File name:

Microsoft.exe

Full analysis: https://app.any.run/tasks/861974c5-9569-4c25-bdf1-d160b36043df
Verdict: Malicious activity
Threats:

AsyncRAT is a RAT that can monitor and remotely control infected systems. This malware was introduced on Github as a legitimate open-source remote administration software, but hackers use it for its many powerful malicious functions.

Analysis date: May 15, 2026, 16:22:16
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
rat
asyncrat
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

7DEC3AD2EC3B95C5C05FF839C89CAE0E

SHA1:

861D2108DD0B9A42FFCCC0192F812EBF5FEB87AB

SHA256:

2D12BAB46846DB6A3D72F34C3567EEA47EF55552FC076F7D038595C5A8A93E0B

SSDEEP:

1536:smSSBOaDLhC7TSJluPQizGbbMwkK2HFW8b0JTnVclN:fSSBOohC7TSJlYnzGbbM37z0JTVY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • Microsoft.exe (PID: 1456)
    • ASYNCRAT has been detected (YARA)

      • Microsoft.exe (PID: 3416)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 1536)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 1536)
    • The executable file from the user directory is run by the CMD process

      • Microsoft.exe (PID: 3416)
    • Executing commands from a ".bat" file

      • Microsoft.exe (PID: 1456)
    • Executable content was dropped or overwritten

      • Microsoft.exe (PID: 1456)
  • INFO

    • Checks supported languages

      • Microsoft.exe (PID: 1456)
      • Microsoft.exe (PID: 3416)
      • Microsoft.exe (PID: 7848)
    • Create files in a temporary directory

      • Microsoft.exe (PID: 1456)
    • Reads the machine GUID from the registry

      • Microsoft.exe (PID: 1456)
      • Microsoft.exe (PID: 3416)
      • Microsoft.exe (PID: 7848)
    • Reads the computer name

      • Microsoft.exe (PID: 1456)
      • Microsoft.exe (PID: 3416)
      • Microsoft.exe (PID: 7848)
    • Launching a file from a Registry key

      • Microsoft.exe (PID: 1456)
    • Creates files or folders in the user directory

      • Microsoft.exe (PID: 1456)
    • Reads Environment values

      • Microsoft.exe (PID: 3416)
    • Manual execution by a user

      • Microsoft.exe (PID: 7848)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

AsyncRat

(PID) Process(3416) Microsoft.exe
C2 (2)akram.in.net
www.akram.in.net
Ports (5)443
80
53
8080
1604
Version1.0.7
Options
AutoRuntrue
Mutexlao-w3k02-j42ika
InstallFolder%AppData%
Certificates
Cert1MIICMDCCAZmgAwIBAgIVAKAAD/SurGzixOhqLGBOobqogcoTMA0GCSqGSIb3DQEBDQUAMGQxFTATBgNVBAMMDERjUmF0IFNlcnZlcjETMBEGA1UECwwKcXdxZGFuY2h1bjEcMBoGA1UECgwTRGNSYXQgQnkgcXdxZGFuY2h1bjELMAkGA1UEBwwCU0gxCzAJBgNVBAYTAkNOMB4XDTI1MDczMDE2MDAzNFoXDTM2MDUwODE2MDAzNFowEDEOMAwGA1UEAwwFRGNSYXQwgZ8wDQYJKoZIhvcNAQEBBQADgY0A...
Server_SignatureMq7Ou3Faz4HniVtcVlwMSWBjqlnl/9xy2pHNGAAq1lvdrGUr7AlcnlPrDlAHz/qQFZasbkPvrBEYUvdjO6dNM9RIJD14VjYsCMD9v6JR+3FGEPU9jvzHj/+AA3TfezxVJYxAbl12aFhxcIU3HH8p6vU/NSChKCfbSkDX48SN8m4=
Keys
AES07a01fd4e173a1fe99ff39d57960975f54ecf11913325e42cd17c7c9a1228da2
SaltDcRatByqwqdanchun
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (56.7)
.exe | Win64 Executable (generic) (21.3)
.scr | Windows screen saver (10.1)
.dll | Win32 Dynamic Link Library (generic) (5)
.exe | Win32 Executable (generic) (3.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:01:12 03:47:42+00:00
ImageFileCharacteristics: Executable
PEType: PE32
LinkerVersion: 8
CodeSize: 59904
InitializedDataSize: 11264
UninitializedDataSize: -
EntryPoint: 0x109be
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 10.0.28000.176
ProductVersionNumber: 10.0.28000.176
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: Microsoft Corporation
FileDescription: -
FileVersion: 10.0.28000.176
InternalName: services.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
LegalTrademarks: Microsoft® Windows® Operating System
OriginalFileName: services.exe
ProductName: Microsoft
ProductVersion: 10.0.28000.176
AssemblyVersion: 10.0.28000.176
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
6
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start microsoft.exe cmd.exe no specs conhost.exe no specs timeout.exe no specs #ASYNCRAT microsoft.exe microsoft.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1456"C:\Users\admin\Desktop\Microsoft.exe" C:\Users\admin\Desktop\Microsoft.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Exit code:
0
Version:
10.0.28000.176
Modules
Images
c:\users\admin\desktop\microsoft.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1536C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\tmp11CE.tmp.bat""C:\Windows\System32\cmd.exeMicrosoft.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
2840timeout 3 C:\Windows\System32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2952\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3416"C:\Users\admin\AppData\Roaming\Microsoft.exe" C:\Users\admin\AppData\Roaming\Microsoft.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Version:
10.0.28000.176
Modules
Images
c:\users\admin\appdata\roaming\microsoft.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
AsyncRat
(PID) Process(3416) Microsoft.exe
C2 (2)akram.in.net
www.akram.in.net
Ports (5)443
80
53
8080
1604
Version1.0.7
Options
AutoRuntrue
Mutexlao-w3k02-j42ika
InstallFolder%AppData%
Certificates
Cert1MIICMDCCAZmgAwIBAgIVAKAAD/SurGzixOhqLGBOobqogcoTMA0GCSqGSIb3DQEBDQUAMGQxFTATBgNVBAMMDERjUmF0IFNlcnZlcjETMBEGA1UECwwKcXdxZGFuY2h1bjEcMBoGA1UECgwTRGNSYXQgQnkgcXdxZGFuY2h1bjELMAkGA1UEBwwCU0gxCzAJBgNVBAYTAkNOMB4XDTI1MDczMDE2MDAzNFoXDTM2MDUwODE2MDAzNFowEDEOMAwGA1UEAwwFRGNSYXQwgZ8wDQYJKoZIhvcNAQEBBQADgY0A...
Server_SignatureMq7Ou3Faz4HniVtcVlwMSWBjqlnl/9xy2pHNGAAq1lvdrGUr7AlcnlPrDlAHz/qQFZasbkPvrBEYUvdjO6dNM9RIJD14VjYsCMD9v6JR+3FGEPU9jvzHj/+AA3TfezxVJYxAbl12aFhxcIU3HH8p6vU/NSChKCfbSkDX48SN8m4=
Keys
AES07a01fd4e173a1fe99ff39d57960975f54ecf11913325e42cd17c7c9a1228da2
SaltDcRatByqwqdanchun
7848"C:\Users\admin\AppData\Roaming\Microsoft.exe"C:\Users\admin\AppData\Roaming\Microsoft.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Exit code:
0
Version:
10.0.28000.176
Modules
Images
c:\users\admin\appdata\roaming\microsoft.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
1 007
Read events
1 006
Write events
1
Delete events
0

Modification events

(PID) Process:(1456) Microsoft.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Microsoft
Value:
"C:\Users\admin\AppData\Roaming\Microsoft.exe"
Executable files
1
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
1456Microsoft.exeC:\Users\admin\AppData\Local\Temp\tmp11CE.tmp.battext
MD5:00D05C0ED852B302057C0F6DED9D48F3
SHA256:BD84D635D5411DDA5742E3F6D5F905CD1C453A98811AD70D976B262EFA9C29A3
1456Microsoft.exeC:\Users\admin\AppData\Roaming\Microsoft.exeexecutable
MD5:7DEC3AD2EC3B95C5C05FF839C89CAE0E
SHA256:2D12BAB46846DB6A3D72F34C3567EEA47EF55552FC076F7D038595C5A8A93E0B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
35
TCP/UDP connections
37
DNS requests
22
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5276
MoUsoCoreWorker.exe
GET
304
48.209.133.15:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
6024
SIHClient.exe
GET
304
74.178.76.128:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
6024
SIHClient.exe
GET
200
135.233.95.135:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
6024
SIHClient.exe
GET
200
74.178.76.128:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
6024
SIHClient.exe
GET
304
74.178.76.128:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
5316
svchost.exe
POST
400
20.190.159.0:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
5316
svchost.exe
POST
200
20.190.159.0:443
https://login.live.com/RST2.srf
US
xml
1.24 Kb
whitelisted
6260
svchost.exe
GET
304
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
whitelisted
5316
svchost.exe
POST
400
20.190.159.0:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
5316
svchost.exe
POST
400
20.190.159.0:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
5276
MoUsoCoreWorker.exe
48.209.138.168:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
128.24.231.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5532
SearchApp.exe
92.123.104.65:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
6260
svchost.exe
48.209.138.168:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5532
SearchApp.exe
23.11.40.157:80
ocsp.digicert.com
AKAMAI-AMS
NL
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
5316
svchost.exe
20.190.159.0:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3428
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5316
svchost.exe
23.11.40.157:80
ocsp.digicert.com
AKAMAI-AMS
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 48.209.138.168
  • 48.209.133.15
  • 51.124.78.146
whitelisted
activation-v2.sls.microsoft.com
  • 128.24.231.64
whitelisted
www.bing.com
  • 92.123.104.65
  • 92.123.104.50
  • 92.123.104.62
  • 92.123.104.37
  • 92.123.104.63
  • 92.123.104.41
  • 92.123.104.61
  • 92.123.104.52
  • 92.123.104.53
whitelisted
ocsp.digicert.com
  • 23.11.40.157
whitelisted
google.com
  • 142.250.154.100
  • 142.250.154.138
  • 142.250.154.139
  • 142.250.154.101
  • 142.250.154.102
  • 142.250.154.113
whitelisted
login.live.com
  • 20.190.159.0
  • 40.126.31.130
  • 20.190.159.73
  • 40.126.31.73
  • 40.126.31.3
  • 20.190.159.131
  • 20.190.159.130
  • 20.190.159.23
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
crl.microsoft.com
  • 23.216.77.25
  • 23.216.77.42
  • 23.216.77.30
  • 23.216.77.36
  • 23.216.77.22
  • 23.216.77.8
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 2.23.246.101
whitelisted
akram.in.net
  • 172.67.173.109
  • 104.21.55.214
unknown

Threats

PID
Process
Class
Message
3416
Microsoft.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/Common RAT related JA3 hash observed
3416
Microsoft.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/Common RAT related JA3 hash observed
3416
Microsoft.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/Common RAT related JA3 hash observed
3416
Microsoft.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/Common RAT related JA3 hash observed
3416
Microsoft.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/Common RAT related JA3 hash observed
3416
Microsoft.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/Common RAT related JA3 hash observed
No debug info