File name:

730ad7ce76d15620901671432a9b35adbdc446fce516bce19c45b1e2f7f128c5.exe

Full analysis: https://app.any.run/tasks/87c0dd27-9b26-491d-b628-8a05323a7c64
Verdict: Malicious activity
Analysis date: June 06, 2024, 16:49:07
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

14A7967FD60059DFF5DC502D9CFF0BC4

SHA1:

45E1F4C94C594D41893134367EB90F5CC143BDB5

SHA256:

730AD7CE76D15620901671432A9B35ADBDC446FCE516BCE19C45B1E2F7F128C5

SSDEEP:

24576:2v0B/OZMqcItJUm5tPKKRNstmB3fGOUk1R40LjTz+c/xkIe2SDLa:2v4WZMqcItJUm5tPKKRNstmB3OOU2R48

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • 730ad7ce76d15620901671432a9b35adbdc446fce516bce19c45b1e2f7f128c5.exe (PID: 3700)
  • SUSPICIOUS

    • Executes application which crashes

      • 730ad7ce76d15620901671432a9b35adbdc446fce516bce19c45b1e2f7f128c5.exe (PID: 3700)
    • The process executes via Task Scheduler

      • default-browser-agent.exe (PID: 1492)
  • INFO

    • Checks supported languages

      • 730ad7ce76d15620901671432a9b35adbdc446fce516bce19c45b1e2f7f128c5.exe (PID: 3700)
      • default-browser-agent.exe (PID: 1492)
    • Checks proxy server information

      • WerFault.exe (PID: 5896)
    • Reads the computer name

      • 730ad7ce76d15620901671432a9b35adbdc446fce516bce19c45b1e2f7f128c5.exe (PID: 3700)
    • Reads the machine GUID from the registry

      • 730ad7ce76d15620901671432a9b35adbdc446fce516bce19c45b1e2f7f128c5.exe (PID: 3700)
    • Reads the software policy settings

      • WerFault.exe (PID: 5896)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 5896)
    • Application launched itself

      • firefox.exe (PID: 5836)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (56.7)
.exe | Win64 Executable (generic) (21.3)
.scr | Windows screen saver (10.1)
.dll | Win32 Dynamic Link Library (generic) (5)
.exe | Win32 Executable (generic) (3.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:06:06 14:15:37+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 762880
InitializedDataSize: 6656
UninitializedDataSize: -
EntryPoint: 0xbc1fe
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 12.2.2.2
ProductVersionNumber: 12.2.2.2
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Scheduling clerk
CompanyName: Scorpio
FileDescription: Scheduling clerk
FileVersion: 12.02.2.2
InternalName: Wqys.exe
LegalCopyright: Copyright © Scorpio 2015
LegalTrademarks: -
OriginalFileName: Wqys.exe
ProductName: Scheduling clerk
ProductVersion: 12.02.2.2
AssemblyVersion: 12.2.2.0
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
130
Monitored processes
5
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start 730ad7ce76d15620901671432a9b35adbdc446fce516bce19c45b1e2f7f128c5.exe werfault.exe default-browser-agent.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1492"C:\Program Files\Mozilla Firefox\default-browser-agent.exe" do-task "308046B0AF4A39CB"C:\Program Files\Mozilla Firefox\default-browser-agent.exesvchost.exe
User:
admin
Company:
Mozilla Foundation
Integrity Level:
MEDIUM
Exit code:
2147500037
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\default-browser-agent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ole32.dll
3700"C:\Users\admin\AppData\Local\Temp\730ad7ce76d15620901671432a9b35adbdc446fce516bce19c45b1e2f7f128c5.exe" C:\Users\admin\AppData\Local\Temp\730ad7ce76d15620901671432a9b35adbdc446fce516bce19c45b1e2f7f128c5.exe
explorer.exe
User:
admin
Company:
Scorpio
Integrity Level:
MEDIUM
Description:
Scheduling clerk
Exit code:
3762504530
Version:
12.02.2.2
Modules
Images
c:\users\admin\appdata\local\temp\730ad7ce76d15620901671432a9b35adbdc446fce516bce19c45b1e2f7f128c5.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
4628"C:\Program Files\Mozilla Firefox\firefox.exe" --backgroundtask defaultagent do-task 308046B0AF4A39CBC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
3
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
5836"C:\Program Files\Mozilla Firefox\firefox.exe" --backgroundtask defaultagent do-task 308046B0AF4A39CBC:\Program Files\Mozilla Firefox\firefox.exedefault-browser-agent.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
3
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
5896C:\WINDOWS\SysWOW64\WerFault.exe -u -p 3700 -s 1104C:\Windows\SysWOW64\WerFault.exe
730ad7ce76d15620901671432a9b35adbdc446fce516bce19c45b1e2f7f128c5.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
Total events
4 866
Read events
4 859
Write events
7
Delete events
0

Modification events

(PID) Process:(5836) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
53D7D5F800000000
(PID) Process:(4628) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
BF9CD6F800000000
(PID) Process:(4628) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Progress
Value:
0
(PID) Process:(4628) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Progress
Value:
1
(PID) Process:(4628) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(4628) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Theme
Value:
1
(PID) Process:(4628) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
Executable files
0
Suspicious files
9
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
5896WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_KTVKZEVW0GDOLVDP_99881bcbbf9634f99b24973c13ae85ee3918e75_09d86764_faba4de5-63e3-4ebc-8112-46e6d5acc90f\Report.wer
MD5:
SHA256:
5896WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\730ad7ce76d15620901671432a9b35adbdc446fce516bce19c45b1e2f7f128c5.exe.3700.dmp
MD5:
SHA256:
5896WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER43DD.tmp.WERInternalMetadata.xmlxml
MD5:0020D6D5C3452305C8253C094820A3D4
SHA256:DA3A3DFB6AFD57569DEA0DC5CCF978097EC7CF1AA5CB4B31008B7D85E3AA7BE5
5896WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER441C.tmp.xmlxml
MD5:FA2BF180D4FCBB5C64AC0C2F1C73C577
SHA256:CC7F8755474A2BC24D5B0BD3BD2FAC31FF61B6B931A0F08A95B9706E27B2F965
5896WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\21253908F3CB05D51B1C2DA8B681A785der
MD5:979F91388D4DF2F2D68497400C9830DD
SHA256:A9F27E26AA818BC97449D30D5707254EDCA571D21D36B4576C7CD9A56FB18BC5
5896WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\21253908F3CB05D51B1C2DA8B681A785binary
MD5:D4320B0BE84D0E33385967888B29CA45
SHA256:F00E44849801A381C48D8D13F5FFFD32D1786877052AD23DA3D3E55BB5D31863
5896WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FEbinary
MD5:093130490C8391C8CF5EB90670098014
SHA256:2E9BD83117469FDEEDC6826DD911AD05DEA4C4FC5BCC605EAC0E50DE67B4BA9A
5896WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER41F8.tmp.dmpdmp
MD5:BB55766154F5A07F774B27B86CA77FB6
SHA256:68D784449C616045B135A023E85930308C883AB8516CFE3B4137EDA0CB117AA7
5896WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\37C951188967C8EB88D99893D9D191FEder
MD5:CBA2426F2AAFE31899569ACE05E89796
SHA256:A465FEBE8A024E3CDB548A3731B2EA60C7B2919E941A24B9A42890B2B039B85A
4628firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Background Tasks Profiles\93u99co2.MozillaBackgroundTask-308046B0AF4A39CB-defaultagent\datareporting\glean\db\data.safe.tmpdbf
MD5:B1C8AA9861B461806C9E738511EDD6AE
SHA256:7CEA48E7ADD3340B36F47BA4EA2DED8D6CB0423FFC2A64B44D7E86E0507D6B70
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
56
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5896
WerFault.exe
GET
200
23.217.131.226:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
4680
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D
unknown
unknown
4012
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
5004
svchost.exe
GET
200
23.217.131.226:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
5004
svchost.exe
GET
200
2.17.147.64:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
4920
SIHClient.exe
GET
200
23.217.131.226:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
unknown
3500
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
unknown
unknown
4920
SIHClient.exe
GET
200
23.217.131.226:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
unknown
5896
WerFault.exe
GET
200
2.17.147.64:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4364
svchost.exe
239.255.255.250:1900
unknown
4
System
192.168.100.255:138
unknown
5004
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
636
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5140
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5004
svchost.exe
2.17.147.64:80
crl.microsoft.com
Akamai International B.V.
CZ
unknown
5004
svchost.exe
23.217.131.226:80
www.microsoft.com
Joint Stock Company TransTeleCom
RU
unknown
5896
WerFault.exe
20.42.73.29:443
watson.events.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
5896
WerFault.exe
2.17.147.64:80
crl.microsoft.com
Akamai International B.V.
CZ
unknown
5896
WerFault.exe
23.217.131.226:80
www.microsoft.com
Joint Stock Company TransTeleCom
RU
unknown

DNS requests

Domain
IP
Reputation
watson.events.data.microsoft.com
  • 20.42.73.29
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 2.17.147.64
  • 2.17.147.99
whitelisted
www.microsoft.com
  • 23.217.131.226
whitelisted
www.bing.com
  • 95.100.146.40
  • 95.100.146.18
  • 95.100.146.19
  • 95.100.146.16
  • 95.100.146.25
  • 95.100.146.32
  • 95.100.146.17
  • 95.100.146.27
  • 95.100.146.35
whitelisted
r.bing.com
  • 95.100.146.16
  • 95.100.146.18
  • 95.100.146.32
  • 95.100.146.17
  • 95.100.146.19
  • 95.100.146.25
  • 95.100.146.27
  • 95.100.146.40
  • 95.100.146.35
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.160.17
  • 20.190.160.14
  • 40.126.32.68
  • 40.126.32.133
  • 40.126.32.74
  • 20.190.160.20
  • 40.126.32.134
  • 40.126.32.72
whitelisted
go.microsoft.com
  • 184.30.154.152
whitelisted
slscr.update.microsoft.com
  • 52.165.165.26
whitelisted

Threats

No threats detected
No debug info