| File name: | release.exe |
| Full analysis: | https://app.any.run/tasks/c26799c4-0d3d-4a4c-b7d7-efe34b67c79a |
| Verdict: | Malicious activity |
| Analysis date: | June 22, 2025, 01:27:34 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, RAR self-extracting archive, 5 sections |
| MD5: | E3BFDFDC34ACCE1A432B2192D48824DE |
| SHA1: | FC5FC3FE8A3C15107E7770778CEA362C31C2104A |
| SHA256: | 8A85A9A0C80850FE7831A7D02A756A3939203C8D343E07F4FF12865ED171C124 |
| SSDEEP: | 12288:bhQmWtujwNOVVVVVVuVV6VVVVVVuVV/7vDt/KyIusU/GpowzB1909:bh6d7vDt9PsU/GpowzB1909 |
| .exe | | | Win32 Executable MS Visual C++ (generic) (35.8) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (31.7) |
| .scr | | | Windows screen saver (15) |
| .dll | | | Win32 Dynamic Link Library (generic) (7.5) |
| .exe | | | Win32 Executable (generic) (5.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2012:06:09 13:19:49+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 74752 |
| InitializedDataSize: | 121344 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xac87 |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 432 | "C:\Users\admin\AppData\Local\Temp\6a0d20ce63a240439d3342d7d207f3e5.exe" | C:\Users\admin\AppData\Local\Temp\6a0d20ce63a240439d3342d7d207f3e5.exe | f42a318c34ef4a4aba8d9fc6ed665bb0.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: ConsoleApplication3 Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 472 | "C:\Users\admin\AppData\Local\Temp\f42a318c34ef4a4aba8d9fc6ed665bb0.exe" | C:\Users\admin\AppData\Local\Temp\f42a318c34ef4a4aba8d9fc6ed665bb0.exe | ConsoleApplication3.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: ConsoleApplication3 Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 724 | "C:\Users\admin\AppData\Local\Temp\34d4bab5f7f84c518a53096fa9577367.exe" | C:\Users\admin\AppData\Local\Temp\34d4bab5f7f84c518a53096fa9577367.exe | f42a318c34ef4a4aba8d9fc6ed665bb0.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: ConsoleApplication3 Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 768 | "C:\Users\admin\AppData\Local\Temp\ccc209de9d5c421e83992139c50872fc.exe" | C:\Users\admin\AppData\Local\Temp\ccc209de9d5c421e83992139c50872fc.exe | a1d4aac2f31f4ed69b35770afac0a776.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: ConsoleApplication3 Version: 1.0.0.0 Modules
| |||||||||||||||
| 1044 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | 2fe37cf75a064350aed5e702f80e19c5.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1080 | "C:\Users\admin\AppData\Local\Temp\f6ef7e94dd2c49a19a4db5ece5293041.exe" | C:\Users\admin\AppData\Local\Temp\f6ef7e94dd2c49a19a4db5ece5293041.exe | 1b4689724f9a492987d4ffe2b5a4e6d3.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: ConsoleApplication3 Version: 1.0.0.0 Modules
| |||||||||||||||
| 1136 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | 6c535aabc86d43eaa263e6fe90c2ee80.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1296 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | 1b4689724f9a492987d4ffe2b5a4e6d3.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1332 | "C:\Users\admin\AppData\Local\Temp\ca72bb147b8e466585f695402cbe2518.exe" | C:\Users\admin\AppData\Local\Temp\ca72bb147b8e466585f695402cbe2518.exe | 790964ae5d804d92b9eb2610b399d199.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: ConsoleApplication3 Version: 1.0.0.0 Modules
| |||||||||||||||
| 1496 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | a1d4aac2f31f4ed69b35770afac0a776.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (3900) ConsoleApplication3.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ConsoleApplication3_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (3900) ConsoleApplication3.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ConsoleApplication3_RASAPI32 |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
| (PID) Process: | (3900) ConsoleApplication3.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ConsoleApplication3_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (3900) ConsoleApplication3.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ConsoleApplication3_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (3900) ConsoleApplication3.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ConsoleApplication3_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
| (PID) Process: | (3900) ConsoleApplication3.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ConsoleApplication3_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (3900) ConsoleApplication3.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ConsoleApplication3_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
| (PID) Process: | (3900) ConsoleApplication3.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ConsoleApplication3_RASMANCS |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (3900) ConsoleApplication3.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ConsoleApplication3_RASMANCS |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
| (PID) Process: | (3900) ConsoleApplication3.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ConsoleApplication3_RASMANCS |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4500 | release.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\ConsoleApplication3.exe | executable | |
MD5:B0F6A53498F242DCB9C967E1A5E6E379 | SHA256:506949C101180FF48530BDFEA2D27A551340A71581A2D8E729ACA50AC2ACE7FE | |||
| 2792 | f42a318c34ef4a4aba8d9fc6ed665bb0.exe | C:\Users\admin\AppData\Local\Temp\6a0d20ce63a240439d3342d7d207f3e5.exe | executable | |
MD5:3519A9CD6AB180B3C4B7FDE79994F3B3 | SHA256:D4038DC2322656695D402AF95BEC462FD92F8002E749BB31A31205381BA2F5C0 | |||
| 2632 | f42a318c34ef4a4aba8d9fc6ed665bb0.exe | C:\Users\admin\AppData\Local\Temp\34d4bab5f7f84c518a53096fa9577367.exe | executable | |
MD5:4259AFF7FADFF3ED73FBEF5247E389AF | SHA256:776EC6A82F017B702876196EDB27B498F714890B8952E0F24CE4CD558DBE4287 | |||
| 5468 | 6a0d20ce63a240439d3342d7d207f3e5.exe | C:\Users\admin\AppData\Local\Temp\a044c9dfee1e4c77ac71a0c1da1a9008.exe | executable | |
MD5:3B195C53B15F10273E8FE9DB4A13F05C | SHA256:ED6DFC7C1CA68FAC9286C7C852A17C6DAE7A1E1202305C07A404BBC3768EAA22 | |||
| 6336 | 6a0d20ce63a240439d3342d7d207f3e5.exe | C:\Users\admin\AppData\Local\Temp\790964ae5d804d92b9eb2610b399d199.exe | executable | |
MD5:EBA85953CD0770A7D7C2C5009C74D793 | SHA256:D67C7518915500AFDA5B771D9873D8025E1CE33B2E7C181004D129AD2B8BA566 | |||
| 6936 | 7b1d5a1e3d5247e5974616f01a91ecf7.exe | C:\Users\admin\AppData\Local\Temp\845ed81413024d3a97264690368b68e7.exe | executable | |
MD5:CA03BF2E3E095A37D1DEC9E08C42FB55 | SHA256:3F7A5C9AA3760C958214E78D6793FF741198F0380B092F7D6E114C6F57B367F3 | |||
| 432 | 6a0d20ce63a240439d3342d7d207f3e5.exe | C:\Users\admin\AppData\Local\Temp\22f0dbbfa3f04a10bbf9e96ae0bcdd2d.exe | executable | |
MD5:39D44B71D7D016F1780D3C84061EE472 | SHA256:66B7EB3E9907E34FB79185066477EC0F9CE68260F153F80B5C74026CEBC8D345 | |||
| 472 | f42a318c34ef4a4aba8d9fc6ed665bb0.exe | C:\Users\admin\AppData\Local\Temp\1b4689724f9a492987d4ffe2b5a4e6d3.exe | executable | |
MD5:27A01E2F36F9A7D42FCA8D5520B63D64 | SHA256:DA81B43416D3D1B38159C0D5865E6FF76924752C5EB2F8BA31A2B69EBAC1C87D | |||
| 6240 | 6a0d20ce63a240439d3342d7d207f3e5.exe | C:\Users\admin\AppData\Local\Temp\623a01845ecd41339efb3e40f12b276a.exe | executable | |
MD5:158FF99C7D28EB73F3F7008BD84350C6 | SHA256:AFB978E80C5B94C177F61CFBCBE51A52F3C11992FE4296E498F556C6BCFF9135 | |||
| 4500 | release.exe | C:\Users\admin\AppData\Local\Temp\RarSFX0\Mono.Cecil.dll | executable | |
MD5:2F096535C228AB0D2082ADFC01678481 | SHA256:C41BDB9FFD3C5F6E17D2382C1012D73703E035E3F1100245FDD4E08C8DC6EB5B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5944 | MoUsoCoreWorker.exe | GET | 200 | 184.25.50.10:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
436 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
5944 | MoUsoCoreWorker.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
5944 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3800 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1268 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3900 | ConsoleApplication3.exe | 104.26.2.158:443 | computernewb.com | CLOUDFLARENET | US | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2792 | f42a318c34ef4a4aba8d9fc6ed665bb0.exe | 104.26.2.158:443 | computernewb.com | CLOUDFLARENET | US | whitelisted |
6472 | f42a318c34ef4a4aba8d9fc6ed665bb0.exe | 104.26.2.158:443 | computernewb.com | CLOUDFLARENET | US | whitelisted |
5716 | f42a318c34ef4a4aba8d9fc6ed665bb0.exe | 104.26.2.158:443 | computernewb.com | CLOUDFLARENET | US | whitelisted |
2632 | f42a318c34ef4a4aba8d9fc6ed665bb0.exe | 104.26.2.158:443 | computernewb.com | CLOUDFLARENET | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
computernewb.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
nexusrules.officeapps.live.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |