File name:

anyukit-win.exe

Full analysis: https://app.any.run/tasks/f28e9f03-c2a5-4b10-a823-569a819e8f76
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: April 13, 2025, 16:22:47
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 3 sections
MD5:

D1E979605343E1DAB303AE5079797807

SHA1:

FED1D620AEEFA4A8A6876ABAE436EC6EF4184FB8

SHA256:

07706271A611BE66D59BD1F056DAF125E4DEEA4FF15DB898293A6D38A36D9099

SSDEEP:

98304:aMJ7iOZi7Di6BMQfFNkwyWcdsQu/w04TIyLBUhBEOn37fFHH5pSuzDeINKAICcd3:XU6J21P/EVKpFt6B

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Get information on the list of running processes

      • anyukit-win.exe (PID: 1164)
    • Process requests binary or script from the Internet

      • anyukit-win.exe (PID: 1164)
    • Connects to unusual port

      • anyukit-win.exe (PID: 1164)
    • Uses TASKKILL.EXE to kill process

      • anyukit-win.exe (PID: 1164)
    • Executable content was dropped or overwritten

      • anyukit_10.8.3.exe (PID: 2340)
    • Process drops legitimate windows executable

      • anyukit_10.8.3.exe (PID: 2340)
  • INFO

    • Checks supported languages

      • anyukit-win.exe (PID: 1164)
      • anyukit_10.8.3.exe (PID: 2340)
    • Checks proxy server information

      • anyukit-win.exe (PID: 1164)
    • Reads the computer name

      • anyukit-win.exe (PID: 1164)
    • The sample compiled with chinese language support

      • anyukit-win.exe (PID: 1164)
    • Reads the machine GUID from the registry

      • anyukit-win.exe (PID: 1164)
    • Create files in a temporary directory

      • anyukit-win.exe (PID: 1164)
      • anyukit_10.8.3.exe (PID: 2340)
    • Creates files in the program directory

      • anyukit-win.exe (PID: 1164)
      • anyukit_10.8.3.exe (PID: 2340)
    • Creates files or folders in the user directory

      • anyukit_10.8.3.exe (PID: 2340)
    • The sample compiled with english language support

      • anyukit_10.8.3.exe (PID: 2340)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (87.1)
.exe | Generic Win/DOS Executable (6.4)
.exe | DOS Executable Generic (6.4)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:01:22 05:16:21+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.42
CodeSize: 7770112
InitializedDataSize: 28672
UninitializedDataSize: 12185600
EntryPoint: 0x1308150
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.1.0.0
ProductVersionNumber: 1.1.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: anyukit-setup
FileVersion: 1.1.0.0
InternalName: anyukit-setup.exe
LegalCopyright: Copyright (C) 2025
ProductName: anyukit-setup
ProductVersion: 1.1.0.0
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
7
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start anyukit-win.exe tasklist.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs anyukit_10.8.3.exe anyukit-win.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1164"C:\Users\admin\Desktop\anyukit-win.exe" C:\Users\admin\Desktop\anyukit-win.exe
explorer.exe
User:
admin
Company:
anyukit-setup
Integrity Level:
HIGH
Version:
1.1.0.0
Modules
Images
c:\users\admin\desktop\anyukit-win.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2340C:\Users\admin\AppData\Local\Temp\Amoyshare\AnyUkit\anyukit_10.8.3.exe /S -path= "C:\Program Files\AnyUkit" -language=EnglishC:\Users\admin\AppData\Local\Temp\Amoyshare\AnyUkit\anyukit_10.8.3.exe
anyukit-win.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\local\temp\amoyshare\anyukit\anyukit_10.8.3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3180tasklist C:\Windows\System32\tasklist.exeanyukit-win.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Lists the current running tasks
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
5072"C:\Users\admin\Desktop\anyukit-win.exe" C:\Users\admin\Desktop\anyukit-win.exeexplorer.exe
User:
admin
Company:
anyukit-setup
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
1.1.0.0
Modules
Images
c:\users\admin\desktop\anyukit-win.exe
c:\windows\system32\ntdll.dll
5072taskkill /F /IM AnyUkit.exeC:\Windows\System32\taskkill.exeanyukit-win.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6028\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetasklist.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6388\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
734
Read events
734
Write events
0
Delete events
0

Modification events

No data
Executable files
45
Suspicious files
4
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1164anyukit-win.exeC:\Users\admin\AppData\Local\Temp\Amoyshare\AnyUkit\anyukit_10.8.3.exe
MD5:
SHA256:
2340anyukit_10.8.3.exeC:\Program Files\AnyUkit\AnyUkit.ilk
MD5:
SHA256:
1164anyukit-win.exeC:\Users\admin\AppData\Local\Temp\Amoyshare\AnyUkit\anyukit_10.8.3.exe.aria2binary
MD5:8463614AF8631E2CB9ADC2868A56CB94
SHA256:BBE5B3CFDA126E1B5761F7F80CD7C2F57C6D0EE7395435D53A02C5017024A3A8
2340anyukit_10.8.3.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\AnyUkit\AnyUkit.lnkbinary
MD5:D8E8DB809FC46FA9F95D11EC75953383
SHA256:312FDDC2A9CACCC71B1B25CF3145817EA7283C2AE7C59E5DC8B7A1C642BA50EB
2340anyukit_10.8.3.exeC:\Program Files\AnyUkit\D3Dcompiler_47.dllexecutable
MD5:B0AE3AA9DD1EBD60BDF51CB94834CD04
SHA256:E994847E01A6F1E4CBDC5A864616AC262F67EE4F14DB194984661A8D927AB7F4
2340anyukit_10.8.3.exeC:\Users\admin\Desktop\AnyUkit.lnkbinary
MD5:1F8B36C241E4FEB6BD5D05AF6210B483
SHA256:C74249AD7AACD54EE3B9EE4EA3022D85FF37B53ADFB6D78E3BC06C63B3F315D1
2340anyukit_10.8.3.exeC:\Program Files\AnyUkit\AnyUkit.exeexecutable
MD5:50C939A1FF1E34BBE9A75D3DBEC82B78
SHA256:336CF3737102A7EF0CE92411E94491998C476FB86E59389C396F112CFA7CFE50
2340anyukit_10.8.3.exeC:\Program Files\AnyUkit\Qt5WebEngineCore.dll
MD5:
SHA256:
2340anyukit_10.8.3.exeC:\Program Files\AnyUkit\Qt5Network.dllexecutable
MD5:3569693D5BAE82854DE1D88F86C33184
SHA256:4EF341AE9302E793878020F0740B09B0F31CB380408A697F75C69FDBD20FC7A1
2340anyukit_10.8.3.exeC:\Program Files\AnyUkit\Qt5Core.dllexecutable
MD5:817520432A42EFA345B2D97F5C24510E
SHA256:8D2FF4CE9096DDCCC4F4CD62C2E41FC854CFD1B0D6E8D296645A7F5FD4AE565A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
23
DNS requests
14
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
2.19.198.194:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1164
anyukit-win.exe
GET
200
34.212.115.64:80
http://anys.1010diy.com/download-software/setup/anyukit-win.json
unknown
1164
anyukit-win.exe
HEAD
200
104.26.8.195:80
http://www.amoyshare.info/download-software/anyukit-win.exe
unknown
756
lsass.exe
GET
200
2.16.252.233:80
http://x1.c.lencr.org/
unknown
whitelisted
4164
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4164
SIHClient.exe
GET
200
2.16.253.202:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
5496
MoUsoCoreWorker.exe
2.19.198.194:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1164
anyukit-win.exe
34.212.115.64:80
anys.1010diy.com
AMAZON-02
US
unknown
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1164
anyukit-win.exe
52.34.86.56:8086
backend.1010diy.com
AMAZON-02
US
unknown
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
1164
anyukit-win.exe
104.26.8.195:80
www.amoyshare.info
CLOUDFLARENET
US
suspicious
1164
anyukit-win.exe
104.26.8.195:443
www.amoyshare.info
CLOUDFLARENET
US
suspicious

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 2.19.198.194
  • 23.32.238.34
whitelisted
google.com
  • 172.217.23.110
whitelisted
anys.1010diy.com
  • 34.212.115.64
  • 44.236.200.183
unknown
backend.1010diy.com
  • 52.34.86.56
  • 44.229.166.19
unknown
client.wns.windows.com
  • 172.211.123.248
whitelisted
www.amoyshare.info
  • 104.26.8.195
  • 172.67.72.121
  • 104.26.9.195
unknown
x1.c.lencr.org
  • 2.16.252.233
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
www.microsoft.com
  • 2.16.253.202
whitelisted

Threats

PID
Process
Class
Message
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
Unknown Traffic
ET HUNTING Suspicious Empty Accept-Encoding Header
No debug info