File name:

dotnet-sdk-8.0.408-win-x64.exe

Full analysis: https://app.any.run/tasks/4516c9e3-80ec-4fe8-a197-8b654fd865c9
Verdict: Malicious activity
Analysis date: May 15, 2025, 18:25:01
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

EBD2D713081FEFEFB7413845D8765C0B

SHA1:

F39706DD1D76019D56C436FB3C769BEC14DA1008

SHA256:

33711360E44BB8DD46D3BD3AD99368AD816486336EE4069DEA8287C619E63B08

SSDEEP:

24576:t+F8g+nZTnAHFo23SjnB/q4iqEUYMdKrWHgfSI3BC9:t+F8g+nZTnAHFo2i7B/qLqeMdKrWHgfc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6112)
  • SUSPICIOUS

    • Starts itself from another location

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6700)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 900)
    • Starts a Microsoft application from unusual location

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6700)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 900)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6112)
    • Process drops legitimate windows executable

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6700)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 900)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6112)
    • Executable content was dropped or overwritten

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6700)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 900)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6112)
    • Searches for installed software

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 900)
    • Reads security settings of Internet Explorer

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 900)
    • Creates a software uninstall entry

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6112)
  • INFO

    • Checks supported languages

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6700)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 900)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6112)
    • The sample compiled with english language support

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6700)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 900)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6112)
    • Create files in a temporary directory

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6700)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 900)
    • Reads the computer name

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 900)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6112)
    • Process checks computer location settings

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 900)
    • Creates files in the program directory

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6112)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:09:23 22:06:56+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.16
CodeSize: 303104
InitializedDataSize: 162816
UninitializedDataSize: -
EntryPoint: 0x3054b
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 8.4.825.16805
ProductVersionNumber: 8.4.825.16805
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Microsoft Corporation
FileDescription: Microsoft .NET SDK 8.0.408 (x64)
FileVersion: 8.4.825.16805
InternalName: setup
LegalCopyright: Copyright (c) Microsoft Corporation. All rights reserved.
OriginalFileName: dotnet-sdk-8.0.408-win-x64.exe
ProductName: Microsoft .NET SDK 8.0.408 (x64)
ProductVersion: 8.4.825.16805
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start dotnet-sdk-8.0.408-win-x64.exe dotnet-sdk-8.0.408-win-x64.exe sppextcomobj.exe no specs slui.exe no specs dotnet-sdk-8.0.408-win-x64.exe

Process information

PID
CMD
Path
Indicators
Parent process
536C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
900"C:\Users\admin\AppData\Local\Temp\{AE4FDBF6-66C4-482E-B4F1-8B7795486619}\.cr\dotnet-sdk-8.0.408-win-x64.exe" -burn.clean.room="C:\Users\admin\AppData\Local\Temp\dotnet-sdk-8.0.408-win-x64.exe" -burn.filehandle.attached=692 -burn.filehandle.self=700 C:\Users\admin\AppData\Local\Temp\{AE4FDBF6-66C4-482E-B4F1-8B7795486619}\.cr\dotnet-sdk-8.0.408-win-x64.exe
dotnet-sdk-8.0.408-win-x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET SDK 8.0.408 (x64)
Exit code:
1
Version:
8.4.825.16805
Modules
Images
c:\users\admin\appdata\local\temp\{ae4fdbf6-66c4-482e-b4f1-8b7795486619}\.cr\dotnet-sdk-8.0.408-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3900"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6112"C:\Users\admin\AppData\Local\Temp\{14A3DDDA-C9B6-44E6-82A0-59A9E5F86A33}\.be\dotnet-sdk-8.0.408-win-x64.exe" -q -burn.elevated BurnPipe.{563FD900-7201-46EB-A664-E9B715477ECF} {518E78B3-B6CE-4347-8640-EBA38BF4600D} 900C:\Users\admin\AppData\Local\Temp\{14A3DDDA-C9B6-44E6-82A0-59A9E5F86A33}\.be\dotnet-sdk-8.0.408-win-x64.exe
dotnet-sdk-8.0.408-win-x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET SDK 8.0.408 (x64)
Exit code:
1
Version:
8.4.825.16805
Modules
Images
c:\users\admin\appdata\local\temp\{14a3ddda-c9b6-44e6-82a0-59a9e5f86a33}\.be\dotnet-sdk-8.0.408-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6700"C:\Users\admin\AppData\Local\Temp\dotnet-sdk-8.0.408-win-x64.exe" C:\Users\admin\AppData\Local\Temp\dotnet-sdk-8.0.408-win-x64.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET SDK 8.0.408 (x64)
Exit code:
1
Version:
8.4.825.16805
Modules
Images
c:\users\admin\appdata\local\temp\dotnet-sdk-8.0.408-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
574
Read events
541
Write events
26
Delete events
7

Modification events

(PID) Process:(6112) dotnet-sdk-8.0.408-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{e5ddf235-1b10-49a5-9229-2717cea94b1d}
Operation:writeName:BundleCachePath
Value:
C:\ProgramData\Package Cache\{e5ddf235-1b10-49a5-9229-2717cea94b1d}\dotnet-sdk-8.0.408-win-x64.exe
(PID) Process:(6112) dotnet-sdk-8.0.408-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{e5ddf235-1b10-49a5-9229-2717cea94b1d}
Operation:writeName:BundleUpgradeCode
Value:
{37A22C9B-5D0E-5AD5-D324-CAF7811A8A62}
(PID) Process:(6112) dotnet-sdk-8.0.408-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{e5ddf235-1b10-49a5-9229-2717cea94b1d}
Operation:writeName:BundleAddonCode
Value:
(PID) Process:(6112) dotnet-sdk-8.0.408-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{e5ddf235-1b10-49a5-9229-2717cea94b1d}
Operation:writeName:BundleDetectCode
Value:
(PID) Process:(6112) dotnet-sdk-8.0.408-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{e5ddf235-1b10-49a5-9229-2717cea94b1d}
Operation:writeName:BundlePatchCode
Value:
(PID) Process:(6112) dotnet-sdk-8.0.408-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{e5ddf235-1b10-49a5-9229-2717cea94b1d}
Operation:writeName:BundleVersion
Value:
8.4.825.16805
(PID) Process:(6112) dotnet-sdk-8.0.408-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{e5ddf235-1b10-49a5-9229-2717cea94b1d}
Operation:writeName:VersionMajor
Value:
8
(PID) Process:(6112) dotnet-sdk-8.0.408-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{e5ddf235-1b10-49a5-9229-2717cea94b1d}
Operation:writeName:VersionMinor
Value:
4
(PID) Process:(6112) dotnet-sdk-8.0.408-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{e5ddf235-1b10-49a5-9229-2717cea94b1d}
Operation:writeName:BundleProviderKey
Value:
{e5ddf235-1b10-49a5-9229-2717cea94b1d}
(PID) Process:(6112) dotnet-sdk-8.0.408-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{e5ddf235-1b10-49a5-9229-2717cea94b1d}
Operation:writeName:BundleTag
Value:
Executable files
5
Suspicious files
1
Text files
21
Unknown types
0

Dropped files

PID
Process
Filename
Type
900dotnet-sdk-8.0.408-win-x64.exeC:\Users\admin\AppData\Local\Temp\{14A3DDDA-C9B6-44E6-82A0-59A9E5F86A33}\.ba\thm.xmlxml
MD5:BC4C1B302D6C87C4026508120E167C95
SHA256:C9E7E37D46601196E0DDA5D42FDF80C533DAB4CDF09D68E5A7C9A86C05795E00
900dotnet-sdk-8.0.408-win-x64.exeC:\Users\admin\AppData\Local\Temp\{14A3DDDA-C9B6-44E6-82A0-59A9E5F86A33}\.ba\wixstdba.dllexecutable
MD5:F1919C6BD85D7A78A70C228A5B227FBE
SHA256:DCEA15F3710822FFC262E62EC04CC7BBBF0F33F5D1A853609FBFB65CB6A45640
6700dotnet-sdk-8.0.408-win-x64.exeC:\Users\admin\AppData\Local\Temp\{AE4FDBF6-66C4-482E-B4F1-8B7795486619}\.cr\dotnet-sdk-8.0.408-win-x64.exeexecutable
MD5:EBD2D713081FEFEFB7413845D8765C0B
SHA256:33711360E44BB8DD46D3BD3AD99368AD816486336EE4069DEA8287C619E63B08
900dotnet-sdk-8.0.408-win-x64.exeC:\Users\admin\AppData\Local\Temp\{14A3DDDA-C9B6-44E6-82A0-59A9E5F86A33}\.ba\thm.wxlxml
MD5:4479C9AAAAE17F8009392786F0910789
SHA256:34919F9197533A6BA636941A91E33E57338FB86A821FA02BF586CB80E9EEBDB2
900dotnet-sdk-8.0.408-win-x64.exeC:\Users\admin\AppData\Local\Temp\{14A3DDDA-C9B6-44E6-82A0-59A9E5F86A33}\.ba\1045\thm.wxlxml
MD5:1F7DA5C4BA7E0F5F3F1C6ADFC746563F
SHA256:C3A1633A331D50F12426F88C7FE95671252DE2E51BA3C9C2EACA1513DF115C21
900dotnet-sdk-8.0.408-win-x64.exeC:\Users\admin\AppData\Local\Temp\{14A3DDDA-C9B6-44E6-82A0-59A9E5F86A33}\.ba\1046\thm.wxlxml
MD5:38BF021610D66A7B3F5FA6D564E61592
SHA256:A52CAD6ACD9A9DBEC0C14B4180CA08E19D09364972798B0E023964642DA9BE40
900dotnet-sdk-8.0.408-win-x64.exeC:\Users\admin\AppData\Local\Temp\{14A3DDDA-C9B6-44E6-82A0-59A9E5F86A33}\.ba\3082\thm.wxlxml
MD5:755AA35262AAF2EAE10D0907EC94B9A2
SHA256:E6A72E311C53647E09CA6B5D900503C6E65DBA252251E3B3387C644047C190A6
900dotnet-sdk-8.0.408-win-x64.exeC:\Users\admin\AppData\Local\Temp\{14A3DDDA-C9B6-44E6-82A0-59A9E5F86A33}\.ba\1049\thm.wxlxml
MD5:9025F4A7F61841A28B6B4B9D1DF8E966
SHA256:200ECE8C767B86FBA523E71EDA17D3C775CF4D37C548BCCC1E20BB71573A358F
900dotnet-sdk-8.0.408-win-x64.exeC:\Users\admin\AppData\Local\Temp\{14A3DDDA-C9B6-44E6-82A0-59A9E5F86A33}\.ba\2052\thm.wxlxml
MD5:D87CFCADE1FD08357523C34429466C81
SHA256:E9D86E7F8D3BE4A61BBB7D249A1E26ACD28AFF7791BB960B5116276F5A6A9F09
900dotnet-sdk-8.0.408-win-x64.exeC:\Users\admin\AppData\Local\Temp\{14A3DDDA-C9B6-44E6-82A0-59A9E5F86A33}\.ba\eula.rtftext
MD5:C6557E40A082DC93ECB51B1347BD9832
SHA256:BB72148C967CE6C31F1ED434DE72F9CD132B08F6A1F2E02D71A25EB4DAFA4FC9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
22
DNS requests
11
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2104
svchost.exe
GET
200
23.48.23.162:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.48.23.162:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2104
svchost.exe
GET
200
2.21.137.121:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2152
RUXIMICS.exe
GET
200
23.48.23.162:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.21.137.121:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2152
RUXIMICS.exe
GET
200
2.21.137.121:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2100
SIHClient.exe
GET
200
2.21.137.121:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2100
SIHClient.exe
GET
200
2.21.137.121:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6544
svchost.exe
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
5496
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2152
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
23.48.23.162:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2104
svchost.exe
23.48.23.162:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2152
RUXIMICS.exe
23.48.23.162:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
2.21.137.121:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
2.21.137.121:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2152
RUXIMICS.exe
2.21.137.121:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.78
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 23.48.23.162
whitelisted
www.microsoft.com
  • 2.21.137.121
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.160.128
whitelisted
ocsp.digicert.com
  • 23.63.118.230
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted

Threats

No threats detected
No debug info