File name:

DHL Express Doc 01143124.exe

Full analysis: https://app.any.run/tasks/4973d6db-ac44-4632-a62e-1867219aa9a9
Verdict: Malicious activity
Analysis date: November 01, 2024, 19:42:25
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
autoit
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

BBCD6B4351BD1FC4B936D6DC17D5248A

SHA1:

BC4F6E8D1EBA20FBEEC68AB22D73C14E14946BCE

SHA256:

D55323CBD79361CC6DF4DEFE9248F9A1BA8330048E9205BE94E2BEE9A619DB5E

SSDEEP:

49152:lPPkzemqoSut3Jh4+QQ/btosJwIA4hHmZlKH2Tw/Pq83zw0bCjvk9G661QGtKUgo:ZP/mp7t3T4+B/btosJwIA4hHmZlKH2Ty

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes application which crashes

      • DHL Express Doc 01143124.exe (PID: 6676)
  • INFO

    • Checks supported languages

      • DHL Express Doc 01143124.exe (PID: 6676)
    • Reads mouse settings

      • DHL Express Doc 01143124.exe (PID: 6676)
    • The process uses AutoIt

      • DHL Express Doc 01143124.exe (PID: 6676)
    • Create files in a temporary directory

      • DHL Express Doc 01143124.exe (PID: 6676)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:11:01 03:30:22+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 633856
InitializedDataSize: 994816
UninitializedDataSize: -
EntryPoint: 0x20577
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (British)
CharacterSet: Unicode
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start THREAT dhl express doc 01143124.exe svchost.exe no specs werfault.exe

Process information

PID
CMD
Path
Indicators
Parent process
1112"C:\Users\admin\AppData\Local\Temp\DHL Express Doc 01143124.exe" C:\Windows\SysWOW64\svchost.exeDHL Express Doc 01143124.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
2652C:\WINDOWS\SysWOW64\WerFault.exe -u -p 6676 -s 676C:\Windows\SysWOW64\WerFault.exe
DHL Express Doc 01143124.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
6676"C:\Users\admin\AppData\Local\Temp\DHL Express Doc 01143124.exe" C:\Users\admin\AppData\Local\Temp\DHL Express Doc 01143124.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Modules
Images
c:\users\admin\appdata\local\temp\dhl express doc 01143124.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\psapi.dll
Total events
3 091
Read events
3 091
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
7
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2652WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_DHL Express Doc _a3aa75f99181ad8b115a15af4f02125f43aba78_22ba1725_988affe5-2a50-4ed1-b3aa-884accc337d3\Report.wer
MD5:
SHA256:
2652WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERFFA8.tmp.xmlxml
MD5:B959A9AA49DFA88288C27AE97AD596F4
SHA256:4F214B7B0E345BD9BD3E9CB09C06D0FB6DE2D7971E00A4889AF4C2D6ADA23260
2652WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\21253908F3CB05D51B1C2DA8B681A785der
MD5:1B7FD5177461034E4086724C5845E927
SHA256:065AF18C229898A1C2A8D989911ADCD9B1E2AB14B1953EBF8EAF34AE37EA1627
2652WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FEbinary
MD5:104FCF9C14CE8E5DF094AFEEB1D52934
SHA256:A0CEED6EDDEC86B285799393C1CD82B938E77D6945CFAD7E35D0CC5FAB71D80A
2652WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERFF78.tmp.WERInternalMetadata.xmlxml
MD5:E3BBABCD2665CF045AF253A506D60A20
SHA256:52901885544C7E8129D946DE2596629EBB1168BDCC274F8A9A29F8EAB5C385CE
2652WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERFE7D.tmp.dmpbinary
MD5:957047E2E31154ABDD3E877CDB9CD0D5
SHA256:55793396D1F3101584E712AF4211F44F759BA80259E617F6EA724971A5DB56E4
2652WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\37C951188967C8EB88D99893D9D191FEder
MD5:F0CF5B1794ECA7CD73F9C020DAAB8EF2
SHA256:2AF00EDCE7EF3266897E52DC81E8DE3B7A079028C0F1F96EAFF9E38AD342F617
6676DHL Express Doc 01143124.exeC:\Users\admin\AppData\Local\Temp\pteropodbinary
MD5:3254627C862D51CDEC0075F23B82237F
SHA256:3D8C5AF331001DCCA95CC7E427E83FAB75EFC935601263EEF1A119F073A8B4F5
2652WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\21253908F3CB05D51B1C2DA8B681A785binary
MD5:1CEB8DD1D47EF273BFEEE8A824F7184E
SHA256:395B6485E9951DAD5DB8D6E2D8303B7FBAD0ABABB89AA707FB0B55C4E9B892FF
2652WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\DHL Express Doc 01143124.exe.6676.dmpdmp
MD5:0D3108EBF7D882318CC0AE7EF79C83F3
SHA256:61445CDC81B92A7A489C8C47A64412D67E0E556E46E60ECE9843EB317D77A74C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
39
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5488
MoUsoCoreWorker.exe
GET
200
2.16.164.114:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
23.32.185.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2724
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6232
SIHClient.exe
GET
200
104.76.201.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6232
SIHClient.exe
GET
200
104.76.201.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2652
WerFault.exe
GET
200
2.23.154.57:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
3020
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
2652
WerFault.exe
GET
200
104.76.201.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6944
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1248
RUXIMICS.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5488
MoUsoCoreWorker.exe
2.16.164.114:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
5488
MoUsoCoreWorker.exe
23.32.185.131:80
www.microsoft.com
AKAMAI-AS
BR
whitelisted
4020
svchost.exe
239.255.255.250:1900
whitelisted
816
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
4360
SearchApp.exe
2.23.209.160:443
www.bing.com
Akamai International B.V.
GB
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 2.16.164.114
  • 2.16.164.89
  • 2.16.164.82
  • 2.16.164.18
  • 2.16.164.49
  • 2.16.164.81
  • 2.16.164.17
  • 2.16.164.106
  • 2.16.164.40
  • 2.23.154.57
  • 104.103.72.96
whitelisted
www.microsoft.com
  • 23.32.185.131
  • 104.76.201.160
whitelisted
google.com
  • 142.250.184.206
whitelisted
www.bing.com
  • 2.23.209.160
  • 2.23.209.130
  • 2.23.209.177
  • 2.23.209.161
  • 2.23.209.158
  • 2.23.209.181
  • 2.23.209.150
  • 2.23.209.185
  • 2.23.209.149
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.4
  • 20.190.159.2
  • 20.190.159.75
  • 40.126.31.67
  • 40.126.31.69
  • 20.190.159.23
  • 20.190.159.64
  • 40.126.31.71
whitelisted
th.bing.com
  • 2.23.209.189
  • 2.23.209.140
  • 2.23.209.133
  • 2.23.209.149
  • 2.23.209.185
  • 2.23.209.176
  • 2.23.209.177
  • 2.23.209.187
  • 2.23.209.130
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted

Threats

No threats detected
No debug info