| File name: | 76edd4d639c8912e9c8ea58ade6e7a8a822bc527b007afd941b569c7586719d2.exe |
| Full analysis: | https://app.any.run/tasks/590b85ed-7e12-48d2-a300-34f4d0fe56d7 |
| Verdict: | Malicious activity |
| Analysis date: | November 18, 2025, 04:24:19 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | F7E81E59493277F59FC5D7F5CB5D1B6A |
| SHA1: | C6FA49D4801851C906537C3574693C3E7321C5EF |
| SHA256: | 76EDD4D639C8912E9C8EA58ADE6E7A8A822BC527B007AFD941B569C7586719D2 |
| SSDEEP: | 12288:wsYXHjErS5EWEc59eZCJDr3VgWZDeX5H2PzZ2WheDeY+rNTeJFGVVh6yzD:wsYXjV7ICJNpZDeJH2bZTeqY+rNs/yz |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2003:11:11 14:39:16+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 10 |
| CodeSize: | 140288 |
| InitializedDataSize: | 356352 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x113b6 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 12.0.4518.1014 |
| ProductVersionNumber: | 12.0.4518.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Microsoft Corporation |
| FileDescription: | Microsoft Office Word |
| FileVersion: | 12.0.4518.1014 |
| InternalName: | WinWord |
| LegalCopyright: | © 2006 Microsoft Corporation. All rights reserved. |
| LegalTrademarks1: | Microsoft® is a registered trademark of Microsoft Corporation. |
| LegalTrademarks2: | Windows® is a registered trademark of Microsoft Corporation. |
| OriginalFileName: | WinWord.exe |
| ProductName: | 2007 Microsoft Office system |
| ProductVersion: | 12.0.4518.1014 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 144 | "C:\Users\admin\AppData\Local\Temp\541B.tmp" | C:\Users\admin\AppData\Local\Temp\541B.tmp | — | 53BD.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 224 | "C:\Users\admin\Desktop\76edd4d639c8912e9c8ea58ade6e7a8a822bc527b007afd941b569c7586719d2.exe" | C:\Users\admin\Desktop\76edd4d639c8912e9c8ea58ade6e7a8a822bc527b007afd941b569c7586719d2.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 272 | "C:\Users\admin\AppData\Local\Temp\D611.tmp" | C:\Users\admin\AppData\Local\Temp\D611.tmp | — | D5B4.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 272 | "C:\Users\admin\AppData\Local\Temp\1CAF.tmp" | C:\Users\admin\AppData\Local\Temp\1CAF.tmp | — | 1C61.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 404 | "C:\Users\admin\AppData\Local\Temp\2F71.tmp" | C:\Users\admin\AppData\Local\Temp\2F71.tmp | 2EF4.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 404 | "C:\Users\admin\AppData\Local\Temp\550A.tmp" | C:\Users\admin\AppData\Local\Temp\550A.tmp | 54BC.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 404 | "C:\Users\admin\AppData\Local\Temp\5F1C.tmp" | C:\Users\admin\AppData\Local\Temp\5F1C.tmp | 5ECE.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 404 | "C:\Users\admin\AppData\Local\Temp\473A.tmp" | C:\Users\admin\AppData\Local\Temp\473A.tmp | — | 46EC.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 404 | "C:\Users\admin\AppData\Local\Temp\57E4.tmp" | C:\Users\admin\AppData\Local\Temp\57E4.tmp | — | 5796.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 408 | "C:\Users\admin\AppData\Local\Temp\59A9.tmp" | C:\Users\admin\AppData\Local\Temp\59A9.tmp | — | 595B.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 224 | 76edd4d639c8912e9c8ea58ade6e7a8a822bc527b007afd941b569c7586719d2.exe | C:\Users\admin\AppData\Local\Temp\2C54.tmp | executable | |
MD5:40F3BC3A1AE9A2D59B2033A6079E27EC | SHA256:7A4B53C032EFB2A47F6AC78AE690766E6370B6C043FE8AD6F2E2CDA38BD91377 | |||
| 5732 | 2C54.tmp | C:\Users\admin\AppData\Local\Temp\2CB2.tmp | executable | |
MD5:2F0C9E4E5B2B8BB67E78AC3FB7AAE90A | SHA256:680FD393C411E5044AF54C734B5905CF6EE52951B67A4AB7B29FAC81AACEA03B | |||
| 2388 | 2D2F.tmp | C:\Users\admin\AppData\Local\Temp\2D8D.tmp | executable | |
MD5:6196451B31F412CB8AFA4B2EEFB02450 | SHA256:BBA8851015CAF9978E658396D062CB239A08FBAED2AB5DAE0BF0710612CCB41D | |||
| 4444 | 2CB2.tmp | C:\Users\admin\AppData\Local\Temp\2D2F.tmp | executable | |
MD5:90080BB2CAB3AF585EE677868B459DEA | SHA256:59FA14DA9611BFA41DABE63228AA9E5ADE95A8D402CFF78C32DA7DAFDF14AEDF | |||
| 876 | 2E48.tmp | C:\Users\admin\AppData\Local\Temp\2EA6.tmp | executable | |
MD5:7096B73263DB9C0DF3ED2D31417762C7 | SHA256:81502837A4715B9A2F02139DB440B5714976FCEB12991C1D5EB7AA77B3AA7015 | |||
| 6400 | 308A.tmp | C:\Users\admin\AppData\Local\Temp\30E8.tmp | executable | |
MD5:A216895278FFDE96D43E7CBED1951AA4 | SHA256:04A144EA0117A6B9AC64AD3616F9656B6372999E2F0715D14CAF8D4B64463B16 | |||
| 3972 | 30E8.tmp | C:\Users\admin\AppData\Local\Temp\3146.tmp | executable | |
MD5:9D97930DD0307CC58B24726B6C6E4DE3 | SHA256:911C9365DB6F9BD1642FCF0B88ED2C1505D6C03A3FFDFD10441ECD3EA448FA6B | |||
| 2636 | 303C.tmp | C:\Users\admin\AppData\Local\Temp\308A.tmp | executable | |
MD5:7C8079C64AEC20DF726BB8A18EE67E9D | SHA256:E44E62C544113FD1FAA0A7D0B359126C5AC1E55306843B91052551A4B287DE97 | |||
| 4556 | 3146.tmp | C:\Users\admin\AppData\Local\Temp\31C3.tmp | executable | |
MD5:42A3EC78D1F178BD95A7688EC2C8611E | SHA256:1C03E0BB75B37F8A160104B7CF41762B232959AE35BAC79E361B8FAF5B68B26E | |||
| 3204 | 3230.tmp | C:\Users\admin\AppData\Local\Temp\327E.tmp | executable | |
MD5:272F0975EDC07978A80673E0F0EA9C23 | SHA256:FAC763453BB9DCC02EFB87762BC72A918BFB41336C5B62F63EA38CAF3122098F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6048 | RUXIMICS.exe | GET | 200 | 95.101.78.32:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | NL | binary | 825 b | whitelisted |
5596 | MoUsoCoreWorker.exe | GET | 200 | 95.101.78.32:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | NL | binary | 825 b | whitelisted |
— | — | POST | 503 | 4.154.185.43:443 | https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail | US | html | 190 b | unknown |
5900 | svchost.exe | GET | 200 | 95.101.78.32:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | NL | binary | 825 b | whitelisted |
— | — | POST | 500 | 4.154.185.43:443 | https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail | US | xml | 512 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
5900 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
6048 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5596 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5900 | svchost.exe | 95.101.78.32:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
5596 | MoUsoCoreWorker.exe | 95.101.78.32:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
6048 | RUXIMICS.exe | 95.101.78.32:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
5524 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1144 | slui.exe | 4.154.185.43:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Unknown Traffic | ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW) |