File name: | 497c4f05f135c5cad23143e13a002126e675bc85e8707032219b1e3932b96b1a |
Full analysis: | https://app.any.run/tasks/70adfb5d-5618-4607-970d-88365ef38cf8 |
Verdict: | Malicious activity |
Analysis date: | December 13, 2024, 19:24:54 |
OS: | Windows 10 Professional (build: 19045, 64 bit) |
Indicators: | |
MIME: | application/vnd.microsoft.portable-executable |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
MD5: | 9A01494DE371C8C7B18A354E295693E3 |
SHA1: | 6262D5E1FA02D0E2BC06D4290D8790E1CE11C9A0 |
SHA256: | 497C4F05F135C5CAD23143E13A002126E675BC85E8707032219B1E3932B96B1A |
SSDEEP: | 6144:Q5j63Wfbf+D4RYqoOYDgd2Qpfr3moHrbEQsF/KK4Oqdh5rKSyw8CH1YYJ1GKrbZS:0qo2ofzZta6gpg5nT9+ |
.exe | | | Win64 Executable (generic) (64.6) |
---|---|---|
.dll | | | Win32 Dynamic Link Library (generic) (15.4) |
.exe | | | Win32 Executable (generic) (10.5) |
.exe | | | Generic Win/DOS Executable (4.6) |
.exe | | | DOS Executable Generic (4.6) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2024:01:10 02:06:42+00:00 |
ImageFileCharacteristics: | Executable, 32-bit |
PEType: | PE32 |
LinkerVersion: | 14.2 |
CodeSize: | 82944 |
InitializedDataSize: | 70656 |
UninitializedDataSize: | - |
EntryPoint: | 0x7552 |
OSVersion: | 5.1 |
ImageVersion: | - |
SubsystemVersion: | 5.1 |
Subsystem: | Windows GUI |
FileVersionNumber: | 1.3.36.371 |
ProductVersionNumber: | 1.3.36.371 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Windows NT 32-bit |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | Process default |
CharacterSet: | Unicode |
CompanyName: | Google LLC |
FileDescription: | Google Installer |
FileVersion: | 1.3.36.371 |
InternalName: | Google Update |
LegalCopyright: | Copyright 2018 Google LLC |
OriginalFileName: | GoogleUpdate.exe |
ProductName: | Google Update |
ProductVersion: | 1.3.36.371 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
6280 | "C:\Users\admin\Desktop\497c4f05f135c5cad23143e13a002126e675bc85e8707032219b1e3932b96b1a.exe" | C:\Users\admin\Desktop\497c4f05f135c5cad23143e13a002126e675bc85e8707032219b1e3932b96b1a.exe | explorer.exe | ||||||||||||
User: admin Company: Google LLC Integrity Level: MEDIUM Description: Google Installer Exit code: 2147942402 Version: 1.3.36.371 Modules
| |||||||||||||||
6340 | "C:\WINDOWS\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe" -ServerName:App.AppXtk181tbxbce2qsex02s8tw7hfxa9xb3t.mca | C:\Windows\SystemApps\ShellExperienceHost_cw5n1h2txyewy\ShellExperienceHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Shell Experience Host Version: 10.0.19041.3758 (WinBuild.160101.0800) Modules
|
(PID) Process: | (6340) ShellExperienceHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.shellexperiencehost_cw5n1h2txyewy\SOFTWARE\Microsoft\Speech_OneCore\Isolated\yYpHriFUdyS-r81lKl88jPGlZr-M05PzoCQ_A6O0gXA\HKEY_CURRENT_USER\SOFTWARE\Microsoft\Speech_OneCore\Voices |
Operation: | write | Name: | DefaultTokenId |
Value: HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Speech_OneCore\Voices\Tokens\MSTTS_V110_enUS_DavidM | |||
(PID) Process: | (6340) ShellExperienceHost.exe | Key: | \REGISTRY\A\{5883135a-91af-db17-043e-6f82a29d253c}\LocalState\ClockFlyoutCache |
Operation: | delete value | Name: | 20240722 |
Value: | |||
(PID) Process: | (6340) ShellExperienceHost.exe | Key: | \REGISTRY\A\{5883135a-91af-db17-043e-6f82a29d253c}\LocalState\ClockFlyoutCache |
Operation: | delete value | Name: | 20240708 |
Value: | |||
(PID) Process: | (6340) ShellExperienceHost.exe | Key: | \REGISTRY\A\{5883135a-91af-db17-043e-6f82a29d253c}\LocalState\ClockFlyoutCache |
Operation: | delete value | Name: | 20240729 |
Value: | |||
(PID) Process: | (6340) ShellExperienceHost.exe | Key: | \REGISTRY\A\{5883135a-91af-db17-043e-6f82a29d253c}\LocalState\ClockFlyoutCache |
Operation: | delete value | Name: | 20240702 |
Value: | |||
(PID) Process: | (6340) ShellExperienceHost.exe | Key: | \REGISTRY\A\{5883135a-91af-db17-043e-6f82a29d253c}\LocalState\ClockFlyoutCache |
Operation: | delete value | Name: | 20240801 |
Value: | |||
(PID) Process: | (6340) ShellExperienceHost.exe | Key: | \REGISTRY\A\{5883135a-91af-db17-043e-6f82a29d253c}\LocalState\ClockFlyoutCache |
Operation: | delete value | Name: | 20240731 |
Value: | |||
(PID) Process: | (6340) ShellExperienceHost.exe | Key: | \REGISTRY\A\{5883135a-91af-db17-043e-6f82a29d253c}\LocalState\ClockFlyoutCache |
Operation: | delete value | Name: | 20240727 |
Value: | |||
(PID) Process: | (6340) ShellExperienceHost.exe | Key: | \REGISTRY\A\{5883135a-91af-db17-043e-6f82a29d253c}\LocalState\ClockFlyoutCache |
Operation: | delete value | Name: | 20240719 |
Value: | |||
(PID) Process: | (6340) ShellExperienceHost.exe | Key: | \REGISTRY\A\{5883135a-91af-db17-043e-6f82a29d253c}\LocalState\ClockFlyoutCache |
Operation: | delete value | Name: | 20240712 |
Value: |
PID | Process | Filename | Type | |
---|---|---|---|---|
6280 | 497c4f05f135c5cad23143e13a002126e675bc85e8707032219b1e3932b96b1a.exe | C:\Users\admin\AppData\Local\Temp\conres.dll | executable | |
MD5:7574CF2C64F35161AB1292E2F532AABF | SHA256:DE055A89DE246E629A8694BDE18AF2B1605E4B9B493C7E4AEF669DD67ACF5085 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
488 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6076 | RUXIMICS.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
488 | svchost.exe | GET | 200 | 23.48.23.167:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 192.168.100.255:137 | — | — | — | whitelisted |
6076 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 104.126.37.171:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
488 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
488 | svchost.exe | 23.48.23.167:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
488 | svchost.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
6076 | RUXIMICS.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
Domain | IP | Reputation |
---|---|---|
www.bing.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |