File name:

vc_redist.x64.exe

Full analysis: https://app.any.run/tasks/4eaa7bb2-b05b-4736-93e8-1bef790398c7
Verdict: Malicious activity
Analysis date: December 17, 2024, 08:46:29
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 7 sections
MD5:

27B141AACC2777A82BB3FA9F6E5E5C1C

SHA1:

3155CB0F146B927FCC30647C1A904CD162548C8C

SHA256:

5EEA714E1F22F1875C1CB7B1738B0C0B1F02AEC5ECB95F0FDB1C5171C6CD93A3

SSDEEP:

393216:xTPq5dCsKSR65cX7Eyd/qnejOX3L8T8KYfU3jq:VP5iw56oyleejcL8T8fc3e

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • WindowsInstaller-KB893803-v2-x86.exe (PID: 5712)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 5008)
      • update.exe (PID: 2828)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 1828)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 1944)
      • update.exe (PID: 1224)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • vc_redist.x64.exe (PID: 244)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 5008)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 1944)
    • Starts a Microsoft application from unusual location

      • vc_redist.x64.exe (PID: 244)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 5712)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 5008)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 1828)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 1944)
    • Executable content was dropped or overwritten

      • vc_redist.x64.exe (PID: 244)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 1944)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 5008)
    • The process creates files with name similar to system file names

      • WindowsInstaller-KB893803-v2-x86.exe (PID: 5008)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 1944)
    • Searches for installed software

      • vc_redist.x64.exe (PID: 244)
  • INFO

    • Checks supported languages

      • vc_redist.x64.exe (PID: 244)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 5008)
      • update.exe (PID: 2828)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 1944)
      • update.exe (PID: 1224)
    • Reads the computer name

      • vc_redist.x64.exe (PID: 244)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 5008)
      • update.exe (PID: 2828)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 1944)
    • Manual execution by a user

      • WindowsInstaller-KB893803-v2-x86.exe (PID: 5712)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 5008)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 1828)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 1944)
    • Create files in a temporary directory

      • vc_redist.x64.exe (PID: 244)
    • Reads the machine GUID from the registry

      • WindowsInstaller-KB893803-v2-x86.exe (PID: 5008)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 1944)
    • The sample compiled with english language support

      • WindowsInstaller-KB893803-v2-x86.exe (PID: 5008)
      • vc_redist.x64.exe (PID: 244)
      • WindowsInstaller-KB893803-v2-x86.exe (PID: 1944)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2015:02:13 19:42:32+00:00
ImageFileCharacteristics: Executable, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 10
CodeSize: 234496
InitializedDataSize: 144896
UninitializedDataSize: -
EntryPoint: 0x28494
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 14.0.23026.0
ProductVersionNumber: 14.0.23026.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Microsoft Corporation
FileDescription: Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026
FileVersion: 14.0.23026.0
InternalName: setup
LegalCopyright: Copyright (c) Microsoft Corporation. All rights reserved.
OriginalFileName: VC_redist.x64.exe
ProductName: Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026
ProductVersion: 14.0.23026.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
131
Monitored processes
7
Malicious processes
2
Suspicious processes
5

Behavior graph

Click at the process to see the details
start vc_redist.x64.exe windowsinstaller-kb893803-v2-x86.exe no specs windowsinstaller-kb893803-v2-x86.exe update.exe no specs windowsinstaller-kb893803-v2-x86.exe no specs windowsinstaller-kb893803-v2-x86.exe update.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
244"C:\Users\admin\AppData\Local\Temp\vc_redist.x64.exe" C:\Users\admin\AppData\Local\Temp\vc_redist.x64.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Visual C++ 2015 Redistributable (x64) - 14.0.23026
Exit code:
1638
Version:
14.0.23026.0
Modules
Images
c:\users\admin\appdata\local\temp\vc_redist.x64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1224c:\0720c279a113e82248006a3f48d3673e\UPDATE\update.exeC:\0720c279a113e82248006a3f48d3673e\update\update.exeWindowsInstaller-KB893803-v2-x86.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Service Pack Setup
Exit code:
1603
Version:
6.1.0022.4 (SRV03_QFE.031113-0918)
Modules
Images
c:\0720c279a113e82248006a3f48d3673e\update\update.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
1828"C:\Users\admin\Desktop\WindowsInstaller-KB893803-v2-x86.exe" C:\Users\admin\Desktop\WindowsInstaller-KB893803-v2-x86.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Update Package
Exit code:
3221226540
Version:
3.1
Modules
Images
c:\users\admin\desktop\windowsinstaller-kb893803-v2-x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1944"C:\Users\admin\Desktop\WindowsInstaller-KB893803-v2-x86.exe" C:\Users\admin\Desktop\WindowsInstaller-KB893803-v2-x86.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Update Package
Exit code:
1603
Version:
3.1
Modules
Images
c:\users\admin\desktop\windowsinstaller-kb893803-v2-x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
2828c:\3c37b312452c7de92ad7a695ef\UPDATE\update.exeC:\3c37b312452c7de92ad7a695ef\update\update.exeWindowsInstaller-KB893803-v2-x86.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Service Pack Setup
Exit code:
1603
Version:
6.1.0022.4 (SRV03_QFE.031113-0918)
Modules
Images
c:\3c37b312452c7de92ad7a695ef\update\update.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
5008"C:\Users\admin\Desktop\WindowsInstaller-KB893803-v2-x86.exe" C:\Users\admin\Desktop\WindowsInstaller-KB893803-v2-x86.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Update Package
Exit code:
1603
Version:
3.1
Modules
Images
c:\users\admin\desktop\windowsinstaller-kb893803-v2-x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
5712"C:\Users\admin\Desktop\WindowsInstaller-KB893803-v2-x86.exe" C:\Users\admin\Desktop\WindowsInstaller-KB893803-v2-x86.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Update Package
Exit code:
3221226540
Version:
3.1
Modules
Images
c:\users\admin\desktop\windowsinstaller-kb893803-v2-x86.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
204
Read events
204
Write events
0
Delete events
0

Modification events

No data
Executable files
21
Suspicious files
8
Text files
45
Unknown types
2

Dropped files

PID
Process
Filename
Type
244vc_redist.x64.exeC:\Users\admin\AppData\Local\Temp\{e46eca4f-393b-40df-9f49-076faf788d83}\.ba1\wixstdba.dllexecutable
MD5:4D20A950A3571D11236482754B4A8E76
SHA256:A9295AD4E909F979E2B6CB2B2495C3D35C8517E689CD64A918C690E17B49078B
244vc_redist.x64.exeC:\Users\admin\AppData\Local\Temp\{e46eca4f-393b-40df-9f49-076faf788d83}\.ba1\1036\license.rtftext
MD5:6F70759DF32F212DBB65464258ECEEAF
SHA256:C7F03DA5D9A7F689B8DCBD507FF0B3FA98DABA55616F902E5E47E9839B753E1F
244vc_redist.x64.exeC:\Users\admin\AppData\Local\Temp\{e46eca4f-393b-40df-9f49-076faf788d83}\.ba1\1028\license.rtftext
MD5:EFA0E0316DBE1D01B04DB8AE55216E89
SHA256:D5147EE2BA7826D5B68E0DC10FC2AC95079F89C38264C5648D924DEC9290D085
244vc_redist.x64.exeC:\Users\admin\AppData\Local\Temp\{e46eca4f-393b-40df-9f49-076faf788d83}\.ba1\1045\license.rtftext
MD5:A0D88589A339E57E412AB01E763D6A27
SHA256:898D5CA01A3271D97350D06A6CCDB8803A176BB42BAF7E2C8F76C9037235CA8E
244vc_redist.x64.exeC:\Users\admin\AppData\Local\Temp\{e46eca4f-393b-40df-9f49-076faf788d83}\.ba1\1042\license.rtftext
MD5:F6E7A2A05EFB4413295C156A179578A3
SHA256:DCEFD9B37D78F37ED8AAEF70AC2BFCDE441DCFB97469A6AA6AF89C1FFADBF814
244vc_redist.x64.exeC:\Users\admin\AppData\Local\Temp\{e46eca4f-393b-40df-9f49-076faf788d83}\.ba1\1055\license.rtftext
MD5:362F60F539B629BF59021003F426583C
SHA256:1E602773F3071636E0F9C6B27037B7B4094DC26F7C2FABCDF3287BC9BCAA8652
244vc_redist.x64.exeC:\Users\admin\AppData\Local\Temp\{e46eca4f-393b-40df-9f49-076faf788d83}\.ba1\2052\license.rtftext
MD5:31AFEC54446E496CE2A1D1CD3B257738
SHA256:63F463F0ACE41FA088ACFB70F501DB47E3B83600DB31538D8DABA010E6B83D42
244vc_redist.x64.exeC:\Users\admin\AppData\Local\Temp\{e46eca4f-393b-40df-9f49-076faf788d83}\.ba1\1040\license.rtftext
MD5:1D07E27F97CE22A58780A04227BE6465
SHA256:F1214784C57AA3323426AF64D132045970717994EBA500B25283684DC1ADEBAA
244vc_redist.x64.exeC:\Users\admin\AppData\Local\Temp\{e46eca4f-393b-40df-9f49-076faf788d83}\.ba1\1046\license.rtftext
MD5:137A9579BA2E02EBB87817440FCBDCB9
SHA256:42DC678EF9D5E4E147BF178FFE2FA3CD4BBBF9C904872B4E344D8BB22C473ED5
244vc_redist.x64.exeC:\Users\admin\AppData\Local\Temp\{e46eca4f-393b-40df-9f49-076faf788d83}\.ba1\thm.wxlxml
MD5:FBFCBC4DACC566A3C426F43CE10907B6
SHA256:70400F181D00E1769774FF36BCD8B1AB5FBC431418067D31B876D18CC04EF4CE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
33
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
23.53.40.178:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5064
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
4980
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4980
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1596
svchost.exe
GET
200
23.53.40.178:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
3884
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
4712
MoUsoCoreWorker.exe
23.53.40.178:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1596
svchost.exe
23.53.40.178:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
1596
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5064
SearchApp.exe
104.126.37.176:443
www.bing.com
Akamai International B.V.
DE
whitelisted
1176
svchost.exe
20.190.159.64:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5064
SearchApp.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 23.53.40.178
  • 23.53.40.176
whitelisted
google.com
  • 142.250.186.174
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
www.bing.com
  • 104.126.37.176
  • 104.126.37.177
  • 104.126.37.162
  • 104.126.37.163
  • 104.126.37.155
  • 104.126.37.171
  • 104.126.37.186
  • 104.126.37.170
  • 104.126.37.161
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.64
  • 20.190.159.75
  • 20.190.159.0
  • 40.126.31.69
  • 20.190.159.23
  • 20.190.159.2
  • 40.126.31.67
  • 40.126.31.71
whitelisted
go.microsoft.com
  • 23.213.166.81
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

No threats detected
No debug info