| File name: | 47feab3f268bfe7b3f56414f8126f4bee0735b327fb054bcac6c84f5414a00f9.bin |
| Full analysis: | https://app.any.run/tasks/e094c256-c400-4a54-bcea-412697b13133 |
| Verdict: | Malicious activity |
| Analysis date: | July 06, 2025, 16:05:36 |
| OS: | Windows 11 Professional (build: 22000, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | FE05CD860CFA87944279EE7BB549C97F |
| SHA1: | F48039D0B876F5F38E80AF33AA0B2CB40236B554 |
| SHA256: | 47FEAB3F268BFE7B3F56414F8126F4BEE0735B327FB054BCAC6C84F5414A00F9 |
| SSDEEP: | 98304:ZH0ZWWjztLaZ90vZysVahHy0MJR3ttrlPyF:bX |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:09:07 12:39:10+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.37 |
| CodeSize: | 2595840 |
| InitializedDataSize: | 1645568 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1ef409 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.5.6.2 |
| ProductVersionNumber: | 2.5.6.2 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Debug |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | Japanese |
| CharacterSet: | Unicode |
| CompanyName: | ざぁこなしまいとすやすやえっちっち |
| FileDescription: | ざぁこなしまいとすやすやえっちっち Installer |
| FileVersion: | 2.5.6.2 |
| InternalName: | SuyasuyaH |
| LegalCopyright: | Copyright (C) 2025 ざぁこなしまいとすやすやえっちっち |
| OriginalFileName: | SuyasuyaH.exe |
| ProductName: | ざぁこなしまいとすやすやえっちっち |
| ProductVersion: | 2.5.6.2 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1572 | "C:\Windows\system32\DllHost.exe" /Processid:{B41DB860-64E4-11D2-9906-E49FADC173CA} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: COM Surrogate Version: 10.0.22000.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2616 | "C:\Users\admin\Desktop\47feab3f268bfe7b3f56414f8126f4bee0735b327fb054bcac6c84f5414a00f9.bin.exe" | C:\Users\admin\Desktop\47feab3f268bfe7b3f56414f8126f4bee0735b327fb054bcac6c84f5414a00f9.bin.exe | explorer.exe | ||||||||||||
User: admin Company: ざぁこなしまいとすやすやえっちっち Integrity Level: HIGH Description: ざぁこなしまいとすやすやえっちっち Installer Exit code: 1 Version: 2.5.6.2 Modules
| |||||||||||||||
| 4800 | "C:\Users\admin\Desktop\47feab3f268bfe7b3f56414f8126f4bee0735b327fb054bcac6c84f5414a00f9.bin.exe" | C:\Users\admin\Desktop\47feab3f268bfe7b3f56414f8126f4bee0735b327fb054bcac6c84f5414a00f9.bin.exe | explorer.exe | ||||||||||||
User: admin Company: ざぁこなしまいとすやすやえっちっち Integrity Level: HIGH Description: ざぁこなしまいとすやすやえっちっち Installer Exit code: 1 Version: 2.5.6.2 Modules
| |||||||||||||||
| 4812 | "C:\Users\admin\Desktop\47feab3f268bfe7b3f56414f8126f4bee0735b327fb054bcac6c84f5414a00f9.bin.exe" | C:\Users\admin\Desktop\47feab3f268bfe7b3f56414f8126f4bee0735b327fb054bcac6c84f5414a00f9.bin.exe | — | explorer.exe | |||||||||||
User: admin Company: ざぁこなしまいとすやすやえっちっち Integrity Level: MEDIUM Description: ざぁこなしまいとすやすやえっちっち Installer Exit code: 3221226540 Version: 2.5.6.2 Modules
| |||||||||||||||
| (PID) Process: | (2616) 47feab3f268bfe7b3f56414f8126f4bee0735b327fb054bcac6c84f5414a00f9.bin.exe | Key: | HKEY_CURRENT_USER\Software\AiTemp |
| Operation: | delete value | Name: | C__Users_admin_Desktop_47feab3f268bfe7b3f56414f8126f4bee0735b327fb054bcac6c84f5414a00f9.bin.exe |
Value: | |||
| (PID) Process: | (2616) 47feab3f268bfe7b3f56414f8126f4bee0735b327fb054bcac6c84f5414a00f9.bin.exe | Key: | HKEY_CURRENT_USER\Software\AiTemp |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (2616) 47feab3f268bfe7b3f56414f8126f4bee0735b327fb054bcac6c84f5414a00f9.bin.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce |
| Operation: | delete value | Name: | C__Users_admin_Desktop_47feab3f268bfe7b3f56414f8126f4bee0735b327fb054bcac6c84f5414a00f9.bin.exe |
Value: | |||
| (PID) Process: | (4800) 47feab3f268bfe7b3f56414f8126f4bee0735b327fb054bcac6c84f5414a00f9.bin.exe | Key: | HKEY_CURRENT_USER\Software\AiTemp |
| Operation: | delete value | Name: | C__Users_admin_Desktop_47feab3f268bfe7b3f56414f8126f4bee0735b327fb054bcac6c84f5414a00f9.bin.exe |
Value: | |||
| (PID) Process: | (4800) 47feab3f268bfe7b3f56414f8126f4bee0735b327fb054bcac6c84f5414a00f9.bin.exe | Key: | HKEY_CURRENT_USER\Software\AiTemp |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (4800) 47feab3f268bfe7b3f56414f8126f4bee0735b327fb054bcac6c84f5414a00f9.bin.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce |
| Operation: | delete value | Name: | C__Users_admin_Desktop_47feab3f268bfe7b3f56414f8126f4bee0735b327fb054bcac6c84f5414a00f9.bin.exe |
Value: | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4944 | rundll32.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2660 | OfficeC2RClient.exe | 52.109.89.18:443 | officeclient.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1524 | svchost.exe | 184.25.50.104:80 | www.msftconnecttest.com | Akamai International B.V. | DE | whitelisted |
6684 | firefox.exe | 34.120.208.123:443 | incoming.telemetry.mozilla.org | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
5164 | pingsender.exe | 34.120.208.123:443 | incoming.telemetry.mozilla.org | GOOGLE-CLOUD-PLATFORM | US | whitelisted |
2860 | svchost.exe | 52.168.117.170:443 | v20.events.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
5268 | svchost.exe | 23.197.142.186:443 | fs.microsoft.com | Akamai International B.V. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
officeclient.microsoft.com |
| whitelisted |
www.msftconnecttest.com |
| whitelisted |
incoming.telemetry.mozilla.org |
| whitelisted |
telemetry-incoming.r53-2.services.mozilla.com |
| whitelisted |
v20.events.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
fs.microsoft.com |
| whitelisted |