| File name: | 1.exe |
| Full analysis: | https://app.any.run/tasks/34cc4e71-76a5-4c4e-b3f9-b881282f7d20 |
| Verdict: | Malicious activity |
| Analysis date: | October 06, 2025, 11:02:31 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections |
| MD5: | 8A28227E6F2B51CE94C5CCFEC8A1A8E0 |
| SHA1: | 643017098B27794E1303A8E7FAADB6B489ACBACC |
| SHA256: | E1794B2EF1735FD1D0E94808E8C56917D8F7EA5720FC4D2ABAF5EAC48DAE3169 |
| SSDEEP: | 98304:mrq3Bdwn1b4+ABHZLCNZg5n/N+fNcMQ/rTa7/BG2RrOUhCJ+Q2cRKfqHrOk+16mx:TipoSAS+nL25WYZP |
| .exe | | | Inno Setup installer (65.1) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (24.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (3.9) |
| .exe | | | Win32 Executable (generic) (2.6) |
| .exe | | | Win16/32 Executable Delphi generic (1.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:06:09 11:07:51+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 685056 |
| InitializedDataSize: | 41984 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xa83bc |
| OSVersion: | 6.1 |
| ImageVersion: | - |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 10.0.14393.0 |
| ProductVersionNumber: | 10.0.14393.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Microsoft Corporation |
| FileDescription: | Storage Tiers Management Setup |
| FileVersion: | 10.0.14393.0 |
| LegalCopyright: | Copyright © Microsoft Corporation |
| OriginalFileName: | |
| ProductName: | Storage Tiers Management |
| ProductVersion: | 10.0.14393.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 992 | "regsvr32" /s /u "C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\jRCf"_"jRCfg"_"jRC-jRCfg3.dll" | C:\Windows\System32\regsvr32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft(C) Register Server Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1588 | "PowerShell.exe" -NoProfile -NonInteractive -Command - | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | — | regsvr32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1824 | "PowerShell.exe" -NoProfile -NonInteractive -Command - | C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exe | — | regsvr32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows PowerShell Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2000 | /s /u "C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\jRCf"_"jRCfg"_"jRC-jRCfg3.dll" | C:\Windows\SysWOW64\regsvr32.exe | — | regsvr32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft(C) Register Server Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2280 | "C:\Users\admin\AppData\Local\Temp\is-00NME.tmp\1.tmp" /SL5="$A0038,8255608,728064,C:\Users\admin\AppData\Local\Temp\1.exe" /VERYSILENT /PASSWORD=. | C:\Users\admin\AppData\Local\Temp\is-00NME.tmp\1.tmp | 1.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2288 | /s /u "C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\jRCf"_"jRCfg"_"jRC-jRCfg3.dll" | C:\Windows\SysWOW64\regsvr32.exe | — | regsvr32.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft(C) Register Server Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2392 | "C:\Users\admin\AppData\Local\Temp\1.exe" /VERYSILENT /PASSWORD=. | C:\Users\admin\AppData\Local\Temp\1.exe | 1.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Storage Tiers Management Setup Exit code: 0 Version: 10.0.14393.0 Modules
| |||||||||||||||
| 4320 | "C:\Users\admin\AppData\Local\Temp\is-4V0J0.tmp\1.tmp" /SL5="$90038,8255608,728064,C:\Users\admin\AppData\Local\Temp\1.exe" | C:\Users\admin\AppData\Local\Temp\is-4V0J0.tmp\1.tmp | 1.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| 4584 | "regsvr32.exe" /s /u "C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\jRCf_jRCfg_jRC-jRCfg3.dll" | C:\Windows\SysWOW64\regsvr32.exe | 1.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft(C) Register Server Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4660 | "C:\Users\admin\AppData\Local\Temp\1.exe" | C:\Users\admin\AppData\Local\Temp\1.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Storage Tiers Management Setup Exit code: 1 Version: 10.0.14393.0 Modules
| |||||||||||||||
| (PID) Process: | (2280) 1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: E8080000424348BDB036DC01 | |||
| (PID) Process: | (2280) 1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: E83F23DB8CB473BFBF056040842E5AE2853648DCB14813442D3B616853E2DB3D | |||
| (PID) Process: | (2280) 1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (2280) 1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\f116a6c2.exe | |||
| (PID) Process: | (2280) 1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFilesHash |
Value: 3650E04208E379C017EDCC6D7DD6A68414079DC3E995B494E45CA9C89509FDC0 | |||
| (PID) Process: | (4320) 1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: E0100000B85209BDB036DC01 | |||
| (PID) Process: | (4320) 1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: C5061CD036CB79C1BD513C1B63F3BE90CC06104190123EE47ECB045746465DB7 | |||
| (PID) Process: | (4320) 1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (4320) 1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (4320) 1.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4320 | 1.tmp | C:\Users\admin\AppData\Local\Temp\is-SENC8.tmp\_isetup\_iscrypt.dll | executable | |
MD5:A69559718AB506675E907FE49DEB71E9 | SHA256:2F6294F9AA09F59A574B5DCD33BE54E16B39377984F3D5658CDA44950FA0F8FC | |||
| 2280 | 1.tmp | C:\Users\admin\AppData\Roaming\Microsoft\SystemCertificates\is-O6J5V.tmp | executable | |
MD5:38CED7C7DCA88182D3D8E02AAA889338 | SHA256:8B8BFE9D542B109EDD6418D5679187ABC1074E0C0F090C7ADA0C608CE868D353 | |||
| 4320 | 1.tmp | C:\Users\admin\AppData\Local\Temp\is-SENC8.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
| 4660 | 1.exe | C:\Users\admin\AppData\Local\Temp\is-4V0J0.tmp\1.tmp | executable | |
MD5:FC5756F163706BB43A19C650DBD90DD4 | SHA256:F5584C8C9BC37F14E725651D42825F49ECF81D1D68ABDA001D6BF6BADFA66301 | |||
| 2280 | 1.tmp | C:\Users\admin\AppData\Local\Temp\is-U44UD.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
| 2280 | 1.tmp | C:\Users\admin\AppData\Local\Temp\is-U44UD.tmp\jRCf_jRCfg_jRC-jRCfg3.dll.zip | compressed | |
MD5:9B059F3A4D126CC76E7D7104FE49308B | SHA256:4308507959394A54C4E3ED9155D09CC842AAE6C1A4F35B4590BF17DC85C6CB3F | |||
| 2280 | 1.tmp | C:\Users\admin\AppData\Local\Temp\is-U44UD.tmp\06r5l.06 | binary | |
MD5:3A92CB78C652E6E3F249B337C3583A41 | SHA256:47CB56989D44C8735426681FD608669A66EACC70CE968418047E0339F21CF8FF | |||
| 2280 | 1.tmp | C:\Users\admin\AppData\Local\Temp\is-U44UD.tmp\is-540BB.tmp | binary | |
MD5:3A92CB78C652E6E3F249B337C3583A41 | SHA256:47CB56989D44C8735426681FD608669A66EACC70CE968418047E0339F21CF8FF | |||
| 2280 | 1.tmp | C:\Users\admin\AppData\Local\Temp\is-U44UD.tmp\is-HP6EF.tmp | binary | |
MD5:E53A02F18EB9498C2168ADC3420BE31A | SHA256:E98DC582BD9EB34431B3B0E6775DA9315DA5A8E6D6100A40D17C8E67FB61C738 | |||
| 2280 | 1.tmp | C:\Users\admin\AppData\Local\Temp\is-U44UD.tmp\wlaJT.wlaJ | binary | |
MD5:E53A02F18EB9498C2168ADC3420BE31A | SHA256:E98DC582BD9EB34431B3B0E6775DA9315DA5A8E6D6100A40D17C8E67FB61C738 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2396 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | DE | binary | 471 b | whitelisted |
7400 | backgroundTaskHost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | DE | binary | 471 b | whitelisted |
2396 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | DE | binary | 471 b | whitelisted |
5460 | backgroundTaskHost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | DE | binary | 314 b | whitelisted |
5868 | backgroundTaskHost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | DE | binary | 471 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2568 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6016 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5224 | SearchApp.exe | 2.16.241.207:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2396 | svchost.exe | 20.190.159.23:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2396 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
5460 | backgroundTaskHost.exe | 2.16.241.221:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
5460 | backgroundTaskHost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
3464 | svchost.exe | 172.211.123.249:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
google.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
arc.msn.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |