File name:

xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exe

Full analysis: https://app.any.run/tasks/a08b8ba9-2dd2-4c4d-89f3-3c42b22ffa57
Verdict: Malicious activity
Threats:

Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks.

Analysis date: April 25, 2026, 06:42:08
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
stealc
stealer
auto-reg
auto
clipbanker
python
amadey
botnet
pyinstaller
openssl
tool
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 7 sections
MD5:

7F2BE5C20B45CA6837E3EA60392200D0

SHA1:

0813910F5D43306C7DBE398D2C6DA64D02FE193D

SHA256:

C83F7D68FA77BA191D01E23878D433E2A894732A20C8AA71E72E82896C7E8DA6

SSDEEP:

98304:ymrfIZ4eaYoSfMVIQMu5IK/0CZFdaNoMZqeLnc1ZaDPHUFK/uXbQKn352U0mTZwY:jIQMu5IpgK8bTyYpNUfuthnS94

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the login/logoff helper path in the registry

      • wdhost.exe (PID: 3212)
    • Changes the autorun value in the registry

      • wdhost.exe (PID: 3212)
      • wmiprv.exe (PID: 8156)
      • svcx.exe (PID: 7408)
      • wmiprv.exe (PID: 7052)
      • svcx.exe (PID: 6108)
      • dismch.exe (PID: 7604)
    • Runs injected code in another process

      • wdhost.exe (PID: 3212)
      • wmiprv.exe (PID: 8156)
      • svcx.exe (PID: 7408)
      • wmiprv.exe (PID: 7052)
      • svcx.exe (PID: 6108)
    • CLIPBANKER has been found (auto)

      • xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exe (PID: 8128)
    • STEALC has been detected

      • shhost.exe (PID: 6988)
    • Application was injected by another process

      • explorer.exe (PID: 4696)
    • STEALC has been detected (SURICATA)

      • shhost.exe (PID: 6988)
    • AMADEY has been detected (SURICATA)

      • donym.exe (PID: 7364)
    • Stealers network behavior

      • shhost.exe (PID: 6988)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exe (PID: 8128)
      • wdhost.exe (PID: 3212)
      • NexiloNitroGen.exe (PID: 7576)
      • dismch.exe (PID: 7604)
    • The process creates files with name similar to system file names

      • xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exe (PID: 8128)
      • wdhost.exe (PID: 3212)
    • Reads the date of Windows installation

      • xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exe (PID: 8128)
      • wdhost.exe (PID: 3212)
      • dismch.exe (PID: 7604)
    • The process executes files with name similar to system file names

      • xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exe (PID: 8128)
      • explorer.exe (PID: 4696)
    • The process drops C-runtime libraries

      • NexiloNitroGen.exe (PID: 7576)
    • Process drops python dynamic module

      • NexiloNitroGen.exe (PID: 7576)
    • Application launched itself

      • NexiloNitroGen.exe (PID: 7576)
    • Loads Python modules

      • NexiloNitroGen.exe (PID: 4336)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 5604)
    • OpenSSL has been detected (YARA)

      • NexiloNitroGen.exe (PID: 4336)
    • Starts itself from another location

      • dismch.exe (PID: 7604)
  • INFO

    • Creates files or folders in the user directory

      • xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exe (PID: 8128)
      • wdhost.exe (PID: 3212)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 4696)
      • xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exe (PID: 8128)
      • shhost.exe (PID: 6988)
      • dismch.exe (PID: 7604)
      • donym.exe (PID: 7364)
    • The sample compiled with english language support

      • xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exe (PID: 8128)
      • wdhost.exe (PID: 3212)
      • NexiloNitroGen.exe (PID: 7576)
    • Reads the computer name

      • xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exe (PID: 8128)
      • wdhost.exe (PID: 3212)
      • wmiprv.exe (PID: 8156)
      • shhost.exe (PID: 6988)
      • rssync.exe (PID: 2524)
      • svcx.exe (PID: 7408)
      • NexiloNitroGen.exe (PID: 7576)
      • wmiprv.exe (PID: 7052)
      • dismch.exe (PID: 7604)
      • svcx.exe (PID: 6108)
      • donym.exe (PID: 7364)
    • Process checks computer location settings

      • xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exe (PID: 8128)
      • dismch.exe (PID: 7604)
    • Checks supported languages

      • xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exe (PID: 8128)
      • wdhost.exe (PID: 3212)
      • rssync.exe (PID: 2524)
      • shhost.exe (PID: 6988)
      • wmiprv.exe (PID: 8156)
      • svcx.exe (PID: 7408)
      • dismch.exe (PID: 7604)
      • NexiloNitroGen.exe (PID: 7576)
      • NexiloNitroGen.exe (PID: 4336)
      • wmiprv.exe (PID: 7052)
      • wdhost.exe (PID: 7888)
      • svcx.exe (PID: 6108)
      • donym.exe (PID: 7364)
      • donym.exe (PID: 5888)
    • Launching a file from a Registry key

      • wdhost.exe (PID: 3212)
      • wmiprv.exe (PID: 8156)
      • svcx.exe (PID: 7408)
      • wmiprv.exe (PID: 7052)
      • svcx.exe (PID: 6108)
      • dismch.exe (PID: 7604)
    • Create files in a temporary directory

      • wdhost.exe (PID: 3212)
      • NexiloNitroGen.exe (PID: 7576)
    • Reads product name

      • wdhost.exe (PID: 3212)
    • Reads Environment values

      • wdhost.exe (PID: 3212)
    • Manual execution by a user

      • wmiprv.exe (PID: 7052)
      • wdhost.exe (PID: 7888)
      • svcx.exe (PID: 6108)
      • donym.exe (PID: 5888)
    • Reads the machine GUID from the registry

      • dismch.exe (PID: 7604)
    • There is functionality for taking screenshot (YARA)

      • rssync.exe (PID: 2524)
    • PyInstaller has been detected (YARA)

      • NexiloNitroGen.exe (PID: 4336)
      • NexiloNitroGen.exe (PID: 7576)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2026:04:23 23:30:44+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.5
CodeSize: 49152
InitializedDataSize: 11638784
UninitializedDataSize: -
EntryPoint: 0x154c
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
149
Monitored processes
18
Malicious processes
11
Suspicious processes
1

Behavior graph

Click at the process to see the details
start #CLIPBANKER xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exe wdhost.exe rssync.exe #STEALC shhost.exe wmiprv.exe svcx.exe dismch.exe slui.exe nexilonitrogen.exe conhost.exe no specs nexilonitrogen.exe no specs cmd.exe no specs wmiprv.exe wdhost.exe no specs svcx.exe #AMADEY donym.exe donym.exe no specs explorer.exe

Process information

PID
CMD
Path
Indicators
Parent process
2524"C:\Users\admin\AppData\Roaming\rssync.exe" C:\Users\admin\AppData\Roaming\rssync.exe
xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\roaming\rssync.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\combase.dll
c:\windows\system32\gdi32.dll
3212"C:\Users\admin\AppData\Roaming\wdhost.exe" C:\Users\admin\AppData\Roaming\wdhost.exe
xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exe
User:
admin
Company:
Intel Corporation
Integrity Level:
MEDIUM
Description:
Volume Shadow Copy Service
Version:
2.9.7035.67
Modules
Images
c:\users\admin\appdata\roaming\wdhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4336"C:\Users\admin\Desktop\NexiloNitroGen.exe" C:\Users\admin\Desktop\NexiloNitroGen.exeNexiloNitroGen.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\desktop\nexilonitrogen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4696C:\WINDOWS\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\twinapi.dll
c:\windows\system32\oleaut32.dll
5604C:\WINDOWS\system32\cmd.exe /c clsC:\Windows\System32\cmd.exeNexiloNitroGen.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
5888C:\ProgramData\donym.exeC:\ProgramData\donym.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\programdata\donym.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wininet.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6108C:\Users\admin\AppData\Roaming\svcx.exeC:\Users\admin\AppData\Roaming\svcx.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\appdata\roaming\svcx.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6208C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6988"C:\Users\admin\AppData\Roaming\shhost.exe" C:\Users\admin\AppData\Roaming\shhost.exe
xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\shhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
7052C:\Users\admin\AppData\Roaming\wmiprv.exeC:\Users\admin\AppData\Roaming\wmiprv.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\appdata\roaming\wmiprv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
7 837
Read events
7 814
Write events
23
Delete events
0

Modification events

(PID) Process:(4696) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Security and Maintenance\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0
Operation:writeName:CheckSetting
Value:
23004100430042006C006F0062000000000000000000000001000000FFFFFFFFFFFF9B13
(PID) Process:(3212) wdhost.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:winhost.exe
Value:
C:\Users\admin\AppData\Roaming\wdhost.exe
(PID) Process:(3212) wdhost.exeKey:HKEY_CURRENT_USER\Environment
Operation:writeName:UserInitMprLogonScript
Value:
"C:\WINDOWS\system32\cmd.exe" /c start /b "" "C:\Users\admin\AppData\Roaming\wdhost.exe"
(PID) Process:(8156) wmiprv.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Windows Defender Security
Value:
C:\Users\admin\AppData\Roaming\wmiprv.exe
(PID) Process:(6988) shhost.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6988) shhost.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6988) shhost.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3212) wdhost.exeKey:HKEY_CURRENT_USER\Environment
Operation:writeName:UserInitMprLogonScript
Value:
"C:\WINDOWS\system32\cmd.exe" /c start /b "" "C:\Users\admin\AppData\Roaming\Microsoft\Windows\Services\winhost.exe"
(PID) Process:(7408) svcx.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Windows Defender Security
Value:
C:\Users\admin\AppData\Roaming\svcx.exe
(PID) Process:(8128) xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
Executable files
31
Suspicious files
1
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
8128xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exeC:\Users\admin\AppData\Roaming\rssync.exeexecutable
MD5:80E815D62DA2C2A2F2917E876A55BC3E
SHA256:DA0AC1068D9E88C53613CB2CAB84DEDE321E5CD9F356593C4E0124C5C2339C79
3212wdhost.exeC:\Users\admin\AppData\Local\Temp\wd.tmpexecutable
MD5:15E7FC24B76E7BB99C368FDEBD13110F
SHA256:F63CDFA3C9792B5E3671C3ECE15871CD3DA22A57C498BD31849954B91F07040F
4696explorer.exeC:\Users\admin\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.dattext
MD5:E49C56350AEDF784BFE00E444B879672
SHA256:A8BD235303668981563DFB5AAE338CB802817C4060E2C199B7C84901D57B7E1E
8128xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exeC:\Users\admin\AppData\Roaming\wdhost.exeexecutable
MD5:9545E8F1A1900B8899B129839AD17024
SHA256:A38926B27A00B97BB98971CF4C8A538FCC7A4B9BC85CC6F77F4A0ABC036B66AA
8128xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exeC:\Users\admin\AppData\Roaming\wmiprv.exeexecutable
MD5:FD4547636601289B5B9C1D713AB01816
SHA256:7B5393D8D7A7A6D1EDF9493EDBBB5F0B037206EE254C47A25530705C75838A62
8128xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exeC:\Users\admin\AppData\Roaming\shhost.exeexecutable
MD5:B1ED5BA271AB4CBB5A0C5121DFCE2405
SHA256:0215F734867BD71C57FF5C524D8CC670BE5B4F1861B2C390CF46D18784A53624
3212wdhost.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Services\winhost.exeexecutable
MD5:9545E8F1A1900B8899B129839AD17024
SHA256:A38926B27A00B97BB98971CF4C8A538FCC7A4B9BC85CC6F77F4A0ABC036B66AA
8128xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exeC:\Users\admin\AppData\Roaming\svcx.exeexecutable
MD5:78CCDDA7E2EC038A97079BFD324CB558
SHA256:E9A3C496009714128863CE18CE5F63F9F0D8F233607F04AF77B299F9F1C8BE6C
8128xc83f7d68fa77ba191d01e23878d433e2a894732a20c8aa71e72e82896c7e8da6.exeC:\Users\admin\Desktop\NexiloNitroGen.exeexecutable
MD5:E080E0A7B4C5A03B8D509FD03D1E0354
SHA256:B16CAB80EE48AC65466977663CC6B583F0B693D413506AFE1413F3F50C720F61
7576NexiloNitroGen.exeC:\Users\admin\AppData\Local\Temp\_MEI75762\VCRUNTIME140.dllexecutable
MD5:862F820C3251E4CA6FC0AC00E4092239
SHA256:36585912E5EAF83BA9FEA0631534F690CCDC2D7BA91537166FE53E56C221E153
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
22
TCP/UDP connections
40
DNS requests
11
Threats
18

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
680
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
680
svchost.exe
GET
200
23.52.181.212:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
3212
wdhost.exe
POST
200
62.60.226.159:80
http://62.60.226.159/post.php
GB
unknown
3212
wdhost.exe
POST
200
62.60.226.159:80
http://62.60.226.159/post.php
GB
unknown
6988
shhost.exe
POST
200
196.251.107.130:80
http://196.251.107.130/16b022998f754137b60a.php
GB
text
64 b
malicious
POST
500
128.24.231.65:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
xml
512 b
whitelisted
6208
slui.exe
POST
500
128.24.231.64:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
xml
512 b
whitelisted
7364
donym.exe
POST
200
62.60.226.159:80
http://62.60.226.159/xvzpjyddlu/getdata.php
GB
malicious
3280
svchost.exe
GET
200
23.52.181.212:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.3.crl
US
binary
813 b
whitelisted
3280
svchost.exe
GET
200
23.52.181.212:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.2.crl
US
binary
400 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8028
slui.exe
128.24.231.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
184.86.251.30:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
680
svchost.exe
23.216.77.6:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
680
svchost.exe
23.52.181.212:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
5276
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
680
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3212
wdhost.exe
62.60.226.159:80
FEMOIT
GB
malicious

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
activation-v2.sls.microsoft.com
  • 128.24.231.64
whitelisted
www.bing.com
  • 184.86.251.30
  • 184.86.251.24
  • 184.86.251.15
  • 184.86.251.13
  • 184.86.251.21
  • 184.86.251.20
  • 184.86.251.4
  • 184.86.251.7
  • 184.86.251.14
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 23.52.181.212
whitelisted
google.com
  • 142.251.14.101
  • 142.251.14.138
  • 142.251.14.139
  • 142.251.14.113
  • 142.251.14.102
  • 142.251.14.100
whitelisted
losslvs.surf
  • 93.127.214.44
unknown
self.events.data.microsoft.com
  • 20.189.173.13
whitelisted

Threats

PID
Process
Class
Message
3212
wdhost.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 8
6988
shhost.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 44
3212
wdhost.exe
A Network Trojan was detected
ET HUNTING Suspicious Fake Windows User-Agent in HTTP Header
3212
wdhost.exe
A Network Trojan was detected
ET HUNTING Suspicious Fake Windows User-Agent in HTTP Header
7364
donym.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
7364
donym.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/Amadey associated URI (/xvzpjyddlu/getdata.php)
3212
wdhost.exe
A Network Trojan was detected
ET HUNTING Suspicious Fake Windows User-Agent in HTTP Header
3212
wdhost.exe
A Network Trojan was detected
ET HUNTING Suspicious Fake Windows User-Agent in HTTP Header
3212
wdhost.exe
A Network Trojan was detected
ET HUNTING Suspicious Fake Windows User-Agent in HTTP Header
6988
shhost.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/Stealc stealer activity observed
No debug info