File name:

4

Full analysis: https://app.any.run/tasks/b8607ff1-617b-4a5d-afd0-5a3635db53ac
Verdict: Malicious activity
Threats:

A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices.

Analysis date: October 03, 2025, 16:45:24
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
pushdo
cutwail
backdoor
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

C34A5F5FC1152632B9B1F965419386F6

SHA1:

2D3DE2A099D2F88893817E11F5A54348F9DCA960

SHA256:

A771A51473AB688E632BA4E6717F3FC7D687E75FA8FB9A263DCA1CBE391631E0

SSDEEP:

6144:D7mfvLFFbqyLJacDzkEkncUBc8++UgjD8dQtCwcY7yDSTQp:D7GbmcDzocUBcJ+UWDMkt7yDgQp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • 4.exe (PID: 6536)
    • PUSHDO has been detected (SURICATA)

      • 4.exe (PID: 6536)
    • Connects to the CnC server

      • 4.exe (PID: 6536)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 4.exe (PID: 6536)
    • Reads security settings of Internet Explorer

      • 4.exe (PID: 6536)
    • Contacting a server suspected of hosting an CnC

      • 4.exe (PID: 6536)
  • INFO

    • Reads the computer name

      • 4.exe (PID: 6536)
    • Creates files or folders in the user directory

      • 4.exe (PID: 6536)
    • Checks supported languages

      • 4.exe (PID: 6536)
    • Reads the machine GUID from the registry

      • 4.exe (PID: 6536)
    • Launching a file from a Registry key

      • 4.exe (PID: 6536)
    • Checks proxy server information

      • 4.exe (PID: 6536)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:07:03 05:31:59+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 12
CodeSize: 127488
InitializedDataSize: 191488
UninitializedDataSize: -
EntryPoint: 0x9907
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
168
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
2428C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
2568C:\WINDOWS\splwow64.exe 8192C:\Windows\splwow64.exe4.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Print driver host for applications
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\splwow64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6536"C:\Users\admin\AppData\Local\Temp\4.exe" C:\Users\admin\AppData\Local\Temp\4.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\4.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msimg32.dll
Total events
3 983
Read events
3 972
Write events
11
Delete events
0

Modification events

(PID) Process:(6536) 4.exeKey:HKEY_CURRENT_USER\SOFTWARE\Qrmvilofghwni
Operation:writeName:Bopbulesmo
Value:
B193CF0CBBF7A7570743F2A2DE8E3EED
(PID) Process:(6536) 4.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:gaszilanfofg
Value:
C:\Users\admin\gaszilanfofg.exe
(PID) Process:(6536) 4.exeKey:HKEY_CURRENT_USER\SOFTWARE\Qrmvilofghwni
Operation:writeName:gaszilanfofgWafdogakox
Value:
6A4C15C401B0609C4CBA2965A1510156
(PID) Process:(6536) 4.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6536) 4.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6536) 4.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
1
Suspicious files
1
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
65364.exeC:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1693682860-607145093-2874071422-1001\c5d8393293ce2ba62f117b2c2d55bc3e_bb926e54-e3ca-40fd-ae90-2764341e7792binary
MD5:60806F4F110A6F85831390DAFBB98385
SHA256:219D1A0D4109122414A4EF1B17D392652E94E7492B490EC6FF33EF553D125A4D
65364.exeC:\Users\admin\gaszilanfofg.exeexecutable
MD5:C34A5F5FC1152632B9B1F965419386F6
SHA256:A771A51473AB688E632BA4E6717F3FC7D687E75FA8FB9A263DCA1CBE391631E0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
116
TCP/UDP connections
115
DNS requests
102
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6536
4.exe
POST
301
104.26.3.124:80
http://www.kernsafe.com/
US
html
148 b
malicious
6536
4.exe
POST
51.79.51.72:80
http://www.holleman.us/
CA
malicious
6536
4.exe
POST
301
85.131.197.10:80
http://www.stajum.com/
DE
html
231 b
malicious
6536
4.exe
POST
301
23.235.195.126:80
http://www.quadlock.com/
US
html
242 b
malicious
6536
4.exe
POST
404
13.223.25.84:80
http://www.petsfan.com/
US
html
77 b
malicious
6536
4.exe
POST
301
104.26.3.124:80
http://www.kernsafe.com/
US
html
148 b
malicious
6536
4.exe
POST
301
23.235.195.126:80
http://www.quadlock.com/
US
html
242 b
malicious
6536
4.exe
POST
200
74.208.236.101:80
http://www.myropcb.com/
US
html
55.8 Kb
malicious
6536
4.exe
POST
403
199.60.103.31:80
http://www.cel-cpa.com/
US
text
17 b
malicious
6536
4.exe
POST
404
118.27.125.181:80
http://www.pr-park.com/
JP
html
18.8 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6016
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
8100
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5224
SearchApp.exe
95.101.136.201:443
www.bing.com
Akamai International B.V.
GB
whitelisted
4
System
192.168.100.255:138
whitelisted
6536
4.exe
172.67.201.26:80
www.pcgrate.com
CLOUDFLARENET
US
malicious
6536
4.exe
51.83.242.112:80
www.xaicom.es
OVH SAS
PL
malicious
6536
4.exe
104.26.7.221:80
www.valdal.com
CLOUDFLARENET
US
malicious
6536
4.exe
85.131.197.10:80
www.stajum.com
Link11 GmbH
DE
malicious
6536
4.exe
51.79.51.72:80
www.holleman.us
OVH SAS
CA
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
www.bing.com
  • 95.101.136.201
  • 95.101.136.194
whitelisted
google.com
  • 216.58.206.46
whitelisted
www.pcgrate.com
  • 172.67.201.26
  • 104.21.66.46
malicious
www.valdal.com
  • 104.26.7.221
  • 172.67.73.176
  • 104.26.6.221
malicious
www.xaicom.es
  • 51.83.242.112
malicious
www.stajum.com
  • 85.131.197.10
malicious
www.udesign.biz
malicious
www.mobilnic.net
malicious
www.quadlock.com
  • 23.235.195.126
malicious

Threats

PID
Process
Class
Message
6536
4.exe
Malware Command and Control Activity Detected
ET MALWARE Backdoor.Win32.Pushdo.s Checkin
6536
4.exe
Potentially Bad Traffic
ET INFO Referrer-Policy set to unsafe-url
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info