| File name: | CheraxLoader.exe |
| Full analysis: | https://app.any.run/tasks/9d1056eb-061c-4c8f-b324-313c7d53f5dc |
| Verdict: | Malicious activity |
| Analysis date: | August 23, 2024, 22:42:53 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows |
| MD5: | BD231EB4A50D36128B576B2AD2202182 |
| SHA1: | 6309C10C96EC5B8531BDFC6E7091B4A64CC7EA1B |
| SHA256: | 9B3F7500A7686B70E3CF97893D2CB9AC5C4A6A66A47C090369F9FA0DF567CB30 |
| SSDEEP: | 98304:CgfnRwE/anfTd3TyNp4XQRoGGVB0HnpBzV:C+nj4kG |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2024:07:25 23:41:41+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 14.4 |
| CodeSize: | 1963520 |
| InitializedDataSize: | 1183744 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x16dd20 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.2097 |
| ProductVersionNumber: | 1.0.0.2097 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Cherax |
| FileDescription: | Cherax Loader |
| FileVersion: | 1.0.0.2097 |
| InternalName: | Cherax.exe |
| LegalCopyright: | Copyright (C) 2019 - 2023 |
| OriginalFileName: | Cherax.exe |
| ProductName: | Cherax Loader |
| ProductVersion: | 1.0.0.2097 |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 1608 | "C:\Users\admin\AppData\Local\Temp\{DA0CBBE8-CAEA-448B-9C50-49ACC9FC3C8D}\.be\VC_redist.x64.exe" -q -burn.elevated BurnPipe.{229C252D-94E9-415C-ABA6-3238D2B7C9A6} {9AB3E48C-9AFA-412A-82CD-CC83AC8C539D} 4056 | C:\Users\admin\AppData\Local\Temp\{DA0CBBE8-CAEA-448B-9C50-49ACC9FC3C8D}\.be\VC_redist.x64.exe | VC_redist.x64.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.40.33810 Exit code: 3010 Version: 14.40.33810.0 | ||||
| 2448 | "C:\Program Files\RUXIM\PLUGscheduler.exe" | C:\Program Files\RUXIM\PLUGScheduler.exe | — | svchost.exe |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Update LifeCycle Component Scheduler Exit code: 0 Version: 10.0.19041.3623 (WinBuild.160101.0800) | ||||
| 2592 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2992 -childID 1 -isForBrowser -prefsHandle 2984 -prefMapHandle 2980 -prefsLen 30371 -prefMapSize 244343 -jsInitHandle 1420 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {ad5c21e5-3ebd-4e14-8adc-5dc1d8e54a7d} 5612 "\\.\pipe\gecko-crash-server-pipe.5612" 20e582d5150 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe |
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 | ||||
| 2668 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=6460 -childID 6 -isForBrowser -prefsHandle 5176 -prefMapHandle 5236 -prefsLen 31959 -prefMapSize 244343 -jsInitHandle 1420 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {e20cf7cb-72dd-44db-977c-dec73f005d2b} 5612 "\\.\pipe\gecko-crash-server-pipe.5612" 20e59a15f50 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe |
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 | ||||
| 4000 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5208 -parentBuildID 20240213221259 -sandboxingKind 0 -prefsHandle 5244 -prefMapHandle 5272 -prefsLen 35696 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {c5f58ecb-794c-48c8-b22a-e1c1198a13c7} 5612 "\\.\pipe\gecko-crash-server-pipe.5612" 20e5b644510 utility | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe |
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 | ||||
| 4056 | "C:\Users\admin\AppData\Local\Temp\{2C91F034-9FCD-4956-B664-ADFF4539CC2D}\.cr\VC_redist.x64.exe" -burn.clean.room="C:\Users\admin\Downloads\VC_redist.x64.exe" -burn.filehandle.attached=732 -burn.filehandle.self=736 | C:\Users\admin\AppData\Local\Temp\{2C91F034-9FCD-4956-B664-ADFF4539CC2D}\.cr\VC_redist.x64.exe | VC_redist.x64.exe | |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Visual C++ 2015-2022 Redistributable (x64) - 14.40.33810 Exit code: 3010 Version: 14.40.33810.0 | ||||
| 4264 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5540 -childID 3 -isForBrowser -prefsHandle 5520 -prefMapHandle 5444 -prefsLen 31902 -prefMapSize 244343 -jsInitHandle 1420 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {9d059384-1198-4fac-b7b6-997708c55a27} 5612 "\\.\pipe\gecko-crash-server-pipe.5612" 20e5d675850 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe |
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 | ||||
| 4268 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5756 -childID 4 -isForBrowser -prefsHandle 5684 -prefMapHandle 5544 -prefsLen 31902 -prefMapSize 244343 -jsInitHandle 1420 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {24c9739c-e917-4f8e-b731-b46e700bff1d} 5612 "\\.\pipe\gecko-crash-server-pipe.5612" 20e5d675a10 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe |
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 | ||||
| 4552 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=5676 -childID 5 -isForBrowser -prefsHandle 5656 -prefMapHandle 5660 -prefsLen 31902 -prefMapSize 244343 -jsInitHandle 1420 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {a7cb258e-92fa-4723-9c32-6520aa00ac93} 5612 "\\.\pipe\gecko-crash-server-pipe.5612" 20e5d675d90 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe |
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 | ||||
| 4616 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=4536 -childID 2 -isForBrowser -prefsHandle 4528 -prefMapHandle 4524 -prefsLen 35589 -prefMapSize 244343 -jsInitHandle 1420 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {55d912cb-d37e-4cf4-b915-3c95a33b4fed} 5612 "\\.\pipe\gecko-crash-server-pipe.5612" 20e58b31310 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe |
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Version: 123.0 | ||||
| (PID) Process: | (6180) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Launcher |
Value: 7E7B15FE00000000 | |||
| (PID) Process: | (6184) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Browser |
Value: F04B16FE00000000 | |||
| (PID) Process: | (6184) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Progress |
Value: 0 | |||
| (PID) Process: | (6184) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Progress |
Value: 1 | |||
| (PID) Process: | (6184) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Installer\308046B0AF4A39CB |
| Operation: | delete value | Name: | installer.taskbarpin.win10.enabled |
Value: | |||
| (PID) Process: | (6184) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Launcher |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry |
Value: 0 | |||
| (PID) Process: | (6184) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe |
Value: 0 | |||
| (PID) Process: | (6184) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\PreXULSkeletonUISettings |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox\firefox.exe|Theme |
Value: 1 | |||
| (PID) Process: | (6184) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableTelemetry |
Value: 1 | |||
| (PID) Process: | (6184) firefox.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\Default Browser Agent |
| Operation: | write | Name: | C:\Program Files\Mozilla Firefox|DisableDefaultBrowserAgent |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6184 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 6184 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cert9.db-journal | binary | |
MD5:11C2C38AE541B6C324B77427AC632368 | SHA256:EC395F311426DC50238F00B9E8F3E035F4E32DC18B8BE5153F5BDAFD0C56133A | |||
| 6184 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json.tmp | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 6184 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\storage\permanent\chrome\idb\3870112724rsegmnoittet-es.sqlite | — | |
MD5:— | SHA256:— | |||
| 6184 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cookies.sqlite-shm | binary | |
MD5:B7C14EC6110FA820CA6B65F5AEC85911 | SHA256:FD4C9FDA9CD3F9AE7C962B0DDF37232294D55580E1AA165AA06129B8549389EB | |||
| 6184 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\cert9.db | binary | |
MD5:9C086DFD1B3F99733B145BA85A985BDA | SHA256:CE20F2A4759C05B3D294C4AF44C3EB5F323F4E6537E918CF63D2F247D33567E8 | |||
| 6184 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\prefs-1.js | text | |
MD5:A1EFCA51104F8DA8AC0D081E9896C22D | SHA256:BAE130BECD49596DA65AD79109C45641AFDA7CCE46F529BE5CFA0496C4E39287 | |||
| 6184 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\sessionCheckpoints.json | binary | |
MD5:EA8B62857DFDBD3D0BE7D7E4A954EC9A | SHA256:792955295AE9C382986222C6731C5870BD0E921E7F7E34CC4615F5CD67F225DA | |||
| 6184 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\AlternateServices.bin | binary | |
MD5:866A784DBA2F6CEBFDB2FAF1EFEBC332 | SHA256:48B719029CFECEB29FF7D2358D3F91D9D220D53C86F1465E80F6917FAEB6EB80 | |||
| 6184 | firefox.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\9kie7cg6.default-release\protections.sqlite-journal | binary | |
MD5:478E64BDEEC20EB03BE964861538FF30 | SHA256:19E36261C508CA7EF26FB1F349904A4E792E94EB87155671D406552C0D13EF2E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
888 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7104 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
888 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
888 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6184 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | whitelisted |
6184 | firefox.exe | POST | — | 142.250.184.227:80 | http://o.pki.goog/wr2 | unknown | — | — | unknown |
6184 | firefox.exe | POST | 200 | 184.24.77.67:80 | http://r11.o.lencr.org/ | unknown | — | — | unknown |
6184 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/success.txt?ipv4 | unknown | — | — | whitelisted |
6184 | firefox.exe | POST | 200 | 184.24.77.67:80 | http://r11.o.lencr.org/ | unknown | — | — | unknown |
6184 | firefox.exe | POST | 200 | 184.24.77.67:80 | http://r10.o.lencr.org/ | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2580 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5504 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
3260 | svchost.exe | 40.113.110.67:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
888 | svchost.exe | 20.190.160.22:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
888 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
7104 | backgroundTaskHost.exe | 20.74.47.205:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | unknown |
7104 | backgroundTaskHost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
arc.msn.com |
| whitelisted |
detectportal.firefox.com |
| whitelisted |
prod.detectportal.prod.cloudops.mozgcp.net |
| whitelisted |
contile.services.mozilla.com |
| whitelisted |
example.org |
| whitelisted |