File name: | libcurl.dll |
Full analysis: | https://app.any.run/tasks/caa68196-8f86-445c-a590-da654b39f629 |
Verdict: | Malicious activity |
Analysis date: | November 02, 2024, 10:17:12 |
OS: | Windows 10 Professional (build: 19045, 64 bit) |
Tags: | |
Indicators: | |
MIME: | application/vnd.microsoft.portable-executable |
File info: | PE32 executable (DLL) (GUI) Intel 80386, for MS Windows, 5 sections |
MD5: | D3C9064911CE5602558DB534C85BDAFC |
SHA1: | 79D09176BD6AC86346CF4968455174262A8B580D |
SHA256: | F451119A4F30B4CDA90F79F3D0199B0FFAD5103DAE9584B172A44D8BD8E18F00 |
SSDEEP: | 6144:SK49r0nOFQJ8itMxFHPvjUP9EVRxyMSEmnfV1H:JYHa8itMfvvY81Lmnfb |
.exe | | | Win64 Executable (generic) (64.6) |
---|---|---|
.dll | | | Win32 Dynamic Link Library (generic) (15.4) |
.exe | | | Win32 Executable (generic) (10.5) |
.exe | | | Generic Win/DOS Executable (4.6) |
.exe | | | DOS Executable Generic (4.6) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2024:10:31 16:35:01+00:00 |
ImageFileCharacteristics: | Executable, 32-bit, DLL |
PEType: | PE32 |
LinkerVersion: | 14.41 |
CodeSize: | 13824 |
InitializedDataSize: | 151040 |
UninitializedDataSize: | - |
EntryPoint: | 0x3a05 |
OSVersion: | 6 |
ImageVersion: | - |
SubsystemVersion: | 6 |
Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2432 | "C:\Windows\System32\rundll32.exe" C:\Users\admin\AppData\Local\Temp\libcurl.dll, #1 | C:\Windows\SysWOW64\rundll32.exe | rundll32.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 3221225477 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
4360 | "C:\WINDOWS\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe" -ServerName:CortanaUI.AppX8z9r6jm96hw4bsbneegw0kyxx296wr9t.mca | C:\Windows\SystemApps\Microsoft.Windows.Search_cw5n1h2txyewy\SearchApp.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Search application Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
4548 | C:\WINDOWS\system32\SppExtComObj.exe -Embedding | C:\Windows\System32\SppExtComObj.Exe | — | svchost.exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: KMS Connection Broker Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
5276 | C:\WINDOWS\SysWOW64\WerFault.exe -u -p 2432 -s 612 | C:\Windows\SysWOW64\WerFault.exe | rundll32.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
6112 | "C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEvent | C:\Windows\System32\slui.exe | — | SppExtComObj.Exe | |||||||||||
User: NETWORK SERVICE Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
6220 | "C:\Windows\System32\rundll32.exe" C:\Users\admin\AppData\Local\Temp\libcurl.dll, #1 | C:\Windows\System32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
|
(PID) Process: | (4360) SearchApp.exe | Key: | \REGISTRY\A\{96200786-8ea1-d57b-2177-28c9e0c39da0}\LocalState\ConstraintIndex |
Operation: | write | Name: | CurrentConstraintIndexCabPath |
Value: 43003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C005000610063006B0061006700650073005C004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E005300650061007200630068005F006300770035006E003100680032007400780079006500770079005C004C006F00630061006C00530074006100740065005C0043006F006E00730074007200610069006E00740049006E006400650078005C0049006E007000750074005F007B00380033003200620036003800640032002D0037006600650032002D0034006500370031002D0061003300610064002D003200360031003600360062003600350036006500630036007D00000040C04466102DDB01 | |||
(PID) Process: | (4360) SearchApp.exe | Key: | \REGISTRY\A\{96200786-8ea1-d57b-2177-28c9e0c39da0}\LocalState\AppsConstraintIndex |
Operation: | write | Name: | LatestConstraintIndexFolder |
Value: 43003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C005000610063006B0061006700650073005C004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E005300650061007200630068005F006300770035006E003100680032007400780079006500770079005C004C006F00630061006C00530074006100740065005C0043006F006E00730074007200610069006E00740049006E006400650078005C0041007000700073005F007B00630065003700350033006300650064002D0031006400610039002D0034003000300066002D0039006200300038002D006600310030006500300066006600320033006100320033007D00000040C04466102DDB01 | |||
(PID) Process: | (4360) SearchApp.exe | Key: | \REGISTRY\A\{96200786-8ea1-d57b-2177-28c9e0c39da0}\LocalState\AppsConstraintIndex |
Operation: | write | Name: | LastConstraintIndexBuildCompleted |
Value: D4F44566102DDB0140C04466102DDB01 | |||
(PID) Process: | (4360) SearchApp.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\Microsoft.Windows.Search_cw5n1h2txyewy\AppsConstraintIndex |
Operation: | write | Name: | CurrentConstraintIndexCabPath |
Value: C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Input_{832b68d2-7fe2-4e71-a3ad-26166b656ec6} | |||
(PID) Process: | (4360) SearchApp.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\Microsoft.Windows.Search_cw5n1h2txyewy\AppsConstraintIndex |
Operation: | write | Name: | LatestConstraintIndexFolder |
Value: C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{ce753ced-1da9-400f-9b08-f10e0ff23a23} | |||
(PID) Process: | (4360) SearchApp.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\SearchSettings |
Operation: | write | Name: | SafeSearchMode |
Value: 1 | |||
(PID) Process: | (4360) SearchApp.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Search\Microsoft.Windows.Search_cw5n1h2txyewy\AppsConstraintIndex |
Operation: | write | Name: | IndexedLanguage |
Value: en-US | |||
(PID) Process: | (4360) SearchApp.exe | Key: | \REGISTRY\A\{96200786-8ea1-d57b-2177-28c9e0c39da0}\LocalState\AppIndexer |
Operation: | write | Name: | LatestCacheFileName |
Value: 410070007000430061006300680065003100330033003700350030003100360032003300340037003000390036003100300037002E00740078007400000040C04466102DDB01 | |||
(PID) Process: | (4360) SearchApp.exe | Key: | \REGISTRY\A\{96200786-8ea1-d57b-2177-28c9e0c39da0}\LocalState\AppIndexer |
Operation: | write | Name: | InstalledWin32AppsRevision |
Value: 7B00360037003600310030003000320031002D0045003400460030002D0034003900450041002D0038003000420044002D003000440042004400340039003400440044003000350045007D00000040C04466102DDB01 | |||
(PID) Process: | (4360) SearchApp.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Feeds\DSB |
Operation: | write | Name: | DynamicText |
Value: |
PID | Process | Filename | Type | |
---|---|---|---|---|
5276 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_rundll32.exe_2ee9827d5c3281ef1bd032185e89f26811bbbd5_67c333ae_59e3019a-ffe3-467d-a89d-65a45d4ba630\Report.wer | — | |
MD5:— | SHA256:— | |||
2432 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\gup.xml | xml | |
MD5:116878A2647BCC21FA7EE6D9EBF3126C | SHA256:3A8C12E021D292232AEFBC93985316902E3901C455E88330ACEDF56C358AA951 | |||
5276 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WERB232.tmp.dmp | dmp | |
MD5:56A6510C46A2699ADAAA99C9BC5F2DDE | SHA256:2F313A47BB69BA2A7BAE652CB266E06855D81066ED8BC8B72236C337AB7F034A | |||
5276 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WERB724.tmp.WERInternalMetadata.xml | xml | |
MD5:554830B83B7FA00A1C4147F693465154 | SHA256:529F8FC31D0B4ED2AC041F2D1F5A9973A9994A2B3DF9C83AA6B7783DEE828A12 | |||
5276 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WERB783.tmp.xml | xml | |
MD5:6CA0DB126B2CD47D40BE07EABAFCC8A6 | SHA256:9D3EF2AE8B5EDFAC3A64AB9D74C0F7D8F2874B6313F779D1C3DE42B863A83CED | |||
4360 | SearchApp.exe | C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{ce753ced-1da9-400f-9b08-f10e0ff23a23}\0.1.filtertrie.intermediate.txt | text | |
MD5:34BD1DFB9F72CF4F86E6DF6DA0A9E49A | SHA256:8E1E6A3D56796A245D0C7B0849548932FEE803BBDB03F6E289495830E017F14C | |||
4360 | SearchApp.exe | C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{ce753ced-1da9-400f-9b08-f10e0ff23a23}\0.2.filtertrie.intermediate.txt | text | |
MD5:C204E9FAAF8565AD333828BEFF2D786E | SHA256:D65B6A3BF11A27A1CED1F7E98082246E40CF01289FD47FE4A5ED46C221F2F73F | |||
4360 | SearchApp.exe | C:\Users\admin\AppData\Local\Packages\Microsoft.Windows.Search_cw5n1h2txyewy\LocalState\ConstraintIndex\Apps_{ce753ced-1da9-400f-9b08-f10e0ff23a23}\Apps.ft | binary | |
MD5:AB5CF5D309581951ACE7978FF8DF0FF0 | SHA256:CA45CAA7DE38CB805EC43EDC8B9332E1E95124A27FBB6E5BD3DDD5E8A526AFC7 | |||
5276 | WerFault.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\37C951188967C8EB88D99893D9D191FE | der | |
MD5:F0CF5B1794ECA7CD73F9C020DAAB8EF2 | SHA256:2AF00EDCE7EF3266897E52DC81E8DE3B7A079028C0F1F96EAFF9E38AD342F617 | |||
5276 | WerFault.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FE | binary | |
MD5:561E87E65309A83D268ADBFF818E80CA | SHA256:D2A2674E497F94898A5DBD42187F44C2B446404B6D1DB50B01A0C6016E961E95 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
5276 | WerFault.exe | GET | 200 | 2.16.164.112:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
5276 | WerFault.exe | GET | 200 | 23.32.185.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6944 | svchost.exe | GET | 200 | 2.16.164.112:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
6944 | svchost.exe | GET | 200 | 23.32.185.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
632 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6268 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
6556 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
6556 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
6944 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
6908 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5488 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4360 | SearchApp.exe | 2.23.209.176:443 | www.bing.com | Akamai International B.V. | GB | whitelisted |
— | — | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5276 | WerFault.exe | 13.89.179.12:443 | watson.events.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
5276 | WerFault.exe | 2.16.164.112:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
5276 | WerFault.exe | 23.32.185.131:80 | www.microsoft.com | AKAMAI-AS | BR | whitelisted |
Domain | IP | Reputation |
---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
google.com |
| whitelisted |
watson.events.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
th.bing.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
— | — | Potentially Bad Traffic | ET EXPLOIT Possible OpenSSL HeartBleed Large HeartBeat Response from Common SSL Port (Outbound from Client) |