File name:

4363463463464363463463463.exe

Full analysis: https://app.any.run/tasks/1d68b25f-8265-4bd5-8f09-e7b908359d50
Verdict: Malicious activity
Threats:

Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks.

Analysis date: February 14, 2026, 21:57:11
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
websocket
github
hausbomber
noescape
wiper
loader
auto
generic
miner
stealer
winring0-sys
vuln-driver
rat
remcos
coinminer
rdpwrap
rmm-tool
ms-smartcard
stealc
advancedinstaller
quasar
rdp
remote
evasion
xor-url
xmrig
delphi
amadey
botnet
phishing
barys
telegram
vidar
santastealer
smb
ransomware
troldesh
shade
emotet
pastebin
scan
smbscan
anti-evasion
xworm
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

2A94F3960C58C6E70826495F76D00B85

SHA1:

E2A1A5641295F5EBF01A37AC1C170AC0814BB71A

SHA256:

2FCAD226B17131DA4274E1B9F8F31359BDD325C9568665F08FD1F6C5D06A23CE

SSDEEP:

192:2we8sGKE6MqyG7c20L7BIW12n/ePSmzkTInu8stYcFwVc03KY:9e8sGKfMqyGg20PKn/cRaInuptYcFwVY

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • GENERIC has been found (auto)

      • 4363463463464363463463463.exe (PID: 7452)
      • 4363463463464363463463463.exe (PID: 7452)
      • 4363463463464363463463463.exe (PID: 7452)
      • 4363463463464363463463463.exe (PID: 7452)
    • HAUSBOMBER has been detected (YARA)

      • 4363463463464363463463463.exe (PID: 7452)
    • COINMINER has been found (auto)

      • xmr.exe (PID: 2640)
      • 4363463463464363463463463.exe (PID: 7452)
    • NOESCAPE has been detected

      • NoEscape.exe (PID: 6272)
    • Vulnerable driver has been detected

      • syswinprdrvc.exe (PID: 6236)
    • Actions looks like stealing of personal data

      • opyhjdase.exe (PID: 9192)
      • 37KKS9R5AOV0.exe (PID: 6360)
      • random.exe (PID: 7196)
    • MINER has been detected (SURICATA)

      • dwm.exe (PID: 908)
    • Steals credentials from Web Browsers

      • opyhjdase.exe (PID: 9192)
      • 37KKS9R5AOV0.exe (PID: 6360)
      • random.exe (PID: 7196)
    • REMCOS has been found (auto)

      • 4363463463464363463463463.exe (PID: 7452)
    • REMCOS mutex has been found

      • prueba.exe (PID: 7620)
    • Uses Task Scheduler to autorun other applications

      • fastping_silent_v4.exe (PID: 8764)
      • dole.exe (PID: 2252)
      • defender.exe (PID: 5500)
      • powershell.exe (PID: 4216)
      • svchost.exe (PID: 5016)
    • REMCOS has been detected

      • prueba.exe (PID: 7620)
    • RDPWRAP has been detected

      • RDPWInst.exe (PID: 7656)
    • Creates or modifies Windows services

      • RDPWInst.exe (PID: 7656)
    • Changes the Windows auto-update feature

      • LGPO.exe (PID: 5636)
    • Uses Task Scheduler to run other applications

      • cmd.exe (PID: 6852)
    • Executing a file with an untrusted certificate

      • cr.exe (PID: 824)
      • vcredist_x86_en.exe (PID: 4828)
      • install.exe (PID: 1428)
      • cabalmain.exe (PID: 1824)
    • XMRIG has been detected (YARA)

      • dwm.exe (PID: 908)
    • XORed URL has been found (YARA)

      • dwm.exe (PID: 908)
    • QUASAR has been found (auto)

      • 4363463463464363463463463.exe (PID: 7452)
      • formy.exe (PID: 888)
      • dole.exe (PID: 2252)
    • STEALC has been detected (SURICATA)

      • 4363463463464363463463463.exe (PID: 7452)
      • formy.exe (PID: 888)
    • REMCOS has been detected (YARA)

      • prueba.exe (PID: 7620)
    • Changes Windows Defender settings

      • formy.exe (PID: 888)
      • cmd.exe (PID: 8532)
      • cmd.exe (PID: 772)
    • Changes powershell execution policy (Bypass)

      • formy.exe (PID: 888)
      • 37KKS9R5AOV0.exe (PID: 6360)
    • Run PowerShell with an invisible window

      • powershell.exe (PID: 8564)
      • powershell.exe (PID: 7244)
      • powershell.exe (PID: 4216)
    • Adds path to the Windows Defender exclusion list

      • formy.exe (PID: 888)
      • cmd.exe (PID: 8532)
      • cmd.exe (PID: 772)
      • svchost.exe (PID: 5016)
    • QUASAR has been detected (SURICATA)

      • defender.exe (PID: 5500)
    • SANTASTEALER has been found (auto)

      • 4363463463464363463463463.exe (PID: 7452)
    • Create files in the Startup directory

      • raw_subprocess.exe (PID: 6940)
      • XClient.exe (PID: 1984)
    • AMADEY has been detected (SURICATA)

      • 4363463463464363463463463.exe (PID: 7452)
    • VIDAR has been found (auto)

      • 4363463463464363463463463.exe (PID: 7452)
    • BARYS has been detected (SURICATA)

      • raw_subprocess.exe (PID: 6940)
    • PHISHING has been detected (SURICATA)

      • svchost.exe (PID: 2292)
    • SANTASTEALER has been detected

      • powershell.exe (PID: 4216)
    • Downloads the requested resource (POWERSHELL)

      • powershell.exe (PID: 4216)
    • Uses AES cipher (POWERSHELL)

      • powershell.exe (PID: 4216)
    • Gets or sets the symmetric key that is used for encryption and decryption (POWERSHELL)

      • powershell.exe (PID: 4216)
    • Gets or sets the initialization vector for the symmetric algorithm (POWERSHELL)

      • powershell.exe (PID: 4216)
    • Troldesh is detected

      • NoMoreRansom.exe (PID: 4876)
    • Changes the autorun value in the registry

      • NoMoreRansom.exe (PID: 4876)
      • XClient.exe (PID: 1984)
    • EMOTET mutex has been found

      • 640.exe (PID: 5220)
      • 640.exe (PID: 7916)
      • paramssps.exe (PID: 4144)
      • paramssps.exe (PID: 9196)
    • SMBSCAN has been detected (SURICATA)

      • Meredrop.exe (PID: 5260)
    • XWORM has been detected

      • XClient.exe (PID: 1984)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • EmmetPROD.exe (PID: 8324)
      • RDPW_Installer.exe (PID: 8504)
      • OGFN%20Updater.exe (PID: 6336)
      • cmd.exe (PID: 6852)
      • loader.exe (PID: 7764)
      • formy.exe (PID: 888)
      • 6AA0.tmp (PID: 2992)
      • svchost.exe (PID: 5016)
    • Uses WMIC.EXE to obtain computer system information

      • cmd.exe (PID: 8824)
    • Uses WMIC.EXE to obtain operating system information

      • cmd.exe (PID: 8824)
    • Uses WMIC.EXE to obtain a list of video controllers

      • cmd.exe (PID: 8824)
    • Executable content was dropped or overwritten

      • 4363463463464363463463463.exe (PID: 7452)
      • xmr.exe (PID: 2640)
      • fastping_silent_v4.exe (PID: 8764)
      • syswinprdrvc.exe (PID: 6236)
      • RDPW_Installer.exe (PID: 8504)
      • xcopy.exe (PID: 7220)
      • xcopy.exe (PID: 6440)
      • RDPWInst.exe (PID: 7656)
      • curl.exe (PID: 3332)
      • curl.exe (PID: 3032)
      • curl.exe (PID: 2780)
      • curl.exe (PID: 7220)
      • formy.exe (PID: 888)
      • dole.exe (PID: 2252)
      • UNP%20Setup.exe (PID: 8800)
      • vcredist_x86_en.exe (PID: 4828)
      • TiWorker.exe (PID: 5604)
      • np08w10.exe (PID: 2252)
      • np08w10.tmp (PID: 3304)
      • raw_subprocess.exe (PID: 6940)
      • 37KKS9R5AOV0.exe (PID: 6360)
      • haeum.exe (PID: 8776)
      • powershell.exe (PID: 4216)
      • riende.exe (PID: 5780)
      • NoMoreRansom.exe (PID: 4876)
      • 640.exe (PID: 7916)
      • svchost.exe (PID: 5016)
      • XClient.exe (PID: 1984)
    • Executes as Windows Service

      • syswinprdrvc.exe (PID: 6236)
      • VSSVC.exe (PID: 2976)
      • paramssps.exe (PID: 9196)
    • Creates a new Windows service

      • sc.exe (PID: 4336)
    • Starts SC.EXE for service management

      • xmr.exe (PID: 2640)
    • Windows service management via SC.EXE

      • sc.exe (PID: 5716)
      • sc.exe (PID: 1316)
    • Uses TASKKILL.EXE to kill Browsers

      • opyhjdase.exe (PID: 9192)
    • Process uses IPCONFIG to get network configuration information

      • cmd.exe (PID: 8824)
    • Stops a currently running service

      • sc.exe (PID: 5548)
    • Uses TASKKILL.EXE to kill process

      • fastping_silent_v4.exe (PID: 8764)
      • opyhjdase.exe (PID: 9192)
    • Drops a system driver (possible attempt to evade defenses)

      • syswinprdrvc.exe (PID: 6236)
      • curl.exe (PID: 3032)
    • Potential Corporate Privacy Violation

      • dwm.exe (PID: 908)
      • Meredrop.exe (PID: 5260)
    • Process drops legitimate windows executable

      • RDPW_Installer.exe (PID: 8504)
      • RDPWInst.exe (PID: 7656)
      • UNP%20Setup.exe (PID: 8800)
      • vcredist_x86_en.exe (PID: 4828)
      • msiexec.exe (PID: 5108)
      • TiWorker.exe (PID: 5604)
      • 4363463463464363463463463.exe (PID: 7452)
      • raw_subprocess.exe (PID: 6940)
      • np08w10.tmp (PID: 3304)
    • Executing commands from a ".bat" file

      • RDPW_Installer.exe (PID: 8504)
      • 6AA0.tmp (PID: 2992)
    • Runs PING.EXE to delay simulation

      • cmd.exe (PID: 6852)
    • The process creates files with name similar to system file names

      • fastping_silent_v4.exe (PID: 8764)
      • powershell.exe (PID: 4216)
      • NoMoreRansom.exe (PID: 4876)
      • 4363463463464363463463463.exe (PID: 7452)
      • XClient.exe (PID: 1984)
      • svchost.exe (PID: 5016)
    • Creates scheduled task with highest privileges

      • schtasks.exe (PID: 8772)
      • schtasks.exe (PID: 5920)
      • schtasks.exe (PID: 5440)
      • schtasks.exe (PID: 5460)
      • schtasks.exe (PID: 3088)
      • schtasks.exe (PID: 7024)
    • Process copies executable file

      • cmd.exe (PID: 6852)
    • The process executes via Task Scheduler

      • FastPingAgent.exe (PID: 8416)
      • FastPingService.exe (PID: 2620)
    • Uses NETSH.EXE to add a firewall rule or allowed programs

      • RDPWInst.exe (PID: 7656)
    • Starts a Microsoft application from unusual location

      • LGPO.exe (PID: 5636)
      • raw_subprocess.exe (PID: 6940)
    • File deletion via cmd.exe

      • cmd.exe (PID: 3664)
      • cmd.exe (PID: 1388)
      • cmd.exe (PID: 7396)
      • cmd.exe (PID: 6980)
      • cmd.exe (PID: 4136)
    • Executable started from TEMP via cmd.exe

      • cmd.exe (PID: 1388)
      • cmd.exe (PID: 7396)
      • cmd.exe (PID: 4136)
      • cmd.exe (PID: 7348)
      • cmd.exe (PID: 3192)
      • cmd.exe (PID: 7724)
      • cmd.exe (PID: 6300)
      • cmd.exe (PID: 8888)
    • Application launched itself

      • cmd.exe (PID: 6852)
      • 640.exe (PID: 5220)
      • paramssps.exe (PID: 9196)
    • Hides command output

      • cmd.exe (PID: 7348)
      • cmd.exe (PID: 8728)
      • cmd.exe (PID: 7724)
      • cmd.exe (PID: 8180)
      • cmd.exe (PID: 6300)
      • cmd.exe (PID: 8888)
    • Execution of CURL command

      • OGFN%20Updater.exe (PID: 6336)
      • loader.exe (PID: 7764)
    • Reads the date of Windows installation

      • FastPingService.exe (PID: 2620)
      • formy.exe (PID: 888)
      • 37KKS9R5AOV0.exe (PID: 6360)
      • random.exe (PID: 7196)
    • ADVANCEDINSTALLER mutex has been found

      • UNP%20Setup.exe (PID: 8800)
    • The process bypasses the loading of PowerShell profile settings

      • formy.exe (PID: 888)
    • Starts POWERSHELL.EXE for commands execution

      • formy.exe (PID: 888)
      • cmd.exe (PID: 8532)
      • 37KKS9R5AOV0.exe (PID: 6360)
      • cmd.exe (PID: 772)
    • Bypass execution policy to execute commands

      • powershell.exe (PID: 8564)
      • powershell.exe (PID: 4216)
    • Script adds exclusion path to Windows Defender

      • formy.exe (PID: 888)
      • cmd.exe (PID: 8532)
      • cmd.exe (PID: 772)
    • Starts itself from another location

      • dole.exe (PID: 2252)
    • Contacting a server suspected of hosting an CnC

      • defender.exe (PID: 5500)
      • 4363463463464363463463463.exe (PID: 7452)
    • Checks for external IP

      • svchost.exe (PID: 2292)
    • Creates file in the systems drive root

      • vcredist_x86_en.exe (PID: 4828)
      • 37KKS9R5AOV0.exe (PID: 6360)
    • Reads the Windows owner or organization settings

      • install.exe (PID: 1428)
      • msiexec.exe (PID: 5108)
      • np08w10.tmp (PID: 3304)
    • The process drops C-runtime libraries

      • msiexec.exe (PID: 5108)
      • TiWorker.exe (PID: 5604)
    • Get information on the list of running processes

      • 37KKS9R5AOV0.exe (PID: 6360)
    • Browser headless start

      • firefox.exe (PID: 7932)
      • chrome.exe (PID: 8332)
      • msedge.exe (PID: 8380)
    • Possible stealing from crypto wallets

      • 37KKS9R5AOV0.exe (PID: 6360)
      • random.exe (PID: 7196)
    • Executes application which crashes

      • msedge.exe (PID: 8380)
      • chrome.exe (PID: 8332)
    • Possible stealing of VPN data

      • 37KKS9R5AOV0.exe (PID: 6360)
    • Possible stealing of FTP data

      • 37KKS9R5AOV0.exe (PID: 6360)
    • Possible stealing of messenger data

      • 37KKS9R5AOV0.exe (PID: 6360)
    • Starts application with an unusual extension

      • haeum.exe (PID: 8776)
    • BASE64 encoded PowerShell command has been detected

      • 37KKS9R5AOV0.exe (PID: 6360)
    • Base64-obfuscated command line is found

      • 37KKS9R5AOV0.exe (PID: 6360)
    • Searches for installed software

      • random.exe (PID: 7196)
    • Uses ATTRIB.EXE to modify file attributes

      • powershell.exe (PID: 4216)
    • Uses REG/REGEDIT.EXE to modify registry

      • powershell.exe (PID: 4216)
    • Gets or sets the security protocol (POWERSHELL)

      • powershell.exe (PID: 4216)
    • Possible stealing from password managers

      • random.exe (PID: 7196)
    • Writes data into a file (POWERSHELL)

      • powershell.exe (PID: 4216)
    • The process checks if it is being run in the virtual environment

      • 1210.exe (PID: 5412)
    • Possible stealing from browsers

      • random.exe (PID: 7196)
  • INFO

    • Checks supported languages

      • 4363463463464363463463463.exe (PID: 7452)
      • EmmetPROD.exe (PID: 8324)
      • xmr.exe (PID: 2640)
      • NoEscape.exe (PID: 6272)
      • opyhjdase.exe (PID: 9192)
      • syswinprdrvc.exe (PID: 6236)
      • fastping_silent_v4.exe (PID: 8764)
      • RDPW_Installer.exe (PID: 8504)
      • RDPWInst.exe (PID: 6608)
      • OGFN%20Updater.exe (PID: 6336)
      • riende.exe (PID: 5780)
      • prueba.exe (PID: 7620)
      • FastPingAgent.exe (PID: 8416)
      • RDPWInst.exe (PID: 7656)
      • FastPingService.exe (PID: 2620)
      • LGPO.exe (PID: 5636)
      • RDP_CnC.exe (PID: 4660)
      • curl.exe (PID: 3332)
      • loader.exe (PID: 7764)
      • curl.exe (PID: 3588)
      • curl.exe (PID: 3032)
      • curl.exe (PID: 6096)
      • curl.exe (PID: 2780)
      • curl.exe (PID: 7220)
      • cr.exe (PID: 824)
      • UNP%20Setup.exe (PID: 8800)
      • WxWorkMultiOpen.exe (PID: 4336)
      • formy.exe (PID: 888)
      • dole.exe (PID: 2252)
      • defender.exe (PID: 5500)
      • vcredist_x86_en.exe (PID: 4828)
      • install.exe (PID: 1428)
      • msiexec.exe (PID: 5108)
      • msiexec.exe (PID: 4484)
      • msiexec.exe (PID: 4664)
      • news_01.exe (PID: 2996)
      • np08w10.exe (PID: 2252)
      • np08w10.tmp (PID: 3304)
      • 37KKS9R5AOV0.exe (PID: 6360)
      • raw_subprocess.exe (PID: 6940)
      • random.exe (PID: 7196)
      • 6AA0.tmp (PID: 2992)
      • haeum.exe (PID: 8776)
      • identity_helper.exe (PID: 8248)
      • identity_helper.exe (PID: 4784)
      • TempSpoofer.exe (PID: 4540)
      • NoMoreRansom.exe (PID: 4876)
      • Meredrop.exe (PID: 5260)
      • 640.exe (PID: 5220)
      • 640.exe (PID: 7916)
      • Lab01-02.exe (PID: 2124)
      • svchost.exe (PID: 5016)
      • 1210.exe (PID: 5412)
      • XClient.exe (PID: 1984)
      • win.exe (PID: 8088)
      • paramssps.exe (PID: 4144)
      • paramssps.exe (PID: 9196)
    • Process checks computer location settings

      • 4363463463464363463463463.exe (PID: 7452)
      • FastPingService.exe (PID: 2620)
      • formy.exe (PID: 888)
      • UNP%20Setup.exe (PID: 8800)
      • 6AA0.tmp (PID: 2992)
      • 37KKS9R5AOV0.exe (PID: 6360)
    • Reads the computer name

      • 4363463463464363463463463.exe (PID: 7452)
      • NoEscape.exe (PID: 6272)
      • opyhjdase.exe (PID: 9192)
      • fastping_silent_v4.exe (PID: 8764)
      • riende.exe (PID: 5780)
      • prueba.exe (PID: 7620)
      • FastPingAgent.exe (PID: 8416)
      • FastPingService.exe (PID: 2620)
      • RDPWInst.exe (PID: 7656)
      • LGPO.exe (PID: 5636)
      • RDP_CnC.exe (PID: 4660)
      • curl.exe (PID: 3332)
      • curl.exe (PID: 6096)
      • curl.exe (PID: 3032)
      • curl.exe (PID: 3588)
      • curl.exe (PID: 7220)
      • cr.exe (PID: 824)
      • UNP%20Setup.exe (PID: 8800)
      • curl.exe (PID: 2780)
      • WxWorkMultiOpen.exe (PID: 4336)
      • formy.exe (PID: 888)
      • dole.exe (PID: 2252)
      • defender.exe (PID: 5500)
      • vcredist_x86_en.exe (PID: 4828)
      • install.exe (PID: 1428)
      • msiexec.exe (PID: 5108)
      • msiexec.exe (PID: 4484)
      • msiexec.exe (PID: 4664)
      • np08w10.tmp (PID: 3304)
      • raw_subprocess.exe (PID: 6940)
      • random.exe (PID: 7196)
      • 37KKS9R5AOV0.exe (PID: 6360)
      • 6AA0.tmp (PID: 2992)
      • identity_helper.exe (PID: 8248)
      • identity_helper.exe (PID: 4784)
      • NoMoreRansom.exe (PID: 4876)
      • TempSpoofer.exe (PID: 4540)
      • Meredrop.exe (PID: 5260)
      • Lab01-02.exe (PID: 2124)
      • svchost.exe (PID: 5016)
      • 1210.exe (PID: 5412)
      • XClient.exe (PID: 1984)
      • 640.exe (PID: 7916)
      • paramssps.exe (PID: 4144)
    • Reads the machine GUID from the registry

      • 4363463463464363463463463.exe (PID: 7452)
      • fastping_silent_v4.exe (PID: 8764)
      • RDPWInst.exe (PID: 7656)
      • FastPingService.exe (PID: 2620)
      • FastPingAgent.exe (PID: 8416)
      • dole.exe (PID: 2252)
      • defender.exe (PID: 5500)
      • vcredist_x86_en.exe (PID: 4828)
      • install.exe (PID: 1428)
      • msiexec.exe (PID: 5108)
      • raw_subprocess.exe (PID: 6940)
      • 37KKS9R5AOV0.exe (PID: 6360)
      • random.exe (PID: 7196)
      • NoMoreRansom.exe (PID: 4876)
      • TempSpoofer.exe (PID: 4540)
      • XClient.exe (PID: 1984)
      • 1210.exe (PID: 5412)
      • svchost.exe (PID: 5016)
      • paramssps.exe (PID: 4144)
    • Disables trace logs

      • 4363463463464363463463463.exe (PID: 7452)
      • defender.exe (PID: 5500)
      • powershell.exe (PID: 4216)
      • TempSpoofer.exe (PID: 4540)
      • svchost.exe (PID: 5016)
    • Checks proxy server information

      • 4363463463464363463463463.exe (PID: 7452)
      • fastping_silent_v4.exe (PID: 8764)
      • RDPWInst.exe (PID: 7656)
      • FastPingService.exe (PID: 2620)
      • FastPingAgent.exe (PID: 8416)
      • formy.exe (PID: 888)
      • defender.exe (PID: 5500)
      • install.exe (PID: 1428)
      • slui.exe (PID: 7220)
      • WerFault.exe (PID: 3368)
      • random.exe (PID: 7196)
      • WerFault.exe (PID: 7920)
      • explorer.exe (PID: 9084)
      • powershell.exe (PID: 4216)
      • TempSpoofer.exe (PID: 4540)
      • explorer.exe (PID: 4972)
      • svchost.exe (PID: 5016)
    • The sample compiled with polish language support

      • 4363463463464363463463463.exe (PID: 7452)
    • Reads security settings of Internet Explorer

      • 4363463463464363463463463.exe (PID: 7452)
      • WMIC.exe (PID: 2248)
      • explorer.exe (PID: 4972)
      • WMIC.exe (PID: 7684)
      • WMIC.exe (PID: 9052)
      • fastping_silent_v4.exe (PID: 8764)
      • RDPWInst.exe (PID: 7656)
      • FastPingService.exe (PID: 2620)
      • FastPingAgent.exe (PID: 8416)
      • formy.exe (PID: 888)
      • UNP%20Setup.exe (PID: 8800)
      • install.exe (PID: 1428)
      • random.exe (PID: 7196)
      • explorer.exe (PID: 1516)
      • 37KKS9R5AOV0.exe (PID: 6360)
      • explorer.exe (PID: 9084)
      • 6AA0.tmp (PID: 2992)
      • TempSpoofer.exe (PID: 4540)
      • 640.exe (PID: 7916)
      • paramssps.exe (PID: 4144)
    • Creates files in the program directory

      • xmr.exe (PID: 2640)
      • xcopy.exe (PID: 6440)
      • xcopy.exe (PID: 7220)
      • xcopy.exe (PID: 6536)
      • RDPWInst.exe (PID: 7656)
      • random.exe (PID: 7196)
      • NoMoreRansom.exe (PID: 4876)
      • np08w10.tmp (PID: 3304)
    • The sample compiled with english language support

      • 4363463463464363463463463.exe (PID: 7452)
      • RDPW_Installer.exe (PID: 8504)
      • xcopy.exe (PID: 7220)
      • xcopy.exe (PID: 6440)
      • RDPWInst.exe (PID: 7656)
      • UNP%20Setup.exe (PID: 8800)
      • vcredist_x86_en.exe (PID: 4828)
      • msiexec.exe (PID: 5108)
      • TiWorker.exe (PID: 5604)
      • msiexec.exe (PID: 5136)
      • raw_subprocess.exe (PID: 6940)
      • 640.exe (PID: 7916)
      • np08w10.tmp (PID: 3304)
    • Drops script file

      • opyhjdase.exe (PID: 9192)
      • RDPW_Installer.exe (PID: 8504)
      • cmd.exe (PID: 6852)
      • xcopy.exe (PID: 6536)
      • powershell.exe (PID: 7244)
      • powershell.exe (PID: 8564)
      • powershell.exe (PID: 8652)
      • 6AA0.tmp (PID: 2992)
      • cmd.exe (PID: 4704)
      • 37KKS9R5AOV0.exe (PID: 6360)
      • cmd.exe (PID: 2256)
      • powershell.exe (PID: 4216)
      • msedge.exe (PID: 7948)
      • riende.exe (PID: 5780)
      • TempSpoofer.exe (PID: 4540)
      • msedge.exe (PID: 3664)
      • msedge.exe (PID: 5764)
      • random.exe (PID: 7196)
      • powershell.exe (PID: 7716)
    • Drops encrypted JS script (Microsoft Script Encoder)

      • opyhjdase.exe (PID: 9192)
    • The sample compiled with japanese language support

      • syswinprdrvc.exe (PID: 6236)
      • vcredist_x86_en.exe (PID: 4828)
      • msiexec.exe (PID: 5108)
      • TiWorker.exe (PID: 5604)
    • The sample compiled with korean language support

      • fastping_silent_v4.exe (PID: 8764)
      • vcredist_x86_en.exe (PID: 4828)
      • msiexec.exe (PID: 5108)
      • TiWorker.exe (PID: 5604)
      • 4363463463464363463463463.exe (PID: 7452)
    • Create files in a temporary directory

      • opyhjdase.exe (PID: 9192)
      • fastping_silent_v4.exe (PID: 8764)
      • RDPW_Installer.exe (PID: 8504)
      • formy.exe (PID: 888)
      • UNP%20Setup.exe (PID: 8800)
      • install.exe (PID: 1428)
      • np08w10.tmp (PID: 3304)
      • np08w10.exe (PID: 2252)
      • 6AA0.tmp (PID: 2992)
      • TempSpoofer.exe (PID: 4540)
      • NoMoreRansom.exe (PID: 4876)
      • svchost.exe (PID: 5016)
    • The sample compiled with Italian language support

      • 4363463463464363463463463.exe (PID: 7452)
      • vcredist_x86_en.exe (PID: 4828)
      • msiexec.exe (PID: 5108)
      • TiWorker.exe (PID: 5604)
    • Creates files or folders in the user directory

      • fastping_silent_v4.exe (PID: 8764)
      • explorer.exe (PID: 4972)
      • RDPWInst.exe (PID: 7656)
      • FastPingService.exe (PID: 2620)
      • formy.exe (PID: 888)
      • dole.exe (PID: 2252)
      • UNP%20Setup.exe (PID: 8800)
      • install.exe (PID: 1428)
      • defender.exe (PID: 5500)
      • raw_subprocess.exe (PID: 6940)
      • random.exe (PID: 7196)
      • WerFault.exe (PID: 7920)
      • WerFault.exe (PID: 3368)
      • XClient.exe (PID: 1984)
    • Creates a software uninstall entry

      • fastping_silent_v4.exe (PID: 8764)
      • msiexec.exe (PID: 5108)
    • RDPWRAP has been detected

      • RDPWInst.exe (PID: 7656)
      • RDP_CnC.exe (PID: 4660)
    • Launching a file from Task Scheduler

      • cmd.exe (PID: 6852)
    • Execution of CURL command

      • cmd.exe (PID: 7348)
      • cmd.exe (PID: 8728)
      • cmd.exe (PID: 8180)
      • cmd.exe (PID: 7724)
      • cmd.exe (PID: 6300)
      • cmd.exe (PID: 8888)
    • Application launched itself

      • msedge.exe (PID: 8800)
      • msedge.exe (PID: 9084)
      • msedge.exe (PID: 4660)
      • msedge.exe (PID: 2640)
      • msedge.exe (PID: 2148)
      • msedge.exe (PID: 5764)
      • chrome.exe (PID: 2860)
      • chrome.exe (PID: 6068)
      • chrome.exe (PID: 7788)
      • chrome.exe (PID: 9412)
    • Manual execution by a user

      • msedge.exe (PID: 9084)
      • msedge.exe (PID: 2148)
    • There is functionality for taking screenshot (YARA)

      • EmmetPROD.exe (PID: 8324)
      • NoEscape.exe (PID: 6272)
      • riende.exe (PID: 5780)
      • prueba.exe (PID: 7620)
      • FastPingService.exe (PID: 2620)
    • The sample compiled with chinese language support

      • 4363463463464363463463463.exe (PID: 7452)
      • vcredist_x86_en.exe (PID: 4828)
      • TiWorker.exe (PID: 5604)
      • msiexec.exe (PID: 5108)
      • np08w10.tmp (PID: 3304)
    • Compiled with Borland Delphi (YARA)

      • riende.exe (PID: 5780)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 8564)
      • powershell.exe (PID: 7244)
      • powershell.exe (PID: 7716)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 7244)
      • powershell.exe (PID: 8564)
      • powershell.exe (PID: 7716)
    • Reads Environment values

      • dole.exe (PID: 2252)
      • defender.exe (PID: 5500)
      • 37KKS9R5AOV0.exe (PID: 6360)
      • identity_helper.exe (PID: 8248)
      • random.exe (PID: 7196)
      • identity_helper.exe (PID: 4784)
      • TempSpoofer.exe (PID: 4540)
    • The sample compiled with german language support

      • vcredist_x86_en.exe (PID: 4828)
      • msiexec.exe (PID: 5108)
      • TiWorker.exe (PID: 5604)
    • The sample compiled with spanish language support

      • vcredist_x86_en.exe (PID: 4828)
      • msiexec.exe (PID: 5108)
      • TiWorker.exe (PID: 5604)
    • The sample compiled with french language support

      • vcredist_x86_en.exe (PID: 4828)
      • msiexec.exe (PID: 5108)
      • TiWorker.exe (PID: 5604)
    • The sample compiled with russian language support

      • vcredist_x86_en.exe (PID: 4828)
      • msiexec.exe (PID: 5108)
      • TiWorker.exe (PID: 5604)
    • Executable content was dropped or overwritten

      • msiexec.exe (PID: 5108)
      • msiexec.exe (PID: 5136)
    • Manages system restore points

      • SrTasks.exe (PID: 1388)
    • Launching a file from the Startup directory

      • raw_subprocess.exe (PID: 6940)
      • XClient.exe (PID: 1984)
    • Reads CPU info

      • 37KKS9R5AOV0.exe (PID: 6360)
      • random.exe (PID: 7196)
    • Reads product name

      • 37KKS9R5AOV0.exe (PID: 6360)
      • random.exe (PID: 7196)
    • Gets data length (POWERSHELL)

      • powershell.exe (PID: 4216)
    • Launching a file from a Registry key

      • NoMoreRansom.exe (PID: 4876)
      • XClient.exe (PID: 1984)
    • Attempt to connect to SMB server

      • Meredrop.exe (PID: 5260)
    • Creating file in SysWOW64

      • 640.exe (PID: 7916)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

Remcos

(PID) Process(7620) prueba.exe
C2 (1)192.168.10.1:2404
BotnetPrueba
Options
Connect_interval1
Install_flagFalse
Install_HKCU\RunTrue
Install_HKLM\RunTrue
Install_HKLM\Explorer\Run0
Install_HKLM\Winlogon\Shell100000
Setup_path%LOCALAPPDATA%
Copy_fileremcos.exe
Startup_valueFalse
Hide_fileFalse
Mutex_nameRmc-7OXI1T
Keylog_flag0
Keylog_path%LOCALAPPDATA%
Keylog_fileregistros.dat
Keylog_cryptFalse
Hide_keylogFalse
Screenshot_flagFalse
Screenshot_time5
Take_ScreenshotFalse
Screenshot_path%APPDATA%
Screenshot_fileCapturas de pantalla
Screenshot_cryptFalse
Mouse_optionFalse
Delete_fileFalse
Audio_record_time5
Audio_path1
Audio_dirMicRecords
Connect_delay0
Copy_dirRemcos
Keylog_dirremcos
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (82.9)
.dll | Win32 Dynamic Link Library (generic) (7.4)
.exe | Win32 Executable (generic) (5.1)
.exe | Generic Win/DOS Executable (2.2)
.exe | DOS Executable Generic (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:12:22 08:29:10+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 80
CodeSize: 5632
InitializedDataSize: 4608
UninitializedDataSize: -
EntryPoint: 0x3552
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
FileDescription:
FileVersion: 0.0.0.0
InternalName: 4363463463464363463463463.exe
LegalCopyright:
OriginalFileName: 4363463463464363463463463.exe
ProductVersion: 0.0.0.0
AssemblyVersion: 0.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
465
Monitored processes
289
Malicious processes
33
Suspicious processes
11

Behavior graph

Click at the process to see the details
start #GENERIC 4363463463464363463463463.exe conhost.exe no specs emmetprod.exe conhost.exe no specs cmd.exe no specs wmic.exe no specs wmic.exe no specs #NOESCAPE noescape.exe no specs wmic.exe no specs ipconfig.exe no specs find.exe no specs find.exe no specs find.exe no specs #COINMINER xmr.exe opyhjdase.exe conhost.exe no specs taskkill.exe no specs taskkill.exe no specs sc.exe no specs conhost.exe no specs sc.exe no specs conhost.exe no specs taskkill.exe no specs sc.exe no specs sc.exe no specs conhost.exe no specs conhost.exe no specs taskkill.exe no specs THREAT syswinprdrvc.exe #MINER dwm.exe taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs fastping_silent_v4.exe taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs rdpw_installer.exe conhost.exe no specs cmd.exe no specs ogfn%20updater.exe no specs conhost.exe no specs rdpwinst.exe no specs ping.exe no specs cmd.exe no specs riende.exe #REMCOS prueba.exe conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs xcopy.exe fastpingagent.exe xcopy.exe schtasks.exe no specs xcopy.exe no specs conhost.exe no specs xcopy.exe no specs THREAT rdpwinst.exe fastpingservice.exe cmd.exe no specs netsh.exe no specs netsh.exe no specs lgpo.exe no specs schtasks.exe no specs cmd.exe no specs rdp_cnc.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs cmd.exe no specs curl.exe cmd.exe no specs cmd.exe no specs cmd.exe no specs loader.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs cmd.exe no specs curl.exe cmd.exe no specs curl.exe cmd.exe no specs curl.exe cmd.exe no specs curl.exe cmd.exe no specs curl.exe cmd.exe no specs cmd.exe no specs msedge.exe no specs cr.exe no specs slui.exe unp%20setup.exe #QUASAR formy.exe wxworkmultiopen.exe no specs conhost.exe no specs powershell.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs powershell.exe no specs #QUASAR dole.exe schtasks.exe no specs conhost.exe no specs #QUASAR defender.exe schtasks.exe no specs conhost.exe no specs #PHISHING svchost.exe vcredist_x86_en.exe install.exe msiexec.exe tiworker.exe msiexec.exe msiexec.exe no specs vssvc.exe no specs srtasks.exe no specs conhost.exe no specs msiexec.exe no specs news_01.exe no specs np08w10.exe np08w10.tmp 37kks9r5aov0.exe powershell.exe no specs conhost.exe no specs #BARYS raw_subprocess.exe random.exe msedge.exe no specs firefox.exe msedge.exe chrome.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs werfault.exe msedge.exe werfault.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs haeum.exe 6aa0.tmp no specs cmd.exe no specs conhost.exe no specs explorer.exe no specs explorer.exe cmd.exe no specs conhost.exe no specs #SANTASTEALER powershell.exe conhost.exe no specs msedge.exe no specs msedge.exe no specs attrib.exe no specs attrib.exe no specs reg.exe no specs reg.exe no specs reg.exe no specs schtasks.exe no specs schtasks.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs identity_helper.exe no specs identity_helper.exe no specs cabalmain.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs #TROLDESH nomoreransom.exe msedge.exe no specs msedge.exe no specs tempspoofer.exe #SMBSCAN meredrop.exe #EMOTET 640.exe no specs #EMOTET 640.exe lab01-02.exe no specs conhost.exe no specs 1210.exe conhost.exe no specs #XWORM xclient.exe win.exe no specs svchost.exe cmd.exe no specs conhost.exe no specs powershell.exe no specs #EMOTET paramssps.exe no specs #EMOTET paramssps.exe schtasks.exe no specs conhost.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs explorer.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs chrome.exe no specs 4363463463464363463463463.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
144C:\WINDOWS\system32\cmd.exe /c echo offC:\Windows\System32\cmd.exeOGFN%20Updater.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
224taskkill /F /IM iridium.exe /TC:\Windows\System32\taskkill.exeopyhjdase.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
404"C:\WINDOWS\system32\attrib.exe" +h +s C:\Users\admin\AppData\Local\Microsoft\OfficeBrokerC:\Windows\System32\attrib.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Attribute Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\attrib.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
492"C:\Program Files\Google\Chrome\Application\chrome.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --disable-quic --string-annotations --field-trial-handle=2384,i,398488096789626468,4058586269550167848,262144 --variations-seed-version=20260214-030037.053000-production --mojo-platform-channel-handle=2400 /prefetch:8C:\Program Files\Google\Chrome\Application\chrome.exechrome.exe
User:
admin
Company:
Google LLC
Integrity Level:
LOW
Description:
Google Chrome
Version:
133.0.6943.127
Modules
Images
c:\program files\google\chrome\application\chrome.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\google\chrome\application\133.0.6943.127\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
676\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
772"cmd.exe" /c powershell -Command "Add-MpPreference -ExclusionPath 'C:\'"C:\Windows\SysWOW64\cmd.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
824"C:\Users\admin\Desktop\Files\cr.exe" C:\Users\admin\Desktop\Files\cr.exe4363463463464363463463463.exe
User:
admin
Integrity Level:
HIGH
Exit code:
4294967295
Modules
Images
c:\users\admin\desktop\files\cr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
824"C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exe" --type=utility --utility-sub-type=winrt_app_id.mojom.WinrtAppIdService --lang=en-US --service-sandbox-type=none --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=4708,i,16698670406283006126,11161999783937906616,262144 --variations-seed-version --mojo-platform-channel-handle=4748 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\133.0.3065.92\identity_helper.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
PWA Identity Proxy Host
Exit code:
3221226029
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\identity_helper.exe
c:\windows\system32\ntdll.dll
876netsh advfirewall firewall add rule name="Remote Desktop" dir=in protocol=udp localport=3389 profile=any action=allowC:\Windows\System32\netsh.exeRDPWInst.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
888find "[1]"C:\Windows\SysWOW64\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\find.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
Total events
99 169
Read events
98 238
Write events
779
Delete events
152

Modification events

(PID) Process:(4972) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Security and Maintenance\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0
Operation:writeName:CheckSetting
Value:
23004100430042006C006F00620000000000000000000000010000000000000000000000
(PID) Process:(4972) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\SessionInfo\1\ApplicationViewManagement\W32:0000000000220374
Operation:writeName:VirtualDesktop
Value:
1000000030304456E9BC50E45F05DB4C86F7D791C25A96C7
(PID) Process:(7452) 4363463463464363463463463.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\4363463463464363463463463_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(7452) 4363463463464363463463463.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\4363463463464363463463463_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(7452) 4363463463464363463463463.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\4363463463464363463463463_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(7452) 4363463463464363463463463.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\4363463463464363463463463_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(7452) 4363463463464363463463463.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\4363463463464363463463463_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(7452) 4363463463464363463463463.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\4363463463464363463463463_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(7452) 4363463463464363463463463.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\4363463463464363463463463_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(7452) 4363463463464363463463463.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\4363463463464363463463463_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
Executable files
176
Suspicious files
637
Text files
1 432
Unknown types
12

Dropped files

PID
Process
Filename
Type
74524363463463464363463463463.exeC:\Users\admin\Desktop\Files\EmmetPROD.exeexecutable
MD5:D62A00606FB383476DB2C7F057F417F2
SHA256:EBE24F9D635E5A1FF23E1B0F41828FFE1B7B0E6DE8897EB01CA68FCB0D3B095F
4972explorer.exeC:\Users\admin\AppData\Local\Microsoft\PenWorkspace\DiscoverCacheData.datbinary
MD5:E49C56350AEDF784BFE00E444B879672
SHA256:A8BD235303668981563DFB5AAE338CB802817C4060E2C199B7C84901D57B7E1E
74524363463463464363463463463.exeC:\Users\admin\Desktop\Files\02.08.2022.exebinary
MD5:27BFEBE23630FF1153EA8A01962D8C61
SHA256:55FD811ED25C1868F638133F0C98A2FB8C23E6D84CB19E6E624BAD6155B5B925
74524363463463464363463463463.exeC:\Users\admin\Desktop\Files\xmr.exeexecutable
MD5:083D5895283755A910B5C59D60A5348B
SHA256:9639F7EBC6A6D69D7BF5B8BC869E7783A1406088F192868624AD8919E9BFD1D4
74524363463463464363463463463.exeC:\Users\admin\Desktop\Files\NoEscape.exeexecutable
MD5:989AE3D195203B323AA2B3ADF04E9833
SHA256:D30D7676A3B4C91B77D403F81748EBF6B8824749DB5F860E114A8A204BCA5B8F
74524363463463464363463463463.exeC:\Users\admin\Desktop\Files\opyhjdase.exeexecutable
MD5:0D53256905411410FCFBBBCDA13ABDBB
SHA256:D336273CEE697DEC1B8F9E1643005A2CD8B80305E9F8DC257AB69D2322F38927
9192opyhjdase.exeC:\Users\admin\AppData\Local\Temp\History_4.tempbinary
MD5:15689BCA2327BD6439BB5A321BFF1115
SHA256:1513329660C876E166FDE7919D705ECFA5339732849159685C59847BE92B7478
2640xmr.exeC:\ProgramData\winmgr\syswinprdrvc.exeexecutable
MD5:083D5895283755A910B5C59D60A5348B
SHA256:9639F7EBC6A6D69D7BF5B8BC869E7783A1406088F192868624AD8919E9BFD1D4
9192opyhjdase.exeC:\Users\admin\AppData\Local\Temp\History_5.tempbinary
MD5:15689BCA2327BD6439BB5A321BFF1115
SHA256:1513329660C876E166FDE7919D705ECFA5339732849159685C59847BE92B7478
9192opyhjdase.exeC:\Users\admin\AppData\Local\Temp\Login Data_1.tempbinary
MD5:A45465CDCDC6CB30C8906F3DA4EC114C
SHA256:4412319EF944EBCCA9581CBACB1D4E1DC614C348D1DFC5D2FAAAAD863D300209
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
179
TCP/UDP connections
15 939
DNS requests
254
Threats
219

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7452
4363463463464363463463463.exe
GET
302
140.82.121.4:443
https://github.com/trasherwithadollarsign/Trashers-Malware-Repo/raw/main/Trojan/NoEscape.exe
US
unknown
5568
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAjTxtAB8my1oj8MfWpz%2F7Y%3D
US
binary
313 b
whitelisted
5568
SearchApp.exe
GET
200
204.79.197.203:80
http://oneocsp.microsoft.com/ocsp/MFQwUjBQME4wTDAJBgUrDgMCGgUABBQ3L3%2F%2Fa6ADK8NraY2GXzVaYrHG4AQUb6t%2B2v%2BXQ3LsO2d33oJhNYhHQoUCEzMAAAAGb6JMMcOVb6sAAAAAAAY%3D
US
binary
960 b
whitelisted
7452
4363463463464363463463463.exe
GET
200
151.101.194.49:443
https://urlhaus.abuse.ch/downloads/text_online/
US
text
800 Kb
unknown
356
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
7452
4363463463464363463463463.exe
GET
200
117.72.220.129:5555
http://117.72.220.129:5555/02.08.2022.exe
CN
binary
234 Kb
unknown
356
svchost.exe
POST
200
40.126.31.71:443
https://login.live.com/RST2.srf
US
11.1 Kb
whitelisted
356
svchost.exe
POST
200
40.126.31.71:443
https://login.live.com/RST2.srf
US
10.3 Kb
whitelisted
7452
4363463463464363463463463.exe
GET
302
140.82.121.4:443
https://github.com/sebaxakerhtc/rdpwrap/releases/download/v1.8.9.9/RDPW_Installer.exe
US
unknown
5412
svchost.exe
GET
200
2.21.23.11:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
5412
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7228
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5568
SearchApp.exe
2.16.106.196:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
5568
SearchApp.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
5568
SearchApp.exe
204.79.197.203:80
oneocsp.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
3412
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
7452
4363463463464363463463463.exe
151.101.194.49:443
urlhaus.abuse.ch
FASTLY
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
whitelisted
google.com
  • 172.217.17.78
whitelisted
self.events.data.microsoft.com
  • 20.42.72.131
  • 20.42.65.88
whitelisted
www.bing.com
  • 2.16.106.196
  • 2.16.106.200
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
oneocsp.microsoft.com
  • 204.79.197.203
whitelisted
client.wns.windows.com
  • 172.211.123.249
  • 172.211.123.250
whitelisted
urlhaus.abuse.ch
  • 151.101.194.49
  • 151.101.130.49
  • 151.101.2.49
  • 151.101.66.49
whitelisted
login.live.com
  • 40.126.31.71
  • 40.126.31.3
  • 20.190.159.0
  • 20.190.159.131
  • 40.126.31.2
  • 40.126.31.128
  • 40.126.31.129
  • 20.190.159.2
  • 20.190.159.64
  • 40.126.31.0
  • 20.190.159.73
  • 40.126.31.1
  • 40.126.31.67
  • 20.190.159.4
  • 20.190.159.128
whitelisted
crl.microsoft.com
  • 2.21.23.11
  • 2.21.23.19
  • 184.24.77.42
  • 184.24.77.41
  • 184.24.77.37
  • 184.24.77.38
  • 184.24.77.6
  • 184.24.77.30
  • 184.24.77.34
  • 184.24.77.31
  • 184.24.77.11
whitelisted

Threats

PID
Process
Class
Message
5412
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
7452
4363463463464363463463463.exe
Potentially Bad Traffic
ET INFO PE EXE or DLL Windows file download HTTP
7452
4363463463464363463463463.exe
Misc activity
ET INFO EXE - Served Attached HTTP
7452
4363463463464363463463463.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
8324
EmmetPROD.exe
Not Suspicious Traffic
INFO [ANY.RUN] Websocket Upgrade Request
2292
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
8324
EmmetPROD.exe
Not Suspicious Traffic
INFO [ANY.RUN] Socket.IO requests event-based bidirectional communication via HTTP
7452
4363463463464363463463463.exe
Misc activity
INFO [ANY.RUN] Connection to IP from commonly abused ASN (AS214943 RAILNET)
7452
4363463463464363463463463.exe
Potentially Bad Traffic
ET INFO PE EXE or DLL Windows file download HTTP
7452
4363463463464363463463463.exe
Potentially Bad Traffic
ET MALWARE Terse alphanumeric executable downloader high likelihood of being hostile
Process
Message
4363463463464363463463463.exe
The specified executable is not a valid application for this OS platform.
riende.exe
-139513856
riende.exe
-149266432
riende.exe
-205099008
riende.exe
-208404480
riende.exe
-317157376
riende.exe
-326017024
riende.exe
-443056128
riende.exe
-462823424
riende.exe
-495161344