File name:

winx.exe

Full analysis: https://app.any.run/tasks/799b555b-be05-4ecc-8573-1ebad1f95882
Verdict: Malicious activity
Threats:

Crypto mining malware is a resource-intensive threat that infiltrates computers with the purpose of mining cryptocurrencies. This type of threat can be deployed either on an infected machine or a compromised website. In both cases the miner will utilize the computing power of the device and its network bandwidth.

Analysis date: October 03, 2025, 17:34:33
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
python
pyinstaller
miner
github
winring0-sys
vuln-driver
xmrig
upx
xor-url
generic
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 7 sections
MD5:

D64DCC284CA96F9C6F43626C8F1A2039

SHA1:

9ACD19753299973EB84AA105315AE0FAE723557A

SHA256:

008A1C1D80575E86E0DC42D1493CD3E7F28C15DF526E5FAF2DB25BB2E13AED3E

SSDEEP:

98304:K1T2Q6axHrjr1wog3UtACy38z6k7eNiMFbumVYVqqo6phxsKzrrJiltdcGq/kgzR:Tq6OpfQGGG1bV30gTaK7uEcO

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • winx.exe (PID: 4596)
      • winx.exe (PID: 5836)
      • zxbbvxaqrces.exe (PID: 6924)
    • Vulnerable driver has been detected

      • zxbbvxaqrces.exe (PID: 6924)
    • XMRIG has been detected (YARA)

      • svchost.exe (PID: 2364)
    • XORed URL has been found (YARA)

      • svchost.exe (PID: 2364)
  • SUSPICIOUS

    • Process drops python dynamic module

      • winx.exe (PID: 5836)
    • Process drops legitimate windows executable

      • winx.exe (PID: 5836)
    • Executable content was dropped or overwritten

      • winx.exe (PID: 5836)
      • winx.exe (PID: 7440)
      • temp_wrapper.py (PID: 2356)
      • zxbbvxaqrces.exe (PID: 6924)
    • Application launched itself

      • winx.exe (PID: 5836)
    • The process drops C-runtime libraries

      • winx.exe (PID: 5836)
    • Loads Python modules

      • winx.exe (PID: 7440)
    • Starts CMD.EXE for commands execution

      • winx.exe (PID: 7440)
    • There is functionality for taking screenshot (YARA)

      • winx.exe (PID: 5836)
      • winx.exe (PID: 7440)
    • Starts application with an unusual extension

      • cmd.exe (PID: 1912)
    • Windows service management via SC.EXE

      • sc.exe (PID: 2288)
      • sc.exe (PID: 6512)
    • Starts SC.EXE for service management

      • temp_wrapper.py (PID: 2356)
    • Stops a currently running service

      • sc.exe (PID: 2852)
    • Executes as Windows Service

      • zxbbvxaqrces.exe (PID: 6924)
    • Drops a system driver (possible attempt to evade defenses)

      • zxbbvxaqrces.exe (PID: 6924)
    • Crypto Currency Mining Activity Detected

      • svchost.exe (PID: 2428)
    • The executable file from the user directory is run by the CMD process

      • temp_wrapper.py (PID: 2356)
    • Creates a new Windows service

      • sc.exe (PID: 5320)
  • INFO

    • Reads the computer name

      • winx.exe (PID: 5836)
    • Checks supported languages

      • winx.exe (PID: 5836)
      • winx.exe (PID: 7440)
      • temp_wrapper.py (PID: 2356)
      • zxbbvxaqrces.exe (PID: 6924)
    • Create files in a temporary directory

      • winx.exe (PID: 5836)
      • winx.exe (PID: 7440)
    • The sample compiled with english language support

      • winx.exe (PID: 5836)
    • Reads the machine GUID from the registry

      • winx.exe (PID: 7440)
    • Checks operating system version

      • winx.exe (PID: 7440)
    • PyInstaller has been detected (YARA)

      • winx.exe (PID: 5836)
      • winx.exe (PID: 7440)
    • Creates files in the program directory

      • temp_wrapper.py (PID: 2356)
    • The sample compiled with japanese language support

      • zxbbvxaqrces.exe (PID: 6924)
    • UPX packer has been detected

      • svchost.exe (PID: 2364)
    • Checks proxy server information

      • slui.exe (PID: 5792)
    • Reads the software policy settings

      • slui.exe (PID: 5792)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:10:03 09:44:31+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.42
CodeSize: 173568
InitializedDataSize: 155648
UninitializedDataSize: -
EntryPoint: 0xce20
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
185
Monitored processes
23
Malicious processes
4
Suspicious processes
3

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
1912C:\WINDOWS\system32\cmd.exe /c "C:\Users\admin\AppData\Local\Temp\_MEI58362\temp_wrapper.py"C:\Windows\System32\cmd.exewinx.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
2284\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2288C:\WINDOWS\system32\sc.exe delete "MFRNCJUT"C:\Windows\System32\sc.exetemp_wrapper.py
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
1060
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
2332\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2356C:\Users\admin\AppData\Local\Temp\_MEI58362\temp_wrapper.pyC:\Users\admin\AppData\Local\Temp\_MEI58362\temp_wrapper.py
cmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\_mei58362\temp_wrapper.py
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
2364svchost.exeC:\Windows\System32\svchost.exe
zxbbvxaqrces.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
2428C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2852C:\WINDOWS\system32\sc.exe stop eventlogC:\Windows\System32\sc.exetemp_wrapper.py
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
1051
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
4596"C:\Users\admin\Desktop\winx.exe" C:\Users\admin\Desktop\winx.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\winx.exe
c:\windows\system32\ntdll.dll
5320C:\WINDOWS\system32\sc.exe create "MFRNCJUT" binpath= "C:\ProgramData\xpmrnpkbycsk\zxbbvxaqrces.exe" start= "auto"C:\Windows\System32\sc.exetemp_wrapper.py
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
Total events
8 120
Read events
8 120
Write events
0
Delete events
0

Modification events

No data
Executable files
36
Suspicious files
1
Text files
11
Unknown types
0

Dropped files

PID
Process
Filename
Type
5836winx.exeC:\Users\admin\AppData\Local\Temp\_MEI58362\api-ms-win-core-file-l1-2-0.dllexecutable
MD5:6A55A7E284B51B086B63CC6F2061CE8B
SHA256:D9973270A952B4CE615104520051E847B26E4B1CC330A5A95BA1AE128F0DFDEB
5836winx.exeC:\Users\admin\AppData\Local\Temp\_MEI58362\api-ms-win-core-localization-l1-2-0.dllexecutable
MD5:2AC1289E4DBAB076B332869BEF26D3CE
SHA256:6475F20F46814D28845C2FA73E9C283A8504483FA16D911325588C778CF76C26
5836winx.exeC:\Users\admin\AppData\Local\Temp\_MEI58362\_socket.pydexecutable
MD5:F73B9863071FB3088C08605F76B8E909
SHA256:8EFDBACF67C223F47B608E57222CF80DD12CEE163945847F6CFA9EA6C26ADA36
5836winx.exeC:\Users\admin\AppData\Local\Temp\_MEI58362\api-ms-win-core-file-l2-1-0.dllexecutable
MD5:6E38A6BED88E1C27155E4DC428188EF0
SHA256:144D3A28E43E47FC1CCE956255CC80467D4A6FBBB8F612EC6D85F62DE030A924
5836winx.exeC:\Users\admin\AppData\Local\Temp\_MEI58362\_cffi_backend.cp310-win_amd64.pydexecutable
MD5:282B92EF9ED04C419564FBAEE2C5CDBE
SHA256:5763C1D29903567CDE4D46355D3A7380D10143543986CA4EEBFCA4D22D991E3E
5836winx.exeC:\Users\admin\AppData\Local\Temp\_MEI58362\api-ms-win-core-processthreads-l1-1-1.dllexecutable
MD5:1AF2A91DC0A4E48BAB0CA123073ADF30
SHA256:AE574C9B8A2467C3EE0AC3E862255E93A02627BCE146AD7B720B99905DC224FC
5836winx.exeC:\Users\admin\AppData\Local\Temp\_MEI58362\_lzma.pydexecutable
MD5:FD4C7582BEE16436BB3F790E1273EB22
SHA256:8AA5CD82D775EA718D3DDD270F0B28985D8711EF937447EE2168318200F0EB80
5836winx.exeC:\Users\admin\AppData\Local\Temp\_MEI58362\_decimal.pydexecutable
MD5:6B07F5C49AE2AF116E4D41CE7D552451
SHA256:04AFE789EAB63D204337E9EDABEF1E1CD003DB69D66DC2CF0FC9E9E7A47304A6
5836winx.exeC:\Users\admin\AppData\Local\Temp\_MEI58362\_hashlib.pydexecutable
MD5:F883652E056FF4882E1BC900D382EDAB
SHA256:583F6D20998E45FF94400EFAEECC4E17204449A0CC7BA68A20D1E8D13617F27B
5836winx.exeC:\Users\admin\AppData\Local\Temp\_MEI58362\_bz2.pydexecutable
MD5:183F1289E094220FBB2841918798598F
SHA256:164F1BF42630B589B50C8F0C6E55AAA8D817E439A00882BE036FFF3CBE8E6DED
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
27
TCP/UDP connections
50
DNS requests
17
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
POST
204
23.192.36.142:443
https://www.bing.com/web/xlsc.aspx?t=5&dl=1&wsbc=1
US
unknown
GET
200
23.192.36.142:443
https://www.bing.com/DSB/search?dsbmr=1&format=dsbjson&client=windowsminiserp&dsbschemaversion=1.1&dsbminiserp=1&q=q&cc=US&setlang=en-us&clientDateTime=10%2F3%2F2025%2C%205%3A36%3A05%20PM
US
64.2 Kb
unknown
GET
200
140.82.121.3:443
https://raw.githubusercontent.com/JosKROS/SUN/refs/heads/main/ROYAL
US
binary
464 b
unknown
2764
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
NL
binary
419 b
whitelisted
GET
200
20.223.36.55:443
https://arc.msn.com/v3/Delivery/Placement?pubid=da63df93-3dbc-42ae-a505-b34988683ac7&pid=88000045&adm=2&w=1&h=1&wpx=1&hpx=1&fmt=json&cltp=app&dim=le&rafb=0&nct=1&pm=1&cfmt=text,image,poly&sft=jpeg,png,gif&topt=1&poptin=0&localid=w:AC7699B0-48EA-FD22-C8DC-06A02098A0F0&ctry=US&time=20251003T173606Z&lc=en-US&pl=en-US&idtp=mid&uid=9115d6d1-9f4e-4053-9297-2a8c833b3912&aid=00000000-0000-0000-0000-000000000000&ua=WindowsShellClient%2F9.0.40929.0%20%28Windows%29&asid=d288ab096a3a4ee0bc1a977a20d1eb48&ctmode=MultiSession&arch=x64&betaedgever=0.0.0.0&canedgever=0.0.0.0&cdm=1&cdmver=10.0.19041.3636&currsel=137271744000000000&devedgever=0.0.0.0&devfam=Windows.Desktop&devform=Unknown&devosver=10.0.19045.4046&disphorzres=1360&dispsize=16.3&dispvertres=768&fosver=16299&isu=0&lo=4245695&metered=false&nettype=ethernet&npid=sc-88000045&oemName=DELL&oemid=DELL&ossku=Professional&prevosver=15063&smBiosDm=DELL&stabedgever=133.0.3065.92&tl=2&tsu=1636225&waasBldFlt=1&waasCfgExp=1&waasCfgSet=1&waasRetail=1&waasRing=&svoffered=2
US
binary
3.21 Kb
unknown
GET
200
23.192.36.137:443
https://www.bing.com/th?id=ODSWG.8229b0e5-fa8c-4e4a-af74-69717698b903&pid=dsb
US
image
4.62 Kb
unknown
GET
200
23.192.36.142:443
https://www.bing.com/th?id=ODSWG.31bcf3d1-4df8-4c6a-9b3a-447ced8d6c39&pid=dsb
US
unknown
POST
200
20.190.160.66:443
https://login.live.com/RST2.srf
US
xml
11.3 Kb
unknown
POST
200
40.126.32.134:443
https://login.live.com/RST2.srf
US
xml
11.3 Kb
unknown
GET
200
23.192.36.137:443
https://www.bing.com/client/config?cc=US&setlang=en-US
US
binary
2.15 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
2.16.241.207:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2364
svchost.exe
141.94.96.71:443
pool.supportxmr.com
OVH SAS
FR
suspicious
2364
svchost.exe
185.199.110.133:443
raw.githubusercontent.com
FASTLY
US
whitelisted
2364
svchost.exe
141.94.96.195:443
pool.supportxmr.com
OVH SAS
FR
suspicious
2144
slui.exe
4.154.209.85:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5224
SearchApp.exe
2.16.241.207:443
www.bing.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
whitelisted
www.bing.com
  • 2.16.241.207
  • 2.16.241.218
  • 2.16.241.201
  • 2.16.241.205
  • 2.16.241.222
whitelisted
google.com
  • 142.250.185.142
whitelisted
pool.supportxmr.com
  • 141.94.96.195
  • 141.94.96.71
  • 141.94.96.144
unknown
raw.githubusercontent.com
  • 185.199.110.133
  • 185.199.111.133
  • 185.199.109.133
  • 185.199.108.133
whitelisted
activation-v2.sls.microsoft.com
  • 4.154.209.85
whitelisted
login.live.com
  • 20.190.159.71
  • 40.126.31.129
  • 20.190.159.23
  • 40.126.31.130
  • 20.190.159.64
  • 40.126.31.0
  • 40.126.31.73
  • 40.126.31.69
whitelisted
slscr.update.microsoft.com
  • 20.165.94.63
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted

Threats

PID
Process
Class
Message
2428
svchost.exe
Crypto Currency Mining Activity Detected
ET MALWARE CoinMiner Domain in DNS Lookup (pool .supportxmr .com)
2428
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
No debug info