File name:

anyukit-win.exe

Full analysis: https://app.any.run/tasks/254dfdeb-ab3a-4d0a-a353-a490bd7ed171
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: March 24, 2025, 16:54:36
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
python
evasion
loader
arch-doc
blind-copy
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 3 sections
MD5:

D1E979605343E1DAB303AE5079797807

SHA1:

FED1D620AEEFA4A8A6876ABAE436EC6EF4184FB8

SHA256:

07706271A611BE66D59BD1F056DAF125E4DEEA4FF15DB898293A6D38A36D9099

SSDEEP:

98304:aMJ7iOZi7Di6BMQfFNkwyWcdsQu/w04TIyLBUhBEOn37fFHH5pSuzDeINKAICcd3:XU6J21P/EVKpFt6B

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • There is functionality for taking screenshot (YARA)

      • anyukit-win.exe (PID: 2140)
      • anyukit_10.8.2.exe (PID: 8152)
      • AnyUkit.exe (PID: 3240)
      • QtWebEngineProcess.exe (PID: 7264)
    • Get information on the list of running processes

      • anyukit-win.exe (PID: 2140)
    • Uses TASKKILL.EXE to kill process

      • anyukit-win.exe (PID: 2140)
    • Executable content was dropped or overwritten

      • anyukit_10.8.2.exe (PID: 8152)
      • AnyUkit.exe (PID: 3240)
    • Process drops legitimate windows executable

      • anyukit_10.8.2.exe (PID: 8152)
    • Connects to unusual port

      • anyukit-win.exe (PID: 2140)
      • AnyUkit.exe (PID: 3240)
      • QtWebEngineProcess.exe (PID: 7264)
    • Reads security settings of Internet Explorer

      • ShellExperienceHost.exe (PID: 7392)
      • anyukit-win.exe (PID: 2140)
    • Checks for external IP

      • svchost.exe (PID: 2196)
      • AnyUkit.exe (PID: 3240)
    • Loads Python modules

      • AnyUkit.exe (PID: 3240)
    • Creates a software uninstall entry

      • anyukit_10.8.2.exe (PID: 8152)
    • The process drops C-runtime libraries

      • anyukit_10.8.2.exe (PID: 8152)
    • Adds/modifies Windows certificates

      • QtWebEngineProcess.exe (PID: 7264)
    • Process requests binary or script from the Internet

      • QtWebEngineProcess.exe (PID: 7264)
    • The process checks if it is being run in the virtual environment

      • perfmon.exe (PID: 2236)
  • INFO

    • Checks supported languages

      • anyukit-win.exe (PID: 2140)
      • ShellExperienceHost.exe (PID: 7392)
      • QtWebEngineProcess.exe (PID: 7264)
      • AnyUkit.exe (PID: 3240)
      • QtWebEngineProcess.exe (PID: 7480)
      • QtWebEngineProcess.exe (PID: 7212)
      • QtWebEngineProcess.exe (PID: 6416)
      • QtWebEngineProcess.exe (PID: 4944)
      • QtWebEngineProcess.exe (PID: 1116)
      • QtWebEngineProcess.exe (PID: 7320)
      • QtWebEngineProcess.exe (PID: 7260)
      • QtWebEngineProcess.exe (PID: 8196)
      • QtWebEngineProcess.exe (PID: 8484)
      • QtWebEngineProcess.exe (PID: 5512)
      • QtWebEngineProcess.exe (PID: 7284)
      • perfmon.exe (PID: 2236)
    • Reads the computer name

      • anyukit-win.exe (PID: 2140)
      • ShellExperienceHost.exe (PID: 7392)
      • AnyUkit.exe (PID: 3240)
      • QtWebEngineProcess.exe (PID: 7320)
      • QtWebEngineProcess.exe (PID: 7264)
      • QtWebEngineProcess.exe (PID: 7480)
      • QtWebEngineProcess.exe (PID: 7260)
      • QtWebEngineProcess.exe (PID: 1116)
      • identity_helper.exe (PID: 3796)
      • QtWebEngineProcess.exe (PID: 8196)
      • QtWebEngineProcess.exe (PID: 7284)
      • QtWebEngineProcess.exe (PID: 5512)
      • perfmon.exe (PID: 2236)
    • Checks proxy server information

      • BackgroundTransferHost.exe (PID: 7776)
      • anyukit-win.exe (PID: 2140)
      • AnyUkit.exe (PID: 3240)
      • QtWebEngineProcess.exe (PID: 7264)
      • slui.exe (PID: 8052)
    • The sample compiled with chinese language support

      • anyukit-win.exe (PID: 2140)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 7776)
      • anyukit_10.8.2.exe (PID: 8152)
      • AnyUkit.exe (PID: 3240)
      • QtWebEngineProcess.exe (PID: 7264)
    • UPX packer has been detected

      • anyukit-win.exe (PID: 2140)
    • Reads the machine GUID from the registry

      • anyukit-win.exe (PID: 2140)
      • AnyUkit.exe (PID: 3240)
      • QtWebEngineProcess.exe (PID: 7264)
    • Create files in a temporary directory

      • anyukit_10.8.2.exe (PID: 8152)
      • anyukit-win.exe (PID: 2140)
    • The sample compiled with english language support

      • anyukit_10.8.2.exe (PID: 8152)
      • msedge.exe (PID: 864)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 7560)
      • BackgroundTransferHost.exe (PID: 8176)
      • BackgroundTransferHost.exe (PID: 7944)
      • BackgroundTransferHost.exe (PID: 7776)
      • BackgroundTransferHost.exe (PID: 4920)
      • resmon.exe (PID: 7584)
    • Reads the software policy settings

      • BackgroundTransferHost.exe (PID: 7776)
      • QtWebEngineProcess.exe (PID: 7264)
    • Creates files in the program directory

      • anyukit-win.exe (PID: 2140)
      • anyukit_10.8.2.exe (PID: 8152)
    • Manual execution by a user

      • msedge.exe (PID: 7876)
      • Taskmgr.exe (PID: 9048)
      • Taskmgr.exe (PID: 8120)
      • resmon.exe (PID: 7584)
    • Application launched itself

      • msedge.exe (PID: 7256)
      • msedge.exe (PID: 7876)
    • Process checks computer location settings

      • QtWebEngineProcess.exe (PID: 7320)
      • QtWebEngineProcess.exe (PID: 7480)
      • QtWebEngineProcess.exe (PID: 7212)
      • QtWebEngineProcess.exe (PID: 6416)
      • QtWebEngineProcess.exe (PID: 4944)
      • QtWebEngineProcess.exe (PID: 1116)
      • QtWebEngineProcess.exe (PID: 8196)
      • QtWebEngineProcess.exe (PID: 5512)
    • Reads Environment values

      • identity_helper.exe (PID: 3796)
    • Reads the time zone

      • perfmon.exe (PID: 2236)
    • Reads CPU info

      • perfmon.exe (PID: 2236)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 864)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (87.1)
.exe | Generic Win/DOS Executable (6.4)
.exe | DOS Executable Generic (6.4)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:01:22 05:16:21+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.42
CodeSize: 7770112
InitializedDataSize: 28672
UninitializedDataSize: 12185600
EntryPoint: 0x1308150
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.1.0.0
ProductVersionNumber: 1.1.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: anyukit-setup
FileVersion: 1.1.0.0
InternalName: anyukit-setup.exe
LegalCopyright: Copyright (C) 2025
ProductName: anyukit-setup
ProductVersion: 1.1.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
238
Monitored processes
88
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start anyukit-win.exe tasklist.exe no specs conhost.exe no specs sppextcomobj.exe no specs slui.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs shellexperiencehost.exe no specs slui.exe taskkill.exe no specs conhost.exe no specs anyukit_10.8.2.exe msedge.exe no specs anyukit.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs svchost.exe qtwebengineprocess.exe qtwebengineprocess.exe no specs qtwebengineprocess.exe no specs qtwebengineprocess.exe no specs qtwebengineprocess.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs qtwebengineprocess.exe no specs qtwebengineprocess.exe no specs qtwebengineprocess.exe no specs qtwebengineprocess.exe no specs qtwebengineprocess.exe no specs qtwebengineprocess.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs taskmgr.exe no specs taskmgr.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs qtwebengineprocess.exe no specs msedge.exe no specs msedge.exe no specs qtwebengineprocess.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs resmon.exe no specs perfmon.exe no specs perfmon.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs anyukit-win.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
132"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6152 --field-trial-handle=2380,i,17340672497708997326,17891686497237044727,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
232"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5680 --field-trial-handle=2380,i,17340672497708997326,17891686497237044727,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
444"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=5444 --field-trial-handle=2380,i,17340672497708997326,17891686497237044727,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
672"C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --no-appcompat-clear --mojo-platform-channel-handle=5628 --field-trial-handle=2380,i,17340672497708997326,17891686497237044727,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\122.0.2365.59\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
3221226029
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\identity_helper.exe
c:\windows\system32\ntdll.dll
864"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=6788 --field-trial-handle=2380,i,17340672497708997326,17891686497237044727,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1040"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=2644 --field-trial-handle=2380,i,17340672497708997326,17891686497237044727,262144 --variations-seed-version /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
122.0.2365.59
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\122.0.2365.59\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1116"C:\Program Files\AnyUkit\QtWebEngineProcess.exe" --type=renderer --disable-speech-api --enable-threaded-compositing --enable-features=AllowContentInitiatedDataUrlNavigations,TracingServiceInProcess --disable-features=BackgroundFetch,ConsolidatedMovementXY,DnsOverHttpsUpgrade,FormControlsRefresh,MojoVideoCapture,PictureInPicture,SmsReceiver,UseSkiaRenderer,WebPayments,WebUSB --lang=en-US --webengine-schemes=qrc:sLV --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --mojo-platform-channel-handle=5168 /prefetch:1C:\Program Files\AnyUkit\QtWebEngineProcess.exeAnyUkit.exe
User:
admin
Company:
The Qt Company Ltd.
Integrity Level:
LOW
Description:
C++ Application Development Framework
Exit code:
0
Version:
5.15.2.0
Modules
Images
c:\program files\anyukit\qtwebengineprocess.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2140"C:\Users\admin\Downloads\anyukit-win.exe" C:\Users\admin\Downloads\anyukit-win.exe
explorer.exe
User:
admin
Company:
anyukit-setup
Integrity Level:
HIGH
Exit code:
0
Version:
1.1.0.0
Modules
Images
c:\users\admin\downloads\anyukit-win.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2196C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2236"C:\WINDOWS\System32\perfmon.exe" /resC:\Windows\System32\perfmon.exe
resmon.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Resource and Performance Monitor
Version:
10.00
Modules
Images
c:\windows\system32\perfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\gdi32.dll
Total events
30 276
Read events
30 196
Write events
73
Delete events
7

Modification events

(PID) Process:(7560) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7560) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7560) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7776) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7776) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7776) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7944) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7944) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7944) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(8176) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
Executable files
219
Suspicious files
1 457
Text files
3 067
Unknown types
3

Dropped files

PID
Process
Filename
Type
7776BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\0fced20b-c0db-41bc-9f9b-7395db675b8b.down_data
MD5:
SHA256:
2140anyukit-win.exeC:\Users\admin\AppData\Local\Temp\Amoyshare\AnyUkit\anyukit_10.8.2.exe
MD5:
SHA256:
8152anyukit_10.8.2.exeC:\Program Files\AnyUkit\AnyUkit.ilk
MD5:
SHA256:
7776BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\deb43245-0eaf-4e5b-b6ea-c4968f064e94.up_meta_securebinary
MD5:BCEF1A56EFB09A2F3F2BE2C154B8F2FB
SHA256:03845B84EDF3D6F8E688A58C068388E6F41CD06CD1CE8B3C86E47BA28A7FC7C2
8152anyukit_10.8.2.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyUkit\AnyUkit.lnkbinary
MD5:D8E8DB809FC46FA9F95D11EC75953383
SHA256:312FDDC2A9CACCC71B1B25CF3145817EA7283C2AE7C59E5DC8B7A1C642BA50EB
8152anyukit_10.8.2.exeC:\Users\admin\Desktop\AnyUkit.lnkbinary
MD5:1F8B36C241E4FEB6BD5D05AF6210B483
SHA256:C74249AD7AACD54EE3B9EE4EA3022D85FF37B53ADFB6D78E3BC06C63B3F315D1
7776BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:2B8088C35DAB38115A17E318781F001C
SHA256:0197C4055C1C5182A6D99B076AAE45370398C8E2CBA5EBD38388A2FE22E25861
2140anyukit-win.exeC:\Users\admin\AppData\Local\Temp\Amoyshare\AnyUkit\anyukit_10.8.2.exe.aria2binary
MD5:0FF611AA1CA7C4E5C6D0BA430DD5803C
SHA256:0D87E4FC18EEAA8B47C111D682E9B68F71300518FE6DF54B4ED7627453F32FAF
8152anyukit_10.8.2.exeC:\Program Files\AnyUkit\AnyUkit.exeexecutable
MD5:DB62D5EB33163BC34865360331639725
SHA256:5CA17E49B47A8D2CE2A25484C036E490838EB1A6833DF4ACE8C491AA363DE12E
2140anyukit-win.exeC:\Users\admin\AppData\Local\Temp\Amoyshare\AnyUkit\anyukit_10.8.2.exe.aria2__tempbinary
MD5:0FF611AA1CA7C4E5C6D0BA430DD5803C
SHA256:0D87E4FC18EEAA8B47C111D682E9B68F71300518FE6DF54B4ED7627453F32FAF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
90
TCP/UDP connections
224
DNS requests
166
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.53.40.176:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2140
anyukit-win.exe
GET
200
52.43.115.201:80
http://anys.1010diy.com/download-software/setup/anyukit-win.json
unknown
unknown
2140
anyukit-win.exe
HEAD
200
104.26.9.195:80
http://www.amoyshare.info/download-software/anyukit-win.exe
unknown
unknown
5332
backgroundTaskHost.exe
GET
200
23.54.109.203:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6544
svchost.exe
GET
200
23.54.109.203:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7776
BackgroundTransferHost.exe
GET
200
23.54.109.203:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
756
lsass.exe
GET
200
23.209.209.135:80
http://x1.c.lencr.org/
unknown
whitelisted
4188
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4188
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7264
QtWebEngineProcess.exe
GET
200
18.245.38.41:80
http://ocsp.rootg2.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBSIfaREXmfqfJR3TkMYnD7O5MhzEgQUnF8A36oB1zArOIiiuG1KnPIRkYMCEwZ%2FlEoqJ83z%2BsKuKwH5CO65xMY%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.53.40.176:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
976
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2140
anyukit-win.exe
52.43.115.201:80
anys.1010diy.com
AMAZON-02
US
suspicious
2140
anyukit-win.exe
34.215.135.181:8086
backend.1010diy.com
AMAZON-02
US
unknown
3216
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
40.126.32.138:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
23.54.109.203:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 23.53.40.176
  • 23.53.40.178
whitelisted
anys.1010diy.com
  • 52.43.115.201
  • 52.42.46.146
unknown
backend.1010diy.com
  • 34.215.135.181
  • 35.86.41.0
unknown
client.wns.windows.com
  • 40.113.110.67
whitelisted
login.live.com
  • 40.126.32.138
  • 40.126.32.76
  • 20.190.160.17
  • 20.190.160.132
  • 20.190.160.64
  • 40.126.32.133
  • 20.190.160.5
  • 20.190.160.14
whitelisted
ocsp.digicert.com
  • 23.54.109.203
  • 2.23.77.188
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
whitelisted
arc.msn.com
  • 20.103.156.88
whitelisted
www.bing.com
  • 2.23.227.215
  • 2.23.227.208
  • 23.53.43.121
  • 23.53.43.115
whitelisted
www.amoyshare.info
  • 104.26.9.195
  • 172.67.72.121
  • 104.26.8.195
unknown

Threats

PID
Process
Class
Message
2140
anyukit-win.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
2140
anyukit-win.exe
Unknown Traffic
ET HUNTING Suspicious Empty Accept-Encoding Header
2196
svchost.exe
Device Retrieving External IP Address Detected
ET INFO External IP Lookup Domain in DNS Lookup (ipinfo .io)
3240
AnyUkit.exe
Device Retrieving External IP Address Detected
ET INFO Possible External IP Lookup Domain Observed in SNI (ipinfo. io)
No debug info