File name:

Hrkill-SilverFox.exe

Full analysis: https://app.any.run/tasks/d101ca98-9fca-427c-ac9f-8ef39790f5bf
Verdict: Malicious activity
Analysis date: June 19, 2025, 12:48:24
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
upx
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections
MD5:

FF64DA1EE176AD63E6E479150B49C1DD

SHA1:

2186E1CFDAAA5F07F0124E973114201F48345807

SHA256:

FA303366CF1BB91AED33EBC07E5594D68FC0177ADEF55CFEEE200FEB77FF920B

SSDEEP:

98304:o4JJYpdCZq1D9qxZe3hmarV+hl6SoMhsWpTkpdX94exQJfDFsShEHBvFJjFL5Eow:zOSt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts application with an unusual extension

      • Hrkill-SilverFox.exe (PID: 1156)
    • Executable content was dropped or overwritten

      • Hrkill-SilverFox.exe (PID: 1156)
    • Creates files in the driver directory

      • Hrkill-SilverFox.exe (PID: 1156)
    • Creates or modifies Windows services

      • Hrkill-SilverFox.exe (PID: 1156)
    • Drops a system driver (possible attempt to evade defenses)

      • Hrkill-SilverFox.exe (PID: 1156)
  • INFO

    • Reads the computer name

      • Hrkill-SilverFox.exe (PID: 1156)
      • 5DFE.tmp (PID: 5168)
      • 5E2E.tmp (PID: 2032)
    • Checks supported languages

      • 5DFE.tmp (PID: 5168)
      • 5E2E.tmp (PID: 2032)
      • Hrkill-SilverFox.exe (PID: 1156)
    • Create files in a temporary directory

      • Hrkill-SilverFox.exe (PID: 1156)
    • UPX packer has been detected

      • Hrkill-SilverFox.exe (PID: 1156)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (43.5)
.exe | Win32 EXE Yoda's Crypter (42.7)
.exe | Win32 Executable (generic) (7.2)
.exe | Generic Win/DOS Executable (3.2)
.exe | DOS Executable Generic (3.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:04:03 07:55:28+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 1937408
InitializedDataSize: 49152
UninitializedDataSize: 3530752
EntryPoint: 0x537210
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2025.4.3.1
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Unknown (0009)
CharacterSet: Unicode
CompanyName: Huorong Security
FileDescription: 火绒银狐木马专杀工具
FileVersion: 2025.04.03.v1
InternalName: HRKill
LegalCopyright: Huorong Security
OriginalFileName: HRKill.exe
ProductName: Huorong Internet Security
ProductVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start hrkill-silverfox.exe 5dfe.tmp no specs 5e2e.tmp no specs slui.exe no specs hrkill-silverfox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1156"C:\Users\admin\AppData\Local\Temp\Hrkill-SilverFox.exe" C:\Users\admin\AppData\Local\Temp\Hrkill-SilverFox.exe
explorer.exe
User:
admin
Company:
Huorong Security
Integrity Level:
HIGH
Description:
火绒银狐木马专杀工具
Exit code:
0
Version:
2025.04.03.v1
Modules
Images
c:\users\admin\appdata\local\temp\hrkill-silverfox.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2032"C:\Users\admin\AppData\Local\Temp\5E2E.tmp" 656C:\Users\admin\AppData\Local\Temp\5E2E.tmpHrkill-SilverFox.exe
User:
admin
Company:
Huorong Security
Integrity Level:
HIGH
Description:
Huorong Internet Security (Uext)
Exit code:
8
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\5e2e.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
3504C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5168"C:\Users\admin\AppData\Local\Temp\5DFE.tmp" 636C:\Users\admin\AppData\Local\Temp\5DFE.tmpHrkill-SilverFox.exe
User:
admin
Company:
Huorong Security
Integrity Level:
HIGH
Description:
Huorong Internet Security (Uext)
Exit code:
4294967282
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\5dfe.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
6892"C:\Users\admin\AppData\Local\Temp\Hrkill-SilverFox.exe" C:\Users\admin\AppData\Local\Temp\Hrkill-SilverFox.exeexplorer.exe
User:
admin
Company:
Huorong Security
Integrity Level:
MEDIUM
Description:
火绒银狐木马专杀工具
Exit code:
3221226540
Version:
2025.04.03.v1
Modules
Images
c:\users\admin\appdata\local\temp\hrkill-silverfox.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
292
Read events
276
Write events
13
Delete events
3

Modification events

(PID) Process:(1156) Hrkill-SilverFox.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\v6s0FsmW_iO
Operation:writeName:DebugLevel
Value:
1
(PID) Process:(1156) Hrkill-SilverFox.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\v6s0FsmW_iO
Operation:writeName:DependOnService
Value:
FltMgr
(PID) Process:(1156) Hrkill-SilverFox.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\v6s0FsmW_iO
Operation:writeName:ErrorControl
Value:
1
(PID) Process:(1156) Hrkill-SilverFox.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\v6s0FsmW_iO
Operation:writeName:Start
Value:
3
(PID) Process:(1156) Hrkill-SilverFox.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\v6s0FsmW_iO
Operation:writeName:Type
Value:
1
(PID) Process:(1156) Hrkill-SilverFox.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\v6s0FsmW_iO
Operation:writeName:Tag
Value:
2
(PID) Process:(1156) Hrkill-SilverFox.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\v6s0FsmW_iO
Operation:writeName:Group
Value:
PNP_TDI
(PID) Process:(1156) Hrkill-SilverFox.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\v6s0FsmW_iO
Operation:writeName:ImagePath
Value:
system32\DRIVERS\v6s0FsmW_iO.sys
(PID) Process:(1156) Hrkill-SilverFox.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\v6s0FsmW_iO
Operation:writeName:DisplayName
Value:
Huorong Internet Security (Kext)
(PID) Process:(1156) Hrkill-SilverFox.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Services\v6s0FsmW_iO
Operation:writeName:Description
Value:
Huorong Internet Security (Kext)
Executable files
3
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1156Hrkill-SilverFox.exeC:\Users\admin\AppData\Local\Temp\5DFE.tmpexecutable
MD5:07EAE3A729C09CA682C943DEAD65663F
SHA256:2F416F84B6A00C106397D62CCAF0A29B8A5A2F8B4FF616BEF432237724199164
1156Hrkill-SilverFox.exeC:\Windows\System32\drivers\v6s0FsmW_iO.sysexecutable
MD5:BDABB7EE1C3213D2E2109DFF3A1AE1B5
SHA256:B388E0914FDA1D69CEE7B3FFBB218B792D1AAA13C2BD9AE9F9AF7E8E36EB1434
1156Hrkill-SilverFox.exeC:\Users\admin\AppData\Local\Temp\5E2E.tmpexecutable
MD5:07EAE3A729C09CA682C943DEAD65663F
SHA256:2F416F84B6A00C106397D62CCAF0A29B8A5A2F8B4FF616BEF432237724199164
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
23
DNS requests
15
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1268
svchost.exe
GET
200
23.55.104.172:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
US
binary
825 b
whitelisted
1268
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
868 b
whitelisted
1200
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
DE
binary
471 b
whitelisted
4460
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
NL
binary
420 b
whitelisted
4460
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
NL
binary
408 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
5944
MoUsoCoreWorker.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4456
RUXIMICS.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
1268
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1268
svchost.exe
23.55.104.172:80
crl.microsoft.com
Akamai International B.V.
US
whitelisted
2336
svchost.exe
172.211.123.248:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
FR
whitelisted
1268
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
1200
svchost.exe
20.190.160.3:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 216.58.212.142
whitelisted
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
crl.microsoft.com
  • 23.55.104.172
  • 23.55.104.190
whitelisted
client.wns.windows.com
  • 172.211.123.248
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
login.live.com
  • 20.190.160.3
  • 40.126.32.134
  • 20.190.160.65
  • 20.190.160.130
  • 20.190.160.14
  • 40.126.32.74
  • 20.190.160.128
  • 40.126.32.136
whitelisted
ocsp.digicert.com
  • 2.23.77.188
whitelisted
nexusrules.officeapps.live.com
  • 52.111.243.29
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted

Threats

No threats detected
No debug info