File name:

mssecsvc.exe

Full analysis: https://app.any.run/tasks/c68a2692-ca70-49f7-9095-6dbc8512cbb5
Verdict: Malicious activity
Threats:

Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.

Analysis date: June 05, 2025, 08:55:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
wannacry
ransomware
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

EEE8DCD12E35775EACC7CAF6F9C2B4C7

SHA1:

B5992BFE525D48A0961C41E95805E54EB65145CE

SHA256:

0FD0D5EBE1E299DAAFA691813BE11F40FD96B8854E5202A19915E368D38B12C1

SSDEEP:

98304:j4ruuETKDGo+fzG4OqTYFSj8GZQmhTlD9I22dNHmJsjh87QemKifYyR2QNoJdzNr:8ZdFu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • WANNACRY has been detected (YARA)

      • mssecsvc.exe (PID: 3660)
  • SUSPICIOUS

    • Reads the Internet Settings

      • mssecsvc.exe (PID: 3344)
      • mssecsvc.exe (PID: 3152)
    • Starts another process probably with elevated privileges via RUNAS.EXE

      • runas.exe (PID: 3900)
    • Reads security settings of Internet Explorer

      • mssecsvc.exe (PID: 3152)
      • mssecsvc.exe (PID: 3344)
      • mssecsvc.exe (PID: 3660)
    • Executes as Windows Service

      • mssecsvc.exe (PID: 3660)
    • Executable content was dropped or overwritten

      • mssecsvc.exe (PID: 3344)
  • INFO

    • Reads the computer name

      • mssecsvc.exe (PID: 3152)
      • mssecsvc.exe (PID: 3344)
      • mssecsvc.exe (PID: 3660)
    • Manual execution by a user

      • explorer.exe (PID: 1564)
      • mssecsvc.exe (PID: 3152)
      • mssecsvc.exe (PID: 3344)
    • Checks supported languages

      • mssecsvc.exe (PID: 3152)
      • mssecsvc.exe (PID: 3344)
      • mssecsvc.exe (PID: 3660)
    • Checks proxy server information

      • mssecsvc.exe (PID: 3152)
      • mssecsvc.exe (PID: 3344)
      • mssecsvc.exe (PID: 3660)
    • Failed to create an executable file in Windows directory

      • mssecsvc.exe (PID: 3152)
    • Reads the machine GUID from the registry

      • mssecsvc.exe (PID: 3660)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:11:20 09:03:08+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 36864
InitializedDataSize: 3682304
UninitializedDataSize: -
EntryPoint: 0x9a16
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
6
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start runas.exe no specs explorer.exe no specs mssecsvc.exe no specs mssecsvc.exe #WANNACRY mssecsvc.exe tasksche.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1564"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3152"C:\Windows\mssecsvc.exe" C:\Windows\mssecsvc.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\windows\mssecsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
3336C:\WINDOWS\tasksche.exe /iC:\Windows\tasksche.exemssecsvc.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3222601730
Modules
Images
c:\windows\tasksche.exe
c:\windows\system32\ntdll.dll
3344"C:\Windows\mssecsvc.exe" C:\Windows\mssecsvc.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\windows\mssecsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
3660C:\Windows\mssecsvc.exe -m securityC:\Windows\mssecsvc.exe
services.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Modules
Images
c:\windows\mssecsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\nsi.dll
3900"C:\Windows\System32\runas.exe" /user:administrator C:\Windows\mssecsvc.exeC:\Windows\System32\runas.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Run As Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\runas.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
Total events
1 502
Read events
1 464
Write events
22
Delete events
16

Modification events

(PID) Process:(3152) mssecsvc.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3152) mssecsvc.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(3152) mssecsvc.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
(PID) Process:(3152) mssecsvc.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoConfigURL
Value:
(PID) Process:(3152) mssecsvc.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoDetect
Value:
(PID) Process:(3152) mssecsvc.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000060010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3152) mssecsvc.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3152) mssecsvc.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3152) mssecsvc.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3152) mssecsvc.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3344mssecsvc.exeC:\Windows\tasksche.exeexecutable
MD5:1B48BB988A50928320EFB614414EB5AF
SHA256:E014A1D3362C38258759C5B3CFB7BFAD82C12B489C85C98AC1165CECA83FFE90
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
196
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
3660
mssecsvc.exe
219.149.66.200:445
Chinanet
CN
unknown
3660
mssecsvc.exe
192.168.100.1:445
unknown
3660
mssecsvc.exe
192.168.100.2:445
whitelisted
3660
mssecsvc.exe
192.168.100.3:445
unknown
3660
mssecsvc.exe
188.146.72.132:445
T-Mobile Polska S.A.
PL
unknown
3660
mssecsvc.exe
20.87.106.97:445
MICROSOFT-CORP-MSN-AS-BLOCK
ZA
unknown
3660
mssecsvc.exe
123.30.36.201:445
VNPT Corp
VN
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.184.238
whitelisted
www.à“
unknown

Threats

No threats detected
No debug info