File name:

windowsdesktop-runtime-8.0.11-win-x64.exe

Full analysis: https://app.any.run/tasks/2882613e-98ff-4737-989d-8c6ba4746f2f
Verdict: Malicious activity
Analysis date: December 10, 2024, 15:07:30
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

FBA0B1010E82EE3896E104749F505F54

SHA1:

E7E43E8DA6AF9CD6A6B740B8F70CAEB5FBFDA730

SHA256:

4AAE588970B5DE7E67C0C46B19D7E671E8186D5FD7082C1F602F57F1CED0E516

SSDEEP:

24576:d+F8g+nZTnAHFo23SjnB/q+MNk7JO/gszhVBcIo13:d+F8g+nZTnAHFo2i7B/qrNuJO/gslVBk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6744)
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6444)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6468)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6744)
    • Executable content was dropped or overwritten

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6444)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6468)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6744)
    • Starts itself from another location

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6444)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6468)
    • Process drops legitimate windows executable

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6444)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6468)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6744)
    • Searches for installed software

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6468)
    • Creates a software uninstall entry

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6744)
  • INFO

    • Checks supported languages

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6444)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6468)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6744)
    • The sample compiled with english language support

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6444)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6468)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6744)
    • Reads the computer name

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6468)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6744)
    • Create files in a temporary directory

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6468)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:09:23 22:06:56+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.16
CodeSize: 303104
InitializedDataSize: 162816
UninitializedDataSize: -
EntryPoint: 0x3054b
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 8.0.11.34221
ProductVersionNumber: 8.0.11.34221
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Microsoft Corporation
FileDescription: Microsoft Windows Desktop Runtime - 8.0.11 (x64)
FileVersion: 8.0.11.34221
InternalName: setup
LegalCopyright: Copyright (c) Microsoft Corporation. All rights reserved.
OriginalFileName: windowsdesktop-runtime-8.0.11-win-x64.exe
ProductName: Microsoft Windows Desktop Runtime - 8.0.11 (x64)
ProductVersion: 8.0.11.34221
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
4
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start windowsdesktop-runtime-8.0.11-win-x64.exe windowsdesktop-runtime-8.0.11-win-x64.exe windowsdesktop-runtime-8.0.11-win-x64.exe rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
5244C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
6444"C:\Users\admin\AppData\Local\Temp\windowsdesktop-runtime-8.0.11-win-x64.exe" C:\Users\admin\AppData\Local\Temp\windowsdesktop-runtime-8.0.11-win-x64.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Desktop Runtime - 8.0.11 (x64)
Exit code:
1
Version:
8.0.11.34221
Modules
Images
c:\users\admin\appdata\local\temp\windowsdesktop-runtime-8.0.11-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6468"C:\Users\admin\AppData\Local\Temp\{2F3A91F6-5EC7-4B77-A271-474F39462326}\.cr\windowsdesktop-runtime-8.0.11-win-x64.exe" -burn.clean.room="C:\Users\admin\AppData\Local\Temp\windowsdesktop-runtime-8.0.11-win-x64.exe" -burn.filehandle.attached=596 -burn.filehandle.self=604 C:\Users\admin\AppData\Local\Temp\{2F3A91F6-5EC7-4B77-A271-474F39462326}\.cr\windowsdesktop-runtime-8.0.11-win-x64.exe
windowsdesktop-runtime-8.0.11-win-x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Desktop Runtime - 8.0.11 (x64)
Exit code:
1
Version:
8.0.11.34221
Modules
Images
c:\users\admin\appdata\local\temp\{2f3a91f6-5ec7-4b77-a271-474f39462326}\.cr\windowsdesktop-runtime-8.0.11-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6744"C:\Users\admin\AppData\Local\Temp\{E652D2F1-8DA7-40E9-8878-F36CDEDAB133}\.be\windowsdesktop-runtime-8.0.11-win-x64.exe" -q -burn.elevated BurnPipe.{36C8F6A9-BD11-4A52-88D2-A837739E493F} {E1E7AEFD-7565-47F1-97DF-F40C62C096CF} 6468C:\Users\admin\AppData\Local\Temp\{E652D2F1-8DA7-40E9-8878-F36CDEDAB133}\.be\windowsdesktop-runtime-8.0.11-win-x64.exe
windowsdesktop-runtime-8.0.11-win-x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Windows Desktop Runtime - 8.0.11 (x64)
Exit code:
1
Version:
8.0.11.34221
Modules
Images
c:\users\admin\appdata\local\temp\{e652d2f1-8da7-40e9-8878-f36cdedab133}\.be\windowsdesktop-runtime-8.0.11-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
521
Read events
488
Write events
26
Delete events
7

Modification events

(PID) Process:(6744) windowsdesktop-runtime-8.0.11-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{bd40e761-3e88-4202-9b53-26c6bed3d467}
Operation:writeName:BundleCachePath
Value:
C:\ProgramData\Package Cache\{bd40e761-3e88-4202-9b53-26c6bed3d467}\windowsdesktop-runtime-8.0.11-win-x64.exe
(PID) Process:(6744) windowsdesktop-runtime-8.0.11-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{bd40e761-3e88-4202-9b53-26c6bed3d467}
Operation:writeName:BundleUpgradeCode
Value:
{7F5F299F-5EB1-6FC0-6D86-FB7931E33C68}
(PID) Process:(6744) windowsdesktop-runtime-8.0.11-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{bd40e761-3e88-4202-9b53-26c6bed3d467}
Operation:writeName:BundleAddonCode
Value:
(PID) Process:(6744) windowsdesktop-runtime-8.0.11-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{bd40e761-3e88-4202-9b53-26c6bed3d467}
Operation:writeName:BundleDetectCode
Value:
(PID) Process:(6744) windowsdesktop-runtime-8.0.11-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{bd40e761-3e88-4202-9b53-26c6bed3d467}
Operation:writeName:BundlePatchCode
Value:
(PID) Process:(6744) windowsdesktop-runtime-8.0.11-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{bd40e761-3e88-4202-9b53-26c6bed3d467}
Operation:writeName:BundleVersion
Value:
8.0.11.34221
(PID) Process:(6744) windowsdesktop-runtime-8.0.11-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{bd40e761-3e88-4202-9b53-26c6bed3d467}
Operation:writeName:VersionMajor
Value:
8
(PID) Process:(6744) windowsdesktop-runtime-8.0.11-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{bd40e761-3e88-4202-9b53-26c6bed3d467}
Operation:writeName:VersionMinor
Value:
0
(PID) Process:(6744) windowsdesktop-runtime-8.0.11-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{bd40e761-3e88-4202-9b53-26c6bed3d467}
Operation:writeName:BundleProviderKey
Value:
{bd40e761-3e88-4202-9b53-26c6bed3d467}
(PID) Process:(6744) windowsdesktop-runtime-8.0.11-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{bd40e761-3e88-4202-9b53-26c6bed3d467}
Operation:writeName:BundleTag
Value:
Executable files
5
Suspicious files
1
Text files
21
Unknown types
0

Dropped files

PID
Process
Filename
Type
6444windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{2F3A91F6-5EC7-4B77-A271-474F39462326}\.cr\windowsdesktop-runtime-8.0.11-win-x64.exeexecutable
MD5:FBA0B1010E82EE3896E104749F505F54
SHA256:4AAE588970B5DE7E67C0C46B19D7E671E8186D5FD7082C1F602F57F1CED0E516
6468windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{E652D2F1-8DA7-40E9-8878-F36CDEDAB133}\.ba\wixstdba.dllexecutable
MD5:F1919C6BD85D7A78A70C228A5B227FBE
SHA256:DCEA15F3710822FFC262E62EC04CC7BBBF0F33F5D1A853609FBFB65CB6A45640
6468windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{E652D2F1-8DA7-40E9-8878-F36CDEDAB133}\.ba\thm.xmlxml
MD5:302563A713B142EE41B59E3EEAC53A90
SHA256:83CA096F7BA2C83FC3B3AEB697B8139A788FA35EB8632943E26BB9FFF7C78E63
6468windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{E652D2F1-8DA7-40E9-8878-F36CDEDAB133}\.ba\thm.wxlxml
MD5:D5070CB3387A0A22B7046AE5AB53F371
SHA256:81A68046B06E09385BE8449373E7CEB9E79F7724C3CF11F0B18A4489A8D4926A
6468windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{E652D2F1-8DA7-40E9-8878-F36CDEDAB133}\.ba\1028\thm.wxlxml
MD5:B9428C94444693B5E3A392C8D0B95170
SHA256:C0413EDFD13FD27EEAB7B8CE60963668236466C48F4173C29F84093011C281AF
6468windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{E652D2F1-8DA7-40E9-8878-F36CDEDAB133}\.ba\1029\thm.wxlxml
MD5:27411946EF45B3B8236319421770E5AD
SHA256:C92D3EFD72D6D14148F9931128EE4143AFFD1DA517EB358AB88ED4138C1434A4
6468windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{E652D2F1-8DA7-40E9-8878-F36CDEDAB133}\.ba\1036\thm.wxlxml
MD5:9F779700FF90DF7211AE3A3340DDD5FC
SHA256:6AF5C2BC88B1E5CE188A97DD9204061D66369EC2689B3657AFF1DC6188F44F22
6468windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{E652D2F1-8DA7-40E9-8878-F36CDEDAB133}\.ba\1042\thm.wxlxml
MD5:F59A0369A337B58A797DDBB5EBBDCADC
SHA256:1B1B0700AA6677AFE3581B8B3F4934BF85F4750C544A108E1D5F1B688078E1CF
6468windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{E652D2F1-8DA7-40E9-8878-F36CDEDAB133}\.ba\bg.pngimage
MD5:9EB0320DFBF2BD541E6A55C01DDC9F20
SHA256:9095BF7B6BAA0107B40A4A6D727215BE077133A190F4CA9BD89A176842141E79
6468windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{E652D2F1-8DA7-40E9-8878-F36CDEDAB133}\.ba\1033\thm.wxlxml
MD5:D5070CB3387A0A22B7046AE5AB53F371
SHA256:81A68046B06E09385BE8449373E7CEB9E79F7724C3CF11F0B18A4489A8D4926A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
31
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4668
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6184
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
4668
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5064
SearchApp.exe
92.123.104.18:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
40.126.32.74:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1076
svchost.exe
184.28.89.167:443
go.microsoft.com
AKAMAI-AS
US
whitelisted
1476
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 92.123.104.18
  • 92.123.104.17
  • 92.123.104.20
  • 92.123.104.15
  • 92.123.104.23
  • 92.123.104.21
  • 92.123.104.19
  • 92.123.104.14
  • 92.123.104.16
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
google.com
  • 142.250.185.206
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 23.52.120.96
  • 88.221.169.152
whitelisted
login.live.com
  • 40.126.32.74
  • 20.190.160.22
  • 40.126.32.136
  • 40.126.32.76
  • 20.190.160.20
  • 40.126.32.134
  • 20.190.160.14
  • 40.126.32.138
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted

Threats

No threats detected
No debug info