File name:

3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe

Full analysis: https://app.any.run/tasks/81529fec-7496-4a1d-a77c-90706e7e1b9d
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: October 03, 2025, 17:41:25
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
m0yv
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

C8FAA15D7FC9A7002C6ED4D264F3B4AE

SHA1:

D8415189F4A70A31F7DEEA8B0E0EB89389E4A14B

SHA256:

3C7ABE58E501AE08895AA05345596ADFB9A7F434CF47975565325975D2D06391

SSDEEP:

98304:U2qqfM8mWGpYohujG822IT1PD222222272TSRTP4WG5N0aFvGSSRkrlcfABLqI1q:xQXeq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • M0YV mutex has been found

      • 3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe (PID: 2364)
      • armsvc.exe (PID: 7068)
      • MicrosoftEdgeUpdate.exe (PID: 5196)
      • AppVClient.exe (PID: 8008)
      • DiagnosticsHub.StandardCollector.Service.exe (PID: 2760)
      • alg.exe (PID: 4384)
      • FlashPlayerUpdateService.exe (PID: 2732)
      • GameInputSvc.exe (PID: 2400)
      • updater.exe (PID: 2816)
      • elevation_service.exe (PID: 5584)
      • updater.exe (PID: 2288)
      • updater.exe (PID: 2504)
      • elevation_service.exe (PID: 6240)
      • updater.exe (PID: 2864)
      • FXSSVC.exe (PID: 2356)
      • GameInputSvc.exe (PID: 5580)
      • updater.exe (PID: 7256)
      • PerceptionSimulationService.exe (PID: 8260)
      • msdtc.exe (PID: 7012)
      • perfhost.exe (PID: 8364)
      • PSEXESVC.exe (PID: 8396)
      • Locator.exe (PID: 8452)
      • maintenanceservice.exe (PID: 5192)
      • updater.exe (PID: 7784)
      • snmptrap.exe (PID: 8572)
      • Spectrum.exe (PID: 8632)
      • SensorDataService.exe (PID: 8520)
      • ssh-agent.exe (PID: 8700)
      • AgentService.exe (PID: 8852)
      • TieringEngineService.exe (PID: 8744)
      • vds.exe (PID: 8892)
      • wbengine.exe (PID: 8944)
      • WmiApSrv.exe (PID: 9016)
      • SearchIndexer.exe (PID: 9080)
      • elevation_service.exe (PID: 9392)
    • M0YV has been detected (SURICATA)

      • svchost.exe (PID: 2428)
    • Connects to the CnC server

      • svchost.exe (PID: 2428)
    • M0YV has been detected (YARA)

      • 3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe (PID: 2364)
      • GameInputSvc.exe (PID: 5580)
      • elevation_service.exe (PID: 5584)
      • GameInputSvc.exe (PID: 2400)
      • armsvc.exe (PID: 7068)
      • DiagnosticsHub.StandardCollector.Service.exe (PID: 2760)
      • alg.exe (PID: 4384)
      • perfhost.exe (PID: 8364)
      • PerceptionSimulationService.exe (PID: 8260)
      • PSEXESVC.exe (PID: 8396)
      • Locator.exe (PID: 8452)
      • msdtc.exe (PID: 7012)
  • SUSPICIOUS

    • Executes as Windows Service

      • armsvc.exe (PID: 7068)
      • AppVClient.exe (PID: 8008)
      • MicrosoftEdgeUpdate.exe (PID: 5196)
      • FXSSVC.exe (PID: 2356)
      • alg.exe (PID: 4384)
      • FlashPlayerUpdateService.exe (PID: 2732)
      • DiagnosticsHub.StandardCollector.Service.exe (PID: 2760)
      • updater.exe (PID: 2288)
      • maintenanceservice.exe (PID: 5192)
      • GameInputSvc.exe (PID: 5580)
      • updater.exe (PID: 7256)
      • msdtc.exe (PID: 7012)
      • PerceptionSimulationService.exe (PID: 8260)
      • perfhost.exe (PID: 8364)
      • PSEXESVC.exe (PID: 8396)
      • Locator.exe (PID: 8452)
      • SensorDataService.exe (PID: 8520)
      • Spectrum.exe (PID: 8632)
      • ssh-agent.exe (PID: 8700)
      • snmptrap.exe (PID: 8572)
      • TieringEngineService.exe (PID: 8744)
      • AgentService.exe (PID: 8852)
      • vds.exe (PID: 8892)
      • wbengine.exe (PID: 8944)
      • WmiApSrv.exe (PID: 9016)
    • Searches for installed software

      • 3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe (PID: 2364)
    • Creates files in the driver directory

      • 3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe (PID: 2364)
    • Application launched itself

      • GameInputSvc.exe (PID: 5580)
    • Process drops legitimate windows executable

      • 3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe (PID: 2364)
    • Executable content was dropped or overwritten

      • 3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe (PID: 2364)
    • Reads security settings of Internet Explorer

      • 3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe (PID: 2364)
    • The process executes via Task Scheduler

      • verclsid.exe (PID: 2332)
  • INFO

    • Checks supported languages

      • 3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe (PID: 2364)
      • armsvc.exe (PID: 7068)
      • MicrosoftEdgeUpdate.exe (PID: 5196)
      • FlashPlayerUpdateService.exe (PID: 2732)
      • elevation_service.exe (PID: 5584)
      • maintenanceservice.exe (PID: 5192)
      • PSEXESVC.exe (PID: 8396)
      • ssh-agent.exe (PID: 8700)
      • identity_helper.exe (PID: 4852)
    • Creates files or folders in the user directory

      • 3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe (PID: 2364)
      • BackgroundTransferHost.exe (PID: 9880)
    • Create files in a temporary directory

      • 3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe (PID: 2364)
    • The sample compiled with english language support

      • 3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe (PID: 2364)
      • msedge.exe (PID: 3116)
    • Reads the computer name

      • 3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe (PID: 2364)
      • armsvc.exe (PID: 7068)
      • MicrosoftEdgeUpdate.exe (PID: 5196)
      • FlashPlayerUpdateService.exe (PID: 2732)
      • elevation_service.exe (PID: 5584)
      • maintenanceservice.exe (PID: 5192)
      • PSEXESVC.exe (PID: 8396)
      • ssh-agent.exe (PID: 8700)
      • identity_helper.exe (PID: 4852)
    • Reads the machine GUID from the registry

      • 3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe (PID: 2364)
    • Creates files in the program directory

      • 3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe (PID: 2364)
      • FXSSVC.exe (PID: 2356)
      • maintenanceservice.exe (PID: 5192)
      • SearchIndexer.exe (PID: 9080)
    • Reads the software policy settings

      • GameInputSvc.exe (PID: 2400)
      • BackgroundTransferHost.exe (PID: 9880)
      • slui.exe (PID: 8472)
    • Executes as Windows Service

      • elevation_service.exe (PID: 5584)
      • SearchIndexer.exe (PID: 9080)
    • Checks proxy server information

      • 3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe (PID: 2364)
      • BackgroundTransferHost.exe (PID: 9880)
      • slui.exe (PID: 8472)
    • Reads the time zone

      • TieringEngineService.exe (PID: 8744)
    • The sample compiled with bulgarian language support

      • 3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe (PID: 2364)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 9316)
      • SearchProtocolHost.exe (PID: 10056)
      • BackgroundTransferHost.exe (PID: 4184)
      • BackgroundTransferHost.exe (PID: 9596)
      • BackgroundTransferHost.exe (PID: 9880)
    • Application launched itself

      • msedge.exe (PID: 9476)
      • msedge.exe (PID: 9424)
      • msedge.exe (PID: 9904)
    • Manual execution by a user

      • msedge.exe (PID: 9904)
    • Reads Environment values

      • identity_helper.exe (PID: 4852)
    • Executable content was dropped or overwritten

      • msedge.exe (PID: 3116)
      • msedge.exe (PID: 9904)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:08:11 15:09:09+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.38
CodeSize: 813568
InitializedDataSize: 1983488
UninitializedDataSize: -
EntryPoint: 0x93875
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 5.3.7.131
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Malwarebytes
FileDescription: Malwarebytes Setup
FileVersion: 5.3.7.131
LegalCopyright: Copyright (C) 2017 - 2024 Malwarebytes, Inc. All rights reserved.
InternalName: MBSetup.exe
OriginalFileName: MBSetup.exe
ProductName: Malwarebytes
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
250
Monitored processes
80
Malicious processes
36
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
992"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --string-annotations --disable-gpu-compositing --video-capture-use-gpu-memory-buffer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=3 --enable-main-frame-before-activation --renderer-client-id=14 --always-read-main-dll --field-trial-handle=5812,i,12623197750456195086,9627366442747122732,262144 --variations-seed-version --mojo-platform-channel-handle=6072 /prefetch:1C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1852"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --disable-gpu-sandbox --use-gl=disabled --gpu-vendor-id=5140 --gpu-device-id=140 --gpu-sub-system-id=0 --gpu-revision=0 --gpu-driver-version=10.0.19041.3636 --string-annotations --gpu-preferences=UAAAAAAAAADoAAAEAAAAAAAAAAAAAAAAAABgAAEAAAAAAAAAAAAAAAAAAABCAAAAAAAAAAAAAAAAAAAAAAAAABAAAAAAAAAAEAAAAAAAAAAIAAAAAAAAAAgAAAAAAAAA --always-read-main-dll --field-trial-handle=5092,i,12623197750456195086,9627366442747122732,262144 --variations-seed-version --mojo-platform-channel-handle=1660 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2288"C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe" --system --windows-service --service=update-internalC:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe
services.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Updater
Exit code:
0
Version:
134.0.6985.0
Modules
Images
c:\program files (x86)\google\googleupdater\134.0.6985.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
2332"C:\WINDOWS\system32\verclsid.exe" /S /C {9E175B8B-F52A-11D8-B9A5-505054503030} /I {0C733A8A-2A1C-11CE-ADE5-00AA0044773D} /X 0x401C:\Windows\System32\verclsid.exeRuntimeBroker.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Extension CLSID Verification Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\verclsid.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\combase.dll
c:\windows\system32\gdi32.dll
2356C:\WINDOWS\system32\fxssvc.exeC:\Windows\System32\FXSSVC.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Fax Service
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\fxssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\shlwapi.dll
2364"C:\Users\admin\Desktop\3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe" C:\Users\admin\Desktop\3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe
explorer.exe
User:
admin
Company:
Malwarebytes
Integrity Level:
HIGH
Description:
Malwarebytes Setup
Version:
5.3.7.131
Modules
Images
c:\users\admin\desktop\3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\crypt32.dll
2400"C:\WINDOWS\System32\GameInputSvc.exe" Global\GameInputSession_1C:\Windows\System32\GameInputSvc.exe
GameInputSvc.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
GameInput Host Service
Version:
0.2309.19041.4046
Modules
Images
c:\windows\system32\gameinputsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\wintrust.dll
2428C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2480"C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=edge_collections.mojom.CollectionsDataManager --lang=en-US --service-sandbox-type=collections --disable-quic --string-annotations --always-read-main-dll --field-trial-handle=6040,i,12623197750456195086,9627366442747122732,262144 --variations-seed-version --mojo-platform-channel-handle=6036 /prefetch:8C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
133.0.3065.92
Modules
Images
c:\program files (x86)\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files (x86)\microsoft\edge\application\133.0.3065.92\msedge_elf.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2504"C:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe" --wake --systemC:\Program Files (x86)\Google\GoogleUpdater\134.0.6985.0\updater.exe
updater.exe
User:
SYSTEM
Company:
Google LLC
Integrity Level:
SYSTEM
Description:
Google Updater
Exit code:
0
Version:
134.0.6985.0
Modules
Images
c:\program files (x86)\google\googleupdater\134.0.6985.0\updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
Total events
231 717
Read events
231 540
Write events
151
Delete events
26

Modification events

(PID) Process:(2364) 3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\mbamtestkey
Operation:delete keyName:(default)
Value:
(PID) Process:(7068) armsvc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Adobe\Adobe ARM\1.0\ARM
Operation:writeName:iLastSvcSuccess
Value:
1515796
(PID) Process:(2356) FXSSVC.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fax
Operation:writeName:RedirectionGuard
Value:
1
(PID) Process:(2356) FXSSVC.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fax\Receipts
Operation:writeName:Password
Value:
00
(PID) Process:(2356) FXSSVC.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fax\Receipts
Operation:delete valueName:Password
Value:
(PID) Process:(2356) FXSSVC.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fax\Receipts
Operation:writeName:Server
Value:
(PID) Process:(2356) FXSSVC.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fax\Receipts
Operation:writeName:From
Value:
(PID) Process:(2356) FXSSVC.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Fax\Receipts
Operation:writeName:User
Value:
(PID) Process:(9016) WmiApSrv.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Wbem\PROVIDERS\Performance
Operation:writeName:Performance Refreshed
Value:
0
(PID) Process:(9080) SearchIndexer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Search
Operation:writeName:SchemaCacheTimestamp
Value:
30F44CD30259DA01
Executable files
157
Suspicious files
343
Text files
66
Unknown types
0

Dropped files

PID
Process
Filename
Type
23643c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exeC:\Program Files (x86)\Common Files\Adobe\ARM\1.0\armsvc.exeexecutable
MD5:63513FF1677DF2B2E09560264C7383BA
SHA256:6515F8323F74D16E6D3EF6F0BAA54DE90433DB43D27D34966EB8A2E809FA9EED
23643c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exeC:\Program Files (x86)\mbamtestfile.dattext
MD5:9F06243ABCB89C70E0C331C61D871FA7
SHA256:837CCB607E312B170FAC7383D7CCFD61FA5072793F19A25E75FBACB56539B86B
7068armsvc.exeC:\Windows\SysWOW64\config\systemprofile\AppData\Roaming\26b799fa89ba8c8f.binbinary
MD5:E8EE78B76A3AEDD8E2191546DD7E91E1
SHA256:44EF8477F9913591D0FA4A3C56EC3751EB014F524BB4869BC0E5590431A537A6
23643c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exeC:\Windows\System32\alg.exeexecutable
MD5:7D158BF598C53BA82A761F78B8E0EFF9
SHA256:8AF970256E52B3F08DA1B71C609CE6C5ED1CD51C4C70029DC30ECEEF73084247
23643c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exeC:\Program Files (x86)\Mozilla Maintenance Service\maintenanceservice.exeexecutable
MD5:99047182CA21992F7CB918A5E5A5FEF2
SHA256:6F45A82851715AFD2D44B77C5C95A238CEB5623755C3C6F3EF1FD305D1EA33B2
2816updater.exeC:\Program Files (x86)\Google\GoogleUpdater\updater.logtext
MD5:55B55FE5AEE500616EEA87E64034C4A6
SHA256:56000D3F34584DD774EAE47C79510D92B8A6769E21F69F54D5F651D70EAC88BB
23643c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exeC:\Users\admin\AppData\Roaming\26b799fa89ba8c8f.binbinary
MD5:E2EB76081F654368B9FE21B240D267EA
SHA256:2F72A21C44F57199738480F1B0A8D5D11F544D82C9743D59742BA66C1BA33203
23643c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exeC:\Windows\SysWOW64\Macromed\Flash\FlashPlayerUpdateService.exeexecutable
MD5:6CF76A12764CBE76492E901F454BDE7B
SHA256:24AEE56B1F0D114CDA5686617F9386C2456947939F3F3438DBEF0A85A5CA4DF2
23643c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exeC:\Windows\SysWOW64\drivers\mbamtestfile.dattext
MD5:9F06243ABCB89C70E0C331C61D871FA7
SHA256:837CCB607E312B170FAC7383D7CCFD61FA5072793F19A25E75FBACB56539B86B
23643c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exeC:\ProgramData\mbamtestfile.dattext
MD5:9F06243ABCB89C70E0C331C61D871FA7
SHA256:837CCB607E312B170FAC7383D7CCFD61FA5072793F19A25E75FBACB56539B86B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
360
TCP/UDP connections
256
DNS requests
218
Threats
14

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7068
armsvc.exe
POST
200
44.244.22.128:80
http://pywolwnvd.biz/j
US
malicious
2364
3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe
POST
200
44.244.22.128:80
http://pywolwnvd.biz/mvo
US
malicious
7068
armsvc.exe
POST
200
50.16.27.236:80
http://ssbzmoy.biz/kvfmnmurtg
US
unknown
2364
3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe
POST
200
50.16.27.236:80
http://ssbzmoy.biz/gcqnvokv
US
unknown
7068
armsvc.exe
POST
200
44.244.22.128:80
http://cvgrf.biz/hduwspl
US
malicious
2364
3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe
POST
200
44.244.22.128:80
http://cvgrf.biz/arfuixqvth
US
malicious
7068
armsvc.exe
POST
200
3.229.117.57:80
http://npukfztj.biz/nftv
US
malicious
2364
3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe
POST
200
3.229.117.57:80
http://npukfztj.biz/afpl
US
malicious
7068
armsvc.exe
POST
200
172.237.146.8:80
http://przvgke.biz/sojglim
US
binary
4.34 Kb
unknown
2364
3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe
POST
200
172.237.146.8:80
http://przvgke.biz/auesjd
US
binary
4.34 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3404
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
6016
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2364
3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe
44.244.22.128:80
pywolwnvd.biz
AMAZON-02
US
malicious
7068
armsvc.exe
44.244.22.128:80
pywolwnvd.biz
AMAZON-02
US
malicious
7068
armsvc.exe
50.16.27.236:80
ssbzmoy.biz
AMAZON-AES
US
malicious
2364
3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe
50.16.27.236:80
ssbzmoy.biz
AMAZON-AES
US
malicious
5948
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7068
armsvc.exe
3.229.117.57:80
npukfztj.biz
AMAZON-AES
US
malicious

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.206
whitelisted
pywolwnvd.biz
  • 44.244.22.128
malicious
ssbzmoy.biz
  • 50.16.27.236
unknown
cvgrf.biz
  • 44.244.22.128
malicious
npukfztj.biz
  • 3.229.117.57
malicious
przvgke.biz
  • 172.237.146.8
  • 172.233.219.49
  • 172.237.146.25
  • 172.237.146.38
  • 172.233.219.78
  • 172.233.219.123
unknown
zlenh.biz
unknown
knjghuig.biz
  • 50.16.27.236
malicious
uhxqin.biz
malicious

Threats

PID
Process
Class
Message
2428
svchost.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/m0yv CnC related domain (zlenh .biz)
2428
svchost.exe
A Network Trojan was detected
ET MALWARE DNS Query to Expiro Related Domain (knjghuig .biz)
2428
svchost.exe
A Network Trojan was detected
ET MALWARE DNS Query to Expiro Related Domain (knjghuig .biz)
2364
3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe
Misc activity
ET INFO Namecheap URL Forward
7068
armsvc.exe
Misc activity
ET INFO Namecheap URL Forward
7068
armsvc.exe
Misc activity
ET INFO Namecheap URL Forward
2364
3c7abe58e501ae08895aa05345596adfb9a7f434cf47975565325975d2d06391.exe
Misc activity
ET INFO Namecheap URL Forward
3116
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
3116
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
3116
msedge.exe
Not Suspicious Traffic
INFO [ANY.RUN] Google Tag Manager analytics (googletagmanager .com)
No debug info