File name:

Client-built.exe

Full analysis: https://app.any.run/tasks/a29c7d5f-da83-4066-99e0-55563d8f80ea
Verdict: Malicious activity
Analysis date: October 03, 2025, 16:49:52
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
uac
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

43ED001B096E0FA2A3D9A9740A2957A0

SHA1:

17414610FA721BB715634650FC9C3F7BF08DAD8F

SHA256:

DAB4A525D618061894F684825BE1360EBF03835BA4CB631CF11F9B74A285C40C

SSDEEP:

49152:jglqSa3bXnax3jfRACqrg+owpFkC7ZBI5NLEVK5jWEmC9fDwv1Zr0i5Gnq2TKh5a:2Za3bXna9pOrCKZBIYwB9fDOCWh5Y4wn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Bypass User Account Control (ComputerDefaults)

      • ComputerDefaults.exe (PID: 4384)
    • Bypass User Account Control (Modify registry)

      • Client-built.exe (PID: 936)
    • Execute application with conhost.exe as parent process

      • cmd.exe (PID: 7460)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Client-built.exe (PID: 936)
    • Changes default file association

      • Client-built.exe (PID: 936)
    • Reads the date of Windows installation

      • Client-built.exe (PID: 936)
    • Starts CMD.EXE for commands execution

      • conhost.exe (PID: 576)
    • Executing commands from a ".bat" file

      • conhost.exe (PID: 576)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 7460)
    • Executable content was dropped or overwritten

      • Client-built.exe (PID: 6388)
  • INFO

    • Checks supported languages

      • Client-built.exe (PID: 936)
      • Client-built.exe (PID: 6388)
    • Reads security settings of Internet Explorer

      • ComputerDefaults.exe (PID: 4384)
    • Reads the computer name

      • Client-built.exe (PID: 936)
      • Client-built.exe (PID: 6388)
    • Reads Environment values

      • Client-built.exe (PID: 936)
      • Client-built.exe (PID: 6388)
    • Create files in a temporary directory

      • Client-built.exe (PID: 936)
    • Reads the machine GUID from the registry

      • Client-built.exe (PID: 936)
      • Client-built.exe (PID: 6388)
    • Process checks computer location settings

      • Client-built.exe (PID: 936)
    • Checks proxy server information

      • slui.exe (PID: 2944)
    • Reads the software policy settings

      • slui.exe (PID: 2944)
    • Creates files or folders in the user directory

      • Client-built.exe (PID: 6388)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (56.7)
.exe | Win64 Executable (generic) (21.3)
.scr | Windows screen saver (10.1)
.dll | Win32 Dynamic Link Library (generic) (5)
.exe | Win32 Executable (generic) (3.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2077:09:19 15:18:11+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 1865216
InitializedDataSize: 3584
UninitializedDataSize: -
EntryPoint: 0x1c954e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.7.4.0
ProductVersionNumber: 1.7.4.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: -
FileVersion: 1.7.4
InternalName: Client.exe
LegalCopyright: -
LegalTrademarks: -
OriginalFileName: Client.exe
ProductName: -
ProductVersion: 1.7.4
AssemblyVersion: 1.7.4.0
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
165
Monitored processes
8
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start client-built.exe no specs computerdefaults.exe no specs computerdefaults.exe conhost.exe no specs cmd.exe no specs timeout.exe no specs client-built.exe slui.exe

Process information

PID
CMD
Path
Indicators
Parent process
576"conhost.exe" --headless "C:\Users\admin\AppData\Local\Temp\a9e991fb.bat"C:\Windows\System32\conhost.exeComputerDefaults.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
936"C:\Users\admin\Desktop\Client-built.exe" C:\Users\admin\Desktop\Client-built.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
5
Version:
1.7.4
Modules
Images
c:\users\admin\desktop\client-built.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2944"C:\Windows\System32\ComputerDefaults.exe" C:\Windows\System32\ComputerDefaults.exeClient-built.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Set Program Access and Computer Defaults Control Panel
Exit code:
3221226540
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\computerdefaults.exe
c:\windows\system32\ntdll.dll
2944C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4384"C:\Windows\System32\ComputerDefaults.exe" C:\Windows\System32\ComputerDefaults.exe
Client-built.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Set Program Access and Computer Defaults Control Panel
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\computerdefaults.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6132timeout /t 4 /nobreak C:\Windows\System32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
timeout - pauses command processing
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
6388"C:\Users\admin\Desktop\Client-built.exe" C:\Users\admin\Desktop\Client-built.exe
cmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
4294967295
Version:
1.7.4
Modules
Images
c:\users\admin\desktop\client-built.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
7460C:\WINDOWS\system32\cmd.exe /c C:\Users\admin\AppData\Local\Temp\a9e991fb.batC:\Windows\System32\cmd.execonhost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\cmdext.dll
c:\windows\system32\advapi32.dll
Total events
5 548
Read events
5 531
Write events
13
Delete events
4

Modification events

(PID) Process:(936) Client-built.exeKey:HKEY_CLASSES_ROOT\ms-settings\Shell\Open\command
Operation:writeName:DelegateExecute
Value:
(PID) Process:(936) Client-built.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(936) Client-built.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(936) Client-built.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(936) Client-built.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(4384) ComputerDefaults.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(4384) ComputerDefaults.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(4384) ComputerDefaults.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(936) Client-built.exeKey:HKEY_CLASSES_ROOT\ms-settings\Shell\Open\command
Operation:delete keyName:(default)
Value:
(PID) Process:(936) Client-built.exeKey:HKEY_CLASSES_ROOT\ms-settings\Shell\Open
Operation:delete keyName:(default)
Value:
Executable files
1
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
6388Client-built.exeC:\Users\admin\AppData\Roaming\Discords\Update.exeexecutable
MD5:43ED001B096E0FA2A3D9A9740A2957A0
SHA256:DAB4A525D618061894F684825BE1360EBF03835BA4CB631CF11F9B74A285C40C
936Client-built.exeC:\Users\admin\AppData\Local\Temp\a9e991fb.battext
MD5:575CCB7CC794E2C2C5460732B61EC538
SHA256:B3622D55BF65CCE3C4D4A87B773ED360A794124376B1AFE420B2EEF2C92AE083
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
12
DNS requests
5
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
POST
4.154.209.85:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
unknown
POST
500
4.154.185.43:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
xml
512 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
7160
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
6016
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5948
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
7248
slui.exe
4.154.209.85:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
2944
slui.exe
4.154.185.43:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.110
whitelisted
activation-v2.sls.microsoft.com
  • 4.154.209.85
  • 4.154.185.43
whitelisted

Threats

PID
Process
Class
Message
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info