File name:

Run.exe

Full analysis: https://app.any.run/tasks/9d9a573c-2414-45ee-87d0-a1691bbc9bf2
Verdict: Malicious activity
Analysis date: May 10, 2025, 06:46:54
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
python
pyinstaller
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32+ executable (console) x86-64, for MS Windows, 7 sections
MD5:

B587F665BC40D44B67E03D02D88F3D11

SHA1:

39327A76AD039CA80B7B39AC3E9AA09B6BAC280E

SHA256:

ED0CA9E07DA29750861F92FD7499A8DC95A35860186F8BC3A33683F1FBAE9732

SSDEEP:

98304:tw4C+tixa+sENic7T8zKyv530MGf+k4l/onUZXFCh0bR5mh7vSRpl89+bE9d9Yb/:9wcpuCvOp5AQN/rrYo

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • Run.exe (PID: 900)
      • Run.exe (PID: 616)
    • The process drops C-runtime libraries

      • Run.exe (PID: 900)
      • Run.exe (PID: 616)
    • Executable content was dropped or overwritten

      • Run.exe (PID: 900)
      • Run.exe (PID: 616)
    • Process drops python dynamic module

      • Run.exe (PID: 900)
      • Run.exe (PID: 616)
    • Application launched itself

      • Run.exe (PID: 900)
      • Run.exe (PID: 5204)
      • Run.exe (PID: 616)
    • Loads Python modules

      • Run.exe (PID: 5204)
      • Run.exe (PID: 960)
    • Reads the date of Windows installation

      • Run.exe (PID: 5204)
    • Reads security settings of Internet Explorer

      • Run.exe (PID: 5204)
  • INFO

    • Checks supported languages

      • Run.exe (PID: 900)
      • Run.exe (PID: 5204)
      • Run.exe (PID: 616)
      • Run.exe (PID: 960)
    • Reads the computer name

      • Run.exe (PID: 900)
      • Run.exe (PID: 5204)
      • Run.exe (PID: 616)
      • Run.exe (PID: 960)
    • The sample compiled with english language support

      • Run.exe (PID: 900)
      • Run.exe (PID: 616)
    • Create files in a temporary directory

      • Run.exe (PID: 900)
      • Run.exe (PID: 616)
    • PyInstaller has been detected (YARA)

      • Run.exe (PID: 900)
    • Reads the machine GUID from the registry

      • Run.exe (PID: 5204)
      • Run.exe (PID: 960)
    • Process checks computer location settings

      • Run.exe (PID: 5204)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2023:11:01 12:14:06+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.32
CodeSize: 165888
InitializedDataSize: 152576
UninitializedDataSize: -
EntryPoint: 0xa340
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start run.exe conhost.exe no specs sppextcomobj.exe no specs slui.exe no specs run.exe no specs run.exe conhost.exe no specs run.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
496\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeRun.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
616"C:\Users\admin\AppData\Local\Temp\Run.exe" C:\Users\admin\AppData\Local\Temp\_MEI9002\main_3th.pyC:\Users\admin\AppData\Local\Temp\Run.exe
Run.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\local\temp\run.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
900"C:\Users\admin\AppData\Local\Temp\Run.exe" C:\Users\admin\AppData\Local\Temp\Run.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\run.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
960"C:\Users\admin\AppData\Local\Temp\Run.exe" C:\Users\admin\AppData\Local\Temp\_MEI9002\main_3th.pyC:\Users\admin\AppData\Local\Temp\Run.exeRun.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\local\temp\run.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
3896"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5024\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeRun.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5204"C:\Users\admin\AppData\Local\Temp\Run.exe" C:\Users\admin\AppData\Local\Temp\Run.exeRun.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\run.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6264C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
Total events
903
Read events
903
Write events
0
Delete events
0

Modification events

No data
Executable files
114
Suspicious files
1 198
Text files
38
Unknown types
0

Dropped files

PID
Process
Filename
Type
900Run.exeC:\Users\admin\AppData\Local\Temp\_MEI9002\_ctypes.pydexecutable
MD5:2787764FE3056F37C79A3FC79E620172
SHA256:41C593C960F3F89B1E1629C6B7BD6171FE306168F816BEF02027332A263DE117
900Run.exeC:\Users\admin\AppData\Local\Temp\_MEI9002\_lzma.pydexecutable
MD5:AB582419629183E1615B76FC5D2C7704
SHA256:5A45F7CD517AD396A042BC2767AE73221DC68F934E828A9433249924A371EE5E
900Run.exeC:\Users\admin\AppData\Local\Temp\_MEI9002\_queue.pydexecutable
MD5:A48AF48DD880C11673469C1ADE525558
SHA256:A98E9F330EEAF40EF516237AB5BC1EFAC1FC49ED321A128BE78DD3FB8733E0A4
900Run.exeC:\Users\admin\AppData\Local\Temp\_MEI9002\_ssl.pydexecutable
MD5:8B5AF5AC31B6BDE9023A4ADC3E7F0CE1
SHA256:7040D3712F31B7D11882CE8C907452FA725678B646B900F6868F43AB3E4DDAB6
900Run.exeC:\Users\admin\AppData\Local\Temp\_MEI9002\_socket.pydexecutable
MD5:10CD16BB63862536570C717FFC453DA4
SHA256:E002A1BD6FBA44681D557B64D439585DBA9820226E1C3DA5A62628BBAA930AE3
900Run.exeC:\Users\admin\AppData\Local\Temp\_MEI9002\_bz2.pydexecutable
MD5:92075C2759AC8246953E6FA6323E43FE
SHA256:E7AF6119B56DDD47FD0A909710F7163D7EF4822405FC138D24E6CE9DE7A5022F
900Run.exeC:\Users\admin\AppData\Local\Temp\_MEI9002\api-ms-win-core-interlocked-l1-1-0.dllexecutable
MD5:28FD20B58320F0ED023D9CA19DA3A06D
SHA256:2F2F9660F4FFA814F465676D5B9CB9BB70D0B7C5FC5EB14C34CFE94A50883B21
900Run.exeC:\Users\admin\AppData\Local\Temp\_MEI9002\api-ms-win-core-heap-l1-1-0.dllexecutable
MD5:E93F34FDCD8E5FFC34AF48C90F6F95D1
SHA256:ECA63FC5C873CE8B36C507E2B9A88CAAEA9617C84669886B15F6BC38BD0024C6
900Run.exeC:\Users\admin\AppData\Local\Temp\_MEI9002\api-ms-win-core-file-l2-1-0.dllexecutable
MD5:361C6BCFCEA263749419B0FBED7A0CE8
SHA256:B74AEFD6FA638BE3F415165C8109121A2093597421101ABC312EE7FFA1130278
900Run.exeC:\Users\admin\AppData\Local\Temp\_MEI9002\api-ms-win-core-handle-l1-1-0.dllexecutable
MD5:C2CD29370B21C0361D7F79D248C05860
SHA256:550B4F5BA95108B01A24F05496576A4E73642334A10DDE61B09846E0EFB9F260
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
21
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
23.48.23.166:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5892
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5892
SIHClient.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
23.48.23.166:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5496
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
20.190.159.129:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.48.23.166
  • 23.48.23.156
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
google.com
  • 216.58.206.46
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 20.190.159.129
  • 40.126.31.73
  • 20.190.159.4
  • 40.126.31.71
  • 20.190.159.75
  • 20.190.159.73
  • 20.190.159.64
  • 20.190.159.128
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 20.12.23.50
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted

Threats

No threats detected
No debug info