File name:

091208478 DTD 10.07.2025 09750913 640976289-85665.exe

Full analysis: https://app.any.run/tasks/c653a81e-4e54-4e2a-973f-e32e39b9d4fa
Verdict: Malicious activity
Analysis date: July 11, 2025, 12:54:01
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

F54C3C32364C91454BEA24A1E6B98713

SHA1:

48554C55CB968BEEA125A5C3FCFDF164D2A6B874

SHA256:

4668DC8468E677499828C63E313945125134803D6C96FE431BB71C332A64BE49

SSDEEP:

49152:9J8NUhOlqhyQkwlC5f/z7/LeKMkeQRWKrs153XDo9Pzla0hTtmY6FmrmKCZLChLp:9J8KVjET7/yKNeuWVe9PpLRmYgmr0ZLA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • 091208478 DTD 10.07.2025 09750913 640976289-85665.exe (PID: 2040)
    • Changes the autorun value in the registry

      • 091208478 DTD 10.07.2025 09750913 640976289-85665.exe (PID: 2040)
      • wmlaunch.exe (PID: 5612)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • 091208478 DTD 10.07.2025 09750913 640976289-85665.exe (PID: 2040)
      • wmlaunch.exe (PID: 5612)
    • There is functionality for taking screenshot (YARA)

      • 091208478 DTD 10.07.2025 09750913 640976289-85665.exe (PID: 2040)
    • Reads security settings of Internet Explorer

      • wmlaunch.exe (PID: 5612)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • 091208478 DTD 10.07.2025 09750913 640976289-85665.exe (PID: 2040)
    • Executable content was dropped or overwritten

      • wmlaunch.exe (PID: 5612)
      • 091208478 DTD 10.07.2025 09750913 640976289-85665.exe (PID: 2040)
    • Connects to unusual port

      • wmlaunch.exe (PID: 5612)
    • Process drops legitimate windows executable

      • wmlaunch.exe (PID: 5612)
  • INFO

    • The sample compiled with english language support

      • 091208478 DTD 10.07.2025 09750913 640976289-85665.exe (PID: 2040)
      • wmlaunch.exe (PID: 5612)
    • Create files in a temporary directory

      • 091208478 DTD 10.07.2025 09750913 640976289-85665.exe (PID: 2040)
      • wmlaunch.exe (PID: 5612)
    • Creates files in the program directory

      • 091208478 DTD 10.07.2025 09750913 640976289-85665.exe (PID: 2040)
    • Reads the computer name

      • 091208478 DTD 10.07.2025 09750913 640976289-85665.exe (PID: 2040)
      • wmlaunch.exe (PID: 5612)
    • Checks supported languages

      • 091208478 DTD 10.07.2025 09750913 640976289-85665.exe (PID: 2040)
      • wmlaunch.exe (PID: 5612)
    • Creates files or folders in the user directory

      • wmlaunch.exe (PID: 5612)
    • Launching a file from a Registry key

      • wmlaunch.exe (PID: 5612)
      • 091208478 DTD 10.07.2025 09750913 640976289-85665.exe (PID: 2040)
    • Checks proxy server information

      • wmlaunch.exe (PID: 5612)
    • Process checks whether UAC notifications are on

      • wmlaunch.exe (PID: 5612)
    • Reads the machine GUID from the registry

      • wmlaunch.exe (PID: 5612)
    • Reads the software policy settings

      • wmlaunch.exe (PID: 5612)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:25 21:56:47+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26624
InitializedDataSize: 141824
UninitializedDataSize: 2048
EntryPoint: 0x3640
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.5.0.0
ProductVersionNumber: 1.5.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: polcpr vindicatively afsigende
FileDescription: uncogently ingulf
FileVersion: 1.5.0.0
LegalCopyright: lateward loftsbelysningens geneviugves
LegalTrademarks: bassett uncases reneglect
OriginalFileName: liggeplads valentino.exe
ProductVersion: 1.5.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
2040"C:\Users\admin\AppData\Local\Temp\091208478 DTD 10.07.2025 09750913 640976289-85665.exe" C:\Users\admin\AppData\Local\Temp\091208478 DTD 10.07.2025 09750913 640976289-85665.exe
explorer.exe
User:
admin
Company:
polcpr vindicatively afsigende
Integrity Level:
MEDIUM
Description:
uncogently ingulf
Exit code:
0
Version:
1.5.0.0
Modules
Images
c:\users\admin\appdata\local\temp\091208478 dtd 10.07.2025 09750913 640976289-85665.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5612"C:\Users\admin\AppData\Local\Temp\091208478 DTD 10.07.2025 09750913 640976289-85665.exe" C:\Program Files (x86)\Windows Media Player\wmlaunch.exe
091208478 DTD 10.07.2025 09750913 640976289-85665.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Launcher
Version:
12.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\mshtml.dll
c:\program files (x86)\windows media player\wmlaunch.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
7092C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe—svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
2 622
Read events
1 911
Write events
711
Delete events
0

Modification events

(PID) Process:(2040) 091208478 DTD 10.07.2025 09750913 640976289-85665.exeKey:HKEY_CURRENT_USER\washoan\Uninstall\blodfattigste
Operation:writeName:parasystole
Value:
0
(PID) Process:(2040) 091208478 DTD 10.07.2025 09750913 640976289-85665.exeKey:HKEY_CURRENT_USER\SOFTWARE\Locales Approx
Operation:writeName:C Langs
Value:
u
(PID) Process:(2040) 091208478 DTD 10.07.2025 09750913 640976289-85665.exeKey:HKEY_CURRENT_USER\bowline\elice\lseplaners
Operation:writeName:Soddened
Value:
43C0E8
(PID) Process:(2040) 091208478 DTD 10.07.2025 09750913 640976289-85665.exeKey:HKEY_CURRENT_USER\SOFTWARE\Locales Approx
Operation:writeName:C Langs
Value:
us
(PID) Process:(2040) 091208478 DTD 10.07.2025 09750913 640976289-85665.exeKey:HKEY_CURRENT_USER\SOFTWARE\Locales Approx
Operation:writeName:C Langs
Value:
use
(PID) Process:(2040) 091208478 DTD 10.07.2025 09750913 640976289-85665.exeKey:HKEY_CURRENT_USER\SOFTWARE\Locales Approx
Operation:writeName:C Langs
Value:
user
(PID) Process:(2040) 091208478 DTD 10.07.2025 09750913 640976289-85665.exeKey:HKEY_CURRENT_USER\SOFTWARE\Locales Approx
Operation:writeName:C Langs
Value:
user3
(PID) Process:(2040) 091208478 DTD 10.07.2025 09750913 640976289-85665.exeKey:HKEY_CURRENT_USER\SOFTWARE\Locales Approx
Operation:writeName:C Langs
Value:
user32
(PID) Process:(2040) 091208478 DTD 10.07.2025 09750913 640976289-85665.exeKey:HKEY_CURRENT_USER\SOFTWARE\Locales Approx
Operation:writeName:C Langs
Value:
user32:
(PID) Process:(2040) 091208478 DTD 10.07.2025 09750913 640976289-85665.exeKey:HKEY_CURRENT_USER\SOFTWARE\Locales Approx
Operation:writeName:C Langs
Value:
user32::
Executable files
2
Suspicious files
8
Text files
6
Unknown types
6

Dropped files

PID
Process
Filename
Type
2040091208478 DTD 10.07.2025 09750913 640976289-85665.exeC:\Users\admin\ansaettelsen\aller.tri —
MD5:—
SHA256:—
2040091208478 DTD 10.07.2025 09750913 640976289-85665.exeC:\Users\admin\ansaettelsen\Guayaberas\synophthalmia.gim —
MD5:—
SHA256:—
2040091208478 DTD 10.07.2025 09750913 640976289-85665.exeC:\Users\admin\AppData\Local\Temp\nso4B81.tmp —
MD5:—
SHA256:—
2040091208478 DTD 10.07.2025 09750913 640976289-85665.exeC:\Users\admin\ansaettelsen\Eighteenths.Sepbinary
MD5:EB9C0E6839592622D94E3AF18D90AE69
SHA256:A67EA135AF005E7CA44CF51BE715772632B6516ABF1003CCA897147635F6A15E
2040091208478 DTD 10.07.2025 09750913 640976289-85665.exeC:\ProgramData\Daaselatterens.lnklnk
MD5:D9FBDEE240A0119B2D93F68B8A6873D8
SHA256:D49518F8623E4C7FABAEB820F4DB6F625AF2E59652890A89543EBC0C6B6578BD
2040091208478 DTD 10.07.2025 09750913 640976289-85665.exeC:\Users\admin\ansaettelsen\Guayaberas\textural.txtini
MD5:F11DCD13A0A106D3207D46A1FDD465CA
SHA256:DA6C846226F9BFA68A14AF5DDC98E0A210750ED741A9161FEB3088DE594F0CBB
5612wmlaunch.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B46811C17859FFB409CF0E904A4AA8F8binary
MD5:D9FEBCE4AA2D6477460A87B2429C695B
SHA256:D95D9FE070EC3FBC0A4FE42E8AECD26E6406B5EA29F502A22EE09BE00749FBEA
2040091208478 DTD 10.07.2025 09750913 640976289-85665.exeC:\Users\admin\ansaettelsen\Guayaberas\precommunicating.initext
MD5:F96B40ECF68F4FCABD6424B31073199E
SHA256:0D7C522E2CDFD1A20719A2348D4874EA1EBB5F5316B1C36C990B5E043F81AF0B
2040091208478 DTD 10.07.2025 09750913 640976289-85665.exeC:\Users\admin\AppData\Local\Temp\Settings.initext
MD5:A6216EF9FBE57B11DEEB1B1FD840C392
SHA256:EDF6C9DA71DAF3B3DA2E89A1BC6B9F4B812F18FC133CF4706A3AE983E4040946
5612wmlaunch.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8B2B9A00839EED1DFDCCC3BFC2F5DF12der
MD5:CA8A9BDCA7AD59F5C8B7E1AA63160039
SHA256:81B7FA53B692B4D26E2E8943F2DDA2F9563CFCB0E11F48679EB2BE4F8C375B90
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
29
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.53.40.178:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
5328
SearchApp.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
DE
binary
314 b
whitelisted
6304
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
QA
binary
420 b
whitelisted
2072
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
5612
wmlaunch.exe
GET
200
172.217.18.99:80
http://c.pki.goog/r/r4.crl
US
binary
530 b
whitelisted
5612
wmlaunch.exe
GET
200
172.217.16.195:80
http://o.pki.goog/we2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTuMJxAT2trYla0jia%2F5EUSmLrk3QQUdb7Ed66J9kQ3fc%2BxaB8dGuvcNFkCEEjyOcDij0ECCQHn9DSrJo0%3D
US
binary
278 b
whitelisted
6304
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
QA
binary
408 b
whitelisted
5612
wmlaunch.exe
GET
200
172.217.16.195:80
http://o.pki.goog/we2/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTuMJxAT2trYla0jia%2F5EUSmLrk3QQUdb7Ed66J9kQ3fc%2BxaB8dGuvcNFkCECdz283NVEpjCi5UeCEUBvs%3D
US
binary
279 b
whitelisted
5612
wmlaunch.exe
GET
200
172.217.18.99:80
http://c.pki.goog/r/gsr1.crl
US
binary
1.70 Kb
whitelisted
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
814 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1268
svchost.exe
40.127.240.158:443
—
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:137
—
—
—
whitelisted
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4680
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
—
—
—
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
23.53.40.178:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2072
svchost.exe
20.190.159.23:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2072
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
  • 4.231.128.59
whitelisted
google.com
  • 142.250.186.78
whitelisted
crl.microsoft.com
  • 23.53.40.178
  • 23.53.40.176
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 2.23.246.101
whitelisted
login.live.com
  • 20.190.159.23
  • 20.190.159.64
  • 20.190.159.68
  • 40.126.31.0
  • 40.126.31.1
  • 20.190.159.2
  • 20.190.159.73
  • 40.126.31.67
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
www.bing.com
  • 92.123.104.67
  • 92.123.104.19
  • 92.123.104.18
  • 92.123.104.66
  • 92.123.104.13
  • 92.123.104.63
  • 92.123.104.8
  • 92.123.104.7
  • 92.123.104.5
whitelisted
nexusrules.officeapps.live.com
  • 52.111.229.48
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted

Threats

No threats detected
No debug info