File name: | Run.exe |
Full analysis: | https://app.any.run/tasks/bfb0debe-d952-4993-8ca7-15dcfdd0ad5c |
Verdict: | Malicious activity |
Analysis date: | May 10, 2025, 06:27:57 |
OS: | Windows 10 Professional (build: 19044, 64 bit) |
Tags: | |
Indicators: | |
MIME: | application/vnd.microsoft.portable-executable |
File info: | PE32+ executable (console) x86-64, for MS Windows, 7 sections |
MD5: | B587F665BC40D44B67E03D02D88F3D11 |
SHA1: | 39327A76AD039CA80B7B39AC3E9AA09B6BAC280E |
SHA256: | ED0CA9E07DA29750861F92FD7499A8DC95A35860186F8BC3A33683F1FBAE9732 |
SSDEEP: | 98304:tw4C+tixa+sENic7T8zKyv530MGf+k4l/onUZXFCh0bR5mh7vSRpl89+bE9d9Yb/:9wcpuCvOp5AQN/rrYo |
.exe | | | Win64 Executable (generic) (87.3) |
---|---|---|
.exe | | | Generic Win/DOS Executable (6.3) |
.exe | | | DOS Executable Generic (6.3) |
MachineType: | AMD AMD64 |
---|---|
TimeStamp: | 2023:11:01 12:14:06+00:00 |
ImageFileCharacteristics: | Executable, Large address aware |
PEType: | PE32+ |
LinkerVersion: | 14.32 |
CodeSize: | 165888 |
InitializedDataSize: | 152576 |
UninitializedDataSize: | - |
EntryPoint: | 0xa340 |
OSVersion: | 5.2 |
ImageVersion: | - |
SubsystemVersion: | 5.2 |
Subsystem: | Windows command line |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
664 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | Run.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
5008 | "C:\Users\admin\AppData\Local\Temp\Run.exe" | C:\Users\admin\AppData\Local\Temp\Run.exe | — | Run.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
5384 | "C:\Users\admin\AppData\Local\Temp\Run.exe" C:\Users\admin\AppData\Local\Temp\_MEI61842\main_3th.py | C:\Users\admin\AppData\Local\Temp\Run.exe | — | Run.exe | |||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
6184 | "C:\Users\admin\AppData\Local\Temp\Run.exe" | C:\Users\admin\AppData\Local\Temp\Run.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
6272 | "C:\Users\admin\AppData\Local\Temp\Run.exe" C:\Users\admin\AppData\Local\Temp\_MEI61842\main_3th.py | C:\Users\admin\AppData\Local\Temp\Run.exe | Run.exe | ||||||||||||
User: admin Integrity Level: HIGH Modules
| |||||||||||||||
6620 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | Run.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
|
PID | Process | Filename | Type | |
---|---|---|---|---|
6184 | Run.exe | C:\Users\admin\AppData\Local\Temp\_MEI61842\api-ms-win-core-file-l1-2-0.dll | executable | |
MD5:9D8413744097196F92327F632A85ACEE | SHA256:6878D8168D5CC159EFE58F14E5BA10310D99B53AB8495521E54C966994DAC50B | |||
6184 | Run.exe | C:\Users\admin\AppData\Local\Temp\_MEI61842\api-ms-win-core-file-l2-1-0.dll | executable | |
MD5:361C6BCFCEA263749419B0FBED7A0CE8 | SHA256:B74AEFD6FA638BE3F415165C8109121A2093597421101ABC312EE7FFA1130278 | |||
6184 | Run.exe | C:\Users\admin\AppData\Local\Temp\_MEI61842\_hashlib.pyd | executable | |
MD5:7808B500FBFB17C968F10EE6D68461DF | SHA256:E2701F4E4A7556ADAB7415E448070289BA4FE047227F48C3A049D7C3154AFF0B | |||
6184 | Run.exe | C:\Users\admin\AppData\Local\Temp\_MEI61842\api-ms-win-core-errorhandling-l1-1-0.dll | executable | |
MD5:6177998C2CE574A177E524746B77EFE7 | SHA256:A0AA340274D4BB46B6D9547D647AB7DC16C229577BBAB836E6A4F3307F310332 | |||
6184 | Run.exe | C:\Users\admin\AppData\Local\Temp\_MEI61842\api-ms-win-core-console-l1-1-0.dll | executable | |
MD5:7699C096202DA0DB6B07FAFC914D60ED | SHA256:0052515763A1A31D2527A2EB2523FB7B88D8E55C4E4DA5EF352B565476BF21E0 | |||
6184 | Run.exe | C:\Users\admin\AppData\Local\Temp\_MEI61842\_ssl.pyd | executable | |
MD5:8B5AF5AC31B6BDE9023A4ADC3E7F0CE1 | SHA256:7040D3712F31B7D11882CE8C907452FA725678B646B900F6868F43AB3E4DDAB6 | |||
6184 | Run.exe | C:\Users\admin\AppData\Local\Temp\_MEI61842\api-ms-win-core-datetime-l1-1-0.dll | executable | |
MD5:928BE2A3FC2E88BDA5CA0808324E97C4 | SHA256:CC6C2FDF1C34FA82036165B111F91220BCF7E43AAB79DFB284F982F0590BEBB1 | |||
6184 | Run.exe | C:\Users\admin\AppData\Local\Temp\_MEI61842\_lzma.pyd | executable | |
MD5:AB582419629183E1615B76FC5D2C7704 | SHA256:5A45F7CD517AD396A042BC2767AE73221DC68F934E828A9433249924A371EE5E | |||
6184 | Run.exe | C:\Users\admin\AppData\Local\Temp\_MEI61842\_bz2.pyd | executable | |
MD5:92075C2759AC8246953E6FA6323E43FE | SHA256:E7AF6119B56DDD47FD0A909710F7163D7EF4822405FC138D24E6CE9DE7A5022F | |||
6184 | Run.exe | C:\Users\admin\AppData\Local\Temp\_MEI61842\VCRUNTIME140.dll | executable | |
MD5:0E675D4A7A5B7CCD69013386793F68EB | SHA256:BF5FF4603557C9959ACEC995653D052D9054AD4826DF967974EFD2F377C723D1 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
— | — | GET | 200 | 23.48.23.156:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6544 | svchost.exe | GET | 200 | 2.17.190.73:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
1276 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
1276 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 23.48.23.156:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
— | — | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
— | — | 172.211.123.249:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | FR | whitelisted |
6544 | svchost.exe | 20.190.160.17:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
6544 | svchost.exe | 2.17.190.73:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
2104 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1276 | SIHClient.exe | 20.12.23.50:443 | slscr.update.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
nexusrules.officeapps.live.com |
| whitelisted |