File name:

ProctorU.exe

Full analysis: https://app.any.run/tasks/192fd051-2219-44ae-a860-91b6091357c0
Verdict: Malicious activity
Analysis date: January 07, 2025, 10:10:43
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
websocket
arch-exec
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows, 2 sections
MD5:

5A9F942C76426C28347C50A947487EFA

SHA1:

6E2517005F216E794AF4155B2C5FEE502DBF67B3

SHA256:

18EFF5CF327C36749E064DE33573607194329B738009FB187491B7AC3B7DA858

SSDEEP:

98304:3EXlfSkb7bayNvkmo/IEucvAcKYVDkA5qhrtabv+tav8fu5QgWmd4/oZqbEsz57N:PK

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ProctorU.exe (PID: 7072)
    • Starts SC.EXE for service management

      • ProctorU.exe (PID: 7072)
    • Creates a new Windows service

      • sc.exe (PID: 6524)
    • Executes as Windows Service

      • syslog.exe (PID: 6420)
  • INFO

    • Checks supported languages

      • ProctorU.exe (PID: 7072)
      • ProctorU.exe (PID: 3724)
    • Reads the computer name

      • ProctorU.exe (PID: 3724)
      • ProctorU.exe (PID: 7072)
    • Manual execution by a user

      • ProctorU.exe (PID: 3724)
      • ProctorU.exe (PID: 628)
    • Reads the machine GUID from the registry

      • ProctorU.exe (PID: 7072)
      • ProctorU.exe (PID: 3724)
    • Creates files or folders in the user directory

      • ProctorU.exe (PID: 7072)
    • The sample compiled with english language support

      • ProctorU.exe (PID: 7072)
      • ProctorU.exe (PID: 3724)
    • Sends debugging messages

      • syslog.exe (PID: 6420)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2048:01:10 11:46:01+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 48
CodeSize: 12732416
InitializedDataSize: 171008
UninitializedDataSize: -
EntryPoint: 0x0000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 12.32.11.2
ProductVersionNumber: 12.32.11.2
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: By accessing or using the Services, you agree to our Privacy Policy
CompanyName: Meazure Learning’s
FileDescription: ProctorU
FileVersion: 12.32.11.2
InternalName: ProctorU.exe
LegalCopyright: California Consumer Privacy Act of 2019 as amended by the California Privacy Rights Act of 2020 (“CCPA”)
LegalTrademarks: ProctorU Inc.
OriginalFileName: ProctorU.exe
ProductName: ProctorU Test Taker
ProductVersion: 12.32.11.2
AssemblyVersion: 4.53.3.5
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
128
Monitored processes
7
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start proctoru.exe proctoru.exe no specs proctoru.exe sc.exe no specs conhost.exe no specs syslog.exe proctoru.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
628"C:\Users\admin\Desktop\ProctorU.exe" C:\Users\admin\Desktop\ProctorU.exeexplorer.exe
User:
admin
Company:
Meazure Learning’s
Integrity Level:
MEDIUM
Description:
ProctorU
Exit code:
3221226540
Version:
12.32.11.2
Modules
Images
c:\users\admin\desktop\proctoru.exe
c:\windows\system32\ntdll.dll
3724"C:\Users\admin\Desktop\ProctorU.exe" C:\Users\admin\Desktop\ProctorU.exe
explorer.exe
User:
admin
Company:
Meazure Learning’s
Integrity Level:
HIGH
Description:
ProctorU
Version:
12.32.11.2
Modules
Images
c:\users\admin\desktop\proctoru.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6348\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6420C:\Users\admin\AppData\Local\packages\syslog.exe NOgggIFDi0Dh+0qGXqPuUJlc8/tamFK5+kyOD6ivVth30t8m4jee2iz2Cg==C:\Users\admin\AppData\Local\Packages\syslog.exe
services.exe
User:
SYSTEM
Company:
SysLink Corporation
Integrity Level:
SYSTEM
Description:
SysLink Manager
Version:
10.0.19041.4124 (WinBuild.162101.0800)
Modules
Images
c:\users\admin\appdata\local\packages\syslog.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ws2_32.dll
6524"sc.exe" create LogMgmt binPath= "C:\Users\admin\AppData\Local\packages\syslog.exe NOgggIFDi0Dh+0qGXqPuUJlc8/tamFK5+kyOD6ivVth30t8m4jee2iz2Cg==" displayName= "LogMgmt" start= autoC:\Windows\System32\sc.exeProctorU.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
6904"C:\Users\admin\Desktop\ProctorU.exe" C:\Users\admin\Desktop\ProctorU.exeexplorer.exe
User:
admin
Company:
Meazure Learning’s
Integrity Level:
MEDIUM
Description:
ProctorU
Exit code:
3221226540
Version:
12.32.11.2
Modules
Images
c:\users\admin\desktop\proctoru.exe
c:\windows\system32\ntdll.dll
7072"C:\Users\admin\Desktop\ProctorU.exe" C:\Users\admin\Desktop\ProctorU.exe
explorer.exe
User:
admin
Company:
Meazure Learning’s
Integrity Level:
HIGH
Description:
ProctorU
Version:
12.32.11.2
Modules
Images
c:\users\admin\desktop\proctoru.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
323
Read events
323
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
2
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
7072ProctorU.exeC:\Users\admin\AppData\Local\Packages\favicon06.png
MD5:
SHA256:
3724ProctorU.exeC:\Users\admin\AppData\Local\Packages\beads.zipcompressed
MD5:37FE0B1B08B92EFDFFEAE85073C77D96
SHA256:7347A8E1616E3FC12C09ED7681860144CBE84884DD025A519CBE55E47DB35EAD
7072ProctorU.exeC:\Users\admin\AppData\Local\Packages\syslog.exeexecutable
MD5:8B3CE44688FECEF58DE23267314CBD65
SHA256:53C4A8AF658FA4D8BECFEFEE0FD2A815035EC3D1194E365FC2749B7E83B7A17D
7072ProctorU.exeC:\Users\admin\AppData\Local\Packages\beads.zipcompressed
MD5:37FE0B1B08B92EFDFFEAE85073C77D96
SHA256:7347A8E1616E3FC12C09ED7681860144CBE84884DD025A519CBE55E47DB35EAD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
38
DNS requests
22
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.230.103:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
6420
syslog.exe
GET
101
54.38.216.83:443
http://register.akamaized.ca:443/ws
unknown
unknown
3732
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3732
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6596
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
GET
200
184.30.230.103:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
1520
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
184.30.230.103:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
184.30.230.103:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
5064
SearchApp.exe
2.23.227.215:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.9
whitelisted
www.microsoft.com
  • 184.30.230.103
  • 184.30.21.171
whitelisted
google.com
  • 216.58.206.46
whitelisted
www.bing.com
  • 2.23.227.215
  • 2.23.227.202
  • 2.23.227.221
  • 2.23.227.208
  • 104.126.37.177
  • 104.126.37.160
  • 104.126.37.179
  • 104.126.37.163
  • 104.126.37.155
  • 104.126.37.178
  • 104.126.37.176
  • 104.126.37.171
  • 104.126.37.162
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.2
  • 20.190.159.0
  • 20.190.159.75
  • 20.190.159.73
  • 20.190.159.23
  • 20.190.159.4
  • 40.126.31.71
  • 20.190.159.64
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
arc.msn.com
  • 20.199.58.43
whitelisted
fd.api.iris.microsoft.com
  • 20.199.58.43
whitelisted

Threats

PID
Process
Class
Message
Misc activity
ET INFO Cloudflare DNS Over HTTPS Certificate Inbound
6420
syslog.exe
Not Suspicious Traffic
INFO [ANY.RUN] Websocket Upgrade Request
Process
Message
syslog.exe
try_run_service
syslog.exe
windows_service: service_main started