| File name: | vhat.exe |
| Full analysis: | https://app.any.run/tasks/e842ab4a-af9e-4e4a-ad85-67df5e6d3b62 |
| Verdict: | Malicious activity |
| Analysis date: | April 19, 2025, 02:03:37 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (console) Intel 80386, for MS Windows, 4 sections |
| MD5: | 5FF75CA5795235EC29125BC6E2E0FC03 |
| SHA1: | 9421B8F5F85596930FD2D1B13B1A5EF502AC1863 |
| SHA256: | C9C4F06E5AFC509C4253345C323FC438C845ECAB0EF91BDDD52AF884E67F247E |
| SSDEEP: | 768:SQAm3cTxyWUucgFwTj9lIUDokoY3Em+mT4mIt:KMGgWNcdbREU3Em7e |
| .exe | | | Win16/32 Executable Delphi generic (34.1) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (32.9) |
| .exe | | | DOS Executable Generic (32.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2025:04:19 01:55:20+00:00 |
| ImageFileCharacteristics: | Executable, Bytes reversed lo, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 2.18 |
| CodeSize: | 29184 |
| InitializedDataSize: | 3584 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x16a0 |
| OSVersion: | 1.11 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows command line |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 516 | ".\Windows\SysWOW64\RdpSaProxy.exe" | C:\Windows\SysWOW64\RdpSaProxy.exe | — | vhat.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: RDP Session Agent Proxy Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 516 | ".\Windows\System32\clip.exe" | C:\Windows\SysWOW64\clip.exe | — | vhat.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Clip - copies the data into clipboard Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 536 | ".\Windows\System32\schtasks.exe" | C:\Windows\SysWOW64\schtasks.exe | — | vhat.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 536 | ".\Windows\HelpPane.exe" | C:\Windows\HelpPane.exe | — | vhat.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Help and Support Exit code: 4294967295 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 536 | ".\Windows\System32\RpcPing.exe" | C:\Windows\SysWOW64\RpcPing.exe | — | vhat.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: RPC Ping Utility Exit code: 5 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 684 | ".\Windows\System32\SyncHost.exe" | C:\Windows\SysWOW64\SyncHost.exe | — | vhat.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Host Process for Windows Sync Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 872 | ".\Windows\SysWOW64\perfmon.exe" | C:\Windows\SysWOW64\perfmon.exe | — | vhat.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Resource and Performance Monitor Exit code: 3221226540 Version: 10.00 Modules
| |||||||||||||||
| 960 | ".\Windows\System32\w32tm.exe" | C:\Windows\System32\w32tm.exe | — | w32tm.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Time Service Diagnostic Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 968 | ".\Windows\System32\netbtugc.exe" | C:\Windows\SysWOW64\netbtugc.exe | — | vhat.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: NetBT Unattend Generic Command Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1004 | C:\WINDOWS\winsxs\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exe -Embedding | C:\Windows\WinSxS\amd64_microsoft-windows-servicingstack_31bf3856ad364e35_10.0.19041.3989_none_7ddb45627cb30e03\TiWorker.exe | — | svchost.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Modules Installer Worker Version: 10.0.19041.3989 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (5800) dllhost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Ole\Instrumentation |
| Operation: | write | Name: | InstrumentationLogFileDir |
Value: C:\WINDOWS\system32\com | |||
| (PID) Process: | (7248) cmmon32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\CMMON32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (7248) cmmon32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\CMMON32 |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
| (PID) Process: | (7248) cmmon32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\CMMON32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (7248) cmmon32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\CMMON32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (7248) cmmon32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\CMMON32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
| (PID) Process: | (7248) cmmon32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\CMMON32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (7248) cmmon32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\CMMON32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
| (PID) Process: | (7884) setup_wm.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\MediaPlayer\Preferences |
| Operation: | delete value | Name: | UsageTracking |
Value: | |||
| (PID) Process: | (7884) setup_wm.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\MediaPlayer\Preferences |
| Operation: | delete value | Name: | ForceUsageTracking |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1228 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_Windows.WARP.JIT_7f62154bdac86d6e50d9d95360b25359a157d2f_2f81cf5c_1ae02f15-d4c5-40fb-b516-80f491f8bad6\Report.wer | — | |
MD5:— | SHA256:— | |||
| 8536 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_Windows.WARP.JIT_7f62154bdac86d6e50d9d95360b25359a157d2f_2f81cf5c_7234155f-6cd3-4471-b4d5-13e1c11eb6db\Report.wer | — | |
MD5:— | SHA256:— | |||
| 1228 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WERED41.tmp.WERInternalMetadata.xml | binary | |
MD5:2D55266CF8A435D983DB17A1EA0FA329 | SHA256:E0590211B347DB8E8D2D547E6450D5953BD4DE77DF695BEFA1D2FACC5588724D | |||
| 5640 | RMActivate_ssp.exe | C:\ProgramData\Microsoft\DRM\Server\S-1-5-21-1693682860-607145093-2874071422-1001\CERT-Machine.drm | binary | |
MD5:6B271CF4E71028D2B0AAB01574AC29CF | SHA256:9671F565369DB1B10706042A0B8498BCF7477FAEBF7B92041757489620362DA8 | |||
| 5640 | RMActivate_ssp.exe | C:\ProgramData\Microsoft\Crypto\RSA\MachineKeys\07f8ec5c7dc978e8826fb97d28402ef0_bb926e54-e3ca-40fd-ae90-2764341e7792 | binary | |
MD5:3A1A9923C4225254154E297B092E93F5 | SHA256:D9ED1121DD214D004AC2D20817BB4AB40F11498368277CE74E83185B042D385A | |||
| 5640 | RMActivate_ssp.exe | C:\ProgramData\Microsoft\DRM\Server\S-1-5-21-1693682860-607145093-2874071422-1001\CERT-Machine-2048.drm | binary | |
MD5:727EFB3E87F7105E2648B7217BF45C3C | SHA256:C7E47DA8E01E1568B69043488A3981FD08BFDBC182F201EEEBE94B8EA233EA7E | |||
| 5800 | dllhost.exe | C:\Windows\Registration\{02D4B3F1-FD88-11D1-960D-00805FC79235}.{8A5722A3-207F-4F9E-9393-10E46600F2F9}.crmlog | binary | |
MD5:306A5E959D38BC962C6D24E5952B18F3 | SHA256:FA46832D1B9F12416FC3216A81BF5E251134137BBF65F3E8513A3C8E5FD4F0B0 | |||
| 7432 | unregmp2.exe | C:\Users\admin\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNSD.XML | text | |
MD5:A9B5DA9AEC61657B32393D96217165F0 | SHA256:9F4611369CF65B33D886489B2486FCA7B1E83E0DC998D35B15B3AA4C8478A28D | |||
| 9452 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_SystemSettings.e_7b9fad3f749d9ab87e3cdc494a240af197021a_e3591d10_df64cd30-dafb-4b86-b9a3-427889d1bafc\Report.wer | — | |
MD5:— | SHA256:— | |||
| 7432 | unregmp2.exe | C:\Users\admin\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.XML.bak | text | |
MD5:7050D5AE8ACFBE560FA11073FEF8185D | SHA256:CB87767C4A384C24E4A0F88455F59101B1AE7B4FB8DE8A5ADB4136C5F7EE545B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2104 | svchost.exe | GET | 200 | 95.101.142.9:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 95.101.142.9:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | GET | 200 | 95.101.142.9:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2104 | svchost.exe | 95.101.142.9:80 | crl.microsoft.com | Akamai International B.V. | SE | whitelisted |
5496 | MoUsoCoreWorker.exe | 95.101.142.9:80 | crl.microsoft.com | Akamai International B.V. | SE | whitelisted |
— | — | 95.101.142.9:80 | crl.microsoft.com | Akamai International B.V. | SE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5496 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3812 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
2196 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
3012 | dasHost.exe | 239.255.255.250:3702 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
2.100.168.192.in-addr.arpa |
| whitelisted |
158.240.127.40.in-addr.arpa |
| unknown |
9.142.101.95.in-addr.arpa |
| unknown |
250.255.255.239.in-addr.arpa |
| unknown |
252.0.0.224.in-addr.arpa |
| unknown |
3.0.0.0.1.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa |
| unknown |
b.f.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.0.2.0.f.f.ip6.arpa |
| unknown |