File name:

FastClient-LATEST.jar

Full analysis: https://app.any.run/tasks/1b88b7b5-c758-4112-b362-2dfe3e0f5b9c
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: May 20, 2026, 03:37:45
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
stealer
weedhack
etherhiding
evasion
auto-sch
auto-reg
auto
loader
Indicators:
MIME: application/java-archive
File info: Java archive data (JAR)
MD5:

7069727CDC1164BAF33A5CDCE715E024

SHA1:

DFB50C9B331291407F60B97712D09A1A05646292

SHA256:

FF27463B3A1EA4787C8DDDE4511B6133DBDC77237C1EA7521BACB9A3C37709E5

SSDEEP:

12288:stDLjnRVs+zWY4rA1/06H3KV8LT+ISVvNz+XtlEm5uC:stDLjnRVs+z6rA1/0W3c8LT+ISVv1+X5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • WEEDHACK has been detected (SURICATA)

      • javaw.exe (PID: 7484)
      • javaw.exe (PID: 2988)
      • javaw.exe (PID: 7600)
      • javaw.exe (PID: 2032)
    • Stealers network behavior

      • javaw.exe (PID: 7484)
      • javaw.exe (PID: 2988)
      • javaw.exe (PID: 7600)
      • javaw.exe (PID: 2032)
    • Known privilege escalation attack

      • dllhost.exe (PID: 5748)
    • Adds process to the Windows Defender exclusion list

      • cmd.exe (PID: 4692)
    • Changes Windows Defender settings

      • cmd.exe (PID: 4692)
      • javaw.exe (PID: 7600)
    • Run PowerShell with an invisible window

      • powershell.exe (PID: 7704)
      • powershell.exe (PID: 3696)
      • powershell.exe (PID: 8040)
    • Changes powershell execution policy (Bypass)

      • javaw.exe (PID: 2988)
      • Telemetry.exe (PID: 6556)
    • Enumerates physical memory (Win32_PhysicalMemory) (SCRIPT)

      • powershell.exe (PID: 416)
    • Steals credentials from Web Browsers

      • javaw.exe (PID: 2988)
    • Actions looks like stealing of personal data

      • javaw.exe (PID: 2988)
    • Changes the autorun value in the registry

      • javaw.exe (PID: 7600)
    • WEEDHACK has been detected

      • javaw.exe (PID: 7600)
    • Uses Task Scheduler to autorun other applications

      • cmd.exe (PID: 4344)
    • Adds path to the Windows Defender exclusion list

      • javaw.exe (PID: 7600)
    • WEEDHACK has been found (auto)

      • javaw.exe (PID: 2988)
    • ETHERHIDING has been detected (SURICATA)

      • AntiMalwareServiceExecutable.exe (PID: 2524)
  • SUSPICIOUS

    • Application launched itself

      • javaw.exe (PID: 1684)
      • javaw.exe (PID: 2988)
      • javaw.exe (PID: 3164)
      • javaw.exe (PID: 7600)
    • There is functionality for VM detection VirtualBox (YARA)

      • javaw.exe (PID: 7484)
      • javaw.exe (PID: 2988)
      • javaw.exe (PID: 7600)
    • There is functionality for VM detection VMWare (YARA)

      • javaw.exe (PID: 7484)
      • javaw.exe (PID: 2988)
      • javaw.exe (PID: 7600)
    • Executable content was dropped or overwritten

      • javaw.exe (PID: 7484)
      • javaw.exe (PID: 2988)
      • javaw.exe (PID: 7600)
      • javaw.exe (PID: 3164)
      • javaw.exe (PID: 1724)
      • javaw.exe (PID: 2032)
    • There is functionality for VM detection antiVM strings (YARA)

      • javaw.exe (PID: 7484)
      • javaw.exe (PID: 2988)
      • javaw.exe (PID: 7600)
    • Used cmstp for execute code hidden within an inf file

      • javaw.exe (PID: 7484)
    • Executing commands from ".cmd" file

      • javaw.exe (PID: 2988)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 5524)
    • The process executes VB scripts

      • wscript.exe (PID: 5524)
    • Script adds exclusion process to Windows Defender

      • cmd.exe (PID: 4692)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 4692)
      • cmd.exe (PID: 1132)
      • cmd.exe (PID: 7160)
      • cmd.exe (PID: 7864)
      • cmd.exe (PID: 4344)
    • Adds exclusion path to Windows Defender (POWERSHELL)

      • cmd.exe (PID: 4692)
      • javaw.exe (PID: 7600)
    • Starts POWERSHELL.EXE for commands execution

      • cmd.exe (PID: 4692)
      • javaw.exe (PID: 2988)
      • javaw.exe (PID: 7600)
      • Telemetry.exe (PID: 6556)
    • Suspicious use of NETSH.EXE

      • javaw.exe (PID: 2988)
    • The process bypasses the loading of PowerShell profile settings

      • javaw.exe (PID: 2988)
      • Telemetry.exe (PID: 6556)
    • Bypass execution policy to execute commands

      • powershell.exe (PID: 7200)
      • powershell.exe (PID: 416)
      • powershell.exe (PID: 3416)
    • Get Video Controller Information (POWERSHELL)

      • javaw.exe (PID: 2988)
    • Checks RAM size (probably for evasion)

      • javaw.exe (PID: 2988)
    • Possible stealing from browsers

      • javaw.exe (PID: 2988)
    • Possible stealing of messenger data

      • javaw.exe (PID: 2988)
    • Loads DLL from Mozilla Firefox

      • javaw.exe (PID: 2988)
    • Uses NETSH.EXE to obtain data on the network

      • javaw.exe (PID: 2988)
    • Possible stealing from crypto wallets

      • javaw.exe (PID: 2988)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 3016)
    • Creates scheduled task with ONLOGON parameter

      • javaw.exe (PID: 7600)
      • cmd.exe (PID: 4344)
    • Creates scheduled task with highest privileges

      • cmd.exe (PID: 4344)
      • schtasks.exe (PID: 6428)
    • The executable file from the user directory is run by the CMD process

      • Telemetry.exe (PID: 6556)
    • Base64-obfuscated command line is found

      • Telemetry.exe (PID: 6556)
    • BASE64 encoded PowerShell command has been detected

      • Telemetry.exe (PID: 6556)
    • Reads the date of Windows installation

      • javaw.exe (PID: 3164)
    • Starts process via Powershell

      • powershell.exe (PID: 8040)
  • INFO

    • Create files in a temporary directory

      • javaw.exe (PID: 1684)
      • javaw.exe (PID: 7484)
      • javaw.exe (PID: 2988)
      • javaw.exe (PID: 7600)
      • javaw.exe (PID: 3164)
      • javaw.exe (PID: 1724)
      • javaw.exe (PID: 2032)
    • Reads Environment values

      • javaw.exe (PID: 1684)
      • javaw.exe (PID: 7484)
      • javaw.exe (PID: 2988)
      • javaw.exe (PID: 7600)
      • javaw.exe (PID: 3164)
      • javaw.exe (PID: 1724)
      • javaw.exe (PID: 2032)
    • Checks supported languages

      • javaw.exe (PID: 1684)
      • javaw.exe (PID: 7484)
      • javaw.exe (PID: 2988)
      • javaw.exe (PID: 7600)
      • Telemetry.exe (PID: 6556)
      • javaw.exe (PID: 3164)
      • javaw.exe (PID: 1724)
      • AntiMalwareServiceExecutable.exe (PID: 2524)
      • javaw.exe (PID: 2032)
    • Reads CPU info

      • javaw.exe (PID: 7484)
      • javaw.exe (PID: 1684)
      • javaw.exe (PID: 2988)
      • javaw.exe (PID: 7600)
      • javaw.exe (PID: 3164)
      • javaw.exe (PID: 1724)
      • AntiMalwareServiceExecutable.exe (PID: 2524)
      • javaw.exe (PID: 2032)
    • Reads the machine GUID from the registry

      • javaw.exe (PID: 7484)
      • javaw.exe (PID: 2988)
      • javaw.exe (PID: 7600)
      • javaw.exe (PID: 3164)
      • Telemetry.exe (PID: 6556)
      • javaw.exe (PID: 1724)
      • AntiMalwareServiceExecutable.exe (PID: 2524)
      • javaw.exe (PID: 2032)
    • Reads the computer name

      • javaw.exe (PID: 7484)
      • javaw.exe (PID: 2988)
      • Telemetry.exe (PID: 6556)
      • javaw.exe (PID: 3164)
      • javaw.exe (PID: 7600)
      • AntiMalwareServiceExecutable.exe (PID: 2524)
      • javaw.exe (PID: 2032)
    • Creates files or folders in the user directory

      • javaw.exe (PID: 7484)
      • javaw.exe (PID: 2988)
      • javaw.exe (PID: 7600)
      • Telemetry.exe (PID: 6556)
    • Disables trace logs

      • cmstp.exe (PID: 7836)
      • dllhost.exe (PID: 5748)
    • Checks transactions between databases Windows and Oracle

      • cmstp.exe (PID: 7836)
    • Process checks computer location settings

      • javaw.exe (PID: 2988)
      • javaw.exe (PID: 3164)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 7704)
      • powershell.exe (PID: 3696)
      • powershell.exe (PID: 3416)
    • Launching a file from a Registry key

      • javaw.exe (PID: 7600)
    • Manual execution by a user

      • javaw.exe (PID: 3164)
    • Reads security settings of Internet Explorer

      • javaw.exe (PID: 3164)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 3696)
    • The executable file from the user directory is run by the Powershell process

      • AntiMalwareServiceExecutable.exe (PID: 2524)
    • .NET Reactor protector has been detected

      • Telemetry.exe (PID: 6556)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.jar | Java Archive (78.3)
.zip | ZIP compressed archive (21.6)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0808
ZipCompression: Deflated
ZipModifyDate: 2026:05:16 20:01:38
ZipCRC: 0x0a5801f7
ZipCompressedSize: 2460
ZipUncompressedSize: 6176
ZipFileName: obf/IlII.class
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
187
Monitored processes
50
Malicious processes
11
Suspicious processes
6

Behavior graph

Click at the process to see the details
start javaw.exe no specs #WEEDHACK javaw.exe slui.exe cmstp.exe no specs CMSTPLUA wscript.exe no specs #WEEDHACK javaw.exe cmd.exe no specs conhost.exe no specs powershell.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs netsh.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs chrome.exe no specs msedge.exe no specs netsh.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs #WEEDHACK javaw.exe cmd.exe no specs conhost.exe no specs schtasks.exe no specs cmd.exe conhost.exe no specs schtasks.exe no specs powershell.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs telemetry.exe javaw.exe powershell.exe no specs conhost.exe no specs javaw.exe powershell.exe no specs conhost.exe no specs #ETHERHIDING antimalwareserviceexecutable.exe #WEEDHACK javaw.exe

Process information

PID
CMD
Path
Indicators
Parent process
416powershell.exe -NoProfile -ExecutionPolicy Bypass -Command "& { (Get-CimInstance -ClassName Win32_ComputerSystem).TotalPhysicalMemory }"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\atl.dll
1132cmd.exe /c "mullvad account get"C:\Windows\System32\cmd.exejavaw.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
1176\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1684"C:\Program Files\Java\jdk-25.0.2\bin\javaw.exe" -jar C:\Users\admin\Desktop\FastClient-LATEST.jarC:\Program Files\Java\jdk-25.0.2\bin\javaw.exeexplorer.exe
User:
admin
Company:
N/A
Integrity Level:
MEDIUM
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
25.0.2.0
Modules
Images
c:\program files\java\jdk-25.0.2\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\java\jdk-25.0.2\bin\jli.dll
c:\program files\java\jdk-25.0.2\bin\vcruntime140.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
1724"C:\Program Files\Java\jdk-25.0.2\bin\javaw.exe" -cp "C:\Users\admin\AppData\Roaming\Microsoft\SecurityUpdates\SecurityManager.jar" dev.majanito.security.MainC:\Program Files\Java\jdk-25.0.2\bin\javaw.exe
javaw.exe
User:
admin
Company:
N/A
Integrity Level:
HIGH
Description:
Java(TM) Platform SE binary
Exit code:
0
Version:
25.0.2.0
Modules
Images
c:\program files\java\jdk-25.0.2\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\program files\java\jdk-25.0.2\bin\jli.dll
c:\program files\java\jdk-25.0.2\bin\vcruntime140.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
1788\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2032"C:\Program Files\Java\jdk-25.0.2\bin\javaw.exe" -cp C:\Users\admin\AppData\Roaming\Microsoft\SecurityUpdates\component-2ff74e81-710c-49b2-82fc-7cd58cd46f9e.jar dev.majanito.Main true f390f1c1-c40a-4af1-9672-1d8c3a07735cC:\Program Files\Java\jdk-25.0.2\bin\javaw.exe
javaw.exe
User:
admin
Company:
N/A
Integrity Level:
HIGH
Description:
Java(TM) Platform SE binary
Version:
25.0.2.0
Modules
Images
c:\program files\java\jdk-25.0.2\bin\javaw.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\java\jdk-25.0.2\bin\vcruntime140.dll
c:\program files\java\jdk-25.0.2\bin\jli.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2132"C:\Program Files\Google\Chrome\Application\chrome.exe"C:\Program Files\Google\Chrome\Application\chrome.exejavaw.exe
User:
admin
Company:
Google LLC
Integrity Level:
HIGH
Description:
Google Chrome
Exit code:
1
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\aclayers.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
2332\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2524"C:\Users\admin\AppData\Roaming\Microsoft\Tlmtry\AntiMalwareServiceExecutable.exe" C:\Users\admin\AppData\Roaming\Microsoft\Tlmtry\AntiMalwareServiceExecutable.exe
powershell.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\roaming\microsoft\tlmtry\antimalwareserviceexecutable.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
56 555
Read events
56 515
Write events
39
Delete events
1

Modification events

(PID) Process:(7408) slui.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\3d\52C64B7E
Operation:writeName:@%SystemRoot%\System32\sppcomapi.dll,-3200
Value:
Software Licensing
(PID) Process:(5748) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\cmmgr32.exe
Operation:writeName:ProfileInstallPath
Value:
C:\ProgramData\Microsoft\Network\Connections\Cm
(PID) Process:(5748) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
Operation:writeName:SM_AccessoriesName
Value:
Accessories
(PID) Process:(5748) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion
Operation:writeName:PF_AccessoriesName
Value:
Accessories
(PID) Process:(5748) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\DllHost_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(5748) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\DllHost_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(5748) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\DllHost_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(5748) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\DllHost_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(5748) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\DllHost_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(5748) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\DllHost_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
Executable files
17
Suspicious files
11
Text files
37
Unknown types
0

Dropped files

PID
Process
Filename
Type
7484javaw.exeC:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1693682860-607145093-2874071422-1001\83aa4cc77f591dfc2374580bbd95f6ba_bb926e54-e3ca-40fd-ae90-2764341e7792binary
MD5:C8366AE350E7019AEFC9D1E6E6A498C6
SHA256:11E6ACA8E682C046C83B721EEB5C72C5EF03CB5936C60DF6F4993511DDC61238
7484javaw.exeC:\Users\admin\AppData\Local\Temp\fkrprglvdv.acdmtext
MD5:A18FB0BBE3E67074CA6D0134C0B7D5F7
SHA256:FDCEAFE4DCF9CF6D23B2033824275C08EC73D6B01ADC644416E43ECCA94C89C9
2988javaw.exeC:\Users\admin\AppData\Local\Temp\lib7824604376133704993.tmpexecutable
MD5:F8C312605C1C695B45C459953AE01B8E
SHA256:499CF4818267FE2384C4C9DFC72BB65A2562560CFE2237CD2EF49471141DE8DA
2988javaw.exeC:\Users\admin\AppData\Local\Temp\WinDefConfig.cmdtext
MD5:B47079E54B7D1B2D8C4245991C933147
SHA256:95BA820E7D0405B2E496C6F1AF93414F425179A6E44746C7868D8CEDA6E3087A
7704powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_tfjtn3n3.cba.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
2988javaw.exeC:\Users\admin\AppData\Roaming\Microsoft\SecurityUpdates\SecurityInfo.jsontext
MD5:7DD210E1E099901530E50446047DF61B
SHA256:0BB44100B8502F6AADEADAE6BB094F762A14515259ABB515ACC25C212F2C10E2
2988javaw.exeC:\Users\admin\AppData\Local\Temp\sqlite-jdbc-3.23.1.jarcompressed
MD5:76C9C25DE0F8603E5706ADAB1CC18009
SHA256:D570AF636A2BE99E20BE9510FB615AA819B2059857B2DD625AECBFF774766331
5200powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_fy2mgk2f.2lw.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
2988javaw.exeC:\Users\admin\AppData\Local\Temp\jna-natives-315016130197337575\jnidispatch.dllexecutable
MD5:719D6BA1946C25AA61CE82F90D77FFD5
SHA256:69C45175ECFD25AF023F96AC0BB2C45E6A95E3BA8A5A50EE7969CCAB14825C44
7484javaw.exeC:\Users\admin\AppData\Local\Temp\jna-1779248301093\jnidispatch.dllexecutable
MD5:2D2475F1F026DD54E9F3E787AE4F81DA
SHA256:5A7FF949F6D93D86491EB5B26B1CFC60051168A60622650224B89995AC420023
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
91
TCP/UDP connections
92
DNS requests
15
Threats
49

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5276
MoUsoCoreWorker.exe
GET
304
48.209.133.15:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
5276
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
GET
200
1.0.0.1:443
https://cloudflare-dns.com/dns-query?name=eth.llamarpc.com&type=A
AU
text
266 b
unknown
3352
svchost.exe
GET
200
48.209.133.15:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/WaasMedic?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&appVer=10.0.19041.3758&ring=Retail&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4
US
text
3.41 Kb
whitelisted
5764
SIHClient.exe
GET
304
135.232.92.137:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
3352
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
7408
slui.exe
POST
500
48.192.1.65:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
xml
512 b
whitelisted
5316
svchost.exe
POST
200
40.126.31.131:443
https://login.live.com/RST2.srf
US
xml
1.24 Kb
whitelisted
7408
slui.exe
POST
500
48.192.1.64:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
xml
512 b
whitelisted
5316
svchost.exe
POST
200
40.126.32.134:443
https://login.live.com/RST2.srf
US
xml
1.24 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
5276
MoUsoCoreWorker.exe
48.209.133.15:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5412
slui.exe
48.192.1.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3352
svchost.exe
48.209.133.15:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
23.11.206.98:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
7484
javaw.exe
104.16.249.249:443
cloudflare-dns.com
CLOUDFLARENET
US
whitelisted
3352
svchost.exe
184.24.77.37:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
3352
svchost.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
5276
MoUsoCoreWorker.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
activation-v2.sls.microsoft.com
  • 48.192.1.64
whitelisted
www.bing.com
  • 23.11.206.98
  • 23.3.89.122
  • 95.100.158.114
whitelisted
google.com
  • 142.251.20.100
  • 142.251.20.113
  • 142.251.20.138
  • 142.251.20.102
  • 142.251.20.101
  • 142.251.20.139
whitelisted
cloudflare-dns.com
  • 104.16.249.249
  • 104.16.248.249
whitelisted
crl.microsoft.com
  • 184.24.77.37
  • 184.24.77.12
  • 184.24.77.35
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
login.live.com
  • 40.126.32.134
  • 40.126.32.140
  • 20.190.160.128
  • 20.190.160.66
  • 20.190.160.130
  • 20.190.160.65
  • 20.190.160.64
  • 20.190.160.3
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
settings-win.data.microsoft.com
  • 48.209.133.15
whitelisted
slscr.update.microsoft.com
  • 135.232.92.137
whitelisted

Threats

PID
Process
Class
Message
2232
svchost.exe
Misc activity
INFO [ANY.RUN] Cloudflare DNS-over-HTTPS service requested (cloudflare-dns .com)
7484
javaw.exe
Misc activity
ET INFO Observed Cloudflare DNS over HTTPS Domain (cloudflare-dns .com in TLS SNI)
7484
javaw.exe
A Network Trojan was detected
STEALER WeedHack TLS activity observed
3352
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
A Network Trojan was detected
ET MALWARE EtherHiding Exfil M2
A Network Trojan was detected
ET MALWARE EtherHiding Exfil M2
Misc activity
INFO [ANY.RUN] DDoS-Guard Hosted Web Content observed
7484
javaw.exe
A Network Trojan was detected
STEALER WeedHack TLS activity observed
A Network Trojan was detected
ET MALWARE EtherHiding Exfil M2
2232
svchost.exe
Misc activity
INFO [ANY.RUN] Cloudflare DNS-over-HTTPS service requested (cloudflare-dns .com)
No debug info