File name:

x318b10a24a51a601bb7209c69b593ac487b6c0a6e7d63a461048ce1fe506720a.exe

Full analysis: https://app.any.run/tasks/e3b48f04-2fa9-4e82-9201-417f67ad77c8
Verdict: Malicious activity
Threats:

Amadey is a formidable Windows infostealer threat, characterized by its persistence mechanisms, modular design, and ability to execute various malicious tasks.

Analysis date: May 24, 2026, 05:11:15
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto-sch
stealc
stealer
auto-reg
payload
arch-doc
nuitka
amadey
botnet
python
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 7 sections
MD5:

7B82C72EC6FC0B5AF4B7FDCD6CB58D74

SHA1:

CA03E9B904DA6BE0891B3B816473720AAF261931

SHA256:

318B10A24A51A601BB7209C69B593AC487B6C0A6E7D63A461048CE1FE506720A

SSDEEP:

196608:jtFg5Phkd69LewhUMEUc4B3AAQKkYJuEpR+Nj0In:j7wkoZ0MEUc49AJ/YJhpRgAIn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • STEALC has been detected

      • ngbkpzuq.exe (PID: 3580)
    • Changes the autorun value in the registry

      • tj38atmk.exe (PID: 7724)
      • 5uyxm5fr.exe (PID: 8060)
      • zy8kr7t5.exe (PID: 7760)
      • 63yg0gki.exe (PID: 4816)
    • Uses Task Scheduler to run other applications

      • tj38atmk.exe (PID: 7724)
    • Application was injected by another process

      • explorer.exe (PID: 4696)
      • RuntimeBroker.exe (PID: 5728)
      • RuntimeBroker.exe (PID: 5232)
      • RuntimeBroker.exe (PID: 7308)
      • sihost.exe (PID: 4412)
      • RuntimeBroker.exe (PID: 6548)
    • Runs injected code in another process

      • 5uyxm5fr.exe (PID: 8060)
      • zy8kr7t5.exe (PID: 7760)
      • iijg3iv5.exe (PID: 2996)
    • Changes the login/logoff helper path in the registry

      • iijg3iv5.exe (PID: 2996)
    • AMADEY has been detected (SURICATA)

      • kxxmu.exe (PID: 4968)
    • STEALC has been detected (SURICATA)

      • ngbkpzuq.exe (PID: 3580)
    • Stealers network behavior

      • ngbkpzuq.exe (PID: 3580)
  • SUSPICIOUS

    • Reads the date of Windows installation

      • x318b10a24a51a601bb7209c69b593ac487b6c0a6e7d63a461048ce1fe506720a.exe (PID: 2528)
      • tj38atmk.exe (PID: 7724)
      • iijg3iv5.exe (PID: 2996)
      • 63yg0gki.exe (PID: 4816)
      • kxxmu.exe (PID: 4968)
    • Executable content was dropped or overwritten

      • x318b10a24a51a601bb7209c69b593ac487b6c0a6e7d63a461048ce1fe506720a.exe (PID: 2528)
      • tj38atmk.exe (PID: 7724)
      • 5uyxm5fr.exe (PID: 8060)
      • iijg3iv5.exe (PID: 2996)
      • l7lm2ai3.exe (PID: 7672)
      • 63yg0gki.exe (PID: 4816)
      • kxxmu.exe (PID: 4968)
    • Executable file located in non-executable user directories

      • tj38atmk.exe (PID: 7724)
      • svchost.exe (PID: 6500)
      • explorer.exe (PID: 4696)
    • The process creates files with name similar to system file names

      • tj38atmk.exe (PID: 7724)
      • iijg3iv5.exe (PID: 2996)
    • Lists all scheduled tasks

      • schtasks.exe (PID: 4308)
    • The process executes files with name similar to system file names

      • explorer.exe (PID: 4696)
    • Possible stealing of messenger data

      • zh3ri4au.exe (PID: 4960)
    • Possible stealing from crypto wallets

      • zh3ri4au.exe (PID: 4960)
    • Potential Corporate Privacy Violation

      • zh3ri4au.exe (PID: 4960)
    • NUITKA compiler has been detected

      • l7lm2ai3.exe (PID: 7672)
    • Process drops python dynamic module

      • l7lm2ai3.exe (PID: 7672)
    • The process drops C-runtime libraries

      • l7lm2ai3.exe (PID: 7672)
    • Starts itself from another location

      • 63yg0gki.exe (PID: 4816)
    • Application launched itself

      • l7lm2ai3.exe (PID: 7672)
    • The process executes via Task Scheduler

      • tpjdzj.exe (PID: 6672)
      • tpjdzj.exe (PID: 7924)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 4308)
    • Loads Python modules

      • l7lm2ai3.exe (PID: 736)
  • INFO

    • Reads security settings of Internet Explorer

      • x318b10a24a51a601bb7209c69b593ac487b6c0a6e7d63a461048ce1fe506720a.exe (PID: 2528)
      • explorer.exe (PID: 4696)
      • ngbkpzuq.exe (PID: 3580)
      • tj38atmk.exe (PID: 7724)
      • zh3ri4au.exe (PID: 4960)
      • iijg3iv5.exe (PID: 2996)
      • notepad.exe (PID: 5588)
      • notepad.exe (PID: 6260)
      • 63yg0gki.exe (PID: 4816)
      • kxxmu.exe (PID: 4968)
      • notepad.exe (PID: 2120)
    • Checks supported languages

      • x318b10a24a51a601bb7209c69b593ac487b6c0a6e7d63a461048ce1fe506720a.exe (PID: 2528)
      • ngbkpzuq.exe (PID: 3580)
      • tj38atmk.exe (PID: 7724)
      • tpjdzj.exe (PID: 4240)
      • 5uyxm5fr.exe (PID: 8060)
      • svchost.exe (PID: 6500)
      • zy8kr7t5.exe (PID: 7760)
      • zh3ri4au.exe (PID: 4960)
      • iijg3iv5.exe (PID: 2996)
      • WindowsStore.Update.exe (PID: 7456)
      • l7lm2ai3.exe (PID: 7672)
      • s6nqleiu.exe (PID: 1980)
      • 63yg0gki.exe (PID: 4816)
      • kxxmu.exe (PID: 4968)
      • tpjdzj.exe (PID: 6672)
      • kxxmu.exe (PID: 3416)
      • BKXOISLQ.exe (PID: 7408)
      • l7lm2ai3.exe (PID: 736)
      • 8dax6u8n.exe (PID: 5100)
      • tpjdzj.exe (PID: 7924)
    • Reads the computer name

      • x318b10a24a51a601bb7209c69b593ac487b6c0a6e7d63a461048ce1fe506720a.exe (PID: 2528)
      • ngbkpzuq.exe (PID: 3580)
      • 5uyxm5fr.exe (PID: 8060)
      • tj38atmk.exe (PID: 7724)
      • zy8kr7t5.exe (PID: 7760)
      • zh3ri4au.exe (PID: 4960)
      • iijg3iv5.exe (PID: 2996)
      • 63yg0gki.exe (PID: 4816)
      • kxxmu.exe (PID: 4968)
      • l7lm2ai3.exe (PID: 736)
    • Create files in a temporary directory

      • x318b10a24a51a601bb7209c69b593ac487b6c0a6e7d63a461048ce1fe506720a.exe (PID: 2528)
      • 5uyxm5fr.exe (PID: 8060)
      • iijg3iv5.exe (PID: 2996)
      • l7lm2ai3.exe (PID: 7672)
      • kxxmu.exe (PID: 4968)
    • The sample compiled with english language support

      • x318b10a24a51a601bb7209c69b593ac487b6c0a6e7d63a461048ce1fe506720a.exe (PID: 2528)
      • tj38atmk.exe (PID: 7724)
      • iijg3iv5.exe (PID: 2996)
      • l7lm2ai3.exe (PID: 7672)
      • kxxmu.exe (PID: 4968)
    • Process checks computer location settings

      • x318b10a24a51a601bb7209c69b593ac487b6c0a6e7d63a461048ce1fe506720a.exe (PID: 2528)
      • tj38atmk.exe (PID: 7724)
      • iijg3iv5.exe (PID: 2996)
      • 63yg0gki.exe (PID: 4816)
      • kxxmu.exe (PID: 4968)
    • Creates files or folders in the user directory

      • tj38atmk.exe (PID: 7724)
      • 5uyxm5fr.exe (PID: 8060)
      • iijg3iv5.exe (PID: 2996)
    • Launching a file from a Registry key

      • tj38atmk.exe (PID: 7724)
      • 5uyxm5fr.exe (PID: 8060)
      • zy8kr7t5.exe (PID: 7760)
      • 63yg0gki.exe (PID: 4816)
    • Manual execution by a user

      • tpjdzj.exe (PID: 4240)
      • svchost.exe (PID: 6500)
      • WindowsStore.Update.exe (PID: 7456)
      • notepad.exe (PID: 5588)
      • notepad.exe (PID: 2120)
      • notepad.exe (PID: 6260)
      • kxxmu.exe (PID: 3416)
    • Launching a file from Task Scheduler

      • tj38atmk.exe (PID: 7724)
    • Reads the machine GUID from the registry

      • 63yg0gki.exe (PID: 4816)
      • kxxmu.exe (PID: 4968)
      • l7lm2ai3.exe (PID: 736)
    • Checks operating system version

      • l7lm2ai3.exe (PID: 736)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2026:05:22 23:55:11+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.29
CodeSize: 44032
InitializedDataSize: 20839424
UninitializedDataSize: -
EntryPoint: 0x1718
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
161
Monitored processes
35
Malicious processes
10
Suspicious processes
4

Behavior graph

Click at the process to see the details
start x318b10a24a51a601bb7209c69b593ac487b6c0a6e7d63a461048ce1fe506720a.exe #STEALC ngbkpzuq.exe tj38atmk.exe schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs tpjdzj.exe no specs 5uyxm5fr.exe svchost.exe no specs zy8kr7t5.exe zh3ri4au.exe windowsstore.update.exe no specs iijg3iv5.exe s6nqleiu.exe no specs l7lm2ai3.exe 63yg0gki.exe notepad.exe no specs notepad.exe no specs notepad.exe no specs #AMADEY kxxmu.exe kxxmu.exe no specs bkxoislq.exe no specs tpjdzj.exe no specs l7lm2ai3.exe no specs cmd.exe no specs conhost.exe no specs 8dax6u8n.exe no specs tpjdzj.exe no specs sihost.exe explorer.exe runtimebroker.exe runtimebroker.exe runtimebroker.exe runtimebroker.exe

Process information

PID
CMD
Path
Indicators
Parent process
736C:\Users\admin\AppData\Local\Temp\l7lm2ai3.exeC:\Users\admin\AppData\Local\Temp\l7lm2ai3.exel7lm2ai3.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\l7lm2ai3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
1980"C:\Users\admin\AppData\Local\Temp\s6nqleiu.exe" C:\Users\admin\AppData\Local\Temp\s6nqleiu.exeiijg3iv5.exe
User:
admin
Company:
Microsoft Windows Host
Integrity Level:
MEDIUM
Description:
Microsoft Windows Host
Exit code:
2
Version:
2.2.0.1
Modules
Images
c:\users\admin\appdata\local\temp\s6nqleiu.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2120"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\\Info.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
2528"C:\Users\admin\Desktop\x318b10a24a51a601bb7209c69b593ac487b6c0a6e7d63a461048ce1fe506720a.exe" C:\Users\admin\Desktop\x318b10a24a51a601bb7209c69b593ac487b6c0a6e7d63a461048ce1fe506720a.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\x318b10a24a51a601bb7209c69b593ac487b6c0a6e7d63a461048ce1fe506720a.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
2996"C:\Users\admin\AppData\Local\Temp\iijg3iv5.exe" C:\Users\admin\AppData\Local\Temp\iijg3iv5.exe
x318b10a24a51a601bb7209c69b593ac487b6c0a6e7d63a461048ce1fe506720a.exe
User:
admin
Company:
Maxtor Corporation
Integrity Level:
MEDIUM
Description:
Python Core Runtime
Version:
7.4.6210.42
Modules
Images
c:\users\admin\appdata\local\temp\iijg3iv5.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
3416C:\ProgramData\kxxmu.exeC:\ProgramData\kxxmu.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\programdata\kxxmu.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wininet.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3580"C:\Users\admin\AppData\Local\Temp\ngbkpzuq.exe" C:\Users\admin\AppData\Local\Temp\ngbkpzuq.exe
x318b10a24a51a601bb7209c69b593ac487b6c0a6e7d63a461048ce1fe506720a.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\ngbkpzuq.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4240C:\Users\admin\AppData\Roaming\tpjdzj.exeC:\Users\admin\AppData\Roaming\tpjdzj.exeexplorer.exe
User:
admin
Company:
Microsoft Windows Host
Integrity Level:
MEDIUM
Description:
Microsoft Windows Host
Exit code:
2
Version:
2.2.0.1
Modules
Images
c:\users\admin\appdata\roaming\tpjdzj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
4308"C:\Windows\System32\schtasks.exe" /query /tn "Google Updater Task"C:\Windows\System32\schtasks.exetj38atmk.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Scheduler Configuration Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
4308C:\WINDOWS\system32\cmd.exe /c "ver"C:\Windows\System32\cmd.exel7lm2ai3.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
Total events
7 023
Read events
6 990
Write events
33
Delete events
0

Modification events

(PID) Process:(4696) explorer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Security and Maintenance\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0
Operation:writeName:CheckSetting
Value:
23004100430042006C006F00620000000000000000000000010000000800000000000000
(PID) Process:(3580) ngbkpzuq.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(3580) ngbkpzuq.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3580) ngbkpzuq.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(7724) tj38atmk.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Microsoft Windows Host
Value:
C:\Users\admin\Pictures\svchost.exe
(PID) Process:(8060) 5uyxm5fr.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:WindowsSvcHost
Value:
C:\Users\admin\AppData\Local\Microsoft\WindowsApps\WindowsStore.Update.exe
(PID) Process:(7760) zy8kr7t5.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Windows Defender Security
Value:
C:\Users\admin\AppData\Local\Temp\zy8kr7t5.exe
(PID) Process:(4960) zh3ri4au.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4960) zh3ri4au.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4960) zh3ri4au.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
46
Suspicious files
7
Text files
885
Unknown types
49

Dropped files

PID
Process
Filename
Type
2528x318b10a24a51a601bb7209c69b593ac487b6c0a6e7d63a461048ce1fe506720a.exeC:\Users\admin\AppData\Local\Temp\tj38atmk.exeexecutable
MD5:5FCF42E6A22A4675A1C2E22383B86C23
SHA256:DF4AA1196A8A025EACBCF0316A4F533B489F254BB260E7157FAD9556FE3C5925
2528x318b10a24a51a601bb7209c69b593ac487b6c0a6e7d63a461048ce1fe506720a.exeC:\Users\admin\AppData\Local\Temp\ngbkpzuq.exeexecutable
MD5:F87FD8891C767F0695E85728F238D33B
SHA256:EFE7EB517CC449CC7721C5C0ACFB8CF454F28FDF2F37C08854AAD4DEEFD7EDC9
7672l7lm2ai3.exeC:\Users\admin\AppData\Local\Temp\onefile_7672_134240730929644639\main.dll
MD5:
SHA256:
7724tj38atmk.exeC:\Users\admin\AppData\Roaming\tpjdzj.exeexecutable
MD5:5FCF42E6A22A4675A1C2E22383B86C23
SHA256:DF4AA1196A8A025EACBCF0316A4F533B489F254BB260E7157FAD9556FE3C5925
7724tj38atmk.exeC:\Users\admin\Pictures\svchost.exeexecutable
MD5:5FCF42E6A22A4675A1C2E22383B86C23
SHA256:DF4AA1196A8A025EACBCF0316A4F533B489F254BB260E7157FAD9556FE3C5925
80605uyxm5fr.exeC:\Users\admin\AppData\Local\Microsoft\WindowsApps\WindowsStore.Update.exeexecutable
MD5:6799A792D2300B35BFC489147492DF29
SHA256:145F510530196C995CBF79BD7D778560C5E24FD2D15A73D17506E94A480B23BF
2528x318b10a24a51a601bb7209c69b593ac487b6c0a6e7d63a461048ce1fe506720a.exeC:\Users\admin\AppData\Local\Temp\zy8kr7t5.exeexecutable
MD5:B6928A2C4FD7143AA8A9CC38CCF7CC3F
SHA256:767A3D3129DC01E7648B3A9E014A94E1AC523A6005445E0A4A2855D096BF9464
2528x318b10a24a51a601bb7209c69b593ac487b6c0a6e7d63a461048ce1fe506720a.exeC:\Users\admin\AppData\Local\Temp\zh3ri4au.exeexecutable
MD5:9B30BA53508BEF0740E68F11DB534553
SHA256:76411376CA672758780751C9D2D9B4EA23C101D32F61E03A3F3286EEDE9CA8FB
2528x318b10a24a51a601bb7209c69b593ac487b6c0a6e7d63a461048ce1fe506720a.exeC:\Users\admin\AppData\Local\Temp\5uyxm5fr.exeexecutable
MD5:6799A792D2300B35BFC489147492DF29
SHA256:145F510530196C995CBF79BD7D778560C5E24FD2D15A73D17506E94A480B23BF
4960zh3ri4au.exeC:\ProgramData\{65b178c1-239c-11ed-b4aa-806e6f6e6963}\FTP Clients\FileZilla\layout.xmlxml
MD5:4526724CD149C14EF9D37D86F825B9F7
SHA256:138167D8F03D48E88DA0AEC3DF38F723BC1895822F75660CCCB5E994814BEE90
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
27
TCP/UDP connections
30
DNS requests
8
Threats
19

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4968
kxxmu.exe
GET
200
62.60.226.159:80
http://62.60.226.159/uploads/rGJmtquOpsb.exe
GB
executable
251 Kb
malicious
4968
kxxmu.exe
POST
200
62.60.226.159:80
http://62.60.226.159/xvzpjyddlu/getdata.php
GB
malicious
3280
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.3.crl
US
binary
400 b
whitelisted
4968
kxxmu.exe
POST
200
62.60.226.159:80
http://62.60.226.159/xvzpjyddlu/getdata.php
GB
binary
50 b
malicious
4968
kxxmu.exe
GET
404
62.60.226.159:80
http://62.60.226.159/uplaods/OXaBlSZnTcE9.exe
GB
html
564 b
malicious
3280
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
US
binary
814 b
whitelisted
3280
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.2.crl
US
binary
400 b
whitelisted
3280
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.3.crl
US
binary
813 b
whitelisted
3280
svchost.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Update%20Signing%20CA%202.2.crl
US
binary
813 b
whitelisted
8044
svchost.exe
GET
200
23.216.77.28:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
48.209.133.15:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
128.24.231.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
8044
svchost.exe
23.216.77.28:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
8044
svchost.exe
72.246.29.11:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
5208
svchost.exe
48.209.133.15:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2952
slui.exe
128.24.231.65:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3580
ngbkpzuq.exe
196.251.107.130:80
FEMOIT
GB
malicious
8044
svchost.exe
48.209.138.189:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
activation-v2.sls.microsoft.com
  • 128.24.231.65
whitelisted
crl.microsoft.com
  • 23.216.77.28
  • 23.216.77.6
whitelisted
www.microsoft.com
  • 72.246.29.11
  • 88.221.169.152
whitelisted
google.com
  • 142.251.127.139
  • 142.251.127.102
  • 142.251.127.113
  • 142.251.127.100
  • 142.251.127.101
  • 142.251.127.138
whitelisted
settings-win.data.microsoft.com
  • 48.209.138.189
whitelisted
self.events.data.microsoft.com
  • 52.168.117.175
whitelisted

Threats

PID
Process
Class
Message
3580
ngbkpzuq.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 45
4960
zh3ri4au.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
4960
zh3ri4au.exe
Misc Attack
ET DROP Spamhaus DROP Listed Traffic Inbound group 9
4960
zh3ri4au.exe
Potential Corporate Privacy Violation
POLICY [ANY.RUN] Sending Screenshot in Archive via POST Request
2996
iijg3iv5.exe
Potentially Bad Traffic
PAYLOAD [ANY.RUN] XORed Windows executable has been loaded
4968
kxxmu.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
4968
kxxmu.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/Amadey associated URI (/xvzpjyddlu/getdata.php)
4968
kxxmu.exe
A Network Trojan was detected
ET MALWARE Executable Downloaded From Common Payload Delivery Host (GET)
4968
kxxmu.exe
Misc activity
INFO [ANY.RUN] USER_AGENTS Suspicious User-Agent (Mozilla/5.0)
4968
kxxmu.exe
A Network Trojan was detected
ET MALWARE Executable Downloaded From Common Payload Delivery Host (GET)
No debug info