File name:

antimicrox-3.5.0-Windows-AMD64.exe

Full analysis: https://app.any.run/tasks/571081de-d697-446f-b50e-aff6a8123a3b
Verdict: Malicious activity
Analysis date: January 06, 2025, 08:02:54
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows, 9 sections
MD5:

C378C34E5512DD0224B3D55C4CBBA014

SHA1:

EA1E62A93A315FB129E57B5D9A7882AA2A039AE9

SHA256:

923E2A18BE68CD11E39D105B4FC42E13848BA6C6B2236CB780249BACB011F717

SSDEEP:

98304:upUiG6Y7v03TkRZTqE8IehrXUL+hkUtnmY8nr26G+PIbWIpcRrikGFQ+XNrl22/U:fR0ElAvWmp4C/g6wE07YWM7BCclC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • antimicrox-3.5.0-Windows-AMD64.exe (PID: 6644)
    • Creates a software uninstall entry

      • antimicrox-3.5.0-Windows-AMD64.exe (PID: 6644)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • antimicrox-3.5.0-Windows-AMD64.exe (PID: 6644)
    • The process creates files with name similar to system file names

      • antimicrox-3.5.0-Windows-AMD64.exe (PID: 6644)
  • INFO

    • Create files in a temporary directory

      • antimicrox-3.5.0-Windows-AMD64.exe (PID: 6644)
    • Checks supported languages

      • antimicrox-3.5.0-Windows-AMD64.exe (PID: 6644)
    • Reads the computer name

      • antimicrox-3.5.0-Windows-AMD64.exe (PID: 6644)
      • antimicrox.exe (PID: 6352)
    • Creates files in the program directory

      • antimicrox-3.5.0-Windows-AMD64.exe (PID: 6644)
    • The sample compiled with english language support

      • antimicrox-3.5.0-Windows-AMD64.exe (PID: 6644)
    • Manual execution by a user

      • antimicrox.exe (PID: 6352)
    • Reads Environment values

      • antimicrox-3.5.0-Windows-AMD64.exe (PID: 6644)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:05:28 20:31:59+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, No debug
PEType: PE32+
LinkerVersion: 2.42
CodeSize: 35840
InitializedDataSize: 73728
UninitializedDataSize: 402432
EntryPoint: 0x4280
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 5.2
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
123
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start antimicrox-3.5.0-windows-amd64.exe antimicrox.exe no specs antimicrox-3.5.0-windows-amd64.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6352"C:\Program Files\AntiMicroX\bin\antimicrox.exe" C:\Program Files\AntiMicroX\bin\antimicrox.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\program files\antimicrox\bin\antimicrox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6480"C:\Users\admin\AppData\Local\Temp\antimicrox-3.5.0-Windows-AMD64.exe" C:\Users\admin\AppData\Local\Temp\antimicrox-3.5.0-Windows-AMD64.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\antimicrox-3.5.0-windows-amd64.exe
c:\windows\system32\ntdll.dll
6644"C:\Users\admin\AppData\Local\Temp\antimicrox-3.5.0-Windows-AMD64.exe" C:\Users\admin\AppData\Local\Temp\antimicrox-3.5.0-Windows-AMD64.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\antimicrox-3.5.0-windows-amd64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
681
Read events
664
Write events
17
Delete events
0

Modification events

(PID) Process:(6644) antimicrox-3.5.0-Windows-AMD64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiMicroX
Operation:writeName:DisplayName
Value:
AntiMicroX
(PID) Process:(6644) antimicrox-3.5.0-Windows-AMD64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiMicroX
Operation:writeName:NoModify
Value:
1
(PID) Process:(6644) antimicrox-3.5.0-Windows-AMD64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiMicroX
Operation:writeName:DisplayIcon
Value:
C:\Program Files\AntiMicroX\bin\antimicrox.exe
(PID) Process:(6644) antimicrox-3.5.0-Windows-AMD64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiMicroX
Operation:writeName:HelpLink
Value:
http:\\github.com/AntiMicroX/antimicrox/wiki
(PID) Process:(6644) antimicrox-3.5.0-Windows-AMD64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiMicroX
Operation:writeName:URLInfoAbout
Value:
http:\\github.com/AntiMicroX/antimicrox
(PID) Process:(6644) antimicrox-3.5.0-Windows-AMD64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiMicroX
Operation:writeName:StartMenu
Value:
AntiMicroX
(PID) Process:(6644) antimicrox-3.5.0-Windows-AMD64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiMicroX
Operation:writeName:DoNotAddToPath
Value:
0
(PID) Process:(6644) antimicrox-3.5.0-Windows-AMD64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiMicroX
Operation:writeName:AddToPathAllUsers
Value:
0
(PID) Process:(6644) antimicrox-3.5.0-Windows-AMD64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiMicroX
Operation:writeName:AddToPathCurrentUser
Value:
1
(PID) Process:(6644) antimicrox-3.5.0-Windows-AMD64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\AntiMicroX
Operation:writeName:InstallToDesktop
Value:
1
Executable files
20
Suspicious files
30
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
6644antimicrox-3.5.0-Windows-AMD64.exeC:\Users\admin\AppData\Local\Temp\nsi5E03.tmp\InstallOptions.dllexecutable
MD5:A7D3A18DDC6206B7D980A40700EA6619
SHA256:C555C346CC1F80FF0CB9AEAAB8875A10C15EA4E5CF445A0F1597363FCF686924
6644antimicrox-3.5.0-Windows-AMD64.exeC:\Users\admin\AppData\Local\Temp\nsi5E03.tmp\UserInfo.dllexecutable
MD5:5DF25C042BDDA748D1F396B4FE070EDE
SHA256:C9DD715D31C8CDF763F5EDC92B8228DF617BC528D7F558D6E531434C62A4B37B
6644antimicrox-3.5.0-Windows-AMD64.exeC:\Program Files\AntiMicroX\bin\Qt6Network.dllexecutable
MD5:6475F7DD3EB936A95FCD3F542C1F91F5
SHA256:1CCEB81520DAC24928C5D0677643741A895E6B85EAD593236B59110E1AAF3546
6644antimicrox-3.5.0-Windows-AMD64.exeC:\Program Files\AntiMicroX\bin\SDL2.dllexecutable
MD5:B2514DA39175D249B3D74CAF2FD64004
SHA256:AE168D45449E24B4BAFE6AEED16BFB89E01453DB4B83D7D0AC884F9F33125ED1
6644antimicrox-3.5.0-Windows-AMD64.exeC:\Program Files\AntiMicroX\bin\libgcc_s_seh-1.dllexecutable
MD5:00A3E9C595821B5EBEA01E04C8B5D271
SHA256:0E057FCCB0E7656BD096BF25A4714E74245EA02B644DAFCC2106F8C524FCC535
6644antimicrox-3.5.0-Windows-AMD64.exeC:\Users\admin\AppData\Local\Temp\nsi5E03.tmp\ioSpecial.initext
MD5:E2D5070BC28DB1AC745613689FF86067
SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0
6644antimicrox-3.5.0-Windows-AMD64.exeC:\Users\admin\AppData\Local\Temp\nsi5E03.tmp\NSIS.InstallOptions.initext
MD5:4CEC39662B98A47A3758AD6DD0150322
SHA256:A9DD686BC389B59966A3DA679C530664BD61D7DEF9CE561DA738CDD735993DB2
6644antimicrox-3.5.0-Windows-AMD64.exeC:\Users\admin\AppData\Local\Temp\nsi5E03.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
6644antimicrox-3.5.0-Windows-AMD64.exeC:\Users\admin\AppData\Local\Temp\nsi5E03.tmp\modern-header.bmpimage
MD5:6AC8F15AAFCCDA554A2668DE25791DB9
SHA256:14B522C61AEC3A6D9D78500DD3B3F7D7984BC11C7F111818CE795427A5A4430F
6644antimicrox-3.5.0-Windows-AMD64.exeC:\Users\admin\AppData\Local\Temp\nsi5E03.tmp\StartMenu.dllexecutable
MD5:65C301D9A85F4342CDEF7FEDEABAFD5D
SHA256:48765294AA273EC2FD55CC5F9301E138B4D56A9F6D00FCF24473788E64B52BFD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
33
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
2.16.164.49:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
1.01 Kb
whitelisted
GET
200
184.30.230.103:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
973 b
whitelisted
GET
200
184.30.230.103:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
US
binary
973 b
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
313 b
whitelisted
2464
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
US
binary
471 b
whitelisted
7000
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
408 b
whitelisted
7000
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
418 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5732
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2.16.164.49:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
184.30.230.103:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
40.126.32.68:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.23.227.208:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.104.136.2
  • 20.73.194.208
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.72
whitelisted
www.microsoft.com
  • 184.30.230.103
  • 184.30.21.171
whitelisted
google.com
  • 142.250.185.142
unknown
login.live.com
  • 40.126.32.68
  • 20.190.160.22
  • 40.126.32.133
  • 20.190.160.17
  • 40.126.32.138
  • 40.126.32.140
  • 40.126.32.72
  • 40.126.32.76
whitelisted
www.bing.com
  • 2.23.227.208
  • 2.23.227.221
  • 2.23.227.215
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 23.56.254.14
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted

Threats

No threats detected
No debug info