| File name: | ä¸é®éå¾äºæ¬¡å .exe |
| Full analysis: | https://app.any.run/tasks/902b5b95-ccc0-43f1-8689-50c7921f5d91 |
| Verdict: | Malicious activity |
| Analysis date: | June 22, 2025, 06:59:03 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows, 6 sections |
| MD5: | 16ABB374EB1B759235AAEA1B03EEF712 |
| SHA1: | 495B467CE61E5D891690FAED3CAABCB04156C56A |
| SHA256: | 4608BCC2632C46335CD9FABEED46837C4FAE07D624BC86CDBB43CECC0B701DD1 |
| SSDEEP: | 393216:LlvWJzq/qE6xebU0ybDPEHDO+hGLZFMwdIhaQE:L1WJzq/5RJfjOu+W0 |
| .exe | | | InstallShield setup (57.6) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (36.9) |
| .exe | | | Generic Win/DOS Executable (2.6) |
| .exe | | | DOS Executable Generic (2.6) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2025:06:20 05:27:02+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 14.4 |
| CodeSize: | 167936 |
| InitializedDataSize: | 104448 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xbe20 |
| OSVersion: | 5.2 |
| ImageVersion: | - |
| SubsystemVersion: | 5.2 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 632 | "C:\Users\admin\AppData\Local\Temp\ä¸é®éå¾äºæ¬¡å .exe" | C:\Users\admin\AppData\Local\Temp\ä¸é®éå¾äºæ¬¡å .exe | ä¸é®éå¾äºæ¬¡å .exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 2296 | C:\WINDOWS\system32\cmd.exe /c notepad %UserProfile%\Desktop\PLEASE_README_TO_SAVE.txt | C:\Windows\System32\cmd.exe | — | ä¸é®éå¾äºæ¬¡å .exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2808 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4372 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4580 | attrib +s +h "C:\Users\admin\Desktop\logo.ico" | C:\Windows\System32\attrib.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Attribute Utility Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4768 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4816 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5780 | notepad C:\Users\admin\Desktop\PLEASE_README_TO_SAVE.txt | C:\Windows\System32\notepad.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5900 | attrib +s +h "C:\Users\admin\Desktop\main_bg.png" | C:\Windows\System32\attrib.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Attribute Utility Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6228 | C:\WINDOWS\system32\cmd.exe /c attrib +s +h "C:\Users\admin\Desktop\logo.ico" | C:\Windows\System32\cmd.exe | — | ä¸é®éå¾äºæ¬¡å .exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (632) ä¸é®éå¾äºæ¬¡å .exe | Key: | HKEY_CURRENT_USER\Control Panel\Desktop |
| Operation: | write | Name: | Wallpaper |
Value: %UserProfile%\Desktop\main_bg.png | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6680 | ä¸é®éå¾äºæ¬¡å .exe | C:\Users\admin\AppData\Local\Temp\_MEI66802\PIL\_imaging.cp312-win_amd64.pyd | executable | |
MD5:0376776F076CD4F4AC15EC4D813C5470 | SHA256:A7DDF4D7CAB08676BB88A42059353C5374600901B3AB880E17EE1A0D0150C380 | |||
| 6680 | ä¸é®éå¾äºæ¬¡å .exe | C:\Users\admin\AppData\Local\Temp\_MEI66802\PIL\_imagingcms.cp312-win_amd64.pyd | executable | |
MD5:48F7F14636DA0BC081A34ACBFE30D77D | SHA256:3C2CEDEBABB5748F78FBA56634FD49CDAAD02C18D808D7E2B4F50E2800C7930F | |||
| 6680 | ä¸é®éå¾äºæ¬¡å .exe | C:\Users\admin\AppData\Local\Temp\_MEI66802\Pythonwin\win32ui.pyd | executable | |
MD5:621449EFF843B6128E15BA20B40E2688 | SHA256:AA9F43412393CD50340570ABF6AE6FD5C3A2119555B5D6CAF43AC693CC2AA244 | |||
| 6680 | ä¸é®éå¾äºæ¬¡å .exe | C:\Users\admin\AppData\Local\Temp\_MEI66802\VCRUNTIME140.dll | executable | |
MD5:BE8DBE2DC77EBE7F88F910C61AEC691A | SHA256:4D292623516F65C80482081E62D5DADB759DC16E851DE5DB24C3CBB57B87DB83 | |||
| 6680 | ä¸é®éå¾äºæ¬¡å .exe | C:\Users\admin\AppData\Local\Temp\_MEI66802\PIL\_webp.cp312-win_amd64.pyd | executable | |
MD5:12D05951F8004E24EEAA0E45D587FE8E | SHA256:D96B196126A033F1D7832E29CEE44928683FAB00242E812815FF95FFFED1AF54 | |||
| 6680 | ä¸é®éå¾äºæ¬¡å .exe | C:\Users\admin\AppData\Local\Temp\_MEI66802\_asyncio.pyd | executable | |
MD5:70FB0B118AC9FD3292DDE530E1D789B8 | SHA256:F8305023F6AD81DDC7124B311E500A58914B05A9B072BF9A6D079EA0F6257793 | |||
| 6680 | ä¸é®éå¾äºæ¬¡å .exe | C:\Users\admin\AppData\Local\Temp\_MEI66802\VCRUNTIME140_1.dll | executable | |
MD5:F8DFA78045620CF8A732E67D1B1EB53D | SHA256:A113F192195F245F17389E6ECBED8005990BCB2476DDAD33F7C4C6C86327AFE5 | |||
| 6680 | ä¸é®éå¾äºæ¬¡å .exe | C:\Users\admin\AppData\Local\Temp\_MEI66802\Pythonwin\mfc140u.dll | executable | |
MD5:84B82C149B450D3C8E0D06F09A416B5D | SHA256:1EC2A31A1302E720C799BAD2FD90CF3457C6B2A375C4B41FAEFEE1A91D92F3E0 | |||
| 6680 | ä¸é®éå¾äºæ¬¡å .exe | C:\Users\admin\AppData\Local\Temp\_MEI66802\PIL\_imagingtk.cp312-win_amd64.pyd | executable | |
MD5:7E912D07A39E16BB25CF32B7153515C8 | SHA256:D1E5D023821A9C38967FFAA9BDBF4DDE998A3A6BC37942CA334A13E55A1FC711 | |||
| 6680 | ä¸é®éå¾äºæ¬¡å .exe | C:\Users\admin\AppData\Local\Temp\_MEI66802\PIL\_imagingmath.cp312-win_amd64.pyd | executable | |
MD5:8F67156CE61C7DE23E19F9445C8BA504 | SHA256:8287A2A551BD99B5D55E18E461FEDB3704B74B0FB60F1E0881C792F90A18CE46 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3100 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 184.24.77.12:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
2940 | svchost.exe | GET | 200 | 2.16.252.233:80 | http://x1.c.lencr.org/ | unknown | — | — | whitelisted |
6376 | SIHClient.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
6376 | SIHClient.exe | GET | 200 | 2.23.181.156:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1268 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6172 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3100 | svchost.exe | 20.190.159.2:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3100 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
2336 | svchost.exe | 172.211.123.249:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
632 | ä¸é®éå¾äºæ¬¡å
.exe | 49.232.237.64:443 | tc.z.wiki | Shenzhen Tencent Computer Systems Company Limited | CN | unknown |
1268 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
tc.z.wiki |
| unknown |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
nexusrules.officeapps.live.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |