File name:

4

Full analysis: https://app.any.run/tasks/7c08036c-42f6-4c81-af0f-e02925019ab9
Verdict: Malicious activity
Threats:

A backdoor is a type of cybersecurity threat that allows attackers to secretly compromise a system and conduct malicious activities, such as stealing data and modifying files. Backdoors can be difficult to detect, as they often use legitimate system applications to evade defense mechanisms. Threat actors often utilize special malware, such as PlugX, to establish backdoors on target devices.

Analysis date: October 03, 2025, 16:46:08
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
pushdo
cutwail
backdoor
upx
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections
MD5:

4888CA08DB9B98BC392941E8A3E5B467

SHA1:

0F3A69422FA9336349853425F9280C2B90192E6F

SHA256:

E22A9D4962985907FCA587FD56961FFA971871F4C8917863AB2A2F1DBDF48B64

SSDEEP:

6144:D4aYgSUW08ACd9B6toX1mmW62rgj+cjRxGBXs2Dlmp:D43J0adb1bW62q+eSB82Dgp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Connects to the CnC server

      • 4.exe (PID: 7780)
    • Changes the autorun value in the registry

      • 4.exe (PID: 7780)
    • PUSHDO has been detected (SURICATA)

      • 4.exe (PID: 7780)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 4.exe (PID: 7780)
    • Reads security settings of Internet Explorer

      • 4.exe (PID: 7780)
    • Contacting a server suspected of hosting an CnC

      • 4.exe (PID: 7780)
  • INFO

    • Reads the computer name

      • 4.exe (PID: 7780)
    • Creates files or folders in the user directory

      • 4.exe (PID: 7780)
      • BackgroundTransferHost.exe (PID: 8468)
    • Checks supported languages

      • 4.exe (PID: 7780)
    • Launching a file from a Registry key

      • 4.exe (PID: 7780)
    • Reads the machine GUID from the registry

      • 4.exe (PID: 7780)
    • Checks proxy server information

      • 4.exe (PID: 7780)
      • BackgroundTransferHost.exe (PID: 8468)
    • UPX packer has been detected

      • 4.exe (PID: 7780)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 6168)
      • BackgroundTransferHost.exe (PID: 8468)
      • BackgroundTransferHost.exe (PID: 8648)
      • BackgroundTransferHost.exe (PID: 8876)
      • BackgroundTransferHost.exe (PID: 9092)
    • Reads the software policy settings

      • BackgroundTransferHost.exe (PID: 8468)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (64.2)
.dll | Win32 Dynamic Link Library (generic) (15.6)
.exe | Win32 Executable (generic) (10.6)
.exe | Generic Win/DOS Executable (4.7)
.exe | DOS Executable Generic (4.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:07:03 05:31:59+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 12
CodeSize: 151552
InitializedDataSize: 12288
UninitializedDataSize: 192512
EntryPoint: 0x54e00
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
177
Monitored processes
9
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
2360C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
2428C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
4800C:\WINDOWS\splwow64.exe 8192C:\Windows\splwow64.exe4.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Print driver host for applications
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\splwow64.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6168"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
7780"C:\Users\admin\AppData\Local\Temp\4.exe" C:\Users\admin\AppData\Local\Temp\4.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\4.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msimg32.dll
8468"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
8648"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
8876"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
9092"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
Total events
6 002
Read events
5 969
Write events
33
Delete events
0

Modification events

(PID) Process:(7780) 4.exeKey:HKEY_CURRENT_USER\SOFTWARE\Qjqmmbeeetuai
Operation:writeName:Bopbulesmo
Value:
A3F8A85894448030DF1CCB7BB7671753
(PID) Process:(7780) 4.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:gaszilanfofg
Value:
C:\Users\admin\gaszilanfofg.exe
(PID) Process:(7780) 4.exeKey:HKEY_CURRENT_USER\SOFTWARE\Qjqmmbeeetuai
Operation:writeName:gaszilanfofgWafdogakox
Value:
D0CB08B7F3A3DF8FCB7BB767A3538F3F
(PID) Process:(7780) 4.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(7780) 4.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(7780) 4.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(6168) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
(PID) Process:(6168) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(6168) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(8468) BackgroundTransferHost.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\CurrentVersion\AppContainer\Storage\microsoft.windows.contentdeliverymanager_cw5n1h2txyewy\Internet Settings\Cache\Content
Operation:writeName:CachePrefix
Value:
Executable files
1
Suspicious files
6
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
8468BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\bbfb4ee8-e144-4045-ab73-d28ff7aa203b.down_data
MD5:
SHA256:
8468BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\cbddbcfd-66a9-4229-95a8-ac6375a13c9c.58c19daa-069e-40fb-be20-d02ae0a3deea.down_metabinary
MD5:7C65187B0BCAB1802CD84FD8952C0732
SHA256:FB2A26AAA417B44AFF98D3E596D89CDBCFE2982BEE25F7FB55466D232D8FE018
77804.exeC:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1693682860-607145093-2874071422-1001\c5d8393293ce2ba62f117b2c2d55bc3e_bb926e54-e3ca-40fd-ae90-2764341e7792binary
MD5:60806F4F110A6F85831390DAFBB98385
SHA256:219D1A0D4109122414A4EF1B17D392652E94E7492B490EC6FF33EF553D125A4D
77804.exeC:\Users\admin\gaszilanfofg.exeexecutable
MD5:4888CA08DB9B98BC392941E8A3E5B467
SHA256:E22A9D4962985907FCA587FD56961FFA971871F4C8917863AB2A2F1DBDF48B64
8468BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:A2459D8C15651BB81784468BC907C939
SHA256:E6360479BE8038E7443DA1855F01EC552F1B602A656A2BF713C1CD760B7CB6C8
8468BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:3B0F9C18B83CDD23728605ECA20CD273
SHA256:7756DB9B2EA022B31DAAA27BA4CD6342F4A9B8BAE11F62647789AF26D8A82029
8468BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\bbfb4ee8-e144-4045-ab73-d28ff7aa203b.58c19daa-069e-40fb-be20-d02ae0a3deea.down_metabinary
MD5:7C65187B0BCAB1802CD84FD8952C0732
SHA256:FB2A26AAA417B44AFF98D3E596D89CDBCFE2982BEE25F7FB55466D232D8FE018
8468BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\cbddbcfd-66a9-4229-95a8-ac6375a13c9c.up_meta_securebinary
MD5:29F9EFD493E8A99DFB6DF3B3875B20E2
SHA256:6A8B92E8F63C7F536CE96207ACA176C0B2E1C1F722165215FB1EB41E070714CD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
137
TCP/UDP connections
133
DNS requests
115
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
7780
4.exe
POST
301
104.26.3.124:80
http://www.kernsafe.com/
US
html
148 b
malicious
7780
4.exe
POST
403
104.26.7.221:80
http://www.valdal.com/
US
html
4.44 Kb
malicious
7780
4.exe
POST
51.79.51.72:80
http://www.holleman.us/
CA
malicious
7780
4.exe
POST
301
23.235.195.126:80
http://www.quadlock.com/
US
html
242 b
malicious
7780
4.exe
POST
301
67.225.154.71:80
http://www.ottospm.com/
US
html
228 b
malicious
7780
4.exe
POST
301
104.21.63.53:80
http://www.yumgiskor.kz/
unknown
malicious
7780
4.exe
POST
301
104.26.3.124:80
http://www.kernsafe.com/
US
html
148 b
malicious
7780
4.exe
POST
200
74.208.236.101:80
http://www.myropcb.com/
US
html
55.8 Kb
malicious
7780
4.exe
POST
301
67.225.154.71:80
http://www.ottospm.com/
US
html
228 b
malicious
7780
4.exe
POST
301
85.131.197.10:80
http://www.stajum.com/
DE
html
231 b
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6016
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6168
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5224
SearchApp.exe
23.36.162.84:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
7780
4.exe
213.186.33.17:80
www.item-pr.com
OVH SAS
FR
malicious
7780
4.exe
51.79.51.72:80
www.holleman.us
OVH SAS
CA
unknown
7780
4.exe
172.67.201.26:80
www.pcgrate.com
CLOUDFLARENET
US
malicious
7780
4.exe
104.26.3.124:80
www.kernsafe.com
CLOUDFLARENET
US
shared
7780
4.exe
104.26.7.221:80
www.valdal.com
CLOUDFLARENET
US
malicious

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
www.bing.com
  • 23.36.162.84
  • 23.36.162.68
  • 2.16.241.199
  • 2.16.241.216
  • 2.16.241.204
  • 2.16.241.201
  • 2.16.241.225
whitelisted
google.com
  • 216.58.212.174
whitelisted
www.quadlock.com
  • 23.235.195.126
malicious
www.valdal.com
  • 104.26.7.221
  • 172.67.73.176
  • 104.26.6.221
malicious
www.stajum.com
  • 85.131.197.10
malicious
www.udesign.biz
malicious
www.item-pr.com
  • 213.186.33.17
  • 185.15.129.58
malicious
www.holleman.us
  • 51.79.51.72
malicious
www.mobilnic.net
malicious

Threats

PID
Process
Class
Message
7780
4.exe
Malware Command and Control Activity Detected
ET MALWARE Backdoor.Win32.Pushdo.s Checkin
7780
4.exe
Potentially Bad Traffic
ET INFO Referrer-Policy set to unsafe-url
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info