File name:

1

Full analysis: https://app.any.run/tasks/1fd1cf94-2b24-4616-9e51-b050e4bd7811
Verdict: Malicious activity
Analysis date: October 03, 2025, 16:33:49
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
zeroaccess
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, 3 sections
MD5:

09C32841C8B38D0EA9041CBF5D7EEE2F

SHA1:

3840803C81A8584B2EF1B6F2D80DB7D2AA7F4D71

SHA256:

ABD690580DE38FAD12A55904A4E896970AAE244F28518C8DD05D5FEF3207115A

SSDEEP:

6144:AZwpXu4UGF/PHCFNMulRmRBEZN2rm6EuFkRFBFkeXSSCbVIj3LtZo:AZwpXUCHCzMq8Oqp1WoQKkc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • ZEROACCESS has been detected (SURICATA)

      • 1.exe (PID: 2840)
    • ZEROACCESS mutex has been found

      • 1.exe (PID: 2840)
    • ZEROACCESS has been detected

      • 1.exe (PID: 2840)
    • Executing a file with an untrusted certificate

      • InstallFlashPlayer.exe (PID: 5836)
  • SUSPICIOUS

    • Executes application which crashes

      • InstallFlashPlayer.exe (PID: 5836)
    • Creates/Modifies COM task schedule object

      • 1.exe (PID: 2840)
    • Reads the date of Windows installation

      • 1.exe (PID: 2840)
    • Executable content was dropped or overwritten

      • 1.exe (PID: 2840)
    • Starts CMD.EXE for commands execution

      • 1.exe (PID: 2840)
    • Reads security settings of Internet Explorer

      • InstallFlashPlayer.exe (PID: 5836)
      • 1.exe (PID: 2840)
    • There is functionality for taking screenshot (YARA)

      • InstallFlashPlayer.exe (PID: 5836)
  • INFO

    • Reads the machine GUID from the registry

      • 1.exe (PID: 2840)
    • Checks supported languages

      • 1.exe (PID: 2840)
      • InstallFlashPlayer.exe (PID: 5836)
    • Reads the computer name

      • InstallFlashPlayer.exe (PID: 5836)
      • 1.exe (PID: 2840)
    • Checks proxy server information

      • WerFault.exe (PID: 8168)
      • InstallFlashPlayer.exe (PID: 5836)
    • The sample compiled with english language support

      • 1.exe (PID: 2840)
    • Process checks computer location settings

      • 1.exe (PID: 2840)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 8168)
    • Reads the software policy settings

      • WerFault.exe (PID: 8168)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)
.vxd | VXD Driver (0.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2004:03:30 18:48:45+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, No debug, Bytes reversed hi
PEType: PE32
LinkerVersion: 6
CodeSize: 98057
InitializedDataSize: 80896
UninitializedDataSize: 4096
EntryPoint: 0x2461
OSVersion: 4
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
176
Monitored processes
6
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
2672\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2840"C:\Users\admin\AppData\Local\Temp\1.exe" C:\Users\admin\AppData\Local\Temp\1.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5836"C:\Users\admin\AppData\Local\Temp\InstallFlashPlayer.exe" C:\Users\admin\AppData\Local\Temp\InstallFlashPlayer.exe
1.exe
User:
admin
Company:
Adobe Systems, Inc.
Integrity Level:
HIGH
Description:
Adobe® Flash® Player Installer/Uninstaller 11.0 r1
Version:
11,0,1,152
Modules
Images
c:\users\admin\appdata\local\temp\installflashplayer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
5888"C:\WINDOWS\system32\cmd.exe"C:\Windows\SysWOW64\cmd.exe1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
4294967295
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
7800C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
8168C:\WINDOWS\SysWOW64\WerFault.exe -u -p 5836 -s 1080C:\Windows\SysWOW64\WerFault.exe
InstallFlashPlayer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
Total events
9 169
Read events
9 142
Write events
24
Delete events
3

Modification events

(PID) Process:(2840) 1.exeKey:HKEY_CLASSES_ROOT\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Both
(PID) Process:(2840) 1.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts
Operation:writeName:LastUpdate
Value:
F3FADF6800000000
(PID) Process:(2840) 1.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:SlowContextMenuEntries
Value:
6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000
(PID) Process:(2840) 1.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2840) 1.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2840) 1.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2840) 1.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(5836) InstallFlashPlayer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(5836) InstallFlashPlayer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(5836) InstallFlashPlayer.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
Executable files
3
Suspicious files
6
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
8168WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_InstallFlashPlay_d4966731d7e64ef099bfdb39f821d342393bd79d_bc883789_a5e7f72d-cf49-49a9-bb63-2d64eb8dd770\Report.wer
MD5:
SHA256:
8168WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER1649.tmp.xmlxml
MD5:54F998275FA9F6307614DA291AB91B55
SHA256:3A7BBD7FAD24C0305225F48ACF8D5F58CF16F2BC6A64857862B6D5BFBFD30955
8168WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER1629.tmp.WERInternalMetadata.xmlxml
MD5:76F6CD525CAF9A32F2B169C4262C0BD3
SHA256:D74FB078A20BBBA0EF0501C0FFA731F5C499DF903663B7C2297B86D3A25DF093
28401.exeC:\$Recycle.Bin\S-1-5-21-1693682860-607145093-2874071422-1001\$81b8c3da9d80cef97346aaa39584b477\@binary
MD5:12C2EB28D18F4186FD3D1ACA78C6D037
SHA256:4CA5980679024C4DE93C8F2FB79B6D6F00E8104E6539FC2BA1E5509EF72AECCF
28401.exeC:\$Recycle.Bin\S-1-5-21-1693682860-607145093-2874071422-1001\$81b8c3da9d80cef97346aaa39584b477\nexecutable
MD5:9E0CD37B6D0809CF7D5FA5B521538D0D
SHA256:55D9748F0556576A8D522CF4B8DCFC9717436ADCC487D49B3320770432960DB2
8168WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FEbinary
MD5:48BF1B8162B81DE98FA0EDB855C21EA7
SHA256:BE0E7C21E3C6976C2896B3100E1A0A0D7ACA16943BB57E2DFEB78CC1E07F6F9A
8168WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\21253908F3CB05D51B1C2DA8B681A785binary
MD5:E9F83AA571B48E17A1CF058DF31461BA
SHA256:6833B875CC6488AAEE11E01F3856DFFB9094A409E4DB85C707E01245726F44AB
28401.exeC:\Users\admin\AppData\Local\Temp\msimg32.dllexecutable
MD5:6A4498AE698B1626C5474F4CBFE1FC58
SHA256:F44477C25470C18D2C4CD0A59AC64E8ACDF0F2E1CF0700537AE22937CEE2811E
8168WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\37C951188967C8EB88D99893D9D191FEbinary
MD5:399B8A260A3FE6BB6F2D2DAE89FB82BB
SHA256:0DC7CEC07635BC159BA8B7FB1D7FC9AA00DE1C0C045BD688351878B65EAFF57B
28401.exeC:\Users\admin\AppData\Local\Temp\InstallFlashPlayer.exeexecutable
MD5:2FF9B590342C62748885D459D082295F
SHA256:672EC8DCEAFD429C1A09CFAFBC4951968953E2081E0D97243040DB16EDB24429
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
49
DNS requests
20
Threats
15

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
8168
WerFault.exe
GET
200
23.216.77.5:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
8168
WerFault.exe
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
DE
binary
814 b
whitelisted
3000
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
7084
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
whitelisted
2284
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
whitelisted
6128
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
313 b
whitelisted
5836
InstallFlashPlayer.exe
GET
404
23.197.137.122:80
http://fpdownload.macromedia.com/get/flashplayer/update/current/install/install_all_win_cab_64_ax_sgn.z
US
html
196 b
whitelisted
3000
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2852
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6016
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5224
SearchApp.exe
92.123.104.67:443
www.bing.com
Akamai International B.V.
DE
whitelisted
2840
1.exe
194.165.17.3:53
malicious
2840
1.exe
66.85.130.234:53
malicious
4
System
192.168.100.255:138
whitelisted
5836
InstallFlashPlayer.exe
23.197.137.122:80
fpdownload.macromedia.com
Akamai International B.V.
US
whitelisted
8168
WerFault.exe
135.234.160.244:443
watson.events.data.microsoft.com
LUCENT-CIO
US
whitelisted
8168
WerFault.exe
23.216.77.5:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
www.bing.com
  • 92.123.104.67
  • 92.123.104.60
  • 92.123.104.62
  • 92.123.104.59
  • 92.123.104.65
  • 92.123.104.63
  • 92.123.104.11
  • 92.123.104.61
  • 92.123.104.13
whitelisted
google.com
  • 142.250.181.238
whitelisted
j.maxmind.com
shared
fpdownload.macromedia.com
  • 23.197.137.122
whitelisted
watson.events.data.microsoft.com
  • 135.234.160.244
whitelisted
crl.microsoft.com
  • 23.216.77.5
  • 23.216.77.35
  • 23.216.77.38
  • 23.216.77.41
  • 23.216.77.39
  • 23.216.77.42
  • 23.216.77.32
  • 23.216.77.31
  • 23.216.77.36
whitelisted
www.microsoft.com
  • 69.192.161.161
whitelisted
login.live.com
  • 40.126.32.134
  • 40.126.32.68
  • 40.126.32.74
  • 40.126.32.72
  • 20.190.160.2
  • 20.190.160.17
  • 20.190.160.20
  • 20.190.160.14
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted

Threats

PID
Process
Class
Message
2840
1.exe
A Network Trojan was detected
ET MALWARE ZeroAccess udp traffic detected
2840
1.exe
A Network Trojan was detected
ET MALWARE ZeroAccess udp traffic detected
2840
1.exe
A Network Trojan was detected
ET MALWARE ZeroAccess udp traffic detected
2840
1.exe
A Network Trojan was detected
ET MALWARE ZeroAccess udp traffic detected
2840
1.exe
A Network Trojan was detected
ET MALWARE ZeroAccess udp traffic detected
2840
1.exe
A Network Trojan was detected
ET MALWARE ZeroAccess udp traffic detected
2840
1.exe
A Network Trojan was detected
ET MALWARE ZeroAccess udp traffic detected
2840
1.exe
A Network Trojan was detected
ET MALWARE ZeroAccess udp traffic detected
2840
1.exe
A Network Trojan was detected
ET MALWARE ZeroAccess udp traffic detected
2840
1.exe
A Network Trojan was detected
ET MALWARE ZeroAccess udp traffic detected
No debug info