| File name: | VirusShare_56b0292360ee44e5cebebff1c896ee10.exe |
| Full analysis: | https://app.any.run/tasks/dac0d2db-c641-4f9b-a7b4-64f721f1678c |
| Verdict: | Malicious activity |
| Analysis date: | August 01, 2025, 06:10:35 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections |
| MD5: | 56B0292360EE44E5CEBEBFF1C896EE10 |
| SHA1: | 6D4CDB7CBFA152BE7B0FC5D2B97AD9632C7E43F1 |
| SHA256: | 74A9E5D7617D8BF28D203C2FCEC3DDD2C9FD2EBD26AF9AC656277BE0F754D811 |
| SSDEEP: | 6144:0KS/LvKQKyLybNkSlHdtf190wg5pihGB2wu6YMf47n5vP4rkNO4/krFFFFFFFFFt:4/L8yLyaSh9hwPYH7i4 |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:06:24 23:01:05+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 10 |
| CodeSize: | 211968 |
| InitializedDataSize: | 3389440 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x17e10 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 17.0.0.0 |
| ProductVersionNumber: | 44.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Special build |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1352 | svchost.exe | C:\Windows\SysWOW64\svchost.exe | — | wlmsfqkj.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Host Process for Windows Services Exit code: 3221225501 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1392 | "C:\Users\admin\AppData\Local\Temp\VirusShare_56b0292360ee44e5cebebff1c896ee10.exe" | C:\Users\admin\AppData\Local\Temp\VirusShare_56b0292360ee44e5cebebff1c896ee10.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221225477 Modules
| |||||||||||||||
| 2076 | C:\WINDOWS\SysWOW64\WerFault.exe -u -p 1392 -s 672 | C:\Windows\SysWOW64\WerFault.exe | — | VirusShare_56b0292360ee44e5cebebff1c896ee10.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2220 | "C:\Windows\System32\wusa.exe" | C:\Windows\SysWOW64\wusa.exe | — | VirusShare_56b0292360ee44e5cebebff1c896ee10.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Update Standalone Installer Exit code: 3221226540 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3628 | "C:\Users\admin\wlmsfqkj.exe" /d"C:\Users\admin\AppData\Local\Temp\VirusShare_56b0292360ee44e5cebebff1c896ee10.exe" /e600702100000007F | C:\Users\admin\wlmsfqkj.exe | VirusShare_56b0292360ee44e5cebebff1c896ee10.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221225477 Modules
| |||||||||||||||
| 3640 | C:\WINDOWS\SysWOW64\WerFault.exe -u -p 3628 -s 560 | C:\Windows\SysWOW64\WerFault.exe | — | wlmsfqkj.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4120 | "C:\WINDOWS\SysWOW64\wusa.exe" | C:\Windows\SysWOW64\wusa.exe | VirusShare_56b0292360ee44e5cebebff1c896ee10.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Update Standalone Installer Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (1392) VirusShare_56b0292360ee44e5cebebff1c896ee10.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | haebdxue |
Value: "C:\Users\admin\wlmsfqkj.exe" | |||
| (PID) Process: | (1352) svchost.exe | Key: | HKEY_CURRENT_USER\Control Panel\Buses |
| Operation: | write | Name: | Config0 |
Value: 008D223DE1F7923C24EDB47D450DD49D084297DCE82E72BAA4C2EB8AA8DAF81D638079A4D1CC945D24EDB47D470DD49D024195DAF71261ADC06D04FDA6E22673BBC9154961CDA56B16DA83447C3FE0A8644490BDBC7823EB975E03C4FD8D3C74BBC4103D37FBA76911D58449710DB8F2054991CFDB2470DD936D5185A7E82469BBC41A5B6BCD9E2B419F8944722DB0FC1048C9F7E52334EC974D06CDF5B5742CD69744053EFEA65747D0D74D743DE4AD5549D4DCB97D24E8915A07CE81AD227CD9EB4405358BA26811D881487138E1A5260D81D8E27024ED915802C8F5BC5E4285D5490D34FDA46D14DD85741B6FACA0541DC48DB47D24EDAD325785F9BD6428D5E8317C42C4CB395CD0844D713C91D8261AFDE2F72429ED945802CFF6CB6C14BBC91D0034FDA16C61A8F64A4D52B6ED591DC488B50B24ED9C646B8EB4B0642DD19C3179418E9E2F4199894D7438E1A5551CC4B4F47C29ED945802CDF6BB6014949F490D34FDA46D14DD8474343EE9AD541DC48DB47D24D4D45909CDF4B8655BD49E443776A8E06014DD81480539E1DB6D5DC580B47D21E89D2C02BFCDFD6620D49D41083D8CA21F2D9D8740743FECDE5D1DC48D8D3D20E0945F04CFF4BF642FEEDF114939FAA11911ABF73E7D04A4AC591DC685C77424ED946444CFF9BA6159D1EB377F34C4E46E19DD844D743DE4AD25248489B97A2399E15A77C88187247183DE4E3704 | |||
| (PID) Process: | (1352) svchost.exe | Key: | HKEY_CURRENT_USER\Control Panel\Buses |
| Operation: | delete value | Name: | Config1 |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1352 | svchost.exe | C:\Users\admin:.repos | binary | |
MD5:01B6F65AC745AB836374063190C4C84B | SHA256:785B56F28054B090E88D83E8A7C035A1A8A3726F2A8B79E51152B9B3D5AAE815 | |||
| 1392 | VirusShare_56b0292360ee44e5cebebff1c896ee10.exe | C:\Users\admin\wlmsfqkj.exe | executable | |
MD5:0AA2D9CF3675B4FE850B72D75552266E | SHA256:0D829C196C66ADF6FC862DAE1052A2AF719E47DBC4FB29E8FA4F508C09D58ADF | |||
| 1392 | VirusShare_56b0292360ee44e5cebebff1c896ee10.exe | C:\Users\admin\AppData\Local\Temp\jlfuqmiz.exe | executable | |
MD5:917F28F2439FC63D73A78FDA07DFF87D | SHA256:54B2729D7FCD3E5F4D05E01330ED501127A9B7C8D4E2F733BCB1A5F6B2DD42EC | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2528 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 23.216.77.28:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1268 | svchost.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1268 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5944 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3876 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2528 | svchost.exe | 40.126.31.128:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2528 | svchost.exe | 184.30.131.245:80 | ocsp.digicert.com | AKAMAI-AS | US | whitelisted |
1268 | svchost.exe | 23.216.77.28:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
1268 | svchost.exe | 95.101.149.131:80 | www.microsoft.com | Akamai International B.V. | NL | whitelisted |
5944 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |