| File name: | quicksoftware-dl.exe |
| Full analysis: | https://app.any.run/tasks/de30250f-b0f7-414f-98b2-74216d8a97dc |
| Verdict: | Malicious activity |
| Analysis date: | May 24, 2025, 12:23:01 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections |
| MD5: | ADD26F07028D142EDB4EC2B018C9D62A |
| SHA1: | 76D903040626DB9DB94552A0FE880E3FA75E863E |
| SHA256: | B12DE74429CCE391832B921C1E60D797C9E629BE3949A7BF24DBF871AC60B1D7 |
| SSDEEP: | 3072:ylZMtTwu1DZN9VVF1VlVrabVFXzaVS4TgIz4O9m5DtXU:y/MtJN9VVF1VlVSTXzaVS4TgIz4iqDm |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2025:03:08 23:05:20+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 27136 |
| InitializedDataSize: | 184832 |
| UninitializedDataSize: | 2048 |
| EntryPoint: | 0x358d |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process |
|---|---|---|---|---|
| 208 | "C:\Users\admin\Desktop\downloaded-files\VirtualBox-7.1.8-168469-Win.exe" | C:\Users\admin\Desktop\downloaded-files\VirtualBox-7.1.8-168469-Win.exe | explorer.exe | |
User: admin Company: Oracle and/or its affiliates Integrity Level: HIGH Description: VirtualBox Installer Version: 7.1.8.168469 | ||||
| 512 | "C:\Program Files\Ablaze Floorp\floorp.exe" -first-startup | C:\Program Files\Ablaze Floorp\floorp.exe | floorp.exe | |
User: admin Company: Mozilla Corporation Integrity Level: MEDIUM Description: Floorp Exit code: 0 Version: 128.11.0 | ||||
| 540 | C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:11 | C:\Windows\System32\SrTasks.exe | — | dllhost.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft® Windows System Protection background tasks. Exit code: 2147942487 Version: 10.0.19041.1 (WinBuild.160101.0800) | ||||
| 684 | C:\WINDOWS\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | services.exe | |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Version: 5.0.19041.1 (WinBuild.160101.0800) | ||||
| 776 | C:\Windows\syswow64\MsiExec.exe -Embedding F1BE0055C721514935BA20BC896F5F98 M Global\MSI0000 | C:\Windows\SysWOW64\msiexec.exe | — | msiexec.exe |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.19041.3636 (WinBuild.160101.0800) | ||||
| 840 | C:\WINDOWS\system32\srtasks.exe ExecuteScopeRestorePoint /WaitForRestorePoint:12 | C:\Windows\System32\SrTasks.exe | — | msiexec.exe |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Windows System Protection background tasks. Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) | ||||
| 1184 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) | ||||
| 1228 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | aria2c.exe |
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) | ||||
| 1228 | "C:\Program Files\Everything\Everything.exe" -disable-update-notification -uninstall-quick-launch-shortcut -no-choose-volumes -language 1033 | C:\Program Files\Everything\Everything.exe | — | Everything-1.4.1.1026.x64-Setup.exe |
User: admin Company: voidtools Integrity Level: MEDIUM Description: Everything Exit code: 0 Version: 1.4.1.1026 | ||||
| 1228 | "C:\Users\admin\AppData\Local\Temp\{29E6096F-97DB-4959-BD69-E279302ACA62}\.be\PowerToysSetup-0.91.1-x64.exe" -q -burn.elevated BurnPipe.{542B1980-416A-499E-943F-48FEA839D396} {60148399-FB13-41A0-B376-2ACC09AF8AA0} 4180 | C:\Users\admin\AppData\Local\Temp\{29E6096F-97DB-4959-BD69-E279302ACA62}\.be\PowerToysSetup-0.91.1-x64.exe | PowerToysSetup-0.91.1-x64.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: PowerToys (Preview) x64 Exit code: 1800 Version: 0.91.1 | ||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4628 | quicksoftware-dl.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\54C62B182F5BF07FA8427C07B0A3AAF8_786EA6C36BF7ABFF201B638497282D19 | binary | |
MD5:2C4D15B99429A495319CDEF89BB38A1D | SHA256:FD2ED1BD4303C246D3514830353F38D24E450F865CB0C41647F7BE80702CEB1E | |||
| 4628 | quicksoftware-dl.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\RR3E01RZ\aria2c[1].exe | executable | |
MD5:6C5EA5A82D756BCA4A9610C8D2260D2F | SHA256:B9CD71B275AF11B63C33457B0F43F2F2675937070C563E195F223EFD7FA4C74B | |||
| 4628 | quicksoftware-dl.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CE7B026C819922EDB9B7ED78605E20A3_731147EC87359F0E7CBB8FC748CE2C9A | binary | |
MD5:8843F1AE49584247BE4128757E5E5500 | SHA256:903F16DAFC8BCDA73B59E9328A3C2FFE4DD350543D847ED50E2EE4B8BF6526CE | |||
| 4628 | quicksoftware-dl.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\KCV3KQBA\urllist[1].txt | text | |
MD5:F71E3833F698C3C62409469692A5446B | SHA256:CFC2233ED169E5BEA2B1D9F04538F24B602B8ECC9016896300A6D5D5C59C7627 | |||
| 4628 | quicksoftware-dl.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CE7B026C819922EDB9B7ED78605E20A3_731147EC87359F0E7CBB8FC748CE2C9A | binary | |
MD5:C1EE51398687C0DFF82034211587B60A | SHA256:F59CE236F8A5010BB66F4791B768B55D28C1644AE3EEF778E864103E77ACAC38 | |||
| 4628 | quicksoftware-dl.exe | C:\Users\admin\AppData\Local\Temp\nsoA655.tmp\System.dll | executable | |
MD5:9B38A1B07A0EBC5C7E59E63346ECC2DB | SHA256:C881253DAFCF1322A771139B1A429EC1E78C507CA81A218A20DC1A4B25ABBFE7 | |||
| 4628 | quicksoftware-dl.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\54C62B182F5BF07FA8427C07B0A3AAF8_786EA6C36BF7ABFF201B638497282D19 | binary | |
MD5:2EAA0859782ED877B89881411A4D2CA1 | SHA256:A2F3DFD9E9644901A5807E03AF713A1FCE517D79B2170CA1C4048302E15A3326 | |||
| 4628 | quicksoftware-dl.exe | C:\Users\admin\AppData\Local\Temp\nsoA655.tmp\INetC.dll | executable | |
MD5:40D7ECA32B2F4D29DB98715DD45BFAC5 | SHA256:85E03805F90F72257DD41BFDAA186237218BBB0EC410AD3B6576A88EA11DCCB9 | |||
| 4628 | quicksoftware-dl.exe | C:\Users\admin\AppData\Local\Temp\nsoA655.tmp\modern-wizard.bmp | image | |
MD5:CBE40FD2B1EC96DAEDC65DA172D90022 | SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2 | |||
| 4628 | quicksoftware-dl.exe | C:\Users\admin\AppData\Local\Temp\nsoA655.tmp\modern-header.bmp | image | |
MD5:583C38FB0F5AF5FE584D9A9B01D6A3E7 | SHA256:4C9E804CE1A391F8E603B7B9C732A6529C1E81BE4D12F125C8562EA9D49095C2 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5496 | MoUsoCoreWorker.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5796 | svchost.exe | GET | 200 | 23.219.150.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 2.16.241.19:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4628 | quicksoftware-dl.exe | GET | 200 | 18.173.205.113:80 | http://ocsps.ssl.com/MEkwRzBFMEMwQTAJBgUrDgMCGgUABBQMDtATfnJO6JAXDQoHl8pAaJdhTQQU3QQJB6L1en1SUxKSle44gCUNplkCCAmX7RCdHwf8 | unknown | — | — | whitelisted |
4628 | quicksoftware-dl.exe | GET | 200 | 18.173.205.113:80 | http://ocsps.ssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTUkpS%2BK0oZhSMx%2FmmCZ76UqdjUxQQUJhR%2B4NzXpvfi1AQn32HxwuznMsoCEFv%2BMpErdkO9Fsl4vDuI1mA%3D | unknown | — | — | whitelisted |
756 | lsass.exe | GET | 200 | 3.167.227.115:80 | http://r11.c.lencr.org/87.crl | unknown | — | — | whitelisted |
756 | lsass.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEFZnHQTqT5lMbxCBR1nSdZQ%3D | unknown | — | — | whitelisted |
756 | lsass.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBSr83eyJy3njhjVpn5bEpfc6MXawQQUOuEJhtTPGcKWdnRJdtzgNcZjY5oCEQDzZE5rbgBQI34JRr174fUd | unknown | — | — | whitelisted |
756 | lsass.exe | GET | 200 | 172.64.149.23:80 | http://ocsp.sectigo.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTPlNxcMEqnlIVyH5VuZ4lawhZX3QQU9oUKOxGG4QR9DqoLLNLuzGR7e64CEQCrZoa1YnvoBZaCEzAShkn1 | unknown | — | — | whitelisted |
756 | lsass.exe | GET | 200 | 2.23.197.184:80 | http://x1.c.lencr.org/ | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
864 | RUXIMICS.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5496 | MoUsoCoreWorker.exe | 2.16.241.19:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
5496 | MoUsoCoreWorker.exe | 23.219.150.101:80 | www.microsoft.com | AKAMAI-AS | CL | whitelisted |
5796 | svchost.exe | 23.219.150.101:80 | www.microsoft.com | AKAMAI-AS | CL | whitelisted |
5796 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4628 | quicksoftware-dl.exe | 139.84.173.225:443 | files.webdevtest.ftp.sh | AS-CHOOPA | US | unknown |
4628 | quicksoftware-dl.exe | 18.173.205.113:80 | ocsps.ssl.com | — | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
files.webdevtest.ftp.sh |
| unknown |
ocsps.ssl.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
7-zip.org |
| unknown |
github.com |
| whitelisted |
netcologne.dl.sourceforge.net |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2196 | svchost.exe | Potentially Bad Traffic | ET DYN_DNS DYNAMIC_DNS Query to a *.ftp .sh Domain |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Requests to a free CDN for open source projects (jsdelivr .net) |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to access raw user content on GitHub |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to access raw user content on GitHub |
2196 | svchost.exe | Not Suspicious Traffic | INFO [ANY.RUN] Attempting to access raw user content on GitHub |