| File name: | 1023e9e92d631f1f2f24c8f443b5796344fcaee6f5cc00dda49f8c52353cf815.exe |
| Full analysis: | https://app.any.run/tasks/c73183d4-a497-4f29-ad59-40ac98f7363b |
| Verdict: | Malicious activity |
| Analysis date: | October 03, 2025, 16:15:17 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections |
| MD5: | C74568F41F4D2984136439DCE91F4B38 |
| SHA1: | C139011E7ADF109DEBC481F0B9544F78E8651054 |
| SHA256: | 1023E9E92D631F1F2F24C8F443B5796344FCAEE6F5CC00DDA49F8C52353CF815 |
| SSDEEP: | 49152:4fU00mvij07m88988NtxUaq41JEzw01S2Ss5+ZNGPyofvejJGm5N4hkTfL:AU00mvjm2UO1S2Ss5uNGqC45yWzL |
| .exe | | | Win32 Executable MS Visual C++ (generic) (35.8) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (31.7) |
| .scr | | | Windows screen saver (15) |
| .dll | | | Win32 Dynamic Link Library (generic) (7.5) |
| .exe | | | Win32 Executable (generic) (5.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:04:10 17:28:39+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 761856 |
| InitializedDataSize: | 479232 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x9add5 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 356 | "C:\Users\admin\Desktop\ABDPY.exe" | C:\Users\admin\Desktop\ABDPY.exe | XFMTA.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 356 | "C:\Users\admin\Desktop\V0K61.exe" | C:\Users\admin\Desktop\V0K61.exe | 7IZ0F.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 356 | "C:\Users\admin\Desktop\23NLI.exe" | C:\Users\admin\Desktop\23NLI.exe | 799L0.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 520 | "C:\Users\admin\Desktop\KY5W0.exe" | C:\Users\admin\Desktop\KY5W0.exe | 3X143.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 520 | "C:\Users\admin\Desktop\LFY95.exe" | C:\Users\admin\Desktop\LFY95.exe | K0NSP.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 532 | "C:\Users\admin\Desktop\0S444.exe" | C:\Users\admin\Desktop\0S444.exe | 0Y9G8.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 560 | "C:\Users\admin\Desktop\R49PK.exe" | C:\Users\admin\Desktop\R49PK.exe | JMM81.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 560 | "C:\Users\admin\Desktop\1I7FH.exe" | C:\Users\admin\Desktop\1I7FH.exe | XTOY8.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 560 | "C:\Users\admin\Desktop\8VP19.exe" | C:\Users\admin\Desktop\8VP19.exe | 8EMZ9.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 560 | "C:\Users\admin\Desktop\3J76C.exe" | C:\Users\admin\Desktop\3J76C.exe | UT37A.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2000) 1023e9e92d631f1f2f24c8f443b5796344fcaee6f5cc00dda49f8c52353cf815.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2000) 1023e9e92d631f1f2f24c8f443b5796344fcaee6f5cc00dda49f8c52353cf815.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2000) 1023e9e92d631f1f2f24c8f443b5796344fcaee6f5cc00dda49f8c52353cf815.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2000) 1023e9e92d631f1f2f24c8f443b5796344fcaee6f5cc00dda49f8c52353cf815.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (7072) 10DL5.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (7072) 10DL5.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (7072) 10DL5.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (7072) 10DL5.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (6364) 68F1M.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (6364) 68F1M.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3040 | MD4AZ.exe | C:\Users\admin\Desktop\8SZ85.exe | executable | |
MD5:52E7F7716D5211C5BCE0AEC657A0311D | SHA256:5D1D540F7351F770606AE27D56502BEC4A52FF83F9ACBA9F04A32D038148D92F | |||
| 7248 | CZP65.exe | C:\Users\admin\Desktop\30186.exe | executable | |
MD5:95ACD3C95ECC4F1B2AEB21AF16E017ED | SHA256:A49EE2CB5D7F2CACDA8018AB16A33CDB68599A7B3778AA797BD8B25778733733 | |||
| 1340 | 0RW8O.exe | C:\Users\admin\Desktop\0U859.exe | executable | |
MD5:3B4982A32D8DB08BD8AF124A28492B2B | SHA256:503779FBB0E5BF6BD7B4E9937D24D7652EFD5ACE7F1ED55E321C9FF060F73957 | |||
| 6364 | 68F1M.exe | C:\Users\admin\Desktop\83092.exe | executable | |
MD5:31EE25048816036F2D0FDD3906512016 | SHA256:822AE22A6BAA61B4EEFFF3DE1252D29D54550E9A200AC2AC89385E038A2056F6 | |||
| 2884 | 0U859.exe | C:\Users\admin\Desktop\05TKT.exe | executable | |
MD5:BC58F268A2B53E034CB55D8F890DB67D | SHA256:C65FD8773F1BE5CA7CEC28B2CC46DCB2E8DAE39BD67B392104EBABD217204708 | |||
| 6364 | 9F95P.exe | C:\Users\admin\Desktop\MD4AZ.exe | executable | |
MD5:8C01C49A8E6931DE52737B2C7717898B | SHA256:7E4CEB73E5889B7399141CD48D9C95FEEBA6902C561DDC3050BBE3FB19E666B4 | |||
| 7536 | 83092.exe | C:\Users\admin\Desktop\DC4UC.exe | executable | |
MD5:3C65552BF5D922F5047958A2B2D94937 | SHA256:57AD7F33198E6337F4E38458F343B446389C6BFDF358F23C50D31001DAC1EA0A | |||
| 3124 | 0T8ES.exe | C:\Users\admin\Desktop\0N2TO.exe | executable | |
MD5:1F4C2459D9775E266135EED17BE25E18 | SHA256:4784128010E2A12CAF551B8322FA6923D3EC9A1F076AC7DABC34A53EA69FA7D5 | |||
| 4744 | 67VC3.exe | C:\Users\admin\Desktop\9SKX8.exe | executable | |
MD5:CAC8BD74BE18B0D0AB6CD2EE81AB1BD6 | SHA256:AC7DC1ED7D64EB9DA723996B24BDFF136D51A44C21887F7E8486D9496BB609C1 | |||
| 7244 | 8SZ85.exe | C:\Users\admin\Desktop\I9R07.exe | executable | |
MD5:E857A4543B64125F0C95FAEE092D72F0 | SHA256:181E58D4B6D22E7E77ABEA6B7369236513438029BAE4A418857B3C33621469A2 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 20.165.94.63:443 | https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL | US | — | — | unknown |
— | — | GET | 200 | 20.242.39.171:443 | https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping | US | — | — | unknown |
— | — | POST | 200 | 20.190.160.14:443 | https://login.live.com/RST2.srf | US | xml | 11.1 Kb | unknown |
— | — | POST | 204 | 92.123.104.65:443 | https://www.bing.com/web/xlsc.aspx?t=5&dl=1&wsbc=1 | unknown | — | — | unknown |
— | — | POST | 200 | 20.190.160.14:443 | https://login.live.com/RST2.srf | US | xml | 11.2 Kb | unknown |
— | — | POST | 200 | 20.190.159.0:443 | https://login.live.com/RST2.srf | US | — | — | unknown |
— | — | GET | 200 | 92.123.104.61:443 | https://www.bing.com/th?id=ODSWG.8229b0e5-fa8c-4e4a-af74-69717698b903&pid=dsb | unknown | image | 4.62 Kb | unknown |
— | — | POST | 200 | 20.190.159.0:443 | https://login.live.com/RST2.srf | US | xml | 11.0 Kb | unknown |
— | — | GET | 200 | 92.123.104.63:443 | https://www.bing.com/th?id=ODSWG.31bcf3d1-4df8-4c6a-9b3a-447ced8d6c39&pid=dsb | unknown | image | 4.64 Kb | unknown |
— | — | POST | 200 | 40.126.31.0:443 | https://login.live.com/RST2.srf | US | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
6016 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1260 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5948 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5224 | SearchApp.exe | 92.123.104.63:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
4460 | svchost.exe | 20.190.160.64:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3040 | backgroundTaskHost.exe | 92.123.104.63:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
3464 | svchost.exe | 172.211.123.250:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6120 | backgroundTaskHost.exe | 20.199.58.43:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
login.live.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |