File name:

Temp.exe

Full analysis: https://app.any.run/tasks/74ff47b4-5a18-40dc-82d6-da96cfd78344
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: February 15, 2026, 06:21:22
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
stealer
vmprotect
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64, for MS Windows, 8 sections
MD5:

764E70BB7A203D94E5CEE9BD1641E6BC

SHA1:

14752F626395FCBB2887AE059A24D730C3BD31B9

SHA256:

CB7833C9CCF83E18E3E39070F2C99E8FFDB64D038732E16C696E71BCD290CA42

SSDEEP:

98304:BXoAGi1aGgpBI48MLGjU/Smt03xze+apprIszP7krSURn37AZkHCR/u96ZGIhv11:Elw5pNIH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes powershell execution policy (Bypass)

      • Temp.exe (PID: 9048)
  • SUSPICIOUS

    • The process bypasses the loading of PowerShell profile settings

      • Temp.exe (PID: 9048)
    • Possible stealing of messenger data

      • powershell.exe (PID: 5440)
      • powershell.exe (PID: 508)
    • Creates file in the systems drive root

      • Temp.exe (PID: 9048)
    • Starts POWERSHELL.EXE for commands execution

      • Temp.exe (PID: 9048)
    • The process executes Powershell scripts

      • powershell.exe (PID: 508)
    • Bypass execution policy to execute commands

      • powershell.exe (PID: 508)
      • powershell.exe (PID: 5440)
    • Starts CMD.EXE for commands execution

      • Temp.exe (PID: 9048)
  • INFO

    • Checks supported languages

      • Temp.exe (PID: 9048)
    • Drops script file

      • Temp.exe (PID: 9048)
      • powershell.exe (PID: 508)
      • powershell.exe (PID: 5440)
    • Checks proxy server information

      • Temp.exe (PID: 9048)
      • slui.exe (PID: 7492)
    • Reads the computer name

      • Temp.exe (PID: 9048)
    • Reads the machine GUID from the registry

      • Temp.exe (PID: 9048)
    • Reads security settings of Internet Explorer

      • Temp.exe (PID: 9048)
    • VMProtect protector has been detected

      • Temp.exe (PID: 9048)
    • Create files in a temporary directory

      • Temp.exe (PID: 9048)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2025:12:10 02:02:27+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.44
CodeSize: 196608
InitializedDataSize: 93184
UninitializedDataSize: -
EntryPoint: 0x3dbd73
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
147
Monitored processes
9
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start temp.exe conhost.exe no specs powershell.exe no specs conhost.exe no specs cmd.exe no specs powershell.exe no specs conhost.exe no specs slui.exe temp.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
508powershell -ExecutionPolicy Bypass -NoProfile -File "C:\Users\admin\AppData\Local\Temp\extract_ids.ps1"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeTemp.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
2456"C:\Users\admin\Desktop\Temp.exe" C:\Users\admin\Desktop\Temp.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\temp.exe
c:\windows\system32\ntdll.dll
3036\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5392C:\WINDOWS\system32\cmd.exe /c clsC:\Windows\System32\cmd.exeTemp.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
5440powershell -ExecutionPolicy Bypass -NoProfile -File "C:\Users\admin\AppData\Local\Temp\extract_ids.ps1"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exeTemp.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
7372\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeTemp.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7492C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
8324\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
9048"C:\Users\admin\Desktop\Temp.exe" C:\Users\admin\Desktop\Temp.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\temp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\virtdisk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
Total events
15 536
Read events
15 533
Write events
3
Delete events
0

Modification events

(PID) Process:(9048) Temp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(9048) Temp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(9048) Temp.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
0
Suspicious files
1
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
508powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_by0t4v1i.rc2.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
5440powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_ybhwayhv.nk1.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
5440powershell.exeC:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractivebinary
MD5:C3A20630854ABFCBA0E5E9E1AB276148
SHA256:ACB6333F86A40CE1C0CB70518DF6CF4C70819EA06BEEE821E999A4B9BECF21BA
9048Temp.exeC:\screenshot.jpgimage
MD5:09868EFC8FFA2321F8215B5EE70A1909
SHA256:59765D4AC83AA803B0EE756A846A6958D6005DEE09B9AF0DA3B2AD5D7BF9D7AE
508powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_s3vzqaqy.utp.ps1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
5440powershell.exeC:\Users\admin\AppData\Local\Temp\__PSScriptPolicyTest_ew3atg3f.tfe.psm1text
MD5:D17FE0A3F47BE24A6453E9EF58C94641
SHA256:96AD1146EB96877EAB5942AE0736B82D8B5E2039A80D3D6932665C1A4C87DCF7
9048Temp.exeC:\Users\admin\AppData\Local\Temp\extract_ids.ps1text
MD5:63152A0A257DE6DC7149C5B326CB90E6
SHA256:63BB0A53FC13C221932BC50571FA52AFC81A662FDEFDCFB469CB0D1A1C4046DA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
17
TCP/UDP connections
24
DNS requests
12
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
8776
svchost.exe
GET
200
2.16.168.124:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
POST
200
188.114.96.3:443
https://spoof.su/api/upload-screenshot
unknown
text
16 b
unknown
GET
200
2.16.168.124:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6768
MoUsoCoreWorker.exe
GET
200
2.16.168.124:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
9048
Temp.exe
POST
200
188.114.96.3:443
https://spoof.su/api/upload-screenshot
unknown
16 b
unknown
POST
500
48.192.1.65:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
unknown
binary
512 b
unknown
3292
svchost.exe
GET
200
72.246.29.11:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.2.crl
unknown
whitelisted
3588
slui.exe
POST
500
48.192.1.65:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
unknown
512 b
whitelisted
3292
svchost.exe
GET
200
72.246.29.11:80
http://www.microsoft.com/pkiops/crl/Microsoft%20Time-Stamp%20PCA%202010(1).crl
unknown
whitelisted
3292
svchost.exe
GET
200
72.246.29.11:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Signing%20CA%202.3.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
95.100.158.115:443
www.bing.com
AKAMAI-ASN1
NL
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
8776
svchost.exe
2.16.168.124:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
2.16.168.124:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
6768
MoUsoCoreWorker.exe
2.16.168.124:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
8776
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
9048
Temp.exe
188.114.96.3:443
spoof.su
CLOUDFLARENET
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
www.bing.com
  • 95.100.158.115
  • 23.3.89.89
  • 23.11.206.104
  • 95.100.158.122
  • 95.100.158.107
  • 23.11.206.107
  • 95.100.158.123
  • 23.11.206.106
  • 23.3.89.96
whitelisted
google.com
  • 142.251.141.174
whitelisted
crl.microsoft.com
  • 2.16.168.124
  • 2.16.168.114
  • 23.216.77.28
  • 23.216.77.6
whitelisted
spoof.su
  • 188.114.96.3
  • 188.114.97.3
unknown
activation-v2.sls.microsoft.com
  • 48.192.1.65
whitelisted
www.microsoft.com
  • 72.246.29.11
  • 2.23.246.101
whitelisted
self.events.data.microsoft.com
  • 40.79.173.41
whitelisted

Threats

PID
Process
Class
Message
2292
svchost.exe
Misc activity
INFO [ANY.RUN] .su TLD domain request
No debug info