File name:

dotnet-sdk-8.0.408-win-x64.exe

Full analysis: https://app.any.run/tasks/4516c9e3-80ec-4fe8-a197-8b654fd865c9
Verdict: Malicious activity
Analysis date: May 15, 2025, 18:25:01
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

EBD2D713081FEFEFB7413845D8765C0B

SHA1:

F39706DD1D76019D56C436FB3C769BEC14DA1008

SHA256:

33711360E44BB8DD46D3BD3AD99368AD816486336EE4069DEA8287C619E63B08

SSDEEP:

24576:t+F8g+nZTnAHFo23SjnB/q4iqEUYMdKrWHgfSI3BC9:t+F8g+nZTnAHFo2i7B/qLqeMdKrWHgfc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6112)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6700)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 900)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6112)
    • Starts a Microsoft application from unusual location

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6700)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 900)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6112)
    • Process drops legitimate windows executable

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6700)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 900)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6112)
    • Starts itself from another location

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6700)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 900)
    • Searches for installed software

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 900)
    • Reads security settings of Internet Explorer

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 900)
    • Creates a software uninstall entry

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6112)
  • INFO

    • Create files in a temporary directory

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6700)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 900)
    • The sample compiled with english language support

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6700)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 900)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6112)
    • Checks supported languages

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6700)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 900)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6112)
    • Reads the computer name

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 900)
      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6112)
    • Process checks computer location settings

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 900)
    • Creates files in the program directory

      • dotnet-sdk-8.0.408-win-x64.exe (PID: 6112)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:09:23 22:06:56+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.16
CodeSize: 303104
InitializedDataSize: 162816
UninitializedDataSize: -
EntryPoint: 0x3054b
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 8.4.825.16805
ProductVersionNumber: 8.4.825.16805
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Microsoft Corporation
FileDescription: Microsoft .NET SDK 8.0.408 (x64)
FileVersion: 8.4.825.16805
InternalName: setup
LegalCopyright: Copyright (c) Microsoft Corporation. All rights reserved.
OriginalFileName: dotnet-sdk-8.0.408-win-x64.exe
ProductName: Microsoft .NET SDK 8.0.408 (x64)
ProductVersion: 8.4.825.16805
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start dotnet-sdk-8.0.408-win-x64.exe dotnet-sdk-8.0.408-win-x64.exe sppextcomobj.exe no specs slui.exe no specs dotnet-sdk-8.0.408-win-x64.exe

Process information

PID
CMD
Path
Indicators
Parent process
536C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
900"C:\Users\admin\AppData\Local\Temp\{AE4FDBF6-66C4-482E-B4F1-8B7795486619}\.cr\dotnet-sdk-8.0.408-win-x64.exe" -burn.clean.room="C:\Users\admin\AppData\Local\Temp\dotnet-sdk-8.0.408-win-x64.exe" -burn.filehandle.attached=692 -burn.filehandle.self=700 C:\Users\admin\AppData\Local\Temp\{AE4FDBF6-66C4-482E-B4F1-8B7795486619}\.cr\dotnet-sdk-8.0.408-win-x64.exe
dotnet-sdk-8.0.408-win-x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET SDK 8.0.408 (x64)
Exit code:
1
Version:
8.4.825.16805
Modules
Images
c:\users\admin\appdata\local\temp\{ae4fdbf6-66c4-482e-b4f1-8b7795486619}\.cr\dotnet-sdk-8.0.408-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
3900"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6112"C:\Users\admin\AppData\Local\Temp\{14A3DDDA-C9B6-44E6-82A0-59A9E5F86A33}\.be\dotnet-sdk-8.0.408-win-x64.exe" -q -burn.elevated BurnPipe.{563FD900-7201-46EB-A664-E9B715477ECF} {518E78B3-B6CE-4347-8640-EBA38BF4600D} 900C:\Users\admin\AppData\Local\Temp\{14A3DDDA-C9B6-44E6-82A0-59A9E5F86A33}\.be\dotnet-sdk-8.0.408-win-x64.exe
dotnet-sdk-8.0.408-win-x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft .NET SDK 8.0.408 (x64)
Exit code:
1
Version:
8.4.825.16805
Modules
Images
c:\users\admin\appdata\local\temp\{14a3ddda-c9b6-44e6-82a0-59a9e5f86a33}\.be\dotnet-sdk-8.0.408-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6700"C:\Users\admin\AppData\Local\Temp\dotnet-sdk-8.0.408-win-x64.exe" C:\Users\admin\AppData\Local\Temp\dotnet-sdk-8.0.408-win-x64.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET SDK 8.0.408 (x64)
Exit code:
1
Version:
8.4.825.16805
Modules
Images
c:\users\admin\appdata\local\temp\dotnet-sdk-8.0.408-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
574
Read events
541
Write events
26
Delete events
7

Modification events

(PID) Process:(6112) dotnet-sdk-8.0.408-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{e5ddf235-1b10-49a5-9229-2717cea94b1d}
Operation:writeName:BundleCachePath
Value:
C:\ProgramData\Package Cache\{e5ddf235-1b10-49a5-9229-2717cea94b1d}\dotnet-sdk-8.0.408-win-x64.exe
(PID) Process:(6112) dotnet-sdk-8.0.408-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{e5ddf235-1b10-49a5-9229-2717cea94b1d}
Operation:writeName:BundleUpgradeCode
Value:
{37A22C9B-5D0E-5AD5-D324-CAF7811A8A62}
(PID) Process:(6112) dotnet-sdk-8.0.408-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{e5ddf235-1b10-49a5-9229-2717cea94b1d}
Operation:writeName:BundleAddonCode
Value:
(PID) Process:(6112) dotnet-sdk-8.0.408-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{e5ddf235-1b10-49a5-9229-2717cea94b1d}
Operation:writeName:BundleDetectCode
Value:
(PID) Process:(6112) dotnet-sdk-8.0.408-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{e5ddf235-1b10-49a5-9229-2717cea94b1d}
Operation:writeName:BundlePatchCode
Value:
(PID) Process:(6112) dotnet-sdk-8.0.408-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{e5ddf235-1b10-49a5-9229-2717cea94b1d}
Operation:writeName:BundleVersion
Value:
8.4.825.16805
(PID) Process:(6112) dotnet-sdk-8.0.408-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{e5ddf235-1b10-49a5-9229-2717cea94b1d}
Operation:writeName:VersionMajor
Value:
8
(PID) Process:(6112) dotnet-sdk-8.0.408-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{e5ddf235-1b10-49a5-9229-2717cea94b1d}
Operation:writeName:VersionMinor
Value:
4
(PID) Process:(6112) dotnet-sdk-8.0.408-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{e5ddf235-1b10-49a5-9229-2717cea94b1d}
Operation:writeName:BundleProviderKey
Value:
{e5ddf235-1b10-49a5-9229-2717cea94b1d}
(PID) Process:(6112) dotnet-sdk-8.0.408-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{e5ddf235-1b10-49a5-9229-2717cea94b1d}
Operation:writeName:BundleTag
Value:
Executable files
5
Suspicious files
1
Text files
21
Unknown types
0

Dropped files

PID
Process
Filename
Type
900dotnet-sdk-8.0.408-win-x64.exeC:\Users\admin\AppData\Local\Temp\{14A3DDDA-C9B6-44E6-82A0-59A9E5F86A33}\.ba\bg.pngimage
MD5:9EB0320DFBF2BD541E6A55C01DDC9F20
SHA256:9095BF7B6BAA0107B40A4A6D727215BE077133A190F4CA9BD89A176842141E79
900dotnet-sdk-8.0.408-win-x64.exeC:\Users\admin\AppData\Local\Temp\{14A3DDDA-C9B6-44E6-82A0-59A9E5F86A33}\.ba\wixstdba.dllexecutable
MD5:F1919C6BD85D7A78A70C228A5B227FBE
SHA256:DCEA15F3710822FFC262E62EC04CC7BBBF0F33F5D1A853609FBFB65CB6A45640
900dotnet-sdk-8.0.408-win-x64.exeC:\Users\admin\AppData\Local\Temp\{14A3DDDA-C9B6-44E6-82A0-59A9E5F86A33}\.ba\thm.wxlxml
MD5:4479C9AAAAE17F8009392786F0910789
SHA256:34919F9197533A6BA636941A91E33E57338FB86A821FA02BF586CB80E9EEBDB2
900dotnet-sdk-8.0.408-win-x64.exeC:\Users\admin\AppData\Local\Temp\{14A3DDDA-C9B6-44E6-82A0-59A9E5F86A33}\.ba\thm.xmlxml
MD5:BC4C1B302D6C87C4026508120E167C95
SHA256:C9E7E37D46601196E0DDA5D42FDF80C533DAB4CDF09D68E5A7C9A86C05795E00
6700dotnet-sdk-8.0.408-win-x64.exeC:\Users\admin\AppData\Local\Temp\{AE4FDBF6-66C4-482E-B4F1-8B7795486619}\.cr\dotnet-sdk-8.0.408-win-x64.exeexecutable
MD5:EBD2D713081FEFEFB7413845D8765C0B
SHA256:33711360E44BB8DD46D3BD3AD99368AD816486336EE4069DEA8287C619E63B08
900dotnet-sdk-8.0.408-win-x64.exeC:\Users\admin\AppData\Local\Temp\{14A3DDDA-C9B6-44E6-82A0-59A9E5F86A33}\.ba\1031\thm.wxlxml
MD5:D9F3E60B1262A4140991C47BC9D2E37F
SHA256:6B37D837535CA6AB6D46703EADF9CD87965DE6DA66F034F0053F52971150FC43
900dotnet-sdk-8.0.408-win-x64.exeC:\Users\admin\AppData\Local\Temp\{14A3DDDA-C9B6-44E6-82A0-59A9E5F86A33}\.ba\1029\thm.wxlxml
MD5:9128B2606544FB6446F43B030C212E46
SHA256:ACD0958C0C2187F766BA87C7F84A2AE3BA1BF7F3E9DD5D874C37C3D7C6FBF5E3
900dotnet-sdk-8.0.408-win-x64.exeC:\Users\admin\AppData\Local\Temp\{14A3DDDA-C9B6-44E6-82A0-59A9E5F86A33}\.ba\1046\thm.wxlxml
MD5:38BF021610D66A7B3F5FA6D564E61592
SHA256:A52CAD6ACD9A9DBEC0C14B4180CA08E19D09364972798B0E023964642DA9BE40
900dotnet-sdk-8.0.408-win-x64.exeC:\Users\admin\AppData\Local\Temp\{14A3DDDA-C9B6-44E6-82A0-59A9E5F86A33}\.ba\1040\thm.wxlxml
MD5:29AECDE585E557A812B86141F0656043
SHA256:04FAD78A493E7123CABCFD4E0A405AF3FD2175CF24AD4CE93B30539029FEC5C3
900dotnet-sdk-8.0.408-win-x64.exeC:\Users\admin\AppData\Local\Temp\{14A3DDDA-C9B6-44E6-82A0-59A9E5F86A33}\.ba\1041\thm.wxlxml
MD5:C94D1C2454375B72D458EFF51F54FD48
SHA256:DAB0F9BAE96057C7C819571E40122BF1CA4A39834627B617A73DD071B2437423
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
22
DNS requests
11
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.162:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2152
RUXIMICS.exe
GET
200
23.48.23.162:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2104
svchost.exe
GET
200
23.48.23.162:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2104
svchost.exe
GET
200
2.21.137.121:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
2.21.137.121:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2152
RUXIMICS.exe
GET
200
2.21.137.121:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2100
SIHClient.exe
GET
200
2.21.137.121:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2100
SIHClient.exe
GET
200
2.21.137.121:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6544
svchost.exe
GET
200
23.63.118.230:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
5496
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2152
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
23.48.23.162:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2104
svchost.exe
23.48.23.162:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2152
RUXIMICS.exe
23.48.23.162:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
2.21.137.121:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
2.21.137.121:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2152
RUXIMICS.exe
2.21.137.121:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.78
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 23.48.23.162
whitelisted
www.microsoft.com
  • 2.21.137.121
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 20.190.160.128
whitelisted
ocsp.digicert.com
  • 23.63.118.230
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted

Threats

No threats detected
No debug info