File name:

4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe

Full analysis: https://app.any.run/tasks/c4633171-76bd-4e11-a9ca-9f589e57e659
Verdict: Malicious activity
Analysis date: October 03, 2025, 17:48:26
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
m0yv
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

FA715941AE44C839714C1BB495A451D3

SHA1:

021C1E3D14418CFF0DABB631C9B34AE57A742925

SHA256:

4C66173FFE45DE9A2B7DF75FB358FB431866D7DB99115D69D3BA9547012EA1BD

SSDEEP:

24576:RtbFk8Poo71k1C/xH0lWVatrgtPtsvIhgd9jeWRNN1:jbS8Poo71k1C/xH0lWV0rgtPtsvIhgdL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • M0YV mutex has been found

      • 4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe (PID: 4676)
    • M0YV has been detected (SURICATA)

      • svchost.exe (PID: 2428)
    • Connects to the CnC server

      • svchost.exe (PID: 2428)
    • M0YV has been detected (YARA)

      • 4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe (PID: 4676)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • 4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe (PID: 4676)
    • Executable content was dropped or overwritten

      • 4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe (PID: 4676)
  • INFO

    • The sample compiled with english language support

      • 4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe (PID: 4676)
    • Creates files or folders in the user directory

      • 4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe (PID: 4676)
    • Checks supported languages

      • 4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe (PID: 4676)
    • Reads the computer name

      • 4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe (PID: 4676)
    • Checks proxy server information

      • 4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe (PID: 4676)
      • slui.exe (PID: 6064)
    • Reads the software policy settings

      • slui.exe (PID: 6064)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:11:02 09:38:31+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 64512
InitializedDataSize: 53248
UninitializedDataSize: -
EntryPoint: 0x1dbe
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 0.3.0.0
ProductVersionNumber: 0.3.0.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Geeks3D
FileDescription: CPU Burner
FileVersion: 0.3.0.0
InternalName: CPUBurner
LegalCopyright: Copyright (C) 2013-2023 Geeks3D
OriginalFileName: cpuburner.exe
ProductName: CPU Burner App
ProductVersion: 0.3.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
158
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
2428C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
4676"C:\Users\admin\Desktop\4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe" C:\Users\admin\Desktop\4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe
explorer.exe
User:
admin
Company:
Geeks3D
Integrity Level:
MEDIUM
Description:
CPU Burner
Version:
0.3.0.0
Modules
Images
c:\users\admin\desktop\4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6064C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
4 628
Read events
4 628
Write events
0
Delete events
0

Modification events

No data
Executable files
7
Suspicious files
1
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
46764c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exeexecutable
MD5:6E053118583C4D9AC1AE455C0C5AC802
SHA256:B9709FEEEAF569EB9B4E17D55DAC19F20D69BC885EA324EFE4DA2C8D8FD2DFFA
46764c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exeexecutable
MD5:6699AE7443E995F777A838F5C5A53A99
SHA256:29A1C91C15E1A1890A17CF66496BCE41CCAA9DBB564142224F2AE6B6017F90F1
46764c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exeC:\ProgramData\Adobe\ARM\S\388\AdobeARMHelper.exeexecutable
MD5:D4A7B18AEFBBD50764C047659F4087F1
SHA256:52D133E502D85A03C5260E5960B5C2CBD5C7130B33FB0840190A440D4BABD981
46764c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exeexecutable
MD5:BF5028EE9200D5EFC7322A4F37A3C350
SHA256:83EB04D006A9FAC5BADB935486966BA7A72E7338CDE70AD9CBF586CF668887A5
46764c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exeexecutable
MD5:E91180814A4696B2520A778FE979AFAA
SHA256:2230124B9BCEADCFB33ECD5276DCDCC1022BE909CAF0C8CC229A68DC2F98058D
46764c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exeC:\Users\admin\AppData\Roaming\26b799fa89ba8c8f.binbinary
MD5:4E8A55F49474430A9C6741E4B57E1377
SHA256:E17C2947C8DC74FF40D3AB98C4F3A140B560F169A7171BAFD877097ED213118B
46764c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exeexecutable
MD5:A3F757C1071342054F56001C626743BF
SHA256:C6E940AFE1A564CA649731A759F316845EF7F4331ED65EE55333E2D1C3FC0003
46764c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exeexecutable
MD5:CF50CEAA7C2329C8FA5218AC9B712E3D
SHA256:C0FAA846B0970156BDD6390815B7776ED84CD939F0CA45617B4D1DE17F87F265
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
50
TCP/UDP connections
53
DNS requests
48
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4676
4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe
POST
200
50.16.27.236:80
http://ssbzmoy.biz/jiuvrranwmuslmdb
US
unknown
4676
4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe
POST
200
172.237.146.8:80
http://przvgke.biz/nj
US
binary
4.29 Kb
unknown
4676
4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe
POST
200
3.238.30.69:80
http://ifsaia.biz/n
US
unknown
4676
4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe
POST
200
3.229.117.57:80
http://saytjshyf.biz/gpg
US
unknown
4676
4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe
POST
200
54.146.6.253:80
http://xlfhhhm.biz/bqdepdsgjsxvvh
US
malicious
4676
4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe
POST
302
192.64.119.165:80
http://anpmnmxo.biz/dahkmbqxayvc
US
unknown
4676
4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe
POST
200
50.16.27.236:80
http://knjghuig.biz/auesjd
US
malicious
4676
4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe
POST
200
44.244.22.128:80
http://pywolwnvd.biz/mieqparkr
US
malicious
4676
4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe
GET
403
91.195.240.19:80
http://www.anpmnmxo.biz/kdrsbkcu
DE
html
93 b
unknown
4676
4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe
POST
200
172.237.146.8:80
http://przvgke.biz/txgiarodtwtyks
US
binary
4.32 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6016
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
4928
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.241.201:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4676
4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe
44.244.22.128:80
pywolwnvd.biz
AMAZON-02
US
malicious
6016
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4676
4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe
50.16.27.236:80
ssbzmoy.biz
AMAZON-AES
US
malicious
5948
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4676
4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe
3.229.117.57:80
npukfztj.biz
AMAZON-AES
US
malicious

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
whitelisted
www.bing.com
  • 2.16.241.201
  • 2.16.241.205
  • 2.16.241.218
  • 2.16.241.207
whitelisted
google.com
  • 142.250.186.174
whitelisted
pywolwnvd.biz
  • 44.244.22.128
malicious
ssbzmoy.biz
  • 50.16.27.236
unknown
cvgrf.biz
  • 44.244.22.128
malicious
npukfztj.biz
  • 3.229.117.57
malicious
przvgke.biz
  • 172.237.146.8
  • 172.237.146.25
  • 172.233.219.123
  • 172.233.219.78
  • 172.233.219.49
  • 172.237.146.38
unknown
zlenh.biz
unknown
knjghuig.biz
  • 50.16.27.236
malicious

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
2428
svchost.exe
A Network Trojan was detected
ET MALWARE DNS Query to Expiro Related Domain (knjghuig .biz)
2428
svchost.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Win32/m0yv CnC related domain (zlenh .biz)
4676
4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe
Misc activity
ET INFO Namecheap URL Forward
4676
4c66173ffe45de9a2b7df75fb358fb431866d7db99115d69d3ba9547012ea1bd.exe
Misc activity
ET INFO Namecheap URL Forward
No debug info