| File name: | Utils.dll |
| Full analysis: | https://app.any.run/tasks/24f34ceb-42f8-4514-b0c8-dbdd9a766c7e |
| Verdict: | Malicious activity |
| Analysis date: | December 09, 2024, 14:06:47 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32+ executable (DLL) (GUI) x86-64, for MS Windows, 8 sections |
| MD5: | 130517610744404955344A6D3D82DB27 |
| SHA1: | 2F374A6651BBA443C478A49A622A10E1EC6579A1 |
| SHA256: | 47A9DE8F0678FAAB11C1150588277C18FE8A43ADA3ECBBA315DD002EC30C9082 |
| SSDEEP: | 49152:cc5TGR2H0NlApphaOYz5nSm3aDjpNkSli6A/hzt5PAUW27uE4g/dn/V1THs22Amg:cc5yA1mXSli9h5P5HL2Y |
| .exe | | | InstallShield setup (57.6) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (36.9) |
| .exe | | | Generic Win/DOS Executable (2.6) |
| .exe | | | DOS Executable Generic (2.6) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2024:12:09 03:10:23+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, DLL |
| PEType: | PE32+ |
| LinkerVersion: | 14.16 |
| CodeSize: | 1137152 |
| InitializedDataSize: | 762368 |
| UninitializedDataSize: | 320000 |
| EntryPoint: | 0x6b7bc |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| CompanyName: | Utils |
| FileDescription: | Utils |
| FileVersion: | 1.0.0.0 |
| InternalName: | Utils.dll |
| LegalCopyright: | |
| OriginalFileName: | Utils.dll |
| ProductName: | Utils |
| ProductVersion: | 1.0.0 |
| AssemblyVersion: | 1.0.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 760 | C:\WINDOWS\system32\lsass.exe | C:\Windows\System32\lsass.exe | — | wininit.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Local Security Authority Process Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1176 | C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s wlidsvc | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1476 | "C:\Program Files\Mozilla Firefox\firefox.exe" --backgroundtask defaultagent do-task 308046B0AF4A39CB | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Firefox Exit code: 3 Version: 123.0 Modules
| |||||||||||||||
| 2360 | C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s WpnService | C:\Windows\System32\svchost.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3544 | C:\WINDOWS\system32\wbem\wmiprvse.exe -secured -Embedding | C:\Windows\System32\wbem\WmiPrvSE.exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: WMI Provider Host Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3976 | C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s UsoSvc | C:\Windows\System32\svchost.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 5780 | C:\WINDOWS\system32\svchost.exe -k wusvcs -p -s WaaSMedicSvc | C:\Windows\System32\svchost.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6092 | C:\WINDOWS\system32\sppsvc.exe | C:\Windows\System32\sppsvc.exe | — | services.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft Software Protection Platform Service Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6184 | C:\WINDOWS\System32\sihclient.exe /cv LfLsW1nqCEikRPA4v04pHA.0.2 | C:\Windows\System32\SIHClient.exe | upfc.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: SIH Client Exit code: 2379777 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6332 | %systemroot%\system32\MusNotificationUx.exe ClearActiveNotifications | C:\Windows\System32\MusNotificationUx.exe | — | MusNotification.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: MusNotificationUx.exe Exit code: 0 Version: 10.0.19041.3693 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (1176) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IdentityCRL\ClockData |
| Operation: | write | Name: | ClockTimeSeconds |
Value: 81F9566700000000 | |||
| (PID) Process: | (1176) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\IdentityCRL\ClockData |
| Operation: | write | Name: | TickCount |
Value: 7D66130000000000 | |||
| (PID) Process: | (1176) svchost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Microsoft\IdentityCRL\DeviceIdentities\production\S-1-5-18\02ysqcmrhhybziza |
| Operation: | write | Name: | AppIdList |
Value: | |||
| (PID) Process: | (6468) backgroundTaskHost.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\SearchSettings |
| Operation: | write | Name: | SafeSearchMode |
Value: 1 | |||
| (PID) Process: | (6468) backgroundTaskHost.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\Flighting |
| Operation: | write | Name: | CachedFeatureString |
Value: | |||
| (PID) Process: | (6468) backgroundTaskHost.exe | Key: | \REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState |
| Operation: | write | Name: | BINGIDENTITY_PROP_USEREMAIL |
Value: 00004BD1769B434ADB01 | |||
| (PID) Process: | (6468) backgroundTaskHost.exe | Key: | \REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState |
| Operation: | write | Name: | BINGIDENTITY_PROP_ACCOUNTTYPETEXT |
Value: 0000FC34799B434ADB01 | |||
| (PID) Process: | (6468) backgroundTaskHost.exe | Key: | \REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState |
| Operation: | write | Name: | BINGIDENTITY_PROP_ACCOUNTTYPE |
Value: 0000FC34799B434ADB01 | |||
| (PID) Process: | (6468) backgroundTaskHost.exe | Key: | \REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState |
| Operation: | write | Name: | BINGIDENTITY_PROP_ACCOUNTTYPE |
Value: 4E006F006E0065000000FC34799B434ADB01 | |||
| (PID) Process: | (1176) svchost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Microsoft\IdentityCRL\DeviceIdentities\production\S-1-5-18\02ysqcmrhhybziza |
| Operation: | write | Name: | Reason |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6388 | rundll32.exe | C:\Users\admin\SystemRootDoc\69fe178f-26e7-43a9-aa7d-2b616b672dde_eventlogservice.dll | executable | |
MD5:AA22ACA4AF887A2C3859F19B037D044C | SHA256:F1A674EF9154775BF524C41D3364C867FEBA50162791DCA851597147D92D172D | |||
| 6388 | rundll32.exe | C:\Users\admin\SystemRootDoc\aadauthhelper.dll | executable | |
MD5:E9715628B4E316BA1FF5B722E583A833 | SHA256:AA7BCB2C7C659B6F743B588BF215DB675A63B4F3D920BF2D3B5117FF4A53050E | |||
| 6388 | rundll32.exe | C:\Users\admin\SystemRootDoc\AboveLockAppHost.dll | executable | |
MD5:C01B2511EED7D69AF427235AD9563F0A | SHA256:372B982C688601A34B4FA1CA1083750EB9249231AC334BA4678340BB4B8B8655 | |||
| 6388 | rundll32.exe | C:\Users\admin\SystemRootDoc\aadjcsp.dll | executable | |
MD5:7BA21AA6AF1926FD531B397D49025272 | SHA256:129672E7AD4BB342EEFAF38E7BBCE8852B0179DC2D1B13119CFBB4C622974B7E | |||
| 6388 | rundll32.exe | C:\Users\admin\SystemRootDoc\AarSvc.dll | executable | |
MD5:B95F718CAE97DF4993D7552325A21B7A | SHA256:B81B6A02F09E43B28E0C92576D008CC6634FC82487A20F9F46B6E65D92F37AA6 | |||
| 6388 | rundll32.exe | C:\Users\admin\SystemRootDoc\aadcloudap.dll | executable | |
MD5:56B567EF3ECA8BAA5D9DDFE5B95198F6 | SHA256:F38FE32DC690A432A0796F057D99AAF690E1F5BB87D50895C7F4E82F05BA89C4 | |||
| 6388 | rundll32.exe | C:\Users\admin\SystemRootDoc\aadWamExtension.dll | executable | |
MD5:8640FE9C8E53B3F61BC95E90A8A94DB9 | SHA256:CBACF0036CA378CE98702AF87AF0F5D56A1319BF00CB0706397B06FB70E3C721 | |||
| 6388 | rundll32.exe | C:\Users\admin\SystemRootDoc\aadtb.dll | executable | |
MD5:20E0C67E71ED8D71A6F111A86F9A4686 | SHA256:1201A0F9D5FDC7A523F533F19F7D19AE4EF602D631120E3B7BB8EFF9C8910B8C | |||
| 6388 | rundll32.exe | C:\Users\admin\SystemRootDoc\AboutSettingsHandlers.dll | executable | |
MD5:2BBCBB5D3A4506155CA068A1233F2E2F | SHA256:89DCF7A25290AA62ADEE71D3166034E19182866A24A7C3581EF1712A0DE8C1A8 | |||
| 6388 | rundll32.exe | C:\Users\admin\SystemRootDoc\accountaccessor.dll | executable | |
MD5:65E03E2FD6E5E613089CDF403D88430B | SHA256:E29CBEF04D96976529154B7D5000A722B0F9F4AE3D756F84E7BFE587863F8637 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6184 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
6476 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 184.24.77.22:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
2164 | svchost.exe | GET | 200 | 184.24.77.22:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6184 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
2164 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5064 | SearchApp.exe | 104.126.37.178:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 184.24.77.22:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
2164 | svchost.exe | 184.24.77.22:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
4712 | MoUsoCoreWorker.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
2164 | svchost.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
— | — | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 23.213.166.81:443 | go.microsoft.com | AKAMAI-AS | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |