File name:

24087zx64.exe

Full analysis: https://app.any.run/tasks/ddd75907-07d8-4032-9ad1-6d82251bba56
Verdict: Malicious activity
Analysis date: June 01, 2025, 15:24:25
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
upx
golang
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (console) Intel 80386, for MS Windows, 7 sections
MD5:

FB968DAC5D14257ED11BE4903FA8C484

SHA1:

E4A7B6268879B2B0357D7AAB34A3F03BBC751D28

SHA256:

43C962DDE0E3943280CCA5E1D9C2B838E4AA59564A95D47B72D9C5B4DA6E0015

SSDEEP:

196608:uuptU25l38nFoKlNjqYN0smNd9x9LJNlAMRVl+Rx2j86sHx:uiUQlsnFDNeY9mNbLJf/RVlwem

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes Windows Defender settings

      • 6UtzjLuhPEgJkT6.exe (PID: 3268)
    • Adds path to the Windows Defender exclusion list

      • 6UtzjLuhPEgJkT6.exe (PID: 3268)
  • SUSPICIOUS

    • Application launched itself

      • 24087zx64.exe (PID: 1176)
      • CoreToolsMgrHelper.exe (PID: 6392)
      • CoreToolsMgrHelper.exe (PID: 6368)
      • CoreToolsMgrHelper.exe (PID: 5360)
    • Executable content was dropped or overwritten

      • 24087zx64.exe (PID: 3968)
      • 6UtzjLuhPEgJkT6.exe (PID: 3268)
    • Reads security settings of Internet Explorer

      • 24087zx64.exe (PID: 1176)
    • Drops 7-zip archiver for unpacking

      • 24087zx64.exe (PID: 3968)
    • Process drops legitimate windows executable

      • 6UtzjLuhPEgJkT6.exe (PID: 3268)
    • The process drops C-runtime libraries

      • 6UtzjLuhPEgJkT6.exe (PID: 3268)
    • Script adds exclusion path to Windows Defender

      • 6UtzjLuhPEgJkT6.exe (PID: 3268)
    • Starts POWERSHELL.EXE for commands execution

      • 6UtzjLuhPEgJkT6.exe (PID: 3268)
    • The process executes via Task Scheduler

      • CoreToolsMgrHelper.exe (PID: 5360)
    • Connects to unusual port

      • CoreToolsMgrHelper.exe (PID: 6136)
      • CoreToolsMgrHelper.exe (PID: 5008)
  • INFO

    • The sample compiled with chinese language support

      • 24087zx64.exe (PID: 1176)
      • 6UtzjLuhPEgJkT6.exe (PID: 3268)
    • Create files in a temporary directory

      • 24087zx64.exe (PID: 3968)
      • 6UtzjLuhPEgJkT6.exe (PID: 3268)
      • CoreToolsMgrHelper.exe (PID: 6136)
    • Checks supported languages

      • 24087zx64.exe (PID: 1176)
      • Qlrjdf31Q75C7F6.exe (PID: 6248)
      • 6UtzjLuhPEgJkT6.exe (PID: 3268)
      • CoreToolsMgrHelper.exe (PID: 6392)
      • CoreToolsMgrHelper.exe (PID: 5008)
      • CoreToolsMgrHelper.exe (PID: 6368)
      • CoreToolsMgrHelper.exe (PID: 5360)
      • CoreToolsMgrHelper.exe (PID: 6136)
    • Process checks computer location settings

      • 24087zx64.exe (PID: 1176)
    • Reads the computer name

      • 24087zx64.exe (PID: 1176)
      • Qlrjdf31Q75C7F6.exe (PID: 6248)
      • 6UtzjLuhPEgJkT6.exe (PID: 3268)
      • CoreToolsMgrHelper.exe (PID: 6392)
      • CoreToolsMgrHelper.exe (PID: 5008)
      • CoreToolsMgrHelper.exe (PID: 6136)
    • The sample compiled with english language support

      • 24087zx64.exe (PID: 3968)
      • 6UtzjLuhPEgJkT6.exe (PID: 3268)
    • Checks if a key exists in the options dictionary (POWERSHELL)

      • powershell.exe (PID: 3156)
    • Script raised an exception (POWERSHELL)

      • powershell.exe (PID: 3156)
    • Drops encrypted JS script (Microsoft Script Encoder)

      • 6UtzjLuhPEgJkT6.exe (PID: 3268)
    • UPX packer has been detected

      • CoreToolsMgrHelper.exe (PID: 5360)
      • CoreToolsMgrHelper.exe (PID: 6368)
      • CoreToolsMgrHelper.exe (PID: 6136)
      • CoreToolsMgrHelper.exe (PID: 5008)
    • Application based on Golang

      • CoreToolsMgrHelper.exe (PID: 5360)
      • CoreToolsMgrHelper.exe (PID: 6368)
      • CoreToolsMgrHelper.exe (PID: 6136)
      • CoreToolsMgrHelper.exe (PID: 5008)
    • Reads the software policy settings

      • slui.exe (PID: 7812)
    • Checks proxy server information

      • slui.exe (PID: 7812)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (83.4)
.exe | Win32 Executable (generic) (8.7)
.exe | Generic Win/DOS Executable (3.8)
.exe | DOS Executable Generic (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 0000:00:00 00:00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 3
CodeSize: 2899456
InitializedDataSize: 295936
UninitializedDataSize: -
EntryPoint: 0x782c0
OSVersion: 6.1
ImageVersion: 1
SubsystemVersion: 6.1
Subsystem: Windows command line
FileVersionNumber: 3.1.9.7264
ProductVersionNumber: 3.1.9.7264
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Windows, Chinese (Simplified)
Comments: 请仔细阅读许可协议
CompanyName: 网易公司
FileDescription: 网易云音乐
FileVersion: 3.1.9.203872
LegalCopyright: 网易公司版权所有Copyright (C)1997-2014
ProductName: 网易云音乐
ProductVersion: 3.1.9.203872
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
14
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 24087zx64.exe no specs conhost.exe no specs 24087zx64.exe 6utzjluhpegjkt6.exe conhost.exe no specs qlrjdf31q75c7f6.exe no specs coretoolsmgrhelper.exe no specs powershell.exe no specs conhost.exe no specs coretoolsmgrhelper.exe no specs coretoolsmgrhelper.exe no specs coretoolsmgrhelper.exe coretoolsmgrhelper.exe slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
1176"C:\Users\admin\AppData\Local\Temp\24087zx64.exe" C:\Users\admin\AppData\Local\Temp\24087zx64.exeexplorer.exe
User:
admin
Company:
网易公司
Integrity Level:
MEDIUM
Description:
网易云音乐
Version:
3.1.9.203872
Modules
Images
c:\users\admin\appdata\local\temp\24087zx64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\bcryptprimitives.dll
1348\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe24087zx64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3156powershell.exe Add-MpPreference -ExclusionPath 'C:\Users\admin\AppData\Local\Temp' -ForceC:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe6UtzjLuhPEgJkT6.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
3268"C:\Users\admin\AppData\Local\Temp\Jek}lzzZcSFsfew\6UtzjLuhPEgJkT6.exe"C:\Users\admin\AppData\Local\Temp\Jek}lzzZcSFsfew\6UtzjLuhPEgJkT6.exe
24087zx64.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\jek}lzzzcsfsfew\6utzjluhpegjkt6.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\umpdc.dll
3968"C:\Users\admin\AppData\Local\Temp\24087zx64.exe" C:\C:\Users\admin\AppData\Local\Temp\24087zx64.exe
24087zx64.exe
User:
admin
Company:
网易公司
Integrity Level:
HIGH
Description:
网易云音乐
Exit code:
0
Version:
3.1.9.203872
5008C:\Users\admin\AppData\Local\Temp\DqQMiIMGWexzyhc\CoreToolsMgrHelper.exe MTQtMjE3LTUtNjM=C:\Users\admin\AppData\Local\Temp\DqQMiIMGWexzyhc\CoreToolsMgrHelper.exe
CoreToolsMgrHelper.exe
User:
admin
Company:
Zuler Network Technology Co., Ltd.
Integrity Level:
HIGH
Description:
Zuler Core Tools Manager Helper
Version:
1.1.0.1
Modules
Images
c:\users\admin\appdata\local\temp\dqqmiimgwexzyhc\coretoolsmgrhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5360"C:\Users\admin\AppData\Local\Temp\DqQMiIMGWexzyhc\CoreToolsMgrHelper.exe"C:\Users\admin\AppData\Local\Temp\DqQMiIMGWexzyhc\CoreToolsMgrHelper.exesvchost.exe
User:
admin
Company:
Zuler Network Technology Co., Ltd.
Integrity Level:
HIGH
Description:
Zuler Core Tools Manager Helper
Version:
1.1.0.1
Modules
Images
c:\users\admin\appdata\local\temp\dqqmiimgwexzyhc\coretoolsmgrhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
5776\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exe6UtzjLuhPEgJkT6.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6136C:\Users\admin\AppData\Local\Temp\DqQMiIMGWexzyhc\CoreToolsMgrHelper.exe MTQtMjE3LTUtNjM=C:\Users\admin\AppData\Local\Temp\DqQMiIMGWexzyhc\CoreToolsMgrHelper.exe
CoreToolsMgrHelper.exe
User:
admin
Company:
Zuler Network Technology Co., Ltd.
Integrity Level:
HIGH
Description:
Zuler Core Tools Manager Helper
Version:
1.1.0.1
Modules
Images
c:\users\admin\appdata\local\temp\dqqmiimgwexzyhc\coretoolsmgrhelper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
6248"C:\Users\admin\AppData\Local\Temp\Jek}lzzZcSFsfew\Qlrjdf31Q75C7F6.exe"C:\Users\admin\AppData\Local\Temp\Jek}lzzZcSFsfew\Qlrjdf31Q75C7F6.exe24087zx64.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Installer
Exit code:
1
Version:
24.08
Modules
Images
c:\users\admin\appdata\local\temp\jek}lzzzcsfsfew\qlrjdf31q75c7f6.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
Total events
10 064
Read events
10 064
Write events
0
Delete events
0

Modification events

No data
Executable files
46
Suspicious files
4
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
32686UtzjLuhPEgJkT6.exeC:\Users\admin\AppData\Local\Temp\DqQMiIMGWexzyhc\CoreToolsMgrHelper.exe.dump
MD5:
SHA256:
396824087zx64.exeC:\Users\admin\AppData\Local\Temp\Jek}lzzZcSFsfew\Qlrjdf31Q75C7F6.exeexecutable
MD5:0330D0BD7341A9AFE5B6D161B1FF4AA1
SHA256:67CB9D3452C9DD974B04F4A5FD842DBCBA8184F2344FF72E3662D7CDB68B099B
32686UtzjLuhPEgJkT6.exeC:\Users\admin\AppData\Local\Temp\DqQMiIMGWexzyhc\api-ms-win-core-errorhandling-l1-1-0.dllexecutable
MD5:2DB5666D3600A4ABCE86BE0099C6B881
SHA256:46079C0A1B660FC187AAFD760707F369D0B60D424D878C57685545A3FCE95819
32686UtzjLuhPEgJkT6.exeC:\Users\admin\AppData\Local\Temp\DqQMiIMGWexzyhc\api-ms-win-core-file-l2-1-0.dllexecutable
MD5:721B60B85094851C06D572F0BD5D88CD
SHA256:DAC867476CAA42FF8DF8F5DFE869FFD56A18DADEE17D47889AFB69ED6519AFBF
32686UtzjLuhPEgJkT6.exeC:\Users\admin\AppData\Local\Temp\DqQMiIMGWexzyhc\CoreToolsMgr.dllexecutable
MD5:B40DB04B4C25B1CD7FA1AE3119D97D90
SHA256:8A065C410BD39EBEE26E980F6136AD5CF4F56D4D2075C7C7B83A903E860A45EF
396824087zx64.exeC:\Users\admin\AppData\Local\Temp\Jek}lzzZcSFsfew\6UtzjLuhPEgJkT6.exeexecutable
MD5:E27F2932467CFBFB4AD8B0F956B84E6B
SHA256:AABB2EFCDA2914224823B680BBCAA57A5541E99E064C139D74BF7641A5BBD307
32686UtzjLuhPEgJkT6.exeC:\Users\admin\AppData\Local\Temp\DqQMiIMGWexzyhc\CoreToolsMgrHelper.exe.dbtext
MD5:2916EF69601E5281A1A436DDA9693983
SHA256:2A8F23E2C9452B6BCB0CE4F8E711719253847DBC38AA39717290DE5A19C07DD3
32686UtzjLuhPEgJkT6.exeC:\Users\admin\AppData\Local\Temp\DqQMiIMGWexzyhc\CoreToolsMgrHelper.exeexecutable
MD5:133531F8C1CE609AB2C3054EE306B929
SHA256:AA4E609EAAB9E93A47B87759AF005876555CAFB0CEB6B2FDE6CD426907ED40CA
32686UtzjLuhPEgJkT6.exeC:\Users\admin\AppData\Local\Temp\DqQMiIMGWexzyhc\api-ms-win-core-console-l1-1-0.dllexecutable
MD5:07EBE4D5CEF3301CCF07430F4C3E32D8
SHA256:8F8B79150E850ACC92FD6AAB614F6E3759BEA875134A62087D5DD65581E3001F
32686UtzjLuhPEgJkT6.exeC:\Users\admin\AppData\Local\Temp\DqQMiIMGWexzyhc\api-ms-win-core-datetime-l1-1-0.dllexecutable
MD5:557405C47613DE66B111D0E2B01F2FDB
SHA256:913EAAA7997A6AEE53574CFFB83F9C9C1700B1D8B46744A5E12D76A1E53376FD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
32
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
868 b
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
7704
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
QA
binary
407 b
whitelisted
7704
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
QA
binary
419 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6544
svchost.exe
20.190.159.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
6136
CoreToolsMgrHelper.exe
27.124.6.50:36676
BGPNET Global ASN
SG
unknown
5008
CoreToolsMgrHelper.exe
27.124.6.50:36676
BGPNET Global ASN
SG
unknown
6544
svchost.exe
40.126.31.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
login.live.com
  • 20.190.159.64
  • 40.126.31.71
  • 20.190.159.68
  • 20.190.159.23
  • 40.126.31.128
  • 20.190.159.75
  • 40.126.31.73
  • 40.126.31.130
  • 20.190.160.66
  • 20.190.160.64
  • 20.190.160.65
  • 20.190.160.131
  • 40.126.32.68
  • 20.190.160.20
  • 20.190.160.128
  • 40.126.32.136
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.78
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.145
  • 23.48.23.139
  • 23.48.23.138
  • 23.48.23.193
  • 23.48.23.191
  • 23.48.23.146
  • 23.48.23.158
  • 23.48.23.140
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 2.23.246.101
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
No debug info