| File name: | 0a39254199807ba9588d2d58b58f2552a074bf170cf3a72b6e3f933ef490e1e1.exe |
| Full analysis: | https://app.any.run/tasks/9bbdab6d-85aa-4d08-a78c-886240458ef5 |
| Verdict: | Malicious activity |
| Analysis date: | November 18, 2025, 05:44:27 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 5 sections |
| MD5: | A39F37AABB72F32767F62A7E63FF7CED |
| SHA1: | B6FFDB822F413DD232679B240F4D55F1F0F1AFBB |
| SHA256: | 0A39254199807BA9588D2D58B58F2552A074BF170CF3A72B6E3F933EF490E1E1 |
| SSDEEP: | 24576:MUKstWIP3Ymyne8H4wSeWgTTxZsasAY5S8zoPBNoEFZ9bp8vey6CwpFZ9bp8veyg:MUKstWIP3Ymyne8HJSeWgTTLsDAY48zI |
| .exe | | | Win32 Executable MS Visual C++ (generic) (27.3) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (24.2) |
| .exe | | | UPX compressed Win32 Executable (23.7) |
| .scr | | | Windows screen saver (11.4) |
| .dll | | | Win32 Dynamic Link Library (generic) (5.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 0000:00:00 00:00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 450560 |
| InitializedDataSize: | 150016 |
| UninitializedDataSize: | 802816 |
| EntryPoint: | 0x132be0 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 144 | "C:\Users\admin\Desktop\Z80J0.exe" | C:\Users\admin\Desktop\Z80J0.exe | 06ALA.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 144 | "C:\Users\admin\Desktop\3SVI9.exe" | C:\Users\admin\Desktop\3SVI9.exe | 81K0Y.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 148 | "C:\Users\admin\Desktop\6215V.exe" | C:\Users\admin\Desktop\6215V.exe | KUP89.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 148 | "C:\Users\admin\Desktop\T9I5K.exe" | C:\Users\admin\Desktop\T9I5K.exe | 4J791.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 148 | "C:\Users\admin\Desktop\B2UZW.exe" | C:\Users\admin\Desktop\B2UZW.exe | E8PYK.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 148 | "C:\Users\admin\Desktop\75VTF.exe" | C:\Users\admin\Desktop\75VTF.exe | — | 795BA.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 204 | "C:\Users\admin\Desktop\TN8LC.exe" | C:\Users\admin\Desktop\TN8LC.exe | R24E8.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 204 | "C:\Users\admin\Desktop\Y5W3P.exe" | C:\Users\admin\Desktop\Y5W3P.exe | — | 9X1H4.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 224 | "C:\Users\admin\Desktop\C9S47.exe" | C:\Users\admin\Desktop\C9S47.exe | CQA1Q.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 224 | "C:\Users\admin\Desktop\O0E74.exe" | C:\Users\admin\Desktop\O0E74.exe | 48250.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (7464) C2K84.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (7464) C2K84.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (7464) C2K84.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (7464) C2K84.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (7568) 70X68.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (7568) 70X68.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (7568) 70X68.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (7568) 70X68.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (7624) 05733.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (7624) 05733.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7516 | 5U51M.exe | C:\Users\admin\Desktop\70X68.exe | executable | |
MD5:A56DAAC324E9F4BAC23540CE08CAEA8A | SHA256:56A911C4795005263966A99AF1050DFF49A1C0DA2CCCA997D611A6457C6EEC00 | |||
| 7696 | 4Z123.exe | C:\Users\admin\Desktop\T7IA7.exe | executable | |
MD5:8F87B82C9EEF68AE2816AEA97E4DC056 | SHA256:2798CA013502F4CDE5AC1AED3F4A4EF8B4D27B86DF1691AD97604246CF9743D1 | |||
| 7464 | C2K84.exe | C:\Users\admin\Desktop\5U51M.exe | executable | |
MD5:6481B2A988BD09F59183D5125B21117E | SHA256:0E5E78CE5ADE477CDE0D44C1F61698ABE476F31427F40D90D12A29D4AA9D2586 | |||
| 6188 | R6NVH.exe | C:\Users\admin\Desktop\I8TM2.exe | executable | |
MD5:095A686FD36E681FB2C8B06D22A5EE46 | SHA256:BBCB03A943ADC8C30C9C0BC026ECF9746DE2802ED8D3DA4BA9BC53FE278C1E02 | |||
| 6456 | Z421C.exe | C:\Users\admin\Desktop\922UV.exe | executable | |
MD5:81B9EBA2558C8838BED55F0128A3061B | SHA256:B93FD56A28303355306D81EEACBF5C7C439BD138E24E8F50DE859BE87EE19FBD | |||
| 7624 | 05733.exe | C:\Users\admin\Desktop\4Z123.exe | executable | |
MD5:5B1A8022FAB6781D322125445C72E9D5 | SHA256:2FADD77B11619E0E8EA23F9C710A4F759E13C2874C55267CE85CD3B17984CF95 | |||
| 7772 | T7IA7.exe | C:\Users\admin\Desktop\GN5J0.exe | executable | |
MD5:AB29D966F2F793673632540ACC6E93AE | SHA256:DE5B79FC17E75BCBA8D52A2B680D3D18095B716590FDD5985BD0F74AE2EED15F | |||
| 8040 | O6GA6.exe | C:\Users\admin\Desktop\Z421C.exe | executable | |
MD5:B0E72A63F8D61F439C9017BD34E9168C | SHA256:DA0C7A7462A54A739F37CEB671BF9FAB4875DE2017AB0CC0888CC79E9B4D9563 | |||
| 7884 | GN5J0.exe | C:\Users\admin\Desktop\7R4D4.exe | executable | |
MD5:65746F1911E122A8A0E802CD338C1C19 | SHA256:252392FA000BC54FF2532E856ECAC63105FB841A43EAAAF666503E5C81E3FF6B | |||
| 2392 | 922UV.exe | C:\Users\admin\Desktop\R6NVH.exe | executable | |
MD5:947C07DF4BB4A18619DD3F9D2EB4F752 | SHA256:ABF4DCEE64FC64C9E1E95B973FB903850BDD427B4DB8E7B49F60273AD0BA17A8 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5656 | svchost.exe | GET | 200 | 95.101.35.35:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
7068 | RUXIMICS.exe | GET | 200 | 95.101.35.35:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5596 | MoUsoCoreWorker.exe | GET | 200 | 95.101.35.35:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | POST | 500 | 4.154.209.85:443 | https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail | unknown | xml | 512 b | unknown |
— | — | POST | 500 | 4.154.209.85:443 | https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail | unknown | xml | 512 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
5656 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5596 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
7068 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 2.16.204.135:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5656 | svchost.exe | 95.101.35.35:80 | crl.microsoft.com | Orange | NL | whitelisted |
5596 | MoUsoCoreWorker.exe | 95.101.35.35:80 | crl.microsoft.com | Orange | NL | whitelisted |
7068 | RUXIMICS.exe | 95.101.35.35:80 | crl.microsoft.com | Orange | NL | whitelisted |
5596 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |