File name:

New Agreement Document 2025.com

Full analysis: https://app.any.run/tasks/1470a410-c455-4757-9f7c-e85511ede864
Verdict: Malicious activity
Analysis date: February 19, 2025, 13:07:49
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 7 sections
MD5:

569CD75E5907FD52FCAB645BCA570946

SHA1:

CBA256EA7B1FE276E73EC45C120A5326FAE4659E

SHA256:

5692D52FB5161FAF27BF7375F72A4AF274571EA4F86E542B5A094EBA5A8529E1

SSDEEP:

98304:pB0tvnOUylgPVQcegXB42OriAV9B3gIgQBWyOeWw+5hInLsiHF4Lqi4/XbTa4ES/:Uel/t3F

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • New Agreement Document 2025.com.exe (PID: 6472)
      • _tinreg32.exe (PID: 6568)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • New Agreement Document 2025.com.exe (PID: 6472)
    • Executable content was dropped or overwritten

      • New Agreement Document 2025.com.exe (PID: 6472)
      • Lightshot.exe (PID: 6612)
    • Uses RUNDLL32.EXE to load library

      • control.exe (PID: 7072)
      • control.exe (PID: 6400)
    • The process executes via Task Scheduler

      • control.exe (PID: 6400)
      • control.exe (PID: 7072)
    • Connects to unusual port

      • rundll32.exe (PID: 7128)
    • Creates a software uninstall entry

      • New Agreement Document 2025.com.exe (PID: 6472)
  • INFO

    • Checks supported languages

      • New Agreement Document 2025.com.exe (PID: 6472)
      • _tinreg32.exe (PID: 6568)
      • Lightshot.exe (PID: 6612)
    • Reads the computer name

      • New Agreement Document 2025.com.exe (PID: 6472)
      • Lightshot.exe (PID: 6612)
    • Create files in a temporary directory

      • New Agreement Document 2025.com.exe (PID: 6472)
    • Reads Microsoft Office registry keys

      • New Agreement Document 2025.com.exe (PID: 6472)
    • Reads Environment values

      • New Agreement Document 2025.com.exe (PID: 6472)
    • Creates files or folders in the user directory

      • New Agreement Document 2025.com.exe (PID: 6472)
      • Lightshot.exe (PID: 6612)
    • Reads security settings of Internet Explorer

      • control.exe (PID: 7072)
      • control.exe (PID: 6400)
    • Manual execution by a user

      • Lightshot.exe (PID: 6612)
    • Reads the machine GUID from the registry

      • Lightshot.exe (PID: 6612)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:12:29 14:51:45+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 8192
InitializedDataSize: 2030592
UninitializedDataSize: -
EntryPoint: 0x15ad
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2025.2.10.958
ProductVersionNumber: 5.5.0.4
FileFlagsMask: 0x003f
FileFlags: Special build
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
ProductName: LigthShoot
ProductVersion: 5.5.0.4
CompanyName: Skillbrains
LegalCopyright: Copyright (c) 2025 Skillbrains
Email: -
WebSite: -
FileDescription: Installer for LigthShoot
FileVersion: 2025.2.10.958
OriginalFileName: LigthShoot-Setup.exe
InternalName: TSULoader
Comments: WinNT (x86) Unicode Lib Rel
ProductCode: {C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}
PackageCode: {A3F73EF0-AB26-44E7-74F8-0505ED09F546}
Arguments: -
SpecialBuild: -
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
9
Malicious processes
1
Suspicious processes
3

Behavior graph

Click at the process to see the details
start new agreement document 2025.com.exe _tinreg32.exe no specs lightshot.exe control.exe no specs rundll32.exe no specs rundll32.exe control.exe no specs rundll32.exe no specs rundll32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6400"C:\WINDOWS\system32\control.EXE" C:\Users\admin\AppData\Roaming\SkyVault\Skymage.dllC:\Windows\System32\control.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Control Panel
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\control.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6468"C:\WINDOWS\system32\rundll32.exe" Shell32.dll,Control_RunDLL C:\Users\admin\AppData\Roaming\SkyVault\Skymage.dllC:\Windows\System32\rundll32.execontrol.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
6472"C:\Users\admin\Downloads\New Agreement Document 2025.com.exe" C:\Users\admin\Downloads\New Agreement Document 2025.com.exe
explorer.exe
User:
admin
Company:
Skillbrains
Integrity Level:
MEDIUM
Description:
Installer for LigthShoot
Exit code:
0
Version:
2025.2.10.958
Modules
Images
c:\users\admin\downloads\new agreement document 2025.com.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6508"C:\WINDOWS\SysWOW64\rundll32.exe" "C:\WINDOWS\SysWOW64\shell32.dll",#44 C:\Users\admin\AppData\Roaming\SkyVault\Skymage.dllC:\Windows\SysWOW64\rundll32.exerundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6568"C:\Users\admin\AppData\Local\Skillbrains\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\_tinreg32.exe" "C:\Users\admin\AppData\Local\Temp\Lightshot.dll" /c /rC:\Users\admin\AppData\Local\Skillbrains\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\_tinreg32.exeNew Agreement Document 2025.com.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Out-of-process DLL registration helper
Exit code:
2147944213
Version:
2024.12.29.1450U
Modules
Images
c:\users\admin\appdata\local\skillbrains\uninstall\{c662c8ed-f2fd-4729-b380-9db19d6adbe2}\_tinreg32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6612"C:\Users\admin\AppData\Local\Temp\Lightshot.exe" C:\Users\admin\AppData\Local\Temp\Lightshot.exe
explorer.exe
User:
admin
Company:
Skillbrains
Integrity Level:
MEDIUM
Description:
Lightshot
Exit code:
0
Version:
5.5.0.4
Modules
Images
c:\users\admin\appdata\local\temp\lightshot.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7072"C:\WINDOWS\system32\control.EXE" C:\Users\admin\AppData\Roaming\SkyVault\Skymage.dllC:\Windows\System32\control.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Control Panel
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\control.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7108"C:\WINDOWS\system32\rundll32.exe" Shell32.dll,Control_RunDLL C:\Users\admin\AppData\Roaming\SkyVault\Skymage.dllC:\Windows\System32\rundll32.execontrol.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
7128"C:\WINDOWS\SysWOW64\rundll32.exe" "C:\WINDOWS\SysWOW64\shell32.dll",#44 C:\Users\admin\AppData\Roaming\SkyVault\Skymage.dllC:\Windows\SysWOW64\rundll32.exe
rundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
1 330
Read events
1 326
Write events
3
Delete events
1

Modification events

(PID) Process:(6472) New Agreement Document 2025.com.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}
Operation:writeName:TizPath
Value:
C:\Users\admin\Downloads\New Agreement Document 2025.com.exe
(PID) Process:(6472) New Agreement Document 2025.com.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\States
Operation:delete valueName:Added_20250210095040
Value:
(PID) Process:(6472) New Agreement Document 2025.com.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\States
Operation:writeName:Product
Value:
4
(PID) Process:(6472) New Agreement Document 2025.com.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
105
Executable files
19
Suspicious files
3
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
6472New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Temp\CAC5D7BA\_Setup.dllexecutable
MD5:3569FA229BD51231DB327C43EF14C6D5
SHA256:E47C195AA55701A30A8196781EA5B321C8DB3CC583B6C9EE562C9DC9477EE9A1
6472New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Skillbrains\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\_tinreg64.exeexecutable
MD5:49175CE08D38ED7CCC43891A0232F9ED
SHA256:5F670EA7561637AA4885494D3A6264E549C6A62F5E6B753DC1944579123E6C57
6472New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Temp\CAC5D7BA\Setup.exeexecutable
MD5:4128E1764395387ACFB4586913EB47FD
SHA256:81F539598A6481CDF5414A4DC26EC4B05EFBE9FFCB07A84DE02673F0C9A8AA90
6472New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Skillbrains\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\Setup.icoimage
MD5:6234FD14AA6A9D4645ADA275EEEA061C
SHA256:47E5F3DC05BBD7464B1373DE6F9B8D9129A348EB2956547F58D3B627337716AA
6472New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Temp\CAC5D7BA\Setup.icoimage
MD5:6234FD14AA6A9D4645ADA275EEEA061C
SHA256:47E5F3DC05BBD7464B1373DE6F9B8D9129A348EB2956547F58D3B627337716AA
6472New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Temp\CAC5D7BA\Readme.txttext
MD5:3154E35EF76E0C11D800C1B3C8C7F20B
SHA256:F70BB349BA773E82648109CBCA5766B61FFD6ACE30F6388719F00865134F79D4
6472New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Skillbrains\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\Readme.txttext
MD5:3154E35EF76E0C11D800C1B3C8C7F20B
SHA256:F70BB349BA773E82648109CBCA5766B61FFD6ACE30F6388719F00865134F79D4
6472New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Skillbrains\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\_Setup.dllexecutable
MD5:3569FA229BD51231DB327C43EF14C6D5
SHA256:E47C195AA55701A30A8196781EA5B321C8DB3CC583B6C9EE562C9DC9477EE9A1
6472New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Skillbrains\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\Tsu.dllexecutable
MD5:DD804E04C89BB795545152159F8F5BCB
SHA256:AA7D394C0245D95B7D65B7B04CF45966F145186655A1E01BBE02B6F33B0D7E6C
6472New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Skillbrains\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\_tinreg32.exeexecutable
MD5:B7C15EF0534F0A125C277B37332B6D9C
SHA256:40D68DE277EFD69E90837C931187CEEF85CAE94C8F30430FF827AC9A2170997A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
37
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4328
svchost.exe
GET
200
2.19.11.105:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4328
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.19.11.105:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
1176
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6732
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
3696
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3696
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
3508
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
2.19.11.105:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
4328
svchost.exe
2.19.11.105:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
4712
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4328
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
5064
SearchApp.exe
2.23.227.208:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
5064
SearchApp.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
4328
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 2.19.11.105
  • 2.19.11.120
whitelisted
www.microsoft.com
  • 95.101.149.131
  • 2.23.246.101
whitelisted
google.com
  • 142.250.185.78
whitelisted
www.bing.com
  • 2.23.227.208
  • 2.23.227.215
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
login.live.com
  • 20.190.159.64
  • 20.190.159.73
  • 40.126.31.129
  • 20.190.159.2
  • 20.190.159.23
  • 40.126.31.1
  • 20.190.159.130
  • 20.190.159.0
whitelisted
go.microsoft.com
  • 2.18.97.227
whitelisted
0542j.com
  • 85.206.168.238
unknown
arc.msn.com
  • 20.223.35.26
whitelisted

Threats

No threats detected
No debug info