File name:

Particle.exe

Full analysis: https://app.any.run/tasks/e35b635a-78e0-421d-b938-49965376412e
Verdict: Malicious activity
Analysis date: July 05, 2024, 19:25:04
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

F6A3A40DA4D9203F28DA87B44E1ECA5C

SHA1:

7DD7881F7A775F9CF0323F5E803EB1182165F98B

SHA256:

F191147C185FD7BADA80523E56BA9A49D448A5106178C44A6E32443D5A602113

SSDEEP:

98304:m899g1egy2sEAbOVlVQN3cyvi2LA625vkEIOywf815K881Kh1uEU7cJBvSk1ejVO:LAiBI1yTenARNh44

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Particle.exe (PID: 5100)
  • SUSPICIOUS

    • Reads the BIOS version

      • Particle.exe (PID: 5100)
  • INFO

    • Process checks whether UAC notifications are on

      • Particle.exe (PID: 5100)
    • Reads the computer name

      • Particle.exe (PID: 5100)
    • Checks supported languages

      • Particle.exe (PID: 5100)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2024:06:15 22:05:45+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.38
CodeSize: 1354752
InitializedDataSize: 6628352
UninitializedDataSize: -
EntryPoint: 0xb62058
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
142
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start particle.exe particle.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1924"C:\Users\admin\Desktop\Particle.exe" C:\Users\admin\Desktop\Particle.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\particle.exe
c:\windows\system32\ntdll.dll
5100"C:\Users\admin\Desktop\Particle.exe" C:\Users\admin\Desktop\Particle.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\particle.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
342
Read events
342
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
1
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
5100Particle.exeC:\Users\admin\Desktop\bin\agree.txttext
MD5:B326B5062B2F0E69046810717534CB09
SHA256:B5BEA41B6C623F7C09F1BF24DCAE58EBAB3C0CDD90AD966BC43A45B44867E12B
5100Particle.exeC:\Users\admin\Desktop\tempcompressed
MD5:76F0CB32B225291ABA34C762FB9C4667
SHA256:48EA7A552133FD536499C6E2A8C95A02A018B35095927EE2C7AAA73FA371837B
5100Particle.exeC:\Users\admin\Desktop\bin\version.txttext
MD5:DCD8A052581BF8AA5CE41B52F33EDCD0
SHA256:30B34F3309C08228A72079F95A2BC14C0D7F2077C5551EFDDE357D070FCFFF86
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
12
TCP/UDP connections
71
DNS requests
23
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
768
lsass.exe
GET
200
172.217.18.3:80
http://c.pki.goog/r/gsr1.crl
unknown
unknown
768
lsass.exe
GET
200
172.217.18.3:80
http://c.pki.goog/r/r4.crl
unknown
unknown
1828
svchost.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
768
lsass.exe
GET
200
172.217.18.3:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFCjJ1PwkYAi7fE%3D
unknown
unknown
1828
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
4656
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
unknown
5100
Particle.exe
GET
301
188.114.96.3:80
http://download.ryo.sh/index.php?license=a9e7c5c926db4ff9969677d6b77cf929
unknown
unknown
6064
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
unknown
6160
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
unknown
6160
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4032
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
1828
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5328
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2832
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5100
Particle.exe
188.114.96.3:443
lapi.ryo.sh
CLOUDFLARENET
NL
unknown
768
lsass.exe
172.217.18.3:80
c.pki.goog
GOOGLE
US
whitelisted
5100
Particle.exe
104.21.24.210:443
nocap.land
CLOUDFLARENET
unknown
1828
svchost.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
lapi.ryo.sh
  • 188.114.96.3
  • 188.114.97.3
unknown
c.pki.goog
  • 172.217.18.3
unknown
nocap.land
  • 104.21.24.210
  • 172.67.220.206
unknown
ocsp.pki.goog
  • 172.217.18.3
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
ryo.sh
  • 188.114.96.3
  • 188.114.97.3
unknown
download.ryo.sh
  • 188.114.96.3
  • 188.114.97.3
unknown
www.bing.com
  • 104.126.37.178
  • 104.126.37.184
  • 104.126.37.171
  • 104.126.37.139
  • 104.126.37.136
  • 104.126.37.170
  • 104.126.37.163
  • 104.126.37.130
  • 104.126.37.186
  • 104.126.37.146
  • 104.126.37.152
  • 104.126.37.123
  • 104.126.37.128
whitelisted

Threats

No threats detected
No debug info