File name:

CookiesGrabber.exe

Full analysis: https://app.any.run/tasks/7466a4e6-8ffa-46f0-9f54-c59cbd4f5f68
Verdict: Malicious activity
Analysis date: June 21, 2025, 18:32:56
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
python
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64, for MS Windows, 7 sections
MD5:

1099BAA9E7504DFFE917EEB846C16943

SHA1:

F69FDF685BC0A2F51ACEAFE516579C50BC830330

SHA256:

B513572FBC4154717C723D52DD793C413D98EF370EFB050FF800A89C8DCD15C4

SSDEEP:

98304:zD/lCFXRRdopaZOl/QOsIgMb1mB75kzlUzUjGNgLN71bxelLb/ncfNAnYRO4Y6Zd:GJG93881mwe/kiPNAnQBI1G

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops python dynamic module

      • CookiesGrabber.exe (PID: 5084)
    • Process drops legitimate windows executable

      • CookiesGrabber.exe (PID: 5084)
    • The process drops C-runtime libraries

      • CookiesGrabber.exe (PID: 5084)
    • Application launched itself

      • CookiesGrabber.exe (PID: 5084)
    • Executable content was dropped or overwritten

      • CookiesGrabber.exe (PID: 5084)
    • Reads browser cookies

      • CookiesGrabber.exe (PID: 1208)
    • Loads Python modules

      • CookiesGrabber.exe (PID: 1208)
  • INFO

    • Reads the computer name

      • CookiesGrabber.exe (PID: 5084)
      • CookiesGrabber.exe (PID: 1208)
    • Checks supported languages

      • CookiesGrabber.exe (PID: 5084)
      • CookiesGrabber.exe (PID: 1208)
    • Create files in a temporary directory

      • CookiesGrabber.exe (PID: 5084)
    • The sample compiled with english language support

      • CookiesGrabber.exe (PID: 5084)
    • Creates files or folders in the user directory

      • CookiesGrabber.exe (PID: 1208)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:06:21 18:25:10+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.43
CodeSize: 179712
InitializedDataSize: 155136
UninitializedDataSize: -
EntryPoint: 0xc650
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
130
Monitored processes
3
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start cookiesgrabber.exe conhost.exe no specs cookiesgrabber.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1208"C:\Users\admin\Desktop\CookiesGrabber.exe" C:\Users\admin\Desktop\CookiesGrabber.exeCookiesGrabber.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\cookiesgrabber.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
3832\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeCookiesGrabber.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5084"C:\Users\admin\Desktop\CookiesGrabber.exe" C:\Users\admin\Desktop\CookiesGrabber.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\cookiesgrabber.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
212
Read events
212
Write events
0
Delete events
0

Modification events

No data
Executable files
69
Suspicious files
1
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
5084CookiesGrabber.exeC:\Users\admin\AppData\Local\Temp\_MEI50842\Crypto\Cipher\_raw_cbc.pydexecutable
MD5:088A5FDA312EC2E1957E83D530F9BB8F
SHA256:FD5AC5C38172A303A274D2B8D1E9B794380773F50350453EAE3117724134EDE1
5084CookiesGrabber.exeC:\Users\admin\AppData\Local\Temp\_MEI50842\Crypto\Cipher\_raw_blowfish.pydexecutable
MD5:403A4F70938F58C15DAEB4A63D7ECADB
SHA256:FB407812E3E4D17B2CA981C8B95C716FF1B288A5E4658A831CD067A2837A753B
5084CookiesGrabber.exeC:\Users\admin\AppData\Local\Temp\_MEI50842\Crypto\Hash\_BLAKE2b.pydexecutable
MD5:7FCAD6D233F8F41636258C970390284C
SHA256:E0D97FD22D02BE38357905F8D833E1CD78839EDF986692EDE944F9EE0CEE8B40
5084CookiesGrabber.exeC:\Users\admin\AppData\Local\Temp\_MEI50842\Crypto\Hash\_BLAKE2s.pydexecutable
MD5:EFB1F498321597F1AAF7FB6A57603C76
SHA256:2A8CA6C6E864F0F5DE6E22736D461AEC5AFA45B4CB77449731AFC0861C20C23D
5084CookiesGrabber.exeC:\Users\admin\AppData\Local\Temp\_MEI50842\Crypto\Cipher\_raw_cast.pydexecutable
MD5:C5ECF284E05E75955A40E1276C9B250D
SHA256:3F65302BA35C1FF1F9A9BE9C5C5300A66B1BC4577E444B3EEE738FA7177135D4
5084CookiesGrabber.exeC:\Users\admin\AppData\Local\Temp\_MEI50842\Crypto\Cipher\_raw_arc2.pydexecutable
MD5:530BB99610B35527C3B06A22FD92CCEC
SHA256:43BC2F864D062BF7FE940E9CC497EF4FDFCC6EAEAB95FD4D4EE837E4D5DE0437
5084CookiesGrabber.exeC:\Users\admin\AppData\Local\Temp\_MEI50842\Crypto\Cipher\_ARC4.pydexecutable
MD5:EFF0F16D6E853EA2CBC7B3BCAB5E0591
SHA256:9892A83A3E511BD1024BFCCE460DBDE2690FD2A3C0C449081950C40EFDBA4C7D
5084CookiesGrabber.exeC:\Users\admin\AppData\Local\Temp\_MEI50842\Crypto\Cipher\_raw_ocb.pydexecutable
MD5:35B044D9ECD823161EF267517BA88509
SHA256:3B236F9148645B4CE4375D2BEE7844F4F5D381746F4A33492A3C35C2B156DE4D
5084CookiesGrabber.exeC:\Users\admin\AppData\Local\Temp\_MEI50842\Crypto\Cipher\_Salsa20.pydexecutable
MD5:17C99EDF022309BC2C54A732FB8FBF26
SHA256:34EB9C505180358711D8D6268E3F0E700C58AC9F47B0AD68565ED73BAB5DBD81
5084CookiesGrabber.exeC:\Users\admin\AppData\Local\Temp\_MEI50842\Crypto\Cipher\_raw_aesni.pydexecutable
MD5:133B156E060C77AF41B38841A32DA4B6
SHA256:20005B988FE848983A65F7F4727EC27148E4D0ABEAB9CFD0E58778F812BF7595
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
8
DNS requests
7
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2292
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4808
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2336
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
2292
svchost.exe
40.126.32.140:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2292
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
google.com
  • 142.250.186.78
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 40.126.32.140
  • 20.190.160.2
  • 20.190.160.64
  • 20.190.160.4
  • 20.190.160.128
  • 40.126.32.74
  • 20.190.160.65
  • 40.126.32.136
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
nexusrules.officeapps.live.com
  • 52.111.227.14
whitelisted

Threats

No threats detected
No debug info