File name:

5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe

Full analysis: https://app.any.run/tasks/4c618300-5deb-4cac-b4eb-0f1707207655
Verdict: Malicious activity
Threats:

LockBit, a ransomware variant, encrypts data on infected machines, demanding a ransom payment for decryption. Used in targeted attacks, It's a significant risk to organizations.

Analysis date: May 15, 2025, 17:21:40
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
xor-url
lockbit
generic
ransomware
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections
MD5:

ABB148AFDB78E76007D59ED015E6BADE

SHA1:

9D469A6DB4899247188C4832FF20B7FB84516300

SHA256:

5988E75518B2F365671DC49DA18B5A70274351721F1F3A8F8F7BF32984E4024C

SSDEEP:

3072:TknnYP1Z0vx1tN/llwQBTbp8StBur8bAo5dlE4zBgAgZkZz0Luc:eZBTNZBVdc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Deletes shadow copies

      • cmd.exe (PID: 7208)
      • cmd.exe (PID: 2152)
      • cmd.exe (PID: 7620)
      • cmd.exe (PID: 2096)
      • cmd.exe (PID: 6768)
      • cmd.exe (PID: 8140)
      • cmd.exe (PID: 7928)
    • Using BCDEDIT.EXE to modify recovery options

      • cmd.exe (PID: 5728)
      • cmd.exe (PID: 1660)
      • cmd.exe (PID: 2140)
      • cmd.exe (PID: 8124)
      • cmd.exe (PID: 7928)
    • Changes the autorun value in the registry

      • 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe (PID: 7584)
    • RANSOMWARE has been detected

      • 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe (PID: 7584)
    • [YARA] LockBit is detected

      • 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe (PID: 7584)
    • XORed URL has been found (YARA)

      • 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe (PID: 7584)
  • SUSPICIOUS

    • Executes as Windows Service

      • VSSVC.exe (PID: 8036)
      • wbengine.exe (PID: 7716)
      • vds.exe (PID: 7628)
    • Reads security settings of Internet Explorer

      • ShellExperienceHost.exe (PID: 1912)
      • 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe (PID: 7584)
    • Write to the desktop.ini file (may be used to cloak folders)

      • 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe (PID: 7584)
    • Uses WMIC.EXE to obtain shadow copy information

      • cmd.exe (PID: 7700)
      • cmd.exe (PID: 3096)
    • Uses WEVTUTIL.EXE to cleanup log

      • cmd.exe (PID: 7892)
      • cmd.exe (PID: 1228)
      • cmd.exe (PID: 7296)
      • cmd.exe (PID: 1660)
      • cmd.exe (PID: 2148)
      • cmd.exe (PID: 2236)
    • Process drops legitimate windows executable

      • 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe (PID: 7584)
    • Executable content was dropped or overwritten

      • 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe (PID: 7584)
    • The process drops C-runtime libraries

      • 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe (PID: 7584)
    • Connects to unusual port

      • 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe (PID: 7584)
    • Starts CMD.EXE for commands execution

      • 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe (PID: 7584)
  • INFO

    • Reads security settings of Internet Explorer

      • dllhost.exe (PID: 7536)
      • WMIC.exe (PID: 7684)
      • WMIC.exe (PID: 8180)
      • WMIC.exe (PID: 2692)
    • Reads the machine GUID from the registry

      • 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe (PID: 7300)
    • Reads the computer name

      • 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe (PID: 7300)
      • ShellExperienceHost.exe (PID: 1912)
      • 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe (PID: 7584)
    • Checks supported languages

      • ShellExperienceHost.exe (PID: 1912)
      • 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe (PID: 7584)
      • 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe (PID: 7300)
    • Creates files in the program directory

      • 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe (PID: 7584)
    • The sample compiled with english language support

      • 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe (PID: 7584)
    • Process checks computer location settings

      • 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe (PID: 7584)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

xor-url

(PID) Process(7584) 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe
Decrypted-URLs (1)https://bridyptor.com
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:04:29 05:58:36+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 124416
InitializedDataSize: 34816
UninitializedDataSize: -
EntryPoint: 0x19840
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
205
Monitored processes
74
Malicious processes
9
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe no specs conhost.exe no specs CMSTPLUA no specs Color Management no specs #LOCKBIT 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe conhost.exe no specs cmd.exe no specs conhost.exe no specs vssadmin.exe no specs vssvc.exe no specs shellexperiencehost.exe no specs sppextcomobj.exe no specs slui.exe no specs cmd.exe no specs conhost.exe no specs vssadmin.exe no specs cmd.exe no specs conhost.exe no specs bcdedit.exe no specs cmd.exe no specs conhost.exe no specs bcdedit.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wbadmin.exe no specs wbadmin.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs cmd.exe no specs conhost.exe no specs wevtutil.exe no specs wevtutil.exe no specs cmd.exe no specs conhost.exe no specs wevtutil.exe no specs cmd.exe no specs conhost.exe no specs vssadmin.exe no specs cmd.exe no specs conhost.exe no specs bcdedit.exe no specs cmd.exe no specs conhost.exe no specs bcdedit.exe no specs cmd.exe no specs conhost.exe no specs wbadmin.exe no specs cmd.exe no specs conhost.exe no specs wbadmin.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs cmd.exe no specs conhost.exe no specs wevtutil.exe no specs cmd.exe no specs conhost.exe no specs wmic.exe no specs wevtutil.exe no specs cmd.exe no specs conhost.exe no specs wevtutil.exe no specs bcdedit.exe no specs bcdedit.exe no specs wbadmin.exe no specs wbengine.exe no specs vdsldr.exe no specs vds.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
660\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
660\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1052bcdedit /set {default} recoveryenabled NoC:\Windows\System32\bcdedit.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Boot Configuration Data Editor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\bcdedit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cryptsp.dll
1072C:\WINDOWS\System32\vdsldr.exe -EmbeddingC:\Windows\System32\vdsldr.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Virtual Disk Service Loader
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vdsldr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
1228/c wevtutil cl applicationC:\Windows\System32\cmd.exe5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
1452\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1660/c bcdedit /set {default} recoveryenabled NoC:\Windows\System32\cmd.exe5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
1660/c wevtutil cl securityC:\Windows\System32\cmd.exe5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\bcrypt.dll
1672wevtutil cl securityC:\Windows\System32\wevtutil.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Eventing Command Line Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wevtutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\combase.dll
c:\windows\system32\sechost.dll
1676wbadmin DELETE SYSTEMSTATEBACKUP -deleteOldestC:\Windows\System32\wbadmin.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Command Line Interface for Microsoft® BLB Backup
Exit code:
4294967293
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\wbadmin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ole32.dll
Total events
5 522
Read events
5 404
Write events
64
Delete events
54

Modification events

(PID) Process:(7584) 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:XO1XADpO01
Value:
"C:\Users\admin\AppData\Local\Temp\5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe"
(PID) Process:(7584) 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exeKey:HKEY_CURRENT_USER\SOFTWARE\LockBit
Operation:writeName:full
Value:
863D80A034C782307A1760342A53270398CF8DB15D7A2EDEA61D813A724D9F6ADF2762977D1050E896F146017E51D63F0BCF1A90BAA27401D3933957A800D77ACA97D8E1C5083CE545B95354092ACCC3BBEE675E2CF8F4B42FCEA6473CBB862F001926A9EF8E5224CB72F767DDAFDAD746EBC75E097B89E1DED7D92FFD732FB255876AABD3A5BA90E628C23622DC903E8FA7EE93CDFF1F4AF0B7DD6301397E92EE8E444D7103AFA68F924911623B40A54BFA04A79D5A9E186BE1CD922490A8840387102A9C0E9F798AB9564FC5FBE2BE46CBA15FAAD7D9FAF632CCB257B7651DD47F2D26154359963303A21DCB26CD52065E30055AC86B497E83E07D3E4D3C540AC81223E75E953ED8FF9217096415911E78AD95071D9FAB220013C4F10765A479429B22B501E18325E351D41E5CC24FE021ACA63B4BE33EDFF7DD14A2546AF8E0C1658C5072E26F79F1DF1EBD552AA4BC3AFD47A9F355802A05065089165A952BFBFCF527F05442E28D9685ACC24412752B48BDF1A42EC7AF0069160B61F2C674239A8953C7BD5FE404F9BCA7FCDFB035EE9D34F777A5B15A75E582316935756C342E2989A090C0481C476AB26631485681399D3878F7F31B726A765894647394CE1C4B26C21400CC35BB07DC4F051E166474686B4F3809CF5C48C3D6B1CA17CF0CB3DCD0ADCAC142980C68DF8D253EA503A6504FC964902B3E7D07DD2D047D0F82D0DF913D9F5FFC362A131A116BACDD2179A0E8923C3E172B5D811973B383B0F439EEADB45929E8DA4ECD5463733E5AA7F7ACF792BFDAAE8FF2A604CCD5EF1A48402A365F60FDACDDD381234E55E70CB9000E890C2A5845D07BE5457AD52823C9739B5F5CEF3BD2E3E6582D7E1BA5BC6B81C7F5DDB1CF399597AC5EB84C190F710FE915B6EEB66BADF76DAADDBA5D4AFE3849DFE805D1F6CB96F3F072263B82B309A8FDCD4EBBB9CEF428A5E71BE176B7D136FC4369351E60345632EB58BBB3B9F9D93C6375FC2A7D23A0AF3B05B1CEE1C6F012CC3972DCF98996C06D3226161B24A14536C2BAE0AC1C1576B9136230AC1B1862A597120DE531E29C31CE343BFF29CED04055D967EB853C14911013C5C4073AC2920E20C83C513A5CD9F08F50F5F6C698BB64D84F3633A2E115988F6F240B92514D8CA9A379506466CCBA53E49DB99DD69229B92CAC7FA652933E456B59A8F11AB5E58A780ABF8755BFCB8324CA2B9F1B53D8F277FB5EFD5586C17D144F67A6A21FC171104CB2C81A57B7DEF19609230FDADAB45D08FFFA48373A78188BACB907978B0AC48190F4B11F42D1268606BCF12214374A43825093C22632E082DE3EB2278E2E1234CCA6745A8449CDAC4C9E6890F0DD9D893813BFBE96F1086E1C9E526B9EE3848E5BB47A6B4D65FBBC69FF69E6740D114A45EB41C7E3371F9180132EC6987C91D926B369E9874987F773BEB58357FE0C9F9179FF56C1A3E2A02F00BF74DBA38B7AB04A9C786E8AF9AE62F881F29B29EB773AC54E7805186BED473F09C2673B8932B4486B1FDF84B3B607F581E3E0B8A1840E4D1825EF754F412E9904A15B18AC40F5BD859A90E020361F2A61945DCEBFE132A7CFE76CDD7E164EE8C91DCB9EB2BB0A5A6323D9794A25824D6234E6288A194672DA58736AB45C0C8548F9EF88804B6DBF5624B32CCFAE195B17848E5DCED174DFEAEF4AD9B208A800DF777B2523A44F2F77AE21EF663F5B68A36FA5A63B6DAB71B64AA5B0EFAFE75BAA2A92611A953C694CE7EF185913EC619BF265D54F55075E103666305D1C86B83F878BD5ADCB72FD186196CE
(PID) Process:(7584) 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exeKey:HKEY_CURRENT_USER\SOFTWARE\LockBit
Operation:writeName:Public
Value:
94D1D2A382C47D8067DFB003D300D44EAE1132D1338E083E9701348D4651002C02ACAB5B04266C3FE3A453ECCD741A0D1276694F0FE10D82BF54FE6D19D82132217A0223DA1DCFB43887ED658C5094D7BA6160B6418B749D90774260E128E6BC695DE84AFA9CF408614B61E8AF1A9FE9B01D27C3D0C7A5640CD1B8DBA63C34EDE4AD887A5004A60DF09D23CDE8FE5F242109EA769D888D7EE1B7036796B654E02CF4C31B9F53B7B958B0564E22B9D1341EE25A6A93CE94AA4D5D08A687C11B27848B7E22CEB3E77BA665DD534A63D1BB074DF6D34AAD7219BA50D1617D861BF47A1B1CF67EB31AE8BE5D4D924ADD3B7B3AF43ED63D1BD77E4D4E5CBD8F5A918F010001
(PID) Process:(7584) 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume\{2f5c5e73-85a9-11eb-90a8-9a9b76358421}
Operation:writeName:MaxCapacity
Value:
83
(PID) Process:(7584) 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume\{eaf65672-68c3-4f99-8d5c-104b5f4d8fff}
Operation:writeName:MaxCapacity
Value:
51
(PID) Process:(7584) 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume\{2f5c5e71-85a9-11eb-90a8-9a9b76358421}
Operation:writeName:MaxCapacity
Value:
49
(PID) Process:(7584) 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume\{2f5c5e73-85a9-11eb-90a8-9a9b76358421}
Operation:writeName:NukeOnDelete
Value:
0
(PID) Process:(7584) 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume\{eaf65672-68c3-4f99-8d5c-104b5f4d8fff}
Operation:writeName:NukeOnDelete
Value:
0
(PID) Process:(7584) 5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume\{2f5c5e71-85a9-11eb-90a8-9a9b76358421}
Operation:writeName:NukeOnDelete
Value:
0
(PID) Process:(7456) dllhost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows NT\CurrentVersion\ICM\Calibration
Operation:writeName:DisplayCalibrator
Value:
C:\Users\admin\AppData\Local\Temp\5988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe
Executable files
40
Suspicious files
1 152
Text files
956
Unknown types
0

Dropped files

PID
Process
Filename
Type
75845988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe\\?\Volume{eaf65672-68c3-4f99-8d5c-104b5f4d8fff}\$WINRE_BACKUP_PARTITION.MARKER.lockbit
MD5:
SHA256:
75845988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe\\?\Volume{2f5c5e71-85a9-11eb-90a8-9a9b76358421}\NvVars.lockbitbinary
MD5:1B6D8F02332E50665E5F3EBEC68915BF
SHA256:EC144DD3FD496037D3BA6EBE798246B974FA1E228EE2DA4A175CC9CD75C18565
75845988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exeC:\found.000\dir0000.chk\UpdateSessionOrchestration.048.etl.lockbitbinary
MD5:B14B352B6D8E53F330F4004256907629
SHA256:1261DDC68472BC4B4634AB432D4406C47D47065C53BBBE6EBC3B2DA13B9BC475
75845988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exeC:\found.000\dir0000.chk\UpdateSessionOrchestration.016.etl.lockbitbinary
MD5:A3BC67DC29FC491624143846C7F2B212
SHA256:ADD1BF1B78F3B8B0F259864E6CE16412AA91BFB57A0F8C6821DD61461952D6C1
75845988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exeC:\$WinREAgent\Backup\location.txt.lockbittext
MD5:F09B8CA2E0F41BA2270F6EF5062BB1A8
SHA256:E4C22462C0619D55326E12995176E7A5D14C16E1F6791F0F8C7E55034AAB1D35
75845988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exeC:\$WinREAgent\Rollback.xml.lockbittext
MD5:DD7327DF2C5DFA8E5FCD520169E98059
SHA256:68B961E182957866BD6BBFB92AAF163FFD7D9AF40765CE0D390E5EF9F8C0E794
75845988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exeC:\found.000\dir0000.chk\UpdateSessionOrchestration.058.etl.lockbitbinary
MD5:389F45A91E7FFC038CCCDB460AAD253D
SHA256:7C38AD8787A332AB2026A1C7516B5502842F8946E1D706ACCB9523BF6210F639
75845988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe\\?\Volume{2f5c5e73-85a9-11eb-90a8-9a9b76358421}\$RECYCLE.BIN\S-1-5-21-1693682860-607145093-2874071422-1001\desktop.iniini
MD5:AD0B0B4416F06AF436328A3C12DC491B
SHA256:23521DE51CA1DB2BC7B18E41DE7693542235284667BF85F6C31902547A947416
75845988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exe\\?\Volume{2f5c5e71-85a9-11eb-90a8-9a9b76358421}\$RECYCLE.BIN\desktop.iniini
MD5:AD0B0B4416F06AF436328A3C12DC491B
SHA256:23521DE51CA1DB2BC7B18E41DE7693542235284667BF85F6C31902547A947416
75845988e75518b2f365671dc49da18b5a70274351721f1f3a8f8f7bf32984e4024c.exeC:\found.000\file00000005.chk.lockbit
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
38
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
8448
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
8448
SIHClient.exe
GET
200
23.219.150.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
2.16.168.124:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
2.16.168.124:80
crl.microsoft.com
Akamai International B.V.
RU
whitelisted
23.219.150.101:80
www.microsoft.com
AKAMAI-AS
CL
whitelisted
2104
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.32.133:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2112
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
crl.microsoft.com
  • 2.16.168.124
  • 2.16.168.114
whitelisted
www.microsoft.com
  • 23.219.150.101
whitelisted
google.com
  • 216.58.206.46
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 40.126.32.133
  • 20.190.160.131
  • 20.190.160.128
  • 40.126.32.68
  • 20.190.160.2
  • 20.190.160.5
  • 20.190.160.132
  • 20.190.160.3
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted

Threats

No threats detected
No debug info