File name:

0a0dcf40a73e7f7a00a488367b7b0cadc4ff3ac7818cf22a46cd3e24ff5cf6e3.exe

Full analysis: https://app.any.run/tasks/e60c2a79-5950-404f-ae8d-112ef8e9ea86
Verdict: Malicious activity
Analysis date: December 26, 2024, 01:59:38
OS: Windows 10 Professional (build: 19045, 64 bit)
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 8 sections
MD5:

38162872C36186016F483D5A94AA831B

SHA1:

8B5D04DF8B44B704DEB20AAE9AC1733C1B732803

SHA256:

0A0DCF40A73E7F7A00A488367B7B0CADC4FF3AC7818CF22A46CD3E24FF5CF6E3

SSDEEP:

98304:/6yEc1VqKNxj4JSeM49DcB1gbWhxd7Ym32/V26FCwQNAmVj7BPt+Ed/MqZjFMDp7:jjF+Me

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • 0a0dcf40a73e7f7a00a488367b7b0cadc4ff3ac7818cf22a46cd3e24ff5cf6e3.exe (PID: 6220)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Reads the computer name

      • 0a0dcf40a73e7f7a00a488367b7b0cadc4ff3ac7818cf22a46cd3e24ff5cf6e3.exe (PID: 6220)
    • The sample compiled with english language support

      • 0a0dcf40a73e7f7a00a488367b7b0cadc4ff3ac7818cf22a46cd3e24ff5cf6e3.exe (PID: 6220)
    • Checks supported languages

      • 0a0dcf40a73e7f7a00a488367b7b0cadc4ff3ac7818cf22a46cd3e24ff5cf6e3.exe (PID: 6220)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:04:03 02:55:17+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 2912768
InitializedDataSize: 3403776
UninitializedDataSize: -
EntryPoint: 0x23c968
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 8.4.1.114
ProductVersionNumber: 8.4.1.114
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Windows NT
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Trellix
FileDescription: Trellix Solidifier Service
FileVersion: 8.4.1-114
InternalName: svc.exe
LegalCopyright: Copyright 2023 Musarubra US, LLC. All Rights Reserved.
OriginalFileName: scsrvc.exe
ProductName: Trellix Solidifier
ProductVersion: 8.4.1-114
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
124
Monitored processes
1
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start 0a0dcf40a73e7f7a00a488367b7b0cadc4ff3ac7818cf22a46cd3e24ff5cf6e3.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6220"C:\Users\admin\AppData\Local\Temp\0a0dcf40a73e7f7a00a488367b7b0cadc4ff3ac7818cf22a46cd3e24ff5cf6e3.exe" C:\Users\admin\AppData\Local\Temp\0a0dcf40a73e7f7a00a488367b7b0cadc4ff3ac7818cf22a46cd3e24ff5cf6e3.exeexplorer.exe
User:
admin
Company:
Trellix
Integrity Level:
MEDIUM
Description:
Trellix Solidifier Service
Version:
8.4.1-114
Modules
Images
c:\users\admin\appdata\local\temp\0a0dcf40a73e7f7a00a488367b7b0cadc4ff3ac7818cf22a46cd3e24ff5cf6e3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
17
Read events
17
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
30
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6328
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
6328
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6936
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6936
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
192.168.100.255:137
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
2.23.209.149:443
www.bing.com
Akamai International B.V.
GB
whitelisted
1176
svchost.exe
40.126.31.73:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1076
svchost.exe
184.28.89.167:443
go.microsoft.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.120
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
google.com
  • 142.250.181.238
whitelisted
www.bing.com
  • 2.23.209.149
  • 2.23.209.182
  • 2.23.209.187
  • 2.23.209.133
whitelisted
login.live.com
  • 40.126.31.73
  • 20.190.159.73
  • 40.126.31.67
  • 20.190.159.0
  • 20.190.159.68
  • 40.126.31.69
  • 20.190.159.71
  • 40.126.31.71
whitelisted
ocsp.digicert.com
  • 192.229.221.95
unknown
go.microsoft.com
  • 184.28.89.167
whitelisted
arc.msn.com
  • 20.74.47.205
whitelisted
fd.api.iris.microsoft.com
  • 20.105.99.58
whitelisted

Threats

No threats detected
No debug info