File name:

_2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe

Full analysis: https://app.any.run/tasks/88198fcd-31f0-4efa-abea-8064bcbd4de6
Verdict: Malicious activity
Threats:

Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks.

Analysis date: May 23, 2026, 14:13:19
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
stealer
stealc
loader
delphi
inno
installer
upx
auto-reg
amadey
botnet
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 5 sections
MD5:

ACF5499BC65F05513C3530D32C991D3E

SHA1:

AA42CC22BAB169F4295930471F5B8097B69BB4AE

SHA256:

2841AAB00EE6F00213E594DC562D03B982E6D8570A6DE2A0797F3A147665F4CA

SSDEEP:

768:qF0Q6kXxmV+KFxGE9KDyFSiD2RBaMhTxnfC:q56kBi+CxGE9JFfg5C

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was injected by another process

      • RuntimeBroker.exe (PID: 6548)
      • RuntimeBroker.exe (PID: 7308)
      • sihost.exe (PID: 4412)
      • explorer.exe (PID: 4696)
      • RuntimeBroker.exe (PID: 5728)
      • RuntimeBroker.exe (PID: 5232)
    • Runs injected code in another process

      • _2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe (PID: 5384)
      • SPTPXMVF.exe (PID: 7204)
    • Changes the login/logoff helper path in the registry

      • _2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe (PID: 5384)
    • STEALC has been detected

      • notepad.exe (PID: 7672)
      • MWSPBURA.exe (PID: 5220)
    • Changes the autorun value in the registry

      • tdlsjrps.exe (PID: 5264)
      • SPTPXMVF.exe (PID: 7204)
    • AMADEY has been detected (SURICATA)

      • ohggf.exe (PID: 4564)
    • STEALC has been detected (SURICATA)

      • ohggf.exe (PID: 4564)
      • MWSPBURA.exe (PID: 5220)
      • notepad.exe (PID: 7672)
    • Stealers network behavior

      • notepad.exe (PID: 7672)
      • MWSPBURA.exe (PID: 5220)
  • SUSPICIOUS

    • Reads the date of Windows installation

      • _2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe (PID: 5384)
      • tdlsjrps.exe (PID: 5264)
      • ohggf.exe (PID: 4564)
    • Executable content was dropped or overwritten

      • _2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe (PID: 5384)
      • 1n0x3fke.exe (PID: 3560)
      • 1n0x3fke.tmp (PID: 1176)
      • 1n0x3fke.exe (PID: 6140)
      • 1n0x3fke.tmp (PID: 7928)
      • FnHotkeyUtility.exe (PID: 6104)
      • tdlsjrps.exe (PID: 5264)
      • ohggf.exe (PID: 4564)
      • SPTPXMVF.exe (PID: 7204)
      • KYKGBIQW.exe (PID: 7388)
      • KYKGBIQW.tmp (PID: 2428)
    • The process creates files with name similar to system file names

      • _2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe (PID: 5384)
    • Reads the Windows owner or organization settings

      • 1n0x3fke.tmp (PID: 1176)
      • 1n0x3fke.tmp (PID: 7928)
      • KYKGBIQW.tmp (PID: 2428)
    • The process drops C-runtime libraries

      • 1n0x3fke.tmp (PID: 7928)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 3136)
    • The executable file from the user directory is run by the CMD process

      • crypted_06x05x2026_x64.exe (PID: 7708)
    • Start notepad (likely ransomware note)

      • crypted_06x05x2026_x64.exe (PID: 7708)
    • The process executes via Task Scheduler

      • FnHotkeyUtility.exe (PID: 5404)
    • Starts itself from another location

      • tdlsjrps.exe (PID: 5264)
  • INFO

    • Reads security settings of Internet Explorer

      • _2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe (PID: 5384)
      • 1n0x3fke.tmp (PID: 1176)
      • notepad.exe (PID: 7672)
      • ohggf.exe (PID: 4564)
      • MWSPBURA.exe (PID: 5220)
      • KYKGBIQW.tmp (PID: 2428)
      • tdlsjrps.exe (PID: 5264)
    • Create files in a temporary directory

      • _2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe (PID: 5384)
      • 1n0x3fke.exe (PID: 3560)
      • 1n0x3fke.exe (PID: 6140)
      • 1n0x3fke.tmp (PID: 1176)
      • 1n0x3fke.tmp (PID: 7928)
      • ohggf.exe (PID: 4564)
      • SPTPXMVF.exe (PID: 7204)
      • KYKGBIQW.exe (PID: 7388)
      • KYKGBIQW.tmp (PID: 2428)
    • Reads the computer name

      • _2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe (PID: 5384)
      • 1n0x3fke.tmp (PID: 1176)
      • 1n0x3fke.tmp (PID: 7928)
      • FnHotkeyUtility.exe (PID: 6104)
      • tdlsjrps.exe (PID: 5264)
      • SPTPXMVF.exe (PID: 7204)
      • ohggf.exe (PID: 4564)
      • KYKGBIQW.tmp (PID: 2428)
      • MWSPBURA.exe (PID: 5220)
      • FnHotkeyUtility.exe (PID: 5404)
      • FnHotkeyUtility.exe (PID: 7304)
    • Creates files or folders in the user directory

      • _2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe (PID: 5384)
      • SPTPXMVF.exe (PID: 7204)
    • The sample compiled with english language support

      • _2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe (PID: 5384)
      • 1n0x3fke.tmp (PID: 7928)
      • ohggf.exe (PID: 4564)
    • Checks supported languages

      • _2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe (PID: 5384)
      • 1n0x3fke.exe (PID: 6140)
      • 1n0x3fke.tmp (PID: 7928)
      • 1n0x3fke.tmp (PID: 1176)
      • FnHotkeyUtility.exe (PID: 6104)
      • crypted_06x05x2026_x64.exe (PID: 7708)
      • tdlsjrps.exe (PID: 5264)
      • ohggf.exe (PID: 4564)
      • SPTPXMVF.exe (PID: 7204)
      • WindowsStore.Update.exe (PID: 4624)
      • KYKGBIQW.exe (PID: 7388)
      • PKWKCCMW.exe (PID: 4932)
      • KYKGBIQW.tmp (PID: 2428)
      • 1n0x3fke.exe (PID: 3560)
      • MWSPBURA.exe (PID: 5220)
      • FnHotkeyUtility.exe (PID: 5404)
      • lf9da0hm.exe (PID: 7668)
      • FnHotkeyUtility.exe (PID: 7304)
      • ohggf.exe (PID: 4304)
    • Process checks computer location settings

      • _2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe (PID: 5384)
      • 1n0x3fke.tmp (PID: 1176)
      • ohggf.exe (PID: 4564)
      • KYKGBIQW.tmp (PID: 2428)
      • tdlsjrps.exe (PID: 5264)
    • Detects InnoSetup installer (YARA)

      • 1n0x3fke.tmp (PID: 1176)
      • 1n0x3fke.exe (PID: 3560)
      • KYKGBIQW.exe (PID: 7388)
      • KYKGBIQW.tmp (PID: 2428)
    • Compiled with Borland Delphi (YARA)

      • 1n0x3fke.exe (PID: 3560)
      • 1n0x3fke.tmp (PID: 1176)
      • KYKGBIQW.exe (PID: 7388)
      • KYKGBIQW.tmp (PID: 2428)
    • Password parameter in command-line

      • 1n0x3fke.tmp (PID: 1176)
      • 1n0x3fke.exe (PID: 6140)
    • The sample compiled with chinese language support

      • 1n0x3fke.tmp (PID: 7928)
    • Reads CPU info

      • FnHotkeyUtility.exe (PID: 6104)
    • UPX packer has been detected

      • FnHotkeyUtility.exe (PID: 6104)
    • Launching a file from a Registry key

      • tdlsjrps.exe (PID: 5264)
      • SPTPXMVF.exe (PID: 7204)
    • Reads the machine GUID from the registry

      • ohggf.exe (PID: 4564)
      • tdlsjrps.exe (PID: 5264)
    • Manual execution by a user

      • ohggf.exe (PID: 4304)
      • WindowsStore.Update.exe (PID: 4624)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2026:05:23 11:52:52+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.5
CodeSize: 19456
InitializedDataSize: 20992
UninitializedDataSize: -
EntryPoint: 0x23d4
OSVersion: 6
ImageVersion: 4
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 7.9.2140.5
ProductVersionNumber: 7.9.2140.5
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Phoenix Technologies
FileDescription: Node.js Event Loop Handler
FileVersion: 7.9.2140.5
InternalName: V8Runtime
LegalCopyright: 2023 Phoenix Technologies. All rights reserved.
OriginalFileName: tclsh86t.exe
ProductName: Node.js Event Loop Handler
ProductVersion: 7.9.2140.5
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
158
Monitored processes
31
Malicious processes
8
Suspicious processes
9

Behavior graph

Click at the process to see the details
start _2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe slui.exe 1n0x3fke.exe 1n0x3fke.tmp 1n0x3fke.exe 1n0x3fke.tmp fnhotkeyutility.exe unsecapp.exe no specs unsecapp.exe no specs cmd.exe no specs conhost.exe no specs crypted_06x05x2026_x64.exe no specs #STEALC notepad.exe tdlsjrps.exe #AMADEY ohggf.exe ohggf.exe no specs sptpxmvf.exe windowsstore.update.exe no specs kykgbiqw.exe pkwkccmw.exe no specs kykgbiqw.tmp #STEALC mwspbura.exe fnhotkeyutility.exe no specs lf9da0hm.exe no specs fnhotkeyutility.exe no specs sihost.exe explorer.exe runtimebroker.exe runtimebroker.exe runtimebroker.exe runtimebroker.exe

Process information

PID
CMD
Path
Indicators
Parent process
664C:\WINDOWS\system32\wbem\unsecapp.exe -EmbeddingC:\Windows\System32\wbem\unsecapp.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Sink to receive asynchronous callbacks for WMI client application
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wbem\unsecapp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
1176"C:\Users\admin\AppData\Local\Temp\is-O5J3YPQR9Q.tmp\1n0x3fke.tmp" /SL5="$A02A0,4658119,905216,C:\Users\admin\AppData\Local\Temp\1n0x3fke.exe" C:\Users\admin\AppData\Local\Temp\is-O5J3YPQR9Q.tmp\1n0x3fke.tmp
1n0x3fke.exe
User:
admin
Company:
Schmitz
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1054.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-o5j3ypqr9q.tmp\1n0x3fke.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
2428"C:\Users\admin\AppData\Local\Temp\is-Y3A0XZD2FF.tmp\KYKGBIQW.tmp" /SL5="$801F4,4658119,905216,C:\Users\admin\AppData\Local\Temp\KYKGBIQW.exe" C:\Users\admin\AppData\Local\Temp\is-Y3A0XZD2FF.tmp\KYKGBIQW.tmp
KYKGBIQW.exe
User:
admin
Company:
Schmitz
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
1
Version:
51.1054.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-y3a0xzd2ff.tmp\kykgbiqw.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
3136"cmd.exe" /c start "" C:\Users\admin\crypted_06x05x2026_x64.exeC:\Windows\System32\cmd.exeFnHotkeyUtility.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
3560"C:\Users\admin\AppData\Local\Temp\1n0x3fke.exe" C:\Users\admin\AppData\Local\Temp\1n0x3fke.exe
_2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe
User:
admin
Company:
Schmitz
Integrity Level:
MEDIUM
Description:
Usb settings handlers implementation for assigned access pro
Exit code:
1
Version:
39.99.38
Modules
Images
c:\users\admin\appdata\local\temp\1n0x3fke.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comctl32.dll
4304C:\ProgramData\ohggf.exeC:\ProgramData\ohggf.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\programdata\ohggf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wininet.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
4412sihost.exeC:\Windows\System32\sihost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Shell Infrastructure Host
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sihost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
4564"C:\ProgramData\ohggf.exe" C:\ProgramData\ohggf.exe
tdlsjrps.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\programdata\ohggf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wininet.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
4624C:\Users\admin\AppData\Local\Microsoft\WindowsApps\WindowsStore.Update.exeC:\Users\admin\AppData\Local\Microsoft\WindowsApps\WindowsStore.Update.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\microsoft\windowsapps\windowsstore.update.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4696C:\WINDOWS\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\twinapi.dll
c:\windows\system32\oleaut32.dll
Total events
11 997
Read events
11 200
Write events
796
Delete events
1

Modification events

(PID) Process:(5384) _2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exeKey:HKEY_CURRENT_USER\Environment
Operation:writeName:UserInitMprLogonScript
Value:
"C:\WINDOWS\system32\cmd.exe" /c start /b "" "C:\Users\admin\AppData\Roaming\Microsoft\Windows\Services\winhost.exe"
(PID) Process:(7660) slui.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\3d\52C64B7E
Operation:writeName:@%SystemRoot%\System32\sppcomapi.dll,-3200
Value:
Software Licensing
(PID) Process:(5384) _2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(1176) 1n0x3fke.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(6104) FnHotkeyUtility.exeKey:HKEY_CURRENT_USER\SOFTWARE\Lenovo\Hotkey\VID_1915&PID_eee0
Operation:writeName:Ex_9D
Value:
0C010310002F
(PID) Process:(6104) FnHotkeyUtility.exeKey:HKEY_CURRENT_USER\SOFTWARE\Lenovo\Hotkey\VID_1915&PID_eee0
Operation:writeName:Ex_9E
Value:
0C0103100030
(PID) Process:(6104) FnHotkeyUtility.exeKey:HKEY_CURRENT_USER\SOFTWARE\Lenovo\Hotkey\VID_1915&PID_eee0
Operation:writeName:Ex_9F
Value:
0C0103100031
(PID) Process:(6104) FnHotkeyUtility.exeKey:HKEY_CURRENT_USER\SOFTWARE\Lenovo\Hotkey\VID_1915&PID_eee0
Operation:writeName:Ex_40
Value:
0C0103100037
(PID) Process:(6104) FnHotkeyUtility.exeKey:HKEY_CURRENT_USER\SOFTWARE\Lenovo\Hotkey\VID_1915&PID_eee0
Operation:writeName:Ex_41
Value:
0C0103100039
(PID) Process:(6104) FnHotkeyUtility.exeKey:HKEY_CURRENT_USER\SOFTWARE\Lenovo\Hotkey\VID_1915&PID_eee0
Operation:writeName:Ex_42
Value:
0C010310003A
Executable files
33
Suspicious files
1
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
5384_2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Services\winhost.exeexecutable
MD5:ACF5499BC65F05513C3530D32C991D3E
SHA256:2841AAB00EE6F00213E594DC562D03B982E6D8570A6DE2A0797F3A147665F4CA
79281n0x3fke.tmpC:\Users\admin\AppData\Local\Temp\is-142OPYW7DX.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
61401n0x3fke.exeC:\Users\admin\AppData\Local\Temp\is-Y3NP0RVVH7.tmp\1n0x3fke.tmpexecutable
MD5:11AFCDCFE2B4F98F9A947FCFCA649452
SHA256:9AD6E0B378DD93244A5257A1A0CE49E61049E58FD3A14CF06DFD05855A1E90EB
79281n0x3fke.tmpC:\ProgramData\TanGoldenRod\is-JPOB7UC7HZ.tmpexecutable
MD5:990A590EB079F420946FDE91975798B9
SHA256:A68A9AC35AA1E183FE3BD9E7144259631530DB07502112A339E5E1C8DCCC9A31
79281n0x3fke.tmpC:\ProgramData\TanGoldenRod\vcruntime140.dllexecutable
MD5:C5BC6D2136F51D438AF4DBE8EF8103D1
SHA256:5DC711B1F190DF5B1257B92883E9C3F10CB4E953591DA13DD50D9F0C7A4AF695
11761n0x3fke.tmpC:\Users\admin\AppData\Local\Temp\is-YP9CA7QKIO.tmp\_isetup\_isdecmp.dllexecutable
MD5:C6AE924AD02500284F7E4EFA11FA7CFC
SHA256:31D04C1E4BFDFA34704C142FA98F80C0A3076E4B312D6ADA57C4BE9D9C7DCF26
11761n0x3fke.tmpC:\Users\admin\AppData\Local\Temp\is-YP9CA7QKIO.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
5384_2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exeC:\Users\admin\AppData\Local\Temp\1n0x3fke.exeexecutable
MD5:DD900C31B79540CCB2E585F82FA9746D
SHA256:EB35E29E65134D98D2A84A140B804014FC52FE90361234E2AED8A52B593D6F7A
35601n0x3fke.exeC:\Users\admin\AppData\Local\Temp\is-O5J3YPQR9Q.tmp\1n0x3fke.tmpexecutable
MD5:11AFCDCFE2B4F98F9A947FCFCA649452
SHA256:9AD6E0B378DD93244A5257A1A0CE49E61049E58FD3A14CF06DFD05855A1E90EB
79281n0x3fke.tmpC:\Users\admin\AppData\Local\Temp\is-142OPYW7DX.tmp\_isetup\_isdecmp.dllexecutable
MD5:C6AE924AD02500284F7E4EFA11FA7CFC
SHA256:31D04C1E4BFDFA34704C142FA98F80C0A3076E4B312D6ADA57C4BE9D9C7DCF26
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
32
TCP/UDP connections
31
DNS requests
10
Threats
27

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4872
svchost.exe
GET
200
2.16.164.112:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
4872
svchost.exe
GET
200
23.52.181.212:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
814 b
whitelisted
5384
_2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe
POST
200
62.60.226.159:80
http://62.60.226.159/api.php
GB
binary
73 b
unknown
5384
_2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe
GET
200
62.60.226.159:80
http://62.60.226.159/uploads/Polarised_6.7897.2734.4933_INSTALL.exe
GB
executable
11.6 Mb
malicious
7660
slui.exe
POST
500
48.192.1.64:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
xml
512 b
whitelisted
7660
slui.exe
POST
500
48.192.1.64:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
xml
512 b
whitelisted
5384
_2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe
POST
200
62.60.226.159:80
http://62.60.226.159/api.php
GB
unknown
3280
svchost.exe
GET
200
23.52.181.212:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.2.crl
US
binary
400 b
whitelisted
7672
notepad.exe
POST
200
196.251.107.130:80
http://196.251.107.130/16b022998f754137b60a.php
GB
text
68 b
malicious
3280
svchost.exe
GET
200
23.52.181.212:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
US
binary
814 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
48.209.138.189:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
48.209.138.168:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7312
slui.exe
48.192.1.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
4872
svchost.exe
2.16.164.112:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
4872
svchost.exe
23.52.181.212:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
5276
MoUsoCoreWorker.exe
48.209.138.189:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4872
svchost.exe
48.209.138.189:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5384
_2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe
62.60.226.159:80
FEMOIT
GB
malicious

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 48.209.138.168
  • 48.209.138.189
whitelisted
activation-v2.sls.microsoft.com
  • 48.192.1.64
whitelisted
crl.microsoft.com
  • 2.16.164.112
  • 2.16.164.88
  • 2.16.164.89
  • 2.16.164.32
  • 2.16.164.49
  • 2.16.164.34
  • 2.16.164.40
  • 2.16.164.9
  • 2.16.164.51
  • 2.16.164.114
whitelisted
www.microsoft.com
  • 23.52.181.212
whitelisted
google.com
  • 142.251.14.138
  • 142.251.14.101
  • 142.251.14.102
  • 142.251.14.139
  • 142.251.14.113
  • 142.251.14.100
whitelisted
3vrtaee2bswrutm97d6afhvg4zgqtagim.com
unknown
self.events.data.microsoft.com
  • 52.168.117.170
whitelisted

Threats

PID
Process
Class
Message
5384
_2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 9
5384
_2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe
A Network Trojan was detected
ET MALWARE Executable Downloaded From Common Payload Delivery Host (GET)
5384
_2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe
A Network Trojan was detected
ET MALWARE Observed StealC_V2 Payload Request (GET)
7672
notepad.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 45
5384
_2841aab00ee6f00213e594dc562d03b982e6d8570a6de2a0797f3a147665f4ca.exe
A Network Trojan was detected
ET MALWARE Executable Downloaded From Common Payload Delivery Host (GET)
4564
ohggf.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
4564
ohggf.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/Amadey associated URI (/xvzpjyddlu/getdata.php)
4564
ohggf.exe
A Network Trojan was detected
ET MALWARE Observed StealC_V2 Payload Request (GET)
4564
ohggf.exe
A Network Trojan was detected
ET MALWARE Executable Downloaded From Common Payload Delivery Host (GET)
4564
ohggf.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
No debug info