| File name: | autoruns.exe |
| Full analysis: | https://app.any.run/tasks/bc5547e5-3de7-4a8b-a4f4-97901181947a |
| Verdict: | Malicious activity |
| Analysis date: | July 08, 2024, 12:31:09 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 583ED542BE17B83F3C102D49FE984E26 |
| SHA1: | 142FC798C0E89B55198C3DFC5CAAB8A10D9AA150 |
| SHA256: | 64D490783ABD017AC36A017B9CB7DCFC2FCEE85F7AE8EE203A0C898DA6D37533 |
| SSDEEP: | 49152:wjLCJSLYIujU519eCvepXi/Wsqo69n1lme8CeD3p:wjLCJSLYdjkrWsqo691lmJ |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2022:02:14 20:13:32+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.29 |
| CodeSize: | 1309184 |
| InitializedDataSize: | 1189888 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xd36ae |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 14.0.9.0 |
| ProductVersionNumber: | 14.0.9.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Sysinternals - www.sysinternals.com |
| FileDescription: | Autostart program viewer |
| FileVersion: | 14.09 |
| InternalName: | Sysinternals Autoruns |
| LegalCopyright: | Copyright (C) 2002-2022 Mark Russinovich |
| OriginalFileName: | autoruns.exe |
| ProductName: | Sysinternals autoruns |
| ProductVersion: | 14.09 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 4860 | "C:\Users\admin\AppData\Local\Temp\autoruns.exe" | C:\Users\admin\AppData\Local\Temp\autoruns.exe | explorer.exe | ||||||||||||
User: admin Company: Sysinternals - www.sysinternals.com Integrity Level: MEDIUM Description: Autostart program viewer Version: 14.09 Modules
| |||||||||||||||
| (PID) Process: | (4860) autoruns.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Sysinternals\Autoruns |
| Operation: | write | Name: | EulaAccepted |
Value: 1 | |||
| (PID) Process: | (4860) autoruns.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\System32\mswsock.dll,-60100 |
Value: MSAFD Tcpip [TCP/IP] | |||
| (PID) Process: | (4860) autoruns.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\System32\mswsock.dll,-60101 |
Value: MSAFD Tcpip [UDP/IP] | |||
| (PID) Process: | (4860) autoruns.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\System32\mswsock.dll,-60102 |
Value: MSAFD Tcpip [RAW/IP] | |||
| (PID) Process: | (4860) autoruns.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\System32\mswsock.dll,-60200 |
Value: MSAFD Tcpip [TCP/IPv6] | |||
| (PID) Process: | (4860) autoruns.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\System32\mswsock.dll,-60201 |
Value: MSAFD Tcpip [UDP/IPv6] | |||
| (PID) Process: | (4860) autoruns.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\System32\mswsock.dll,-60202 |
Value: MSAFD Tcpip [RAW/IPv6] | |||
| (PID) Process: | (4860) autoruns.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\System32\wshqos.dll,-100 |
Value: RSVP TCPv6 Service Provider | |||
| (PID) Process: | (4860) autoruns.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\System32\wshqos.dll,-101 |
Value: RSVP TCP Service Provider | |||
| (PID) Process: | (4860) autoruns.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\System32\wshqos.dll,-102 |
Value: RSVP UDPv6 Service Provider | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4860 | autoruns.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\36AC0BE60E1243344AE145F746D881FE | binary | |
MD5:A20961D8BD1A5A7D241026D0011751FB | SHA256:4D6AE5BBEF0EACFDC09D5ADE4D145E883CF41B131E4C6988738769F1D32E12F3 | |||
| 4860 | autoruns.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB | binary | |
MD5:0D34D0FB9073A923FE096C1C2035AC61 | SHA256:6E2280168773037115DB79DB4CCE69C00B4365E23F762C67C5A2AF559B93547A | |||
| 4860 | autoruns.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\4C7F163ED126D5C3CB9457F68EC64E9E | binary | |
MD5:92EAB03C771E2873C170D7835E98FC93 | SHA256:B13036F0FEC353CDBF9B73F2B7C28B1AFD3331DF5D5E12A4A9EA592B3B4353C6 | |||
| 4860 | autoruns.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0B8A20E1F3F4D73D52A19929F922C892 | binary | |
MD5:AB8508CE5BB034E895357B71E5C4A30E | SHA256:817A13BE52F0436FF291390A430C65AC1946A28924B3AE3D447AB828FDB55C65 | |||
| 4860 | autoruns.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\8EC9B1D0ABBD7F98B401D425828828CE_EB45B4DDD2CA201E87E40B2FB5245AEF | binary | |
MD5:BD21511A50BF6A330E453DF82929C06E | SHA256:6E601C238F1E0E99A9BC9F7C552A94E6FE9273F2194F9E7FB07BDDC1D06BC588 | |||
| 4860 | autoruns.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\4C7F163ED126D5C3CB9457F68EC64E9E | binary | |
MD5:1AD5F25419B60337F276A68FEFFB826C | SHA256:0B2CCA39C77DB566F0009D0D5FB1F79B1167D2CC955EAD2B7F6DB2B96F5FA03A | |||
| 4860 | autoruns.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C0018BB1B5834735BFA60CD063B31956 | binary | |
MD5:A46F0E6DCC15F0055D73A0BCF66BAFFB | SHA256:7C8693D46D9298CC1BB6B25F07EF6FE82FE6CB1820B1218547BF1FFC031D34C0 | |||
| 4860 | autoruns.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141 | binary | |
MD5:148C0AE23D31B795166AC6ED31C0AD6F | SHA256:C9750FD018A5B66DC4AD13E3950BDD8D155E0F21FCC90BC8E5474D85571CFD57 | |||
| 4860 | autoruns.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\698460A0B6E60F2F602361424D832905_8BB23D43DE574E82F2BEE0DF0EC47EEB | binary | |
MD5:A94B4CAD16B1611B51960BBF1221BAFC | SHA256:246168EB3A9B9BABD78392C8B06254A28A5023C104BA3AB2A6648BB5BEC5743B | |||
| 4860 | autoruns.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\C8E534EE129F27D55460CE17FD628216_1130D9B25898B0DB0D4F04DC5B93F141 | binary | |
MD5:94A884307C1CEC1C090A17990C4C637C | SHA256:D17B7DC124CEDD72ED7EDF6949E31DFE50D3E657F90E8D7F12E7E34513D49263 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1616 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | unknown |
4860 | autoruns.exe | GET | 200 | 23.53.40.178:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl | unknown | — | — | unknown |
2808 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | unknown |
4860 | autoruns.exe | GET | 200 | 23.53.40.178:80 | http://crl.microsoft.com/pki/crl/products/MicCodSigPCA_2010-07-06.crl | unknown | — | — | unknown |
4860 | autoruns.exe | GET | 200 | 23.218.209.163:80 | http://www.microsoft.com/pkiops/crl/MicWinProPCA2011_2011-10-19.crl%20 | unknown | — | — | unknown |
4860 | autoruns.exe | GET | 200 | 23.218.209.163:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl | unknown | — | — | unknown |
4860 | autoruns.exe | GET | 200 | 23.53.40.178:80 | http://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl | unknown | — | — | unknown |
4860 | autoruns.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT3xL4LQLXDRDM9P665TW442vrsUQQUReuir%2FSSy4IxLVGLp6chnfNtyA8CEA6bGI750C3n79tQ4ghAGFo%3D | unknown | — | — | unknown |
4860 | autoruns.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfIs%2BLjDtGwQ09XEB1Yeq%2BtX%2BBgQQU7NfjgtJxXWRM3y5nP%2Be6mK4cD08CEAitQLJg0pxMn17Nqb2Trtk%3D | unknown | — | — | unknown |
4860 | autoruns.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSRXerF0eFeSWRripTgTkcJWMm7iQQUaDfg67Y7%2BF8Rhvv%2BYXsIiGX0TkICEARSlvj82CmnXclClPWkFaQ%3D | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4032 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4656 | SearchApp.exe | 104.126.37.186:443 | — | Akamai International B.V. | DE | unknown |
1828 | svchost.exe | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
1220 | RUXIMICS.exe | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
2808 | svchost.exe | 40.126.31.71:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2808 | svchost.exe | 192.229.221.95:80 | crl.verisign.com | EDGECAST | US | whitelisted |
4656 | SearchApp.exe | 104.126.37.128:443 | — | Akamai International B.V. | DE | unknown |
1060 | svchost.exe | 23.213.166.81:443 | go.microsoft.com | AKAMAI-AS | DE | unknown |
3040 | OfficeClickToRun.exe | 52.111.227.13:443 | nexusrules.officeapps.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
Domain | IP | Reputation |
|---|---|---|
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
nexusrules.officeapps.live.com |
| whitelisted |
arc.msn.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
crl.verisign.com |
| whitelisted |
ocsp.verisign.com |
| whitelisted |
csc3-2004-crl.verisign.com |
| unknown |