File name:

shutdownBlocker.exe

Full analysis: https://app.any.run/tasks/5f09a433-8248-4792-8e91-fcc6c69e93fd
Verdict: Malicious activity
Analysis date: April 07, 2025, 18:58:33
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

2BA67A3C8592348FFBFC3495A4F98581

SHA1:

5C13530B92E54D44D28F5BCCC578AF39F5BC1175

SHA256:

4C37776F2F1E9EAC129359101039FDA5E5E9D9C90A9997A4CAF9F802987E1C98

SSDEEP:

3072:FB+gojNqa0ixvrt54N2qyB1jG+ytK+pjW/h7M3wquxauJUr:M0ixvr3wwhAAU2U

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes image file execution options

      • shutdownBlocker.exe (PID: 7476)
    • Uses Task Scheduler to autorun other applications

      • shutdownBlocker.exe (PID: 7476)
  • SUSPICIOUS

    • There is functionality for taking screenshot (YARA)

      • shutdownBlocker.exe (PID: 7476)
    • Lists all scheduled tasks

      • schtasks.exe (PID: 7584)
      • schtasks.exe (PID: 5936)
      • schtasks.exe (PID: 2152)
    • Reads Internet Explorer settings

      • shutdownBlocker.exe (PID: 7476)
  • INFO

    • Reads the computer name

      • shutdownBlocker.exe (PID: 7476)
    • Reads the machine GUID from the registry

      • shutdownBlocker.exe (PID: 7476)
    • Checks supported languages

      • shutdownBlocker.exe (PID: 7476)
    • Creates files or folders in the user directory

      • shutdownBlocker.exe (PID: 7476)
    • Reads the software policy settings

      • slui.exe (PID: 7540)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (56.7)
.exe | Win64 Executable (generic) (21.3)
.scr | Windows screen saver (10.1)
.dll | Win32 Dynamic Link Library (generic) (5)
.exe | Win32 Executable (generic) (3.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:03:30 23:25:19+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 81920
InitializedDataSize: 37376
UninitializedDataSize: -
EntryPoint: 0x15f2a
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: cresstone.com
FileDescription: shutdownBlocker
FileVersion: 1.0.0.0
InternalName: shutdownBlocker.exe
LegalCopyright: Copyright © 2014
LegalTrademarks: -
OriginalFileName: shutdownBlocker.exe
ProductName: shutdownBlocker
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
146
Monitored processes
13
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start shutdownblocker.exe sppextcomobj.exe no specs slui.exe schtasks.exe no specs conhost.exe no specs slui.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs shutdownblocker.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2152"schtasks" /Query /TN shutDownBlockerC:\Windows\System32\schtasks.exeshutdownBlocker.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Scheduler Configuration Tool
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2244\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5512\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5544C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
3221226091
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5936"schtasks" /Query /TN shutDownBlockerC:\Windows\System32\schtasks.exeshutdownBlocker.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Scheduler Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
6372"schtasks" /Create /TN shutDownBlocker /SC ONLOGON /RL HIGHEST /DELAY 0000:30 /IT /TR "C:\Users\admin\Downloads\shutdownBlocker.exe -starthidden -block"C:\Windows\System32\schtasks.exeshutdownBlocker.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Task Scheduler Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
7176\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7368"C:\Users\admin\Downloads\shutdownBlocker.exe" C:\Users\admin\Downloads\shutdownBlocker.exeexplorer.exe
User:
admin
Company:
cresstone.com
Integrity Level:
MEDIUM
Description:
shutdownBlocker
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\downloads\shutdownblocker.exe
c:\windows\system32\ntdll.dll
7476"C:\Users\admin\Downloads\shutdownBlocker.exe" C:\Users\admin\Downloads\shutdownBlocker.exe
explorer.exe
User:
admin
Company:
cresstone.com
Integrity Level:
HIGH
Description:
shutdownBlocker
Version:
1.0.0.0
Modules
Images
c:\users\admin\downloads\shutdownblocker.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
7500C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
Total events
3 906
Read events
3 904
Write events
2
Delete events
0

Modification events

(PID) Process:(7476) shutdownBlocker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\shutdown.exe
Operation:writeName:Debugger
Value:
"C:\Users\admin\Downloads\shutdownBlocker.exe" -intercepted_sd
(PID) Process:(7476) shutdownBlocker.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\MusNotification.exe
Operation:writeName:Debugger
Value:
"C:\Users\admin\Downloads\shutdownBlocker.exe" -intercepted_MSU
Executable files
0
Suspicious files
1
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
7476shutdownBlocker.exeC:\Users\admin\Downloads\shutdownBlocker_settings.initext
MD5:02E474BE210D70412D0A23A52F2AA5F4
SHA256:46DD0E048B545B6B5DC07E7F2EAF869371BA438D5081174F6B92A2098B940C8A
7476shutdownBlocker.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\shutdownBlocker.lnkbinary
MD5:AE7309F6461EAE60B09B8B6B7DE121F9
SHA256:3872FDE031F551B6557C632172004F20D3F2F9AD964D7E0C39BB23F4ACA6BC8C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
59
DNS requests
17
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:137
whitelisted
2104
svchost.exe
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
5496
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
20.190.159.129:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2112
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.181.238
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.159.129
  • 20.190.159.130
  • 20.190.159.64
  • 20.190.159.131
  • 40.126.31.3
  • 40.126.31.0
  • 20.190.159.71
  • 40.126.31.69
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
  • 2603:1030:408:7::3d
whitelisted
206.23.85.13.in-addr.arpa
unknown
d.3.0.0.0.0.0.0.0.0.0.0.0.0.0.0.7.0.0.0.8.0.4.0.0.3.0.1.3.0.6.2.ip6.arpa
unknown
www.bing.com
  • 104.126.37.129
  • 104.126.37.131
  • 104.126.37.171
  • 104.126.37.185
  • 104.126.37.123
  • 104.126.37.137
  • 104.126.37.130
  • 104.126.37.176
  • 104.126.37.186
whitelisted
nexusrules.officeapps.live.com
  • 52.111.229.19
whitelisted

Threats

No threats detected
No debug info