File name:

EPJFCWT5TRDLKE4KGNP.exe

Full analysis: https://app.any.run/tasks/b85d59af-acf4-40ea-a4f0-432d06775f5f
Verdict: Malicious activity
Analysis date: October 18, 2024, 20:53:01
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

B3251FBDC10F347197A02B11F857D4D3

SHA1:

30CECA9633E48D19FF61B272330E1F1AC5DDE2F6

SHA256:

DBDDC2D90914D54E7E1B30B2A30EFF51C013E89C67B96D0638034DDFE9AC2CE7

SSDEEP:

98304:vO2ff3cBjCn2nUc6rQhWznya7jjIOOO7nLnuJtLxLpD6pIGUIy5UOiPm3QnFFVYd:p2OaYAgsFbnhex+85rscAZqTLmhNelFg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Known privilege escalation attack

      • dllhost.exe (PID: 4836)
  • SUSPICIOUS

    • Starts application with an unusual extension

      • EPJFCWT5TRDLKE4KGNP.exe (PID: 4956)
    • Connects to unusual port

      • explorer.exe (PID: 6344)
  • INFO

    • Checks supported languages

      • EPJFCWT5TRDLKE4KGNP.exe (PID: 6728)
      • EPJFCWT5TRDLKE4KGNP.exe (PID: 4956)
      • more.com (PID: 1172)
    • Reads the computer name

      • EPJFCWT5TRDLKE4KGNP.exe (PID: 6728)
      • EPJFCWT5TRDLKE4KGNP.exe (PID: 4956)
    • Create files in a temporary directory

      • EPJFCWT5TRDLKE4KGNP.exe (PID: 6728)
      • EPJFCWT5TRDLKE4KGNP.exe (PID: 4956)
    • Reads the machine GUID from the registry

      • EPJFCWT5TRDLKE4KGNP.exe (PID: 6728)
    • Checks transactions between databases Windows and Oracle

      • EPJFCWT5TRDLKE4KGNP.exe (PID: 6728)
    • The process uses the downloaded file

      • dllhost.exe (PID: 4836)
    • Reads security settings of Internet Explorer

      • dllhost.exe (PID: 4836)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (49.6)
.exe | DOS Executable Generic (49.5)
.vxd | VXD Driver (0.7)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:06:24 14:32:12+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 8
CodeSize: 6825472
InitializedDataSize: 7784960
UninitializedDataSize: -
EntryPoint: 0x66eb30
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 10.0.6044.0
ProductVersionNumber: 10.0.6044.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Future Systems Solutions, Inc.
FileDescription: Casper 10.0 (Trial Edition)
FileVersion: 10.0.6044
InternalName: CASPER
LegalCopyright: Copyright © 1998-2016 Future Systems Solutions, Inc. All Rights Reserved.
LegalTrademarks: Casper, SmartClone, SmartRestore, SmartSense, SmartStart, SmartWrite, and 1-Click Cloning are either registered trademarks or trademarks of Future Systems Solutions, Inc.
OriginalFileName: CASPER.EXE
ProductName: Casper 10.0 (Trial Edition)
ProductVersion: 10.0.6044
Comments: Visit Future Systems Solutions online at http://www.fssdev.com
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
129
Monitored processes
6
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start epjfcwt5trdlke4kgnp.exe no specs CMSTPLUA epjfcwt5trdlke4kgnp.exe no specs more.com no specs conhost.exe no specs explorer.exe

Process information

PID
CMD
Path
Indicators
Parent process
1172C:\WINDOWS\SysWOW64\more.comC:\Windows\SysWOW64\more.comEPJFCWT5TRDLKE4KGNP.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
More Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\more.com
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\ulib.dll
1500\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exemore.com
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4836C:\WINDOWS\system32\DllHost.exe /Processid:{3E5FC7F9-9A51-4367-9063-A120244FBEC7}C:\Windows\System32\dllhost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\bcryptprimitives.dll
4956"C:\Users\admin\AppData\Local\Temp\EPJFCWT5TRDLKE4KGNP.exe" C:\Users\admin\AppData\Local\Temp\EPJFCWT5TRDLKE4KGNP.exedllhost.exe
User:
admin
Company:
Future Systems Solutions, Inc.
Integrity Level:
HIGH
Description:
Casper 10.0 (Trial Edition)
Exit code:
1
Version:
10.0.6044
Modules
Images
c:\users\admin\appdata\local\temp\epjfcwt5trdlke4kgnp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wininet.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
6344C:\WINDOWS\SysWOW64\explorer.exeC:\Windows\SysWOW64\explorer.exe
more.com
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Explorer
Version:
10.0.19041.3758 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\appdata\local\temp\qoojua
c:\windows\syswow64\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcp_win.dll
6728"C:\Users\admin\AppData\Local\Temp\EPJFCWT5TRDLKE4KGNP.exe" C:\Users\admin\AppData\Local\Temp\EPJFCWT5TRDLKE4KGNP.exeexplorer.exe
User:
admin
Company:
Future Systems Solutions, Inc.
Integrity Level:
MEDIUM
Description:
Casper 10.0 (Trial Edition)
Exit code:
0
Version:
10.0.6044
Modules
Images
c:\users\admin\appdata\local\temp\epjfcwt5trdlke4kgnp.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\wininet.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
Total events
4 209
Read events
4 209
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
1
Text files
0
Unknown types
1

Dropped files

PID
Process
Filename
Type
6728EPJFCWT5TRDLKE4KGNP.exeC:\Users\admin\AppData\Local\Temp\7a6643c4
MD5:
SHA256:
4956EPJFCWT5TRDLKE4KGNP.exeC:\Users\admin\AppData\Local\Temp\7acbda8f
MD5:
SHA256:
4956EPJFCWT5TRDLKE4KGNP.exeC:\Users\admin\AppData\Local\Temp\7b07e8f6
MD5:
SHA256:
1172more.comC:\Users\admin\AppData\Local\Temp\qoojua
MD5:
SHA256:
1172more.comC:\Users\admin\AppData\Local\Temp\mojuklnk
MD5:9B31B253862BA5220C9D9B127065499F
SHA256:8E9C828746F45868AF7DD07A37C30B6D86CE99A3AC6B6F8D182A49779ED732E9
1172more.comC:\Windows\Tasks\L-Connect Service.jobbinary
MD5:A82910E4762DB09F68F69D884147055A
SHA256:A9BE8F94550825D4A7FC785DBFB7E524AC8C20BD45600B7478CBEED3DF5BB5F0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
59
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5488
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
2.16.241.19:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
2364
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6240
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6240
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5328
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
6944
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5984
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5488
MoUsoCoreWorker.exe
2.16.241.19:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5488
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4360
SearchApp.exe
2.23.209.133:443
www.bing.com
Akamai International B.V.
GB
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
4020
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 2.16.241.19
  • 2.16.241.12
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
google.com
  • 142.250.186.142
whitelisted
www.bing.com
  • 2.23.209.133
  • 2.23.209.182
  • 2.23.209.140
  • 2.23.209.130
  • 2.23.209.179
  • 2.23.209.187
  • 2.23.209.149
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 20.190.159.0
  • 40.126.31.73
  • 20.190.159.4
  • 20.190.159.75
  • 20.190.159.68
  • 20.190.159.2
  • 20.190.159.23
  • 40.126.31.69
whitelisted
th.bing.com
  • 2.23.209.130
  • 2.23.209.149
  • 2.23.209.133
  • 2.23.209.187
  • 2.23.209.140
  • 2.23.209.179
  • 2.23.209.182
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
slscr.update.microsoft.com
  • 52.149.20.212
whitelisted

Threats

No threats detected
No debug info