| File name: | 43b9d6403174aca0ddd8ef49cd6f7c7570940fbc1b2a1f543ff772174aad67a8 |
| Full analysis: | https://app.any.run/tasks/1d2d732d-f6d8-47a3-8900-50575fd2a8af |
| Verdict: | Malicious activity |
| Threats: | Glupteba is a loader with information-stealing and traffic routing functionality. It is designed primarily to install other viruses on infected PCs but can do much more than that. In addition, it is being constantly updated, making this virus one to watch out for. |
| Analysis date: | April 22, 2025, 05:17:44 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections |
| MD5: | 0391BB0E33FDFD666972B1770667AAF7 |
| SHA1: | E79556C496C58440A97F0D47F01B2FDF462E769A |
| SHA256: | 43B9D6403174ACA0DDD8EF49CD6F7C7570940FBC1B2A1F543FF772174AAD67A8 |
| SSDEEP: | 98304:IkjHfew03++HY1Wna9/3bP1BxdLYGm42Tb3F2LdKgKBxk4nsjPC9UHcFnhqo4hEL:GShOzaLCV |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:12:22 14:08:57+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 4237824 |
| InitializedDataSize: | 5111808 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x758f |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 18.0.0.0 |
| ProductVersionNumber: | 8.0.0.0 |
| FileFlagsMask: | 0x183a |
| FileFlags: | (none) |
| FileOS: | Unknown (0x20461) |
| ObjectFileType: | Unknown |
| FileSubtype: | - |
| LanguageCode: | Faeroese |
| CharacterSet: | Unknown (31F6) |
| LegalCopyright: | Copyright (C) 2023, parking |
| OriginalFileName: | bigthing.exe |
| ProductsVersion: | 36.47.26.15 |
| ProductName: | SolarOmir |
| ProductionVersion: | 1.24.17.52 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 680 | "C:\WINDOWS\system32\fodhelper.exe" | C:\Windows\System32\fodhelper.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Features On Demand Helper Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 680 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | powershell.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1132 | C:\WINDOWS\Sysnative\cmd.exe /C "netsh advfirewall firewall add rule name="csrss" dir=in action=allow program="C:\WINDOWS\rss\csrss.exe" enable=yes" | C:\Windows\System32\cmd.exe | — | 43b9d6403174aca0ddd8ef49cd6f7c7570940fbc1b2a1f543ff772174aad67a8.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1280 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2148 | netsh advfirewall firewall add rule name="csrss" dir=in action=allow program="C:\WINDOWS\rss\csrss.exe" enable=yes | C:\Windows\System32\netsh.exe | — | cmd.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Network Command Shell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2196 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2344 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2168 -parentBuildID 20240213221259 -prefsHandle 2156 -prefMapHandle 2144 -prefsLen 31031 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {925977ca-47bb-4784-8132-5e61ac452243} 6656 "\\.\pipe\gecko-crash-server-pipe.6656" 1d471780110 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Version: 123.0 Modules
| |||||||||||||||
| 2420 | "C:\Users\admin\AppData\Local\Temp\43b9d6403174aca0ddd8ef49cd6f7c7570940fbc1b2a1f543ff772174aad67a8.exe" | C:\Users\admin\AppData\Local\Temp\43b9d6403174aca0ddd8ef49cd6f7c7570940fbc1b2a1f543ff772174aad67a8.exe | 43b9d6403174aca0ddd8ef49cd6f7c7570940fbc1b2a1f543ff772174aad67a8.exe | ||||||||||||
User: SYSTEM Integrity Level: SYSTEM Modules
| |||||||||||||||
| 2504 | "C:\Users\admin\AppData\Local\Temp\43b9d6403174aca0ddd8ef49cd6f7c7570940fbc1b2a1f543ff772174aad67a8.exe" | C:\Users\admin\AppData\Local\Temp\43b9d6403174aca0ddd8ef49cd6f7c7570940fbc1b2a1f543ff772174aad67a8.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 2552 | powershell -nologo -noprofile | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | — | 43b9d6403174aca0ddd8ef49cd6f7c7570940fbc1b2a1f543ff772174aad67a8.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows PowerShell Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (2504) 43b9d6403174aca0ddd8ef49cd6f7c7570940fbc1b2a1f543ff772174aad67a8.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\fde20f96 |
| Operation: | write | Name: | Servers |
Value: https://окрф.рф | |||
| (PID) Process: | (2504) 43b9d6403174aca0ddd8ef49cd6f7c7570940fbc1b2a1f543ff772174aad67a8.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\fde20f96 |
| Operation: | write | Name: | UUID |
Value: | |||
| (PID) Process: | (2504) 43b9d6403174aca0ddd8ef49cd6f7c7570940fbc1b2a1f543ff772174aad67a8.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\fde20f96 |
| Operation: | write | Name: | FirstInstallDate |
Value: 8026076800000000 | |||
| (PID) Process: | (2504) 43b9d6403174aca0ddd8ef49cd6f7c7570940fbc1b2a1f543ff772174aad67a8.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\fde20f96 |
| Operation: | write | Name: | ServiceVersion |
Value: | |||
| (PID) Process: | (2504) 43b9d6403174aca0ddd8ef49cd6f7c7570940fbc1b2a1f543ff772174aad67a8.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\fde20f96 |
| Operation: | write | Name: | PGDSE |
Value: 0000000000000000 | |||
| (PID) Process: | (2504) 43b9d6403174aca0ddd8ef49cd6f7c7570940fbc1b2a1f543ff772174aad67a8.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\fde20f96 |
| Operation: | write | Name: | ServersVersion |
Value: C300000000000000 | |||
| (PID) Process: | (2504) 43b9d6403174aca0ddd8ef49cd6f7c7570940fbc1b2a1f543ff772174aad67a8.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\fde20f96 |
| Operation: | write | Name: | OSCaption |
Value: Microsoft Windows 10 Pro | |||
| (PID) Process: | (2504) 43b9d6403174aca0ddd8ef49cd6f7c7570940fbc1b2a1f543ff772174aad67a8.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\fde20f96 |
| Operation: | write | Name: | OSArchitecture |
Value: 64-bit | |||
| (PID) Process: | (2504) 43b9d6403174aca0ddd8ef49cd6f7c7570940fbc1b2a1f543ff772174aad67a8.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\fde20f96 |
| Operation: | write | Name: | IsAdmin |
Value: 1 | |||
| (PID) Process: | (2504) 43b9d6403174aca0ddd8ef49cd6f7c7570940fbc1b2a1f543ff772174aad67a8.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\fde20f96 |
| Operation: | write | Name: | AV |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4188 | powershell.exe | C:\Windows\Temp\__PSScriptPolicyTest_i4x5ctkq.0re.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 2552 | powershell.exe | C:\Windows\Temp\__PSScriptPolicyTest_ukb4cjre.wj2.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 2552 | powershell.exe | C:\Windows\Temp\__PSScriptPolicyTest_x0rhipnx.qib.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 4188 | powershell.exe | C:\Windows\Temp\__PSScriptPolicyTest_ybsxxdub.lvr.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 2552 | powershell.exe | C:\Windows\SysWOW64\config\systemprofile\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-Interactive | binary | |
MD5:A5929777B5B1794924FF7968068F6C37 | SHA256:712DDD0A211611258DA83FEB2285D76C412C035F5DC0C743647201106118A3D3 | |||
| 2552 | powershell.exe | C:\Windows\Temp\__PSScriptPolicyTest_gsurjykz.5nd.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 6656 | firefox.exe | C:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin | — | |
MD5:— | SHA256:— | |||
| 5968 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_kctcm3wu.ugv.ps1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
| 5968 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-Interactive | binary | |
MD5:08541B6326616C2978C79BD4F25A7F2A | SHA256:1DF3078DE9DCB18A621833D3EE8501CC9767FD6E4F0B5B03FA3B9F12B5AAA2D4 | |||
| 5968 | powershell.exe | C:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_4yufojve.3ep.psm1 | text | |
MD5:D17FE0A3F47BE24A6453E9EF58C94641 | SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.216.77.6:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
668 | SIHClient.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
668 | SIHClient.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
6656 | firefox.exe | POST | 200 | 2.16.168.113:80 | http://r11.o.lencr.org/ | unknown | — | — | whitelisted |
6656 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
6656 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
6656 | firefox.exe | POST | 200 | 142.250.185.163:80 | http://o.pki.goog/s/wr3/cgo | unknown | — | — | whitelisted |
6656 | firefox.exe | POST | — | 142.250.185.163:80 | http://o.pki.goog/s/wr3/UTA | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2104 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 23.216.77.6:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 2.23.181.156:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3216 | svchost.exe | 172.211.123.249:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6544 | svchost.exe | 40.126.31.131:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6544 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
2112 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
c1761ce5-a623-4195-b636-a63888545a2d.uuid.xn--j1ahhq.xn--p1ai |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
2196 | svchost.exe | Misc activity | ET INFO Observed Discord Domain in DNS Lookup (discordapp .com) |
4212 | csrss.exe | Misc activity | ET INFO Observed Discord Domain (discordapp .com in TLS SNI) |