File name:

windowsdesktop-runtime-8.0.11-win-x64.exe

Full analysis: https://app.any.run/tasks/2882613e-98ff-4737-989d-8c6ba4746f2f
Verdict: Malicious activity
Analysis date: December 10, 2024, 15:07:30
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections
MD5:

FBA0B1010E82EE3896E104749F505F54

SHA1:

E7E43E8DA6AF9CD6A6B740B8F70CAEB5FBFDA730

SHA256:

4AAE588970B5DE7E67C0C46B19D7E671E8186D5FD7082C1F602F57F1CED0E516

SSDEEP:

24576:d+F8g+nZTnAHFo23SjnB/q+MNk7JO/gszhVBcIo13:d+F8g+nZTnAHFo2i7B/qrNuJO/gslVBk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6744)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6444)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6468)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6744)
    • Starts a Microsoft application from unusual location

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6468)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6444)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6744)
    • Searches for installed software

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6468)
    • Starts itself from another location

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6444)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6468)
    • Process drops legitimate windows executable

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6468)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6444)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6744)
    • Creates a software uninstall entry

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6744)
  • INFO

    • The sample compiled with english language support

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6444)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6468)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6744)
    • Checks supported languages

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6444)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6468)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6744)
    • Create files in a temporary directory

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6468)
    • Reads the computer name

      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6468)
      • windowsdesktop-runtime-8.0.11-win-x64.exe (PID: 6744)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:09:23 22:06:56+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 14.16
CodeSize: 303104
InitializedDataSize: 162816
UninitializedDataSize: -
EntryPoint: 0x3054b
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 8.0.11.34221
ProductVersionNumber: 8.0.11.34221
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Microsoft Corporation
FileDescription: Microsoft Windows Desktop Runtime - 8.0.11 (x64)
FileVersion: 8.0.11.34221
InternalName: setup
LegalCopyright: Copyright (c) Microsoft Corporation. All rights reserved.
OriginalFileName: windowsdesktop-runtime-8.0.11-win-x64.exe
ProductName: Microsoft Windows Desktop Runtime - 8.0.11 (x64)
ProductVersion: 8.0.11.34221
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
4
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start windowsdesktop-runtime-8.0.11-win-x64.exe windowsdesktop-runtime-8.0.11-win-x64.exe windowsdesktop-runtime-8.0.11-win-x64.exe rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
5244C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
6444"C:\Users\admin\AppData\Local\Temp\windowsdesktop-runtime-8.0.11-win-x64.exe" C:\Users\admin\AppData\Local\Temp\windowsdesktop-runtime-8.0.11-win-x64.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Desktop Runtime - 8.0.11 (x64)
Exit code:
1
Version:
8.0.11.34221
Modules
Images
c:\users\admin\appdata\local\temp\windowsdesktop-runtime-8.0.11-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6468"C:\Users\admin\AppData\Local\Temp\{2F3A91F6-5EC7-4B77-A271-474F39462326}\.cr\windowsdesktop-runtime-8.0.11-win-x64.exe" -burn.clean.room="C:\Users\admin\AppData\Local\Temp\windowsdesktop-runtime-8.0.11-win-x64.exe" -burn.filehandle.attached=596 -burn.filehandle.self=604 C:\Users\admin\AppData\Local\Temp\{2F3A91F6-5EC7-4B77-A271-474F39462326}\.cr\windowsdesktop-runtime-8.0.11-win-x64.exe
windowsdesktop-runtime-8.0.11-win-x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Desktop Runtime - 8.0.11 (x64)
Exit code:
1
Version:
8.0.11.34221
Modules
Images
c:\users\admin\appdata\local\temp\{2f3a91f6-5ec7-4b77-a271-474f39462326}\.cr\windowsdesktop-runtime-8.0.11-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6744"C:\Users\admin\AppData\Local\Temp\{E652D2F1-8DA7-40E9-8878-F36CDEDAB133}\.be\windowsdesktop-runtime-8.0.11-win-x64.exe" -q -burn.elevated BurnPipe.{36C8F6A9-BD11-4A52-88D2-A837739E493F} {E1E7AEFD-7565-47F1-97DF-F40C62C096CF} 6468C:\Users\admin\AppData\Local\Temp\{E652D2F1-8DA7-40E9-8878-F36CDEDAB133}\.be\windowsdesktop-runtime-8.0.11-win-x64.exe
windowsdesktop-runtime-8.0.11-win-x64.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Windows Desktop Runtime - 8.0.11 (x64)
Exit code:
1
Version:
8.0.11.34221
Modules
Images
c:\users\admin\appdata\local\temp\{e652d2f1-8da7-40e9-8878-f36cdedab133}\.be\windowsdesktop-runtime-8.0.11-win-x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
521
Read events
488
Write events
26
Delete events
7

Modification events

(PID) Process:(6744) windowsdesktop-runtime-8.0.11-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{bd40e761-3e88-4202-9b53-26c6bed3d467}
Operation:writeName:BundleCachePath
Value:
C:\ProgramData\Package Cache\{bd40e761-3e88-4202-9b53-26c6bed3d467}\windowsdesktop-runtime-8.0.11-win-x64.exe
(PID) Process:(6744) windowsdesktop-runtime-8.0.11-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{bd40e761-3e88-4202-9b53-26c6bed3d467}
Operation:writeName:BundleUpgradeCode
Value:
{7F5F299F-5EB1-6FC0-6D86-FB7931E33C68}
(PID) Process:(6744) windowsdesktop-runtime-8.0.11-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{bd40e761-3e88-4202-9b53-26c6bed3d467}
Operation:writeName:BundleAddonCode
Value:
(PID) Process:(6744) windowsdesktop-runtime-8.0.11-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{bd40e761-3e88-4202-9b53-26c6bed3d467}
Operation:writeName:BundleDetectCode
Value:
(PID) Process:(6744) windowsdesktop-runtime-8.0.11-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{bd40e761-3e88-4202-9b53-26c6bed3d467}
Operation:writeName:BundlePatchCode
Value:
(PID) Process:(6744) windowsdesktop-runtime-8.0.11-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{bd40e761-3e88-4202-9b53-26c6bed3d467}
Operation:writeName:BundleVersion
Value:
8.0.11.34221
(PID) Process:(6744) windowsdesktop-runtime-8.0.11-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{bd40e761-3e88-4202-9b53-26c6bed3d467}
Operation:writeName:VersionMajor
Value:
8
(PID) Process:(6744) windowsdesktop-runtime-8.0.11-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{bd40e761-3e88-4202-9b53-26c6bed3d467}
Operation:writeName:VersionMinor
Value:
0
(PID) Process:(6744) windowsdesktop-runtime-8.0.11-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{bd40e761-3e88-4202-9b53-26c6bed3d467}
Operation:writeName:BundleProviderKey
Value:
{bd40e761-3e88-4202-9b53-26c6bed3d467}
(PID) Process:(6744) windowsdesktop-runtime-8.0.11-win-x64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{bd40e761-3e88-4202-9b53-26c6bed3d467}
Operation:writeName:BundleTag
Value:
Executable files
5
Suspicious files
1
Text files
21
Unknown types
0

Dropped files

PID
Process
Filename
Type
6444windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{2F3A91F6-5EC7-4B77-A271-474F39462326}\.cr\windowsdesktop-runtime-8.0.11-win-x64.exeexecutable
MD5:FBA0B1010E82EE3896E104749F505F54
SHA256:4AAE588970B5DE7E67C0C46B19D7E671E8186D5FD7082C1F602F57F1CED0E516
6468windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{E652D2F1-8DA7-40E9-8878-F36CDEDAB133}\.ba\wixstdba.dllexecutable
MD5:F1919C6BD85D7A78A70C228A5B227FBE
SHA256:DCEA15F3710822FFC262E62EC04CC7BBBF0F33F5D1A853609FBFB65CB6A45640
6468windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{E652D2F1-8DA7-40E9-8878-F36CDEDAB133}\.ba\thm.wxlxml
MD5:D5070CB3387A0A22B7046AE5AB53F371
SHA256:81A68046B06E09385BE8449373E7CEB9E79F7724C3CF11F0B18A4489A8D4926A
6468windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{E652D2F1-8DA7-40E9-8878-F36CDEDAB133}\.ba\1033\thm.wxlxml
MD5:D5070CB3387A0A22B7046AE5AB53F371
SHA256:81A68046B06E09385BE8449373E7CEB9E79F7724C3CF11F0B18A4489A8D4926A
6468windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{E652D2F1-8DA7-40E9-8878-F36CDEDAB133}\.ba\1029\thm.wxlxml
MD5:27411946EF45B3B8236319421770E5AD
SHA256:C92D3EFD72D6D14148F9931128EE4143AFFD1DA517EB358AB88ED4138C1434A4
6468windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{E652D2F1-8DA7-40E9-8878-F36CDEDAB133}\.ba\1031\thm.wxlxml
MD5:B45249A2238A5568B377E58D4CE89E9A
SHA256:0C4203A81DCD01D53378036AF78CFFCF9E9A5AF7754DFBDD56584AE74C21CC61
6468windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{E652D2F1-8DA7-40E9-8878-F36CDEDAB133}\.ba\1036\thm.wxlxml
MD5:9F779700FF90DF7211AE3A3340DDD5FC
SHA256:6AF5C2BC88B1E5CE188A97DD9204061D66369EC2689B3657AFF1DC6188F44F22
6468windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{E652D2F1-8DA7-40E9-8878-F36CDEDAB133}\.ba\1042\thm.wxlxml
MD5:F59A0369A337B58A797DDBB5EBBDCADC
SHA256:1B1B0700AA6677AFE3581B8B3F4934BF85F4750C544A108E1D5F1B688078E1CF
6468windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{E652D2F1-8DA7-40E9-8878-F36CDEDAB133}\.ba\1041\thm.wxlxml
MD5:E5FD798D4BBDD419A602423A699E2854
SHA256:00AEC52B4564BC07302881FCFD510F7CCA535AC9E05CFD95A86738171626F6C4
6468windowsdesktop-runtime-8.0.11-win-x64.exeC:\Users\admin\AppData\Local\Temp\{E652D2F1-8DA7-40E9-8878-F36CDEDAB133}\.ba\2052\thm.wxlxml
MD5:ED946A363E47DCC77017EC10B1032C54
SHA256:3BB9CE59BA1C4B76FA6B35F544E2B04C85387053EDD8B25D8C8D4FE637FB0A85
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
31
DNS requests
17
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6184
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
4668
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4668
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5064
SearchApp.exe
92.123.104.18:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
1176
svchost.exe
40.126.32.74:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1076
svchost.exe
184.28.89.167:443
go.microsoft.com
AKAMAI-AS
US
whitelisted
1476
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 92.123.104.18
  • 92.123.104.17
  • 92.123.104.20
  • 92.123.104.15
  • 92.123.104.23
  • 92.123.104.21
  • 92.123.104.19
  • 92.123.104.14
  • 92.123.104.16
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
whitelisted
google.com
  • 142.250.185.206
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 23.52.120.96
  • 88.221.169.152
whitelisted
login.live.com
  • 40.126.32.74
  • 20.190.160.22
  • 40.126.32.136
  • 40.126.32.76
  • 20.190.160.20
  • 40.126.32.134
  • 20.190.160.14
  • 40.126.32.138
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted

Threats

No threats detected
No debug info