File name:

payload.ps1

Full analysis: https://app.any.run/tasks/843c025a-6e6a-41fb-bced-5a3b2bb01943
Verdict: Malicious activity
Threats:

AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.

Analysis date: August 08, 2025, 09:30:56
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
susp-clipboard
clickfix
loader
rat
asyncrat
remote
auto-startup
emmenhtal
Indicators:
MIME: text/plain
File info: ASCII text, with no line terminators
MD5:

4CBB8911521D70BC5187D9903CE3C997

SHA1:

3B13CE27DEF6F015EC63FF471F77BDD0DD812BAA

SHA256:

DBE3A83934B1C8BA9021A61A424F8671C73354D1C24200D68D18EA204B9F4778

SSDEEP:

3:VSJJFI9IrFhwQwDuxHEiioEYtXiW8+zicU0dWIpTVVs6MFIKg1:s8qXwQSQEJYtSomcU0MIpTVVs6MFIz1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Bypass execution policy to execute commands

      • powershell.exe (PID: 2380)
      • powershell.exe (PID: 2132)
      • powershell.exe (PID: 2320)
      • powershell.exe (PID: 1324)
      • powershell.exe (PID: 2212)
    • Probably downloads file via BitsAdmin

      • powershell.exe (PID: 4112)
      • powershell.exe (PID: 3620)
      • powershell.exe (PID: 2228)
    • Probably downloads file via BitsAdmin (POWERSHELL)

      • powershell.exe (PID: 4112)
      • powershell.exe (PID: 3620)
    • Creates a new folder (SCRIPT)

      • mshta.exe (PID: 856)
    • Checks whether a specified folder exists (SCRIPT)

      • mshta.exe (PID: 856)
    • Gets %appdata% folder path (SCRIPT)

      • mshta.exe (PID: 856)
    • Accesses environment variables (SCRIPT)

      • mshta.exe (PID: 856)
    • Gets startup folder path (SCRIPT)

      • mshta.exe (PID: 856)
    • Gets path to any of the special folders (SCRIPT)

      • mshta.exe (PID: 856)
    • Changes powershell execution policy (Bypass)

      • powershell.exe (PID: 1324)
    • Create files in the Startup directory

      • launer.exe (PID: 7276)
      • powershell.exe (PID: 2212)
    • ASYNCRAT has been detected (SURICATA)

      • svchost.exe (PID: 2200)
    • EMMENHTAL has been detected (YARA)

      • mshta.exe (PID: 856)
    • Connects to the CnC server

      • svchost.exe (PID: 2200)
  • SUSPICIOUS

    • Starts process via Powershell

      • powershell.exe (PID: 4112)
      • powershell.exe (PID: 3620)
      • powershell.exe (PID: 2228)
      • powershell.exe (PID: 1324)
    • Suspicious clipboard command

      • [System Process] (PID: 0)
    • Starts POWERSHELL.EXE for commands execution

      • powershell.exe (PID: 2380)
      • powershell.exe (PID: 2320)
      • mshta.exe (PID: 856)
      • powershell.exe (PID: 1324)
    • Application launched itself

      • powershell.exe (PID: 2380)
      • powershell.exe (PID: 2320)
      • powershell.exe (PID: 1324)
    • Manipulates environment variables

      • powershell.exe (PID: 2228)
    • Writes binary data to a Stream object (SCRIPT)

      • mshta.exe (PID: 856)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • mshta.exe (PID: 856)
    • Starts CMD.EXE for commands execution

      • mshta.exe (PID: 856)
    • Hides command output

      • cmd.exe (PID: 5812)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 5812)
    • The process executes Powershell scripts

      • mshta.exe (PID: 856)
      • powershell.exe (PID: 1324)
    • Runs shell command (SCRIPT)

      • mshta.exe (PID: 856)
    • Executable content was dropped or overwritten

      • powershell.exe (PID: 2212)
    • Contacting a server suspected of hosting an CnC

      • svchost.exe (PID: 2200)
    • Connects to unusual port

      • launer.exe (PID: 7276)
    • Potential Corporate Privacy Violation

      • powershell.exe (PID: 2212)
    • Gets path to any of the special folders (POWERSHELL)

      • powershell.exe (PID: 2212)
    • Process requests binary or script from the Internet

      • powershell.exe (PID: 2212)
  • INFO

    • Manual execution by a user

      • powershell.exe (PID: 2132)
      • powershell.exe (PID: 2320)
      • notepad++.exe (PID: 4232)
      • msedge.exe (PID: 3628)
      • powershell.exe (PID: 2228)
    • Reads Internet Explorer settings

      • mshta.exe (PID: 5884)
      • mshta.exe (PID: 6636)
      • mshta.exe (PID: 856)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 4112)
      • powershell.exe (PID: 3620)
      • powershell.exe (PID: 2212)
    • Create files in a temporary directory

      • svchost.exe (PID: 3620)
    • Application launched itself

      • msedge.exe (PID: 3628)
    • The executable file from the user directory is run by the Powershell process

      • launer.exe (PID: 7276)
    • Launching a file from the Startup directory

      • launer.exe (PID: 7276)
      • powershell.exe (PID: 2212)
    • Creates files or folders in the user directory

      • launer.exe (PID: 7276)
    • Checks proxy server information

      • slui.exe (PID: 6004)
      • powershell.exe (PID: 2212)
    • Reads the software policy settings

      • slui.exe (PID: 6004)
    • Checks supported languages

      • identity_helper.exe (PID: 7996)
      • launer.exe (PID: 7276)
    • Reads Environment values

      • identity_helper.exe (PID: 7996)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 2212)
    • Reads the computer name

      • launer.exe (PID: 7276)
      • identity_helper.exe (PID: 7996)
    • Reads the machine GUID from the registry

      • launer.exe (PID: 7276)
    • Disables trace logs

      • powershell.exe (PID: 2212)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
185
Monitored processes
47
Malicious processes
10
Suspicious processes
1

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
0[System Process]
[System Process]
Integrity Level:
UNKNOWN
856"C:\WINDOWS\system32\mshta.exe" C:\Users\admin\AppData\Local\Temp\UE.hta C:\Windows\System32\mshta.exe
powershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft (R) HTML Application host
Version:
11.00.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\mshta.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\wldp.dll
1096"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:4 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=133.0.6943.142 "--annotation=exe=C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win64 --annotation=prod=Edge --annotation=ver=133.0.3065.92 --initial-client-data=0x310,0x314,0x318,0x308,0x324,0x7ffc44d5f208,0x7ffc44d5f214,0x7ffc44d5f220C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe—msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1288"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=2488,i,13485330512009070577,1603965647187986848,262144 --variations-seed-version --mojo-platform-channel-handle=2684 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe—msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1324"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -Command Start-Process powershell -Verb RunAs -Wait -ArgumentList '-ExecutionPolicy Bypass -File "C:\Users\admin\AppData\Roaming\RunCache\tasklo1.ps1"'C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe—mshta.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\win32u.dll
1644"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=5480,i,13485330512009070577,1603965647187986848,262144 --variations-seed-version --mojo-platform-channel-handle=5384 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe—msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1688timeout /t 2 C:\Windows\System32\timeout.exe—cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
1728\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe—powershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1976\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe—powershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2132"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -ep bypass "C:\Users\admin\Desktop\payload.ps1"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe—explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
3221225786
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\atl.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
Total events
48 152
Read events
48 132
Write events
20
Delete events
0

Modification events

(PID) Process:(3628) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(3628) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(3628) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(3628) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\721634
Operation:writeName:WindowTabManagerFileMappingId
Value:
{15191B50-E50A-409B-AF1C-BAD3A6E31B16}
(PID) Process:(3628) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(3628) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
E7C7F2886D9A2F00
(PID) Process:(3628) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1693682860-607145093-2874071422-1001
Value:
6566F8886D9A2F00
(PID) Process:(3628) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\721634
Operation:writeName:WindowTabManagerFileMappingId
Value:
{3FC2420A-6362-4409-B231-D56C237188FC}
(PID) Process:(3620) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\BITS
Operation:writeName:PerfMMFileName
Value:
Global\MMF_BITSce1e389a-8d95-440e-a151-3ab2d63da5f4
(PID) Process:(3628) msedge.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\WindowProperties\721634
Operation:writeName:WindowTabManagerFileMappingId
Value:
{FFF888E2-7E6F-4089-904F-F9316E433F41}
Executable files
2
Suspicious files
553
Text files
130
Unknown types
30

Dropped files

PID
Process
Filename
Type
2132powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-msbinary
MD5:D9A15BDCAD9D8BF524D60C9D727F6F2C
SHA256:27A29465E6B1FFFF31F23A0A0A9F475D8CAAF6CDCB763D842246A893114614CB
4112powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivebinary
MD5:A2A5489F83DD117E7EF2407AA48C742C
SHA256:1E5016BA1AEEEA98A8CE3AE244209E6AC681F58B9590ABADEEE20F25F798F2AE
4112powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_ts0bpbxj.smj.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
2380powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_c3my2zqo.drb.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
2380powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-msbinary
MD5:32F2796A9A58C9C3E54B2386BC01BA81
SHA256:C9E5EAD3DF1F149417D5FF36E2C142E84B9A7920DC1588A38127B7903D70CCDE
3620powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_sfy502jw.adh.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
2320powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\PHL4FIOUZG7QT8N5F4CY.tempbinary
MD5:D766D0973D4312A2CDC3810968E425FD
SHA256:18DBA6F192FDB962DA1F910BE005AA2D32708CB3B0ACCB22E2393EA7747ABFC9
2320powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\590aee7bdd69b59b.customDestinations-msbinary
MD5:D766D0973D4312A2CDC3810968E425FD
SHA256:18DBA6F192FDB962DA1F910BE005AA2D32708CB3B0ACCB22E2393EA7747ABFC9
2380powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_jgvpkpyh.qdp.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
2132powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\Y6D10MXZUA1V8T0IF7WI.tempbinary
MD5:D9A15BDCAD9D8BF524D60C9D727F6F2C
SHA256:27A29465E6B1FFFF31F23A0A0A9F475D8CAAF6CDCB763D842246A893114614CB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
447
TCP/UDP connections
188
DNS requests
99
Threats
13

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
—
—
POST
400
20.190.159.71:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
—
—
POST
400
40.126.31.129:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
—
—
POST
400
20.190.159.68:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
—
—
POST
400
40.126.31.67:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
—
—
POST
400
40.126.31.69:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
—
—
POST
400
20.190.159.71:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
—
—
POST
400
20.190.159.4:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
—
—
POST
400
40.126.31.69:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
—
—
POST
400
20.190.159.68:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
—
—
POST
400
20.190.159.128:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
—
—
—
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3732
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
—
—
—
whitelisted
1268
svchost.exe
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5944
MoUsoCoreWorker.exe
23.216.77.28:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5944
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5944
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.206
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
login.live.com
  • 20.190.159.4
  • 40.126.31.69
  • 40.126.31.131
  • 40.126.31.1
  • 20.190.159.64
  • 40.126.31.71
  • 20.190.159.130
  • 40.126.31.130
  • 40.126.31.129
  • 40.126.31.67
  • 20.190.159.75
  • 20.190.159.129
  • 20.190.159.23
  • 40.126.31.128
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
self.events.data.microsoft.com
  • 20.189.173.28
whitelisted
activation-v2.sls.microsoft.com
  • 20.83.72.98
whitelisted
www.bing.com
  • 92.123.104.32
  • 92.123.104.38
  • 92.123.104.41
  • 92.123.104.46
  • 92.123.104.49
  • 92.123.104.34
  • 92.123.104.50
  • 92.123.104.35
  • 92.123.104.37
  • 92.123.104.29
  • 92.123.104.30
  • 92.123.104.23
  • 92.123.104.31
  • 92.123.104.21
  • 92.123.104.26
  • 92.123.104.22
  • 92.123.104.19
  • 92.123.104.27
  • 92.123.104.64
  • 92.123.104.61
  • 92.123.104.65
  • 92.123.104.63
  • 92.123.104.59
  • 92.123.104.67
  • 92.123.104.5
  • 92.123.104.62
  • 92.123.104.66
  • 184.86.251.22
  • 184.86.251.27
whitelisted

Threats

PID
Process
Class
Message
—
—
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
2212
powershell.exe
Not Suspicious Traffic
ET INFO Windows Powershell User-Agent Usage
2212
powershell.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
2212
powershell.exe
Misc activity
ET INFO Request for EXE via Powershell
2200
svchost.exe
Domain Observed Used for C2 Detected
MALWARE [ANY.RUN] Win32/AsyncRAT CnC related domain (8nioqhxciwoqc .click)
2200
svchost.exe
Domain Observed Used for C2 Detected
MALWARE [ANY.RUN] Win32/AsyncRAT CnC related domain (8nioqhxciwoqc .click)
2200
svchost.exe
Domain Observed Used for C2 Detected
MALWARE [ANY.RUN] Win32/AsyncRAT CnC related domain (8hdfiqowchq .click)
3620
svchost.exe
A Network Trojan was detected
SUSPICIOUS [ANY.RUN] VBS is used to run Shell
3620
svchost.exe
A Network Trojan was detected
LOADER [ANY.RUN] Gen.Powershell.Downloader Script Payload
—
—
Potentially Bad Traffic
ET INFO Possible Chrome Plugin install
Process
Message
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\SciLexer.dll
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
ED255D9151912E40DF048A56288E969A8D0DAFA3
notepad++.exe
VerifyLibrary: C:\Program Files\Notepad++\updater\gup.exe
notepad++.exe
VerifyLibrary: certificate revocation checking is disabled
notepad++.exe
VerifyLibrary: error while getting certificate informations