| File name: | bff3d0ae0754aace2eb079ec6219dace494620a3aaf71a2d2d8a2e09211f070b.exe |
| Full analysis: | https://app.any.run/tasks/b554a271-efe0-41c2-8ce2-44ad7ea1d313 |
| Verdict: | Malicious activity |
| Analysis date: | October 03, 2025, 16:24:57 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | D51D8F1AA8ED51625E2CF6B8593DDB53 |
| SHA1: | 978F99636D9C7431886E6A2BB86D404106D98A87 |
| SHA256: | BFF3D0AE0754AACE2EB079EC6219DACE494620A3AAF71A2D2D8A2E09211F070B |
| SSDEEP: | 12288:GEY859yqwTEvcPdZnCtsy27ibu2TQbQVtClL7lhPAIkrkNVVh6yzD3:GEY89WxCtD278u2U4IV7lhPAIkrTyzr |
| .exe | | | DOS Executable Generic (100) |
|---|
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2003:11:11 14:39:16+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 10 |
| CodeSize: | 140288 |
| InitializedDataSize: | 356352 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x113b6 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 12.0.4518.1014 |
| ProductVersionNumber: | 12.0.4518.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Microsoft Corporation |
| FileDescription: | Microsoft Office Word |
| FileVersion: | 12.0.4518.1014 |
| InternalName: | WinWord |
| LegalCopyright: | © 2006 Microsoft Corporation. All rights reserved. |
| LegalTrademarks1: | Microsoft® is a registered trademark of Microsoft Corporation. |
| LegalTrademarks2: | Windows® is a registered trademark of Microsoft Corporation. |
| OriginalFileName: | WinWord.exe |
| ProductName: | 2007 Microsoft Office system |
| ProductVersion: | 12.0.4518.1014 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 8 | "C:\Users\admin\AppData\Local\Temp\B4C9.tmp" | C:\Users\admin\AppData\Local\Temp\B4C9.tmp | — | B46B.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 8 | "C:\Users\admin\AppData\Local\Temp\D5DE.tmp" | C:\Users\admin\AppData\Local\Temp\D5DE.tmp | — | D409.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 8 | "C:\Users\admin\AppData\Local\Temp\E9E3.tmp" | C:\Users\admin\AppData\Local\Temp\E9E3.tmp | — | E985.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 8 | "C:\Users\admin\AppData\Local\Temp\1DF.tmp" | C:\Users\admin\AppData\Local\Temp\1DF.tmp | — | 182.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 8 | "C:\Users\admin\AppData\Local\Temp\433E.tmp" | C:\Users\admin\AppData\Local\Temp\433E.tmp | — | 42D0.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 532 | "C:\Users\admin\AppData\Local\Temp\4EC7.tmp" | C:\Users\admin\AppData\Local\Temp\4EC7.tmp | — | 4E69.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 532 | "C:\Users\admin\AppData\Local\Temp\6BB5.tmp" | C:\Users\admin\AppData\Local\Temp\6BB5.tmp | — | 6B67.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 572 | "C:\Users\admin\AppData\Local\Temp\902A.tmp" | C:\Users\admin\AppData\Local\Temp\902A.tmp | — | 8FCC.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 572 | "C:\Users\admin\AppData\Local\Temp\E8D9.tmp" | C:\Users\admin\AppData\Local\Temp\E8D9.tmp | — | E87B.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 572 | "C:\Users\admin\AppData\Local\Temp\E5.tmp" | C:\Users\admin\AppData\Local\Temp\E5.tmp | — | 97.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| (PID) Process: | (7472) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (7472) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (7472) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (6760) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (6760) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (6760) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (7032) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (7032) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (7032) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (4212) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6136 | 1EB3.tmp | C:\Users\admin\AppData\Local\Temp\1F30.tmp | executable | |
MD5:3ECA30899FBE217DB183B8066783DAAB | SHA256:907D2BE81CBB6DEB7AE45F2756FB316596009C12A1CC03166205802AC3E7156D | |||
| 6120 | 1DD8.tmp | C:\Users\admin\AppData\Local\Temp\1E46.tmp | executable | |
MD5:299EAB5C7B68817AF8BE1FED1A3E521A | SHA256:442B8888C643421FCE64342C8E51E0350879988DB17C404A11E94383C5294317 | |||
| 7024 | 1E46.tmp | C:\Users\admin\AppData\Local\Temp\1EB3.tmp | executable | |
MD5:02FA5D4536281141CE15F7362BA473FC | SHA256:FDBBA334F01DF30D5CA0E0C40933149034899730E160E85BDABF7670FA05B8E7 | |||
| 1132 | bff3d0ae0754aace2eb079ec6219dace494620a3aaf71a2d2d8a2e09211f070b.exe | C:\Users\admin\AppData\Local\Temp\1DD8.tmp | executable | |
MD5:53CB6A38D5D2AF5228DEA599D77E7545 | SHA256:0A29A950A6E3DE40CF114D4EBE5966BA6DB6160D47E765DB45B1512F77E9A3D6 | |||
| 7036 | 1F30.tmp | C:\Users\admin\AppData\Local\Temp\1F9D.tmp | executable | |
MD5:BF229212DBF13F57301CE07E3CA46681 | SHA256:5CE855EB84C66F5FFC9DE1FA798C62A51156DD99A4A643C834E4B5A55ADB19E5 | |||
| 4740 | 1F9D.tmp | C:\Users\admin\AppData\Local\Temp\1FFB.tmp | executable | |
MD5:7E6BBE327F94D39D9E636D57B4FBACCF | SHA256:4B2134471986B89473755F7B9DB87FD5DD329091ACB0C3B31A99F42C9E8DDBD0 | |||
| 7160 | 1FFB.tmp | C:\Users\admin\AppData\Local\Temp\2059.tmp | executable | |
MD5:08475B62BAFA5C1A558606B1D27939B4 | SHA256:CAA2CD2D9E19BB037EFCDAF5BBFF87173226E7390CC3DB5205A981A4DB87FB08 | |||
| 8084 | 2059.tmp | C:\Users\admin\AppData\Local\Temp\20A7.tmp | executable | |
MD5:AF1B27BA384E1ECDA05F2978756FD93D | SHA256:0B8F239AA34E80A5E06ECB8A149D71E45FB5313D8697B6EB375264C6A5F719C6 | |||
| 5580 | 2114.tmp | C:\Users\admin\AppData\Local\Temp\2182.tmp | executable | |
MD5:BE02327821619E5FE9ABF51B8095228C | SHA256:D4C1261B08BC75587BA9B7C8F2A42D1C5B10925FDF74F438981D52224C5DCDD8 | |||
| 5636 | 2328.tmp | C:\Users\admin\AppData\Local\Temp\23A5.tmp | executable | |
MD5:122C7D71883D790989526420AFBA476C | SHA256:E7AC21E5DC96F41854DA1855EE8C02C4E35174189E186DFC9A0E5C915D44896B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | POST | 204 | 2.18.29.200:443 | https://www.bing.com/web/xlsc.aspx?t=5&dl=1&wsbc=1 | unknown | — | — | unknown |
— | — | GET | 200 | 2.18.29.200:443 | https://www.bing.com/DSB/search?dsbmr=1&format=dsbjson&client=windowsminiserp&dsbschemaversion=1.1&dsbminiserp=1&q=q&cc=US&setlang=en-us&clientDateTime=10%2F3%2F2025%2C%204%3A25%3A12%20PM | unknown | binary | 64.3 Kb | unknown |
— | — | POST | 200 | 20.190.160.3:443 | https://login.live.com/RST2.srf | US | xml | 11.2 Kb | unknown |
— | — | POST | 200 | 20.190.160.130:443 | https://login.live.com/RST2.srf | US | xml | 11.1 Kb | unknown |
— | — | POST | 200 | 20.190.160.17:443 | https://login.live.com/RST2.srf | US | xml | 11.3 Kb | unknown |
— | — | POST | 200 | 40.126.32.76:443 | https://login.live.com/RST2.srf | US | xml | 11.0 Kb | unknown |
— | — | POST | 200 | 20.190.160.132:443 | https://login.live.com/RST2.srf | US | xml | 11.3 Kb | unknown |
— | — | GET | 200 | 2.18.29.210:443 | https://www.bing.com/th?id=ODSWG.31bcf3d1-4df8-4c6a-9b3a-447ced8d6c39&pid=dsb | unknown | image | 4.64 Kb | unknown |
— | — | GET | 200 | 20.223.36.55:443 | https://arc.msn.com/v3/Delivery/Placement?pubid=da63df93-3dbc-42ae-a505-b34988683ac7&pid=310091&adm=2&w=1&h=1&wpx=1&hpx=1&fmt=json&cltp=app&dim=le&rafb=0&nct=1&pm=1&cfmt=text,image,poly&sft=jpeg,png,gif&topt=1&poptin=0&localid=w:AC7699B0-48EA-FD22-C8DC-06A02098A0F0&ctry=US&time=20251003T162512Z&lc=en-US&pl=en-US&idtp=mid&uid=9115d6d1-9f4e-4053-9297-2a8c833b3912&aid=00000000-0000-0000-0000-000000000000&ua=WindowsShellClient%2F9.0.40929.0%20%28Windows%29&asid=17b7dd2d3d394a70a38e18d524fe7d17&ctmode=MultiSession&arch=x64&betaedgever=0.0.0.0&canedgever=0.0.0.0&cdm=1&cdmver=10.0.19041.3636&currsel=134045512450000000&devedgever=0.0.0.0&devfam=Windows.Desktop&devform=Unknown&devosver=10.0.19045.4046&disphorzres=1360&dispsize=16.3&dispvertres=768&fosver=16299&isu=0&lo=4245624&metered=false&nettype=ethernet&npid=sc-310091&oemName=DELL&oemid=DELL&ossku=Professional&prevosver=15063&rver=2&smBiosDm=DELL&stabedgever=133.0.3065.92&tl=2&tsu=1636154&waasBldFlt=1&waasCfgExp=1&waasCfgSet=1&waasRetail=1&waasRing=&svoffered=2 | US | binary | 4.38 Kb | unknown |
— | — | GET | 200 | 20.223.35.26:443 | https://arc.msn.com/v3/Delivery/Placement?pubid=da63df93-3dbc-42ae-a505-b34988683ac7&pid=280815&adm=2&w=1&h=1&wpx=1&hpx=1&fmt=json&cltp=app&dim=le&rafb=0&nct=1&pm=1&cfmt=text,image,poly&sft=jpeg,png,gif&topt=1&poptin=0&localid=w:AC7699B0-48EA-FD22-C8DC-06A02098A0F0&ctry=US&time=20251003T162512Z&lc=en-US&pl=en-US&idtp=mid&uid=9115d6d1-9f4e-4053-9297-2a8c833b3912&aid=00000000-0000-0000-0000-000000000000&ua=WindowsShellClient%2F9.0.40929.0%20%28Windows%29&asid=80ef9a468676405c8512dceb6f3ffaeb&ctmode=MultiSession&arch=x64&betaedgever=0.0.0.0&canedgever=0.0.0.0&cdm=1&cdmver=10.0.19041.3636&currsel=137271744000000000&devedgever=0.0.0.0&devfam=Windows.Desktop&devform=Unknown&devosver=10.0.19045.4046&disphorzres=1360&dispsize=16.3&dispvertres=768&fosver=16299&isu=0&lo=4245624&metered=false&nettype=ethernet&npid=sc-280815&oemName=DELL&oemid=DELL&ossku=Professional&prevosver=15063&smBiosDm=DELL&stabedgever=133.0.3065.92&tl=2&tsu=1636154&waasBldFlt=1&waasCfgExp=1&waasCfgSet=1&waasRetail=1&waasRing=&svoffered=2 | US | binary | 3.21 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
6016 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2652 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 2.16.241.218:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6016 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5948 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5224 | SearchApp.exe | 2.16.241.222:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
2832 | svchost.exe | 20.190.160.4:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4068 | backgroundTaskHost.exe | 20.223.36.55:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
google.com |
| whitelisted |
login.live.com |
| whitelisted |
arc.msn.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |