File name:

New Agreement Document 2025.com

Full analysis: https://app.any.run/tasks/332a3d20-5b1f-4169-ac38-50e32f48f90c
Verdict: Malicious activity
Analysis date: February 12, 2025, 15:52:22
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
tsuloader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 7 sections
MD5:

569CD75E5907FD52FCAB645BCA570946

SHA1:

CBA256EA7B1FE276E73EC45C120A5326FAE4659E

SHA256:

5692D52FB5161FAF27BF7375F72A4AF274571EA4F86E542B5A094EBA5A8529E1

SSDEEP:

98304:pB0tvnOUylgPVQcegXB42OriAV9B3gIgQBWyOeWw+5hInLsiHF4Lqi4/XbTa4ES/:Uel/t3F

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • New Agreement Document 2025.com.exe (PID: 2956)
      • Lightshot.exe (PID: 6148)
    • Process drops legitimate windows executable

      • New Agreement Document 2025.com.exe (PID: 2956)
    • Creates a software uninstall entry

      • New Agreement Document 2025.com.exe (PID: 2956)
    • The process executes via Task Scheduler

      • control.exe (PID: 6096)
    • Connects to unusual port

      • rundll32.exe (PID: 5992)
    • Uses RUNDLL32.EXE to load library

      • control.exe (PID: 6096)
  • INFO

    • Reads Microsoft Office registry keys

      • New Agreement Document 2025.com.exe (PID: 2956)
    • Create files in a temporary directory

      • New Agreement Document 2025.com.exe (PID: 2956)
    • Creates files or folders in the user directory

      • New Agreement Document 2025.com.exe (PID: 2956)
      • Lightshot.exe (PID: 6148)
    • Checks supported languages

      • New Agreement Document 2025.com.exe (PID: 2956)
      • _tinreg32.exe (PID: 2940)
      • Lightshot.exe (PID: 6148)
    • Reads Environment values

      • New Agreement Document 2025.com.exe (PID: 2956)
    • Manual execution by a user

      • Lightshot.exe (PID: 6148)
    • Reads the computer name

      • New Agreement Document 2025.com.exe (PID: 2956)
      • Lightshot.exe (PID: 6148)
    • Reads the machine GUID from the registry

      • Lightshot.exe (PID: 6148)
    • TSULoader has been detected

      • New Agreement Document 2025.com.exe (PID: 2956)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:12:29 14:51:45+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 8192
InitializedDataSize: 2030592
UninitializedDataSize: -
EntryPoint: 0x15ad
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2025.2.10.958
ProductVersionNumber: 5.5.0.4
FileFlagsMask: 0x003f
FileFlags: Special build
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
ProductName: LigthShoot
ProductVersion: 5.5.0.4
CompanyName: Skillbrains
LegalCopyright: Copyright (c) 2025 Skillbrains
Email: -
WebSite: -
FileDescription: Installer for LigthShoot
FileVersion: 2025.2.10.958
OriginalFileName: LigthShoot-Setup.exe
InternalName: TSULoader
Comments: WinNT (x86) Unicode Lib Rel
ProductCode: {C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}
PackageCode: {A3F73EF0-AB26-44E7-74F8-0505ED09F546}
Arguments: -
SpecialBuild: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
134
Monitored processes
6
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start new agreement document 2025.com.exe _tinreg32.exe no specs lightshot.exe control.exe no specs rundll32.exe no specs rundll32.exe

Process information

PID
CMD
Path
Indicators
Parent process
1544"C:\WINDOWS\system32\rundll32.exe" Shell32.dll,Control_RunDLL C:\Users\admin\AppData\Roaming\SkyVault\Skymage.dllC:\Windows\System32\rundll32.execontrol.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
2940"C:\Users\admin\AppData\Local\Skillbrains\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\_tinreg32.exe" "C:\Users\admin\AppData\Local\Temp\Lightshot.dll" /c /rC:\Users\admin\AppData\Local\Skillbrains\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\_tinreg32.exeNew Agreement Document 2025.com.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Out-of-process DLL registration helper
Exit code:
2147944213
Version:
2024.12.29.1450U
Modules
Images
c:\users\admin\appdata\local\skillbrains\uninstall\{c662c8ed-f2fd-4729-b380-9db19d6adbe2}\_tinreg32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2956"C:\Users\admin\AppData\Local\Temp\New Agreement Document 2025.com.exe" C:\Users\admin\AppData\Local\Temp\New Agreement Document 2025.com.exe
explorer.exe
User:
admin
Company:
Skillbrains
Integrity Level:
MEDIUM
Description:
Installer for LigthShoot
Exit code:
0
Version:
2025.2.10.958
Modules
Images
c:\users\admin\appdata\local\temp\new agreement document 2025.com.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5992"C:\WINDOWS\SysWOW64\rundll32.exe" "C:\WINDOWS\SysWOW64\shell32.dll",#44 C:\Users\admin\AppData\Roaming\SkyVault\Skymage.dllC:\Windows\SysWOW64\rundll32.exe
rundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
6096"C:\WINDOWS\system32\control.EXE" C:\Users\admin\AppData\Roaming\SkyVault\Skymage.dllC:\Windows\System32\control.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Control Panel
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\control.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6148"C:\Users\admin\AppData\Local\Temp\Lightshot.exe" C:\Users\admin\AppData\Local\Temp\Lightshot.exe
explorer.exe
User:
admin
Company:
Skillbrains
Integrity Level:
MEDIUM
Description:
Lightshot
Exit code:
0
Version:
5.5.0.4
Modules
Images
c:\users\admin\appdata\local\temp\lightshot.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
992
Read events
988
Write events
3
Delete events
1

Modification events

(PID) Process:(2956) New Agreement Document 2025.com.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}
Operation:writeName:TizPath
Value:
C:\Users\admin\AppData\Local\Temp\New Agreement Document 2025.com.exe
(PID) Process:(2956) New Agreement Document 2025.com.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\States
Operation:delete valueName:Added_20250210095040
Value:
(PID) Process:(2956) New Agreement Document 2025.com.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\States
Operation:writeName:Product
Value:
4
(PID) Process:(2956) New Agreement Document 2025.com.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
105
Executable files
19
Suspicious files
3
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
2956New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Temp\BE93EA94\Setup.exeexecutable
MD5:4128E1764395387ACFB4586913EB47FD
SHA256:81F539598A6481CDF5414A4DC26EC4B05EFBE9FFCB07A84DE02673F0C9A8AA90
2956New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Skillbrains\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\Setup.icoimage
MD5:6234FD14AA6A9D4645ADA275EEEA061C
SHA256:47E5F3DC05BBD7464B1373DE6F9B8D9129A348EB2956547F58D3B627337716AA
2956New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Skillbrains\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\_Setup.dllexecutable
MD5:3569FA229BD51231DB327C43EF14C6D5
SHA256:E47C195AA55701A30A8196781EA5B321C8DB3CC583B6C9EE562C9DC9477EE9A1
2956New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Temp\BE93EA94\_Setup.dllexecutable
MD5:3569FA229BD51231DB327C43EF14C6D5
SHA256:E47C195AA55701A30A8196781EA5B321C8DB3CC583B6C9EE562C9DC9477EE9A1
2956New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Temp\BE93EA94.datbinary
MD5:442494A43FDE46CF784860193FD8FBEF
SHA256:2F41B5A2B458AD788B3A16F749D848DD398C7FD9B8E9D55E51130E8AD41420F1
2956New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Skillbrains\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\_tinreg64.exeexecutable
MD5:49175CE08D38ED7CCC43891A0232F9ED
SHA256:5F670EA7561637AA4885494D3A6264E549C6A62F5E6B753DC1944579123E6C57
2956New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Temp\TsuE30C92C7.dllexecutable
MD5:DD804E04C89BB795545152159F8F5BCB
SHA256:AA7D394C0245D95B7D65B7B04CF45966F145186655A1E01BBE02B6F33B0D7E6C
2956New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Skillbrains\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\Readme.txttext
MD5:3154E35EF76E0C11D800C1B3C8C7F20B
SHA256:F70BB349BA773E82648109CBCA5766B61FFD6ACE30F6388719F00865134F79D4
2956New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Skillbrains\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\Setup.exeexecutable
MD5:4128E1764395387ACFB4586913EB47FD
SHA256:81F539598A6481CDF5414A4DC26EC4B05EFBE9FFCB07A84DE02673F0C9A8AA90
2956New Agreement Document 2025.com.exeC:\Users\admin\AppData\Local\Skillbrains\Uninstall\{C662C8ED-F2FD-4729-B380-9DB19D6ADBE2}\_tinreg32.exeexecutable
MD5:B7C15EF0534F0A125C277B37332B6D9C
SHA256:40D68DE277EFD69E90837C931187CEEF85CAE94C8F30430FF827AC9A2170997A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
43
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
104.124.11.58:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
7032
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7032
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1176
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6612
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3296
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4712
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
104.124.11.58:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
2.19.96.18:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:137
whitelisted
5064
SearchApp.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
3296
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 104.124.11.58
  • 104.124.11.17
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
google.com
  • 142.250.181.238
whitelisted
www.bing.com
  • 2.19.96.18
  • 2.19.96.50
  • 2.19.96.130
  • 2.19.96.66
  • 2.19.96.26
  • 2.19.96.19
  • 2.19.96.40
  • 2.19.96.64
  • 2.19.96.27
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
login.live.com
  • 40.126.32.72
  • 40.126.32.133
  • 40.126.32.138
  • 20.190.160.67
  • 40.126.32.68
  • 20.190.160.22
  • 40.126.32.74
  • 40.126.32.136
whitelisted
go.microsoft.com
  • 2.19.106.8
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted

Threats

No threats detected
No debug info