| File name: | 6bc5c8f3a7f6e773fee3808113b8816eccdab0efa40efdba573e94c6a91d0059.exe |
| Full analysis: | https://app.any.run/tasks/13c92ebc-523a-4e87-8830-11e7aa35a31a |
| Verdict: | Malicious activity |
| Analysis date: | August 17, 2024, 16:03:23 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows |
| MD5: | 0AFD0C95C4799AC82596A8AAC76DE9EE |
| SHA1: | 18D821B109779B12FA4116E59B1113EBE387D2B9 |
| SHA256: | 6BC5C8F3A7F6E773FEE3808113B8816ECCDAB0EFA40EFDBA573E94C6A91D0059 |
| SSDEEP: | 49152:/yL4t3nxi+W8gLy+UBhe26CXLl4p2La9fNLWhLtPXDXTt1SaT1A0:O4t3xhpGy+U/T66o2La9f9ELtPTXTSa5 |
| .exe | | | Win64 Executable (generic) (87.3) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (6.3) |
| .exe | | | DOS Executable Generic (6.3) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2024:08:15 12:32:39+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 10 |
| CodeSize: | 5120 |
| InitializedDataSize: | 1735680 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1d90 |
| OSVersion: | 5.2 |
| ImageVersion: | - |
| SubsystemVersion: | 5.2 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1316 | C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s Schedule | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6452 | "C:\Users\admin\Desktop\6bc5c8f3a7f6e773fee3808113b8816eccdab0efa40efdba573e94c6a91d0059.exe" | C:\Users\admin\Desktop\6bc5c8f3a7f6e773fee3808113b8816eccdab0efa40efdba573e94c6a91d0059.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 6484 | C:\windows\system32\winver.exe | C:\Windows\System32\winver.exe | — | 6bc5c8f3a7f6e773fee3808113b8816eccdab0efa40efdba573e94c6a91d0059.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Version Reporter Applet Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6532 | C:\windows\system32\taskmgr.exe | C:\Windows\System32\Taskmgr.exe | 6bc5c8f3a7f6e773fee3808113b8816eccdab0efa40efdba573e94c6a91d0059.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Task Manager Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6540 | C:\Users\admin\Desktop\6bc5c8f3a7f6e773fee3808113b8816eccdab0efa40efdba573e94c6a91d0059.exe | C:\Users\admin\Desktop\6bc5c8f3a7f6e773fee3808113b8816eccdab0efa40efdba573e94c6a91d0059.exe | Taskmgr.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 6568 | cmd /c move C:\WINDOWS\temp\941062 "C:\Program Files\StarRail.exe" | C:\Windows\System32\cmd.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6588 | cmd /c move C:\WINDOWS\temp\941187 "C:\Program Files\StarRailBase.dll" | C:\Windows\System32\cmd.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6608 | cmd /c move C:\WINDOWS\temp\941296 "C:\Program Files\StarRailBase.dat" | C:\Windows\System32\cmd.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6628 | "C:\Program Files\StarRail.exe" | C:\Program Files\StarRail.exe | — | services.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
| 6652 | C:\WINDOWS\system32\svchost.exe -Install | C:\Windows\System32\svchost.exe | StarRail.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6652) svchost.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\3c\52C64B7E |
| Operation: | write | Name: | @%SystemRoot%\system32\shell32.dll,-50176 |
Value: File Operation | |||
| (PID) Process: | (1316) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WinDefScan |
| Operation: | write | Name: | SD |
Value: 01000480B4000000C400000000000000140000000200A00007000000001018009F011F0001020000000000052000000020020000001014009F011F00010100000000000512000000001014008900120001010000000000050B0000000010140089001200010100000000000513000000001014008900120001010000000000051400000000101800FF011F000102000000000005200000002002000000001400890012000101000000000005120000000000000001020000000000052000000020020000010100000000000512000000 | |||
| (PID) Process: | (1316) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WinDefScan |
| Operation: | write | Name: | Id |
Value: {E6B0DB24-547A-4502-B99B-BF0F870F0B87} | |||
| (PID) Process: | (1316) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WinDefScan |
| Operation: | write | Name: | Index |
Value: 1 | |||
| (PID) Process: | (1316) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E6B0DB24-547A-4502-B99B-BF0F870F0B87} |
| Operation: | write | Name: | Path |
Value: \Microsoft\Windows\WinDefScan | |||
| (PID) Process: | (1316) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E6B0DB24-547A-4502-B99B-BF0F870F0B87} |
| Operation: | write | Name: | Hash |
Value: 5BDCA39ACA14D8A0DDAB5A0E01882A68CEB956F12F0EBB400D9A1525523B83E2 | |||
| (PID) Process: | (1316) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E6B0DB24-547A-4502-B99B-BF0F870F0B87} |
| Operation: | write | Name: | Schema |
Value: 65538 | |||
| (PID) Process: | (1316) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E6B0DB24-547A-4502-B99B-BF0F870F0B87} |
| Operation: | delete value | Name: | Version |
Value: | |||
| (PID) Process: | (1316) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E6B0DB24-547A-4502-B99B-BF0F870F0B87} |
| Operation: | delete value | Name: | Date |
Value: | |||
| (PID) Process: | (1316) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{E6B0DB24-547A-4502-B99B-BF0F870F0B87} |
| Operation: | delete value | Name: | SecurityDescriptor |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6540 | 6bc5c8f3a7f6e773fee3808113b8816eccdab0efa40efdba573e94c6a91d0059.exe | C:\Windows\Temp\941187 | executable | |
MD5:7A8543A2FAA9E9A70661A4AC195B7B88 | SHA256:32987958B0F77DBE9BB70BFD1B7C81EC407991AF111B455EF4CE255FE96B6C19 | |||
| 6540 | 6bc5c8f3a7f6e773fee3808113b8816eccdab0efa40efdba573e94c6a91d0059.exe | C:\Windows\Temp\941062 | executable | |
MD5:09CBEBE3306F81DBB1498E2C214B897D | SHA256:2AA3366883B707C1FEA777156417F4BE0B5C90F209FDA1AFAC1C8544ACAB702C | |||
| 6540 | 6bc5c8f3a7f6e773fee3808113b8816eccdab0efa40efdba573e94c6a91d0059.exe | C:\Windows\Temp\941296 | binary | |
MD5:F452FD4A33F300AB7FF2B66205BAFE5D | SHA256:036A89250A9560291D37FAF5926CBB6FF5C490506EB8584AE0C4A01EEC1CE266 | |||
| 6588 | cmd.exe | C:\Program Files\StarRailBase.dll | executable | |
MD5:7A8543A2FAA9E9A70661A4AC195B7B88 | SHA256:32987958B0F77DBE9BB70BFD1B7C81EC407991AF111B455EF4CE255FE96B6C19 | |||
| 6608 | cmd.exe | C:\Program Files\StarRailBase.dat | binary | |
MD5:F452FD4A33F300AB7FF2B66205BAFE5D | SHA256:036A89250A9560291D37FAF5926CBB6FF5C490506EB8584AE0C4A01EEC1CE266 | |||
| 6568 | cmd.exe | C:\Program Files\StarRail.exe | executable | |
MD5:09CBEBE3306F81DBB1498E2C214B897D | SHA256:2AA3366883B707C1FEA777156417F4BE0B5C90F209FDA1AFAC1C8544ACAB702C | |||
| 6652 | svchost.exe | C:\Windows\System32\WinDefScan\StarRail.exe | executable | |
MD5:09CBEBE3306F81DBB1498E2C214B897D | SHA256:2AA3366883B707C1FEA777156417F4BE0B5C90F209FDA1AFAC1C8544ACAB702C | |||
| 1316 | svchost.exe | C:\Windows\System32\Tasks\Microsoft\Windows\WindowsUpdate\RUXIM\PLUGScheduler | xml | |
MD5:1E0FD17505DF7FDD52708C59FCD5284C | SHA256:B374CE865F05A467798DE01B77F9AEEA861325CF274390D4C06753E77CDA564D | |||
| 1316 | svchost.exe | C:\Windows\System32\Tasks\Microsoft\Windows\WinDefScan | xml | |
MD5:134A405EB0F41F39A9236991035F0AD5 | SHA256:EE01D8B23B09DF37C9E713F4D24541539F095D8B72F6DB8CB19F70B562B98D8F | |||
| 1316 | svchost.exe | C:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Maintenance Work | xml | |
MD5:4838EE953DAB2C7A1BF57E0C6620A79D | SHA256:22C798E00C4793749EAC39CFB6EA3DD75112FD4453A3706E839038A64504D45D | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6748 | svchost.exe | GET | — | 83.229.127.205:80 | http://83.229.127.205/ | unknown | — | — | unknown |
6748 | svchost.exe | GET | — | 83.229.127.205:80 | http://83.229.127.205/ | unknown | — | — | unknown |
6748 | svchost.exe | GET | — | 83.229.127.205:80 | http://83.229.127.205/ | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
5116 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
1060 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
2120 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
— | — | 192.168.100.255:138 | — | — | — | whitelisted |
6748 | svchost.exe | 83.229.127.205:6639 | — | — | NG | unknown |
4324 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
5116 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6748 | svchost.exe | 83.229.127.205:80 | — | — | NG | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6748 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Websocket Upgrade Request |
6748 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Websocket Upgrade Request |
6748 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Websocket Upgrade Request |