| File name: | 5cd4014907f6065bd3d12c575dda5bd1.exe |
| Full analysis: | https://app.any.run/tasks/c426992f-0e9a-4c41-8724-aabbfb3cf879 |
| Verdict: | Malicious activity |
| Analysis date: | March 25, 2025, 05:34:11 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows, 8 sections |
| MD5: | 5CD4014907F6065BD3D12C575DDA5BD1 |
| SHA1: | ABDEDE27BD0D532C4E7644AA1F58A011B016F981 |
| SHA256: | 16C1C34C4380CB4BB8DBD9425B20BA540148FBD08A7319FFA5CCFD72E2996736 |
| SSDEEP: | 98304:/hpSaRmPx+2XovC6o9zlyQn5PxoVnkwGLt+708n8hsJ9Ub59GUmKaWlFYpcgHEfh:R0SezB |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2023:04:17 05:36:36+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 9 |
| CodeSize: | 47616 |
| InitializedDataSize: | 1640448 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x30ec35 |
| OSVersion: | 5.2 |
| ImageVersion: | - |
| SubsystemVersion: | 5.2 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 12.0.22621.1 |
| ProductVersionNumber: | 12.0.22621.1 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Microsoft Corporation |
| FileDescription: | Microsoft Windows Media Player Legacy Setup Utility |
| FileVersion: | 12.0.22621.1 (WinBuild.160101.0800) |
| InternalName: | unregmp2.exe |
| LegalCopyright: | © Microsoft Corporation. All rights reserved. |
| OriginalFileName: | unregmp2.exe |
| ProductName: | Microsoft® Windows® Operating System |
| ProductVersion: | 12.0.22621.1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3268 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) | |||||||||||||||
| 3300 | "C:\Users\admin\AppData\Local\Temp\5cd4014907f6065bd3d12c575dda5bd1.exe" | C:\Users\admin\AppData\Local\Temp\5cd4014907f6065bd3d12c575dda5bd1.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Windows Media Player Legacy Setup Utility Exit code: 0 Version: 12.0.22621.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5024 | "C:\WINDOWS\system32\wuauclt.exe" /detectnow | C:\Windows\System32\wuauclt.exe | — | 5cd4014907f6065bd3d12c575dda5bd1.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Update Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5024 | "C:\WINDOWS\system32\wusa.exe" C:\WINDOWS\system32\kb7022484.msu | C:\Windows\System32\wusa.exe | 5cd4014907f6065bd3d12c575dda5bd1.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Update Standalone Installer Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6724 | powershell Add-MpPreference -ExclusionPath C:\ | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | mmc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7148 | \??\C:\WINDOWS\system32\mmc.exe | C:\Windows\System32\mmc.exe | wusa.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Management Console Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (7148) mmc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\S28Zyz0_7148 |
| Operation: | write | Name: | ErrorControl |
Value: 1 | |||
| (PID) Process: | (7148) mmc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\S28Zyz0_7148 |
| Operation: | write | Name: | Type |
Value: 1 | |||
| (PID) Process: | (7148) mmc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\S28Zyz0_7148 |
| Operation: | write | Name: | Start |
Value: 3 | |||
| (PID) Process: | (7148) mmc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\S28Zyz0_7148 |
| Operation: | write | Name: | ImagePath |
Value: \??\C:\WINDOWS\Temp\Q6d5xHhp_7148.sys | |||
| (PID) Process: | (7148) mmc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\S28Zyz0_7148 |
| Operation: | write | Name: | KB001 |
Value: 2F9C9397736423B0B076DC3A0A63268625AFAAE643CA10B792E89639C712663F2EBBC8261252B16FF8E53A3D7D4D8666955D8C4B0DD28EA619DE59829A142AB515AEF58B79694C6575F8EE5EB97E00C6C23EF4F9B9821CCA599E07063F95A1A4888B7302D5535EFC34156268854546A4B060CBD68317F8384EED55893FD2575B5799A05097DFC34A55BE3C57B0BA8703BD44259437052686956A395A8B89EBF6B23C638F8018CA7492612C4E33F04AFB4A1A45AA174F011BD21C8123ECCAC307CBF6B47ED8ED49CC1BBC35E413CD8D03954A1C9B37B6CCF145DEF5060325327E906F8A8D9E00EA1EE2E929776DC288DD85FA62FA5A9BC38D0F698305E391BA9EE6078B80842865B47E19686E489961D4C0283BDC8890DAD68604388FB71D853529376952179010840789B41FA71B7E138BB8A556C26AC7C3666A37B0DA83EF446473B2F8CE21BA31F760EBD9C44988A8249FF79430907F33905BAECB4C5BA5DEC40813EE2A3AAAF1359DF831727A9AC20CAE849A124A7A6E7518D2CA8FE3F880F38BADA80CE3B153E3034CD30382702BFEC46D9A1C99D2287644DC4310DDC64504F2E69C572C493F7D4C95FA1400ABD8FB0D7A3EB11BFAF1091D1723965BD2F6A807A4700CFA39D8B08ABC0028A5D5BA6CEA4E0C59C0F55E5309E9C12B33871FDA550BB56F8EB282FE899870EDF673FED6B3E67BE4E3829F4F1B39A806EC0164 | |||
| (PID) Process: | (7148) mmc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\S28Zyz0_7148 |
| Operation: | write | Name: | KB002 |
Value: E0F7849D35531BA82ED859C49E15927BB65A7DC4FF268B5743C4E57100EF7930 | |||
| (PID) Process: | (7148) mmc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\S28Zyz0_7148 |
| Operation: | write | Name: | KB003 |
Value: 2EF7F9BEE40F9841786EB361FF8499676CE255DCF12E9E97DD971FBDA9BA8791564AE737BD3BED5F64015EA815EEE154C45A200369F2ECF7C086005D23E25B9892CED95DBE7A14F25307843C80BF8F0F0DE081A09AFBE461B1357B030B3F86CF4265F560D0BC6AABC2CBBED5B6BB26C120354E3A06C92113C72CBEAEB27A8C6D66D9062E15BBD376AC03D1D5CBC8F3748A0BADF7A7F96E947E985584EF17D601810DFFD267B7866C89B8EDF5955A0F9CDAACF2234BB1639463FC3C6561B2AF9D8B6E96FA4D255FAD216727067669901EEC6D0022DDF3DEFCF6CC276E46139EB7FB6CA242C2E4114007B398612D7E8A63C9740DF44BBB14A3DF9CE3DAB2720E6D561895DA5EC1B305FFF72C14770E4F13BE29429D1D10B31036885C21B2608F842717A28BC2BC0E8353C39D7F755E6292D663BB2D2B704FDFA1B5761892C8CD646989EC6F5304C567DC07D622736A1589497FAB7FBEF15FD7014DA24A5FDD07508BE66518E20208EBF8E283C683B9E38F09398F87BDB533FA091C1AC798C53EB7FBC43967EC772BE89803E3DB165FE09A80D81CC2F6D7B2F28FC516E6688BC571B250792A7E54DFE25E43913E3E138FE440D3667EFCB1DB498C4FF9F8C2A673681FC30D09F7567E5ECE6ED7346102DDFC32AC3D2E5C0D7DC88BBD9F1F644BD30ED3776F09E21E90DE53F832503ACF9B5CDF3FAD7D56572D55E3F175E6C1A7788B | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6724 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive | binary | |
MD5:7CF26F5B0658C0291D64FC04E68F645C | SHA256:1F1D41F5A3FD6ED00D0B32080CD10E19AB2DF2B6D7AB5818EBD8E764DFA2F468 | |||
| 6724 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_ycz4ixbl.5ww.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 6724 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_elkqnusr.oks.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 7148 | mmc.exe | C:\Windows\Temp\Q6d5xHhp_7148.sys | executable | |
MD5:136B2B4CC69999006C7C3B7A1A3A9144 | SHA256:C37BF1ABC0662B4F18607E2D7B75F5C600E45EA5604DAFFA54674E2AEBDCE9F0 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.53.40.176:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.53.40.176:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
7148 | mmc.exe | HEAD | 206 | 104.168.28.10:80 | http://104.168.28.10/001/01/d1 | unknown | — | — | malicious |
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7148 | mmc.exe | GET | 206 | 104.168.28.10:80 | http://104.168.28.10/001/01/d1 | unknown | — | — | malicious |
7148 | mmc.exe | GET | 206 | 104.168.28.10:80 | http://104.168.28.10/001/01/d1 | unknown | — | — | malicious |
7148 | mmc.exe | GET | 206 | 104.168.28.10:80 | http://104.168.28.10/001/01/d1 | unknown | — | — | malicious |
7148 | mmc.exe | GET | 206 | 104.168.28.10:80 | http://104.168.28.10/001/01/d1 | unknown | — | — | malicious |
7148 | mmc.exe | GET | 206 | 104.168.28.10:80 | http://104.168.28.10/001/01/d1 | unknown | — | — | malicious |
7148 | mmc.exe | GET | 206 | 104.168.28.10:80 | http://104.168.28.10/001/01/d1 | unknown | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 23.53.40.176:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3216 | svchost.exe | 40.115.3.253:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 20.190.160.4:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
7148 | mmc.exe | 104.168.28.10:80 | — | AS-COLOCROSSING | US | malicious |
6544 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
— | — | 40.115.3.253:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2112 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2104 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |