File name:

个人团队拖算记帐明细.exe

Full analysis: https://app.any.run/tasks/a0fc1bb7-ccc4-4318-9be5-8f68fd2aeb16
Verdict: Malicious activity
Analysis date: August 28, 2024, 07:20:09
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
upx
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

7414B4CAC0C3315F16FBBE56FD375A1E

SHA1:

E7F0630D1F2FC7F0CD4DF8A0BA510F847DD922F7

SHA256:

C4C8D1077FF59CD74C9085DD0D6D450D5C4D5A5ACD5A6664E812DF36E2200946

SSDEEP:

49152:YyL4t3nxi+W8gLy+UBhe26CXLl4p2La9fNLWhLtPXDXTt1SaT1A0:T4t3xhpGy+U/T66o2La9f9ELtPTXTSa5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was injected by another process

      • svchost.exe (PID: 1316)
    • Runs injected code in another process

      • StarRail.exe (PID: 5152)
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • 个人团队拖算记帐明细.exe (PID: 5088)
      • 个人团队拖算记帐明细.exe (PID: 6792)
      • cmd.exe (PID: 3984)
      • cmd.exe (PID: 3964)
    • Executable content was dropped or overwritten

      • 个人团队拖算记帐明细.exe (PID: 6792)
      • cmd.exe (PID: 3984)
      • cmd.exe (PID: 3964)
      • svchost.exe (PID: 5724)
    • Executes as Windows Service

      • cmd.exe (PID: 3984)
      • cmd.exe (PID: 3964)
      • cmd.exe (PID: 4804)
      • StarRail.exe (PID: 1480)
    • The process executes via Task Scheduler

      • StarRail.exe (PID: 5152)
      • svchost.exe (PID: 1920)
    • Connects to unusual port

      • svchost.exe (PID: 1920)
  • INFO

    • Reads the computer name

      • 个人团队拖算记帐明细.exe (PID: 5088)
      • 个人团队拖算记帐明细.exe (PID: 6792)
      • StarRail.exe (PID: 5152)
    • Checks supported languages

      • 个人团队拖算记帐明细.exe (PID: 5088)
      • 个人团队拖算记帐明细.exe (PID: 6792)
      • StarRail.exe (PID: 1480)
      • StarRail.exe (PID: 5152)
    • Reads security settings of Internet Explorer

      • svchost.exe (PID: 5724)
    • UPX packer has been detected

      • svchost.exe (PID: 1920)
      • dllhost.exe (PID: 6752)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:08:23 14:56:36+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 10
CodeSize: 7680
InitializedDataSize: 1738240
UninitializedDataSize: -
EntryPoint: 0x2610
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
13
Malicious processes
1
Suspicious processes
3

Behavior graph

Click at the process to see the details
start 个人团队拖算记帐明细.exe no specs winver.exe no specs taskmgr.exe 个人团队拖算记帐明细.exe cmd.exe cmd.exe cmd.exe no specs starrail.exe no specs svchost.exe starrail.exe no specs THREAT svchost.exe THREAT dllhost.exe no specs svchost.exe

Process information

PID
CMD
Path
Indicators
Parent process
1316C:\WINDOWS\system32\svchost.exe -k netsvcs -p -s ScheduleC:\Windows\System32\svchost.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
1480"C:\Program Files\StarRail.exe"C:\Program Files\StarRail.exeservices.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\program files\starrail.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\starrailbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
1920C:\WINDOWS\system32\svchost.exe -k netsvcsC:\Windows\System32\svchost.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
3964cmd /c move C:\WINDOWS\temp\1220578 "C:\Program Files\StarRailBase.dll"C:\Windows\System32\cmd.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
3984cmd /c move C:\WINDOWS\temp\1220468 "C:\Program Files\StarRail.exe"C:\Windows\System32\cmd.exe
services.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
4804cmd /c move C:\WINDOWS\temp\1220687 "C:\Program Files\StarRailBase.dat"C:\Windows\System32\cmd.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
5088"C:\Users\admin\Desktop\个人团队拖算记帐明细.exe" C:\Users\admin\Desktop\个人团队拖算记帐明细.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\个人团队拖算记帐明细.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
5152"C:\WINDOWS\system32\WinDefScan\StarRail.exe" -svcC:\Windows\System32\WinDefScan\StarRail.exesvchost.exe
User:
SYSTEM
Company:
上海米哈游网络科技股份有限公司
Integrity Level:
SYSTEM
Description:
Star Rail
Exit code:
0
Version:
2019.4.34.1463972
Modules
Images
c:\windows\system32\windefscan\starrail.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\windefscan\starrailbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
5724C:\WINDOWS\system32\svchost.exe -InstallC:\Windows\System32\svchost.exe
StarRail.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
6752C:\WINDOWS\system32\dllhost.exe /Processid:{F8284233-48F4-4680-ADDD-F8284233}C:\Windows\System32\dllhost.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
COM Surrogate
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
Total events
5 404
Read events
4 992
Write events
199
Delete events
213

Modification events

(PID) Process:(1316) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{C2AF3602-9179-4BAE-85B3-74A4EF5CF51F}
Operation:writeName:DynamicInfo
Value:
03000000BDCB09F80A59DA01492E22B81AF9DA010000000000000000927933BA1AF9DA01
(PID) Process:(1316) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{AB5CE85E-303A-486F-B7F1-956D2D90533C}
Operation:writeName:DynamicInfo
Value:
030000000324C327AAB7D801492E22B81AF9DA010000000000000000906469BB1AF9DA01
(PID) Process:(5724) svchost.exeKey:HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\3c\52C64B7E
Operation:writeName:@%SystemRoot%\system32\shell32.dll,-50176
Value:
File Operation
(PID) Process:(1316) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WinDefScan
Operation:writeName:SD
Value:
01000480B4000000C400000000000000140000000200A00007000000001018009F011F0001020000000000052000000020020000001014009F011F00010100000000000512000000001014008900120001010000000000050B0000000010140089001200010100000000000513000000001014008900120001010000000000051400000000101800FF011F000102000000000005200000002002000000001400890012000101000000000005120000000000000001020000000000052000000020020000010100000000000512000000
(PID) Process:(1316) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WinDefScan
Operation:writeName:Id
Value:
{B5B552FB-3C7E-4EA0-B377-C4BD7C641B51}
(PID) Process:(1316) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tree\Microsoft\Windows\WinDefScan
Operation:writeName:Index
Value:
1
(PID) Process:(1316) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B5B552FB-3C7E-4EA0-B377-C4BD7C641B51}
Operation:writeName:Path
Value:
\Microsoft\Windows\WinDefScan
(PID) Process:(1316) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B5B552FB-3C7E-4EA0-B377-C4BD7C641B51}
Operation:writeName:Hash
Value:
5BDCA39ACA14D8A0DDAB5A0E01882A68CEB956F12F0EBB400D9A1525523B83E2
(PID) Process:(1316) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B5B552FB-3C7E-4EA0-B377-C4BD7C641B51}
Operation:writeName:Schema
Value:
65538
(PID) Process:(1316) svchost.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Schedule\TaskCache\Tasks\{B5B552FB-3C7E-4EA0-B377-C4BD7C641B51}
Operation:delete valueName:Version
Value:
Executable files
6
Suspicious files
3
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
5724svchost.exeC:\Windows\System32\WinDefScan\StarRailBase.dllexecutable
MD5:7A8543A2FAA9E9A70661A4AC195B7B88
SHA256:32987958B0F77DBE9BB70BFD1B7C81EC407991AF111B455EF4CE255FE96B6C19
3984cmd.exeC:\Program Files\StarRail.exeexecutable
MD5:09CBEBE3306F81DBB1498E2C214B897D
SHA256:2AA3366883B707C1FEA777156417F4BE0B5C90F209FDA1AFAC1C8544ACAB702C
6792个人团队拖算记帐明细.exeC:\Windows\Temp\1220468executable
MD5:09CBEBE3306F81DBB1498E2C214B897D
SHA256:2AA3366883B707C1FEA777156417F4BE0B5C90F209FDA1AFAC1C8544ACAB702C
1316svchost.exeC:\Windows\System32\Tasks\Microsoft\Windows\UpdateOrchestrator\Schedule Scanxml
MD5:11954764DE4745B35A42219A7C5E2DCA
SHA256:997FCF971A38394C30D9E5CA0C6B36E782630E83B52D2664C56F1DEFBA54CB6C
6792个人团队拖算记帐明细.exeC:\Windows\Temp\1220578executable
MD5:7A8543A2FAA9E9A70661A4AC195B7B88
SHA256:32987958B0F77DBE9BB70BFD1B7C81EC407991AF111B455EF4CE255FE96B6C19
6792个人团队拖算记帐明细.exeC:\Windows\Temp\1220687binary
MD5:F452FD4A33F300AB7FF2B66205BAFE5D
SHA256:036A89250A9560291D37FAF5926CBB6FF5C490506EB8584AE0C4A01EEC1CE266
5724svchost.exeC:\Windows\System32\WinDefScan\StarRail.exeexecutable
MD5:09CBEBE3306F81DBB1498E2C214B897D
SHA256:2AA3366883B707C1FEA777156417F4BE0B5C90F209FDA1AFAC1C8544ACAB702C
4804cmd.exeC:\Program Files\StarRailBase.datbinary
MD5:F452FD4A33F300AB7FF2B66205BAFE5D
SHA256:036A89250A9560291D37FAF5926CBB6FF5C490506EB8584AE0C4A01EEC1CE266
5724svchost.exeC:\Windows\System32\WinDefScan\StarRailBase.datbinary
MD5:F452FD4A33F300AB7FF2B66205BAFE5D
SHA256:036A89250A9560291D37FAF5926CBB6FF5C490506EB8584AE0C4A01EEC1CE266
3964cmd.exeC:\Program Files\StarRailBase.dllexecutable
MD5:7A8543A2FAA9E9A70661A4AC195B7B88
SHA256:32987958B0F77DBE9BB70BFD1B7C81EC407991AF111B455EF4CE255FE96B6C19
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
12
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4316
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
6020
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1920
svchost.exe
83.229.127.205:6639
NG
unknown
2120
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4316
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4324
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
google.com
  • 142.250.74.206
whitelisted

Threats

No threats detected
No debug info