File name:

netio-gui_v1.0.8_portable.exe

Full analysis: https://app.any.run/tasks/f3442e47-db4a-43f9-89f6-680678527ca0
Verdict: Malicious activity
Analysis date: March 31, 2025, 11:34:08
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

A0D78015185E2DB9614CB580F92AE75F

SHA1:

0FB53ECACF609DE78C8A4F5B44D8939873AAA060

SHA256:

F1D1AA228C4F8717B72FF51294C64B9AB9202A717AE33DBFD9D3B17E84953273

SSDEEP:

98304:7FVuvB7VlhSiP2Mpoi/eZzjD5JSu6fkQOUqwejUgE3rUumf1u9kVm9UjuBMnV47S:zejVU0RH3W

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops 7-zip archiver for unpacking

      • netio-gui_v1.0.8_portable.exe (PID: 6572)
    • Executable content was dropped or overwritten

      • netio-gui_v1.0.8_portable.exe (PID: 6572)
    • Process drops legitimate windows executable

      • netio-gui_v1.0.8_portable.exe (PID: 6572)
    • Reads security settings of Internet Explorer

      • NetIO-GUI.exe (PID: 6488)
  • INFO

    • Reads the computer name

      • netio-gui_v1.0.8_portable.exe (PID: 6572)
      • NetIO-GUI.exe (PID: 6488)
    • Checks supported languages

      • netio-gui_v1.0.8_portable.exe (PID: 6572)
      • NetIO-GUI.exe (PID: 6488)
    • The sample compiled with english language support

      • netio-gui_v1.0.8_portable.exe (PID: 6572)
    • Manual execution by a user

      • NetIO-GUI.exe (PID: 6488)
    • Reads the machine GUID from the registry

      • NetIO-GUI.exe (PID: 6488)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:07:15 14:00:00+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 178176
InitializedDataSize: 54784
UninitializedDataSize: -
EntryPoint: 0x294cc
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 22.1.0.0
ProductVersionNumber: 22.1.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Igor Pavlov
FileDescription: 7z SFX
FileVersion: 22.01
InternalName: 7z.sfx
LegalCopyright: Copyright (c) 1999-2022 Igor Pavlov
OriginalFileName: 7z.sfx.exe
ProductName: 7-Zip
ProductVersion: 22.01
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
131
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start netio-gui_v1.0.8_portable.exe sppextcomobj.exe no specs slui.exe no specs rundll32.exe no specs netio-gui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
732"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
6004C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6048C:\WINDOWS\System32\rundll32.exe C:\WINDOWS\System32\shell32.dll,SHCreateLocalServerRunDll {9aa46009-3ce0-458a-a354-715610a075e6} -EmbeddingC:\Windows\System32\rundll32.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
6488"C:\Users\admin\Downloads\NetIO-GUI.exe" C:\Users\admin\Downloads\NetIO-GUI.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
NetIO-GUI
Version:
1.0.8
Modules
Images
c:\users\admin\downloads\netio-gui.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
6572"C:\Users\admin\Downloads\netio-gui_v1.0.8_portable.exe" C:\Users\admin\Downloads\netio-gui_v1.0.8_portable.exe
explorer.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7z SFX
Exit code:
0
Version:
22.01
Modules
Images
c:\users\admin\downloads\netio-gui_v1.0.8_portable.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\oleaut32.dll
Total events
552
Read events
552
Write events
0
Delete events
0

Modification events

No data
Executable files
22
Suspicious files
5
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
6572netio-gui_v1.0.8_portable.exeC:\Users\admin\Downloads\netio\readme.txttext
MD5:7164D767A06E36CC53007B40C2E1E5CF
SHA256:ED369285CE32C11549670D52DC6677AFD0229497CDA8BE989C969212058A7C92
6572netio-gui_v1.0.8_portable.exeC:\Users\admin\Downloads\NLog.configxml
MD5:5FBCB8EA88154F38DBA6DA10BC4113E5
SHA256:8020A05D896EEBE04FA41307EF530A34B4FF86541A4467F5163640F119C8462D
6572netio-gui_v1.0.8_portable.exeC:\Users\admin\Downloads\netio\netio.doctext
MD5:9B55E6E7B647C96F8ED23768B85E9214
SHA256:873435C204513C9CC32E0E44C57534EFBE72F662E62138CE9129A97256DB005B
6572netio-gui_v1.0.8_portable.exeC:\Users\admin\Downloads\NetIO-GUI.pdfpdf
MD5:BFB42D653832F51418DFDCD8B18AB185
SHA256:A22674E7682CE66DB5BEBD6F26483583D7DC29159D88AD8D1E59335D9D5CBD2D
6572netio-gui_v1.0.8_portable.exeC:\Users\admin\Downloads\NetIO-GUI_En.pdfpdf
MD5:F75E7EB5AA3ABEC0FDA8EF98A4D225F3
SHA256:BDCF6F9F1618B96C7AFFC5BA78D721F42879EB7B2D0E08999A0E8383C8FD9096
6572netio-gui_v1.0.8_portable.exeC:\Users\admin\Downloads\NLog.dllexecutable
MD5:0E788AB71533FB558319BDC0B80463AD
SHA256:D0866DD6C8BA342ADE14402DFE8AE8E6D64DF35F42C4028CDA3F47D340D5B5E1
6572netio-gui_v1.0.8_portable.exeC:\Users\admin\Downloads\netio\netio_win32-i686.exeexecutable
MD5:4E6AE80AA0AF615E700B666C733A4C62
SHA256:6F880E3B872069F5C8529DA7CB0CDF9D33CD85623655116B504081D93B681C11
6572netio-gui_v1.0.8_portable.exeC:\Users\admin\Downloads\gpl.txttext
MD5:06E9D8445FB8DD0C4D4311BDCE043C12
SHA256:79F39BA4DA8E919AF5BED2E616646D87048B77F040F9CD081572DCA4F6B63B3E
6572netio-gui_v1.0.8_portable.exeC:\Users\admin\Downloads\en\NetIO-GUI.resources.dllexecutable
MD5:73EC116DEB1E3EA9AF73E1D651E669D0
SHA256:B0504A8F2312D63D7E25FB77CDF9B484B3087AAEB68E6C45FA8C5BA0883AEBB5
6572netio-gui_v1.0.8_portable.exeC:\Users\admin\Downloads\de\NetIO-GUI.resources.dllexecutable
MD5:7D91BD6DE869DD171E53D75289228B32
SHA256:C6395CF4E26CC820FAB5A55709B6129EAF740B472DB48C72423A095E2F49E974
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
17
DNS requests
12
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
23.216.77.8:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1312
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1312
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.216.77.8:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
3216
svchost.exe
20.7.2.167:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
6544
svchost.exe
20.190.160.130:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
whitelisted
4
System
192.168.100.255:137
whitelisted
2104
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1312
SIHClient.exe
4.245.163.56:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1312
SIHClient.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 142.250.184.206
whitelisted
crl.microsoft.com
  • 23.216.77.8
  • 23.216.77.13
  • 23.216.77.27
  • 23.216.77.19
  • 23.216.77.29
  • 23.216.77.30
  • 23.216.77.25
  • 23.216.77.26
  • 23.216.77.21
whitelisted
client.wns.windows.com
  • 20.7.2.167
whitelisted
login.live.com
  • 20.190.160.130
  • 20.190.160.128
  • 40.126.32.74
  • 40.126.32.134
  • 20.190.160.14
  • 20.190.160.2
  • 40.126.32.68
  • 20.190.160.5
whitelisted
ocsp.digicert.com
  • 184.30.131.245
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted

Threats

No threats detected
No debug info