File name:

5d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502

Full analysis: https://app.any.run/tasks/3a5e7681-23e5-4f93-b2a6-388fa0bb4b2a
Verdict: Malicious activity
Analysis date: January 10, 2025, 17:55:35
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

8D46BAF183C4F911EA9BF65C8797D8EA

SHA1:

1C65169105317DD39497D511F4C7CC1592FBFB69

SHA256:

5D24A5CB60554C37DD1850F057E8EA8EA021CAE00CB7FEBED5CA6D9768F27502

SSDEEP:

24576:f5pg7y6x6byHGx5/LK6N/NFa4X79QwWaEgAvFQgnqGiYzkrx83I7Ad:f5pg7ym6byHGx5/L3N/NFa4X79QwWaEX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • 5d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502.exe (PID: 4516)
    • Uses Task Scheduler to run other applications

      • 5d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502.exe (PID: 4516)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 5d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502.exe (PID: 4516)
    • Reads security settings of Internet Explorer

      • 5d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502.exe (PID: 4516)
  • INFO

    • Reads the computer name

      • 5d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502.exe (PID: 4516)
    • Creates files or folders in the user directory

      • 5d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502.exe (PID: 4516)
    • Checks supported languages

      • 5d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502.exe (PID: 4516)
    • Reads the machine GUID from the registry

      • 5d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502.exe (PID: 4516)
    • Process checks computer location settings

      • 5d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502.exe (PID: 4516)
    • The process uses the downloaded file

      • 5d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502.exe (PID: 4516)
    • Create files in a temporary directory

      • 5d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502.exe (PID: 4516)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

AssemblyVersion: 2.0.0.781
ProductVersion: 2.0.0.781
ProductName: Adobe Reader
OriginalFileName: OavGB.exe
LegalTrademarks: PDF document
LegalCopyright: Adobe Inc. All rights reserved
InternalName: OavGB.exe
FileVersion: 2.0.0.781
FileDescription: Microsoft PDF Document
CompanyName: Adobe Reader
Comments: PDF document
CharacterSet: Unicode
LanguageCode: Neutral
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 2.0.0.781
FileVersionNumber: 2.0.0.781
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0xebb06
UninitializedDataSize: -
InitializedDataSize: 2560
CodeSize: 957440
LinkerVersion: 48
PEType: PE32
ImageFileCharacteristics: Executable, 32-bit
TimeStamp: 2044:04:30 21:02:13+00:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
133
Monitored processes
7
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 5d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502.exe schtasks.exe no specs conhost.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs regsvcs.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
4516"C:\Users\admin\AppData\Local\Temp\5d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502.exe" C:\Users\admin\AppData\Local\Temp\5d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502.exe
explorer.exe
User:
admin
Company:
Adobe Reader
Integrity Level:
MEDIUM
Description:
Microsoft PDF Document
Exit code:
0
Version:
2.0.0.781
Modules
Images
c:\users\admin\appdata\local\temp\5d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
5300"C:\Windows\System32\schtasks.exe" /Create /TN "Updates\uEugNEto" /XML "C:\Users\admin\AppData\Local\Temp\tmpB931.tmp"C:\Windows\SysWOW64\schtasks.exe5d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Scheduler Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1356\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4384"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe5d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Services Installation Utility
Exit code:
4294967295
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regsvcs.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
5488"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe5d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Services Installation Utility
Exit code:
4294967295
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regsvcs.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1868"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe5d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Services Installation Utility
Exit code:
4294967295
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regsvcs.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4320"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe5d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Services Installation Utility
Exit code:
0
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regsvcs.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
492
Read events
492
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
45165d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502.exeC:\Users\admin\AppData\Local\Temp\tmpB931.tmpxml
MD5:A1C5DC93A23BC4F818F8C26E529497B0
SHA256:50C9FE565BAB53BD81AE7EB4178E83CEE39213D325C47D183B00E67237400209
45165d24a5cb60554c37dd1850f057e8ea8ea021cae00cb7febed5ca6d9768f27502.exeC:\Users\admin\AppData\Roaming\uEugNEto.exeexecutable
MD5:8D46BAF183C4F911EA9BF65C8797D8EA
SHA256:5D24A5CB60554C37DD1850F057E8EA8EA021CAE00CB7FEBED5CA6D9768F27502
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
33
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4400
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5244
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
GET
200
2.16.241.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4400
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4712
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2092
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.241.12:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
4
System
192.168.100.255:138
whitelisted
5064
SearchApp.exe
2.23.227.215:443
Ooredoo Q.S.C.
QA
unknown
2092
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5064
SearchApp.exe
2.23.227.208:443
Ooredoo Q.S.C.
QA
unknown
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 20.73.194.208
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.174
whitelisted
crl.microsoft.com
  • 2.16.241.12
  • 2.16.241.19
whitelisted
www.microsoft.com
  • 2.23.246.101
  • 95.101.149.131
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.136
  • 40.126.32.140
  • 40.126.32.74
  • 20.190.160.17
  • 40.126.32.72
  • 20.190.160.22
  • 20.190.160.14
  • 40.126.32.76
whitelisted
go.microsoft.com
  • 2.23.242.9
whitelisted
slscr.update.microsoft.com
  • 20.109.210.53
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted

Threats

No threats detected
No debug info