File name:

Ask3lad Test Drive GUI v1.0.exe

Full analysis: https://app.any.run/tasks/70e2399e-1445-4b76-990d-d82165d020f9
Verdict: Malicious activity
Analysis date: June 29, 2025, 17:52:11
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
pyinstaller
python
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64, for MS Windows, 7 sections
MD5:

A6A82FD086C636466B7780D6AEE02E18

SHA1:

6DC3EA9AAA89BB7D6CD0FDC6E60DFFF915273204

SHA256:

4ED6E2CC2E4D2A2CDF0D33EEA4D085710BFFC359C6735C4A13385D17688CE62B

SSDEEP:

98304:B1T2Q69eg7aLeiEtzUz6yW6H+lAJuz3R0z86VoIsvRPnPigA8SeSok24iVoumzy1:M6dI49LEEZ5KAOJdGV6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • The process drops C-runtime libraries

      • Ask3lad Test Drive GUI v1.0.exe (PID: 2076)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 4320)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 3908)
    • Executable content was dropped or overwritten

      • Ask3lad Test Drive GUI v1.0.exe (PID: 2076)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 3908)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 4320)
    • Process drops python dynamic module

      • Ask3lad Test Drive GUI v1.0.exe (PID: 2076)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 3908)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 4320)
    • Process drops legitimate windows executable

      • Ask3lad Test Drive GUI v1.0.exe (PID: 2076)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 4320)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 3908)
    • Application launched itself

      • Ask3lad Test Drive GUI v1.0.exe (PID: 2076)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 3908)
    • Loads Python modules

      • Ask3lad Test Drive GUI v1.0.exe (PID: 2468)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 3624)
    • There is functionality for taking screenshot (YARA)

      • Ask3lad Test Drive GUI v1.0.exe (PID: 2076)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 3908)
    • Reads security settings of Internet Explorer

      • Ask3lad Test Drive GUI v1.0.exe (PID: 2468)
  • INFO

    • Checks supported languages

      • Ask3lad Test Drive GUI v1.0.exe (PID: 2076)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 3908)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 4320)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 2468)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 3624)
    • Reads the computer name

      • Ask3lad Test Drive GUI v1.0.exe (PID: 2076)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 3908)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 4320)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 2468)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 3624)
    • Create files in a temporary directory

      • Ask3lad Test Drive GUI v1.0.exe (PID: 2076)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 3908)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 4320)
    • Manual execution by a user

      • Ask3lad Test Drive GUI v1.0.exe (PID: 3908)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 4320)
    • The sample compiled with english language support

      • Ask3lad Test Drive GUI v1.0.exe (PID: 2076)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 4320)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 3908)
    • PyInstaller has been detected (YARA)

      • Ask3lad Test Drive GUI v1.0.exe (PID: 2076)
      • Ask3lad Test Drive GUI v1.0.exe (PID: 3908)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (57.6)
.exe | Win64 Executable (generic) (36.9)
.exe | Generic Win/DOS Executable (2.6)
.exe | DOS Executable Generic (2.6)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:04:23 21:42:46+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.42
CodeSize: 173568
InitializedDataSize: 109568
UninitializedDataSize: -
EntryPoint: 0xce20
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
5
Malicious processes
0
Suspicious processes
3

Behavior graph

Click at the process to see the details
start ask3lad test drive gui v1.0.exe ask3lad test drive gui v1.0.exe ask3lad test drive gui v1.0.exe ask3lad test drive gui v1.0.exe no specs ask3lad test drive gui v1.0.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2076"C:\Users\admin\Desktop\Ask3lad Test Drive GUI v1.0.exe" C:\Users\admin\Desktop\Ask3lad Test Drive GUI v1.0.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\ask3lad test drive gui v1.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2468"C:\Users\admin\Desktop\Ask3lad Test Drive GUI v1.0.exe" C:\Users\admin\Desktop\Ask3lad Test Drive GUI v1.0.exeAsk3lad Test Drive GUI v1.0.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\ask3lad test drive gui v1.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
3624"C:\Users\admin\Desktop\Ask3lad Test Drive GUI v1.0.exe" C:\Users\admin\Desktop\Ask3lad Test Drive GUI v1.0.exeAsk3lad Test Drive GUI v1.0.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\ask3lad test drive gui v1.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3908"C:\Users\admin\Desktop\Ask3lad Test Drive GUI v1.0.exe" C:\Users\admin\Desktop\Ask3lad Test Drive GUI v1.0.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\ask3lad test drive gui v1.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
4320"C:\Users\admin\Desktop\Ask3lad Test Drive GUI v1.0.exe" C:\Users\admin\Desktop\Ask3lad Test Drive GUI v1.0.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\desktop\ask3lad test drive gui v1.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
3 747
Read events
3 711
Write events
35
Delete events
1

Modification events

(PID) Process:(2468) Ask3lad Test Drive GUI v1.0.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
(PID) Process:(2468) Ask3lad Test Drive GUI v1.0.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:MRUListEx
Value:
040000000000000003000000110000000E000000100000000F0000000C0000000D0000000B000000050000000A000000090000000800000001000000070000000600000002000000FFFFFFFF
(PID) Process:(2468) Ask3lad Test Drive GUI v1.0.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\4
Operation:writeName:MRUListEx
Value:
040000000000000003000000050000000200000001000000FFFFFFFF
(PID) Process:(2468) Ask3lad Test Drive GUI v1.0.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\119\Shell
Operation:writeName:SniffedFolderType
Value:
Documents
(PID) Process:(2468) Ask3lad Test Drive GUI v1.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
121
(PID) Process:(2468) Ask3lad Test Drive GUI v1.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\*
Operation:writeName:9
Value:
14001F50E04FD020EA3A6910A2D808002B30309D3A002E80922B16D365937A46956B92703ACA08AF260001002600EFBE11000000FCD61862AF27D301269D8E065892DB01609C93A21EE9DB0114000000
(PID) Process:(2468) Ask3lad Test Drive GUI v1.0.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\OpenSavePidlMRU\*
Operation:writeName:MRUListEx
Value:
09000000070000000800000006000000050000000400000003000000020000000100000000000000FFFFFFFF
(PID) Process:(2468) Ask3lad Test Drive GUI v1.0.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\119\ComDlg\{7D49D726-3C21-4F05-99AA-FDC2C9474656}
Operation:writeName:Mode
Value:
4
(PID) Process:(2468) Ask3lad Test Drive GUI v1.0.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\119\ComDlg\{7D49D726-3C21-4F05-99AA-FDC2C9474656}
Operation:writeName:LogicalViewMode
Value:
1
(PID) Process:(2468) Ask3lad Test Drive GUI v1.0.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\119\ComDlg\{7D49D726-3C21-4F05-99AA-FDC2C9474656}
Operation:writeName:FFlags
Value:
Executable files
57
Suspicious files
8
Text files
2 722
Unknown types
0

Dropped files

PID
Process
Filename
Type
2076Ask3lad Test Drive GUI v1.0.exeC:\Users\admin\AppData\Local\Temp\_MEI20762\PIL\_imagingcms.cp311-win_amd64.pydexecutable
MD5:43B3768D75BE9F6635FBEC96633D70E0
SHA256:CCD589E4B61B76F696B7B8DC8BB93A0E1DDF78A91BC78ED0E3A0DB0CEE101CEF
2076Ask3lad Test Drive GUI v1.0.exeC:\Users\admin\AppData\Local\Temp\_MEI20762\PIL\_imaging.cp311-win_amd64.pydexecutable
MD5:12B15796716A81A13B79A79D26C61F22
SHA256:B231D11718A12994A32E744B93F830E931409AE13FAEB150D9F020A2E81CB18C
2076Ask3lad Test Drive GUI v1.0.exeC:\Users\admin\AppData\Local\Temp\_MEI20762\VCRUNTIME140.dllexecutable
MD5:BE8DBE2DC77EBE7F88F910C61AEC691A
SHA256:4D292623516F65C80482081E62D5DADB759DC16E851DE5DB24C3CBB57B87DB83
2076Ask3lad Test Drive GUI v1.0.exeC:\Users\admin\AppData\Local\Temp\_MEI20762\_tcl_data\auto.tcltext
MD5:08EDF746B4A088CB4185C165177BD604
SHA256:517204EE436D08EFC287ABC97433C3BFFCAF42EC6592A3009B9FD3B985AD772C
2076Ask3lad Test Drive GUI v1.0.exeC:\Users\admin\AppData\Local\Temp\_MEI20762\_tcl_data\clock.tcltext
MD5:88BB44A1364147FDD80F9FD78FBCEF61
SHA256:1947F8B188AB4AB6AA72EA68A58D2D9ADD0894FDF320F6B074EAE0F198368FB7
2076Ask3lad Test Drive GUI v1.0.exeC:\Users\admin\AppData\Local\Temp\_MEI20762\_ssl.pydexecutable
MD5:0F02ECCD7933B7A7C2BDEDCA2A72AAB6
SHA256:BA5388D6A6557D431E086734A3323621DC447F63BA299B0A815E5837CF869678
2076Ask3lad Test Drive GUI v1.0.exeC:\Users\admin\AppData\Local\Temp\_MEI20762\PIL\_webp.cp311-win_amd64.pydexecutable
MD5:043CAA5BB08233C47E0C9B5DA450A8BD
SHA256:0EB411217C819288CC542ED73C54AC613D6ACAA6BAFF3DEA2B627489C9ABDA3E
2076Ask3lad Test Drive GUI v1.0.exeC:\Users\admin\AppData\Local\Temp\_MEI20762\PIL\_imagingtk.cp311-win_amd64.pydexecutable
MD5:E3C58E98FFA96D316726622CA861406D
SHA256:301F02CDA274D34E59B26BA94E980FB454047613D7DC998CBB5526CB2B494CFC
2076Ask3lad Test Drive GUI v1.0.exeC:\Users\admin\AppData\Local\Temp\_MEI20762\_socket.pydexecutable
MD5:B77017BAA2004833EF3847A3A3141280
SHA256:A19E3C7C03EF1B5625790B1C9C42594909311AB6DF540FBF43C6AA93300AB166
2076Ask3lad Test Drive GUI v1.0.exeC:\Users\admin\AppData\Local\Temp\_MEI20762\_tcl_data\encoding\big5.enctext
MD5:41A874778111CC218BD421CF9C795EC2
SHA256:AD1ED201B69855BFD353BF969DFC55576DA35A963ABF1BF7FC6D8B5142A61A61
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
21
DNS requests
15
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
640
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
640
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6672
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5504
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
6672
svchost.exe
20.190.159.75:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6672
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
  • 20.73.194.208
whitelisted
google.com
  • 142.250.186.142
whitelisted
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
login.live.com
  • 20.190.159.75
  • 40.126.31.3
  • 40.126.31.2
  • 40.126.31.69
  • 20.190.159.2
  • 40.126.31.131
  • 40.126.31.1
  • 20.190.159.68
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
nexusrules.officeapps.live.com
  • 52.111.243.31
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info