File name:

Piesixem.one

Full analysis: https://app.any.run/tasks/2fe751d5-dc06-4287-b42f-52c05a9aa9c1
Verdict: Malicious activity
Analysis date: September 14, 2024, 14:22:50
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/octet-stream
File info: data
MD5:

E4780CCA4C2AB22C55C01D36B620C955

SHA1:

68606CFCE4BC962AFBE22606C7BA6C4C87430983

SHA256:

78632BBB0A21ACB272A6238C54434B3DF1E89BF95104A2EA6F0A7C880ACF0D13

SSDEEP:

6144:6wLjeoAi6pj+b/9DnAu4WMoBdsIceQld3s5Sq:6SjeoAi6pj+bNpGoB+PF6j

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Creates file in the systems drive root

      • ONENOTE.EXE (PID: 5692)
    • Detected use of alternative data streams (AltDS)

      • ONENOTE.EXE (PID: 5692)
  • INFO

    • Reads the computer name

      • ONENOTEM.EXE (PID: 2640)
    • Sends debugging messages

      • ONENOTE.EXE (PID: 5692)
    • Reads Microsoft Office registry keys

      • ONENOTEM.EXE (PID: 2640)
    • Checks supported languages

      • ONENOTEM.EXE (PID: 2640)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.one | Microsoft OneNote note (100)
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
130
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start onenote.exe onenotem.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2640/tsrC:\Program Files\Microsoft Office\root\Office16\ONENOTEM.EXEONENOTE.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Send to OneNote Tool
Version:
16.0.16026.20146
Modules
Images
c:\program files\microsoft office\root\office16\onenotem.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\common files\microsoft shared\clicktorun\appvisvsubsystems64.dll
c:\program files\common files\microsoft shared\clicktorun\c2r64.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\msvcrt.dll
5692"C:\Program Files\Microsoft Office\Root\Office16\ONENOTE.EXE" C:\Users\admin\AppData\Local\Temp\Piesixem.oneC:\Program Files\Microsoft Office\root\Office16\ONENOTE.EXE
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft OneNote
Version:
16.0.16026.20146
Modules
Images
c:\program files\microsoft office\root\office16\onenote.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\program files\common files\microsoft shared\clicktorun\appvisvsubsystems64.dll
c:\windows\system32\ole32.dll
c:\windows\system32\ucrtbase.dll
c:\program files\common files\microsoft shared\clicktorun\c2r64.dll
c:\windows\system32\rpcrt4.dll
Total events
6 344
Read events
6 084
Write events
223
Delete events
37

Modification events

(PID) Process:(5692) ONENOTE.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\ClientTelemetry\Sampling
Operation:writeName:12
Value:
012C19000000001000B24E9A3E02000000000000000200000000000000
(PID) Process:(5692) ONENOTE.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\Common\CrashPersistence\ONENOTE\5692
Operation:writeName:0
Value:
0B0E10645A0F6C9F53F34C8A6D381DD0848E3F23004680AFB4CB99D6C1ED016A04102400449A7D64B29D01008500A907556E6B6E6F776EC9062E225763446C494E41384C537237784C67357549303451703444396E4730426B415A4C6B6C6361656270562B303D22CA0DC2190000C91003783634C511BC2CD2120B6F006E0065006E006F00740065002E00650078006500C51620C517808004C91808323231322D44656300
(PID) Process:(5692) ONENOTE.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:en-US
Value:
2
(PID) Process:(5692) ONENOTE.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:de-de
Value:
2
(PID) Process:(5692) ONENOTE.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:fr-fr
Value:
2
(PID) Process:(5692) ONENOTE.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:es-es
Value:
2
(PID) Process:(5692) ONENOTE.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:it-it
Value:
2
(PID) Process:(5692) ONENOTE.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:ja-jp
Value:
2
(PID) Process:(5692) ONENOTE.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:ko-kr
Value:
2
(PID) Process:(5692) ONENOTE.EXEKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Office\16.0\Common\LanguageResources\EnabledEditingLanguages
Operation:writeName:pt-br
Value:
2
Executable files
0
Suspicious files
15
Text files
12
Unknown types
0

Dropped files

PID
Process
Filename
Type
5692ONENOTE.EXEC:\Users\admin\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\00000009.binimage
MD5:33DCA72504D567C57F95452A0358ED2F
SHA256:7E131D7DD2D98E5BF76866FFE0EB5C0AC994E1E791B07F61FB3A756F24D7317C
5692ONENOTE.EXEC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9binary
MD5:5F305219CE5B073AB4E863FBCCF5975D
SHA256:13B31CC60CE234615C39ADA1FE661A7ACF65106BFF3788FB6C7BBBBA304741EC
5692ONENOTE.EXEC:\Users\admin\AppData\Local\Temp\{930A0E66-5832-4FAC-A283-A403017E81AE}html
MD5:6728239FC3B4ABA373181331259FA004
SHA256:FBDA1D961CF1B73F9DB4158806EA6A2E7B61ED000E60084B56909D849AEDDF82
5692ONENOTE.EXEC:\Users\admin\AppData\Local\Microsoft\Office\16.0\WebServiceCache\AllUsers\officeclient.microsoft.com\D4C13F94-C867-485C-8B81-070AD30B348Bxml
MD5:9B809CB3158144407B2EEB6476C94BD5
SHA256:29DE9564E39DCB9B6CB85D1370F7C3D117F8CCDD73770D683DAF0A43DBFF5A8C
5692ONENOTE.EXEC:\Users\admin\AppData\Local\Temp\{1DB1C270-7F36-4A62-9E2F-E2CF0FFB2414}image
MD5:2CCB7FD40E61B6DD2CD936E61929FB81
SHA256:CBF4835796C6C58C2EEBB12BFE73AAAE73D0E9F37C5BD5DC63092ED776485FE8
5692ONENOTE.EXEC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_6372E0472AFF76BB926C97818BC773B9binary
MD5:0413400FB5C29631192C1EE6B2CBDD4E
SHA256:0332DC78365062A7E4D18258BB532AD1FB13B6C0D57D2085CC3D8C80E8D5FC86
5692ONENOTE.EXEC:\Users\admin\AppData\Local\Temp\{94F0C2A8-ED96-44F5-BF53-13206911B389}image
MD5:4D5F7AFD30851031376DA0FA6D0E3F80
SHA256:F918BB0C65D2F90593265FE4087B9C6905148BD7B46579D902B9ABD5415415F5
5692ONENOTE.EXEC:\Users\admin\AppData\Local\Microsoft\OneNote\16.0\cache\tmp\0000000B.binimage
MD5:4D5F7AFD30851031376DA0FA6D0E3F80
SHA256:F918BB0C65D2F90593265FE4087B9C6905148BD7B46579D902B9ABD5415415F5
5692ONENOTE.EXEC:\Users\admin\AppData\Local\Microsoft\TokenBroker\Cache\56a61aeb75d8f5be186c26607f4bb213abe7c5ec.tbresbinary
MD5:90E9BFE1E3682419CEC68F0BF167DFD4
SHA256:0FEFE07FC74C07F437A331F5CB6AAD9D1AEB9155A6CC02F246706ED692EB7B48
5692ONENOTE.EXEC:\Users\admin\AppData\Local\Temp\{D8770EF7-FF48-44DF-9AFD-894C6C6BAB5B}image
MD5:33DCA72504D567C57F95452A0358ED2F
SHA256:7E131D7DD2D98E5BF76866FFE0EB5C0AC994E1E791B07F61FB3A756F24D7317C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
38
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5692
ONENOTE.EXE
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA77flR%2B3w%2FxBpruV2lte6A%3D
unknown
whitelisted
6816
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2120
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5692
ONENOTE.EXE
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
3844
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3844
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
608
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6412
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4324
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3260
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5692
ONENOTE.EXE
52.109.28.46:443
officeclient.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
GB
whitelisted
5692
ONENOTE.EXE
52.113.194.132:443
ecs.office.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
  • 52.183.220.149
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 88.221.169.152
whitelisted
google.com
  • 172.217.18.110
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
officeclient.microsoft.com
  • 52.109.28.46
whitelisted
ecs.office.com
  • 52.113.194.132
whitelisted
roaming.officeapps.live.com
  • 52.109.89.19
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.136
  • 20.190.160.22
  • 40.126.32.72
  • 40.126.32.140
  • 40.126.32.133
  • 40.126.32.68
  • 40.126.32.74
  • 40.126.32.138
whitelisted
self.events.data.microsoft.com
  • 13.89.179.10
whitelisted

Threats

No threats detected
Process
Message
ONENOTE.EXE
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
ONENOTE.EXE
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.
ONENOTE.EXE
WebView2: Failed to find an installed WebView2 runtime or non-stable Microsoft Edge installation.