| File name: | 03.exe.exe |
| Full analysis: | https://app.any.run/tasks/2b1f895e-0e69-4e28-af5c-ce414e4df3bc |
| Verdict: | Malicious activity |
| Analysis date: | May 11, 2025, 02:27:27 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections |
| MD5: | EF9AA4D03A69E69BBC44867F8436001D |
| SHA1: | 57DB1F7070D71B752C4A8457D53908752A6C23C6 |
| SHA256: | 0379D402A94F960380D7D91E3BFA106EEAC01CD39AE7B0BA5010BA737088A215 |
| SSDEEP: | 6144:A/TLLtKUmyP+3hZzbmQA/3fVf8lYImAvxJkNdxAQk:AbtmyG3hpbmQA/tklYXNbg |
| .exe | | | Win64 Executable (generic) (72.3) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (11.8) |
| .exe | | | Clipper DOS Executable (5.2) |
| .exe | | | Generic Win/DOS Executable (5.2) |
| .exe | | | DOS Executable Generic (5.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:09:07 06:03:30+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 181248 |
| InitializedDataSize: | 42273792 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1fcd6 |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 85.0.0.0 |
| ProductVersionNumber: | 40.0.0.0 |
| FileFlagsMask: | 0x005f |
| FileFlags: | Private build |
| FileOS: | Unknown (0x40324) |
| ObjectFileType: | Static library |
| FileSubtype: | 86 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2196 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4428 | C:\WINDOWS\SysWOW64\WerFault.exe -u -p 7220 -s 1276 | C:\Windows\SysWOW64\WerFault.exe | — | 03.exe.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4988 | C:\WINDOWS\SysWOW64\WerFault.exe -u -p 7220 -s 1912 | C:\Windows\SysWOW64\WerFault.exe | — | 03.exe.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7036 | C:\WINDOWS\SysWOW64\WerFault.exe -u -p 7220 -s 920 | C:\Windows\SysWOW64\WerFault.exe | — | 03.exe.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7220 | "C:\Users\admin\AppData\Local\Temp\03.exe.exe" | C:\Users\admin\AppData\Local\Temp\03.exe.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 7420 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7528 | C:\WINDOWS\SysWOW64\WerFault.exe -u -p 7220 -s 500 | C:\Windows\SysWOW64\WerFault.exe | — | 03.exe.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7696 | C:\WINDOWS\SysWOW64\WerFault.exe -u -p 7220 -s 548 | C:\Windows\SysWOW64\WerFault.exe | — | 03.exe.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7832 | C:\WINDOWS\SysWOW64\WerFault.exe -u -p 7220 -s 640 | C:\Windows\SysWOW64\WerFault.exe | — | 03.exe.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7904 | C:\WINDOWS\SysWOW64\WerFault.exe -u -p 7220 -s 700 | C:\Windows\SysWOW64\WerFault.exe | — | 03.exe.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7528 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_03.exe.exe_c6cc7ced5dc4359f09234f3aed519865117abf3_0337d69a_3bbdfe52-7e34-497b-82a9-e11adcccfdd6\Report.wer | — | |
MD5:— | SHA256:— | |||
| 7696 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_03.exe.exe_c6cc7ced5dc4359f09234f3aed519865117abf3_0337d69a_5a1c3bdd-ac7a-4fa5-b5dc-df027f29f3ab\Report.wer | — | |
MD5:— | SHA256:— | |||
| 7832 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_03.exe.exe_c6cc7ced5dc4359f09234f3aed519865117abf3_0337d69a_521af664-e300-4eba-ac3e-cac81cb27351\Report.wer | — | |
MD5:— | SHA256:— | |||
| 7904 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_03.exe.exe_c6cc7ced5dc4359f09234f3aed519865117abf3_0337d69a_3d542d19-29a8-4cd3-a62b-a8414acb1452\Report.wer | — | |
MD5:— | SHA256:— | |||
| 7976 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_03.exe.exe_c6cc7ced5dc4359f09234f3aed519865117abf3_0337d69a_0bdb1998-a960-41c8-80f0-3c2cf50014f2\Report.wer | — | |
MD5:— | SHA256:— | |||
| 7528 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WERC4B9.tmp.dmp | binary | |
MD5:CD28147911E750C9977F90E1D0FA1145 | SHA256:428F29F2299338CDA8F39418769408303BB77F08D4361376FB8AE16D876A7348 | |||
| 7696 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WERCE3F.tmp.dmp | dmp | |
MD5:FCA829A268307A7B75BF498087FEB624 | SHA256:5927DE534755AD5E27BB25F3C375AB0E6FF475647645F9C40BEC956D61512008 | |||
| 7832 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WERD207.tmp.dmp | binary | |
MD5:2210B616B0351CA3BF3E9144B2C7932A | SHA256:C95869307C71BB7B10111646B11B8A49FCC251EAB1CACE4506C4C4ADE138E9D2 | |||
| 7696 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WERCF0B.tmp.WERInternalMetadata.xml | binary | |
MD5:E0AAA3A584AECC78A242AFB40F45D000 | SHA256:E13FCD90C8725DB8413FAE73ED7642C4B266A2A6EC2AFB3CAB079ED90D83A87B | |||
| 8068 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_03.exe.exe_c6cc7ced5dc4359f09234f3aed519865117abf3_0337d69a_16071405-e78f-4f2f-a7bc-f682cce120e1\Report.wer | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6544 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6540 | SIHClient.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
6540 | SIHClient.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.19.11.105:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.19.11.105:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.19.11.105:80 | crl.microsoft.com | Elisa Oyj | NL | whitelisted |
— | — | 2.19.11.105:80 | crl.microsoft.com | Elisa Oyj | NL | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.219.150.101:80 | www.microsoft.com | AKAMAI-AS | CL | whitelisted |
— | — | 23.219.150.101:80 | www.microsoft.com | AKAMAI-AS | CL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3216 | svchost.exe | 172.211.123.249:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6544 | svchost.exe | 20.190.160.4:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
gc-prtnrs.top |
| unknown |
gcc-prtnrs.top |
| unknown |
slscr.update.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2196 | svchost.exe | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |
2196 | svchost.exe | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |
2196 | svchost.exe | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |
2196 | svchost.exe | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |