File name:

32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exe

Full analysis: https://app.any.run/tasks/696dc0b5-e85b-4743-8246-544673c8906c
Verdict: Malicious activity
Analysis date: September 03, 2025, 16:31:18
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto-startup
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

177C3F4049BE4EB3619ECC9CDD36F5BC

SHA1:

023EA3A70DEB22E635E77AA360B6EEC80C4C070A

SHA256:

32DF691DA0929298F88B37F712B47FBD17C7B2172AEA31C200EEDD08D5C296FB

SSDEEP:

98304:X8JyT/gk2VymklI6Lq291ejwzhYJ4zrOkJqqvZc/OHS6LvoLmJwGosht/Bbnxrw7:BJ3MSjxm

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Create files in the Startup directory

      • 32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exe (PID: 1592)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exe (PID: 1592)
    • Reads security settings of Internet Explorer

      • 32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exe (PID: 1592)
      • JXYXEwq.exe (PID: 7116)
      • JXYXEwq.exe (PID: 1520)
    • Application launched itself

      • 32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exe (PID: 4372)
      • JXYXEwq.exe (PID: 4156)
      • JXYXEwq.exe (PID: 2620)
      • JXYXEwq.exe (PID: 1520)
    • Starts CMD.EXE for commands execution

      • JXYXEwq.exe (PID: 7116)
    • Connects to unusual port

      • cmd.exe (PID: 4820)
  • INFO

    • Checks supported languages

      • 32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exe (PID: 1592)
      • 32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exe (PID: 4372)
      • JXYXEwq.exe (PID: 4156)
      • JXYXEwq.exe (PID: 7116)
      • JXYXEwq.exe (PID: 2620)
      • JXYXEwq.exe (PID: 6012)
      • JXYXEwq.exe (PID: 1520)
    • Creates files or folders in the user directory

      • 32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exe (PID: 1592)
    • Launching a file from the Startup directory

      • 32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exe (PID: 1592)
    • Process checks computer location settings

      • 32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exe (PID: 1592)
      • JXYXEwq.exe (PID: 7116)
      • JXYXEwq.exe (PID: 1520)
    • Reads the computer name

      • 32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exe (PID: 1592)
      • JXYXEwq.exe (PID: 7116)
      • JXYXEwq.exe (PID: 1520)
      • JXYXEwq.exe (PID: 6012)
    • Manual execution by a user

      • JXYXEwq.exe (PID: 2620)
    • Checks proxy server information

      • slui.exe (PID: 7104)
    • Reads the software policy settings

      • slui.exe (PID: 7104)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 EXE PECompact compressed (generic) (31.8)
.exe | Win32 Executable MS Visual C++ (generic) (23.8)
.exe | Win64 Executable (generic) (21.1)
.scr | Windows screen saver (10)
.dll | Win32 Dynamic Link Library (generic) (5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:08:26 23:29:44+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, 32-bit
PEType: PE32
LinkerVersion: 2.24
CodeSize: 6656
InitializedDataSize: 3544576
UninitializedDataSize: -
EntryPoint: 0x20fc
OSVersion: 4
ImageVersion: 1
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
10
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start 32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exe no specs 32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exe jxyxewq.exe no specs jxyxewq.exe no specs cmd.exe conhost.exe no specs jxyxewq.exe no specs jxyxewq.exe no specs jxyxewq.exe no specs slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
1160\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1520"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JXYXEwq.exe"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JXYXEwq.exeJXYXEwq.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\microsoft\windows\start menu\programs\startup\jxyxewq.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
1592"C:\Users\admin\Desktop\32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exe" C:\Users\admin\Desktop\32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exe
32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
2620"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JXYXEwq.exe"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JXYXEwq.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\microsoft\windows\start menu\programs\startup\jxyxewq.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
4156"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JXYXEwq.exe" "C:\Users\admin\Desktop\32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exe" C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JXYXEwq.exe32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\microsoft\windows\start menu\programs\startup\jxyxewq.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4372"C:\Users\admin\Desktop\32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exe" C:\Users\admin\Desktop\32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
4820"C:\Windows\SysWOW64\cmd.exe" C:\Windows\SysWOW64\cmd.exe
JXYXEwq.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
6012"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JXYXEwq.exe" "C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JXYXEwq.exe"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JXYXEwq.exeJXYXEwq.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\microsoft\windows\start menu\programs\startup\jxyxewq.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\user32.dll
c:\windows\syswow64\win32u.dll
7104C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7116"C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JXYXEwq.exe" "C:\Users\admin\Desktop\32df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exe" C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JXYXEwq.exeJXYXEwq.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\microsoft\windows\start menu\programs\startup\jxyxewq.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
4 961
Read events
4 961
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
159232df691da0929298f88b37f712b47fbd17c7b2172aea31c200eedd08d5c296fb.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\JXYXEwq.exeexecutable
MD5:D6175C1BAC44F91197C593E3EBAACB73
SHA256:84900124D45B0F96163A091C5ED736A0CB869F628B6F2458614D51E1341898A8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
45
TCP/UDP connections
58
DNS requests
18
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2168
RUXIMICS.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
1268
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
814 b
whitelisted
2168
RUXIMICS.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
814 b
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
814 b
whitelisted
POST
200
20.190.160.4:443
https://login.live.com/RST2.srf
US
xml
1.24 Kb
unknown
POST
400
20.190.160.65:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
unknown
POST
400
40.126.32.133:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
unknown
POST
400
40.126.32.74:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
203 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2168
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5944
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2168
RUXIMICS.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5944
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.124.78.146
  • 51.104.136.2
whitelisted
google.com
  • 172.217.18.14
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
  • 2.16.164.34
  • 2.16.164.35
  • 2.16.164.81
  • 2.16.164.49
  • 2.16.164.66
  • 2.16.164.73
  • 2.16.164.96
  • 2.16.164.83
  • 2.16.164.58
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 88.221.169.152
whitelisted
login.live.com
  • 20.190.160.4
  • 40.126.32.72
  • 40.126.32.140
  • 20.190.160.17
  • 40.126.32.74
  • 20.190.160.130
  • 40.126.32.133
  • 20.190.160.65
whitelisted
slscr.update.microsoft.com
  • 74.178.76.128
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted
self.events.data.microsoft.com
  • 104.208.16.95
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted
x1.c.lencr.org
  • 23.3.109.48
whitelisted

Threats

PID
Process
Class
Message
4820
cmd.exe
Misc Attack
ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 149
4820
cmd.exe
Misc Attack
ET TOR Known Tor Relay/Router (Not Exit) Node Traffic group 149
No debug info