File name:

ER Death Counter-2989-3-7-1-1721229508.exe

Full analysis: https://app.any.run/tasks/8abe3a2c-d6b0-4216-9aa3-0864fde6d573
Verdict: Malicious activity
Analysis date: April 29, 2025, 05:09:25
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
github
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

DA84F5202A83190FDEE6D662CFAD0C82

SHA1:

0CADCA82C3149F827154B6DD9F188A74EFC59348

SHA256:

DF1AAA32BB15F4132B33B91972AA01CDAD7101B5F1E3F8D1EDC67040921BC89E

SSDEEP:

98304:WCs2eniZnMlyMxK3bxA+GRkmTZR7vKJt7UNxQe3KHH0gvmeLbGqGfO4B6tCKO4D6:IxixuDT4qLvwINkZqie

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ER Death Counter-2989-3-7-1-1721229508.exe (PID: 7428)
    • Creates a software uninstall entry

      • ER Death Counter-2989-3-7-1-1721229508.exe (PID: 7428)
    • The process creates files with name similar to system file names

      • ER Death Counter-2989-3-7-1-1721229508.exe (PID: 7428)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • ER Death Counter-2989-3-7-1-1721229508.exe (PID: 7428)
    • There is functionality for taking screenshot (YARA)

      • ER Death Counter-2989-3-7-1-1721229508.exe (PID: 7428)
  • INFO

    • Create files in a temporary directory

      • ER Death Counter-2989-3-7-1-1721229508.exe (PID: 7428)
    • Checks supported languages

      • ER Death Counter-2989-3-7-1-1721229508.exe (PID: 7428)
      • ER_DeathCounter.exe (PID: 7336)
    • Creates files in the program directory

      • ER Death Counter-2989-3-7-1-1721229508.exe (PID: 7428)
    • Reads the computer name

      • ER Death Counter-2989-3-7-1-1721229508.exe (PID: 7428)
      • ER_DeathCounter.exe (PID: 7336)
    • The sample compiled with english language support

      • ER Death Counter-2989-3-7-1-1721229508.exe (PID: 7428)
    • Creates files or folders in the user directory

      • ER Death Counter-2989-3-7-1-1721229508.exe (PID: 7428)
      • ER_DeathCounter.exe (PID: 7336)
    • Manual execution by a user

      • ER_DeathCounter.exe (PID: 7336)
    • Reads the time zone

      • ER_DeathCounter.exe (PID: 7336)
    • Checks proxy server information

      • ER_DeathCounter.exe (PID: 7336)
    • Process checks computer location settings

      • ER_DeathCounter.exe (PID: 7336)
    • Reads the machine GUID from the registry

      • ER_DeathCounter.exe (PID: 7336)
    • Reads the software policy settings

      • ER_DeathCounter.exe (PID: 7336)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:08:01 00:33:59+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 25600
InitializedDataSize: 141824
UninitializedDataSize: 2048
EntryPoint: 0x3489
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
139
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start er death counter-2989-3-7-1-1721229508.exe sppextcomobj.exe no specs slui.exe no specs er_deathcounter.exe er death counter-2989-3-7-1-1721229508.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
7324"C:\Users\admin\AppData\Local\Temp\ER Death Counter-2989-3-7-1-1721229508.exe" C:\Users\admin\AppData\Local\Temp\ER Death Counter-2989-3-7-1-1721229508.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\er death counter-2989-3-7-1-1721229508.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
7336"C:\Program Files (x86)\ER Death Counter\ER_DeathCounter.exe" C:\Program Files (x86)\ER Death Counter\ER_DeathCounter.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\program files (x86)\er death counter\er_deathcounter.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
7428"C:\Users\admin\AppData\Local\Temp\ER Death Counter-2989-3-7-1-1721229508.exe" C:\Users\admin\AppData\Local\Temp\ER Death Counter-2989-3-7-1-1721229508.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\er death counter-2989-3-7-1-1721229508.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7436C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
7468"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
Total events
42 018
Read events
42 013
Write events
5
Delete events
0

Modification events

(PID) Process:(7428) ER Death Counter-2989-3-7-1-1721229508.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ER Death Counter
Operation:writeName:DisplayName
Value:
ER Death Counter
(PID) Process:(7428) ER Death Counter-2989-3-7-1-1721229508.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ER Death Counter
Operation:writeName:UninstallString
Value:
"C:\Program Files (x86)\ER Death Counter\Uninstall.exe"
(PID) Process:(7428) ER Death Counter-2989-3-7-1-1721229508.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ER Death Counter
Operation:writeName:Publisher
Value:
Kam1k4dze
(PID) Process:(7428) ER Death Counter-2989-3-7-1-1721229508.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ER Death Counter
Operation:writeName:DisplayVersion
Value:
3.7.1
(PID) Process:(7428) ER Death Counter-2989-3-7-1-1721229508.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ER Death Counter
Operation:writeName:DisplayIcon
Value:
"C:\Program Files (x86)\ER Death Counter\ER_DeathCounter.exe"
Executable files
16
Suspicious files
6
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
7428ER Death Counter-2989-3-7-1-1721229508.exeC:\Users\admin\AppData\Local\Temp\nsnF196.tmp
MD5:
SHA256:
7428ER Death Counter-2989-3-7-1-1721229508.exeC:\Program Files (x86)\ER Death Counter\platforms\qwindows.dllexecutable
MD5:F5FEFF27C553F17F4248037D43C5B4DF
SHA256:E628CE1198FA8A65E7E3E15AF420AFE1818A421332C80A49A18A6AC75E0881D2
7428ER Death Counter-2989-3-7-1-1721229508.exeC:\Program Files (x86)\ER Death Counter\ER_DeathCounter.exeexecutable
MD5:D10B54401FA1822823D43168298B143A
SHA256:301CDF96DB3A77025A6FAA14A0C19028021353A138ACC92880F567BF319D52E2
7428ER Death Counter-2989-3-7-1-1721229508.exeC:\Program Files (x86)\ER Death Counter\Qt6Gui.dllexecutable
MD5:19FBF9146EB1F65E49DAD3CEA480C42E
SHA256:F67734847A4A29116332781A1322B629658185E44173975822D145EB4CDA3B8A
7428ER Death Counter-2989-3-7-1-1721229508.exeC:\Program Files (x86)\ER Death Counter\Qt6Widgets.dllexecutable
MD5:E87D59592B93387E1D19AEB572021CF7
SHA256:262476E4516E98EFF35850AD86E313B3B9105F3807E315A2DB6AF3E9B6F9888B
7428ER Death Counter-2989-3-7-1-1721229508.exeC:\Program Files (x86)\ER Death Counter\Qt6Core.dllexecutable
MD5:CBB90FBBEE5725B125924F63D6BE0044
SHA256:009C9EC26DCF18236A9213E76C7EA51C51197B943B061387E415D8651EF2EC8A
7428ER Death Counter-2989-3-7-1-1721229508.exeC:\Program Files (x86)\ER Death Counter\Qt6Network.dllexecutable
MD5:3B8F82A572801B883C31156BA5BCE4FC
SHA256:DDEB036988417F4A0082DB5AEE022D317A4D6003F4C6A61E4E887F115D90375C
7428ER Death Counter-2989-3-7-1-1721229508.exeC:\Program Files (x86)\ER Death Counter\iconengines\qsvgicon.dllexecutable
MD5:EA13F190EE2037978614D4AF5CA8CDD9
SHA256:D8F6DD929F773E84661206B8112E8790F4CDCB51EF5DFD4231EC13EBB40190EB
7428ER Death Counter-2989-3-7-1-1721229508.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\ER Death Counter.lnkbinary
MD5:F2619AD93F86EE833149C4AF499FDAED
SHA256:5EDA0BBF8B835DEAAE8D4EA238EA9F778F7809110811A4CEF4DC820B7F3E51C1
7428ER Death Counter-2989-3-7-1-1721229508.exeC:\Program Files (x86)\ER Death Counter\networkinformation\qnetworklistmanager.dllexecutable
MD5:D3D3E0CABE0C2ACAFDD19AB6FDFBE80D
SHA256:BC7A3C0D9410BF09DD9E3BE40A3C415DE123DF9D692078C68E35F28F1A8FFC3F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
23
DNS requests
16
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.6:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
8144
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
8144
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7336
ER_DeathCounter.exe
GET
200
172.64.149.23:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
whitelisted
7336
ER_DeathCounter.exe
GET
200
104.18.38.233:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5496
MoUsoCoreWorker.exe
23.216.77.6:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
5496
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
6544
svchost.exe
20.190.159.75:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
5496
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2112
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
crl.microsoft.com
  • 23.216.77.6
  • 23.216.77.28
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 142.250.185.206
whitelisted
login.live.com
  • 20.190.159.75
  • 20.190.159.131
  • 40.126.31.1
  • 20.190.159.64
  • 40.126.31.128
  • 20.190.159.2
  • 40.126.31.73
  • 40.126.31.2
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted
raw.githubusercontent.com
  • 185.199.108.133
  • 185.199.109.133
  • 185.199.110.133
  • 185.199.111.133
whitelisted

Threats

PID
Process
Class
Message
2196
svchost.exe
Not Suspicious Traffic
INFO [ANY.RUN] Attempting to access raw user content on GitHub
No debug info