File name:

OpenHardwareMonitor.exe

Full analysis: https://app.any.run/tasks/e2a27a16-e70d-42a0-bee9-65a1e2850dff
Verdict: Malicious activity
Analysis date: April 13, 2025, 16:00:53
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
winring0x64-sys
vuln-driver
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

DAE08B0E78454BE7811735DC898F74C6

SHA1:

D1D92E35737D627D9FCA8D628661DDE832A6288D

SHA256:

8180AD6F15ACBBDA840CDA6D5D2CEE30ECEC4305EDF6EE0B57D98AB1BD408BF2

SSDEEP:

49152:nijZo19vCrJ9hCQD/TZWDMKGyDdXYCG8ogRjmFQ8MGoAZ94c+eNysvmBZo:i9o3QD/tWayDdXY/8ogyrPZ9dNysvgZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • OpenHardwareMonitor.exe (PID: 5968)
    • Vulnerable driver has been detected

      • OpenHardwareMonitor.exe (PID: 5968)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • OpenHardwareMonitor.exe (PID: 5968)
    • Drops a system driver (possible attempt to evade defenses)

      • OpenHardwareMonitor.exe (PID: 5968)
    • There is functionality for taking screenshot (YARA)

      • OpenHardwareMonitor.exe (PID: 5968)
  • INFO

    • Reads Environment values

      • OpenHardwareMonitor.exe (PID: 5968)
    • Reads the machine GUID from the registry

      • OpenHardwareMonitor.exe (PID: 5968)
    • Reads the computer name

      • OpenHardwareMonitor.exe (PID: 5968)
    • Create files in a temporary directory

      • OpenHardwareMonitor.exe (PID: 5968)
    • The sample compiled with japanese language support

      • OpenHardwareMonitor.exe (PID: 5968)
    • Creates files in the program directory

      • OpenHardwareMonitor.exe (PID: 5968)
    • Process checks computer location settings

      • OpenHardwareMonitor.exe (PID: 5968)
    • Checks supported languages

      • OpenHardwareMonitor.exe (PID: 5968)
    • Disables trace logs

      • OpenHardwareMonitor.exe (PID: 5968)
    • Checks proxy server information

      • OpenHardwareMonitor.exe (PID: 5968)
    • Reads the software policy settings

      • OpenHardwareMonitor.exe (PID: 5968)
      • slui.exe (PID: 4652)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (49.4)
.scr | Windows screen saver (23.4)
.dll | Win32 Dynamic Link Library (generic) (11.7)
.exe | Win32 Executable (generic) (8)
.exe | Generic Win/DOS Executable (3.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:04:12 20:09:32+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 1185792
InitializedDataSize: 38400
UninitializedDataSize: -
EntryPoint: 0x12360e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2025.1.9233.41686
ProductVersionNumber: 2025.1.9233.41686
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: Sergiy Egoshyn
FileDescription: Open Hardware Monitor
FileVersion: 2025.1.9233.41686
InternalName: OpenHardwareMonitor.exe
LegalCopyright: Copyright © 2022 Sergiy Egoshyn
OriginalFileName: OpenHardwareMonitor.exe
ProductName: Open Hardware Monitor
ProductVersion: 2025.1.9233.41686
AssemblyVersion: 2025.1.9233.41686
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
132
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start THREAT openhardwaremonitor.exe sppextcomobj.exe no specs slui.exe slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3956C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
4652"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5968"C:\Users\admin\AppData\Local\Temp\OpenHardwareMonitor.exe" C:\Users\admin\AppData\Local\Temp\OpenHardwareMonitor.exe
explorer.exe
User:
admin
Company:
Sergiy Egoshyn
Integrity Level:
MEDIUM
Description:
Open Hardware Monitor
Version:
2025.1.9233.41686
Modules
Images
c:\users\admin\appdata\local\temp\openhardwaremonitor.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6148C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
1 755
Read events
1 722
Write events
29
Delete events
4

Modification events

(PID) Process:(5968) OpenHardwareMonitor.exeKey:HKEY_CURRENT_USER\SOFTWARE\sergiye\openHardwareMonitor
Operation:writeName:theme
Value:
auto
(PID) Process:(5968) OpenHardwareMonitor.exeKey:HKEY_CURRENT_USER\SOFTWARE\sergiye\openHardwareMonitor
Operation:delete keyName:(default)
Value:
(PID) Process:(5968) OpenHardwareMonitor.exeKey:HKEY_CURRENT_USER\SOFTWARE\sergiye\openHardwareMonitor
Operation:writeName:mainForm.Location.X
Value:
290
(PID) Process:(5968) OpenHardwareMonitor.exeKey:HKEY_CURRENT_USER\SOFTWARE\sergiye\openHardwareMonitor
Operation:writeName:mainForm.Location.Y
Value:
20
(PID) Process:(5968) OpenHardwareMonitor.exeKey:HKEY_CURRENT_USER\SOFTWARE\sergiye\openHardwareMonitor
Operation:writeName:mainForm.Width
Value:
700
(PID) Process:(5968) OpenHardwareMonitor.exeKey:HKEY_CURRENT_USER\SOFTWARE\sergiye\openHardwareMonitor
Operation:writeName:mainForm.Height
Value:
640
(PID) Process:(5968) OpenHardwareMonitor.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OpenHardwareMonitor_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(5968) OpenHardwareMonitor.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OpenHardwareMonitor_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(5968) OpenHardwareMonitor.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OpenHardwareMonitor_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(5968) OpenHardwareMonitor.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OpenHardwareMonitor_RASAPI32
Operation:writeName:FileTracingMask
Value:
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
5968OpenHardwareMonitor.exeC:\Users\admin\AppData\Local\Temp\tmpB855.sysexecutable
MD5:0C0195C48B6B8582FA6F6373032118DA
SHA256:11BD2C9F9E2397C9A16E0990E4ED2CF0679498FE0FD418A3DFDAC60B5C160EE5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
19
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.19.11.105:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
2320
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2320
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
2.19.11.105:80
crl.microsoft.com
Elisa Oyj
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
5968
OpenHardwareMonitor.exe
140.82.121.6:443
api.github.com
GITHUB
US
whitelisted
6544
svchost.exe
20.190.160.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2320
SIHClient.exe
4.245.163.56:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
whitelisted
crl.microsoft.com
  • 2.19.11.105
  • 2.19.11.120
whitelisted
google.com
  • 142.250.186.142
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
api.github.com
  • 140.82.121.6
whitelisted
login.live.com
  • 20.190.160.130
  • 20.190.160.5
  • 20.190.160.65
  • 40.126.32.136
  • 40.126.32.74
  • 40.126.32.133
  • 20.190.160.22
  • 20.190.160.128
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

No threats detected
No debug info