File name:

sirhurt.exe

Full analysis: https://app.any.run/tasks/c7f048d0-5371-4e9e-adce-52838ad7208f
Verdict: Malicious activity
Analysis date: February 13, 2025, 12:02:29
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
themida
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64, for MS Windows, 14 sections
MD5:

AD435666851AA3AF1B51AD5B38445D9D

SHA1:

4609F4B0FD77B9987D0EFADEE0FE76481199777A

SHA256:

6A611A7FF03E87D32FE9A06B3316C37BAF0AC7E322C604E10F1BED7DCCBC692F

SSDEEP:

98304:kqUlmjkcQr2k6S05P2fgucuXt4ajzpw+yQy1ZvWBW/JmMZlwWt0/Ngwud/Li63GE:/4IYLNY/UET

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the BIOS version

      • sirhurt.exe (PID: 6668)
    • Executable content was dropped or overwritten

      • sirhurt.exe (PID: 6668)
  • INFO

    • Process checks whether UAC notifications are on

      • sirhurt.exe (PID: 6668)
    • Reads the machine GUID from the registry

      • sirhurt.exe (PID: 6668)
    • The sample compiled with english language support

      • sirhurt.exe (PID: 6668)
    • Themida protector has been detected

      • sirhurt.exe (PID: 6668)
    • Reads the computer name

      • sirhurt.exe (PID: 6668)
    • Checks supported languages

      • sirhurt.exe (PID: 6668)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:02:08 08:40:12+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.29
CodeSize: 1135616
InitializedDataSize: 401920
UninitializedDataSize: -
EntryPoint: 0x825058
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
121
Monitored processes
3
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start sirhurt.exe conhost.exe no specs sirhurt.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6504"C:\Users\admin\Desktop\sirhurt.exe" C:\Users\admin\Desktop\sirhurt.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\sirhurt.exe
c:\windows\system32\ntdll.dll
6668"C:\Users\admin\Desktop\sirhurt.exe" C:\Users\admin\Desktop\sirhurt.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\sirhurt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6680\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesirhurt.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
368
Read events
368
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
6668sirhurt.exeC:\Users\admin\Desktop\zip.dllexecutable
MD5:D18F84C69C2931986B3284AC0E0BEE00
SHA256:A7EC733AF1BA0172ED54F9A714C5DC4E6901CC1FD7DC8D3B17D195FACA69C22F
6668sirhurt.exeC:\Users\admin\Desktop\zlib.dllexecutable
MD5:3E92F13E42188AE8C51861DF292B53AD
SHA256:4CE30751722EC8078DF18EAB0DDBA2A7EC6D7404BC86586D7996C2B254870186
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
19
DNS requests
11
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2736
svchost.exe
GET
200
2.22.242.90:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2736
svchost.exe
GET
200
23.219.240.231:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
23.219.240.231:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.22.242.90:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
172.67.149.166:443
https://www.sirhurt.net/asshurt/update/v5/validatechecksum.php?ver=2
unknown
binary
364 b
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
2.19.96.91:443
www.bing.com
Akamai International B.V.
DE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2736
svchost.exe
2.22.242.90:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
4712
MoUsoCoreWorker.exe
2.22.242.90:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2736
svchost.exe
23.219.240.231:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
4712
MoUsoCoreWorker.exe
23.219.240.231:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
  • 51.124.78.146
whitelisted
www.bing.com
  • 2.19.96.91
  • 2.19.96.81
  • 2.19.96.98
  • 2.19.96.89
  • 2.19.96.90
  • 2.19.96.83
  • 2.19.96.96
  • 2.19.96.99
  • 2.19.96.82
whitelisted
google.com
  • 142.250.186.174
whitelisted
crl.microsoft.com
  • 2.22.242.90
  • 2.22.242.121
whitelisted
www.microsoft.com
  • 23.219.240.231
whitelisted
www.sirhurt.net
  • 104.21.95.242
  • 172.67.149.166
unknown
self.events.data.microsoft.com
  • 13.89.178.26
whitelisted

Threats

No threats detected
No debug info