File name:

8.exe

Full analysis: https://app.any.run/tasks/c5535d12-95ee-4123-8d45-e6101fa3f120
Verdict: Malicious activity
Analysis date: August 24, 2024, 14:36:02
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

7FF76B5BEB86B5301239BBA18F72E18C

SHA1:

D626A9274229C75F563C42DFB1F88F7C336C640E

SHA256:

F2A441B66B3E2DD90D80CD20F31D5137F166421D8A72DA5E547DD42B9749B003

SSDEEP:

98304:+LES5krzSl/ZOVAwXQj6NErTcG5oVouBQozl62Ps2LEijYmWZVwrhFZkSYMvshKy:+Lse

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops the executable file immediately after the start

      • 8.exe (PID: 6716)
    • Executes application which crashes

      • 8.exe (PID: 6716)
    • The process checks if it is being run in the virtual environment

      • 8.exe (PID: 6716)
  • INFO

    • Creates files or folders in the user directory

      • 8.exe (PID: 6716)
      • WerFault.exe (PID: 6644)
    • Checks supported languages

      • 8.exe (PID: 6716)
    • Reads the machine GUID from the registry

      • 8.exe (PID: 6716)
    • Checks proxy server information

      • 8.exe (PID: 6716)
      • WerFault.exe (PID: 6644)
    • Reads the computer name

      • 8.exe (PID: 6716)
    • Reads the software policy settings

      • WerFault.exe (PID: 6644)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (39.5)
.exe | UPX compressed Win32 Executable (38.7)
.dll | Win32 Dynamic Link Library (generic) (9.4)
.exe | Win32 Executable (generic) (6.4)
.exe | Generic Win/DOS Executable (2.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:08:13 15:46:54+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 14.37
CodeSize: 1945600
InitializedDataSize: 4096
UninitializedDataSize: 2109440
EntryPoint: 0x3de130
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
127
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 8.exe werfault.exe

Process information

PID
CMD
Path
Indicators
Parent process
6644C:\WINDOWS\SysWOW64\WerFault.exe -u -p 6716 -s 1032C:\Windows\SysWOW64\WerFault.exe
8.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
6716"C:\Users\admin\Desktop\8.exe" C:\Users\admin\Desktop\8.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Modules
Images
c:\users\admin\desktop\8.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
8 622
Read events
8 622
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
2
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
6644WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_8.exe_78933bf5198b12a8b7177dff866ba2734f4b3_188444c2_7228e7a9-53a4-4ee1-a717-4655e50d79a5\Report.wer
MD5:
SHA256:
6644WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\8.exe.6716.dmp
MD5:
SHA256:
67168.exeC:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1693682860-607145093-2874071422-1001\e6d889b9d4a26ff7b8379cc5cc168ca3_bb926e54-e3ca-40fd-ae90-2764341e7792dbf
MD5:6B7B344A09169556E471A409DBA04169
SHA256:786D9DF73D802EBA4FA409C51DFF30B9E899F577CF40D28953003E297F166CCC
6644WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERB45.tmp.xmlxml
MD5:DA4D737C8C4B6A0FE93D939F1BD6B120
SHA256:B39A580B0B8EFD21F654C09254FE0C81155D3CF107EB5F5EFB17B4B652185FD4
6644WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WER930.tmp.dmpdmp
MD5:61D5233EB27481A3DCEE5FEDCB5FBCF2
SHA256:37325803198BFE68438EE7D3CAE3B874F7E02CBCD4B7D4C6B3DCB2658406E264
6644WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERAF6.tmp.WERInternalMetadata.xmlxml
MD5:F0290EB00C585CF24343934834B793B1
SHA256:16E8D6797421DFE8BB665368F831A2FB3699F9181C161107EB0BD9698991A947
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
15
DNS requests
5
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1616
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
192.168.100.255:138
whitelisted
2088
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
1616
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4324
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6644
WerFault.exe
52.182.143.212:443
watson.events.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 51.104.136.2
whitelisted
google.com
  • 142.250.185.206
whitelisted
watson.events.data.microsoft.com
  • 52.182.143.212
whitelisted

Threats

No threats detected
No debug info