File name:

SW2010-2013.Activator.SSQ.exe

Full analysis: https://app.any.run/tasks/1a32e2ff-4ca3-4e5d-b0d4-5a5a7eda8301
Verdict: Malicious activity
Analysis date: April 12, 2025, 14:39:12
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 4 sections
MD5:

F6DCD44E9409E1833F0C434D6B2CB513

SHA1:

57E55C10742A20051D1B461D67B30DEE262BBB37

SHA256:

8482D8CDBA714AEC85A0CD385443990CB91F027608E397BBD00C30E9B1F6A2C1

SSDEEP:

98304:YbkWRvIVoYRFplCqFwWsom9m3QMImuOlyTu19aPirSt0XE+aViTCTMxkGV4T3jth:LSsQz9hf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Gets a file object corresponding to the file in a specified path (SCRIPT)

      • wscript.exe (PID: 7752)
    • Deletes a file (SCRIPT)

      • wscript.exe (PID: 7752)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • SW2010-2013.Activator.SSQ.exe (PID: 7188)
    • The process executes VB scripts

      • SW2010-2013.Activator.SSQ.exe (PID: 7188)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • wscript.exe (PID: 7752)
    • Gets full path of the running script (SCRIPT)

      • wscript.exe (PID: 7752)
    • There is functionality for taking screenshot (YARA)

      • SW2010-2013.Activator.SSQ.exe (PID: 7188)
  • INFO

    • Checks supported languages

      • SW2010-2013.Activator.SSQ.exe (PID: 7188)
      • SW2010-2013.Activator.SSQ.exe (PID: 7464)
    • Create files in a temporary directory

      • SW2010-2013.Activator.SSQ.exe (PID: 7188)
    • Reads the computer name

      • SW2010-2013.Activator.SSQ.exe (PID: 7188)
      • SW2010-2013.Activator.SSQ.exe (PID: 7464)
    • The sample compiled with english language support

      • SW2010-2013.Activator.SSQ.exe (PID: 7188)
    • Creates files in the program directory

      • SW2010-2013.Activator.SSQ.exe (PID: 7188)
    • Manual execution by a user

      • firefox.exe (PID: 7852)
    • Application launched itself

      • firefox.exe (PID: 7852)
      • firefox.exe (PID: 7872)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2005:05:10 12:10:55+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 80384
InitializedDataSize: 55808
UninitializedDataSize: -
EntryPoint: 0xc36e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
145
Monitored processes
17
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start sw2010-2013.activator.ssq.exe sppextcomobj.exe no specs slui.exe no specs sw2010-2013.activator.ssq.exe no specs wscript.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs sw2010-2013.activator.ssq.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2240"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5080 -childID 4 -isForBrowser -prefsHandle 5068 -prefMapHandle 5064 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1508 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {ea55b3fa-d477-446f-b7c1-cefd2b3d44fd} 7872 "\\.\pipe\gecko-crash-server-pipe.7872" 23583b7ff50 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
2420"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5072 -childID 3 -isForBrowser -prefsHandle 5028 -prefMapHandle 4860 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1508 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {01f134b1-9d97-4d3c-b23a-dab576071410} 7872 "\\.\pipe\gecko-crash-server-pipe.7872" 23583b7fd90 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
3100"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4308 -childID 2 -isForBrowser -prefsHandle 4328 -prefMapHandle 4324 -prefsLen 36588 -prefMapSize 244583 -jsInitHandle 1508 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {7608bcb5-8144-4501-ae72-50e32c075df4} 7872 "\\.\pipe\gecko-crash-server-pipe.7872" 23585d70850 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
4024"C:\Users\admin\AppData\Local\Temp\SW2010-2013.Activator.SSQ.exe" C:\Users\admin\AppData\Local\Temp\SW2010-2013.Activator.SSQ.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\sw2010-2013.activator.ssq.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4212"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5984 -childID 6 -isForBrowser -prefsHandle 5964 -prefMapHandle 5960 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1508 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {970ae1f5-95d6-4fb2-9866-399832dc9c07} 7872 "\\.\pipe\gecko-crash-server-pipe.7872" 2358ab11150 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\bcrypt.dll
4724"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2604 -childID 1 -isForBrowser -prefsHandle 2856 -prefMapHandle 2692 -prefsLen 31447 -prefMapSize 244583 -jsInitHandle 1508 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {64834e7f-17a4-431d-a444-3d874a97b178} 7872 "\\.\pipe\gecko-crash-server-pipe.7872" 2358419df50 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\crypt32.dll
5360"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5300 -childID 5 -isForBrowser -prefsHandle 5292 -prefMapHandle 5092 -prefsLen 31243 -prefMapSize 244583 -jsInitHandle 1508 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {18c42015-a5dc-4346-97f5-bee4d38a3c60} 7872 "\\.\pipe\gecko-crash-server-pipe.7872" 23588dfdf50 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
6676"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4960 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 4952 -prefMapHandle 4948 -prefsLen 38181 -prefMapSize 244583 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {b8a66348-3e85-48ab-a859-7930b87afcb5} 7872 "\\.\pipe\gecko-crash-server-pipe.7872" 23587830310 utilityC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
c:\windows\system32\vcruntime140_1.dll
c:\windows\system32\crypt32.dll
7188"C:\Users\admin\AppData\Local\Temp\SW2010-2013.Activator.SSQ.exe" C:\Users\admin\AppData\Local\Temp\SW2010-2013.Activator.SSQ.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\sw2010-2013.activator.ssq.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
7264C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
Total events
11 977
Read events
11 975
Write events
2
Delete events
0

Modification events

(PID) Process:(7188) SW2010-2013.Activator.SSQ.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\SW2010-2013.Activator.SSQ.exe
Operation:writeName:Path
Value:
C:\Temp\
(PID) Process:(7872) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
Executable files
7
Suspicious files
152
Text files
23
Unknown types
0

Dropped files

PID
Process
Filename
Type
7872firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\9kie7cg6.default-release\startupCache\scriptCache-current.bin
MD5:
SHA256:
7188SW2010-2013.Activator.SSQ.exeC:\Users\admin\AppData\Local\Temp\SPIC9E9.tmp\setup.dattext
MD5:AD70BC6C4446F327F2900767DF8D9B5F
SHA256:89B5DC10C72186D746C91E7532A47B0C9000BAB653ECB4C4302AC472C9EF219C
7188SW2010-2013.Activator.SSQ.exeC:\Users\admin\AppData\Local\Temp\InsD92E.tmpexecutable
MD5:5EBD032DBA5306002BA06911138E849D
SHA256:79D3430AE20E7CD76FAFCE23A442F30670E753998D3ECC29D9C4FF41C761BF60
7188SW2010-2013.Activator.SSQ.exeC:\Temp\swactwiz_libFNP.dllexecutable
MD5:47B0BAD8F3D1A15702962FD39ABA0456
SHA256:24060ADE8D7CECD919C67801E40AF0F71006BE9BFD7747482F2981948735486A
7188SW2010-2013.Activator.SSQ.exeC:\Users\admin\AppData\Local\Temp\SPIC9E9.tmp\setup.bmpimage
MD5:5D18EA2A9ABE3066C2C42A202FFFF884
SHA256:97EB85519404F36E8EB62B9EEB3C72A59940E46EED940C7DE2DDBBDD94776552
7188SW2010-2013.Activator.SSQ.exeC:\Users\admin\AppData\Local\Temp\ExtDC04.tmpcompressed
MD5:F6C18204A4797DCD75A6EC81B1397BBE
SHA256:8F818395D0DF0E97199BF8323929C0F772AA8F0D3176115324D1AAC9BD5D465C
7188SW2010-2013.Activator.SSQ.exeC:\Users\admin\AppData\Local\Temp\InsDAB9.tmpexecutable
MD5:47B0BAD8F3D1A15702962FD39ABA0456
SHA256:24060ADE8D7CECD919C67801E40AF0F71006BE9BFD7747482F2981948735486A
7188SW2010-2013.Activator.SSQ.exeC:\Users\admin\AppData\Local\Temp\ExtD9ED.tmpcompressed
MD5:56826B933296075681017B42BED2C233
SHA256:410A381D5DE9343D2E6E20FDDAACC19623C074F3F31584E4DE7056AB2F54332B
7188SW2010-2013.Activator.SSQ.exeC:\Users\admin\AppData\Local\Temp\InsDC03.tmptext
MD5:46F34B2BCF4DE350B697DE1E0CB4C646
SHA256:6B71FFDC23B2C27E6D183C33E2F32F5A6DCC7697DD93948AF4891E774141E2E3
7188SW2010-2013.Activator.SSQ.exeC:\Temp\test.vbstext
MD5:46F34B2BCF4DE350B697DE1E0CB4C646
SHA256:6B71FFDC23B2C27E6D183C33E2F32F5A6DCC7697DD93948AF4891E774141E2E3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
31
TCP/UDP connections
82
DNS requests
114
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.42:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
7872
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/success.txt?ipv4
US
text
8 b
whitelisted
7872
firefox.exe
POST
200
2.16.206.148:80
http://r10.o.lencr.org/
DE
binary
504 b
whitelisted
GET
200
23.216.77.42:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
7872
firefox.exe
GET
200
34.107.221.82:80
http://detectportal.firefox.com/canonical.html
US
text
90 b
whitelisted
7872
firefox.exe
POST
200
216.58.212.163:80
http://o.pki.goog/we2
US
binary
279 b
whitelisted
7872
firefox.exe
POST
200
216.58.212.163:80
http://o.pki.goog/we2
US
binary
278 b
whitelisted
7872
firefox.exe
POST
200
2.16.206.148:80
http://r10.o.lencr.org/
DE
binary
504 b
whitelisted
7872
firefox.exe
POST
200
216.58.212.163:80
http://o.pki.goog/we2
US
binary
280 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.216.77.42:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.42:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
3216
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.160.131:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
7872
firefox.exe
34.36.137.203:443
contile.services.mozilla.com
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.78
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.216.77.42
  • 23.216.77.36
  • 23.216.77.20
  • 23.216.77.38
  • 23.216.77.18
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
login.live.com
  • 20.190.160.131
  • 20.190.160.67
  • 20.190.160.22
  • 40.126.32.134
  • 20.190.160.65
  • 20.190.160.2
  • 40.126.32.136
  • 40.126.32.133
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted
example.org
  • 96.7.128.186
  • 23.215.0.132
  • 96.7.128.192
  • 23.215.0.133
whitelisted
ipv4only.arpa
  • 192.0.0.171
  • 192.0.0.170
whitelisted

Threats

No threats detected
No debug info