File name:

Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exe

Full analysis: https://app.any.run/tasks/db2695ca-7ac3-499a-bb4e-002af6df76d3
Verdict: Malicious activity
Analysis date: October 29, 2025, 20:34:45
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

101B0EB2E4E9A66491ED3F9411683452

SHA1:

9D1D3DB6DE8071A96CCC80FA661FB7432510EAB7

SHA256:

2E6346CE1ADF15BFFCA31A0C96274F615E3E0BBF53235E4B4C85555BC012B9D9

SSDEEP:

49152:xemwATuYin7V88988Ntl61QyVSEYxQHvvVPUcmWy88i88at8hnYtQTQTG+VQhSJx:xemwATuPxJYZvvVPUcmctYtQOihSJS1Q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Create files in the Startup directory

      • Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exe (PID: 7352)
    • Changes the autorun value in the registry

      • Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exe (PID: 7352)
  • SUSPICIOUS

    • Starts itself from another location

      • Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exe (PID: 7352)
    • Executable content was dropped or overwritten

      • Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exe (PID: 7352)
    • There is functionality for taking screenshot (YARA)

      • Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exe (PID: 7548)
  • INFO

    • Checks supported languages

      • Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exe (PID: 7352)
      • Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exe (PID: 7548)
    • Reads the computer name

      • Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exe (PID: 7352)
      • Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exe (PID: 7548)
    • The sample compiled with chinese language support

      • Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exe (PID: 7352)
    • Launching a file from the Startup directory

      • Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exe (PID: 7352)
    • Creates files or folders in the user directory

      • Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exe (PID: 7352)
    • Launching a file from a Registry key

      • Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exe (PID: 7352)
    • Checks proxy server information

      • slui.exe (PID: 2388)
    • Reads the software policy settings

      • slui.exe (PID: 2388)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (35.8)
.exe | Win64 Executable (generic) (31.7)
.scr | Windows screen saver (15)
.dll | Win32 Dynamic Link Library (generic) (7.5)
.exe | Win32 Executable (generic) (5.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:11:11 08:31:32+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 1056768
InitializedDataSize: 405504
UninitializedDataSize: -
EntryPoint: 0xe0c61
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
FileVersion: 1.0.0.0
FileDescription: Windows 资源管理器后台服务
ProductName: Windows 资源管理器后台服务
ProductVersion: 1.0.0.0
LegalCopyright: 作者版权所有 请尊重并使用正版
Comments: 本程序使用易语言编写(http://www.eyuyan.com)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
2388C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7352"C:\Users\admin\Desktop\Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exe" C:\Users\admin\Desktop\Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Windows 资源管理器后台服务
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\windows ×êô´¹üàíºóì¨ïß³ì.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ws2_32.dll
7548"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exe"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exe—Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Windows 资源管理器后台服务
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\microsoft\windows\start menu\programs\startup\windows ×êô´¹üàíºóì¨ïß³ì.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ws2_32.dll
Total events
4 682
Read events
4 679
Write events
3
Delete events
0

Modification events

(PID) Process:(7352) Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:system
Value:
C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exe
(PID) Process:(7352) Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:systemin
Value:
C:\Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exe
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
7352Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Windows ×ÊÔ´¹ÜÀíºǫ́Ïß³Ì.exeexecutable
MD5:101B0EB2E4E9A66491ED3F9411683452
SHA256:2E6346CE1ADF15BFFCA31A0C96274F615E3E0BBF53235E4B4C85555BC012B9D9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
24
DNS requests
16
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4220
svchost.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
1128
svchost.exe
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
8104
SIHClient.exe
GET
200
23.59.18.102:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.3.crl
US
binary
401 b
whitelisted
8104
SIHClient.exe
GET
200
23.59.18.102:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.3.crl
US
binary
813 b
whitelisted
8104
SIHClient.exe
GET
200
23.59.18.102:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
US
binary
814 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
—
—
—
whitelisted
4220
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5596
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1952
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
—
—
—
whitelisted
1128
svchost.exe
40.126.32.136:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1128
svchost.exe
23.63.118.230:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4220
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4220
svchost.exe
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
3440
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.110
whitelisted
login.live.com
  • 40.126.32.136
  • 40.126.32.140
  • 20.190.160.5
  • 20.190.160.66
  • 40.126.32.72
  • 20.190.160.2
  • 20.190.160.4
  • 20.190.160.132
whitelisted
ocsp.digicert.com
  • 23.63.118.230
whitelisted
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
slscr.update.microsoft.com
  • 74.178.240.61
whitelisted
www.microsoft.com
  • 23.59.18.102
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted
activation-v2.sls.microsoft.com
  • 20.165.238.210
whitelisted

Threats

PID
Process
Class
Message
—
—
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info