File name:

CloudCheck.exe

Full analysis: https://app.any.run/tasks/711100c6-005d-4aaf-b35c-6a73811fa171
Verdict: Malicious activity
Analysis date: October 24, 2023, 20:33:05
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
MD5:

1384BD7BB45E7B7298788ECAD20CC6C9

SHA1:

684254F4EF54F34AED449905759EC238194F7087

SHA256:

91D7D387C8D1CAC4EAD0A0613E1DD505DD49A43083F759BD843BB936A502B4A8

SSDEEP:

98304:C8aQSkFr66I4l8mUS7sxw/gyoOa/Ahv9P4:Rg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads settings of System Certificates

      • CloudCheck.exe (PID: 2968)
    • Checks Windows Trust Settings

      • CloudCheck.exe (PID: 2968)
    • Reads security settings of Internet Explorer

      • CloudCheck.exe (PID: 2968)
    • Reads the Internet Settings

      • CloudCheck.exe (PID: 2968)
  • INFO

    • Checks supported languages

      • CloudCheck.exe (PID: 2968)
    • Reads the machine GUID from the registry

      • CloudCheck.exe (PID: 2968)
    • Reads the computer name

      • CloudCheck.exe (PID: 2968)
    • Creates files or folders in the user directory

      • CloudCheck.exe (PID: 2968)
    • Create files in a temporary directory

      • CloudCheck.exe (PID: 2968)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (71.5)
.scr | Windows screen saver (21.7)
.exe | Generic Win/DOS Executable (3.3)
.exe | DOS Executable Generic (3.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2023:06:27 16:17:44+02:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Large address aware, No debug
PEType: PE32+
LinkerVersion: 8
CodeSize: 3387392
InitializedDataSize: 2407424
UninitializedDataSize: -
EntryPoint: 0x7420
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2023.3.450.0
ProductVersionNumber: 2023.3.450.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Cloudflare
FileDescription: Cloudflare WARP
FileVersion: 2023.3.450.0
InternalName: Cloudflare WARP.dll
LegalCopyright: (c) 2021, Cloudflare Inc.
OriginalFileName: Cloudflare WARP.dll
ProductName: Cloudflare WARP
ProductVersion: 2023.3.450.0
AssemblyVersion: 2023.3.450.0
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
30
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start cloudcheck.exe

Process information

PID
CMD
Path
Indicators
Parent process
2968"C:\Users\admin\AppData\Local\Temp\CloudCheck.exe" C:\Users\admin\AppData\Local\Temp\CloudCheck.exe
explorer.exe
User:
admin
Company:
Cloudflare
Integrity Level:
MEDIUM
Description:
Cloudflare WARP
Exit code:
0
Version:
2023.3.450.0
Modules
Images
c:\users\admin\appdata\local\temp\cloudcheck.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
Total events
1 051
Read events
1 036
Write events
15
Delete events
0

Modification events

(PID) Process:(2968) CloudCheck.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\156\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2968) CloudCheck.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Skype.exe
Executable files
0
Suspicious files
6
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2968CloudCheck.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:F3441B8572AAE8801C04F3060B550443
SHA256:6720349E7D82EE0A8E73920D3C2B7CB2912D9FCF2EDB6FD98F2F12820158B0BF
2968CloudCheck.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:06B83742CC755F40F30BE1C7C9237AD7
SHA256:078894D1448B06AFF4A668E546A973AB7EAAADE0587C859160165F3BEC335776
2968CloudCheck.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\538F535B7FBDE384E456CC9F5DA5FBABbinary
MD5:6449C7DCF2762CA7DEF8D6EB882B4A8F
SHA256:2C857D21C1538C083CC7FC8402E4F0E65DEC34D6C81D02CEC436A8422EB0A1B2
2968CloudCheck.exeC:\Users\admin\AppData\Local\Temp\CabB62C.tmpcompressed
MD5:F3441B8572AAE8801C04F3060B550443
SHA256:6720349E7D82EE0A8E73920D3C2B7CB2912D9FCF2EDB6FD98F2F12820158B0BF
2968CloudCheck.exeC:\Users\admin\AppData\Local\Temp\TarB62D.tmpbinary
MD5:9441737383D21192400ECA82FDA910EC
SHA256:BC3A6E84E41FAEB57E7C21AA3B60C2A64777107009727C5B7C0ED8FE658909E5
2968CloudCheck.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\538F535B7FBDE384E456CC9F5DA5FBABbinary
MD5:6D469ED9256D08235B5E747D1E27DBF2
SHA256:B676F2EDDAE8775CD36CB0F63CD1D4603961F49E6265BA013A2F0307B6D0B804
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
8
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2968
CloudCheck.exe
GET
200
8.241.9.126:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?d0cd07ef863564e8
unknown
compressed
61.6 Kb
unknown
2968
CloudCheck.exe
GET
200
23.53.42.242:80
http://repository.certum.pl/ctnca2.cer
unknown
binary
1.46 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
324
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted
2968
CloudCheck.exe
23.53.42.242:80
repository.certum.pl
Akamai International B.V.
DE
unknown
4
System
192.168.100.255:138
whitelisted
2968
CloudCheck.exe
8.241.9.126:80
ctldl.windowsupdate.com
LEVEL3
US
unknown

DNS requests

Domain
IP
Reputation
repository.certum.pl
  • 23.53.42.242
  • 23.53.43.41
whitelisted
ctldl.windowsupdate.com
  • 8.241.9.126
  • 8.241.121.254
  • 8.241.9.254
  • 67.27.159.254
  • 8.248.149.254
whitelisted

Threats

No threats detected
No debug info