| File name: | Client.vshost.exe |
| Full analysis: | https://app.any.run/tasks/0519e6eb-4a7b-4083-b24f-bf0ac5dedfeb |
| Verdict: | Malicious activity |
| Analysis date: | December 10, 2023, 07:02:30 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| MD5: | 91DF22D4ADB0CE96817937638BFAE13A |
| SHA1: | 8DCB86CA5B3D269001C787E524D41202B6CA8A2C |
| SHA256: | 7B0FA55256B097ABE9BB2A4CD7F8C069C5E7E87F18B850304B1FC3D2A07C0A13 |
| SSDEEP: | 384:OYfiWE9WOzla21g39/Ii6Pvx+r9R1LPj3tU8aqJWD3I0+26BB:O3Da2y31s0LrdUmWD3IJ |
| .dll | | | Win32 Dynamic Link Library (generic) (43.5) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (29.8) |
| .exe | | | Generic Win/DOS Executable (13.2) |
| .exe | | | DOS Executable Generic (13.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2014:07:23 08:02:12+02:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 11 |
| CodeSize: | 3072 |
| InitializedDataSize: | 2048 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x2bde |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 12.0.30723.0 |
| ProductVersionNumber: | 12.0.30723.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | vshost-clr2.exe |
| CompanyName: | Microsoft Corporation |
| FileDescription: | vshost-clr2.exe |
| FileVersion: | 12.0.30723.0 |
| InternalName: | vshost-clr2.exe |
| LegalCopyright: | © Microsoft Corporation. All rights reserved. |
| OriginalFileName: | vshost-clr2.exe |
| ProductName: | Microsoft® Visual Studio® 2013 |
| ProductVersion: | 12.0.30723.0 |
| AssemblyVersion: | 12.0.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1088 | dw20.exe -x -s 884 | C:\Windows\Microsoft.NET\Framework\v2.0.50727\dw20.exe | Client.vshost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft .NET Error Reporting Shim Exit code: 0 Version: 2.0.50727.5483 (Win7SP1GDR.050727-5400) Modules
| |||||||||||||||
| 1352 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1864 | "C:\Users\admin\AppData\Local\Temp\Client.vshost.exe" | C:\Users\admin\AppData\Local\Temp\Client.vshost.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: vshost-clr2.exe Exit code: 3762507597 Version: 12.0.30723.0 Modules
| |||||||||||||||
| (PID) Process: | (1864) Client.vshost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1088) dw20.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles |
| Operation: | write | Name: | FirstLevelConsentDialog |
Value: 7603050000000000 | |||
| (PID) Process: | (1088) dw20.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles |
| Operation: | write | Name: | FirstLevelConsentDialog |
Value: 7603050000000000 | |||
| (PID) Process: | (1088) dw20.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug |
| Operation: | write | Name: | StoreLocation |
Value: C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_aga.exe_b1af04294ac80144576abfc50b4daa16fd011ca_cab_059b2052 | |||
| (PID) Process: | (1088) dw20.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\Windows Error Reporting\Debug |
| Operation: | write | Name: | StoreLocation |
Value: C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_aga.exe_b1af04294ac80144576abfc50b4daa16fd011ca_cab_059b2052 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1088 | dw20.exe | C:\Users\admin\AppData\Local\Temp\WER5E8B.tmp.hdmp | — | |
MD5:— | SHA256:— | |||
| 1088 | dw20.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\WER\ReportQueue\AppCrash_Client.vshost.ex_e7ffb7e49d277427bf6b4c93b4a932883d8209_cab_04616919\WER5E8B.tmp.hdmp | — | |
MD5:— | SHA256:— | |||
| 1088 | dw20.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\WER\ReportQueue\AppCrash_Client.vshost.ex_e7ffb7e49d277427bf6b4c93b4a932883d8209_cab_04616919\Report.wer | — | |
MD5:— | SHA256:— | |||
| 1088 | dw20.exe | C:\Users\admin\AppData\Local\Temp\WER3538.tmp.WERInternalMetadata.xml | xml | |
MD5:A636A487581CFD38444226CBC4BD6A43 | SHA256:225F09EC1BEEA53B86BF3C983FBC0C762121AB657FF87A74C82761AD4F8FF022 | |||
| 1088 | dw20.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\WER\ReportQueue\AppCrash_Client.vshost.ex_e7ffb7e49d277427bf6b4c93b4a932883d8209_cab_04616919\WER689E.tmp.mdmp | binary | |
MD5:4FB053655B696F5254E8CB1D9199D322 | SHA256:E6111EAE0AF5B44580E704ED5EAD183D17633D76806D111AEDE7F0D46CB5B18A | |||
| 1088 | dw20.exe | C:\Users\admin\AppData\Local\Temp\WER689E.tmp.mdmp | binary | |
MD5:4FB053655B696F5254E8CB1D9199D322 | SHA256:E6111EAE0AF5B44580E704ED5EAD183D17633D76806D111AEDE7F0D46CB5B18A | |||
| 1088 | dw20.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\WER\ReportQueue\AppCrash_Client.vshost.ex_e7ffb7e49d277427bf6b4c93b4a932883d8209_cab_04616919\WER3538.tmp.WERInternalMetadata.xml | xml | |
MD5:A636A487581CFD38444226CBC4BD6A43 | SHA256:225F09EC1BEEA53B86BF3C983FBC0C762121AB657FF87A74C82761AD4F8FF022 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1088 | dw20.exe | 104.208.16.93:443 | watson.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
Domain | IP | Reputation |
|---|---|---|
watson.microsoft.com |
| whitelisted |