ANY.RUN Interactive Sandbox
- Full browser-level visibility into phishing
- Huge database of samples and IOCs
- Interactivity in a safe environment
- Actionable Tier 1 reports
Get full visibility into malware and phishing behavior in a safe environment.
| File name: | 755d8d9cd93cb0fed15ceaf755151c37157e46da6daaaee0e60ec01603e28401.exe |
| Full analysis: | https://app.any.run/tasks/a71190a2-7527-4c83-8e7c-8dd349882a06 |
| Verdict: | Malicious activity |
| Analysis date: | October 03, 2025, 16:25:37 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 6 sections |
| MD5: | D57AFCCD8378C1B035F427C58DAE691F |
| SHA1: | F1A360274E78F2ADE497E1E2ABED90C86EA7EE0A |
| SHA256: | 755D8D9CD93CB0FED15CEAF755151C37157E46DA6DAAAEE0E60EC01603E28401 |
| SSDEEP: | 24576:EsYXjV71C9uM1TrQl8SAxyHEAkpah+0CmnQYyz:EsYXjV5C9j1TrQl8SAckAkpc+0CmnQYU |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2003:11:11 14:39:16+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 10 |
| CodeSize: | 140288 |
| InitializedDataSize: | 356352 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x113b6 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 12.0.4518.1014 |
| ProductVersionNumber: | 12.0.4518.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Microsoft Corporation |
| FileDescription: | Microsoft Office Word |
| FileVersion: | 12.0.4518.1014 |
| InternalName: | WinWord |
| LegalCopyright: | © 2006 Microsoft Corporation. All rights reserved. |
| LegalTrademarks1: | Microsoft® is a registered trademark of Microsoft Corporation. |
| LegalTrademarks2: | Windows® is a registered trademark of Microsoft Corporation. |
| OriginalFileName: | WinWord.exe |
| ProductName: | 2007 Microsoft Office system |
| ProductVersion: | 12.0.4518.1014 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 520 | "C:\Users\admin\AppData\Local\Temp\86D3.tmp" | C:\Users\admin\AppData\Local\Temp\86D3.tmp | — | 8676.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 520 | "C:\Users\admin\AppData\Local\Temp\C534.tmp" | C:\Users\admin\AppData\Local\Temp\C534.tmp | — | C4C7.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 520 | "C:\Users\admin\AppData\Local\Temp\FB77.tmp" | C:\Users\admin\AppData\Local\Temp\FB77.tmp | — | FB29.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 520 | "C:\Users\admin\AppData\Local\Temp\D1A.tmp" | C:\Users\admin\AppData\Local\Temp\D1A.tmp | — | CBD.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 532 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 572 | "C:\Users\admin\AppData\Local\Temp\A42F.tmp" | C:\Users\admin\AppData\Local\Temp\A42F.tmp | — | A3C2.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 572 | "C:\Users\admin\AppData\Local\Temp\B3FE.tmp" | C:\Users\admin\AppData\Local\Temp\B3FE.tmp | — | B3B0.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 572 | "C:\Users\admin\AppData\Local\Temp\D958.tmp" | C:\Users\admin\AppData\Local\Temp\D958.tmp | — | D8EB.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 572 | "C:\Users\admin\AppData\Local\Temp\1EED.tmp" | C:\Users\admin\AppData\Local\Temp\1EED.tmp | — | 1E8F.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 572 | "C:\Users\admin\AppData\Local\Temp\32B3.tmp" | C:\Users\admin\AppData\Local\Temp\32B3.tmp | — | 3246.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2876 | 755d8d9cd93cb0fed15ceaf755151c37157e46da6daaaee0e60ec01603e28401.exe | C:\Users\admin\AppData\Local\Temp\1D8A.tmp | executable | |
MD5:436FE9F9C18A8491E82E37E120DA1042 | SHA256:0288528BBC704E4B3D0775991A75E25DA7A92A8F6533B1C4979D62B6E41A1071 | |||
| 3040 | updater.exe | C:\Program Files (x86)\Google\GoogleUpdater\updater.log | text | |
MD5:13965168E68D78AA169FDDEAD2991D1B | SHA256:F157064D36A43B1AB1C7AE62604499B50D237200B444D02C62795B4A212590BA | |||
| 6788 | 1D8A.tmp | C:\Users\admin\AppData\Local\Temp\1DE8.tmp | executable | |
MD5:1E9FE3A9E6B85569EBE4976648353D1D | SHA256:E0E9020D6A0556BE9EC2D2B632F503A54269D30A1C2BB1DA5DA5945632DADF68 | |||
| 6364 | 1EA3.tmp | C:\Users\admin\AppData\Local\Temp\1F11.tmp | executable | |
MD5:66FE15E30928798296B7274CCF0A19AE | SHA256:8682613511D410ED8F345A43DEA891C8D8006E11012CAB7BB00E74A15F167660 | |||
| 4680 | 1DE8.tmp | C:\Users\admin\AppData\Local\Temp\1E46.tmp | executable | |
MD5:F8B52962940978578A41F45FD2FE2704 | SHA256:3F0E77CD9B94129E06A9EAA9734643F561BC73D14D60F81055FEBD6437A30B1D | |||
| 2152 | 1E46.tmp | C:\Users\admin\AppData\Local\Temp\1EA3.tmp | executable | |
MD5:114F5BBD1E60D58EDD1BE9FBC146316F | SHA256:72B11E865BF41E1F0242C4F0962DF183A92FF4CA4152CC3819989A0FBE128594 | |||
| 3572 | 1F6F.tmp | C:\Users\admin\AppData\Local\Temp\1FCC.tmp | executable | |
MD5:B73D1612FE0D777F5EA42C920BA72FEA | SHA256:A377379E66D5B5191D0240949273501AC0E4C0BCF7C52AADDC69804A5AEAEDCC | |||
| 3084 | 201A.tmp | C:\Users\admin\AppData\Local\Temp\2097.tmp | executable | |
MD5:F263A2317FB6385F9E3A249BD9515AB3 | SHA256:ECCC5216FBF82D9C7C2A42A71C737BC7067F4DC01257B89E00EFFA5D93236FCB | |||
| 3404 | 1F11.tmp | C:\Users\admin\AppData\Local\Temp\1F6F.tmp | executable | |
MD5:118344D750DE505C955C5BD8601F3CFE | SHA256:4EC0E6A52901ABDB2B03F92FD922D8F9165C810D4FBC0BECCE30514B3A7B9B40 | |||
| 8012 | 1FCC.tmp | C:\Users\admin\AppData\Local\Temp\201A.tmp | executable | |
MD5:D3668394D805759311708AD233B6D869 | SHA256:A2884D8FCEB419BBECECE4B393E381721C02A066CEA862BC4A7DF02314DA075F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | POST | 500 | 4.154.185.43:443 | https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail | US | xml | 512 b | unknown |
— | — | POST | 500 | 4.154.209.85:443 | https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail | US | xml | 512 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4212 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6016 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 2.18.29.211:443 | www.bing.com | Akamai International B.V. | PL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6016 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5948 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
144 | slui.exe | 4.154.209.85:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
— | — | 4.154.209.85:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
google.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |