File name:

f3ca80318e621070ccee3cb24412daab9c031092ad66e04301a6350f54e88675

Full analysis: https://app.any.run/tasks/e6ad6185-722e-4add-aa4f-8fe23de5c172
Verdict: Malicious activity
Analysis date: May 10, 2025, 01:23:49
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto-startup
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

474A9D3A63BB9A2B0DC18E58A6E8BB52

SHA1:

4D3B4995919970D67022B8525D2AB44A8E4EA0B8

SHA256:

F3CA80318E621070CCEE3CB24412DAAB9C031092AD66E04301A6350F54E88675

SSDEEP:

49152:+h8Pq1+Ju20+UsBfGCeQI9+6RVNC2RyKQqSm7IpG5j0NH8i0gROsU50nI2YWPTzu:+SPO+XJUa+wIA6RVNC2gKnJNj68tWIsM

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Create files in the Startup directory

      • f3ca80318e621070ccee3cb24412daab9c031092ad66e04301a6350f54e88675.exe (PID: 1852)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • f3ca80318e621070ccee3cb24412daab9c031092ad66e04301a6350f54e88675.exe (PID: 1852)
    • The process checks if it is being run in the virtual environment

      • RegAsm.exe (PID: 5024)
      • RegAsm.exe (PID: 5988)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 6184)
  • INFO

    • Checks supported languages

      • f3ca80318e621070ccee3cb24412daab9c031092ad66e04301a6350f54e88675.exe (PID: 1852)
      • RegAsm.exe (PID: 5024)
      • TypeId.exe (PID: 5800)
      • RegAsm.exe (PID: 5988)
    • Reads the computer name

      • f3ca80318e621070ccee3cb24412daab9c031092ad66e04301a6350f54e88675.exe (PID: 1852)
      • RegAsm.exe (PID: 5024)
      • TypeId.exe (PID: 5800)
      • RegAsm.exe (PID: 5988)
    • Auto-launch of the file from Startup directory

      • f3ca80318e621070ccee3cb24412daab9c031092ad66e04301a6350f54e88675.exe (PID: 1852)
    • Reads the machine GUID from the registry

      • f3ca80318e621070ccee3cb24412daab9c031092ad66e04301a6350f54e88675.exe (PID: 1852)
      • RegAsm.exe (PID: 5024)
      • TypeId.exe (PID: 5800)
      • RegAsm.exe (PID: 5988)
    • Creates files or folders in the user directory

      • f3ca80318e621070ccee3cb24412daab9c031092ad66e04301a6350f54e88675.exe (PID: 1852)
    • Manual execution by a user

      • RegAsm.exe (PID: 5024)
      • wscript.exe (PID: 6184)
      • RegAsm.exe (PID: 5988)
    • Reads the software policy settings

      • slui.exe (PID: 5332)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:04:28 12:21:21+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 1588224
InitializedDataSize: 2560
UninitializedDataSize: -
EntryPoint: 0x185a1e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.6571.12715
ProductVersionNumber: 1.0.6571.12715
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: SWIFT COPY 471098765432USD
FileVersion: 1.0.6571.12715
InternalName: SWIFT COPY 471098765432USD.exe
LegalCopyright: Copyright © 2017
LegalTrademarks: -
OriginalFileName: SWIFT COPY 471098765432USD.exe
ProductName: SWIFT COPY 471098765432USD
ProductVersion: 1.0.6571.12715
AssemblyVersion: 1.0.8145.28418
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
137
Monitored processes
8
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start f3ca80318e621070ccee3cb24412daab9c031092ad66e04301a6350f54e88675.exe sppextcomobj.exe no specs regasm.exe no specs slui.exe wscript.exe no specs typeid.exe no specs regasm.exe no specs slui.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1852"C:\Users\admin\AppData\Local\Temp\f3ca80318e621070ccee3cb24412daab9c031092ad66e04301a6350f54e88675.exe" C:\Users\admin\AppData\Local\Temp\f3ca80318e621070ccee3cb24412daab9c031092ad66e04301a6350f54e88675.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
SWIFT COPY 471098765432USD
Exit code:
4294967295
Version:
1.0.6571.12715
Modules
Images
c:\users\admin\appdata\local\temp\f3ca80318e621070ccee3cb24412daab9c031092ad66e04301a6350f54e88675.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
5024"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Assembly Registration Utility
Exit code:
0
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regasm.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
5332"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exe
SppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5548C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5800"C:\Users\admin\AppData\Roaming\TypeId.exe" C:\Users\admin\AppData\Roaming\TypeId.exewscript.exe
User:
admin
Integrity Level:
MEDIUM
Description:
SWIFT COPY 471098765432USD
Exit code:
4294967295
Version:
1.0.6571.12715
Modules
Images
c:\users\admin\appdata\roaming\typeid.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
5968C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
5988"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET Assembly Registration Utility
Exit code:
0
Version:
4.8.9037.0 built by: NET481REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\regasm.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
6184wscript "C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TypeId.vbs"C:\Windows\System32\wscript.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.812.10240.16384
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
1 896
Read events
1 896
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
1852f3ca80318e621070ccee3cb24412daab9c031092ad66e04301a6350f54e88675.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\TypeId.vbstext
MD5:9D608CD1F64AE38186AE154430E32471
SHA256:6908DE6483DBD6A873DA9F4B4F4044FBFA3545A81CCDFA0B55EECE80BE8EE160
1852f3ca80318e621070ccee3cb24412daab9c031092ad66e04301a6350f54e88675.exeC:\Users\admin\AppData\Roaming\TypeId.exeexecutable
MD5:474A9D3A63BB9A2B0DC18E58A6E8BB52
SHA256:F3CA80318E621070CCEE3CB24412DAAB9C031092AD66E04301A6350F54E88675
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
23
DNS requests
18
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
5496
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
4980
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
4980
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
6544
svchost.exe
GET
200
2.17.190.73:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5496
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3216
svchost.exe
172.211.123.250:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
6544
svchost.exe
40.126.32.136:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6544
svchost.exe
2.17.190.73:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 20.73.194.208
  • 51.124.78.146
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.166
  • 23.48.23.176
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
google.com
  • 172.217.18.14
whitelisted
client.wns.windows.com
  • 172.211.123.250
whitelisted
login.live.com
  • 40.126.32.136
  • 20.190.160.66
  • 40.126.32.134
  • 40.126.32.138
  • 40.126.32.140
  • 40.126.32.72
  • 20.190.160.5
  • 20.190.160.4
whitelisted
ocsp.digicert.com
  • 2.17.190.73
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 13.95.31.18
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted

Threats

No threats detected
No debug info