File name:

266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe

Full analysis: https://app.any.run/tasks/364f6089-4c2d-4fb5-a893-4750c8a415b5
Verdict: Malicious activity
Threats:

GravityRAT is a sophisticated spyware and remote access trojan that has been actively targeting organizations and government entities since 2016. It uses innovative anti-analysis techniques and made an evolution from a Windows-only threat to a cross-platform espionage tool capable of compromising Windows, Android, and macOS systems.

Analysis date: October 03, 2025, 16:39:26
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
api-base64
golang
wmi-base64
gravityrat
rat
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows, 5 sections
MD5:

DCFCD8980EAD292011A41DA546419C34

SHA1:

B561CED6E11AD668701870005FDAC61C09F71476

SHA256:

266E072A7B68655E68FFCBC7E870B103E78C8768192DB08599647A57081E5C62

SSDEEP:

98304:6AbDg6Mruq2aOhsFn9i1VO0B1St3Q9eGx28ivLwP+1GDeGx28ivLwP+1GZeGx28y:NP1StZ3tTfP8Zq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • GRAVITYRAT has been detected (YARA)

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
  • SUSPICIOUS

    • There is functionality for taking screenshot (YARA)

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
    • Process creates executable files without a name

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
    • Executable content was dropped or overwritten

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
  • INFO

    • Reads the computer name

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
    • Checks supported languages

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
    • Reads the machine GUID from the registry

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
    • Reads the software policy settings

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
      • slui.exe (PID: 4732)
    • Detects GO elliptic curve encryption (YARA)

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
    • Application based on Golang

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
    • Found Base64 encoded reference to WMI classes (YARA)

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
    • Potential library load (Base64 Encoded 'LoadLibrary')

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
    • Failed to create an executable file in Windows directory

      • 266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe (PID: 5256)
    • Checks proxy server information

      • slui.exe (PID: 4732)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.3)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 0000:00:00 00:00:00
ImageFileCharacteristics: No relocs, Executable, Large address aware, No debug
PEType: PE32+
LinkerVersion: 3
CodeSize: 2279424
InitializedDataSize: 210432
UninitializedDataSize: -
EntryPoint: 0x58b20
OSVersion: 4
ImageVersion: 1
SubsystemVersion: 4
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
159
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
2380\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4732C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5256"C:\Users\admin\Desktop\266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe" C:\Users\admin\Desktop\266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
2
Modules
Images
c:\users\admin\desktop\266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
6 863
Read events
6 863
Write events
0
Delete events
0

Modification events

No data
Executable files
105
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
5256266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvSubsystems64_msix.dllexecutable
MD5:57CA1CA44A7401AFA57A77B025592C19
SHA256:AADD7A747E5ED65AAB8B585D234FD721FE7C586821E157FF71BFED86218765CC
5256266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.cs-cz.dllexecutable
MD5:00B135A7B51A1D7CDC8E6FFDE2A80CDA
SHA256:63E28739CD16A0002FAC982FBFDB0B4174A509DC0BBBE54C035E707B072690D4
5256266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.en-us.dllexecutable
MD5:A5AA0F94AFB09A465F5A5E74A34FBD60
SHA256:B95161B6219E5E49BE1431CE91AC955B9AE6C33F7ACF9CFA474A711A835640A2
5256266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppVClientIsv.manexecutable
MD5:B5F844147CD25109B4E7F9BCAE57C56B
SHA256:F71CB2E3C958758514F97AE230F0DCEB5C4E9D33C1E2002DF7CCE24D4BBFB270
5256266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exeexecutable
MD5:B98341BF089B3E659D9F76306585FE9B
SHA256:4AD6BA23A3DD8DAC1769FF1BE674479395B46EB66243699E1E7B2A727DD5A798
5256266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppVScripting.dllexecutable
MD5:C2E9159CB1AC1BA465B018DA20FC23A8
SHA256:4277447CB945D6EA621A2B21B8FC7B16CE211595506E6A1A5F50F8DD945EF81D
5256266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems64_arm64x.dllexecutable
MD5:C66F56A60049F28A38ACE750C9D75C95
SHA256:9AA14FD223A50FDC8910D5419C5346E8CCDE0F5C8871A95EE1E6CE21AD47329C
5256266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.bg-bg.dllexecutable
MD5:7B8C8015B117CE087920B3B4DFD63952
SHA256:06E0D6AA0A2E3B41526CC032AE406618D1B72EF48395080C5B195C616E5F3EC2
5256266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32_msix.dllexecutable
MD5:CAD225CA2E67858223867DFB8A1E00BC
SHA256:DC0614AB30B67BAC9C730CF07FE3CD77BD898530FA6EC48F88190B83C171EE4E
5256266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.ar-sa.dllexecutable
MD5:47E2A221F8CF2FFB294E585EAAA7BE21
SHA256:C7176EDB0B34CEA3668081E2E7A8EE48BAC4645E2FD786A5E1F1C2BDAED24052
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
14
DNS requests
8
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
POST
500
4.154.209.85:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
xml
512 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
7416
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
6016
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.23.227.208:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
4
System
192.168.100.255:138
whitelisted
5256
266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe
198.51.100.1:443
ent34ndx3cz8k.x.pipedream.net
whitelisted
5948
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7716
slui.exe
4.154.209.85:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4732
slui.exe
4.154.209.85:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
www.bing.com
  • 2.23.227.208
  • 2.23.227.215
whitelisted
google.com
  • 142.250.186.110
whitelisted
ent34ndx3cz8k.x.pipedream.net
  • 198.51.100.1
unknown
UeFnewV.b17da333ec194ec4b767.d.requestbin.net
unknown
UhsFBKuVsp.b17da333ec194ec4b767.d.requestbin.net
unknown
activation-v2.sls.microsoft.com
  • 4.154.209.85
whitelisted

Threats

PID
Process
Class
Message
2428
svchost.exe
Misc activity
ET INFO DNS Query for Webhook/HTTP Request Inspection Service (x .pipedream .net)
5256
266e072a7b68655e68ffcbc7e870b103e78c8768192db08599647a57081e5c62.exe
Misc activity
ET INFO Webhook/HTTP Request Inspection Service Domain (x .pipedream .net in TLS SNI)
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
2428
svchost.exe
Misc activity
ET INFO DNSBin Demo (requestbin .net) - Data Exfil
Misc activity
ET INFO Go-http-client User-Agent Observed Outbound
Misc activity
ET USER_AGENTS Go HTTP Client User-Agent
Misc activity
ET INFO Request for EXE via GO HTTP Client
No debug info