File name:

9573141b32182ee7824e02e5a67d65ed4f6d489cd06362b487ddbfbbefb592db

Full analysis: https://app.any.run/tasks/01d3db97-d97b-480a-9b0c-7fd7fe3ac3e5
Verdict: Malicious activity
Analysis date: January 10, 2025, 18:54:14
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

3F0717E382B7B43D2181E7C4A1A7BE07

SHA1:

11BC6FF6802F67509CE887AC1C41E251D9BF9B62

SHA256:

9573141B32182EE7824E02E5A67D65ED4F6D489CD06362B487DDBFBBEFB592DB

SSDEEP:

24576:jlhP9j/dFUO1J2PkNIzxbok+q2A0YlJykGAOLpD/Mc6SgCgZfASq1k:jlhP9j/jUO3VNIzxbok+q2A0YlJykGAV

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Executing a file with an untrusted certificate

      • 9573141b32182ee7824e02e5a67d65ed4f6d489cd06362b487ddbfbbefb592db.exe (PID: 4628)
    • Uses Task Scheduler to run other applications

      • 9573141b32182ee7824e02e5a67d65ed4f6d489cd06362b487ddbfbbefb592db.exe (PID: 4628)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • 9573141b32182ee7824e02e5a67d65ed4f6d489cd06362b487ddbfbbefb592db.exe (PID: 4628)
    • Executable content was dropped or overwritten

      • 9573141b32182ee7824e02e5a67d65ed4f6d489cd06362b487ddbfbbefb592db.exe (PID: 4628)
  • INFO

    • Creates files or folders in the user directory

      • 9573141b32182ee7824e02e5a67d65ed4f6d489cd06362b487ddbfbbefb592db.exe (PID: 4628)
    • Create files in a temporary directory

      • 9573141b32182ee7824e02e5a67d65ed4f6d489cd06362b487ddbfbbefb592db.exe (PID: 4628)
    • Reads the computer name

      • 9573141b32182ee7824e02e5a67d65ed4f6d489cd06362b487ddbfbbefb592db.exe (PID: 4628)
    • Process checks computer location settings

      • 9573141b32182ee7824e02e5a67d65ed4f6d489cd06362b487ddbfbbefb592db.exe (PID: 4628)
    • Checks supported languages

      • RegSvcs.exe (PID: 2144)
      • 9573141b32182ee7824e02e5a67d65ed4f6d489cd06362b487ddbfbbefb592db.exe (PID: 4628)
    • Reads the machine GUID from the registry

      • 9573141b32182ee7824e02e5a67d65ed4f6d489cd06362b487ddbfbbefb592db.exe (PID: 4628)
    • The process uses the downloaded file

      • 9573141b32182ee7824e02e5a67d65ed4f6d489cd06362b487ddbfbbefb592db.exe (PID: 4628)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.scr | Windows screen saver (46.4)
.dll | Win32 Dynamic Link Library (generic) (23.3)
.exe | Win32 Executable (generic) (15.9)
.exe | Generic Win/DOS Executable (7.1)
.exe | DOS Executable Generic (7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:12:06 02:04:34+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 729088
InitializedDataSize: 6144
UninitializedDataSize: -
EntryPoint: 0xb3e96
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.781
ProductVersionNumber: 2.0.0.781
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: PDF document
CompanyName: Adobe Reader
FileDescription: Microsoft PDF Document
FileVersion: 2.0.0.781
InternalName: NRDCa.exe
LegalCopyright: Adobe Inc. All rights reserved
LegalTrademarks: PDF document
OriginalFileName: NRDCa.exe
ProductName: Adobe Reader
ProductVersion: 2.0.0.781
AssemblyVersion: 2.0.0.781
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
130
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 9573141b32182ee7824e02e5a67d65ed4f6d489cd06362b487ddbfbbefb592db.exe schtasks.exe no specs conhost.exe no specs regsvcs.exe no specs regsvcs.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
4628"C:\Users\admin\AppData\Local\Temp\9573141b32182ee7824e02e5a67d65ed4f6d489cd06362b487ddbfbbefb592db.exe" C:\Users\admin\AppData\Local\Temp\9573141b32182ee7824e02e5a67d65ed4f6d489cd06362b487ddbfbbefb592db.exe
explorer.exe
User:
admin
Company:
Adobe Reader
Integrity Level:
MEDIUM
Description:
Microsoft PDF Document
Exit code:
0
Version:
2.0.0.781
Modules
Images
c:\users\admin\appdata\local\temp\9573141b32182ee7824e02e5a67d65ed4f6d489cd06362b487ddbfbbefb592db.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
3640"C:\Windows\System32\schtasks.exe" /Create /TN "Updates\SgPjgFGj" /XML "C:\Users\admin\AppData\Local\Temp\tmpE449.tmp"C:\Windows\SysWOW64\schtasks.exe9573141b32182ee7824e02e5a67d65ed4f6d489cd06362b487ddbfbbefb592db.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Scheduler Configuration Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
5548\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2548"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe9573141b32182ee7824e02e5a67d65ed4f6d489cd06362b487ddbfbbefb592db.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Services Installation Utility
Exit code:
4294967295
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regsvcs.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
2144"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe9573141b32182ee7824e02e5a67d65ed4f6d489cd06362b487ddbfbbefb592db.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Services Installation Utility
Exit code:
0
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regsvcs.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
490
Read events
490
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
46289573141b32182ee7824e02e5a67d65ed4f6d489cd06362b487ddbfbbefb592db.exeC:\Users\admin\AppData\Roaming\SgPjgFGj.exeexecutable
MD5:3F0717E382B7B43D2181E7C4A1A7BE07
SHA256:9573141B32182EE7824E02E5A67D65ED4F6D489CD06362B487DDBFBBEFB592DB
46289573141b32182ee7824e02e5a67d65ed4f6d489cd06362b487ddbfbbefb592db.exeC:\Users\admin\AppData\Local\Temp\tmpE449.tmpxml
MD5:8F574AC530D1FD1D901FD76504999F1C
SHA256:9D14E7768E6D6DE23AB4BDD990847D268371E4D1BBEE8D376C32ED30723A2E50
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
32
DNS requests
22
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4144
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5540
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
4144
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
23.48.23.150:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5064
SearchApp.exe
104.126.37.131:443
www.bing.com
Akamai International B.V.
DE
unknown
4
System
192.168.100.255:137
unknown
4712
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4008
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
23.48.23.150:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
unknown
1176
svchost.exe
40.126.32.74:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
4
System
192.168.100.255:138
unknown
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 104.126.37.131
  • 104.126.37.145
  • 104.126.37.139
unknown
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
  • 4.231.128.59
unknown
google.com
  • 142.250.185.110
unknown
crl.microsoft.com
  • 23.48.23.150
  • 23.48.23.137
  • 23.48.23.159
  • 23.48.23.190
  • 23.48.23.138
  • 23.48.23.191
  • 23.48.23.194
  • 23.48.23.147
  • 23.48.23.146
unknown
www.microsoft.com
  • 184.30.21.171
  • 2.23.246.101
unknown
login.live.com
  • 40.126.32.74
  • 40.126.32.133
  • 20.190.160.17
  • 40.126.32.76
  • 20.190.160.20
  • 40.126.32.138
  • 40.126.32.134
  • 40.126.32.140
  • 20.190.159.75
  • 40.126.31.69
  • 20.190.159.0
  • 40.126.31.67
  • 20.190.159.23
  • 20.190.159.64
  • 40.126.31.71
  • 20.190.159.68
unknown
ocsp.digicert.com
  • 192.229.221.95
unknown
go.microsoft.com
  • 23.35.238.131
unknown
slscr.update.microsoft.com
  • 20.109.210.53
unknown
arc.msn.com
  • 20.31.169.57
unknown

Threats

No threats detected
No debug info