File name:

133573fec4d57c6d7cd662d283d8593c75fac511874605020f0c83ff4e0a95e3

Full analysis: https://app.any.run/tasks/1734760b-b09f-4f63-9309-214bbe5d0409
Verdict: Malicious activity
Analysis date: December 13, 2024, 06:21:55
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

8F196DAE26F820859CD7364D48AEE5E1

SHA1:

4B0C91EAD868A76D84E6AD2A03BF8FEEDFFA4E08

SHA256:

133573FEC4D57C6D7CD662D283D8593C75FAC511874605020F0C83FF4E0A95E3

SSDEEP:

6144:vChvmvDvrEye5cLq2Ao6kpz5QEMzaaayI49FNjjjjbRhTYRdNCWclHIE7a7/NeZ/:vCqvrUwbAWoYtdeZam

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Starts NET.EXE for service management

      • 133573fec4d57c6d7cd662d283d8593c75fac511874605020f0c83ff4e0a95e3.exe (PID: 3364)
      • net.exe (PID: 5628)
      • net.exe (PID: 6004)
  • SUSPICIOUS

    • Uses REG/REGEDIT.EXE to modify registry

      • 133573fec4d57c6d7cd662d283d8593c75fac511874605020f0c83ff4e0a95e3.exe (PID: 3364)
    • Uses TASKKILL.EXE to kill process

      • 133573fec4d57c6d7cd662d283d8593c75fac511874605020f0c83ff4e0a95e3.exe (PID: 3364)
    • Application launched itself

      • rundll32.exe (PID: 3296)
    • Reads Microsoft Outlook installation path

      • rundll32.exe (PID: 3296)
      • rundll32.exe (PID: 6432)
    • Write to the desktop.ini file (may be used to cloak folders)

      • rundll32.exe (PID: 6432)
  • INFO

    • Creates files or folders in the user directory

      • 133573fec4d57c6d7cd662d283d8593c75fac511874605020f0c83ff4e0a95e3.exe (PID: 3364)
      • rundll32.exe (PID: 6432)
    • Checks supported languages

      • 133573fec4d57c6d7cd662d283d8593c75fac511874605020f0c83ff4e0a95e3.exe (PID: 3364)
    • Reads security settings of Internet Explorer

      • rundll32.exe (PID: 3296)
      • rundll32.exe (PID: 6432)
    • Checks proxy server information

      • rundll32.exe (PID: 3296)
      • rundll32.exe (PID: 6432)
    • Reads the computer name

      • 133573fec4d57c6d7cd662d283d8593c75fac511874605020f0c83ff4e0a95e3.exe (PID: 3364)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:12:01 11:59:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 278528
InitializedDataSize: 344064
UninitializedDataSize: -
EntryPoint: 0x30692
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
164
Monitored processes
42
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
444taskkill /im Fondue.exe /fC:\Windows\SysWOW64\taskkill.exe133573fec4d57c6d7cd662d283d8593c75fac511874605020f0c83ff4e0a95e3.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
624taskkill /im TslGame_BE.exe /fC:\Windows\SysWOW64\taskkill.exe133573fec4d57c6d7cd662d283d8593c75fac511874605020f0c83ff4e0a95e3.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
640taskkill /im wscript.exe /fC:\Windows\SysWOW64\taskkill.exe133573fec4d57c6d7cd662d283d8593c75fac511874605020f0c83ff4e0a95e3.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
836\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1156taskkill /im iigw_server.exe /fC:\Windows\SysWOW64\taskkill.exe133573fec4d57c6d7cd662d283d8593c75fac511874605020f0c83ff4e0a95e3.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1804\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3080\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3296Rundll32 InetCpl.cpl,ClearMyTracksByProcess 255C:\Windows\SysWOW64\rundll32.exe133573fec4d57c6d7cd662d283d8593c75fac511874605020f0c83ff4e0a95e3.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
3364"C:\Users\admin\Desktop\133573fec4d57c6d7cd662d283d8593c75fac511874605020f0c83ff4e0a95e3.exe" C:\Users\admin\Desktop\133573fec4d57c6d7cd662d283d8593c75fac511874605020f0c83ff4e0a95e3.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\133573fec4d57c6d7cd662d283d8593c75fac511874605020f0c83ff4e0a95e3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
3560"C:\Users\admin\Desktop\133573fec4d57c6d7cd662d283d8593c75fac511874605020f0c83ff4e0a95e3.exe" C:\Users\admin\Desktop\133573fec4d57c6d7cd662d283d8593c75fac511874605020f0c83ff4e0a95e3.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\133573fec4d57c6d7cd662d283d8593c75fac511874605020f0c83ff4e0a95e3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
3 017
Read events
2 986
Write events
27
Delete events
4

Modification events

(PID) Process:(3296) rundll32.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3296) rundll32.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3296) rundll32.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3296) rundll32.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\WindowsSearch
Operation:writeName:Version
Value:
WS not running
(PID) Process:(3296) rundll32.exeKey:HKEY_USERS\S-1-5-19\SOFTWARE\Microsoft\Cryptography\TPM\Telemetry
Operation:writeName:TraceTimeLast
Value:
4DC21C54274DDB01
(PID) Process:(3296) rundll32.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage\Total
Operation:delete keyName:(default)
Value:
(PID) Process:(3296) rundll32.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\LowRegistry\DOMStorage
Operation:delete keyName:(default)
Value:
(PID) Process:(3296) rundll32.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\DomStorageState
Operation:writeName:EdpCleanupState
Value:
0
(PID) Process:(3296) rundll32.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\TypedURLs
Operation:delete keyName:(default)
Value:
(PID) Process:(3296) rundll32.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\BrowserEmulation
Operation:writeName:IECompatVersionHigh
Value:
0
Executable files
1
Suspicious files
3
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3364133573fec4d57c6d7cd662d283d8593c75fac511874605020f0c83ff4e0a95e3.exeC:\Users\admin\AppData\Local\TslGame\Saved\Config\WindowsNoEditor\GameUserSettings.iniini
MD5:3C3FBAFBA6BCDD1E4A2EA7537A32048A
SHA256:285C292385F2B3C0A0C1C6E0069D62CBDA5560877CE447570E39180BA735E0DE
6432rundll32.exeC:\Users\admin\AppData\Local\Packages\windows_ie_ac_001\AC\INetHistory\desktop.initext
MD5:FFFA3520C04320177050AA7C77C362E1
SHA256:68CFDEB4843FD56030848AEAB87B86582F429080CAEA55D7A1F31B7A9E2E155F
6432rundll32.exeC:\Users\admin\AppData\Local\Packages\windows_ie_ac_001\AC\INetCache\MSIMGSIZ.DATbinary
MD5:0392ADA071EB68355BED625D8F9695F3
SHA256:B1313DD95EAF63F33F86F72F09E2ECD700D11159A8693210C37470FCB84038F7
6432rundll32.exeC:\Users\admin\AppData\Local\Packages\windows_ie_ac_001\AC\INetCache\SmartScreenCache.datbinary
MD5:1C7D3E30536E10B1EA45E1621B9E51C1
SHA256:76910FBC1BCFA7296DD7E9CC5AD08904F9AD3FAA71BABBFA44F7EE4CBAB13B2D
3296rundll32.exeC:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\Low\SmartScreenCache.datbinary
MD5:872FCA914B123250A14FD186E393438B
SHA256:20D2844CB3AB160F009E43526BC8DB41BFF018B0794DE0113F47DFAC00C62343
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
20
DNS requests
7
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4308
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
973 b
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
1.01 Kb
whitelisted
4308
svchost.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
1.01 Kb
whitelisted
6032
RUXIMICS.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
1.01 Kb
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
973 b
whitelisted
6032
RUXIMICS.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
973 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6032
RUXIMICS.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
192.168.100.255:137
whitelisted
4308
svchost.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4308
svchost.exe
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
6032
RUXIMICS.exe
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4308
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.142
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.106
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
self.events.data.microsoft.com
  • 20.42.65.91
whitelisted

Threats

No threats detected
No debug info