File name:

cff82d1c233c2478551162a70c820ed257a3c1132dc976697795d25f1d378add

Full analysis: https://app.any.run/tasks/f1812fcc-c887-441c-ab66-df46a653b78c
Verdict: Malicious activity
Analysis date: May 18, 2025, 17:53:16
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

3D8A150ABF0CA4765A9FBFC8427E838C

SHA1:

A61EFEF714D230B0256A1D16CCBD101579178957

SHA256:

CFF82D1C233C2478551162A70C820ED257A3C1132DC976697795D25F1D378ADD

SSDEEP:

6144:Tev0JgIzkDHYbfo2oDlGvco36HmCP8ekwMPNqimawiKuly4AkYrRT/w:TevhHgf9oDlG3c8w360drRk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • cff82d1c233c2478551162a70c820ed257a3c1132dc976697795d25f1d378add.exe (PID: 2852)
    • Application was injected by another process

      • firefox.exe (PID: 668)
      • firefox.exe (PID: 6656)
    • Runs injected code in another process

      • ~B960.tmp (PID: 1280)
      • ~BD47.tmp (PID: 2088)
      • ~C249.tmp (PID: 7036)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • cff82d1c233c2478551162a70c820ed257a3c1132dc976697795d25f1d378add.exe (PID: 2852)
      • MRINonce.exe (PID: 4300)
    • Starts application with an unusual extension

      • MRINonce.exe (PID: 4300)
    • Executes application which crashes

      • cff82d1c233c2478551162a70c820ed257a3c1132dc976697795d25f1d378add.exe (PID: 2852)
  • INFO

    • Checks supported languages

      • cff82d1c233c2478551162a70c820ed257a3c1132dc976697795d25f1d378add.exe (PID: 2852)
      • ~B940.tmp (PID: 780)
      • MRINonce.exe (PID: 4300)
      • ~B960.tmp (PID: 1280)
      • ~B990.tmp (PID: 1628)
      • ~BD47.tmp (PID: 2088)
      • ~C249.tmp (PID: 7036)
    • Reads the computer name

      • cff82d1c233c2478551162a70c820ed257a3c1132dc976697795d25f1d378add.exe (PID: 2852)
    • Creates files or folders in the user directory

      • cff82d1c233c2478551162a70c820ed257a3c1132dc976697795d25f1d378add.exe (PID: 2852)
      • WerFault.exe (PID: 4408)
    • Failed to create an executable file in Windows directory

      • cff82d1c233c2478551162a70c820ed257a3c1132dc976697795d25f1d378add.exe (PID: 2852)
    • Manual execution by a user

      • ~BD47.tmp (PID: 2088)
      • ~C249.tmp (PID: 7036)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2015:01:23 23:19:49+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 2560
InitializedDataSize: 428544
UninitializedDataSize: -
EntryPoint: 0x11e8
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
12
Malicious processes
3
Suspicious processes
4

Behavior graph

Click at the process to see the details
start cff82d1c233c2478551162a70c820ed257a3c1132dc976697795d25f1d378add.exe sppextcomobj.exe no specs slui.exe no specs mrinonce.exe ~b940.tmp no specs ~b960.tmp no specs ~b990.tmp no specs werfault.exe no specs ~bd47.tmp no specs ~c249.tmp no specs firefox.exe firefox.exe

Process information

PID
CMD
Path
Indicators
Parent process
668"C:\Program Files\Mozilla Firefox\firefox.exe" --backgroundtask defaultagent do-task 308046B0AF4A39CBC:\Program Files\Mozilla Firefox\firefox.exe
default-browser-agent.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
3
Version:
123.0
Modules
Images
c:\windows\system32\wininet.dll
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\windows\system32\bcrypt.dll
7805492 250888 4300 1C:\Users\admin\AppData\Local\Temp\~B940.tmpMRINonce.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\~b940.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
1132C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
1280668 250888 4300 2C:\Users\admin\AppData\Local\Temp\~B960.tmpMRINonce.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\~b960.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
16286656 250888 4300 2C:\Users\admin\AppData\Local\Temp\~B990.tmpMRINonce.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\~b990.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
20886656 250888 5492 2C:\Users\admin\AppData\Local\Temp\~BD47.tmpexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\~bd47.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
2852"C:\Users\admin\AppData\Local\Temp\cff82d1c233c2478551162a70c820ed257a3c1132dc976697795d25f1d378add.exe" C:\Users\admin\AppData\Local\Temp\cff82d1c233c2478551162a70c820ed257a3c1132dc976697795d25f1d378add.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Modules
Images
c:\users\admin\appdata\local\temp\cff82d1c233c2478551162a70c820ed257a3c1132dc976697795d25f1d378add.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4300"C:\Users\admin\AppData\Roaming\comptify"C:\Users\admin\AppData\Roaming\comptify\MRINonce.exe
cff82d1c233c2478551162a70c820ed257a3c1132dc976697795d25f1d378add.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\comptify\mrinonce.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
4408C:\WINDOWS\SysWOW64\WerFault.exe -u -p 2852 -s 652C:\Windows\SysWOW64\WerFault.execff82d1c233c2478551162a70c820ed257a3c1132dc976697795d25f1d378add.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
4996"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
2 579
Read events
2 576
Write events
3
Delete events
0

Modification events

(PID) Process:(6656) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
(PID) Process:(2852) cff82d1c233c2478551162a70c820ed257a3c1132dc976697795d25f1d378add.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:psrdown
Value:
C:\Users\admin\AppData\Roaming\comptify\MRINonce.exe
(PID) Process:(2852) cff82d1c233c2478551162a70c820ed257a3c1132dc976697795d25f1d378add.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\StartupApproved\Run
Operation:writeName:psrdown
Value:
000000000000000000000000
Executable files
4
Suspicious files
5
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
4408WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_cff82d1c233c2478_ba501a62dd8510880a71a565ee3fb0aaa4878f_338440f2_9964c9ff-7638-4ef3-9e6f-3c961c8dd35f\Report.wer
MD5:
SHA256:
4300MRINonce.exeC:\Users\admin\AppData\Local\Temp\~B960.tmpexecutable
MD5:AAC3165ECE2959F39FF98334618D10D9
SHA256:96FA6A7714670823C83099EA01D24D6D3AE8FEF027F01A4DDAC14F123B1C9974
4408WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERBBD0.tmp.dmpbinary
MD5:F09DD658FEC172D8C742001AA045C875
SHA256:5A15A8BA9FB76DA46BB85108C00DB488E659169238872DFD6F4ED168DBC8A61A
4408WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERBCAC.tmp.WERInternalMetadata.xmlbinary
MD5:04BD69771FBC38578DE92549A0D26045
SHA256:F97AE6FD897C86459C10FB93145B37F9F1FD9B1E733F794A6035C6CF80E2C110
4300MRINonce.exeC:\Users\admin\AppData\Local\Temp\~B940.tmpexecutable
MD5:AAC3165ECE2959F39FF98334618D10D9
SHA256:96FA6A7714670823C83099EA01D24D6D3AE8FEF027F01A4DDAC14F123B1C9974
4408WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\cff82d1c233c2478551162a70c820ed257a3c1132dc976697795d25f1d378add.exe.2852.dmpbinary
MD5:E83E0D5305EF9616150C5FB047347494
SHA256:439C7A29ED4559D902A2C01D8FF297EEFF4BBB3DA7723B65E9EEAC9AA109806B
4408WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERBCFB.tmp.xmlxml
MD5:4A2A54307A73A35ED36CC763D2C039EF
SHA256:F7E71F93454BD7272D34E75D76C583673C1C4BDA6BAB3A474968B48FCFF8E50B
4300MRINonce.exeC:\Users\admin\AppData\Local\Temp\~B990.tmpexecutable
MD5:AAC3165ECE2959F39FF98334618D10D9
SHA256:96FA6A7714670823C83099EA01D24D6D3AE8FEF027F01A4DDAC14F123B1C9974
6656firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Background Tasks Profiles\93u99co2.MozillaBackgroundTask-308046B0AF4A39CB-defaultagent\datareporting\glean\db\data.safe.binbinary
MD5:C58234A092F9D899F0A623E28A4AB9DB
SHA256:EAEC709A98B57CD9C054A205F9BFA76C7424DB2845C077822804F31E16AC134C
6656firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Background Tasks Profiles\93u99co2.MozillaBackgroundTask-308046B0AF4A39CB-defaultagent\prefs-1.jstext
MD5:6427609ECB30A5668D4F436E4B2A9823
SHA256:C5DDDB08D3E1F9FA0E6DE695D43AD56B5AF6BD8401BCD8DAE1F3D5B7FF25C037
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
19
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.180:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3176
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
3176
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
23.48.23.180:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
2112
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3216
svchost.exe
172.211.123.249:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.32.136:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.48.23.180
  • 23.48.23.159
  • 23.48.23.194
  • 23.48.23.166
  • 23.48.23.193
  • 23.48.23.173
  • 23.48.23.141
  • 23.48.23.164
  • 23.48.23.177
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 172.217.18.14
whitelisted
client.wns.windows.com
  • 172.211.123.249
whitelisted
login.live.com
  • 40.126.32.136
  • 40.126.32.76
  • 20.190.160.5
  • 40.126.32.140
  • 20.190.160.64
  • 20.190.160.2
  • 20.190.160.20
  • 40.126.32.138
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted

Threats

No threats detected
No debug info