| File name: | 1023e9e92d631f1f2f24c8f443b5796344fcaee6f5cc00dda49f8c52353cf815.exe |
| Full analysis: | https://app.any.run/tasks/c73183d4-a497-4f29-ad59-40ac98f7363b |
| Verdict: | Malicious activity |
| Analysis date: | October 03, 2025, 16:15:17 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections |
| MD5: | C74568F41F4D2984136439DCE91F4B38 |
| SHA1: | C139011E7ADF109DEBC481F0B9544F78E8651054 |
| SHA256: | 1023E9E92D631F1F2F24C8F443B5796344FCAEE6F5CC00DDA49F8C52353CF815 |
| SSDEEP: | 49152:4fU00mvij07m88988NtxUaq41JEzw01S2Ss5+ZNGPyofvejJGm5N4hkTfL:AU00mvjm2UO1S2Ss5uNGqC45yWzL |
| .exe | | | Win32 Executable MS Visual C++ (generic) (35.8) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (31.7) |
| .scr | | | Windows screen saver (15) |
| .dll | | | Win32 Dynamic Link Library (generic) (7.5) |
| .exe | | | Win32 Executable (generic) (5.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:04:10 17:28:39+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 761856 |
| InitializedDataSize: | 479232 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x9add5 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 356 | "C:\Users\admin\Desktop\ABDPY.exe" | C:\Users\admin\Desktop\ABDPY.exe | XFMTA.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 356 | "C:\Users\admin\Desktop\V0K61.exe" | C:\Users\admin\Desktop\V0K61.exe | 7IZ0F.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 356 | "C:\Users\admin\Desktop\23NLI.exe" | C:\Users\admin\Desktop\23NLI.exe | 799L0.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 520 | "C:\Users\admin\Desktop\KY5W0.exe" | C:\Users\admin\Desktop\KY5W0.exe | 3X143.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 520 | "C:\Users\admin\Desktop\LFY95.exe" | C:\Users\admin\Desktop\LFY95.exe | K0NSP.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 532 | "C:\Users\admin\Desktop\0S444.exe" | C:\Users\admin\Desktop\0S444.exe | 0Y9G8.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 560 | "C:\Users\admin\Desktop\R49PK.exe" | C:\Users\admin\Desktop\R49PK.exe | JMM81.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 560 | "C:\Users\admin\Desktop\1I7FH.exe" | C:\Users\admin\Desktop\1I7FH.exe | XTOY8.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 560 | "C:\Users\admin\Desktop\8VP19.exe" | C:\Users\admin\Desktop\8VP19.exe | 8EMZ9.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 560 | "C:\Users\admin\Desktop\3J76C.exe" | C:\Users\admin\Desktop\3J76C.exe | UT37A.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2000) 1023e9e92d631f1f2f24c8f443b5796344fcaee6f5cc00dda49f8c52353cf815.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2000) 1023e9e92d631f1f2f24c8f443b5796344fcaee6f5cc00dda49f8c52353cf815.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2000) 1023e9e92d631f1f2f24c8f443b5796344fcaee6f5cc00dda49f8c52353cf815.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2000) 1023e9e92d631f1f2f24c8f443b5796344fcaee6f5cc00dda49f8c52353cf815.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (7072) 10DL5.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (7072) 10DL5.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (7072) 10DL5.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (7072) 10DL5.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (6364) 68F1M.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (6364) 68F1M.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2000 | 1023e9e92d631f1f2f24c8f443b5796344fcaee6f5cc00dda49f8c52353cf815.exe | C:\Users\admin\Desktop\T5VI3.exe | executable | |
MD5:7563BE45E7675CA1C34F960F1446C3D9 | SHA256:B1D3AD50ABE32762374195BFDBD19FEF7EC5B92625DF50A7ECE1083E429E711D | |||
| 5424 | DC4UC.exe | C:\Users\admin\Desktop\CZP65.exe | executable | |
MD5:B1E8AF81318224AF16C3E7A257644947 | SHA256:707FCA423F929E29E331CFF101F998C8212788E5B7E277DCFF59031958D997EB | |||
| 6364 | 68F1M.exe | C:\Users\admin\Desktop\83092.exe | executable | |
MD5:31EE25048816036F2D0FDD3906512016 | SHA256:822AE22A6BAA61B4EEFFF3DE1252D29D54550E9A200AC2AC89385E038A2056F6 | |||
| 7248 | CZP65.exe | C:\Users\admin\Desktop\30186.exe | executable | |
MD5:95ACD3C95ECC4F1B2AEB21AF16E017ED | SHA256:A49EE2CB5D7F2CACDA8018AB16A33CDB68599A7B3778AA797BD8B25778733733 | |||
| 3124 | 0T8ES.exe | C:\Users\admin\Desktop\0N2TO.exe | executable | |
MD5:1F4C2459D9775E266135EED17BE25E18 | SHA256:4784128010E2A12CAF551B8322FA6923D3EC9A1F076AC7DABC34A53EA69FA7D5 | |||
| 7536 | 83092.exe | C:\Users\admin\Desktop\DC4UC.exe | executable | |
MD5:3C65552BF5D922F5047958A2B2D94937 | SHA256:57AD7F33198E6337F4E38458F343B446389C6BFDF358F23C50D31001DAC1EA0A | |||
| 4744 | 67VC3.exe | C:\Users\admin\Desktop\9SKX8.exe | executable | |
MD5:CAC8BD74BE18B0D0AB6CD2EE81AB1BD6 | SHA256:AC7DC1ED7D64EB9DA723996B24BDFF136D51A44C21887F7E8486D9496BB609C1 | |||
| 7244 | 8SZ85.exe | C:\Users\admin\Desktop\I9R07.exe | executable | |
MD5:E857A4543B64125F0C95FAEE092D72F0 | SHA256:181E58D4B6D22E7E77ABEA6B7369236513438029BAE4A418857B3C33621469A2 | |||
| 5792 | 9SKX8.exe | C:\Users\admin\Desktop\0T8ES.exe | executable | |
MD5:52918F57326E9DE4A4C4F873A6F2E629 | SHA256:83BCD13078E6C9F957D975565C1460E86882DB7AAFBF16A0E9AE6F5FE76A22AA | |||
| 5708 | T5VI3.exe | C:\Users\admin\Desktop\10DL5.exe | executable | |
MD5:1545B5F792D60E4E5B18C4E0B771B343 | SHA256:023CFEA99A3FECDC76C2FB6B6E217F0BEDFFCABFA0AAFAE9F179975314790B9E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | POST | 204 | 92.123.104.65:443 | https://www.bing.com/web/xlsc.aspx?t=5&dl=1&wsbc=1 | unknown | — | — | unknown |
— | — | GET | 200 | 92.123.104.58:443 | https://www.bing.com/DSB/search?dsbmr=1&format=dsbjson&client=windowsminiserp&dsbschemaversion=1.1&dsbminiserp=1&q=q&cc=US&setlang=en-us&clientDateTime=10%2F3%2F2025%2C%204%3A15%3A34%20PM | unknown | binary | 64.2 Kb | unknown |
— | — | POST | 200 | 20.190.159.0:443 | https://login.live.com/RST2.srf | US | xml | 11.0 Kb | unknown |
— | — | POST | 200 | 20.190.160.14:443 | https://login.live.com/RST2.srf | US | xml | 11.2 Kb | unknown |
— | — | POST | 200 | 20.190.160.14:443 | https://login.live.com/RST2.srf | US | xml | 11.1 Kb | unknown |
— | — | POST | 200 | 20.190.159.0:443 | https://login.live.com/RST2.srf | US | — | — | unknown |
— | — | GET | 200 | 92.123.104.61:443 | https://www.bing.com/th?id=ODSWG.8229b0e5-fa8c-4e4a-af74-69717698b903&pid=dsb | unknown | image | 4.62 Kb | unknown |
— | — | GET | 304 | 20.165.94.63:443 | https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL | US | — | — | unknown |
— | — | GET | 200 | 92.123.104.56:443 | https://www.bing.com/client/config?cc=US&setlang=en-US | unknown | binary | 2.15 Kb | unknown |
— | — | GET | 200 | 20.165.94.63:443 | https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL | US | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
6016 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1260 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5948 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5224 | SearchApp.exe | 92.123.104.63:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
4460 | svchost.exe | 20.190.160.64:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3040 | backgroundTaskHost.exe | 92.123.104.63:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
3464 | svchost.exe | 172.211.123.250:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6120 | backgroundTaskHost.exe | 20.199.58.43:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
login.live.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |