File name:

protected_app.exe

Full analysis: https://app.any.run/tasks/64206507-eceb-4f3b-9854-68a5f00c5d82
Verdict: Malicious activity
Analysis date: July 06, 2025, 00:15:43
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
python
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 7 sections
MD5:

AFA0E3CA466637CCA8ACB9E18004468E

SHA1:

D96B1C1D7220771A39F015B59F20D7B91069F989

SHA256:

30D0A54CE7DF22647A18C3FCFCFEA08A37F18FC00530023CFCB3DA85AC29FC90

SSDEEP:

98304:5C3CpA4Jjs6S0QneeQrhuZzpvRERRdopaZOl/QOsIgMb1mB75kzlUzUjGNgLN71I:MyxGvfkK881mwe/kil9UHlI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops python dynamic module

      • protected_app.exe (PID: 2976)
    • Executable content was dropped or overwritten

      • protected_app.exe (PID: 2976)
      • protected_app.exe (PID: 6584)
    • Process drops legitimate windows executable

      • protected_app.exe (PID: 2976)
    • The process drops C-runtime libraries

      • protected_app.exe (PID: 2976)
    • Application launched itself

      • protected_app.exe (PID: 2976)
    • Loads Python modules

      • protected_app.exe (PID: 6584)
  • INFO

    • The sample compiled with english language support

      • protected_app.exe (PID: 2976)
    • Checks supported languages

      • protected_app.exe (PID: 2976)
      • protected_app.exe (PID: 6584)
    • Reads the computer name

      • protected_app.exe (PID: 2976)
    • Create files in a temporary directory

      • protected_app.exe (PID: 2976)
      • protected_app.exe (PID: 6584)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:07:06 00:11:06+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.43
CodeSize: 174592
InitializedDataSize: 157184
UninitializedDataSize: -
EntryPoint: 0xd0d0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start protected_app.exe protected_app.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2976"C:\Users\admin\AppData\Local\Temp\protected_app.exe" C:\Users\admin\AppData\Local\Temp\protected_app.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\protected_app.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6216C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6584"C:\Users\admin\AppData\Local\Temp\protected_app.exe" C:\Users\admin\AppData\Local\Temp\protected_app.exe
protected_app.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\protected_app.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
390
Read events
390
Write events
0
Delete events
0

Modification events

No data
Executable files
105
Suspicious files
1
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
2976protected_app.exeC:\Users\admin\AppData\Local\Temp\_MEI29762\Crypto\Cipher\_Salsa20.pydexecutable
MD5:17C99EDF022309BC2C54A732FB8FBF26
SHA256:34EB9C505180358711D8D6268E3F0E700C58AC9F47B0AD68565ED73BAB5DBD81
2976protected_app.exeC:\Users\admin\AppData\Local\Temp\_MEI29762\Crypto\Cipher\_raw_arc2.pydexecutable
MD5:530BB99610B35527C3B06A22FD92CCEC
SHA256:43BC2F864D062BF7FE940E9CC497EF4FDFCC6EAEAB95FD4D4EE837E4D5DE0437
2976protected_app.exeC:\Users\admin\AppData\Local\Temp\_MEI29762\Crypto\Hash\_BLAKE2s.pydexecutable
MD5:EFB1F498321597F1AAF7FB6A57603C76
SHA256:2A8CA6C6E864F0F5DE6E22736D461AEC5AFA45B4CB77449731AFC0861C20C23D
2976protected_app.exeC:\Users\admin\AppData\Local\Temp\_MEI29762\Crypto\Cipher\_raw_des.pydexecutable
MD5:A2DE9A3A802296D900F1630358EBA28D
SHA256:DA5E3E81F96EC3CBE7C9587344421F86E422A6E74A022E565FD6184FB03BBA1C
2976protected_app.exeC:\Users\admin\AppData\Local\Temp\_MEI29762\Crypto\Cipher\_raw_ctr.pydexecutable
MD5:3D0FB2250C76B501ABF008D8E6180594
SHA256:E5E2B54591D4CA2DC43F6D0FFDBFF45393D092E9E37C072FFE7B8769EEC3B82E
2976protected_app.exeC:\Users\admin\AppData\Local\Temp\_MEI29762\Crypto\Cipher\_raw_eksblowfish.pydexecutable
MD5:B6037CEAA162C50FC25F1B361B4250C9
SHA256:605AECF52ACD7D17B7B1000AEEDEE6C0601D6BC5F753756E7EE70A83F44FCCB2
2976protected_app.exeC:\Users\admin\AppData\Local\Temp\_MEI29762\Crypto\Cipher\_raw_cbc.pydexecutable
MD5:088A5FDA312EC2E1957E83D530F9BB8F
SHA256:FD5AC5C38172A303A274D2B8D1E9B794380773F50350453EAE3117724134EDE1
2976protected_app.exeC:\Users\admin\AppData\Local\Temp\_MEI29762\Crypto\Cipher\_raw_ocb.pydexecutable
MD5:35B044D9ECD823161EF267517BA88509
SHA256:3B236F9148645B4CE4375D2BEE7844F4F5D381746F4A33492A3C35C2B156DE4D
2976protected_app.exeC:\Users\admin\AppData\Local\Temp\_MEI29762\Crypto\Cipher\_raw_ofb.pydexecutable
MD5:A2B9F1DB81EE431F07A848F44153518F
SHA256:CD11346BDC23F15D68701C3F602B621BB7C93CF1AAA193FF079225603514122D
2976protected_app.exeC:\Users\admin\AppData\Local\Temp\_MEI29762\Crypto\Cipher\_raw_ecb.pydexecutable
MD5:B9F8151C65BDAF81BF9407A32E77959B
SHA256:ED154E6C22235659E57532B0A8B3CD7A081603C6CAE9CB165E436006881C1C74
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
22
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
2.20.245.137:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
7076
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2468
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2468
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6128
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
2.20.245.137:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
1268
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
7076
svchost.exe
20.190.160.66:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7076
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2336
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
google.com
  • 142.250.184.206
whitelisted
crl.microsoft.com
  • 2.20.245.137
  • 2.20.245.139
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 184.30.21.171
whitelisted
login.live.com
  • 20.190.160.66
  • 20.190.160.20
  • 20.190.160.132
  • 40.126.32.74
  • 20.190.160.65
  • 20.190.160.5
  • 40.126.32.76
  • 20.190.160.64
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
nexusrules.officeapps.live.com
  • 52.111.243.29
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted

Threats

No threats detected
No debug info