File name:

LEM75S_ADM_KM_2025-10-03_18_24_47.321.zip

Full analysis: https://app.any.run/tasks/ed0c8dea-bdec-4703-978b-f4fcee583d5f
Verdict: Malicious activity
Analysis date: October 03, 2025, 18:30:17
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
neshta
Indicators:
MIME: application/zip
File info: Zip archive data, at least v4.5 to extract, compression method=deflate
MD5:

CB2F9F5ECE97F02EC180CCBF5437B1A6

SHA1:

8EA1D70761B9FF43D800B0B3210C2A170F3C33B4

SHA256:

D5AF50100C9331F8247117EA3A9A37EDBAD85584BFA327E2CB2B365E435C331C

SSDEEP:

98304:gG9eeVL+KHSPk+BUud7oScOfAw5qkHpuqzz+EiwR2+4g+LFsUW7Wyi38Z2QBdYM+:/9hH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • NESHTA mutex has been found

      • stmg.org.exe (PID: 7520)
  • SUSPICIOUS

    • Mutex name with non-standard characters

      • stmg.org.exe (PID: 7520)
    • Reads security settings of Internet Explorer

      • stmg.org.exe (PID: 7520)
      • WinRAR.exe (PID: 2944)
    • Executable content was dropped or overwritten

      • stmg.org.exe (PID: 7520)
  • INFO

    • Checks supported languages

      • stmg.org.exe (PID: 7520)
      • stmg.org.exe (PID: 1260)
    • Create files in a temporary directory

      • stmg.org.exe (PID: 7520)
      • stmg.org.exe (PID: 1260)
    • Process checks computer location settings

      • stmg.org.exe (PID: 7520)
    • Reads the computer name

      • stmg.org.exe (PID: 7520)
    • Executable content was dropped or overwritten

      • WinRAR.exe (PID: 2944)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.zip | ZIP compressed archive (100)

EXIF

ZIP

ZipRequiredVersion: 20
ZipBitFlag: 0x0801
ZipCompression: Deflated
ZipModifyDate: 1980:00:00 00:00:00
ZipCRC: 0x879c8857
ZipCompressedSize: 2430243
ZipUncompressedSize: 4962304
ZipFileName: Device/HarddiskVolume3/Users/kadmin/Downloads/stmg.org.exe
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
172
Monitored processes
5
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
1260"C:\Users\admin\AppData\Local\Temp\3582-490\stmg.org.exe" C:\Users\admin\AppData\Local\Temp\3582-490\stmg.org.exestmg.org.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\3582-490\stmg.org.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2944"C:\Program Files\WinRAR\WinRAR.exe" C:\Users\admin\AppData\Local\Temp\LEM75S_ADM_KM_2025-10-03_18_24_47.321.zipC:\Program Files\WinRAR\WinRAR.exe
explorer.exe
User:
admin
Company:
Alexander Roshal
Integrity Level:
MEDIUM
Description:
WinRAR archiver
Version:
5.91.0
Modules
Images
c:\program files\winrar\winrar.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
3164C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6416\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exestmg.org.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
7520"C:\Users\admin\AppData\Local\Temp\Rar$EXb2944.40418\Device\HarddiskVolume3\Users\kadmin\Downloads\stmg.org.exe" C:\Users\admin\AppData\Local\Temp\Rar$EXb2944.40418\Device\HarddiskVolume3\Users\kadmin\Downloads\stmg.org.exe
WinRAR.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\rar$exb2944.40418\device\harddiskvolume3\users\kadmin\downloads\stmg.org.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
9 070
Read events
9 006
Write events
50
Delete events
14

Modification events

(PID) Process:(2944) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtBMP
Value:
(PID) Process:(2944) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\Interface\Themes
Operation:writeName:ShellExtIcon
Value:
(PID) Process:(2944) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:3
Value:
C:\Users\admin\Desktop\preferences.zip
(PID) Process:(2944) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:2
Value:
C:\Users\admin\Desktop\chromium_ext.zip
(PID) Process:(2944) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:1
Value:
C:\Users\admin\Desktop\omni_23_10_2024_.zip
(PID) Process:(2944) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\ArcHistory
Operation:writeName:0
Value:
C:\Users\admin\AppData\Local\Temp\LEM75S_ADM_KM_2025-10-03_18_24_47.321.zip
(PID) Process:(2944) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:name
Value:
120
(PID) Process:(2944) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:size
Value:
80
(PID) Process:(2944) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:type
Value:
120
(PID) Process:(2944) WinRAR.exeKey:HKEY_CURRENT_USER\SOFTWARE\WinRAR\FileList\FileColumnWidths
Operation:writeName:mtime
Value:
100
Executable files
12
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2944WinRAR.exeC:\Users\admin\Desktop\manifest.jsontext
MD5:1CFFB3C833E2AD79D56ADAD5896B6C63
SHA256:2AEF926857688C1B4B65962B0B9A2CF2F7F7FD54425ABD39B4E316759ED6CDA4
2944WinRAR.exeC:\Users\admin\Desktop\Device\HarddiskVolume3\Users\kadmin\Downloads\stmg.org.exeexecutable
MD5:C58996B0A626D9FB8FADAF09FFF8B812
SHA256:B630C06B8283D2851BEC0032F38FCFDBCB70470D883A4A7E9ABECF85DAB740C1
7520stmg.org.exeC:\ProgramData\Adobe\ARM\S\388\AdobeARMHelper.exeexecutable
MD5:85A67D34298E33D2D5A9EC789B6AB594
SHA256:1DEE143B4F88F2375B85C6271A58E2E78FED081BEAE4090678CB2DD7A37FB2D4
2944WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2944.40418\manifest.jsontext
MD5:1CFFB3C833E2AD79D56ADAD5896B6C63
SHA256:2AEF926857688C1B4B65962B0B9A2CF2F7F7FD54425ABD39B4E316759ED6CDA4
1260stmg.org.exeC:\Users\admin\AppData\Local\Temp\QLOG\ThreadId(1).LOGtext
MD5:D55E48C7C8DD0B5B9286EB41B73B4794
SHA256:7C0820A58734D65C4C35E992661BD49C6E84A5929E9E67FA8E01B2FDE86B3656
7520stmg.org.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\OneDriveUpdaterService.exeexecutable
MD5:E73AC057B2CFEF016B8199389F0DF590
SHA256:20ABA9D6001E5CDC287CD5BD452D0F2D05980D83F851D2B309BF49E9D9A8AC4C
7520stmg.org.exeC:\Users\admin\AppData\Local\Temp\3582-490\stmg.org.exeexecutable
MD5:53DD90D3548F92D01AB0D03499FB4ABA
SHA256:B5B5C1AF2F9D7F1C242C53CD65EC106F12E8E6B8E60C608075FA3B705BDC1FCC
7520stmg.org.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\FileSyncConfig.exeexecutable
MD5:0C5EC1AE9A301408AF26032B445FBB08
SHA256:3A8010F1E4E028782093877D969EB127B80AE48B7215A8D3F91E8AB9C165AC7A
2944WinRAR.exeC:\Users\admin\AppData\Local\Temp\Rar$EXb2944.40418\Device\HarddiskVolume3\Users\kadmin\Downloads\stmg.org.exeexecutable
MD5:C58996B0A626D9FB8FADAF09FFF8B812
SHA256:B630C06B8283D2851BEC0032F38FCFDBCB70470D883A4A7E9ABECF85DAB740C1
7520stmg.org.exeC:\Users\admin\AppData\Local\Microsoft\OneDrive\19.043.0304.0013\FileCoAuth.exeexecutable
MD5:13C2D5BF03C4A2B28E930F990CCC32DB
SHA256:12D24D0BC0E7CDC902E3540A3C6F7B755094F011A8EAD49A47A00563710B8F80
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
31
DNS requests
15
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2656
svchost.exe
GET
200
23.50.108.3:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
CH
binary
471 b
whitelisted
2656
svchost.exe
GET
200
23.50.108.3:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
CH
binary
471 b
whitelisted
5356
backgroundTaskHost.exe
GET
200
23.50.108.3:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
CH
binary
313 b
whitelisted
2836
backgroundTaskHost.exe
GET
200
23.50.108.3:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
CH
binary
471 b
whitelisted
6332
backgroundTaskHost.exe
GET
200
23.50.108.3:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
CH
binary
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6016
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
6080
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5224
SearchApp.exe
95.100.98.80:443
www.bing.com
Akamai International B.V.
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5948
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5224
SearchApp.exe
95.100.98.83:443
www.bing.com
Akamai International B.V.
IE
whitelisted
2656
svchost.exe
40.126.31.3:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2656
svchost.exe
23.50.108.3:80
ocsp.digicert.com
AKAMAI-AS
CH
whitelisted
5356
backgroundTaskHost.exe
95.100.98.83:443
www.bing.com
Akamai International B.V.
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
www.bing.com
  • 95.100.98.80
  • 95.100.98.83
  • 95.100.98.104
whitelisted
google.com
  • 142.250.185.78
whitelisted
login.live.com
  • 40.126.31.3
  • 40.126.31.129
  • 40.126.31.0
  • 40.126.31.1
  • 20.190.159.73
  • 40.126.31.2
  • 20.190.159.2
  • 20.190.159.71
whitelisted
ocsp.digicert.com
  • 23.50.108.3
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
arc.msn.com
  • 20.74.47.205
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted
slscr.update.microsoft.com
  • 74.179.77.204
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info