| File name: | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_ |
| Full analysis: | https://app.any.run/tasks/7eabbc1c-f61a-4a82-8ef4-0a5b222048de |
| Verdict: | Malicious activity |
| Analysis date: | April 29, 2025, 02:37:20 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | 13343D20D39EC792BBFF9CD51A7D12D5 |
| SHA1: | 0D32C9E1855436943C60A96C5847223D03D79A87 |
| SHA256: | 76EFDA6C81B51A09CA94C5AA645CF08D2BF876CC0EAD4855BA57582BB32BCB2D |
| SSDEEP: | 24576:oC+OmQHJldaOmLvQOpau+Dm21dfAkbGyThhh+niqtZHxOX2Z1u:oC+OmoJHaOmLvQOpau+D91RAkqyVhh+W |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2013:11:21 16:55:51+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 36864 |
| InitializedDataSize: | 19968 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x795a |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.701.3.3014 |
| ProductVersionNumber: | 1.701.3.3014 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Adobe Systems Incorporated |
| FileDescription: | Adobe Acrobat Update Service |
| FileVersion: | 1.701.3.3014 |
| InternalName: | armsvc.exe |
| LegalCopyright: | Copyright © 2013 Adobe Systems Incorporated. All rights reserved. |
| OriginalFileName: | armsvc.exe |
| ProductName: | Adobe Acrobat Update Service |
| ProductVersion: | 1.701.3.3014 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2196 | C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s Dnscache | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6436 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | — | SppExtComObj.Exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6620 | "C:\Users\admin\AppData\Local\Temp\76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe" | C:\Users\admin\AppData\Local\Temp\76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | explorer.exe | ||||||||||||
User: admin Company: Adobe Systems Incorporated Integrity Level: MEDIUM Description: Adobe Acrobat Update Service Version: 1.701.3.3014 Modules
| |||||||||||||||
| 6964 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | C:\Program Files\Common Files\microsoft shared\ClickToRun\OfficeC2RClient.exe | executable | |
MD5:691966582F7C3A00ABCBCE6BE80F0B9C | SHA256:D59FB5EB1B2130D09EC52383971265286AF2EED62E8DE4190D88CD5078BAAF59 | |||
| 6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | C:\Users\admin\AppData\Roaming\26b799fa89ba8c8f.bin | binary | |
MD5:863CE899AFE1D24CDE86934F278D25BC | SHA256:5B1A8EFC81CEE440079D0459CD49EB2EC61F243974CF49F55327C2DD8EF6059F | |||
| 6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | C:\Program Files\Common Files\microsoft shared\ClickToRun\appvcleaner.exe | executable | |
MD5:22F6B640C504D2ADB3C936A0546D725E | SHA256:D2627A1CD58657B4BBBC5347A62F78D3A73A09A5E31C6D13AD3CA2C0F731B63B | |||
| 6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | C:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exe | executable | |
MD5:B9418875DC22DF7F87775A18DDAE4994 | SHA256:3DAFBDE72B99B4E178FC206DE9AB4B4EFCD63E0B8C98BB0133E1F056B7503588 | |||
| 6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | C:\Program Files\Common Files\microsoft shared\ClickToRun\IntegratedOffice.exe | executable | |
MD5:5E5F48057CBEAD7E92837538BE626D29 | SHA256:495C1EA7EB6310C7E728D061AD0E10F7D95ECD8668370B36EC8DDF4300CB60B5 | |||
| 6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | C:\Program Files\Common Files\microsoft shared\ClickToRun\officesvcmgr.exe | executable | |
MD5:80D9CA1D44D6EB774585FDA8AC56D1FB | SHA256:32100F6C647E4A5BBC64318B4302DCD47931177C30FE259F782B208AC1B6F353 | |||
| 6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | C:\ProgramData\Adobe\ARM\S\388\AdobeARMHelper.exe | executable | |
MD5:BF622DE62F9B2C48FE3FE830379AB2F0 | SHA256:42DE952AB496F5AC7279CD73D9E29B5FE002B8478D2D0E651F3434C9B513DF7C | |||
| 6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | C:\Program Files\Common Files\microsoft shared\ClickToRun\MavInject32.exe | executable | |
MD5:1A382D028F4EB1029A8F73CE2DFC5CE1 | SHA256:ACEDC0522BE26BBF09D34A43EC7E8CE64AB562364E85D07F801F859672D0E398 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 23.216.77.28:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | DE | binary | 825 b | whitelisted |
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | DE | binary | 868 b | whitelisted |
6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | POST | 200 | 52.11.240.239:80 | http://pywolwnvd.biz/vemhk | US | — | — | malicious |
6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | POST | 200 | 18.234.103.197:80 | http://ssbzmoy.biz/bntgfd | US | — | — | malicious |
6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | POST | 200 | 52.11.240.239:80 | http://cvgrf.biz/xove | US | — | — | malicious |
6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | POST | 200 | 3.229.117.57:80 | http://npukfztj.biz/selge | US | — | — | malicious |
6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | POST | 200 | 172.233.219.123:80 | http://przvgke.biz/imby | US | binary | 4.16 Kb | unknown |
6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | POST | 200 | 172.233.219.123:80 | http://przvgke.biz/lstssm | US | binary | 4.17 Kb | unknown |
6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | POST | 200 | 18.234.103.197:80 | http://knjghuig.biz/phrgdqqcu | US | — | — | malicious |
6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | GET | 432 | 91.195.240.19:80 | http://www.anpmnmxo.biz/dax | DE | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 23.216.77.28:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
2104 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | 52.11.240.239:80 | pywolwnvd.biz | AMAZON-02 | US | malicious |
6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | 18.234.103.197:80 | ssbzmoy.biz | AMAZON-AES | US | malicious |
6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | 3.229.117.57:80 | npukfztj.biz | AMAZON-AES | US | malicious |
6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | 172.233.219.123:80 | przvgke.biz | Akamai International B.V. | US | unknown |
Domain | IP | Reputation |
|---|---|---|
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
pywolwnvd.biz |
| malicious |
ssbzmoy.biz |
| malicious |
cvgrf.biz |
| malicious |
npukfztj.biz |
| malicious |
przvgke.biz |
| unknown |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | A Network Trojan was detected | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value Snkz |
6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | A Network Trojan was detected | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst |
6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | A Network Trojan was detected | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value Snkz |
6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | A Network Trojan was detected | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst |
6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | A Network Trojan was detected | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value Snkz |
6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | A Network Trojan was detected | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value btst |
2196 | svchost.exe | A Network Trojan was detected | ET MALWARE DNS Query to Expiro Related Domain (knjghuig .biz) |
6620 | 76efda6c81b51a09ca94c5aa645cf08d2bf876cc0ead4855ba57582bb32bcb2d.ex_.exe | Misc activity | ET INFO Namecheap URL Forward |