| File name: | 8.exe |
| Full analysis: | https://app.any.run/tasks/c5535d12-95ee-4123-8d45-e6101fa3f120 |
| Verdict: | Malicious activity |
| Analysis date: | August 24, 2024, 14:36:02 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5: | 7FF76B5BEB86B5301239BBA18F72E18C |
| SHA1: | D626A9274229C75F563C42DFB1F88F7C336C640E |
| SHA256: | F2A441B66B3E2DD90D80CD20F31D5137F166421D8A72DA5E547DD42B9749B003 |
| SSDEEP: | 98304:+LES5krzSl/ZOVAwXQj6NErTcG5oVouBQozl62Ps2LEijYmWZVwrhFZkSYMvshKy:+Lse |
| .exe | | | Win64 Executable (generic) (39.5) |
|---|---|---|
| .exe | | | UPX compressed Win32 Executable (38.7) |
| .dll | | | Win32 Dynamic Link Library (generic) (9.4) |
| .exe | | | Win32 Executable (generic) (6.4) |
| .exe | | | Generic Win/DOS Executable (2.8) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:08:13 15:46:54+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.37 |
| CodeSize: | 1945600 |
| InitializedDataSize: | 4096 |
| UninitializedDataSize: | 2109440 |
| EntryPoint: | 0x3de130 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 6644 | C:\WINDOWS\SysWOW64\WerFault.exe -u -p 6716 -s 1032 | C:\Windows\SysWOW64\WerFault.exe | 8.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6716 | "C:\Users\admin\Desktop\8.exe" | C:\Users\admin\Desktop\8.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221225477 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6644 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\ReportQueue\AppCrash_8.exe_78933bf5198b12a8b7177dff866ba2734f4b3_188444c2_7228e7a9-53a4-4ee1-a717-4655e50d79a5\Report.wer | — | |
MD5:— | SHA256:— | |||
| 6644 | WerFault.exe | C:\Users\admin\AppData\Local\CrashDumps\8.exe.6716.dmp | — | |
MD5:— | SHA256:— | |||
| 6716 | 8.exe | C:\Users\admin\AppData\Roaming\Microsoft\Crypto\RSA\S-1-5-21-1693682860-607145093-2874071422-1001\e6d889b9d4a26ff7b8379cc5cc168ca3_bb926e54-e3ca-40fd-ae90-2764341e7792 | dbf | |
MD5:6B7B344A09169556E471A409DBA04169 | SHA256:786D9DF73D802EBA4FA409C51DFF30B9E899F577CF40D28953003E297F166CCC | |||
| 6644 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WERB45.tmp.xml | xml | |
MD5:DA4D737C8C4B6A0FE93D939F1BD6B120 | SHA256:B39A580B0B8EFD21F654C09254FE0C81155D3CF107EB5F5EFB17B4B652185FD4 | |||
| 6644 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WER930.tmp.dmp | dmp | |
MD5:61D5233EB27481A3DCEE5FEDCB5FBCF2 | SHA256:37325803198BFE68438EE7D3CAE3B874F7E02CBCD4B7D4C6B3DCB2658406E264 | |||
| 6644 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WERAF6.tmp.WERInternalMetadata.xml | xml | |
MD5:F0290EB00C585CF24343934834B793B1 | SHA256:16E8D6797421DFE8BB665368F831A2FB3699F9181C161107EB0BD9698991A947 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1616 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 192.168.100.255:138 | — | — | — | whitelisted |
2088 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2120 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2120 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1616 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4324 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6644 | WerFault.exe | 52.182.143.212:443 | watson.events.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
watson.events.data.microsoft.com |
| whitelisted |