File name:

ratonClient.exe

Full analysis: https://app.any.run/tasks/d15750a8-0826-46b4-ad55-b71d6e25d629
Verdict: Malicious activity
Threats:

Remote access trojans (RATs) are a type of malware that enables attackers to establish complete to partial control over infected computers. Such malicious programs often have a modular design, offering a wide range of functionalities for conducting illicit activities on compromised systems. Some of the most common features of RATs include access to the users’ data, webcam, and keystrokes. This malware is often distributed through phishing emails and links.

Analysis date: April 29, 2026, 18:40:12
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
raton
rat
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

E147CCB15C1F84119F42280DFA9B0F00

SHA1:

51E16D5F63AC3481B00F977E3A60929CAAEA1E89

SHA256:

B8912FB7517D365885A1C9E2BEA550EB3694B7666B95CC8A635DF16280F2AA3D

SSDEEP:

98304:LJvE0TV3746r8IxZnm86moKZR/RFbAsZCkAmMLwAkGBixxVab+XGg3Z1DGfi8iSm:lb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • RATON has been detected

      • ratonClient.exe (PID: 7260)
      • cmd.exe (PID: 7608)
      • ratonClient.exe (PID: 2528)
    • Changes the autorun value in the registry

      • ratonClient.exe (PID: 2528)
    • RATON has been detected (YARA)

      • ratonClient.exe (PID: 2528)
  • SUSPICIOUS

    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 7608)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 7608)
    • Starts application with an unusual extension

      • cmd.exe (PID: 7608)
    • Executable content was dropped or overwritten

      • ratonClient.exe (PID: 7260)
    • Executing commands from a ".bat" file

      • ratonClient.exe (PID: 7260)
    • The executable file from the user directory is run by the CMD process

      • ratonClient.exe (PID: 2528)
    • Contacting a server suspected of hosting an CnC

      • ratonClient.exe (PID: 2528)
  • INFO

    • Reads the computer name

      • ratonClient.exe (PID: 2528)
      • ratonClient.exe (PID: 7260)
    • Checks supported languages

      • ratonClient.exe (PID: 2528)
      • chcp.com (PID: 572)
      • ratonClient.exe (PID: 7260)
    • Changes the display of characters in the console

      • cmd.exe (PID: 7608)
    • Reads security settings of Internet Explorer

      • ratonClient.exe (PID: 7260)
      • ratonClient.exe (PID: 2528)
    • Create files in a temporary directory

      • ratonClient.exe (PID: 7260)
    • Creates files or folders in the user directory

      • ratonClient.exe (PID: 7260)
    • Reads the machine GUID from the registry

      • ratonClient.exe (PID: 2528)
    • There is functionality for taking screenshot (YARA)

      • ratonClient.exe (PID: 2528)
    • Launching a file from a Registry key

      • ratonClient.exe (PID: 2528)
    • Reads Environment values

      • ratonClient.exe (PID: 2528)
    • Disables trace logs

      • ratonClient.exe (PID: 2528)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (42.5)
.exe | InstallShield setup (25)
.exe | Win64 Executable (generic) (16)
.scr | Windows screen saver (7.6)
.dll | Win32 Dynamic Link Library (generic) (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2101:01:23 19:23:27+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 2942464
InitializedDataSize: 2048
UninitializedDataSize: -
EntryPoint: 0x2d044e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: Application
FileVersion: 1.0.0.0
InternalName: clientForCrypters.exe
LegalCopyright: Copyright © 2026
LegalTrademarks: -
OriginalFileName: clientForCrypters.exe
ProductName: Application
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
143
Monitored processes
7
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #RATON ratonclient.exe #RATON cmd.exe no specs conhost.exe no specs chcp.com no specs timeout.exe no specs #RATON ratonclient.exe timeout.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
572chcp 65001 C:\Windows\System32\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Change CodePage Utility
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\chcp.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\fsutilext.dll
2528"C:\Users\admin\AppData\Roaming\PlatformRuntime\ratonClient.exe" C:\Users\admin\AppData\Roaming\PlatformRuntime\ratonClient.exe
cmd.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Application
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\platformruntime\ratonclient.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2840timeout /t 1 /nobreak C:\Windows\System32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
2960timeout /t 2 /nobreak C:\Windows\System32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
7260"C:\Users\admin\AppData\Local\Temp\ratonClient.exe" C:\Users\admin\AppData\Local\Temp\ratonClient.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Application
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\ratonclient.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
7448\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7608C:\WINDOWS\system32\cmd.exe /c ""C:\Users\admin\AppData\Roaming\Temp\cleanup_BSY3L2i9OOlnP4wrqhWx0uLBxv3WBD.bat""C:\Windows\System32\cmd.exe
ratonClient.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
Total events
4 243
Read events
4 228
Write events
15
Delete events
0

Modification events

(PID) Process:(2528) ratonClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ratonClient_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2528) ratonClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ratonClient_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(2528) ratonClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ratonClient_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(2528) ratonClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ratonClient_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(2528) ratonClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ratonClient_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(2528) ratonClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ratonClient_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(2528) ratonClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ratonClient_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(2528) ratonClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ratonClient_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(2528) ratonClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ratonClient_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(2528) ratonClient.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\ratonClient_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
22
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
7260ratonClient.exeC:\Users\admin\AppData\Local\Temp\Costura\43C0B7C2D694D39E487F61CFD3964734\microsoft.win32.registry.dllexecutable
MD5:DA40F3DB8B34571684C0CB5BCECD2A79
SHA256:619737E2AF8FB713085726631DD2E522FE130CAC1D388A59C38907A47D7AADEA
7260ratonClient.exeC:\Users\admin\AppData\Local\Temp\Costura\43C0B7C2D694D39E487F61CFD3964734\naudio.dllexecutable
MD5:E90AC3063409EF6876E26422DC61D0EB
SHA256:5DCA4B3B7F1F2ABDD2F94D3A056E4C414605DA248612F02A0D2AB38083AA8EF8
7260ratonClient.exeC:\Users\admin\AppData\Local\Temp\Costura\43C0B7C2D694D39E487F61CFD3964734\naudio.core.dllexecutable
MD5:4E4302CE791E48F985A3A221A19A272B
SHA256:4F8D8C4140146674B103C8A3C46FBC4C768A86C0012A167168E3F7DA2B3E5C09
7260ratonClient.exeC:\Users\admin\AppData\Local\Temp\Costura\43C0B7C2D694D39E487F61CFD3964734\stuff.dllexecutable
MD5:F8D5274E3368AA40CC0FD5798D19C783
SHA256:D8EE0FC96CE8DE2E37BC8FDC051DA7C1852B9A510270E663BA17281DE23F049B
7260ratonClient.exeC:\Users\admin\AppData\Local\Temp\Costura\43C0B7C2D694D39E487F61CFD3964734\aforge.video.dllexecutable
MD5:0BD34AA29C7EA4181900797395A6DA78
SHA256:BAFA6ED04CA2782270074127A0498DDE022C2A9F4096C6BB2B8E3C08BB3D404D
7260ratonClient.exeC:\Users\admin\AppData\Local\Temp\Costura\43C0B7C2D694D39E487F61CFD3964734\aforge.dllexecutable
MD5:02C63F568E598AAD85DD401D7B26E82A
SHA256:966A474060A8ACA70C73BA09D0B6FE2353035961C7107B9003EF879C010FF8DA
7260ratonClient.exeC:\Users\admin\AppData\Local\Temp\Costura\43C0B7C2D694D39E487F61CFD3964734\aforge.video.directshow.dllexecutable
MD5:17ED442E8485AC3F7DC5B3C089654A61
SHA256:666D44798D94EAFA1ED21AF79E9BC0293FFD96F863AB5D87F78BCEE9EF9FFD6B
7260ratonClient.exeC:\Users\admin\AppData\Local\Temp\Costura\43C0B7C2D694D39E487F61CFD3964734\costura.dllexecutable
MD5:109BD38D2107F41573C48544992EAD99
SHA256:7A9E767AD824AFA2C1B0AED513FE1CF2B8DAC6D40F24E7C4075AF32B1CF23A20
7260ratonClient.exeC:\Users\admin\AppData\Local\Temp\Costura\43C0B7C2D694D39E487F61CFD3964734\naudio.asio.dllexecutable
MD5:01A76191D31B3D6042484E452BD66CE0
SHA256:504DD507C34817A8A8BE1965E82DD091FF0F5A85BA444EA784783F196677BFD1
7260ratonClient.exeC:\Users\admin\AppData\Local\Temp\Costura\43C0B7C2D694D39E487F61CFD3964734\naudio.winforms.dllexecutable
MD5:115137414B41A26D6E73738CD94C036C
SHA256:82A92CB6B9001E013C653C65E4AE460346770EC7512856879E63018D9CAFC41A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
39
TCP/UDP connections
29
DNS requests
22
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2528
ratonClient.exe
GET
200
104.26.7.74:443
https://ipwhois.app/json/
US
text
675 b
unknown
4944
SIHClient.exe
GET
304
74.178.240.61:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
4944
SIHClient.exe
GET
200
74.178.240.51:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
4944
SIHClient.exe
GET
200
74.178.240.61:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
4944
SIHClient.exe
GET
304
74.178.240.61:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
5316
svchost.exe
POST
200
20.190.160.20:443
https://login.live.com/RST2.srf
US
xml
1.24 Kb
whitelisted
5316
svchost.exe
POST
400
20.190.160.20:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
204 b
whitelisted
8044
svchost.exe
GET
304
4.231.128.59:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
whitelisted
5316
svchost.exe
POST
400
20.190.160.20:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
204 b
whitelisted
5316
svchost.exe
POST
400
20.190.160.20:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
204 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
Not routed
whitelisted
5276
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
48.192.1.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8044
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
2528
ratonClient.exe
158.160.75.185:40532
portbuddy.dev
YANDEXCLOUD
RU
malicious
2528
ratonClient.exe
104.26.7.74:443
ipwhois.app
CLOUDFLARENET
US
whitelisted
5316
svchost.exe
20.190.160.20:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5316
svchost.exe
23.11.40.157:80
ocsp.digicert.com
AKAMAI-AMS
NL
whitelisted
3428
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
activation-v2.sls.microsoft.com
  • 48.192.1.64
whitelisted
google.com
  • 142.251.20.113
  • 142.251.20.101
  • 142.251.20.100
  • 142.251.20.138
  • 142.251.20.102
  • 142.251.20.139
whitelisted
portbuddy.dev
  • 158.160.75.185
unknown
ipwhois.app
  • 104.26.7.74
  • 172.67.70.190
  • 104.26.6.74
unknown
login.live.com
  • 20.190.160.20
  • 40.126.32.140
  • 40.126.32.134
  • 20.190.160.2
  • 40.126.32.138
  • 20.190.160.3
  • 20.190.160.14
  • 20.190.160.4
whitelisted
ocsp.digicert.com
  • 23.11.40.157
whitelisted
client.wns.windows.com
  • 172.211.123.250
  • 172.211.123.248
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.216.77.34
  • 23.216.77.19
  • 23.216.77.26
  • 23.216.77.22
  • 23.216.77.39
  • 23.216.77.29
  • 23.216.77.33
  • 23.216.77.21
  • 23.216.77.41
  • 23.216.77.25
  • 23.216.77.30
  • 23.216.77.35
  • 23.216.77.18
whitelisted
www.microsoft.com
  • 88.221.169.152
  • 23.52.181.212
whitelisted

Threats

PID
Process
Class
Message
2528
ratonClient.exe
Domain Observed Used for C2 Detected
ET MALWARE Raton TLS Server Certificate
8044
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
2528
ratonClient.exe
Misc activity
HUNTING [ANY.RUN] TCP binary protocol 16-BE pkt-len prefix on non-standard port outbound
2528
ratonClient.exe
Misc activity
HUNTING [ANY.RUN] TCP binary protocol 32-BE pkt-len prefix on non-standard port inbound
No debug info