File name:

a440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin

Full analysis: https://app.any.run/tasks/3ea4bc90-c9d0-4f44-93a4-b7ea4c926df3
Verdict: Malicious activity
Analysis date: June 21, 2025, 17:26:06
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto-reg
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64, for MS Windows, 10 sections
MD5:

FE3C84D9A1572F22F3498E19E48669E0

SHA1:

FBC96222ED826A0BF753AC68AA841562A48CDFF7

SHA256:

A440A5597DE165566EEB12B8808EF88AD5FA2A04A6A4FEF51B1793499D8E7B26

SSDEEP:

98304:EtA8CkNzyGuFvfqJSjV7cZpFItXyENaPlUBI5uMNNPBsg5mlaf2b+T4+TdMI7U/f:E5n1n

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • reg.exe (PID: 316)
      • reg.exe (PID: 984)
      • reg.exe (PID: 6492)
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • a440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin.exe (PID: 2044)
      • a440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin.exe (PID: 6360)
    • Process drops legitimate windows executable

      • a440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin.exe (PID: 2044)
      • a440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin.exe (PID: 6360)
    • Application launched itself

      • a440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin.exe (PID: 2044)
      • upgngcodhcfv.exe (PID: 3740)
      • upgngcodhcfv.exe (PID: 3092)
    • Uses REG/REGEDIT.EXE to modify registry

      • a440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin.exe (PID: 6360)
      • upgngcodhcfv.exe (PID: 2808)
      • upgngcodhcfv.exe (PID: 5184)
    • Executable content was dropped or overwritten

      • a440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin.exe (PID: 6360)
    • Starts itself from another location

      • a440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin.exe (PID: 6360)
  • INFO

    • The sample compiled with english language support

      • a440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin.exe (PID: 2044)
      • a440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin.exe (PID: 6360)
    • Checks supported languages

      • a440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin.exe (PID: 2044)
      • a440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin.exe (PID: 6360)
      • upgngcodhcfv.exe (PID: 3740)
      • upgngcodhcfv.exe (PID: 3092)
      • upgngcodhcfv.exe (PID: 2808)
      • upgngcodhcfv.exe (PID: 5184)
    • Launching a file from a Registry key

      • reg.exe (PID: 316)
      • reg.exe (PID: 6492)
      • reg.exe (PID: 984)
    • Creates files or folders in the user directory

      • a440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin.exe (PID: 6360)
    • Manual execution by a user

      • upgngcodhcfv.exe (PID: 3092)
    • Checks proxy server information

      • slui.exe (PID: 5424)
    • Reads the software policy settings

      • slui.exe (PID: 5424)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:06:20 16:12:18+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14
CodeSize: 434688
InitializedDataSize: 99328
UninitializedDataSize: -
EntryPoint: 0x457c0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
FileVersionNumber: 10.0.19041.3636
ProductVersionNumber: 10.0.19041.3636
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Sxs Tracing Tool
FileVersion: 10.0.19041.3636 (WinBuild.160101.0800)
InternalName: sxstrace.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFileName: sxstrace.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.19041.3636
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
150
Monitored processes
17
Malicious processes
1
Suspicious processes
4

Behavior graph

Click at the process to see the details
start a440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin.exe no specs conhost.exe no specs a440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin.exe reg.exe conhost.exe no specs upgngcodhcfv.exe no specs conhost.exe no specs upgngcodhcfv.exe no specs conhost.exe no specs upgngcodhcfv.exe no specs upgngcodhcfv.exe no specs reg.exe conhost.exe no specs conhost.exe no specs reg.exe conhost.exe no specs slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
316C:\WINDOWS\system32\reg.exe add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "RGZVVRNE" /t REG_SZ /f /d "C:\Users\admin\AppData\Roaming\avrthmriomco\upgngcodhcfv.exe"C:\Windows\System32\reg.exe
a440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
984C:\WINDOWS\system32\reg.exe add "HKCU\SOFTWARE\Microsoft\Windows\CurrentVersion\Run" /v "RGZVVRNE" /t REG_SZ /f /d "C:\Users\admin\AppData\Roaming\avrthmriomco\upgngcodhcfv.exe"C:\Windows\System32\reg.exe
upgngcodhcfv.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Console Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\reg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ws2_32.dll
1028\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exereg.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1520\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exea440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2044"C:\Users\admin\Desktop\a440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin.exe" C:\Users\admin\Desktop\a440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Sxs Tracing Tool
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\desktop\a440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2188\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeupgngcodhcfv.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2808"C:\Users\admin\AppData\Roaming\avrthmriomco\upgngcodhcfv.exe"C:\Users\admin\AppData\Roaming\avrthmriomco\upgngcodhcfv.exeupgngcodhcfv.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Sxs Tracing Tool
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\appdata\roaming\avrthmriomco\upgngcodhcfv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
3092C:\Users\admin\AppData\Roaming\avrthmriomco\upgngcodhcfv.exeC:\Users\admin\AppData\Roaming\avrthmriomco\upgngcodhcfv.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Sxs Tracing Tool
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\appdata\roaming\avrthmriomco\upgngcodhcfv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
3100C:\WINDOWS\system32\conhost.exeC:\Windows\System32\conhost.exeupgngcodhcfv.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
3740"C:\Users\admin\AppData\Roaming\avrthmriomco\upgngcodhcfv.exe"C:\Users\admin\AppData\Roaming\avrthmriomco\upgngcodhcfv.exea440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Sxs Tracing Tool
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\appdata\roaming\avrthmriomco\upgngcodhcfv.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
Total events
3 781
Read events
3 778
Write events
3
Delete events
0

Modification events

(PID) Process:(316) reg.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:RGZVVRNE
Value:
C:\Users\admin\AppData\Roaming\avrthmriomco\upgngcodhcfv.exe
(PID) Process:(984) reg.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:RGZVVRNE
Value:
C:\Users\admin\AppData\Roaming\avrthmriomco\upgngcodhcfv.exe
(PID) Process:(6492) reg.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:RGZVVRNE
Value:
C:\Users\admin\AppData\Roaming\avrthmriomco\upgngcodhcfv.exe
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
6360a440a5597de165566eeb12b8808ef88ad5fa2a04a6a4fef51b1793499d8e7b26.bin.exeC:\Users\admin\AppData\Roaming\avrthmriomco\upgngcodhcfv.exeexecutable
MD5:FE3C84D9A1572F22F3498E19E48669E0
SHA256:A440A5597DE165566EEB12B8808EF88AD5FA2A04A6A4FEF51B1793499D8E7B26
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
32
TCP/UDP connections
45
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
184.24.77.22:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
184.24.77.22:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
13.85.23.206:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
unknown
2228
RUXIMICS.exe
GET
200
184.24.77.22:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1268
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5944
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2228
RUXIMICS.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
304
4.245.163.56:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
unknown
POST
200
40.126.32.76:443
https://login.live.com/RST2.srf
unknown
xml
1.24 Kb
whitelisted
GET
200
4.245.163.56:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
unknown
compressed
23.9 Kb
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2228
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
184.24.77.22:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5944
MoUsoCoreWorker.exe
184.24.77.22:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
2228
RUXIMICS.exe
184.24.77.22:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5944
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
whitelisted
google.com
  • 142.250.185.78
whitelisted
crl.microsoft.com
  • 184.24.77.22
  • 184.24.77.27
  • 184.24.77.6
  • 184.24.77.23
  • 184.24.77.30
  • 184.24.77.28
  • 184.24.77.38
  • 184.24.77.37
  • 184.24.77.24
  • 23.55.104.172
  • 23.55.104.190
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 95.101.149.131
whitelisted
login.live.com
  • 20.190.159.128
  • 40.126.31.2
  • 20.190.159.4
  • 40.126.31.3
  • 20.190.159.130
  • 40.126.31.129
  • 40.126.31.73
  • 40.126.31.0
whitelisted
client.wns.windows.com
  • 172.211.123.248
  • 172.211.123.250
whitelisted
nexusrules.officeapps.live.com
  • 52.111.227.13
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.85.23.206
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
No debug info