File name:

CloudCheck.exe

Full analysis: https://app.any.run/tasks/e93f7135-f544-42e2-80c3-ef3c6fa5827e
Verdict: Malicious activity
Analysis date: October 29, 2023, 12:16:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64 (stripped to external PDB), for MS Windows
MD5:

81C4E0D97B822D5D2802B6ECEC9AF8BF

SHA1:

C57C66F2D29D8F85ED4D3A348D6A7CC76105A43B

SHA256:

A83E4D482B1E12406BC6D4809623B3DFF088DD30406D4A7BC1FBAE009A0D7207

SSDEEP:

98304:C8aQSkFr66I4l8mUS7sxw/gyoOa/Ahv9PU:Rs

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Internet Settings

      • CloudCheck.exe (PID: 1392)
    • Reads settings of System Certificates

      • CloudCheck.exe (PID: 1392)
    • Reads security settings of Internet Explorer

      • CloudCheck.exe (PID: 1392)
    • Checks Windows Trust Settings

      • CloudCheck.exe (PID: 1392)
  • INFO

    • Checks supported languages

      • CloudCheck.exe (PID: 1392)
    • Creates files or folders in the user directory

      • CloudCheck.exe (PID: 1392)
    • Create files in a temporary directory

      • CloudCheck.exe (PID: 1392)
    • Reads the computer name

      • CloudCheck.exe (PID: 1392)
    • Reads the machine GUID from the registry

      • CloudCheck.exe (PID: 1392)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (71.5)
.scr | Windows screen saver (21.7)
.exe | Generic Win/DOS Executable (3.3)
.exe | DOS Executable Generic (3.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2023:06:27 16:17:44+02:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Large address aware, No debug
PEType: PE32+
LinkerVersion: 8
CodeSize: 3387392
InitializedDataSize: 2407424
UninitializedDataSize: -
EntryPoint: 0x7420
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 2023.3.450.0
ProductVersionNumber: 2023.3.450.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Cloudflare
FileDescription: Cloudflare WARP
FileVersion: 2023.3.450.0
InternalName: Cloudflare WARP.dll
LegalCopyright: (c) 2021, Cloudflare Inc.
OriginalFileName: Cloudflare WARP.dll
ProductName: Cloudflare WARP
ProductVersion: 2023.3.450.0
AssemblyVersion: 2023.3.450.0
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
30
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start cloudcheck.exe

Process information

PID
CMD
Path
Indicators
Parent process
1392"C:\Users\admin\AppData\Local\Temp\CloudCheck.exe" C:\Users\admin\AppData\Local\Temp\CloudCheck.exe
explorer.exe
User:
admin
Company:
Cloudflare
Integrity Level:
MEDIUM
Description:
Cloudflare WARP
Exit code:
0
Version:
2023.3.450.0
Modules
Images
c:\users\admin\appdata\local\temp\cloudcheck.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
Total events
1 051
Read events
1 036
Write events
15
Delete events
0

Modification events

(PID) Process:(1392) CloudCheck.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\156\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1392) CloudCheck.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Skype.exe
Executable files
0
Suspicious files
6
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1392CloudCheck.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:F3441B8572AAE8801C04F3060B550443
SHA256:6720349E7D82EE0A8E73920D3C2B7CB2912D9FCF2EDB6FD98F2F12820158B0BF
1392CloudCheck.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:DD48B4368159B6F60FDE21D34255BCE0
SHA256:52FF576B3093DEDA53CA656392AF4128F8044C8323CF88FD4F1023BC3AE25773
1392CloudCheck.exeC:\Users\admin\AppData\Local\Temp\TarB33F.tmpbinary
MD5:9441737383D21192400ECA82FDA910EC
SHA256:BC3A6E84E41FAEB57E7C21AA3B60C2A64777107009727C5B7C0ED8FE658909E5
1392CloudCheck.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\538F535B7FBDE384E456CC9F5DA5FBABbinary
MD5:6E9DFA27EDE33194542E4572CDC07054
SHA256:4DCF0F293AE45C47C06DD28A926254E9645205E8D0E2A067256B1756FF57B5F7
1392CloudCheck.exeC:\Users\admin\AppData\Local\Temp\CabB33E.tmpcompressed
MD5:F3441B8572AAE8801C04F3060B550443
SHA256:6720349E7D82EE0A8E73920D3C2B7CB2912D9FCF2EDB6FD98F2F12820158B0BF
1392CloudCheck.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\538F535B7FBDE384E456CC9F5DA5FBABbinary
MD5:6D469ED9256D08235B5E747D1E27DBF2
SHA256:B676F2EDDAE8775CD36CB0F63CD1D4603961F49E6265BA013A2F0307B6D0B804
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
8
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1392
CloudCheck.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?2f41e588fd180c9a
unknown
compressed
61.6 Kb
unknown
1392
CloudCheck.exe
GET
200
2.17.100.234:80
http://repository.certum.pl/ctnca2.cer
unknown
binary
1.46 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
324
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
1392
CloudCheck.exe
2.17.100.234:80
repository.certum.pl
Akamai International B.V.
DE
unknown
1956
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
1392
CloudCheck.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted

DNS requests

Domain
IP
Reputation
repository.certum.pl
  • 2.17.100.234
  • 2.17.100.209
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted

Threats

No threats detected
No debug info