| File name: | 1 |
| Full analysis: | https://app.any.run/tasks/1fd1cf94-2b24-4616-9e51-b050e4bd7811 |
| Verdict: | Malicious activity |
| Analysis date: | October 03, 2025, 16:33:49 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows, 3 sections |
| MD5: | 09C32841C8B38D0EA9041CBF5D7EEE2F |
| SHA1: | 3840803C81A8584B2EF1B6F2D80DB7D2AA7F4D71 |
| SHA256: | ABD690580DE38FAD12A55904A4E896970AAE244F28518C8DD05D5FEF3207115A |
| SSDEEP: | 6144:AZwpXu4UGF/PHCFNMulRmRBEZN2rm6EuFkRFBFkeXSSCbVIj3LtZo:AZwpXUCHCzMq8Oqp1WoQKkc |
| .dll | | | Win32 Dynamic Link Library (generic) (43.5) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (29.8) |
| .exe | | | Generic Win/DOS Executable (13.2) |
| .exe | | | DOS Executable Generic (13.2) |
| .vxd | | | VXD Driver (0.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2004:03:30 18:48:45+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit, No debug, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 98057 |
| InitializedDataSize: | 80896 |
| UninitializedDataSize: | 4096 |
| EntryPoint: | 0x2461 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2672 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2840 | "C:\Users\admin\AppData\Local\Temp\1.exe" | C:\Users\admin\AppData\Local\Temp\1.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 5836 | "C:\Users\admin\AppData\Local\Temp\InstallFlashPlayer.exe" | C:\Users\admin\AppData\Local\Temp\InstallFlashPlayer.exe | 1.exe | ||||||||||||
User: admin Company: Adobe Systems, Inc. Integrity Level: HIGH Description: Adobe® Flash® Player Installer/Uninstaller 11.0 r1 Version: 11,0,1,152 Modules
| |||||||||||||||
| 5888 | "C:\WINDOWS\system32\cmd.exe" | C:\Windows\SysWOW64\cmd.exe | — | 1.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 4294967295 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 7800 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 8168 | C:\WINDOWS\SysWOW64\WerFault.exe -u -p 5836 -s 1080 | C:\Windows\SysWOW64\WerFault.exe | InstallFlashPlayer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Problem Reporting Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (2840) 1.exe | Key: | HKEY_CLASSES_ROOT\CLSID\{fbeb8a05-beee-4442-804e-409d6c4515e9}\InprocServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Both | |||
| (PID) Process: | (2840) 1.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\OneDrive\Accounts |
| Operation: | write | Name: | LastUpdate |
Value: F3FADF6800000000 | |||
| (PID) Process: | (2840) 1.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | SlowContextMenuEntries |
Value: 6024B221EA3A6910A2DC08002B30309D0A010000BD0E0C47735D584D9CEDE91E22E23282770100000114020000000000C0000000000000468D0000006078A409B011A54DAFA526D86198A780390100009AD298B2EDA6DE11BA8CA68E55D895936E000000 | |||
| (PID) Process: | (2840) 1.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2840) 1.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2840) 1.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2840) 1.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (5836) InstallFlashPlayer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (5836) InstallFlashPlayer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (5836) InstallFlashPlayer.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 8168 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_InstallFlashPlay_d4966731d7e64ef099bfdb39f821d342393bd79d_bc883789_a5e7f72d-cf49-49a9-bb63-2d64eb8dd770\Report.wer | — | |
MD5:— | SHA256:— | |||
| 8168 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WER1649.tmp.xml | xml | |
MD5:54F998275FA9F6307614DA291AB91B55 | SHA256:3A7BBD7FAD24C0305225F48ACF8D5F58CF16F2BC6A64857862B6D5BFBFD30955 | |||
| 8168 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WER1629.tmp.WERInternalMetadata.xml | xml | |
MD5:76F6CD525CAF9A32F2B169C4262C0BD3 | SHA256:D74FB078A20BBBA0EF0501C0FFA731F5C499DF903663B7C2297B86D3A25DF093 | |||
| 2840 | 1.exe | C:\$Recycle.Bin\S-1-5-21-1693682860-607145093-2874071422-1001\$81b8c3da9d80cef97346aaa39584b477\@ | binary | |
MD5:12C2EB28D18F4186FD3D1ACA78C6D037 | SHA256:4CA5980679024C4DE93C8F2FB79B6D6F00E8104E6539FC2BA1E5509EF72AECCF | |||
| 2840 | 1.exe | C:\$Recycle.Bin\S-1-5-21-1693682860-607145093-2874071422-1001\$81b8c3da9d80cef97346aaa39584b477\n | executable | |
MD5:9E0CD37B6D0809CF7D5FA5B521538D0D | SHA256:55D9748F0556576A8D522CF4B8DCFC9717436ADCC487D49B3320770432960DB2 | |||
| 8168 | WerFault.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FE | binary | |
MD5:48BF1B8162B81DE98FA0EDB855C21EA7 | SHA256:BE0E7C21E3C6976C2896B3100E1A0A0D7ACA16943BB57E2DFEB78CC1E07F6F9A | |||
| 8168 | WerFault.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\21253908F3CB05D51B1C2DA8B681A785 | binary | |
MD5:E9F83AA571B48E17A1CF058DF31461BA | SHA256:6833B875CC6488AAEE11E01F3856DFFB9094A409E4DB85C707E01245726F44AB | |||
| 2840 | 1.exe | C:\Users\admin\AppData\Local\Temp\msimg32.dll | executable | |
MD5:6A4498AE698B1626C5474F4CBFE1FC58 | SHA256:F44477C25470C18D2C4CD0A59AC64E8ACDF0F2E1CF0700537AE22937CEE2811E | |||
| 8168 | WerFault.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\37C951188967C8EB88D99893D9D191FE | binary | |
MD5:399B8A260A3FE6BB6F2D2DAE89FB82BB | SHA256:0DC7CEC07635BC159BA8B7FB1D7FC9AA00DE1C0C045BD688351878B65EAFF57B | |||
| 2840 | 1.exe | C:\Users\admin\AppData\Local\Temp\InstallFlashPlayer.exe | executable | |
MD5:2FF9B590342C62748885D459D082295F | SHA256:672EC8DCEAFD429C1A09CFAFBC4951968953E2081E0D97243040DB16EDB24429 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
8168 | WerFault.exe | GET | 200 | 23.216.77.5:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | DE | binary | 825 b | whitelisted |
8168 | WerFault.exe | GET | 200 | 69.192.161.161:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | DE | binary | 814 b | whitelisted |
3000 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | US | binary | 471 b | whitelisted |
7084 | backgroundTaskHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | US | binary | 471 b | whitelisted |
2284 | backgroundTaskHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | US | binary | 471 b | whitelisted |
6128 | backgroundTaskHost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | US | binary | 313 b | whitelisted |
5836 | InstallFlashPlayer.exe | GET | 404 | 23.197.137.122:80 | http://fpdownload.macromedia.com/get/flashplayer/update/current/install/install_all_win_cab_64_ax_sgn.z | US | html | 196 b | whitelisted |
3000 | svchost.exe | GET | 200 | 184.30.131.245:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | US | binary | 471 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2852 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6016 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5224 | SearchApp.exe | 92.123.104.67:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
2840 | 1.exe | 194.165.17.3:53 | — | — | — | malicious |
2840 | 1.exe | 66.85.130.234:53 | — | — | — | malicious |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5836 | InstallFlashPlayer.exe | 23.197.137.122:80 | fpdownload.macromedia.com | Akamai International B.V. | US | whitelisted |
8168 | WerFault.exe | 135.234.160.244:443 | watson.events.data.microsoft.com | LUCENT-CIO | US | whitelisted |
8168 | WerFault.exe | 23.216.77.5:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
google.com |
| whitelisted |
j.maxmind.com |
| shared |
fpdownload.macromedia.com |
| whitelisted |
watson.events.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2840 | 1.exe | A Network Trojan was detected | ET MALWARE ZeroAccess udp traffic detected |
2840 | 1.exe | A Network Trojan was detected | ET MALWARE ZeroAccess udp traffic detected |
2840 | 1.exe | A Network Trojan was detected | ET MALWARE ZeroAccess udp traffic detected |
2840 | 1.exe | A Network Trojan was detected | ET MALWARE ZeroAccess udp traffic detected |
2840 | 1.exe | A Network Trojan was detected | ET MALWARE ZeroAccess udp traffic detected |
2840 | 1.exe | A Network Trojan was detected | ET MALWARE ZeroAccess udp traffic detected |
2840 | 1.exe | A Network Trojan was detected | ET MALWARE ZeroAccess udp traffic detected |
2840 | 1.exe | A Network Trojan was detected | ET MALWARE ZeroAccess udp traffic detected |
2840 | 1.exe | A Network Trojan was detected | ET MALWARE ZeroAccess udp traffic detected |
2840 | 1.exe | A Network Trojan was detected | ET MALWARE ZeroAccess udp traffic detected |