File name:

Apa itu Mis imágenes.exe

Full analysis: https://app.any.run/tasks/459b6992-88af-4a22-b1da-6ebd76a2137c
Verdict: Malicious activity
Analysis date: April 30, 2026, 02:26:19
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections
MD5:

6C08BD41F70D51662DF04EB4ECD2F9EE

SHA1:

1E75F3F14DE56B34D503CB92426957999A310F4D

SHA256:

D24596A87B810ED934078EB7F474973FDE52DD4866C9114BE2E53E720C118750

SSDEEP:

768:wqP0kw7+1eOYN0QLycBu99AJtV7R0GrDybt:wq8kwY4N0Qex98tV7R0GSbt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Create files in the Startup directory

      • Apa itu Mis imágenes.exe (PID: 1684)
    • Changes the autorun value in the registry

      • Apa itu Mis imágenes.exe (PID: 1684)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Apa itu Mis imágenes.exe (PID: 1684)
    • Start notepad (likely ransomware note)

      • Apa itu Mis imágenes.exe (PID: 1684)
  • INFO

    • The sample compiled with english language support

      • Apa itu Mis imágenes.exe (PID: 1684)
    • Checks supported languages

      • Apa itu Mis imágenes.exe (PID: 1684)
    • Create files in a temporary directory

      • Apa itu Mis imágenes.exe (PID: 1684)
    • Launching a file from a Registry key

      • Apa itu Mis imágenes.exe (PID: 1684)
    • Creates files or folders in the user directory

      • Apa itu Mis imágenes.exe (PID: 1684)
    • Launching a file from the Startup directory

      • Apa itu Mis imágenes.exe (PID: 1684)
    • Failed to create an executable file in Windows directory

      • Apa itu Mis imágenes.exe (PID: 1684)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Microsoft Visual Basic 6 (84.4)
.dll | Win32 Dynamic Link Library (generic) (6.7)
.exe | Win32 Executable (generic) (4.6)
.exe | Generic Win/DOS Executable (2)
.exe | DOS Executable Generic (2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2006:06:11 10:07:15+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 45056
InitializedDataSize: 16384
UninitializedDataSize: -
EntryPoint: 0x183c
OSVersion: 4
ImageVersion: 1.1
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.1.0.1
ProductVersionNumber: 1.1.0.1
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: Take easy! I willn't harm your computer. FaTaLisTiCz_Fx #CyBeRz@Allnetwork.Org #CyBeRz@Dal.Net
CompanyName:
FileDescription: Microsoft Word Document
LegalCopyright: © 2006 By FaTaLisTiCz_Fx
ProductName: FeeLCoMz.By.FaTaLisTiCz_Fx
FileVersion: 1.01.0001
ProductVersion: 1.01.0001
InternalName: FeeLCoMz_V1B
OriginalFileName: FeeLCoMz_V1B.exe
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start apa itu mis imágenes.exe notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1684"C:\Users\admin\AppData\Local\Temp\Apa itu Mis imágenes.exe" C:\Users\admin\AppData\Local\Temp\Apa itu Mis imágenes.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Microsoft Word Document
Exit code:
0
Version:
1.01.0001
Modules
Images
c:\users\admin\appdata\local\temp\apa itu mis imágenes.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
6148Notepad.exe C:\WINDOWS\FeeLCoMz\Apa itu Mis imágenes.txtC:\Windows\SysWOW64\notepad.exeApa itu Mis imágenes.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\gdi32.dll
Total events
115
Read events
112
Write events
3
Delete events
0

Modification events

(PID) Process:(1684) Apa itu Mis imágenes.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Winzip Quick Pick
Value:
C:\WINDOWS\System32\Winzip.exe
(PID) Process:(1684) Apa itu Mis imágenes.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Microsoft Local Security Authority Subsystem Service
Value:
C:\WINDOWS\System\lsass.exe
(PID) Process:(1684) Apa itu Mis imágenes.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Generic Host Process for Win32 Services
Value:
C:\WINDOWS\System\svchost.exe
Executable files
1
Suspicious files
1
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
1684Apa itu Mis imágenes.exeC:\Users\admin\AppData\Local\VirtualStore\Windows\FeeLCoMz\Apa itu Mis imágenes.txttext
MD5:6056B1A076BBD0E814A9B570A5BEB25B
SHA256:B2B2FD042EE38BBBB47540073A4CE88E041CB838778618F90625CBC84CC2529F
1684Apa itu Mis imágenes.exeC:\Users\admin\AppData\Local\Temp\~DF4C27F082C9FEF78D.TMPbinary
MD5:356E93CC8D29B7F0D9889A2C2C3F4D10
SHA256:F8C63B0AAE58A22C95B8A924B555192AE0A81FAC5D3CA81ED01C9F9A39F49C0B
1684Apa itu Mis imágenes.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Hardware Monitor.exeexecutable
MD5:6C08BD41F70D51662DF04EB4ECD2F9EE
SHA256:D24596A87B810ED934078EB7F474973FDE52DD4866C9114BE2E53E720C118750
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
25
TCP/UDP connections
21
DNS requests
16
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5276
MoUsoCoreWorker.exe
GET
304
51.124.78.146:443
https://settings-win.data.microsoft.com/settings/v3.0/wsd/muse?ProcessorClockSpeed=3094&FlightIds=&UpdateOfferedDays=4294967295&BranchReadinessLevel=CB&OEMManufacturerName=DELL&IsCloudDomainJoined=0&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&sku=48&ActivationChannel=Retail&AttrDataVer=186&IsMDMEnrolled=0&ProcessorCores=6&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&TotalPhysicalRAM=6144&PrimaryDiskType=4294967295&FlightingBranchName=&ChassisTypeId=1&OEMModelNumber=DELL&SystemVolumeTotalCapacity=260281&sampleId=95271487&deviceClass=Windows.Desktop&App=muse&DisableDualScan=0&AppVer=10.0&OEMSubModel=J5CR&locale=en-US&IsAlwaysOnAlwaysConnectedCapable=0&ms=0&DefaultUserRegion=244&UpdateServiceUrl=http%3A%2F%2Fneverupdatewindows10.com&osVer=10.0.19045.4046.amd64fre.vb_release.191206-1406&os=windows&deviceId=s%3ABAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&DeferQualityUpdatePeriodInDays=0&ring=Retail&DeferFeatureUpdatePeriodInDays=30
US
whitelisted
7796
SIHClient.exe
GET
304
135.232.92.137:443
https://slscr.update.microsoft.com/SLS/%7B522D76A4-93E1-47F8-B8CE-07C937AD1A1E%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
7796
SIHClient.exe
GET
200
135.232.92.97:443
https://fe3cr.delivery.mp.microsoft.com/clientwebservice/ping
US
whitelisted
7796
SIHClient.exe
GET
200
135.232.92.137:443
https://slscr.update.microsoft.com/sls/ping
US
whitelisted
7796
SIHClient.exe
GET
304
135.232.92.137:443
https://slscr.update.microsoft.com/SLS/%7BE7A50285-D08D-499D-9FF8-180FDC2332BC%7D/x64/10.0.19045.4046/0?CH=686&L=en-US&P=&PT=0x30&WUA=10.0.19041.3996&MK=DELL&MD=DELL
US
whitelisted
680
svchost.exe
GET
304
40.127.240.158:443
https://settings-win.data.microsoft.com/settings/v3.0/WSD/UpdateHealthTools?os=Windows&osVer=10.0.19041.1.amd64fre.vb_release.191206-&sku=48&deviceClass=Windows.Desktop&locale=en-US&deviceId=s:BAD99146-31D3-4EC6-A1A4-BE76F32BA5D4&sampleId=s:95271487&appVer=10.0.19041.3626&FlightRing=Retail&TelemetryLevel=1&HidOverGattReg=C%3A%5CWINDOWS%5CSystem32%5CDriverStore%5CFileRepository%5Chidbthle.inf_amd64_9610b4821fdf82a5%5CMicrosoft.Bluetooth.Profiles.HidOverGatt.dll&AppVer=&ProcessorIdentifier=AMD64%20Family%2023%20Model%201%20Stepping%202&OEMModel=DELL&UpdateOfferedDays=4294967295&ProcessorManufacturer=AuthenticAMD&InstallDate=1661339444&OEMModelBaseBoard=&BranchReadinessLevel=CB&OEMSubModel=J5CR&IsCloudDomainJoined=0&DeferFeatureUpdatePeriodInDays=30&IsDeviceRetailDemo=0&FlightingBranchName=&OSUILocale=en-US&DeviceFamily=Windows.Desktop&WuClientVer=10.0.19041.3996&UninstallActive=1&IsFlightingEnabled=0&OSSkuId=48&ProcessorClockSpeed=3094&TotalPhysicalRAM=6144&SecureBootCapable=0&App=SedimentPack&ProcessorCores=6&CurrentBranch=vb_release&InstallLanguage=en-US&DeferQualityUpdatePeriodInDays=0&OEMName_Uncleaned=DELL&TPMVersion=0&PrimaryDiskTotalCapacity=262144&InstallationType=Client&AttrDataVer=186&ProcessorModel=AMD%20Ryzen%205%203500%206-Core%20Processor&IsEdgeWithChromiumInstalled=1&OSVersion=10.0.19045.4046&IsMDMEnrolled=0&ActivationChannel=Retail&FirmwareVersion=A.40&TrendInstalledKey=1&OSArchitecture=AMD64&DefaultUserRegion=244&UpdateManagementGroup=2
US
whitelisted
5316
svchost.exe
POST
400
40.126.31.69:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
204 b
whitelisted
5316
svchost.exe
POST
400
40.126.31.69:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
204 b
whitelisted
7796
SIHClient.exe
GET
200
23.59.18.102:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
US
binary
407 b
whitelisted
5316
svchost.exe
POST
400
40.126.31.69:443
https://login.live.com/ppsecure/deviceaddcredential.srf
US
text
204 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
680
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:137
Not routed
whitelisted
5276
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
48.192.1.64:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
Not routed
whitelisted
680
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
680
svchost.exe
2.16.164.49:80
crl.microsoft.com
AKAMAI-ASN1
NL
whitelisted
680
svchost.exe
23.59.18.102:80
www.microsoft.com
AKAMAI-AS
US
whitelisted
3428
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
5316
svchost.exe
40.126.31.69:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
activation-v2.sls.microsoft.com
  • 48.192.1.64
whitelisted
google.com
  • 192.178.183.139
  • 192.178.183.102
  • 192.178.183.113
  • 192.178.183.100
  • 192.178.183.138
  • 192.178.183.101
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 2.16.164.49
  • 2.16.164.120
whitelisted
www.microsoft.com
  • 23.59.18.102
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 40.126.31.69
  • 40.126.31.71
  • 20.190.159.73
  • 20.190.159.71
  • 20.190.159.2
  • 20.190.159.4
  • 20.190.159.128
  • 40.126.31.73
whitelisted
ocsp.digicert.com
  • 23.11.40.157
whitelisted
slscr.update.microsoft.com
  • 135.232.92.137
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 135.232.92.97
whitelisted

Threats

PID
Process
Class
Message
680
svchost.exe
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info