File name:

cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53

Full analysis: https://app.any.run/tasks/332a245d-4e11-4af3-a761-b4785507aac0
Verdict: Malicious activity
Analysis date: November 13, 2024, 18:10:11
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64, for MS Windows, 5 sections
MD5:

A6A3351187150EF3B8AFEAFC06762F01

SHA1:

CC3932A9C6A8ABC19BA771B4BF05FDF3CD1663C9

SHA256:

CD2956B443FE41A96CD3D6ACFD4932F77482C27E65EE8ACD92AF58629E233B53

SSDEEP:

384:YsL4RnbWV+QYqG4IG6OLvl3im4CF/Cr1BLIs9fR:10qG6jt3V4CF/rs9fR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the date of Windows installation

      • cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe (PID: 920)
    • Reads security settings of Internet Explorer

      • cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe (PID: 920)
      • cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe (PID: 6256)
    • Checks Windows Trust Settings

      • cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe (PID: 6256)
    • Application launched itself

      • cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe (PID: 920)
    • Creates file in the systems drive root

      • cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe (PID: 6256)
  • INFO

    • Checks supported languages

      • cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe (PID: 920)
      • cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe (PID: 6256)
    • Reads the computer name

      • cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe (PID: 920)
      • cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe (PID: 6256)
    • Process checks computer location settings

      • cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe (PID: 920)
    • The process uses the downloaded file

      • cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe (PID: 920)
    • Checks proxy server information

      • cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe (PID: 6256)
    • Reads the software policy settings

      • cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe (PID: 6256)
    • Creates files in the program directory

      • cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe (PID: 6256)
    • Reads the machine GUID from the registry

      • cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe (PID: 6256)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:07:25 20:37:53+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.4
CodeSize: 9216
InitializedDataSize: 11264
UninitializedDataSize: -
EntryPoint: 0x287c
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
130
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe no specs conhost.exe no specs cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
920"C:\Users\admin\Desktop\cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe" C:\Users\admin\Desktop\cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
4076\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5276\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6256"C:\Users\admin\Desktop\cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe" --foodsumC:\Users\admin\Desktop\cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe
cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
70 921
Read events
70 918
Write events
3
Delete events
0

Modification events

(PID) Process:(6256) cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6256) cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6256) cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
1
Suspicious files
4 660
Text files
357
Unknown types
112

Dropped files

PID
Process
Filename
Type
6256cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exeC:\Users\admin\Desktop\desktop.ini.enc
MD5:
SHA256:
6256cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exeC:\Users\admin\Documents\OneNote Notebooks\My Notebook\Open Notebook.onetoc2.encbinary
MD5:79EC8E9EA22CF492DE2F5DFDC06F1AEF
SHA256:CDDBA5D14140CDD3FDA00EFC4E06190255C5314071835A92DC46917A61933950
6256cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exeC:\Users\admin\Documents\OneNote Notebooks\My Notebook\Quick Notes.one.encbinary
MD5:13430AEE6C7DF39C35B327AA0E25F27D
SHA256:862C67F4F5C001E17BDDCA60162DE19FB78CFC6FCF03A98DA49C1406F6562FA7
6256cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exeC:\Users\admin\Desktop\motorprivate.png.encbinary
MD5:5C254E1A90F927576602DFAA923E8B33
SHA256:E84221E4391EB7DE77C12398247BF72CA52B0ABEEFA68BAEBFF4948529560155
6256cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exeC:\Users\admin\Desktop\electronicversion.rtf.encbinary
MD5:69C2828214F5914715C19B8A46AFE771
SHA256:2751E9F43FD211DF3607A71CF1C5BB5D3636781925B34B01943160DA78DB4CBF
6256cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exeC:\Users\admin\Documents\Outlook Files\Outlook1.pst.encbinary
MD5:596168906563F9282D33F48C64B93F17
SHA256:F861551E3C2DC7FD9BFEAD0D55DF01130EA6677EE0519479D959A0EACF5D8A35
6256cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exeC:\Users\admin\Pictures\Saved Pictures\README.txttext
MD5:CEB9BE74330728EE94BB9A44C23B3548
SHA256:850AEA6611C2CF34A16D315B5925600EDA2BD731C8F76CC115D0A5CF7D511FCA
6256cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exeC:\Users\admin\Pictures\Saved Pictures\desktop.ini.enc
MD5:
SHA256:
6256cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exeC:\Users\admin\Documents\seechristian.rtf.encbinary
MD5:7D1698669DC776657B3A12407A7713B7
SHA256:E7A5F9B70E32BC3E993DF4E71F9638CC681388925CBA85E1EEBFE88B6B3DECC3
6256cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exeC:\Users\admin\Documents\amazonopportunities.rtf.encbinary
MD5:64F6F4C31DDDC1902A4ACE882981E432
SHA256:11F320BE72B9934C16F52884561CF44F51530D11E306E93C6DD7FFE92A943B2A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
20
DNS requests
10
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5488
MoUsoCoreWorker.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6944
svchost.exe
GET
304
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6944
svchost.exe
GET
200
2.16.241.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
POST
204
92.123.104.62:443
https://www.bing.com/threshold/xls.aspx
unknown
whitelisted
POST
404
35.173.69.207:443
https://tdsoperational.pythonanywhere.com/c2/data
unknown
html
2.89 Kb
whitelisted
POST
204
92.123.104.64:443
https://www.bing.com/threshold/xls.aspx
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
2.16.241.12:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5488
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6256
cd2956b443fe41a96cd3d6acfd4932f77482c27e65ee8acd92af58629e233b53.exe
35.173.69.207:443
tdsoperational.pythonanywhere.com
AMAZON-AES
US
whitelisted
4020
svchost.exe
239.255.255.250:1900
whitelisted
6944
svchost.exe
88.221.169.152:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4360
SearchApp.exe
2.23.209.179:443
www.bing.com
Akamai International B.V.
GB
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
  • 51.104.136.2
whitelisted
google.com
  • 142.250.186.46
whitelisted
crl.microsoft.com
  • 2.16.241.12
  • 2.16.241.14
whitelisted
www.microsoft.com
  • 88.221.169.152
whitelisted
tdsoperational.pythonanywhere.com
  • 35.173.69.207
whitelisted
www.bing.com
  • 2.23.209.179
  • 2.23.209.176
  • 2.23.209.189
  • 2.23.209.149
  • 2.23.209.133
  • 2.23.209.150
  • 2.23.209.130
  • 2.23.209.177
  • 2.23.209.182
whitelisted
self.events.data.microsoft.com
  • 13.89.179.14
whitelisted

Threats

PID
Process
Class
Message
Misc activity
ET INFO Observed HTTP Request to *.pythonanywhere .com Domain
No debug info