| File name: | 2d61e31b04ed31df35eb2c471e77306a6d6112250882534ba20c30630f033285 |
| Full analysis: | https://app.any.run/tasks/f4376d15-de3a-4b10-aa79-23dff3cd58ef |
| Verdict: | Malicious activity |
| Analysis date: | March 24, 2025, 12:55:26 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, PECompact2 compressed, 2 sections |
| MD5: | 95629CA4B125447CFE83A6EF1D787B4D |
| SHA1: | 0873131E0A9D9CF4EB2B427FA0C980BBAFB3A610 |
| SHA256: | 2D61E31B04ED31DF35EB2C471E77306A6D6112250882534BA20C30630F033285 |
| SSDEEP: | 6144:kpU/HtbklvrLXfGidoyt251UriZFwfsDX2UznsaFVNJCvhoDOber:ke/tI1rLXfbdBYHUrAwfMp3C6nr |
| .exe | | | DOS Executable Generic (100) |
|---|
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2015:01:27 03:56:27+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit, No debug |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 45056 |
| InitializedDataSize: | 4096 |
| UninitializedDataSize: | 106496 |
| EntryPoint: | 0x27000 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 208 | c:\0841q.exe | C:\0841q.exe | — | 87lv80t.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 208 | c:\ab56dn.exe | C:\ab56dn.exe | — | 16x6v5.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 208 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 236 | c:\858i066.exe | C:\858i066.exe | — | x1705am.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 300 | c:\e308n8.exe | C:\e308n8.exe | — | 2a72b6.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 300 | c:\6v2h05d.exe | C:\6v2h05d.exe | — | 4gn403.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 300 | c:\chl11.exe | C:\chl11.exe | — | 40090n6.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 300 | c:\ow64a.exe | C:\ow64a.exe | — | goog8h.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 444 | c:\6nh64.exe | C:\6nh64.exe | — | 858i066.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 516 | c:\pdc3po.exe | C:\pdc3po.exe | v3100.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7300 | t60q4.exe | C:\33eaq34.exe | executable | |
MD5:525B1A5DAD39E88FE92DD6474B77393C | SHA256:F490634F7A15B3E6B24B8A06314CB900F48C50A8FFBBB3674D6AC345D5C5DF1A | |||
| 3268 | 33eaq34.exe | C:\r66o5.exe | executable | |
MD5:7C32D50E30890FA8739A145B4BD849B1 | SHA256:22357CC640896581884C0614B07BAF42B7D46F8778F0D3CEEF6729B519B97F3F | |||
| 2140 | 2d61e31b04ed31df35eb2c471e77306a6d6112250882534ba20c30630f033285.exe | C:\t60q4.exe | executable | |
MD5:CCE1E9E7035A65455FCA0465C630670F | SHA256:316604B864C604BF0EBAA03D5F9643F2350A88A78CA35123EA3567BDB31DA0D1 | |||
| 7776 | eb5q2.exe | C:\2wq8ch.exe | executable | |
MD5:FF2ADB22937846B80DDBC89A2F453EB8 | SHA256:9D686B0A6007075949C5CD63B2AF4CDF691124D01CD9D9554B350DCF5D8D4272 | |||
| 7380 | 2a8xu9.exe | C:\3nbt2.exe | executable | |
MD5:090697224B8565212E1EA7CE19860C2D | SHA256:E2B346A4269E6ADAB84235ACFEB2E4BA02A923D598823ECCCD388E1E20A08012 | |||
| 7452 | 2wq8ch.exe | C:\4knx0vm.exe | executable | |
MD5:9E5D93AFB82F0F855E2C4EEBDB9EA41D | SHA256:78B2F9957D23335AE81E7339AB8EB61299099657B43305424DC03CB45D8240A9 | |||
| 7536 | nb3l6v.exe | C:\j6nd24.exe | executable | |
MD5:B229186075825FE71816683D8E4552EA | SHA256:F5CD972124F24C5BA831751D9077783022154940DC3C7E6BACC72DE258BAF895 | |||
| 7440 | 4knx0vm.exe | C:\067kw7.exe | executable | |
MD5:133D04A947641456F02CC871DC452A76 | SHA256:D046C589105EC47A3637D1441E4C0D7FC642BA68BF6BA3367ECDEDE0F98117A7 | |||
| 7556 | ju783o.exe | C:\5j131c.exe | executable | |
MD5:76EA22F41DB5B95B2A790462705DB01A | SHA256:E70C0224F14DED233BA48511D86483AFDF490087333E224DFA7DA087C2C9DF5D | |||
| 7588 | 5j131c.exe | C:\nb3l6v.exe | executable | |
MD5:74CFE173E5B1D02D8E5023AF69C0606F | SHA256:C5D5BE155E962C16782F818C92DD77C38A4982215BC6E8B44B55CF2AF2971655 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2104 | svchost.exe | GET | 200 | 23.53.40.176:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 304 | 20.12.23.50:443 | https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL | unknown | — | — | unknown |
— | — | GET | 200 | 13.85.23.206:443 | https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping | unknown | — | — | unknown |
1244 | SIHClient.exe | GET | 200 | 23.53.40.176:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl | unknown | — | — | whitelisted |
1244 | SIHClient.exe | GET | 200 | 23.53.40.176:80 | http://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl | unknown | — | — | whitelisted |
1244 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.1.crl | unknown | — | — | whitelisted |
— | — | POST | 400 | 20.190.160.2:443 | https://login.live.com/ppsecure/deviceaddcredential.srf | unknown | text | 203 b | whitelisted |
— | — | GET | 200 | 20.223.35.26:443 | https://arc.msn.com/v3/Delivery/Placement?pubid=da63df93-3dbc-42ae-a505-b34988683ac7&pid=310091&adm=2&w=1&h=1&wpx=1&hpx=1&fmt=json&cltp=app&dim=le&rafb=0&nct=1&pm=1&cfmt=text,image,poly&sft=jpeg,png,gif&topt=1&poptin=0&localid=w:AC7699B0-48EA-FD22-C8DC-06A02098A0F0&ctry=US&time=20250324T125536Z&lc=en-US&pl=en-US,en-GB&idtp=mid&uid=9115d6d1-9f4e-4053-9297-2a8c833b3912&aid=00000000-0000-0000-0000-000000000000&ua=WindowsShellClient%2F9.0.40929.0%20%28Windows%29&asid=f62192e72ec6404eb4f6429efe5c9590&ctmode=MultiSession&arch=x64&betaedgever=0.0.0.0&canedgever=0.0.0.0&cdm=1&cdmver=10.0.19041.3636&devedgever=0.0.0.0&devfam=Windows.Desktop&devform=Unknown&devosver=10.0.19045.4046&disphorzres=1280&dispsize=15.3&dispvertres=720&fosver=16299&isu=0&lo=3967494&metered=false&nettype=ethernet&npid=sc-310091&oemName=DELL&oemid=DELL&ossku=Professional&prevosver=15063&rver=2&smBiosDm=DELL&stabedgever=122.0.2365.59&tl=2&tsu=1358024&waasBldFlt=1&waasCfgExp=1&waasCfgSet=1&waasRetail=1&waasRing=&svoffered=2 | unknown | binary | 1.31 Kb | whitelisted |
— | — | POST | 400 | 40.126.32.76:443 | https://login.live.com/ppsecure/deviceaddcredential.srf | unknown | text | 203 b | whitelisted |
— | — | POST | 400 | 40.126.31.71:443 | https://login.live.com/ppsecure/deviceaddcredential.srf | unknown | text | 203 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 40.115.3.253:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 40.126.31.129:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2104 | svchost.exe | 23.53.40.176:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
6544 | svchost.exe | 40.126.31.129:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
7472 | backgroundTaskHost.exe | 20.223.35.26:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3216 | svchost.exe | 40.115.3.253:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 20.190.160.65:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |