File name:

OOSU10.exe

Full analysis: https://app.any.run/tasks/563e30c7-5d21-4523-84b8-4291edbad8ca
Verdict: Malicious activity
Analysis date: August 31, 2024, 06:01:41
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

01B0162F0C62DB1FDF06998C71EAC79C

SHA1:

A9747673D1D22D411D5878CE83837D99B4CF181D

SHA256:

48B2FA453CA6B32AB5B29E75A3952F4734F177E6FEFAF33E636942E4E5048171

SSDEEP:

49152:BRnE6QUEyLQfpUPJjJwJNJi1YQyLydIoaXMsb8klcumNNXbl5zkQUIe+iROkG8GA:fjkXMsb8klsz3Ze+icx1ZrDSO+Tnrdn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • OOSU10.exe (PID: 6792)
    • Executes as Windows Service

      • VSSVC.exe (PID: 6984)
    • Searches for installed software

      • dllhost.exe (PID: 6996)
  • INFO

    • Checks supported languages

      • OOSU10.exe (PID: 6792)
    • Create files in a temporary directory

      • OOSU10.exe (PID: 6792)
    • Reads Microsoft Office registry keys

      • OOSU10.exe (PID: 6792)
    • Reads the machine GUID from the registry

      • OOSU10.exe (PID: 6792)
    • Reads the computer name

      • OOSU10.exe (PID: 6792)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (49.4)
.scr | Windows screen saver (23.4)
.dll | Win32 Dynamic Link Library (generic) (11.7)
.exe | Win32 Executable (generic) (8)
.exe | Generic Win/DOS Executable (3.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2058:03:14 05:28:23+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 1932288
InitializedDataSize: 36864
UninitializedDataSize: -
EntryPoint: 0x1d9aae
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.9.1438.411
ProductVersionNumber: 1.9.1438.411
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: O&O ShutUp10++
CompanyName: O&O Software GmbH
FileDescription: O&O ShutUp10++
FileVersion: 1.9.1438.411
InternalName: OOSU10.exe
LegalCopyright: © 2015-2024 O&O Software GmbH, Berlin.
LegalTrademarks: -
OriginalFileName: OOSU10.exe
ProductName: O&O ShutUp10++
ProductVersion: 1.9.1438.411
AssemblyVersion: 1.9.1438.411
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
138
Monitored processes
6
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start oosu10.exe SPPSurrogate no specs vssvc.exe no specs sppextcomobj.exe no specs slui.exe no specs oosu10.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
320"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6328C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6768"C:\Users\admin\AppData\Local\Temp\OOSU10.exe" C:\Users\admin\AppData\Local\Temp\OOSU10.exeexplorer.exe
User:
admin
Company:
O&O Software GmbH
Integrity Level:
MEDIUM
Description:
O&O ShutUp10++
Exit code:
3221226540
Version:
1.9.1438.411
Modules
Images
c:\users\admin\appdata\local\temp\oosu10.exe
c:\windows\system32\ntdll.dll
6792"C:\Users\admin\AppData\Local\Temp\OOSU10.exe" C:\Users\admin\AppData\Local\Temp\OOSU10.exe
explorer.exe
User:
admin
Company:
O&O Software GmbH
Integrity Level:
HIGH
Description:
O&O ShutUp10++
Version:
1.9.1438.411
Modules
Images
c:\users\admin\appdata\local\temp\oosu10.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6984C:\WINDOWS\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6996C:\WINDOWS\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
Total events
3 099
Read events
2 916
Write events
173
Delete events
10

Modification events

(PID) Process:(6792) OOSU10.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore
Operation:writeName:SystemRestorePointCreationFrequency
Value:
0
(PID) Process:(6996) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Enter)
Value:
4800000000000000D71FB94B6BFBDA01541B000060090000D20700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6996) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGetSnapshots (Leave)
Value:
4800000000000000BE3CFE4B6BFBDA01541B000060090000D20700000100000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6996) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Enter)
Value:
4800000000000000BE3CFE4B6BFBDA01541B000060090000D10700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6996) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppEnumGroups (Leave)
Value:
4800000000000000D49F004C6BFBDA01541B000060090000D10700000100000000000000010000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6996) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4800000000000000F066054C6BFBDA01541B000060090000D00700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6996) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
11
(PID) Process:(6996) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\SPP
Operation:writeName:SppGatherWriterMetadata (Enter)
Value:
48000000000000000F92754C6BFBDA01541B000060090000D30700000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(6996) dllhost.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\VssapiPublisher
Operation:writeName:IDENTIFY (Enter)
Value:
480000000000000061CF774C6BFBDA01541B0000DC0B0000E80300000100000000000000000000009F4EAFDA86927D49A8C0129EA6EB5DD400000000000000000000000000000000
(PID) Process:(6984) VSSVC.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\VSS\Diag\ASR Writer
Operation:writeName:IDENTIFY (Enter)
Value:
4800000000000000C5C0834C6BFBDA01481B0000F0190000E80300000100000001000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
0
Suspicious files
2
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
6996dllhost.exeC:\System Volume Information\SPP\metadata-2
MD5:
SHA256:
6996dllhost.exeC:\System Volume Information\SPP\snapshot-2binary
MD5:CBA08DC6303F00EF65CCEA13FDBC8BF9
SHA256:05CBAB1FEC6C695A5D71E7EB0D0E0105DE5AC045262B0DDEBE3420A0754011F2
6792OOSU10.exeC:\Users\admin\AppData\Local\Temp\OOSU10.cfgxml
MD5:194845751A122FC129C8E2179325CC89
SHA256:0415A2A103D5C519D34A0921292F747176CF84F31F4F6DC803DFC8F01897C219
6996dllhost.exeC:\System Volume Information\SPP\OnlineMetadataCache\{daaf4e9f-9286-497d-a8c0-129ea6eb5dd4}_OnDiskSnapshotPropbinary
MD5:CBA08DC6303F00EF65CCEA13FDBC8BF9
SHA256:05CBAB1FEC6C695A5D71E7EB0D0E0105DE5AC045262B0DDEBE3420A0754011F2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
36
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6216
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1828
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6216
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
192.168.100.255:137
whitelisted
7072
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6252
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7072
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1828
svchost.exe
20.190.159.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1828
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3260
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
  • 40.127.240.158
whitelisted
google.com
  • 172.217.18.110
whitelisted
login.live.com
  • 20.190.159.71
  • 20.190.159.73
  • 40.126.31.67
  • 20.190.159.23
  • 20.190.159.4
  • 40.126.31.73
  • 20.190.159.75
  • 20.190.159.68
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
slscr.update.microsoft.com
  • 52.165.165.26
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

No threats detected
No debug info