File name:

qilin.exe

Full analysis: https://app.any.run/tasks/6b7e767b-1e44-469a-837f-542896b22bd7
Verdict: Malicious activity
Threats:

Ransomware is a type of malicious software that locks users out of their system or data using different methods to force them to pay a ransom. Most often, such programs encrypt files on an infected machine and demand a fee to be paid in exchange for the decryption key. Additionally, such programs can be used to steal sensitive information from the compromised computer and even conduct DDoS attacks against affected organizations to pressure them into paying.

Analysis date: April 29, 2025, 07:11:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
ransomware
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (console) Intel 80386 (stripped to external PDB), for MS Windows, 9 sections
MD5:

6A93E618E467ED13F98819172E24FFFA

SHA1:

D34550EBC2BEE47C708C8E048EB78881468E6BCA

SHA256:

E90BDAAF5F9CA900133B699F18E4062562148169B29CB4EB37A0577388C22527

SSDEEP:

49152:qngIXil301bF/SvandXDIKtFSuNgMPyrzrZ9OUFdDhGgEoB0:qnP32MM9VFvGgEo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Deletes shadow copies

      • cmd.exe (PID: 2948)
    • Renames files like ransomware

      • qilin.exe (PID: 2812)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • qilin.exe (PID: 2812)
    • Reads the Internet Settings

      • rundll32.exe (PID: 3236)
  • INFO

    • Reads the computer name

      • qilin.exe (PID: 2812)
    • Checks supported languages

      • qilin.exe (PID: 2812)
    • Creates files or folders in the user directory

      • qilin.exe (PID: 2812)
    • Manual execution by a user

      • rundll32.exe (PID: 3236)
      • explorer.exe (PID: 1396)
    • Application launched itself

      • msedge.exe (PID: 3220)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:09:13 09:55:04+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Large address aware, 32-bit, No debug
PEType: PE32
LinkerVersion: 2.35
CodeSize: 1053696
InitializedDataSize: 1641472
UninitializedDataSize: 512
EntryPoint: 0x14c0
OSVersion: 4
ImageVersion: 1
SubsystemVersion: 4
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
54
Monitored processes
19
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start qilin.exe no specs PhotoViewer.dll no specs cmd.exe no specs vssadmin.exe no specs explorer.exe no specs rundll32.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
656"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=3440 --field-trial-handle=1140,i,6392494958457184707,265340259131524339,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
944"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --extension-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=3224 --field-trial-handle=1140,i,6392494958457184707,265340259131524339,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
972vssadmin.exe delete shadows /all /quietC:\Windows\System32\vssadmin.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Command Line Interface for Microsoft® Volume Shadow Copy Service
Exit code:
2
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssadmin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\atl.dll
c:\windows\system32\user32.dll
1076"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1640 --field-trial-handle=1140,i,6392494958457184707,265340259131524339,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1396"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2112"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3844 --field-trial-handle=1140,i,6392494958457184707,265340259131524339,131072 --enable-features=msMicrosoftRootStoreUsed /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2276C:\Windows\system32\DllHost.exe /Processid:{76D0CB12-7604-4048-B83C-1005C7DDC503}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2812"C:\qilin.exe" -password AgendaPassC:\qilin.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\qilin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\psapi.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2948"cmd" /C "vssadmin.exe delete shadows /all /quiet"C:\Windows\System32\cmd.exeqilin.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3220"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://go.microsoft.com/fwlink/?LinkId=57426&Ext=MmXReVIxLVC:\Program Files\Microsoft\Edge\Application\msedge.exe
rundll32.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
2 850
Read events
2 805
Write events
39
Delete events
6

Modification events

(PID) Process:(2276) dllhost.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
DllHost.exe
(PID) Process:(2276) dllhost.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows Photo Viewer\Viewer
Operation:writeName:MainWndPos
Value:
6000000034000000A00400008002000000000000
(PID) Process:(3220) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(3220) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(3220) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(3220) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(3220) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(3220) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:dr
Value:
1
(PID) Process:(3220) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(3220) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1302019708-1500728564-335382590-1000
Value:
B5BC9ADD7B922F00
Executable files
4
Suspicious files
241
Text files
72
Unknown types
0

Dropped files

PID
Process
Filename
Type
2812qilin.exeC:\Users\admin\AppData\Local\VirtualStore\README-RECOVER-MmXReVIxLV.txttext
MD5:0B080299BD4389F496CB40D4F87BE3BF
SHA256:16CBD60F0E147C4998E3C3D140AF23365E77C3403737BE0157B878753BF4F999
2812qilin.exeC:\Users\admin\README-RECOVER-MmXReVIxLV.txttext
MD5:0B080299BD4389F496CB40D4F87BE3BF
SHA256:16CBD60F0E147C4998E3C3D140AF23365E77C3403737BE0157B878753BF4F999
2812qilin.exeC:\Users\admin\.oracle_jre_usage\README-RECOVER-MmXReVIxLV.txttext
MD5:0B080299BD4389F496CB40D4F87BE3BF
SHA256:16CBD60F0E147C4998E3C3D140AF23365E77C3403737BE0157B878753BF4F999
2812qilin.exeC:\Users\admin\Contacts\README-RECOVER-MmXReVIxLV.txttext
MD5:0B080299BD4389F496CB40D4F87BE3BF
SHA256:16CBD60F0E147C4998E3C3D140AF23365E77C3403737BE0157B878753BF4F999
2812qilin.exeC:\Users\admin\Desktop\README-RECOVER-MmXReVIxLV.txttext
MD5:0B080299BD4389F496CB40D4F87BE3BF
SHA256:16CBD60F0E147C4998E3C3D140AF23365E77C3403737BE0157B878753BF4F999
2812qilin.exeC:\Users\admin\Desktop\computersexpress.jpgbinary
MD5:1805A43B40AC44D6B363A9694F20703E
SHA256:1570377DF7046C0D59D2DAC008CC09A07D1CE6F77211F280CE34BB1561B3CC04
2812qilin.exeC:\Users\admin\Desktop\computersexpress.jpg.MmXReVIxLVbinary
MD5:1805A43B40AC44D6B363A9694F20703E
SHA256:1570377DF7046C0D59D2DAC008CC09A07D1CE6F77211F280CE34BB1561B3CC04
2812qilin.exeC:\Users\admin\Desktop\fictiontell.rtfbinary
MD5:0184D5A255FF8F34D96D103A282D8D07
SHA256:25F3AE37ECC54569B7E7F0CF695FC2BA313D9CAAE0BE83ED38A1CFE5CE2F86B7
2812qilin.exeC:\Users\admin\Desktop\areasentire.png.MmXReVIxLVbinary
MD5:091EA8061ECD4E935E9F15C98B129D7C
SHA256:4CEFA7803F732E0C1E6E217FF7E853D91C49F02D617539CAD88359FC620904EF
2812qilin.exeC:\Users\admin\Contacts\admin.contactbinary
MD5:19D51CB299361AD914B025F95077DB2F
SHA256:88612CBE312D608A24CC54920A361EB456D30B83D8FF12A5DC937FF7D3F6AD26
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
24
DNS requests
25
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4024
msedge.exe
GET
302
23.218.210.69:80
http://go.microsoft.com/fwlink/?LinkId=57426&Ext=MmXReVIxLV
unknown
whitelisted
4024
msedge.exe
GET
301
23.32.238.225:80
http://shell.windows.com/fileassoc/fileassoc.asp?Ext=MmXReVIxLV
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
whitelisted
4
System
192.168.100.255:138
whitelisted
3220
msedge.exe
239.255.255.250:1900
whitelisted
4024
msedge.exe
150.171.28.11:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4024
msedge.exe
23.218.210.69:80
go.microsoft.com
AKAMAI-AS
DE
whitelisted
4024
msedge.exe
23.32.238.225:80
shell.windows.com
Akamai International B.V.
DE
whitelisted
4024
msedge.exe
2.16.204.152:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4024
msedge.exe
2.16.204.160:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4024
msedge.exe
2.16.204.137:443
r.bing.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.142
whitelisted
config.edge.skype.com
  • 13.107.43.16
whitelisted
edge.microsoft.com
  • 150.171.28.11
  • 150.171.27.11
whitelisted
go.microsoft.com
  • 23.218.210.69
whitelisted
shell.windows.com
  • 23.32.238.225
  • 23.32.238.185
whitelisted
www.bing.com
  • 2.16.204.152
  • 2.16.204.160
  • 2.16.204.156
  • 2.16.204.153
  • 2.16.204.158
  • 2.16.204.149
  • 2.16.204.157
  • 2.16.204.161
  • 2.16.204.159
whitelisted
r.bing.com
  • 2.16.204.137
  • 2.16.204.146
  • 2.16.204.135
  • 2.16.204.160
  • 2.16.204.138
  • 2.16.204.143
  • 2.16.204.134
  • 2.16.204.161
  • 2.16.204.142
whitelisted
th.bing.com
  • 2.16.204.160
  • 2.16.204.156
  • 2.16.204.152
  • 2.16.204.153
  • 2.16.204.159
  • 2.16.204.148
  • 2.16.204.149
  • 2.16.204.158
  • 2.16.204.157
  • 2.16.204.142
  • 2.16.204.137
  • 2.16.204.146
  • 2.16.204.135
  • 2.16.204.138
  • 2.16.204.143
  • 2.16.204.134
  • 2.16.204.161
whitelisted
login.live.com
  • 40.126.31.129
  • 40.126.31.1
  • 20.190.159.75
  • 20.190.159.130
  • 40.126.31.67
  • 20.190.159.128
  • 20.190.159.71
  • 40.126.31.3
whitelisted
www2.bing.com
  • 150.171.30.10
  • 150.171.29.10
whitelisted

Threats

No threats detected
No debug info