File name:

266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe

Full analysis: https://app.any.run/tasks/364f6089-4c2d-4fb5-a893-4750c8a415b5
Verdict: Malicious activity
Threats:

GravityRAT is a sophisticated spyware and remote access trojan that has been actively targeting organizations and government entities since 2016. It uses innovative anti-analysis techniques and made an evolution from a Windows-only threat to a cross-platform espionage tool capable of compromising Windows, Android, and macOS systems.

Analysis date: October 03, 2025, 16:39:26
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
api-base64
golang
wmi-base64
gravityrat
rat
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows, 5 sections
MD5:

DCFCD8980EAD292011A41DA546419C34

SHA1:

B561CED6E11AD668701870005FDAC61C09F71476

SHA256:

266E072A7B68655E68FFCBC7E870B103E78C8768192DB08599647A57081E5C62

SSDEEP:

98304:6AbDg6Mruq2aOhsFn9i1VO0B1St3Q9eGx28ivLwP+1GDeGx28ivLwP+1GZeGx28y:NP1StZ3tTfP8Zq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • GRAVITYRAT has been detected (YARA)

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
  • SUSPICIOUS

    • There is functionality for taking screenshot (YARA)

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
    • Process creates executable files without a name

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
    • Executable content was dropped or overwritten

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
  • INFO

    • Checks supported languages

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
    • Reads the machine GUID from the registry

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
    • Reads the software policy settings

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
      • slui.exe (PID: 4732)
    • Reads the computer name

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
    • Found Base64 encoded reference to WMI classes (YARA)

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
    • Application based on Golang

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
    • Detects GO elliptic curve encryption (YARA)

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
    • Potential library load (Base64 Encoded 'LoadLibrary')

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
    • Failed to create an executable file in Windows directory

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
    • Checks proxy server information

      • slui.exe (PID: 4732)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.3)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 0000:00:00 00:00:00
ImageFileCharacteristics: No relocs, Executable, Large address aware, No debug
PEType: PE32+
LinkerVersion: 3
CodeSize: 2279424
InitializedDataSize: 210432
UninitializedDataSize: -
EntryPoint: 0x58b20
OSVersion: 4
ImageVersion: 1
SubsystemVersion: 4
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
159
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
2380\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4732C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5256"C:\Users\admin\Desktop\266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe" C:\Users\admin\Desktop\266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
2
Modules
Images
c:\users\admin\desktop\266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
6 863
Read events
6 863
Write events
0
Delete events
0

Modification events

No data
Executable files
105
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
5256266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.da-dk.dllexecutable
MD5:2D11B4F6E99B1940AB1BBE8449532E8B
SHA256:84C89B212313C88287FCCB616EDE6808958E985FE1B73F79AC294330514451D7
5256266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvSubsystems64_msix.dllexecutable
MD5:57CA1CA44A7401AFA57A77B025592C19
SHA256:AADD7A747E5ED65AAB8B585D234FD721FE7C586821E157FF71BFED86218765CC
5256266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppVClient.manexecutable
MD5:4BE526DA99486B3AF0F28F2A82392504
SHA256:FCF6BBFA70C1C33550F2E2A78F0B870742C3148944C55D24318D3B3A82DE3087
5256266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exeexecutable
MD5:B98341BF089B3E659D9F76306585FE9B
SHA256:4AD6BA23A3DD8DAC1769FF1BE674479395B46EB66243699E1E7B2A727DD5A798
5256266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppVClientIsv.manexecutable
MD5:B5F844147CD25109B4E7F9BCAE57C56B
SHA256:F71CB2E3C958758514F97AE230F0DCEB5C4E9D33C1E2002DF7CCE24D4BBFB270
5256266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dllexecutable
MD5:34AFDE50B0B8A95C75F3E61AB574E9CA
SHA256:D242154B8102D9D33EDE2A8EEF901334C41C8CD5B68DA70B1157E0C6F3FBC7FF
5256266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppVScripting.dllexecutable
MD5:C2E9159CB1AC1BA465B018DA20FC23A8
SHA256:4277447CB945D6EA621A2B21B8FC7B16CE211595506E6A1A5F50F8DD945EF81D
5256266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32_msix.dllexecutable
MD5:CAD225CA2E67858223867DFB8A1E00BC
SHA256:DC0614AB30B67BAC9C730CF07FE3CD77BD898530FA6EC48F88190B83C171EE4E
5256266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems64.dllexecutable
MD5:8619D605F5738AD1B01153A4F3CC028F
SHA256:BF0735DE101675DFFBA35B3AA5C6933701EE19640D337D6471E8E3BC57B62792
5256266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems64_arm64x.dllexecutable
MD5:C66F56A60049F28A38ACE750C9D75C95
SHA256:9AA14FD223A50FDC8910D5419C5346E8CCDE0F5C8871A95EE1E6CE21AD47329C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
14
DNS requests
8
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
POST
500
4.154.209.85:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
xml
512 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
7416
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
6016
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.23.227.208:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
4
System
192.168.100.255:138
whitelisted
5256
266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe
198.51.100.1:443
ent34ndx3cz8k.x.pipedream.net
whitelisted
5948
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7716
slui.exe
4.154.209.85:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4732
slui.exe
4.154.209.85:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
www.bing.com
  • 2.23.227.208
  • 2.23.227.215
whitelisted
google.com
  • 142.250.186.110
whitelisted
ent34ndx3cz8k.x.pipedream.net
  • 198.51.100.1
unknown
UeFnewV.b17da333ec194ec4b767.d.requestbin.net
unknown
UhsFBKuVsp.b17da333ec194ec4b767.d.requestbin.net
unknown
activation-v2.sls.microsoft.com
  • 4.154.209.85
whitelisted

Threats

PID
Process
Class
Message
2428
svchost.exe
Misc activity
ET INFO DNS Query for Webhook/HTTP Request Inspection Service (x .pipedream .net)
5256
266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe
Misc activity
ET INFO Webhook/HTTP Request Inspection Service Domain (x .pipedream .net in TLS SNI)
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
2428
svchost.exe
Misc activity
ET INFO DNSBin Demo (requestbin .net) - Data Exfil
Misc activity
ET INFO Go-http-client User-Agent Observed Outbound
Misc activity
ET USER_AGENTS Go HTTP Client User-Agent
Misc activity
ET INFO Request for EXE via GO HTTP Client
No debug info