File name:

tabservicepack.exe

Full analysis: https://app.any.run/tasks/3d33f6b2-6262-4d84-bcc4-c93dd6c12e62
Verdict: Malicious activity
Threats:

Stealers are a group of malicious software that are intended for gaining unauthorized access to users’ information and transferring it to the attacker. The stealer malware category includes various types of programs that focus on their particular kind of data, including files, passwords, and cryptocurrency. Stealers are capable of spying on their targets by recording their keystrokes and taking screenshots. This type of malware is primarily distributed as part of phishing campaigns.

Analysis date: March 24, 2025, 05:06:56
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
stealer
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

ECC8CE5151A5794698CE70F0DB078CFE

SHA1:

7AD06EBAB05B325DB8AFA2D0DB55F2CB43803BC9

SHA256:

FA96D252A92A3216578C662CFB6A19A763324F207C209C9327FDEC6F8A16BB8A

SSDEEP:

12288:u/hYmzDK8/Glxgsuwl2Vfq+pxXmjojKpnza2JGbhN5giC/vmxmEBGJCXdTLpEeLU:AhYSf13WjojUiNKimLgdTeeLU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • tabservicepack.exe (PID: 6620)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • tabservicepack.exe (PID: 6620)
  • INFO

    • Reads the machine GUID from the registry

      • tabservicepack.exe (PID: 6620)
    • Reads the software policy settings

      • tabservicepack.exe (PID: 6620)
      • BackgroundTransferHost.exe (PID: 7672)
    • Reads the computer name

      • tabservicepack.exe (PID: 6620)
    • Checks supported languages

      • tabservicepack.exe (PID: 6620)
    • Disables trace logs

      • tabservicepack.exe (PID: 6620)
    • Checks proxy server information

      • tabservicepack.exe (PID: 6620)
      • BackgroundTransferHost.exe (PID: 7672)
    • Create files in a temporary directory

      • tabservicepack.exe (PID: 6620)
    • Reads security settings of Internet Explorer

      • BackgroundTransferHost.exe (PID: 7672)
      • BackgroundTransferHost.exe (PID: 7448)
      • BackgroundTransferHost.exe (PID: 7836)
      • BackgroundTransferHost.exe (PID: 7244)
      • BackgroundTransferHost.exe (PID: 8052)
    • Creates files or folders in the user directory

      • BackgroundTransferHost.exe (PID: 7672)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2025:01:23 09:23:52+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 1209344
InitializedDataSize: 203776
UninitializedDataSize: -
EntryPoint: 0x12924e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.1
ProductVersionNumber: 1.0.0.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: tabservicepack
FileVersion: 1.0.0.1
InternalName: tabservicepack.exe
LegalCopyright: Copyright © 2024
LegalTrademarks: -
OriginalFileName: tabservicepack.exe
ProductName: tabservicepack
ProductVersion: 1.0.0.1
AssemblyVersion: 1.0.0.1
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
144
Monitored processes
9
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start tabservicepack.exe sppextcomobj.exe no specs slui.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs backgroundtransferhost.exe no specs tabservicepack.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
4980"C:\WINDOWS\System32\SLUI.exe" RuleId=3482d82e-ca2c-4e1f-8864-da0267b484b2;Action=AutoActivate;AppId=55c92734-d682-4d71-983e-d6ec3f16059f;SkuId=4de7cb65-cdf1-4de9-8ae8-e3cce27b9f2c;NotificationInterval=1440;Trigger=TimerEventC:\Windows\System32\slui.exeSppExtComObj.Exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Activation Client
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
5156"C:\Users\admin\AppData\Local\Temp\tabservicepack.exe" C:\Users\admin\AppData\Local\Temp\tabservicepack.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
tabservicepack
Exit code:
3221226540
Version:
1.0.0.1
Modules
Images
c:\users\admin\appdata\local\temp\tabservicepack.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
5512C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\sppextcomobj.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\oleaut32.dll
6620"C:\Users\admin\AppData\Local\Temp\tabservicepack.exe" C:\Users\admin\AppData\Local\Temp\tabservicepack.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
tabservicepack
Version:
1.0.0.1
Modules
Images
c:\users\admin\appdata\local\temp\tabservicepack.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
7244"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
7448"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
7672"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
7836"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
8052"BackgroundTransferHost.exe" -ServerName:BackgroundTransferHost.1C:\Windows\System32\BackgroundTransferHost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Download/Upload Host
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\backgroundtransferhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\kernel.appcore.dll
c:\windows\system32\bcryptprimitives.dll
Total events
4 815
Read events
4 754
Write events
61
Delete events
0

Modification events

(PID) Process:(6620) tabservicepack.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\tabservicepack_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6620) tabservicepack.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\tabservicepack_RASAPI32
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6620) tabservicepack.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\tabservicepack_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(6620) tabservicepack.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\tabservicepack_RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(6620) tabservicepack.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\tabservicepack_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(6620) tabservicepack.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\tabservicepack_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(6620) tabservicepack.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\tabservicepack_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(6620) tabservicepack.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\tabservicepack_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(6620) tabservicepack.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\tabservicepack_RASMANCS
Operation:writeName:EnableAutoFileTracing
Value:
0
(PID) Process:(6620) tabservicepack.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Tracing\tabservicepack_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
Executable files
0
Suspicious files
4
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
7672BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\Content\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10D
MD5:
SHA256:
7672BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\23ce22bf-ef38-4ef8-bd43-95c979f184ad.down_data
MD5:
SHA256:
6620tabservicepack.exeC:\Users\admin\AppData\Local\Temp\ad_config.xmlxml
MD5:C3521C1DFF4EB02F6D704D9B254D0E9A
SHA256:AB94818EA29FB141188843BB835236956A3CE090222F8AD79D57BB7A7EE592E4
6620tabservicepack.exeC:\Users\admin\AppData\Local\Temp\ad_shortcutbookmark.xmlxml
MD5:896E8B51B03D7A550AF0EC88CCDA4DA8
SHA256:AD279241ED936F3376869FCCD578CE2566A286E3E77E77910F1EC6D27262EA73
7672BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\8afb7a67-61e0-4735-8554-755714cdbbd1.up_meta_securebinary
MD5:028EF166280ECCB060CC5C61353A321D
SHA256:6593868977BC8C4AFE27046F8049097C4205615961EF974E2155808D0F761324
7672BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\Microsoft\CryptnetUrlCache\MetaData\26C212D9399727259664BDFCA073966E_F9F7D6A7ECE73106D2A8C63168CDA10Dbinary
MD5:88E11DBA54A5C8E795CC8376745EFDE7
SHA256:42961783C697CDD3CE0B19EB9EE365F95BDB2BE83192D2F90147560DD91BEF8F
7672BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\23ce22bf-ef38-4ef8-bd43-95c979f184ad.2a93c0d7-c389-4d90-8d4f-1a981f05b2c1.down_metabinary
MD5:6ADB640D8FA5DDFE7CC020BB1EFC185C
SHA256:338BB9C78F9903F28181AA3C8C14945BF083F4E7E0DE2BD0AD96A0383BF33D88
7672BackgroundTransferHost.exeC:\Users\admin\AppData\Local\Packages\Microsoft.Windows.ContentDeliveryManager_cw5n1h2txyewy\AC\BackgroundTransferApi\8afb7a67-61e0-4735-8554-755714cdbbd1.2a93c0d7-c389-4d90-8d4f-1a981f05b2c1.down_metabinary
MD5:6ADB640D8FA5DDFE7CC020BB1EFC185C
SHA256:338BB9C78F9903F28181AA3C8C14945BF083F4E7E0DE2BD0AD96A0383BF33D88
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
9
TCP/UDP connections
34
DNS requests
21
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5496
MoUsoCoreWorker.exe
GET
200
23.216.77.23:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
DE
binary
825 b
unknown
6544
svchost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
471 b
unknown
6620
tabservicepack.exe
GET
200
184.24.77.4:80
http://www.msftncsi.com/ncsi.txt
DE
text
14 b
unknown
GET
200
184.24.77.4:80
http://www.msftncsi.com/ncsi.txt
DE
text
14 b
unknown
6768
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
US
binary
471 b
unknown
7672
BackgroundTransferHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
313 b
unknown
7508
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
DE
binary
419 b
unknown
7508
SIHClient.exe
GET
200
2.23.181.156:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
DE
binary
407 b
unknown
2984
backgroundTaskHost.exe
GET
200
184.30.131.245:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
US
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2104
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
192.168.100.255:137
unknown
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
5496
MoUsoCoreWorker.exe
23.216.77.23:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
4
System
192.168.100.255:138
unknown
6620
tabservicepack.exe
119.192.233.34:443
update.searchalgorithm.co.kr
Korea Telecom
KR
unknown
3216
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
6544
svchost.exe
40.126.31.2:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
6544
svchost.exe
184.30.131.245:80
ocsp.digicert.com
AKAMAI-AS
US
unknown
2112
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.124.78.146
  • 20.73.194.208
unknown
google.com
  • 142.250.184.238
unknown
crl.microsoft.com
  • 23.216.77.23
  • 23.216.77.21
unknown
update.searchalgorithm.co.kr
  • 119.192.233.34
unknown
client.wns.windows.com
  • 40.115.3.253
unknown
login.live.com
  • 40.126.31.2
  • 20.190.159.71
  • 20.190.159.73
  • 40.126.31.1
  • 20.190.159.129
  • 40.126.31.73
  • 40.126.31.67
  • 40.126.31.130
unknown
ocsp.digicert.com
  • 184.30.131.245
unknown
www.msftncsi.com
  • 184.24.77.4
  • 184.24.77.24
unknown
ad.searchalgorithm.co.kr
  • 119.192.233.34
unknown
arc.msn.com
  • 20.31.169.57
unknown

Threats

No threats detected
No debug info