File name:

git.exe

Full analysis: https://app.any.run/tasks/0f131cea-6a6f-4458-aa91-e8ce8d4728a6
Verdict: Malicious activity
Threats:

Cephalus is a targeted ransomware threat discovered in 2025. It’s known for infiltrating organizations that deal with sensitive data through compromised RDP access. It leverages DLL sideloading with a legitimate SentinelOne executable. Cephalus is able to exfiltrate data and destroy backup options. Its payload is also tailored to each victim, which makes identification and mitigation more complex.

Analysis date: September 03, 2025, 17:44:54
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
cephalus
ransomware
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows, 9 sections
MD5:

6221B0BF4D365454D40C546CF7133570

SHA1:

5D34CD76FF09D2C7045AB47C195E22C178A9A104

SHA256:

B3E53168FC05AEEDEA828BD2042E2CC34BBF8193DEADAB9DD4AA507E5B9C045A

SSDEEP:

98304:sKCp/9dHALPDg/c3/b+vpaOhWYLhKRZSCDxElQ:V

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Renames files like ransomware

      • git.exe (PID: 4648)
    • Deletes shadow copies

      • git.exe (PID: 4648)
    • Executing a file with an untrusted certificate

      • git.exe (PID: 4648)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Manual execution by a user

      • notepad.exe (PID: 7016)
    • Reads the computer name

      • git.exe (PID: 4648)
    • Reads the software policy settings

      • slui.exe (PID: 5988)
    • Reads security settings of Internet Explorer

      • notepad.exe (PID: 7016)
    • Create files in a temporary directory

      • git.exe (PID: 4648)
    • Checks supported languages

      • git.exe (PID: 4648)
    • Checks proxy server information

      • slui.exe (PID: 5988)
    • Drops encrypted JS script (Microsoft Script Encoder)

      • git.exe (PID: 4648)
    • Creates files or folders in the user directory

      • git.exe (PID: 4648)
    • The sample compiled with english language support

      • git.exe (PID: 4648)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:07:29 14:22:04+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Large address aware, No debug
PEType: PE32+
LinkerVersion: 3
CodeSize: 1386496
InitializedDataSize: 1860608
UninitializedDataSize: -
EntryPoint: 0x74ac0
OSVersion: 6.1
ImageVersion: 1
SubsystemVersion: 6.1
Subsystem: Windows command line
FileVersionNumber: 2.49.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Unknown (0)
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: Git for Windows
FileVersion: 2.49.0.windows.1
ProductName: Git
ProductVersion: 2.49.0.windows.1
LegalCopyright: -
OriginalFileName: git.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
1592vssadmin delete shadows /all /quietC:\Windows\System32\vssadmin.exegit.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Command Line Interface for Microsoft® Volume Shadow Copy Service
Exit code:
2
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\vssadmin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4072\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exegit.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4648"C:\Users\admin\AppData\Local\Temp\git.exe" C:\Users\admin\AppData\Local\Temp\git.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Git for Windows
Exit code:
256
Version:
2.49.0.windows.1
Modules
Images
c:\users\admin\appdata\local\temp\git.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\bcryptprimitives.dll
c:\windows\system32\powrprof.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\umpdc.dll
5988C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
7016"C:\WINDOWS\system32\NOTEPAD.EXE" C:\Users\admin\Desktop\recover.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
Total events
967
Read events
967
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
66
Text files
24
Unknown types
0

Dropped files

PID
Process
Filename
Type
4648git.exeC:\Users\admin\Downloads\recover.txttext
MD5:313C7E0BE5FDE35F038BB3E09FC3C121
SHA256:B11FF5DF30B87B53A269F65CEADA22D3AF3C21B30015BC56F274A6423F783855
4648git.exeC:\Users\admin\Music\recover.txttext
MD5:313C7E0BE5FDE35F038BB3E09FC3C121
SHA256:B11FF5DF30B87B53A269F65CEADA22D3AF3C21B30015BC56F274A6423F783855
4648git.exeC:\Users\admin\Documents\PowerShell\recover.txttext
MD5:313C7E0BE5FDE35F038BB3E09FC3C121
SHA256:B11FF5DF30B87B53A269F65CEADA22D3AF3C21B30015BC56F274A6423F783855
4648git.exeC:\Users\admin\Desktop\recover.txttext
MD5:313C7E0BE5FDE35F038BB3E09FC3C121
SHA256:B11FF5DF30B87B53A269F65CEADA22D3AF3C21B30015BC56F274A6423F783855
4648git.exeC:\Users\admin\AppData\Local\Temp\encrypted_key.binbinary
MD5:0F14E39618947B1C9CD1B9D5D5DAA89C
SHA256:ACC40595889E59D7CD729B017D5769A2599CD7BDE2EAE7D5438A3F464049DA8F
4648git.exeC:\Users\admin\AppData\Local\temp.datbinary
MD5:0F14E39618947B1C9CD1B9D5D5DAA89C
SHA256:ACC40595889E59D7CD729B017D5769A2599CD7BDE2EAE7D5438A3F464049DA8F
4648git.exeC:\Users\admin\Videos\recover.txttext
MD5:313C7E0BE5FDE35F038BB3E09FC3C121
SHA256:B11FF5DF30B87B53A269F65CEADA22D3AF3C21B30015BC56F274A6423F783855
4648git.exeC:\Users\admin\Documents\recover.txttext
MD5:313C7E0BE5FDE35F038BB3E09FC3C121
SHA256:B11FF5DF30B87B53A269F65CEADA22D3AF3C21B30015BC56F274A6423F783855
4648git.exeC:\Users\admin\Documents\OneNote Notebooks\recover.txttext
MD5:313C7E0BE5FDE35F038BB3E09FC3C121
SHA256:B11FF5DF30B87B53A269F65CEADA22D3AF3C21B30015BC56F274A6423F783855
4648git.exeC:\Users\admin\AppData\Roaming\.system_cachebinary
MD5:0F14E39618947B1C9CD1B9D5D5DAA89C
SHA256:ACC40595889E59D7CD729B017D5769A2599CD7BDE2EAE7D5438A3F464049DA8F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
8
TCP/UDP connections
33
DNS requests
27
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
814 b
whitelisted
4124
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
NL
binary
419 b
whitelisted
4124
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
NL
binary
407 b
whitelisted
4088
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D
US
binary
471 b
whitelisted
5328
SearchApp.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
313 b
whitelisted
2940
svchost.exe
GET
200
72.246.169.163:80
http://x1.c.lencr.org/
DE
binary
734 b
whitelisted
3396
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5944
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
1268
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4460
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
3396
svchost.exe
40.126.31.0:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3396
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
  • 51.104.136.2
whitelisted
google.com
  • 216.58.206.46
whitelisted
login.live.com
  • 40.126.31.0
  • 40.126.31.2
  • 40.126.31.130
  • 20.190.159.131
  • 20.190.159.4
  • 20.190.159.130
  • 40.126.31.3
  • 20.190.159.0
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
slscr.update.microsoft.com
  • 20.165.94.63
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
www.bing.com
  • 92.123.104.30
  • 92.123.104.18
  • 92.123.104.63
  • 92.123.104.9
  • 92.123.104.19
  • 92.123.104.65
  • 92.123.104.67
  • 92.123.104.61
  • 92.123.104.31
whitelisted
self.events.data.microsoft.com
  • 20.189.173.11
whitelisted

Threats

No threats detected
No debug info