File name:

c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exe

Full analysis: https://app.any.run/tasks/898bdf90-dde7-4c7f-a8de-cab4c10dc26b
Verdict: Malicious activity
Threats:

GravityRAT is a sophisticated spyware and remote access trojan that has been actively targeting organizations and government entities since 2016. It uses innovative anti-analysis techniques and made an evolution from a Windows-only threat to a cross-platform espionage tool capable of compromising Windows, Android, and macOS systems.

Analysis date: October 03, 2025, 16:26:21
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
api-base64
wmi-base64
golang
gravityrat
rat
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64 (stripped to external PDB), for MS Windows, 5 sections
MD5:

D61B0C0981D23844D820A440A0FE7501

SHA1:

B1D16B0E9AAC310552B0A69BBCAC04DE4EB02E93

SHA256:

C9650205A19CCBEB439F1D1FECD8AD62CB173A3F8708C105CEF008C634ACEF5D

SSDEEP:

98304:6AbDg6Mruq2aOhsFn9i1VO0B1St3Q9eGx28ivLwP+1GDeGx28ivLwP+1GveGx28d:NP1StZ3nsmoMm7Beqii

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • GRAVITYRAT has been detected (YARA)

      • c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exe (PID: 756)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exe (PID: 756)
    • There is functionality for taking screenshot (YARA)

      • c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exe (PID: 756)
  • INFO

    • Checks proxy server information

      • slui.exe (PID: 2652)
    • Potential library load (Base64 Encoded 'LoadLibrary')

      • c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exe (PID: 756)
    • Reads the software policy settings

      • slui.exe (PID: 2652)
      • c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exe (PID: 756)
    • Failed to create an executable file in Windows directory

      • c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exe (PID: 756)
    • Application based on Golang

      • c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exe (PID: 756)
    • Found Base64 encoded reference to WMI classes (YARA)

      • c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exe (PID: 756)
    • Detects GO elliptic curve encryption (YARA)

      • c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exe (PID: 756)
    • Reads the machine GUID from the registry

      • c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exe (PID: 756)
    • Reads the computer name

      • c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exe (PID: 756)
    • Checks supported languages

      • c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exe (PID: 756)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.3)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 0000:00:00 00:00:00
ImageFileCharacteristics: No relocs, Executable, Large address aware, No debug
PEType: PE32+
LinkerVersion: 3
CodeSize: 2279424
InitializedDataSize: 210432
UninitializedDataSize: -
EntryPoint: 0x58b20
OSVersion: 4
ImageVersion: 1
SubsystemVersion: 4
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
152
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
560\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exec9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
756"C:\Users\admin\Desktop\c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exe" C:\Users\admin\Desktop\c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
2
Modules
Images
c:\users\admin\desktop\c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2652C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
6 964
Read events
6 964
Write events
0
Delete events
0

Modification events

No data
Executable files
105
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
756c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppVScripting.dllexecutable
MD5:DB7382ECFE39AE5853706295B6A4846B
SHA256:276E2CE8527500D511D77D1A2840156B8F139E8A61BDCC3AAAA4C6E8866FED7F
756c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems64_arm64x.dllexecutable
MD5:CA4B234DE63DB13F9DDE8B1EB25B175F
SHA256:8507C69781ECA884EF1BC693698D2ED3CDD4BA3E5A79C79C4E60974D6EFBCC91
756c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\C2R64.dllexecutable
MD5:4FD0BA7AA342521F99C266FE11006278
SHA256:DE8A7E94882324036AC72BEA5F110E262994C96E0F4D476BC61D7DD80CF4CC18
756c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\C2R32.dllexecutable
MD5:06C9C5B4524C633D642A8B0A7C6BEF7F
SHA256:D772D8A15CD56B4F36C33B581EA4AC190E5E628318F1C275A42240F0752F9269
756c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\C2RINTL.cs-cz.dllexecutable
MD5:A70ADB12D740711B1BDDAB9C0FBD860F
SHA256:75B4B78A855F59E087AC5051BBE09316CFAF854A4B96D3F358945D5209F37E26
756c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppvIsvSubsystems32.dllexecutable
MD5:9F862844D38D238026324A3E71A640FC
SHA256:C20A20FB3F628CE79FBB58BDCEBEA8CA81F104D357A7623CB5CAF169DB8F8E6D
756c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppVClientIsv.manexecutable
MD5:53E7DB60DC1856DA42398EE99AFF5E4E
SHA256:F89820927C557BC74632E006A5C481CD0CE14E6182692EB14B73CD7C905712AA
756c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppVClient.manexecutable
MD5:30AA080983E3C2F97FC6B260464DB635
SHA256:4732D6DF2C7BEDE6F99B35C0065109921EF7438BCCBF9F5625EFE6D28DCB9A1F
756c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppVIsvSubsystems64_msix.dllexecutable
MD5:09F5C2B521EBCC7053D3B7F89C29BD49
SHA256:1DEB5B848860BA2BD232D5CC4294432EA64CD25A9218FC4D1D8C25421982BA7D
756c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exeC:\Program Files\Common Files\microsoft shared\ClickToRun\AppVShNotify.exeexecutable
MD5:B1C19913A2396634BBDDF7AD31A507A8
SHA256:9FE338AC711E24360201FBBDB2CD1D4DFF6B92AF9C64422BECCF33BEBDF23D80
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
14
DNS requests
11
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
POST
500
4.154.209.85:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
xml
512 b
unknown
POST
500
4.154.209.85:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
xml
512 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
92.123.104.52:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
756
c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exe
198.51.100.1:443
ent34ndx3cz8k.x.pipedream.net
whitelisted
3848
slui.exe
4.154.185.43:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2652
slui.exe
4.154.185.43:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
whitelisted
www.bing.com
  • 92.123.104.52
  • 92.123.104.8
  • 92.123.104.13
  • 92.123.104.51
  • 92.123.104.62
  • 92.123.104.53
  • 92.123.104.17
  • 92.123.104.54
  • 92.123.104.61
whitelisted
google.com
  • 142.250.186.46
whitelisted
ent34ndx3cz8k.x.pipedream.net
  • 198.51.100.1
unknown
EvlXFW.b17da333ec194ec4b767.d.requestbin.net
unknown
soHFIBPq.b17da333ec194ec4b767.d.requestbin.net
unknown
t.b17da333ec194ec4b767.d.requestbin.net
unknown
stdEvN.b17da333ec194ec4b767.d.requestbin.net
unknown
MTwl.b17da333ec194ec4b767.d.requestbin.net
unknown
activation-v2.sls.microsoft.com
  • 4.154.185.43
whitelisted

Threats

PID
Process
Class
Message
756
c9650205a19ccbeb439f1d1fecd8ad62cb173a3f8708c105cef008c634acef5d.exe
Misc activity
ET INFO Webhook/HTTP Request Inspection Service Domain (x .pipedream .net in TLS SNI)
2428
svchost.exe
Misc activity
ET INFO DNS Query for Webhook/HTTP Request Inspection Service (x .pipedream .net)
2428
svchost.exe
Misc activity
ET INFO DNSBin Demo (requestbin .net) - Data Exfil
No debug info