File name:

f_001466

Full analysis: https://app.any.run/tasks/c7032073-b3e6-4671-83f0-f1c3b3705d49
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: July 11, 2025, 15:52:18
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
upx
loader
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections
MD5:

E9023AFD6887FB860B238DD3F75E0804

SHA1:

92BB7FF78A35BD026F299E5F04533CD5E88EBD26

SHA256:

BC02CA4422BABC8716DA18B914EAAD401CE624DEEB8972D0D2B3718200B647D9

SSDEEP:

98304:gud83q4gd24fIN07wOyoXSj3Kep/BHiaS6CkrkXrwnBHr9r1G1j2j6jkgJx3NqGF:AJofrLv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • f_001466.exe (PID: 768)
  • SUSPICIOUS

    • There is functionality for taking screenshot (YARA)

      • f_001466.exe (PID: 768)
    • Stops a currently running service

      • sc.exe (PID: 2680)
      • sc.exe (PID: 3740)
      • sc.exe (PID: 7076)
      • sc.exe (PID: 1508)
      • sc.exe (PID: 2664)
    • Windows service management via SC.EXE

      • sc.exe (PID: 1044)
      • sc.exe (PID: 7000)
      • sc.exe (PID: 3944)
      • sc.exe (PID: 3948)
      • sc.exe (PID: 5504)
    • Uses TASKKILL.EXE to kill process

      • f_001466.exe (PID: 768)
    • Potential Corporate Privacy Violation

      • f_001466.exe (PID: 768)
    • Process requests binary or script from the Internet

      • f_001466.exe (PID: 768)
    • Creates a software uninstall entry

      • f_001466.exe (PID: 768)
    • Executable content was dropped or overwritten

      • f_001466.exe (PID: 768)
    • Process drops legitimate windows executable

      • f_001466.exe (PID: 768)
    • The process drops C-runtime libraries

      • f_001466.exe (PID: 768)
  • INFO

    • Reads the machine GUID from the registry

      • f_001466.exe (PID: 768)
    • Checks supported languages

      • f_001466.exe (PID: 768)
    • The sample compiled with chinese language support

      • f_001466.exe (PID: 768)
    • Reads the computer name

      • f_001466.exe (PID: 768)
    • UPX packer has been detected

      • f_001466.exe (PID: 768)
    • Creates files or folders in the user directory

      • f_001466.exe (PID: 768)
    • The sample compiled with english language support

      • f_001466.exe (PID: 768)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (76)
.exe | Win32 Executable (generic) (12.6)
.exe | Generic Win/DOS Executable (5.6)
.exe | DOS Executable Generic (5.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:07:08 02:59:57+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 2682880
InitializedDataSize: 8192
UninitializedDataSize: 2494464
EntryPoint: 0x4f0ad0
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.61
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: -
FileDescription:
FileVersion: 1.0.0.61
LegalCopyright: Copyright (C) 2022
ProductVersion: 0.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
179
Monitored processes
43
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start f_001466.exe sc.exe no specs sc.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs sc.exe no specs sc.exe no specs regsvr32.exe no specs conhost.exe no specs taskkill.exe no specs sc.exe no specs conhost.exe no specs sc.exe no specs regsvr32.exe no specs taskkill.exe no specs taskkill.exe no specs sc.exe no specs sc.exe no specs conhost.exe no specs taskkill.exe no specs taskkill.exe no specs sc.exe no specs sc.exe no specs conhost.exe no specs conhost.exe no specs taskkill.exe no specs taskkill.exe no specs conhost.exe no specs taskkill.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs conhost.exe no specs slui.exe no specs f_001466.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
728\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
768"C:\Users\admin\AppData\Local\Temp\f_001466.exe" C:\Users\admin\AppData\Local\Temp\f_001466.exe
explorer.exe
User:
admin
Company:
-
Integrity Level:
HIGH
Description:
Version:
1.0.0.61
Modules
Images
c:\users\admin\appdata\local\temp\f_001466.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
868\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exetaskkill.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1028taskkill /f /im PdfReader.exeC:\Windows\SysWOW64\taskkill.exef_001466.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1044sc delete WinToolBoxUpdateSrvC:\Windows\SysWOW64\sc.exef_001466.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
1060
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1052taskkill /f /im winToolBox.exeC:\Windows\SysWOW64\taskkill.exef_001466.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1508sc stop pdfReaderUpdateSrvC:\Windows\SysWOW64\sc.exef_001466.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Service Control Manager Configuration Tool
Exit code:
1060
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\sc.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1612taskkill /f /im CClear.exeC:\Windows\SysWOW64\taskkill.exef_001466.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2116\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exesc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2148regsvr32 /s /u C:\Users\admin\AppData\Local\winToolBox\Tools\zip\ShellMenu64.dllC:\Windows\SysWOW64\regsvr32.exef_001466.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
3
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\aclayers.dll
Total events
1 693
Read events
1 681
Write events
12
Delete events
0

Modification events

(PID) Process:(768) f_001466.exeKey:HKEY_CURRENT_USER\SOFTWARE\winToolBox
Operation:writeName:userHash
Value:
8c93c25a7007590b1385bc3c0bfac48e
(PID) Process:(768) f_001466.exeKey:HKEY_CURRENT_USER\SOFTWARE\winToolBox
Operation:writeName:userTime
Value:
20280
(PID) Process:(768) f_001466.exeKey:HKEY_CURRENT_USER\SOFTWARE\winToolBox
Operation:writeName:nameType
Value:
0
(PID) Process:(768) f_001466.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\winToolBox
Operation:writeName:DisplayName
Value:
Win工具箱
(PID) Process:(768) f_001466.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\winToolBox
Operation:writeName:UninstallString
Value:
C:\Users\admin\AppData\Local\winToolBox\unist00.exe
(PID) Process:(768) f_001466.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\winToolBox
Operation:writeName:DisplayVersion
Value:
1.0.0.61
(PID) Process:(768) f_001466.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\winToolBox
Operation:writeName:DisplayIcon
Value:
C:\Users\admin\AppData\Local\winToolBox\winToolBox.exe
(PID) Process:(768) f_001466.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\winToolBox
Operation:writeName:InstallDir
Value:
C:\Users\admin\AppData\Local\winToolBox
(PID) Process:(768) f_001466.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\winToolBox
Operation:writeName:Publisher
Value:
Win工具箱
(PID) Process:(768) f_001466.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\winToolBox
Operation:writeName:Installer
Value:
Executable files
56
Suspicious files
0
Text files
5
Unknown types
0

Dropped files

PID
Process
Filename
Type
768f_001466.exeC:\Users\admin\AppData\Local\winToolBox\computer-nonet\css\reset.csscsv
MD5:4593F56181D98BF62E58E64383B20DED
SHA256:8F16B478B5A247F70351BAD25CD1FAC49F979F38A447AE0384D2DA83944677E2
768f_001466.exeC:\Users\admin\AppData\Local\winToolBox\computer-nonet\css\index.csstext
MD5:5EA974A5AFCC5EFCE319BF3B387D1E93
SHA256:E6516EF3C716B01BBC530E911FEF0AC469FA3D37F098FCFE6965F8A65D0C753A
768f_001466.exeC:\Users\admin\AppData\Local\winToolBox\api-ms-win-core-file-l1-2-0.dllexecutable
MD5:79EE4A2FCBE24E9A65106DE834CCDA4A
SHA256:9F7BDA59FAAFC8A455F98397A63A7F7D114EFC4E8A41808C791256EBF33C7613
768f_001466.exeC:\Users\admin\AppData\Local\winToolBox\computer-nonet\imgs\nonet.pngimage
MD5:478F594AE8B0C03F058A4E381C7974C6
SHA256:51DC7C17FE88421483C2B4CFBD38CA54D7C2DBC8F7577D41D4586E3EE78DED4E
768f_001466.exeC:\Users\admin\AppData\Local\winToolBox\computer-nonet\css\index.scsstext
MD5:29E23EF86106B697CF16D5BD88DDB145
SHA256:21CCB46BDC07EE636D797C11DCB42BE828D72307A4B6551A94FBDCEB6714E5C5
768f_001466.exeC:\Users\admin\AppData\Local\winToolBox\About.exeexecutable
MD5:5DAC6591871B2809EC91669F14A48CDD
SHA256:51807D464D914984A1B84C1F9AD0CC2CA56DEA934C48B29CFE5AC33A8C21899E
768f_001466.exeC:\Users\admin\AppData\Local\winToolBox\computer-nonet\index.htmlhtml
MD5:5DD5D34DA11CE54B0DFCAA9C61E2FBE0
SHA256:919B6153F338B6CD826094D66639C0EFDF9CFA661812333351A724D36C153A73
768f_001466.exeC:\Users\admin\AppData\Local\winToolBox\api-ms-win-core-datetime-l1-1-0.dllexecutable
MD5:8894176AF3EA65A09AE5CF4C0E6FF50F
SHA256:C64B7C6400E9BACC1A4F1BAED6374BFBCE9A3F8CF20C2D03F81EF18262F89C60
768f_001466.exeC:\Users\admin\AppData\Local\winToolBox\api-ms-win-core-debug-l1-1-0.dllexecutable
MD5:879920C7FA905036856BCB10875121D9
SHA256:7E4CBA620B87189278B5631536CDAD9BFDA6E12ABD8E4EB647CB85369A204FE8
768f_001466.exeC:\Users\admin\AppData\Local\winToolBox\api-ms-win-core-errorhandling-l1-1-0.dllexecutable
MD5:D91BF81CF5178D47D1A588B0DF98EB24
SHA256:F8E3B45FD3E22866006F16A9E73E28B5E357F31F3C275B517692A5F16918B492
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
18
TCP/UDP connections
29
DNS requests
22
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
768
f_001466.exe
GET
115.223.9.120:80
http://static.flmgr.net/ver/file/main_10060
CN
unknown
768
f_001466.exe
GET
115.223.9.120:80
http://static.flmgr.net/ver/file/tool_10060
CN
unknown
768
f_001466.exe
GET
104.192.108.17:80
http://softdl.360tpcdn.com/pcrj/WindowsSoftMgrSetupv2.exe
US
unknown
768
f_001466.exe
POST
200
112.126.77.202:80
http://apiinfo.lfuerts.cn/v1/client/softmgr/info
CN
text
304 b
unknown
768
f_001466.exe
GET
200
112.126.77.202:80
http://apiinfo.lfuerts.cn/v1/client/theme?User=8c93c25a7007590b1385bc3c0bfac48e&Ver=1.0.0.61&Winver=10.0&Softid=&Webid=
CN
binary
48 b
unknown
768
f_001466.exe
GET
200
115.223.9.120:80
http://static.flmgr.net/ver/file/skin
CN
binary
992 Kb
unknown
1268
svchost.exe
GET
200
23.48.23.143:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
whitelisted
768
f_001466.exe
POST
200
60.205.148.178:80
http://api.nasyeo.com/log/next
CN
malicious
2668
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
768
f_001466.exe
POST
200
112.126.77.202:80
http://apiinfo.lfuerts.cn/v1/client/configs
CN
text
340 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3964
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
768
f_001466.exe
112.126.77.202:80
apiinfo.lfuerts.cn
Hangzhou Alibaba Advertising Co.,Ltd.
CN
unknown
768
f_001466.exe
115.223.9.120:80
static.flmgr.net
WENZHOU, ZHEJIANG Province, P.R.China.
CN
unknown
1268
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1268
svchost.exe
23.48.23.143:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
1268
svchost.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
  • 51.104.136.2
whitelisted
google.com
  • 142.250.185.110
whitelisted
apiinfo.lfuerts.cn
  • 112.126.77.202
unknown
static.flmgr.net
  • 115.223.9.120
  • 221.194.141.168
  • 36.42.77.167
  • 36.42.77.166
  • 36.41.168.166
  • 113.240.117.107
  • 112.46.58.112
  • 113.240.117.108
  • 36.41.168.170
  • 61.54.86.167
  • 121.22.232.165
  • 61.54.86.169
  • 121.22.232.170
  • 115.223.9.117
  • 112.46.58.107
  • 116.153.39.132
  • 116.153.39.129
unknown
crl.microsoft.com
  • 23.48.23.143
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
login.live.com
  • 20.190.159.129
  • 20.190.159.130
  • 40.126.31.69
  • 40.126.31.131
  • 40.126.31.3
  • 40.126.31.67
  • 20.190.159.64
  • 20.190.159.131
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
api.nasyeo.com
  • 60.205.148.178
unknown
nexusrules.officeapps.live.com
  • 52.111.236.21
whitelisted

Threats

PID
Process
Class
Message
768
f_001466.exe
Potential Corporate Privacy Violation
ET INFO PE EXE or DLL Windows file download HTTP
Process
Message
f_001466.exe
???:
f_001466.exe
1.0.0.61
f_001466.exe
10061
f_001466.exe
????????
f_001466.exe
??360????????
f_001466.exe
--- ?????? ---
f_001466.exe
--- ??????? ---
f_001466.exe
?????
f_001466.exe
Edge???
f_001466.exe
?????