| File name: | 7381a8c598e28bb0cf60ab6630760cf8.exe |
| Full analysis: | https://app.any.run/tasks/c352cf6e-774b-456b-b0b6-aa406701b0fd |
| Verdict: | Malicious activity |
| Analysis date: | December 08, 2024, 08:57:29 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows, 6 sections |
| MD5: | 7381A8C598E28BB0CF60AB6630760CF8 |
| SHA1: | A318DE08F346EE0790BF28E19B6EF97C342DAB6B |
| SHA256: | 7B3550BDBD3E52D332453B18473618BB15F5E49AC8E39269F1EF48BA0C6D2B1C |
| SSDEEP: | 98304:LEWn4ErFvt0A2qzpZyBGXZOflNZGHOQya0TuqTA0PzRYqmh7vSRpl89+bE9d9YbA:R0KCFboh11kYANW |
| .exe | | | Win64 Executable (generic) (87.3) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (6.3) |
| .exe | | | DOS Executable Generic (6.3) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2024:12:08 00:41:04+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 14.4 |
| CodeSize: | 168960 |
| InitializedDataSize: | 153600 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xc0d0 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 420 | C:\WINDOWS\System32\sihclient.exe /cv Xepf/9I1q06Q9ozUJoX9gQ.0.2 | C:\Windows\System32\SIHClient.exe | upfc.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: SIH Client Exit code: 2379777 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6240 | C:\WINDOWS\system32\wbem\wmiprvse.exe -secured -Embedding | C:\Windows\System32\wbem\WmiPrvSE.exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: WMI Provider Host Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6320 | C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s wuauserv | C:\Windows\System32\svchost.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6408 | "C:\Users\admin\AppData\Local\Temp\7381a8c598e28bb0cf60ab6630760cf8.exe" | C:\Users\admin\AppData\Local\Temp\7381a8c598e28bb0cf60ab6630760cf8.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 6440 | "C:\Users\admin\AppData\Local\Temp\7381a8c598e28bb0cf60ab6630760cf8.exe" | C:\Users\admin\AppData\Local\Temp\7381a8c598e28bb0cf60ab6630760cf8.exe | — | 7381a8c598e28bb0cf60ab6630760cf8.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 6480 | "C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:CortanaUI.AppX3bn25b6f886wmg6twh46972vprk9tnbf.mca | C:\Windows\System32\backgroundTaskHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Background Task Host Exit code: 1 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6504 | "C:\WINDOWS\system32\backgroundTaskHost.exe" -ServerName:Global.IrisService.AppXwt29n3t7x7q6fgyrrbbqxwzkqjfjaw4y.mca | C:\Windows\System32\backgroundTaskHost.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Background Task Host Exit code: 1 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6624 | C:\WINDOWS\System32\svchost.exe -k wsappx -p -s ClipSVC | C:\Windows\System32\svchost.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6784 | C:\Windows\System32\RuntimeBroker.exe -Embedding | C:\Windows\System32\RuntimeBroker.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Runtime Broker Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7060 | %systemroot%\system32\MusNotificationUx.exe ClearActiveNotifications | C:\Windows\System32\MusNotificationUx.exe | — | MusNotification.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: MusNotificationUx.exe Exit code: 0 Version: 10.0.19041.3693 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6480) backgroundTaskHost.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\SearchSettings |
| Operation: | write | Name: | SafeSearchMode |
Value: 1 | |||
| (PID) Process: | (6480) backgroundTaskHost.exe | Key: | \REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState |
| Operation: | write | Name: | BINGIDENTITY_PROP_USEREMAIL |
Value: 0000236EC53C4F49DB01 | |||
| (PID) Process: | (6480) backgroundTaskHost.exe | Key: | \REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState |
| Operation: | write | Name: | BINGIDENTITY_PROP_ACCOUNTTYPETEXT |
Value: 00001FD2C73C4F49DB01 | |||
| (PID) Process: | (6480) backgroundTaskHost.exe | Key: | \REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState |
| Operation: | write | Name: | BINGIDENTITY_PROP_ACCOUNTTYPE |
Value: 00001FD2C73C4F49DB01 | |||
| (PID) Process: | (6480) backgroundTaskHost.exe | Key: | \REGISTRY\A\{ee080948-b2ea-145a-6870-f9164b908eb9}\LocalState |
| Operation: | write | Name: | BINGIDENTITY_PROP_ACCOUNTTYPE |
Value: 4E006F006E00650000001FD2C73C4F49DB01 | |||
| (PID) Process: | (6480) backgroundTaskHost.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\Flighting |
| Operation: | write | Name: | CachedFeatureString |
Value: | |||
| (PID) Process: | (6504) backgroundTaskHost.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\IrisService\Providers\Display |
| Operation: | write | Name: | Version |
Value: 2 | |||
| (PID) Process: | (6504) backgroundTaskHost.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\IrisService\Providers\Display |
| Operation: | write | Name: | Attributes |
Value: {"disphorzres":"1280","dispsize":"15.3","dispvertres":"720","ldisphorzres":"1280","ldispvertres":"720","moncnt":"1"} | |||
| (PID) Process: | (6504) backgroundTaskHost.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\IrisService\Providers\Display |
| Operation: | write | Name: | UpdateTime |
Value: 2024-12-08T08:57:41Z | |||
| (PID) Process: | (6624) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion |
| Operation: | write | Name: | ProductName |
Value: Windows 10 Pro | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6408 | 7381a8c598e28bb0cf60ab6630760cf8.exe | C:\Users\admin\AppData\Local\Temp\_MEI64082\api-ms-win-core-file-l2-1-0.dll | executable | |
MD5:7D4D4593B478B4357446C106B64E61F8 | SHA256:0A6E2224CDE90A0D41926E8863F9956848FFBF19848E8855BD08953112AFC801 | |||
| 6408 | 7381a8c598e28bb0cf60ab6630760cf8.exe | C:\Users\admin\AppData\Local\Temp\_MEI64082\api-ms-win-core-file-l1-2-0.dll | executable | |
MD5:F0C73F7454A5CE6FB8E3D795FDB0235D | SHA256:2A59DD891533A028FAE7A81E690E4C28C9074C2F327393FAB17329AFFE53FD7B | |||
| 6408 | 7381a8c598e28bb0cf60ab6630760cf8.exe | C:\Users\admin\AppData\Local\Temp\_MEI64082\api-ms-win-core-console-l1-1-0.dll | executable | |
MD5:B56D69079D2001C1B2AF272774B53A64 | SHA256:F3A41D882544202B2E1BDF3D955458BE11FC7F76BA12668388A681870636F143 | |||
| 6408 | 7381a8c598e28bb0cf60ab6630760cf8.exe | C:\Users\admin\AppData\Local\Temp\_MEI64082\_hashlib.pyd | executable | |
MD5:A6448BC5E5DA21A222DE164823ADD45C | SHA256:3692FC8E70E6E29910032240080FC8109248CE9A996F0A70D69ACF1542FCA69A | |||
| 6408 | 7381a8c598e28bb0cf60ab6630760cf8.exe | C:\Users\admin\AppData\Local\Temp\_MEI64082\_bz2.pyd | executable | |
MD5:3DC8AF67E6EE06AF9EEC52FE985A7633 | SHA256:C55821F5FDB0064C796B2C0B03B51971F073140BC210CBE6ED90387DB2BED929 | |||
| 6408 | 7381a8c598e28bb0cf60ab6630760cf8.exe | C:\Users\admin\AppData\Local\Temp\_MEI64082\_ctypes.pyd | executable | |
MD5:F1E33A8F6F91C2ED93DC5049DD50D7B8 | SHA256:9459D246DF7A3C638776305CF3683946BA8DB26A7DE90DF8B60E1BE0B27E53C4 | |||
| 6408 | 7381a8c598e28bb0cf60ab6630760cf8.exe | C:\Users\admin\AppData\Local\Temp\_MEI64082\VCRUNTIME140.dll | executable | |
MD5:0E675D4A7A5B7CCD69013386793F68EB | SHA256:BF5FF4603557C9959ACEC995653D052D9054AD4826DF967974EFD2F377C723D1 | |||
| 6408 | 7381a8c598e28bb0cf60ab6630760cf8.exe | C:\Users\admin\AppData\Local\Temp\_MEI64082\_lzma.pyd | executable | |
MD5:37057C92F50391D0751F2C1D7AD25B02 | SHA256:9442DC46829485670A6AC0C02EF83C54B401F1570D1D5D1D85C19C1587487764 | |||
| 6408 | 7381a8c598e28bb0cf60ab6630760cf8.exe | C:\Users\admin\AppData\Local\Temp\_MEI64082\_socket.pyd | executable | |
MD5:D6BAE4B430F349AB42553DC738699F0E | SHA256:587C4F3092B5F3E34F6B1E927ECC7127B3FE2F7FA84E8A3D0C41828583BD5CEF | |||
| 6408 | 7381a8c598e28bb0cf60ab6630760cf8.exe | C:\Users\admin\AppData\Local\Temp\_MEI64082\api-ms-win-core-datetime-l1-1-0.dll | executable | |
MD5:5AF784F599437629DEEA9FE4E8EB4799 | SHA256:7E5BD3EE263D09C7998E0D5FFA684906DDC56DA61536331C89C74B039DF00C7C | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2380 | svchost.exe | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
2380 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1176 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
420 | SIHClient.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
420 | SIHClient.exe | GET | 200 | 88.221.169.152:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
6504 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2380 | svchost.exe | 23.48.23.143:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
2380 | svchost.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
— | — | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
5064 | SearchApp.exe | 104.126.37.147:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
— | — | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1176 | svchost.exe | 40.126.32.133:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
google.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |