File name:

New Quotation 4634-09172025.exe

Full analysis: https://app.any.run/tasks/a433b9c4-bdbd-4e29-a11e-ad62eb66057f
Verdict: Malicious activity
Analysis date: March 25, 2025, 05:17:39
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

2F176248DBA9998FE0C1477EEF2F8EC4

SHA1:

5EAE04FE9A2170EAC0D57EA71287FF43B71539CD

SHA256:

48402227FDB3C99BEB56DD976C827F81801A10DFE4153178D0407D05CFCD7510

SSDEEP:

49152:PsoqHHeW46Y+BuYrb6CsWEkPwti9112lqxSPr+uJpFTY4mC5P1xrKziDxE735DJB:PsNenJgHv6CsWEk4k9nxM+uPFPmCrxrQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Create files in the Startup directory

      • New Quotation 4634-09172025.exe (PID: 2656)
  • SUSPICIOUS

    • Executes application which crashes

      • InstallUtil.exe (PID: 7224)
    • Executable content was dropped or overwritten

      • New Quotation 4634-09172025.exe (PID: 2656)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 8132)
    • The process checks if it is being run in the virtual environment

      • InstallUtil.exe (PID: 5936)
  • INFO

    • Checks supported languages

      • New Quotation 4634-09172025.exe (PID: 2656)
      • ChannelData.exe (PID: 2908)
      • InstallUtil.exe (PID: 5936)
    • Reads the computer name

      • New Quotation 4634-09172025.exe (PID: 2656)
      • ChannelData.exe (PID: 2908)
      • InstallUtil.exe (PID: 5936)
    • Creates files or folders in the user directory

      • New Quotation 4634-09172025.exe (PID: 2656)
      • WerFault.exe (PID: 7356)
    • Reads the machine GUID from the registry

      • New Quotation 4634-09172025.exe (PID: 2656)
      • ChannelData.exe (PID: 2908)
      • InstallUtil.exe (PID: 5936)
    • Manual execution by a user

      • InstallUtil.exe (PID: 7224)
      • wscript.exe (PID: 8132)
      • InstallUtil.exe (PID: 5936)
    • Create files in a temporary directory

      • WerFault.exe (PID: 7356)
    • Autorun file from Startup directory

      • New Quotation 4634-09172025.exe (PID: 2656)
    • Reads the software policy settings

      • slui.exe (PID: 7516)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (82.9)
.dll | Win32 Dynamic Link Library (generic) (7.4)
.exe | Win32 Executable (generic) (5.1)
.exe | Generic Win/DOS Executable (2.2)
.exe | DOS Executable Generic (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:03:23 23:32:42+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 1423360
InitializedDataSize: 2560
UninitializedDataSize: -
EntryPoint: 0x15d77e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: New Quotation 4634-09172025
FileVersion: 1.0.0.0
InternalName: New Quotation 4634-09172025.exe
LegalCopyright: Copyright © 2024
LegalTrademarks: -
OriginalFileName: New Quotation 4634-09172025.exe
ProductName: New Quotation 4634-09172025
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
148
Monitored processes
9
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start new quotation 4634-09172025.exe installutil.exe werfault.exe no specs sppextcomobj.exe no specs slui.exe wscript.exe no specs channeldata.exe no specs installutil.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2656"C:\Users\admin\AppData\Local\Temp\New Quotation 4634-09172025.exe" C:\Users\admin\AppData\Local\Temp\New Quotation 4634-09172025.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
New Quotation 4634-09172025
Exit code:
4294967295
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\new quotation 4634-09172025.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
2908"C:\Users\admin\AppData\Roaming\ChannelData.exe" C:\Users\admin\AppData\Roaming\ChannelData.exewscript.exe
User:
admin
Integrity Level:
MEDIUM
Description:
New Quotation 4634-09172025
Exit code:
4294967295
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\channeldata.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
5936"C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
.NET Framework installation utility
Exit code:
0
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\installutil.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
7224"C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
.NET Framework installation utility
Exit code:
3221225477
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\installutil.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7356C:\WINDOWS\SysWOW64\WerFault.exe -u -p 7224 -s 12C:\Windows\SysWOW64\WerFault.exeInstallUtil.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
7464C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7516"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7616C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
8132"C:\WINDOWS\System32\WScript.exe" "C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ChannelData.vbs"C:\Windows\System32\wscript.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
3 170
Read events
3 170
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
2
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
7356WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_bad_module_info_dcd3242e9fa4189184df4216daa4e4c7cdf1959_85207d7d_da3da521-9491-4962-ac35-894baab1f378\Report.wer
MD5:
SHA256:
2656New Quotation 4634-09172025.exeC:\Users\admin\AppData\Roaming\ChannelData.exeexecutable
MD5:2F176248DBA9998FE0C1477EEF2F8EC4
SHA256:48402227FDB3C99BEB56DD976C827F81801A10DFE4153178D0407D05CFCD7510
2656New Quotation 4634-09172025.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ChannelData.vbstext
MD5:9CDC8ACED1B683DBDF3555EB011A82FC
SHA256:BB2FCCC063C29EB7344E2E08E7A40078A6575C00C50302D49B2FDD0B07852543
7356WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERD3AF.tmp.WERInternalMetadata.xmlbinary
MD5:D3F4BB6848035E99CE1D3A966512AFFE
SHA256:4A1B92590D304F8FFE5C783A853087B5D92A0C22E40AB121BE9FE2A423E34E86
7356WerFault.exeC:\Users\admin\AppData\Local\Temp\WERC3DF.tmp.WERDataCollectionStatus.txtbinary
MD5:E35CD1638D53AA0B859B252213AEB161
SHA256:8535C4BC8469AAA165840D62673D32BD19698C4F9ED6D7D35C229AD935B1152A
7356WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERD3DF.tmp.xmlxml
MD5:505C0D466E16D88FACC32BD9BC5537E9
SHA256:568D4A26517CE0BD4638F21ED621E8FFC7894523DE82D290CF29CEA38BC5602D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
24
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.53.40.178:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
7400
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
unknown
720
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
unknown
720
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
2104
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
unknown
5496
MoUsoCoreWorker.exe
23.53.40.178:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
5496
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
3216
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
6544
svchost.exe
40.126.32.140:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
unknown
2152
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
unknown
google.com
  • 142.250.181.238
unknown
crl.microsoft.com
  • 23.53.40.178
  • 23.53.40.176
unknown
client.wns.windows.com
  • 40.113.103.199
unknown
login.live.com
  • 40.126.32.140
  • 40.126.32.136
  • 40.126.32.72
  • 20.190.160.17
  • 20.190.160.64
  • 20.190.160.20
  • 20.190.160.65
  • 40.126.32.76
unknown
ocsp.digicert.com
  • 184.30.131.245
unknown
arc.msn.com
  • 20.31.169.57
unknown
slscr.update.microsoft.com
  • 172.202.163.200
unknown
www.microsoft.com
  • 184.30.21.171
unknown
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
unknown

Threats

No threats detected
No debug info