| File name: | 1023e9e92d631f1f2f24c8f443b5796344fcaee6f5cc00dda49f8c52353cf815.exe |
| Full analysis: | https://app.any.run/tasks/c73183d4-a497-4f29-ad59-40ac98f7363b |
| Verdict: | Malicious activity |
| Analysis date: | October 03, 2025, 16:15:17 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections |
| MD5: | C74568F41F4D2984136439DCE91F4B38 |
| SHA1: | C139011E7ADF109DEBC481F0B9544F78E8651054 |
| SHA256: | 1023E9E92D631F1F2F24C8F443B5796344FCAEE6F5CC00DDA49F8C52353CF815 |
| SSDEEP: | 49152:4fU00mvij07m88988NtxUaq41JEzw01S2Ss5+ZNGPyofvejJGm5N4hkTfL:AU00mvjm2UO1S2Ss5uNGqC45yWzL |
| .exe | | | Win32 Executable MS Visual C++ (generic) (35.8) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (31.7) |
| .scr | | | Windows screen saver (15) |
| .dll | | | Win32 Dynamic Link Library (generic) (7.5) |
| .exe | | | Win32 Executable (generic) (5.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:04:10 17:28:39+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 761856 |
| InitializedDataSize: | 479232 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x9add5 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 356 | "C:\Users\admin\Desktop\ABDPY.exe" | C:\Users\admin\Desktop\ABDPY.exe | XFMTA.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 356 | "C:\Users\admin\Desktop\V0K61.exe" | C:\Users\admin\Desktop\V0K61.exe | 7IZ0F.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 356 | "C:\Users\admin\Desktop\23NLI.exe" | C:\Users\admin\Desktop\23NLI.exe | 799L0.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 520 | "C:\Users\admin\Desktop\KY5W0.exe" | C:\Users\admin\Desktop\KY5W0.exe | 3X143.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 520 | "C:\Users\admin\Desktop\LFY95.exe" | C:\Users\admin\Desktop\LFY95.exe | K0NSP.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 532 | "C:\Users\admin\Desktop\0S444.exe" | C:\Users\admin\Desktop\0S444.exe | 0Y9G8.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 560 | "C:\Users\admin\Desktop\R49PK.exe" | C:\Users\admin\Desktop\R49PK.exe | JMM81.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 560 | "C:\Users\admin\Desktop\1I7FH.exe" | C:\Users\admin\Desktop\1I7FH.exe | XTOY8.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 560 | "C:\Users\admin\Desktop\8VP19.exe" | C:\Users\admin\Desktop\8VP19.exe | 8EMZ9.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 560 | "C:\Users\admin\Desktop\3J76C.exe" | C:\Users\admin\Desktop\3J76C.exe | UT37A.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2000) 1023e9e92d631f1f2f24c8f443b5796344fcaee6f5cc00dda49f8c52353cf815.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2000) 1023e9e92d631f1f2f24c8f443b5796344fcaee6f5cc00dda49f8c52353cf815.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2000) 1023e9e92d631f1f2f24c8f443b5796344fcaee6f5cc00dda49f8c52353cf815.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2000) 1023e9e92d631f1f2f24c8f443b5796344fcaee6f5cc00dda49f8c52353cf815.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (7072) 10DL5.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (7072) 10DL5.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (7072) 10DL5.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (7072) 10DL5.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (6364) 68F1M.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (6364) 68F1M.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7072 | 10DL5.exe | C:\Users\admin\Desktop\68F1M.exe | executable | |
MD5:27E5F1917DB2006AE9955D6EFD3D25A6 | SHA256:AB07925B482AB541AA9F216FFDAED212B1B766466528DC170056A8178AB45EDE | |||
| 6364 | 68F1M.exe | C:\Users\admin\Desktop\83092.exe | executable | |
MD5:31EE25048816036F2D0FDD3906512016 | SHA256:822AE22A6BAA61B4EEFFF3DE1252D29D54550E9A200AC2AC89385E038A2056F6 | |||
| 2000 | 1023e9e92d631f1f2f24c8f443b5796344fcaee6f5cc00dda49f8c52353cf815.exe | C:\Users\admin\Desktop\T5VI3.exe | executable | |
MD5:7563BE45E7675CA1C34F960F1446C3D9 | SHA256:B1D3AD50ABE32762374195BFDBD19FEF7EC5B92625DF50A7ECE1083E429E711D | |||
| 5708 | T5VI3.exe | C:\Users\admin\Desktop\10DL5.exe | executable | |
MD5:1545B5F792D60E4E5B18C4E0B771B343 | SHA256:023CFEA99A3FECDC76C2FB6B6E217F0BEDFFCABFA0AAFAE9F179975314790B9E | |||
| 7248 | CZP65.exe | C:\Users\admin\Desktop\30186.exe | executable | |
MD5:95ACD3C95ECC4F1B2AEB21AF16E017ED | SHA256:A49EE2CB5D7F2CACDA8018AB16A33CDB68599A7B3778AA797BD8B25778733733 | |||
| 5424 | DC4UC.exe | C:\Users\admin\Desktop\CZP65.exe | executable | |
MD5:B1E8AF81318224AF16C3E7A257644947 | SHA256:707FCA423F929E29E331CFF101F998C8212788E5B7E277DCFF59031958D997EB | |||
| 7400 | 30186.exe | C:\Users\admin\Desktop\5T6XL.exe | executable | |
MD5:A8D873D99E86E1C6CA35BF54E920DAB0 | SHA256:52FE40DD4C5F87D9771AD564B2B8A17C90079B9A2D378D503CDF2F4E011FCF72 | |||
| 7536 | 83092.exe | C:\Users\admin\Desktop\DC4UC.exe | executable | |
MD5:3C65552BF5D922F5047958A2B2D94937 | SHA256:57AD7F33198E6337F4E38458F343B446389C6BFDF358F23C50D31001DAC1EA0A | |||
| 3240 | 05TKT.exe | C:\Users\admin\Desktop\9F95P.exe | executable | |
MD5:B9FA4E6A729A461C4169DB95EE2C7584 | SHA256:FC663AE7196F758B50A460D11DE9716CD53E6193E4DFB0C67554BCBB92A442A1 | |||
| 6364 | 9F95P.exe | C:\Users\admin\Desktop\MD4AZ.exe | executable | |
MD5:8C01C49A8E6931DE52737B2C7717898B | SHA256:7E4CEB73E5889B7399141CD48D9C95FEEBA6902C561DDC3050BBE3FB19E666B4 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 92.123.104.58:443 | https://www.bing.com/DSB/search?dsbmr=1&format=dsbjson&client=windowsminiserp&dsbschemaversion=1.1&dsbminiserp=1&q=q&cc=US&setlang=en-us&clientDateTime=10%2F3%2F2025%2C%204%3A15%3A34%20PM | unknown | binary | 64.2 Kb | unknown |
— | — | POST | 200 | 20.190.160.14:443 | https://login.live.com/RST2.srf | US | xml | 11.1 Kb | unknown |
— | — | POST | 204 | 92.123.104.65:443 | https://www.bing.com/web/xlsc.aspx?t=5&dl=1&wsbc=1 | unknown | — | — | unknown |
— | — | POST | 200 | 20.190.160.14:443 | https://login.live.com/RST2.srf | US | xml | 11.2 Kb | unknown |
— | — | GET | 200 | 92.123.104.61:443 | https://www.bing.com/th?id=ODSWG.8229b0e5-fa8c-4e4a-af74-69717698b903&pid=dsb | unknown | image | 4.62 Kb | unknown |
— | — | GET | 200 | 92.123.104.63:443 | https://www.bing.com/th?id=ODSWG.31bcf3d1-4df8-4c6a-9b3a-447ced8d6c39&pid=dsb | unknown | image | 4.64 Kb | unknown |
— | — | POST | 200 | 20.190.159.0:443 | https://login.live.com/RST2.srf | US | xml | 11.0 Kb | unknown |
— | — | POST | 200 | 40.126.31.0:443 | https://login.live.com/RST2.srf | US | — | — | unknown |
— | — | POST | 200 | 20.190.159.0:443 | https://login.live.com/RST2.srf | US | — | — | unknown |
— | — | POST | 200 | 20.190.159.130:443 | https://login.live.com/RST2.srf | US | xml | 11.3 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
6016 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1260 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5948 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5224 | SearchApp.exe | 92.123.104.63:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
4460 | svchost.exe | 20.190.160.64:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3040 | backgroundTaskHost.exe | 92.123.104.63:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
3464 | svchost.exe | 172.211.123.250:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6120 | backgroundTaskHost.exe | 20.199.58.43:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
login.live.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |