| File name: | bff3d0ae0754aace2eb079ec6219dace494620a3aaf71a2d2d8a2e09211f070b.exe |
| Full analysis: | https://app.any.run/tasks/b554a271-efe0-41c2-8ce2-44ad7ea1d313 |
| Verdict: | Malicious activity |
| Analysis date: | October 03, 2025, 16:24:57 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
| MD5: | D51D8F1AA8ED51625E2CF6B8593DDB53 |
| SHA1: | 978F99636D9C7431886E6A2BB86D404106D98A87 |
| SHA256: | BFF3D0AE0754AACE2EB079EC6219DACE494620A3AAF71A2D2D8A2E09211F070B |
| SSDEEP: | 12288:GEY859yqwTEvcPdZnCtsy27ibu2TQbQVtClL7lhPAIkrkNVVh6yzD3:GEY89WxCtD278u2U4IV7lhPAIkrTyzr |
| .exe | | | DOS Executable Generic (100) |
|---|
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2003:11:11 14:39:16+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 10 |
| CodeSize: | 140288 |
| InitializedDataSize: | 356352 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x113b6 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 12.0.4518.1014 |
| ProductVersionNumber: | 12.0.4518.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Microsoft Corporation |
| FileDescription: | Microsoft Office Word |
| FileVersion: | 12.0.4518.1014 |
| InternalName: | WinWord |
| LegalCopyright: | © 2006 Microsoft Corporation. All rights reserved. |
| LegalTrademarks1: | Microsoft® is a registered trademark of Microsoft Corporation. |
| LegalTrademarks2: | Windows® is a registered trademark of Microsoft Corporation. |
| OriginalFileName: | WinWord.exe |
| ProductName: | 2007 Microsoft Office system |
| ProductVersion: | 12.0.4518.1014 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 8 | "C:\Users\admin\AppData\Local\Temp\B4C9.tmp" | C:\Users\admin\AppData\Local\Temp\B4C9.tmp | — | B46B.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 8 | "C:\Users\admin\AppData\Local\Temp\D5DE.tmp" | C:\Users\admin\AppData\Local\Temp\D5DE.tmp | — | D409.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 8 | "C:\Users\admin\AppData\Local\Temp\E9E3.tmp" | C:\Users\admin\AppData\Local\Temp\E9E3.tmp | — | E985.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 8 | "C:\Users\admin\AppData\Local\Temp\1DF.tmp" | C:\Users\admin\AppData\Local\Temp\1DF.tmp | — | 182.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 8 | "C:\Users\admin\AppData\Local\Temp\433E.tmp" | C:\Users\admin\AppData\Local\Temp\433E.tmp | — | 42D0.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 532 | "C:\Users\admin\AppData\Local\Temp\4EC7.tmp" | C:\Users\admin\AppData\Local\Temp\4EC7.tmp | — | 4E69.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 532 | "C:\Users\admin\AppData\Local\Temp\6BB5.tmp" | C:\Users\admin\AppData\Local\Temp\6BB5.tmp | — | 6B67.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 572 | "C:\Users\admin\AppData\Local\Temp\902A.tmp" | C:\Users\admin\AppData\Local\Temp\902A.tmp | — | 8FCC.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 572 | "C:\Users\admin\AppData\Local\Temp\E8D9.tmp" | C:\Users\admin\AppData\Local\Temp\E8D9.tmp | — | E87B.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| 572 | "C:\Users\admin\AppData\Local\Temp\E5.tmp" | C:\Users\admin\AppData\Local\Temp\E5.tmp | — | 97.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Word Exit code: 0 Version: 12.0.4518.1014 Modules
| |||||||||||||||
| (PID) Process: | (7472) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (7472) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (7472) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (6760) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (6760) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (6760) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (7032) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (7032) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (7032) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (4212) BackgroundTransferHost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 7588 | 21E0.tmp | C:\Users\admin\AppData\Local\Temp\224D.tmp | executable | |
MD5:E81F372ED0679DB53DE7526EE0650F89 | SHA256:E591367505B58A56BB2D34D5208C9E398105AA63B4CF9F1470A50A2F42456795 | |||
| 7036 | 1F30.tmp | C:\Users\admin\AppData\Local\Temp\1F9D.tmp | executable | |
MD5:BF229212DBF13F57301CE07E3CA46681 | SHA256:5CE855EB84C66F5FFC9DE1FA798C62A51156DD99A4A643C834E4B5A55ADB19E5 | |||
| 8084 | 2059.tmp | C:\Users\admin\AppData\Local\Temp\20A7.tmp | executable | |
MD5:AF1B27BA384E1ECDA05F2978756FD93D | SHA256:0B8F239AA34E80A5E06ECB8A149D71E45FB5313D8697B6EB375264C6A5F719C6 | |||
| 7160 | 1FFB.tmp | C:\Users\admin\AppData\Local\Temp\2059.tmp | executable | |
MD5:08475B62BAFA5C1A558606B1D27939B4 | SHA256:CAA2CD2D9E19BB037EFCDAF5BBFF87173226E7390CC3DB5205A981A4DB87FB08 | |||
| 5580 | 2114.tmp | C:\Users\admin\AppData\Local\Temp\2182.tmp | executable | |
MD5:BE02327821619E5FE9ABF51B8095228C | SHA256:D4C1261B08BC75587BA9B7C8F2A42D1C5B10925FDF74F438981D52224C5DCDD8 | |||
| 7792 | 20A7.tmp | C:\Users\admin\AppData\Local\Temp\2114.tmp | executable | |
MD5:6528FD50F602D9065551C9D4DECB4A12 | SHA256:C741F18F339E1ED8F12B132447771E7BE9965109AA5C0DAD083BF133B965E360 | |||
| 6972 | 224D.tmp | C:\Users\admin\AppData\Local\Temp\22AB.tmp | executable | |
MD5:E8FBD0B638076D705DC5094A83F19403 | SHA256:AFA2D249DCF292E85C342E6A0DAB83F213255F7DC5454EA7F189CE8CC84F53CD | |||
| 6120 | 1DD8.tmp | C:\Users\admin\AppData\Local\Temp\1E46.tmp | executable | |
MD5:299EAB5C7B68817AF8BE1FED1A3E521A | SHA256:442B8888C643421FCE64342C8E51E0350879988DB17C404A11E94383C5294317 | |||
| 1132 | bff3d0ae0754aace2eb079ec6219dace494620a3aaf71a2d2d8a2e09211f070b.exe | C:\Users\admin\AppData\Local\Temp\1DD8.tmp | executable | |
MD5:53CB6A38D5D2AF5228DEA599D77E7545 | SHA256:0A29A950A6E3DE40CF114D4EBE5966BA6DB6160D47E765DB45B1512F77E9A3D6 | |||
| 4740 | 1F9D.tmp | C:\Users\admin\AppData\Local\Temp\1FFB.tmp | executable | |
MD5:7E6BBE327F94D39D9E636D57B4FBACCF | SHA256:4B2134471986B89473755F7B9DB87FD5DD329091ACB0C3B31A99F42C9E8DDBD0 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 2.18.29.200:443 | https://www.bing.com/DSB/search?dsbmr=1&format=dsbjson&client=windowsminiserp&dsbschemaversion=1.1&dsbminiserp=1&q=q&cc=US&setlang=en-us&clientDateTime=10%2F3%2F2025%2C%204%3A25%3A12%20PM | unknown | binary | 64.3 Kb | unknown |
— | — | POST | 204 | 2.18.29.200:443 | https://www.bing.com/web/xlsc.aspx?t=5&dl=1&wsbc=1 | unknown | — | — | unknown |
— | — | POST | 200 | 20.190.160.3:443 | https://login.live.com/RST2.srf | US | xml | 11.2 Kb | unknown |
— | — | POST | 200 | 20.190.160.4:443 | https://login.live.com/RST2.srf | US | xml | 11.3 Kb | unknown |
— | — | POST | 200 | 20.190.160.17:443 | https://login.live.com/RST2.srf | US | xml | 11.3 Kb | unknown |
— | — | POST | 200 | 40.126.32.76:443 | https://login.live.com/RST2.srf | US | xml | 11.0 Kb | unknown |
— | — | POST | 200 | 20.190.160.130:443 | https://login.live.com/RST2.srf | US | xml | 11.1 Kb | unknown |
— | — | POST | 200 | 20.190.160.132:443 | https://login.live.com/RST2.srf | US | xml | 11.3 Kb | unknown |
— | — | GET | 200 | 2.18.29.227:443 | https://www.bing.com/th?id=ODSWG.8229b0e5-fa8c-4e4a-af74-69717698b903&pid=dsb | unknown | image | 4.62 Kb | unknown |
— | — | GET | 200 | 2.18.29.210:443 | https://www.bing.com/th?id=ODSWG.31bcf3d1-4df8-4c6a-9b3a-447ced8d6c39&pid=dsb | unknown | image | 4.64 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
6016 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2652 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 2.16.241.218:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6016 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5948 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5224 | SearchApp.exe | 2.16.241.222:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
2832 | svchost.exe | 20.190.160.4:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4068 | backgroundTaskHost.exe | 20.223.36.55:443 | arc.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
google.com |
| whitelisted |
login.live.com |
| whitelisted |
arc.msn.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |