe (PID: 5288)
    • The sample compiled with english language support

      • javaw.exe (PID: 7704)
      • python.exe (PID: 5288)
      • python.exe (PID: 4968)
    • Manual execution by a user

      • cmd.exe (PID: 2032)
      • notepad.exe (PID: 7936)
      • notepad.exe (PID: 6872)
      • notepad.exe (PID: 5524)
      • notepad.exe (PID: 2368)
      • notepad.exe (PID: 5584)
      • notepad.exe (PID: 4272)
      • notepad.exe (PID: 6212)
      • wscript.exe (PID: 3560)
      • notepad.exe (PID: 8028)
      • cmd.exe (PID: 5864)
      • notepad.exe (PID: 7580)
      • notepad.exe (PID: 6404)
      • notepad.exe (PID: 6728)
      • notepad.exe (PID: 3320)
      • notepad.exe (PID: 8156)
    • Creates files or folders in the user directory

      • javaw.exe (PID: 7704)
      • python.exe (PID: 5288)
      • javaw.exe (PID: 7368)
      • python.exe (PID: 4968)
    • Reads CPU info

      • javaw.exe (PID: 7368)
      • javaw.exe (PID: 7704)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 7936)
      • notepad.exe (PID: 5524)
      • notepad.exe (PID: 6872)
      • notepad.exe (PID: 4272)
      • notepad.exe (PID: 6212)
      • notepad.exe (PID: 5584)
      • notepad.exe (PID: 8028)
      • notepad.exe (PID: 2368)
      • notepad.exe (PID: 7580)
      • notepad.exe (PID: 6404)
      • notepad.exe (PID: 6728)
      • notepad.exe (PID: 3320)
      • notepad.exe (PID: 8156)
    • Reads the computer name

      • javaw.exe (PID: 7704)
      • python.exe (PID: 5288)
      • python.exe (PID: 4968)
    • Drops encrypted JS script (Microsoft Script Encoder)

      • python.exe (PID: 5288)
      • python.exe (PID: 4968)
    • Reads Environment values

      • javaw.exe (PID: 7368)
      • javaw.exe (PID: 7704)
    • Python executable

      • python.exe (PID: 5288)
      • python.exe (PID: 4968)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.jar | Java Archive (78.3)
.zip | ZIP compressed archive (21.6)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: -
ZipCompression: Deflated
ZipModifyDate: 2026:03:14 16:31:16
ZipCRC: 0x57d4855f
ZipCompressedSize: 5825
ZipUncompressedSize: 11982
ZipFileName: com/libmod/LangProvider.class
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
157
Monitored processes
25
Malicious processes
0
Suspicious processes
3

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
352\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe—python.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
684\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe—python.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1180\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe—cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2032C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\Desktop\ctypes\macholib\fetch_macholib.bat" "C:\Windows\System32\cmd.exe—explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
c:\windows\system32\advapi32.dll
2368"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\pip-26.1.1.dist-info/entry_points.txtC:\Windows\System32\notepad.exe—explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
3320"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\certifi-2026.4.22.dist-info/top_level.txtC:\Windows\System32\notepad.exe—explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
3560"C:\Windows\System32\WScript.exe" C:\Users\admin\Desktop\urllib3/contrib/emscripten/emscripten_fetch_worker.jsC:\Windows\System32\wscript.exe—explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4272"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\charset_normalizer-3.4.7.dist-info/entry_points.txtC:\Windows\System32\notepad.exe—explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
4968C:\Users\admin\AppData\Local\Microsoft\Windows\NtProfileIndex\python.exe -m pip install -r C:\Users\admin\AppData\Local\Microsoft\Windows\NtProfileIndex\requirements.txt --no-warn-script-location -qC:\Users\admin\AppData\Local\Microsoft\Windows\NtProfileIndex\python.exe
javaw.exe
User:
admin
Company:
Python Software Foundation
Integrity Level:
MEDIUM
Description:
Python
Version:
3.12.7
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\ntprofileindex\python.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\windows\ntprofileindex\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\windows\ntprofileindex\python312.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
5288C:\Users\admin\AppData\Local\Microsoft\Windows\NtProfileIndex\python.exe C:\Users\admin\AppData\Local\Microsoft\Windows\NtProfileIndex\get-pip.py --no-warn-script-locationC:\Users\admin\AppData\Local\Microsoft\Windows\NtProfileIndex\python.exe
javaw.exe
User:
admin
Company:
Python Software Foundation
Integrity Level:
MEDIUM
Description:
Python
Exit code:
0
Version:
3.12.7
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\ntprofileindex\python.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\users\admin\appdata\local\microsoft\windows\ntprofileindex\vcruntime140.dll
c:\users\admin\appdata\local\microsoft\windows\ntprofileindex\python312.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\rpcrt4.dll
Total events
0
Read events
0
Write events
0
Delete events
0

Modification events

No data
Executable files
96
Suspicious files
958
Text files
1 054
Unknown types
10

Dropped files

PID
Process
Filename
Type
7704javaw.exeC:\Users\admin\AppData\Local\Microsoft\Windows\NtProfileIndex\_install.logtext
MD5:08D21CE3D4A3DC6547E0BEF0FC25A9CC
SHA256:3ABA9A3D80BEE7BEB47CE7921924B6C4B66673EDC7B4880ED2964AE96CF95D7F
7704javaw.exeC:\Users\admin\AppData\Local\Microsoft\Windows\NtProfileIndex\python312.dllexecutable
MD5:B243D61F4248909BC721674D70A633DE
SHA256:93488FA7E631CC0A2BD808B9EEE8617280EE9B6FF499AB424A1A1CBF24D77DC7
7704javaw.exeC:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1693682860-607145093-2874071422-1001\83aa4cc77f591dfc2374580bbd95f6ba_bb926e54-e3ca-40fd-ae90-2764341e7792binary
MD5:C8366AE350E7019AEFC9D1E6E6A498C6
SHA256:11E6ACA8E682C046C83B721EEB5C72C5EF03CB5936C60DF6F4993511DDC61238
7704javaw.exeC:\Users\admin\AppData\Local\Microsoft\Windows\NtProfileIndex\_bz2.pydexecutable
MD5:FE499B0A9F7F361FA705E7C81E1011FA
SHA256:160B5218C2035CCCBAAB9DC4CA26D099F433DCB86DBBD96425C933DC796090DF
7704javaw.exeC:\Users\admin\AppData\Local\Microsoft\Windows\NtProfileIndex\_ctypes.pydexecutable
MD5:302DDF5F83B5887AB9C4B8CC4E40B7A6
SHA256:8250B4C102ABD1DBA49FC5B52030CAA93CA34E00B86CEE6547CC0A7F22326807
7704javaw.exeC:\Users\admin\AppData\Local\Microsoft\Windows\NtProfileIndex\python.exeexecutable
MD5:FD6AFF3A270AE170C7657373316D37C0
SHA256:CA60CF785B2314A6D6599ECED15BDF094E6DB171BEC996B97A70B995942C3C37
7704javaw.exeC:\Users\admin\AppData\Local\Microsoft\Windows\NtProfileIndex\python3.dllexecutable
MD5:2E2BB725B92A3D30B1E42CC43275BB7B
SHA256:D52BACA085F88B40F30C855E6C55791E5375C80F60F94057061E77E33F4CAD7A
7704javaw.exeC:\Users\admin\AppData\Local\Microsoft\Windows\NtProfileIndex\_decimal.pydexecutable
MD5:82321FB8245333842E1C31F874329170
SHA256:B7F9603F98EF232A2C5BCE7001D842C01D76ED35171AFBD898E6D17FACF38B56
7704javaw.exeC:\Users\admin\AppData\Local\Microsoft\Windows\NtProfileIndex\_asyncio.pydexecutable
MD5:E74E8B37BD359F581F368BA092EED90E
SHA256:184FC13677C7856E7A8B31DFE79CE68DCEA10CDF83A205DE2B0D5497FB0FFDF3
7704javaw.exeC:\Users\admin\AppData\Local\Microsoft\Windows\NtProfileIndex\_hashlib.pydexecutable
MD5:0ABFEE1DB6C16E8DDAFF12CD3E86475B
SHA256:B4CEC162B985D34AB768F66E8FA41ED28DC2F273FDE6670EEACE1D695789B137
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
58
TCP/UDP connections
31
DNS requests
15
Threats
16

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5276
MoUsoCoreWorker.exe
GET
304
48.209.133.15:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
—
—
whitelisted
680
svchost.exe
GET
—
48.209.133.15:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/WaasMedic?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&appVer=10.0.19041.3758&ring=Retail&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4
US
—
—
whitelisted
5276
MoUsoCoreWorker.exe
GET
200
23.52.181.212:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
5276
MoUsoCoreWorker.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
6988
slui.exe
POST
500
128.24.231.64:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
xml
512 b
whitelisted
5288
python.exe
GET
200
151.101.64.223:443
https://files.pythonhosted.org/packages/3a/eb/fea4d1d51c49832120f7f285d07306db3960f423a2612c6057caf3e8196f/pip-26.1.1-py3-none-any.whl.metadata
US
text
4.46 Kb
unknown
3280
svchost.exe
GET
200
23.52.181.212:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
US
binary
814 b
whitelisted
7704
javaw.exe
PUT
200
104.21.91.94:443
https://v3.thisisafalsepositive.ru/cdn/e/42a522313d92
US
text
292 b
unknown
7704
javaw.exe
POST
200
150.136.141.142:443
https://rpc-mainnet.matic.quiknode.pro/
US
text
231 b
unknown
3280
svchost.exe
GET
200
23.52.181.212:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.2.crl
US
binary
400 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5276
MoUsoCoreWorker.exe
48.209.133.15:443
—
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
—
Not routed
—
whitelisted
7312
slui.exe
128.24.231.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
680
svchost.exe
48.209.133.15:443
—
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
—
Not routed
—
whitelisted
680
svchost.exe
23.216.77.28:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
5276
MoUsoCoreWorker.exe
23.216.77.28:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
5276
MoUsoCoreWorker.exe
23.52.181.212:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
680
svchost.exe
23.52.181.212:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
7704
javaw.exe
173.244.207.30:443
polygon-rpc.com
UK2NET-AS
GB
suspicious

DNS requests

Domain
IP
Reputation
activation-v2.sls.microsoft.com
  • 128.24.231.65
whitelisted
google.com
  • 142.251.20.138
  • 142.251.20.113
  • 142.251.20.139
  • 142.251.20.100
  • 142.251.20.102
  • 142.251.20.101
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
  • 23.216.77.42
whitelisted
www.microsoft.com
  • 23.52.181.212
whitelisted
polygon-rpc.com
  • 173.244.207.30
unknown
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
rpc-mainnet.matic.quiknode.pro
  • 150.136.141.142
unknown
www.python.org
  • 151.101.0.223
  • 151.101.128.223
  • 151.101.64.223
  • 151.101.192.223
whitelisted
bootstrap.pypa.io
  • 151.101.0.175
  • 151.101.192.175
  • 151.101.64.175
  • 151.101.128.175
unknown
v3.thisisafalsepositive.ru
  • 104.21.91.94
  • 172.67.214.234
unknown

Threats

PID
Process
Class
Message
2232
svchost.exe
Misc activity
ET INFO Blockchain RPC Domain in DNS Lookup (polygon-rpc .com)
7704
javaw.exe
Misc activity
ET INFO Blockchain RPC Domain in TLS SNI (polygon-rpc .com)
5276
MoUsoCoreWorker.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
2232
svchost.exe
Misc activity
ET INFO Observed DNS Query to Blockchain RPC Domain (rpc-mainnet .matic .quiknode .pro)
7704
javaw.exe
Misc activity
ET INFO Observed Blockchain RPC Domain (rpc-mainnet .matic .quiknode .pro in TLS SNI)
—
—
A Network Trojan was detected
ET MALWARE EtherHiding Exfil M2
—
—
A Network Trojan was detected
ET MALWARE EtherHiding Exfil M2
—
—
Misc activity
ET INFO JAVA - Zip/JAR File Downloaded Containing Executable Downloaded
—
—
Potentially Bad Traffic
SUSPICIOUS [ANY.RUN] ZIP Archive Download Containing EXE File
—
—
Potentially Bad Traffic
SUSPICIOUS [ANY.RUN] ZIP Archive Download Containing EXE File
No debug info