File name:

Vitya.exe

Full analysis: https://app.any.run/tasks/87c54bfd-ac32-4da4-819a-33532a093606
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: February 14, 2026, 03:53:32
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
telegram
exfiltration
stealer
ims-api
generic
amsi-bypass
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 4 sections
MD5:

5B218B5268F2018CC667D5EA832C6E9F

SHA1:

C1CBC09CED99D05488655A88DA617AB317E96427

SHA256:

395BFDAD0807BF4930F521E3F63C3E01C4606AF017341925B6A4F09CFA1DE4DE

SSDEEP:

98304:samRdu6A5kuXawlJ0ndacT/G07sJptY7u4pIkEO79Gtqlu2SesepKcHJLaqAITcO:ep7l1iFdvaDZO+l

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes Windows Defender settings

      • Vitya.exe (PID: 6336)
    • Changes settings for real-time protection

      • powershell.exe (PID: 7748)
    • Using BCDEDIT.EXE to modify recovery options

      • cmd.exe (PID: 9176)
    • Deletes shadow copies

      • vssadmin.exe (PID: 3952)
      • wbadmin.exe (PID: 6924)
    • Deleting the backup catalog via wbadmin

      • cmd.exe (PID: 4300)
    • Modifies files in the Chrome extension folder

      • Vitya.exe (PID: 6336)
  • SUSPICIOUS

    • Reads the date of Windows installation

      • Vitya.exe (PID: 6336)
    • Starts CMD.EXE for commands execution

      • Vitya.exe (PID: 6336)
    • Script disables Windows Defender's real-time protection

      • Vitya.exe (PID: 6336)
    • Starts POWERSHELL.EXE for commands execution

      • Vitya.exe (PID: 6336)
    • Modifies hosts file to alter network resolution

      • Vitya.exe (PID: 6336)
    • The process connected to a server suspected of theft

      • Vitya.exe (PID: 6336)
    • Possibly patching Antimalware Scan Interface function (YARA)

      • Vitya.exe (PID: 6336)
    • Creates file in the systems drive root

      • Vitya.exe (PID: 6336)
    • Possible usage of Discord/Telegram API has been detected (YARA)

      • Vitya.exe (PID: 6336)
    • The process creates files with name similar to system file names

      • Vitya.exe (PID: 6336)
    • Executable content was dropped or overwritten

      • Vitya.exe (PID: 6336)
  • INFO

    • Reads the computer name

      • Vitya.exe (PID: 6336)
    • Checks supported languages

      • Vitya.exe (PID: 6336)
    • Process checks computer location settings

      • Vitya.exe (PID: 6336)
    • Reads security settings of Internet Explorer

      • Vitya.exe (PID: 6336)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 7748)
    • Creates files in the program directory

      • Vitya.exe (PID: 6336)
    • Drops script file

      • Vitya.exe (PID: 6336)
      • powershell.exe (PID: 7748)
    • Creates files or folders in the user directory

      • Vitya.exe (PID: 6336)
    • Disables trace logs

      • Vitya.exe (PID: 6336)
    • Checks proxy server information

      • Vitya.exe (PID: 6336)
      • slui.exe (PID: 2452)
    • Reads Environment values

      • Vitya.exe (PID: 6336)
    • Reads the machine GUID from the registry

      • Vitya.exe (PID: 6336)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 7748)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (81)
.dll | Win32 Dynamic Link Library (generic) (7.2)
.exe | Win32 Executable (generic) (4.9)
.exe | Win16/32 Executable Delphi generic (2.2)
.exe | Generic Win/DOS Executable (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 0000:00:00 00:00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 6037504
InitializedDataSize: 2048
UninitializedDataSize: -
EntryPoint: 0x5c3fee
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: Invariant
CharacterSet: Unicode
Comments:
CompanyName:
FileDescription:
FileVersion: 0.0.0.0
InternalName: Vitya
LegalCopyright:
LegalTrademarks:
OriginalFileName: Vitya.exe
ProductName:
ProductVersion:
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
155
Monitored processes
13
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
2452C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
3952vssadmin delete shadows /all /quietC:\Windows\System32\vssadmin.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Command Line Interface for Microsoft® Volume Shadow Copy Service
Exit code:
2
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssadmin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4300"C:\Windows\System32\cmd.exe" /c wbadmin delete catalog -quietC:\Windows\System32\cmd.exeVitya.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
4294967294
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
6336"C:\Users\admin\Desktop\Vitya.exe" C:\Users\admin\Desktop\Vitya.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\vitya.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6472\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6924wbadmin delete catalog -quietC:\Windows\System32\wbadmin.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Command Line Interface for Microsoft® BLB Backup
Exit code:
4294967294
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wbadmin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
7420\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7748"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -Command Set-MpPreference -DisableRealtimeMonitoring $trueC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeVitya.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
7772\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
8712bcdedit /set {default} recoveryenabled NoC:\Windows\System32\bcdedit.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Boot Configuration Data Editor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\bcdedit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cryptsp.dll
Total events
44 663
Read events
44 649
Write events
14
Delete events
0

Modification events

(PID) Process:(6336) Vitya.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Vitya_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6336) Vitya.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Vitya_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6336) Vitya.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Vitya_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6336) Vitya.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Vitya_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(6336) Vitya.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Vitya_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(6336) Vitya.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Vitya_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(6336) Vitya.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Vitya_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(6336) Vitya.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Vitya_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6336) Vitya.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Vitya_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6336) Vitya.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Vitya_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
10
Suspicious files
2 687
Text files
19
Unknown types
0

Dropped files

PID
Process
Filename
Type
6336Vitya.exeC:\ProgramData\Adobe\ARM\Acrobat_23.001.20093\AcroRdrDCx64Upd2300820470_MUI.msp.vitek
MD5:
SHA256:
6336Vitya.exeC:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Markdig.Signed.vitekbinary
MD5:D4F2BDE3F7826C9FAF8FD342957E0828
SHA256:9EA1CC355ED73EFA29F44CB2CFCF11B67B671A82898156EFBC5509D881F5E598
6336Vitya.exeC:\ProgramData\Adobe\ARM\S\388\AdobeARM.msi.vitekbinary
MD5:EBE25E340353786A7CA706D666242AAE
SHA256:B875AD9E1EB9003409B40EA4728F971EBDDF0EBE0E7DA9E000D1027A651F8EFD
6336Vitya.exeC:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Bcl.AsyncInterfaces.vitekbinary
MD5:A68982B9AAEBC15DB72CA0B368BB6DF4
SHA256:142F4E8E0927446C30BFA465E7B012D3A0DCD7CE017F984B571C98367CC50EF7
7748powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivebinary
MD5:D60758228403BDEE170694A1628EF0CD
SHA256:FF0CD5084EEC04DC41D9D440F7D3991D5CC413743C14174020FCDE1F3DFCD9D9
6336Vitya.exeC:\$Recycle.Bin\S-1-5-21-1693682860-607145093-2874071422-1001\desktop.ini.vitekbinary
MD5:E53E5A05EB346C9B6C3F009BD2745672
SHA256:423AD8AA697BE90D43895B63B74959B0CE51D3C8DCCF1AB4AF7B28376A58057A
7748powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_q0uhl05p.jyr.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
7748powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_eqbcmts4.u5v.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
6336Vitya.exeC:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.CodeAnalysis.Common,4.4.0.vitekbinary
MD5:341C4035AA116D3F93976CAB83BD7710
SHA256:4F93D7A5F4B37BBE2BA8B40B0E52368135CFD3DE6DDEF24DEE057F6EF41ED82D
6336Vitya.exeC:\ProgramData\Microsoft\NetFramework\BreadcrumbStore\netcore,Microsoft.Bcl.AsyncInterfaces,7.0.0.vitekbinary
MD5:63A352091C8D273E671D730BF33D6796
SHA256:0E5A8764E317764A7DDC9C988F9DB729318E467F493551EB41B40DACAE01DD84
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
49
TCP/UDP connections
49
DNS requests
23
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7828
SIHClient.exe
GET
304
135.233.95.144:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
6768
MoUsoCoreWorker.exe
GET
200
2.21.23.11:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
POST
200
40.126.31.3:443
https://login.live.com/RST2.srf
US
binary
11.1 Kb
unknown
7828
SIHClient.exe
GET
200
40.69.42.241:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
3656
svchost.exe
GET
200
2.21.23.11:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
825 b
whitelisted
POST
200
20.190.160.3:443
https://login.live.com/RST2.srf
US
binary
10.3 Kb
unknown
POST
200
40.126.31.3:443
https://login.live.com/RST2.srf
US
binary
10.3 Kb
unknown
7828
SIHClient.exe
GET
200
135.233.95.144:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
POST
200
149.154.167.99:443
https://api.telegram.org/bot8317431687:AAGTBreB-MurOpD3QbV3wf5EdzokVnI-W8M/sendMessage
GB
binary
896 b
unknown
7828
SIHClient.exe
GET
304
135.233.95.144:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
2.16.27.74:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6768
MoUsoCoreWorker.exe
2.21.23.11:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
2.21.23.11:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
3656
svchost.exe
2.21.23.11:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
356
svchost.exe
20.190.159.131:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6336
Vitya.exe
149.154.166.110:443
api.telegram.org
TELEGRAM
VG
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
www.bing.com
  • 2.16.27.74
  • 2.16.27.98
whitelisted
self.events.data.microsoft.com
  • 20.42.65.88
  • 20.189.173.17
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
google.com
  • 142.250.201.78
whitelisted
crl.microsoft.com
  • 2.21.23.11
  • 2.21.23.19
whitelisted
login.live.com
  • 20.190.159.131
  • 40.126.31.3
  • 40.126.31.129
  • 20.190.159.75
  • 40.126.31.2
  • 40.126.31.69
  • 20.190.159.128
  • 40.126.31.0
  • 20.190.160.65
  • 20.190.160.132
  • 20.190.160.64
  • 40.126.32.68
  • 20.190.160.2
  • 40.126.32.133
  • 20.190.160.3
  • 40.126.32.76
whitelisted
api.telegram.org
  • 149.154.166.110
whitelisted
slscr.update.microsoft.com
  • 135.233.95.144
whitelisted
www.microsoft.com
  • 184.30.158.70
whitelisted

Threats

PID
Process
Class
Message
2292
svchost.exe
Misc activity
ET HUNTING Telegram API Domain in DNS Lookup
6336
Vitya.exe
Misc activity
ET HUNTING Telegram API Certificate Observed
6336
Vitya.exe
Successful Credential Theft Detected
STEALER [ANY.RUN] Attempt to exfiltrate via Telegram
6336
Vitya.exe
Misc activity
ET HUNTING Observed Telegram API Domain (api .telegram .org in TLS SNI)
Attempted Information Leak
SUSPICIOUS [ANY.RUN] Possible Stolen Data Exfil via Telegram Bot API
6336
Vitya.exe
Attempted Information Leak
SUSPICIOUS [ANY.RUN] Possible Stolen Data Exfil via Telegram Bot API
Process
Message
wbadmin.exe
Invalid parameter passed to C runtime function.