| File name: | 0d119a4ab7269d5a5a1881b0d27bf7fb49cc47241972a9c5c276c5136f5d7741.exe |
| Full analysis: | https://app.any.run/tasks/7532e11a-e932-4c08-8b6f-7f3f9b9d37db |
| Verdict: | Malicious activity |
| Analysis date: | October 03, 2025, 16:27:35 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections |
| MD5: | CBCF2BBFE2CD3372EAA209433FA398F0 |
| SHA1: | 317E1782AAC19800B44741111427420779C30E21 |
| SHA256: | 0D119A4AB7269D5A5A1881B0D27BF7FB49CC47241972A9C5C276C5136F5D7741 |
| SSDEEP: | 12288:EsYXHjErS5EWEc59eAC9+ICgHaDpPyyx1LWqpfvoXqARVVh6yzRu:EsYXjV71C9HJaDxyYWqpfvoXqAOyzs |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2003:11:11 14:39:16+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 10 |
| CodeSize: | 140288 |
| InitializedDataSize: | 356352 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x113b6 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 12.0.4518.1014 |
| ProductVersionNumber: | 12.0.4518.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Microsoft Corporation |
| FileDescription: | Microsoft Office Word |
| FileVersion: | 12.0.4518.1014 |
| InternalName: | WinWord |
| LegalCopyright: | © 2006 Microsoft Corporation. All rights reserved. |
| LegalTrademarks1: | Microsoft® is a registered trademark of Microsoft Corporation. |
| LegalTrademarks2: | Windows® is a registered trademark of Microsoft Corporation. |
| OriginalFileName: | WinWord.exe |
| ProductName: | 2007 Microsoft Office system |
| ProductVersion: | 12.0.4518.1014 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 8 | "C:\Users\admin\AppData\Local\Temp\EBC7.tmp" | C:\Users\admin\AppData\Local\Temp\EBC7.tmp | — | EB69.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 8 | "C:\Users\admin\AppData\Local\Temp\4FE0.tmp" | C:\Users\admin\AppData\Local\Temp\4FE0.tmp | — | 4F73.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 332 | "C:\Users\admin\AppData\Local\Temp\C9A9.tmp" | C:\Users\admin\AppData\Local\Temp\C9A9.tmp | — | C93B.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 332 | "C:\Users\admin\AppData\Local\Temp\E658.tmp" | C:\Users\admin\AppData\Local\Temp\E658.tmp | — | E5FB.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 356 | "C:\Users\admin\AppData\Local\Temp\1E9F.tmp" | C:\Users\admin\AppData\Local\Temp\1E9F.tmp | — | 1E51.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 356 | "C:\Users\admin\AppData\Local\Temp\3033.tmp" | C:\Users\admin\AppData\Local\Temp\3033.tmp | — | 2FE5.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 520 | "C:\Users\admin\AppData\Local\Temp\9D59.tmp" | C:\Users\admin\AppData\Local\Temp\9D59.tmp | — | 9D0B.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 520 | "C:\Users\admin\AppData\Local\Temp\BCD7.tmp" | C:\Users\admin\AppData\Local\Temp\BCD7.tmp | — | BC89.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 520 | "C:\Users\admin\AppData\Local\Temp\D0CD.tmp" | C:\Users\admin\AppData\Local\Temp\D0CD.tmp | — | D06F.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 520 | "C:\Users\admin\AppData\Local\Temp\CCC.tmp" | C:\Users\admin\AppData\Local\Temp\CCC.tmp | — | C5F.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3944 | 1702.tmp | C:\Users\admin\AppData\Local\Temp\1760.tmp | — | |
MD5:C8505961EC6949247CA0412945E17907 | SHA256:7F526E81BCD7A3136913D9648CA8044D6A0E4AFE9E7E366A3258A1012C08CC11 | |||
| 6080 | 1760.tmp | C:\Users\admin\AppData\Local\Temp\17DD.tmp | — | |
MD5:59B3F9DCCB7921A97E3F64255C3334F7 | SHA256:DDE54FF1C5DA7783BACDF38372313FD58639B26A65BED122D91F3122F2ADAAEC | |||
| 5508 | 1993.tmp | C:\Users\admin\AppData\Local\Temp\1A00.tmp | — | |
MD5:A393CEED985E99CD38B443A6B1572BE6 | SHA256:12DEF517C8D138DAA12358CE03BDB81AE51A2BEFA79BBEA7DF86219DECFD64B6 | |||
| 7116 | 1695.tmp | C:\Users\admin\AppData\Local\Temp\1702.tmp | — | |
MD5:586350E0946F6A2888E0D9576DA3D2C4 | SHA256:1BE478961C65C62DF3BF5441255987015B6239BDC3B804E9DF39B3255CE88C8E | |||
| 3404 | 18A8.tmp | C:\Users\admin\AppData\Local\Temp\1925.tmp | — | |
MD5:DFD4C55CA672BA79118168BFCED8B600 | SHA256:3FE570D756BC8B842B51B62F131D7C7F2A682C193A21B6A5E7FEA994C62D123E | |||
| 4212 | 183B.tmp | C:\Users\admin\AppData\Local\Temp\18A8.tmp | — | |
MD5:36F63CE4DE83D0F138AC7FF846410E44 | SHA256:FD25550A8C49B3476E78875D669A203A4C8AFA0DE398CC9D4AE0D7A20ED2F6D8 | |||
| 592 | 17DD.tmp | C:\Users\admin\AppData\Local\Temp\183B.tmp | — | |
MD5:8B929350AC80B8670DC14E31BE580B8B | SHA256:0D8EA206A002E82B00ABF19C49F214EE963940E865F9768D9BE9989BD273D3FE | |||
| 5888 | 1637.tmp | C:\Users\admin\AppData\Local\Temp\1695.tmp | — | |
MD5:8210C97CA77BC0DBA0336FE4604380B0 | SHA256:2DF6DB9DE89BF39B9F2ED2CBE2508419FB80E3674ED1C754C56E38BA6D2B4746 | |||
| 7604 | 15CA.tmp | C:\Users\admin\AppData\Local\Temp\1637.tmp | — | |
MD5:D6C6F67DDA239E61CF4BAA507C22960D | SHA256:F79CB0E6EE3BE986219210CC851DB679197992309A4A4F788CD1CAE2915142CA | |||
| 2996 | 0d119a4ab7269d5a5a1881b0d27bf7fb49cc47241972a9c5c276c5136f5d7741.exe | C:\Users\admin\AppData\Local\Temp\15CA.tmp | — | |
MD5:9EBCF1675E33EA72CD39B5BF74497374 | SHA256:300990DB9577292BEA415F7203B5BF13C02B82142CD0C713A0E6B17C5CFAAEA0 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | POST | 500 | 4.154.185.43:443 | https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail | US | xml | 512 b | unknown |
— | — | POST | 500 | 4.154.209.85:443 | https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail | US | xml | 512 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
8112 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6016 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5948 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3420 | slui.exe | 4.154.209.85:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
— | — | 4.154.209.85:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |