File name:

Ratv2-byEthicalGeek.exe

Full analysis: https://app.any.run/tasks/b2428757-8f6a-4227-92d3-9c4ccc944f39
Verdict: Malicious activity
Analysis date: October 03, 2025, 16:42:22
OS: Windows 10 Professional (build: 19044, 64 bit)
Tags:
auto-reg
crypto-regex
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

B724595E676F5FC8FFADB0780B31B5BD

SHA1:

BC60985460D27BA3A5D1D30B61C64653B07BD6E5

SHA256:

FD71A400853031574FAFA0DA6E7A580C9CFFEFB4FECF50004E118AB338C40109

SSDEEP:

49152:3+ZpJywQsez93HrJGXBLi4OPLh9cy5Fbze8n4TyJOLK7JsW7MaIpVJZPh7VgOSA6:NwWHrJs24OP19cyFbLn4TyJ8K7SWYaoy

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • Ratv2-byEthicalGeek.exe (PID: 5792)
      • Client.exe (PID: 4852)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Ratv2-byEthicalGeek.exe (PID: 5792)
    • Starts itself from another location

      • Ratv2-byEthicalGeek.exe (PID: 5792)
    • Found regular expressions for crypto-addresses (YARA)

      • Client.exe (PID: 4852)
    • There is functionality for taking screenshot (YARA)

      • Client.exe (PID: 4852)
    • Connects to unusual port

      • Client.exe (PID: 4852)
  • INFO

    • Reads the computer name

      • Ratv2-byEthicalGeek.exe (PID: 5792)
      • Client.exe (PID: 4852)
      • Client.exe (PID: 6860)
    • Checks supported languages

      • Ratv2-byEthicalGeek.exe (PID: 5792)
      • Client.exe (PID: 4852)
      • Client.exe (PID: 6860)
    • Reads Environment values

      • Ratv2-byEthicalGeek.exe (PID: 5792)
      • Client.exe (PID: 4852)
      • Client.exe (PID: 6860)
    • Reads the machine GUID from the registry

      • Ratv2-byEthicalGeek.exe (PID: 5792)
      • Client.exe (PID: 4852)
      • Client.exe (PID: 6860)
    • Creates files or folders in the user directory

      • Ratv2-byEthicalGeek.exe (PID: 5792)
    • Launching a file from a Registry key

      • Ratv2-byEthicalGeek.exe (PID: 5792)
      • Client.exe (PID: 4852)
    • Manual execution by a user

      • Client.exe (PID: 6860)
    • Reads the software policy settings

      • slui.exe (PID: 3264)
    • Checks proxy server information

      • slui.exe (PID: 3264)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (56.7)
.exe | Win64 Executable (generic) (21.3)
.scr | Windows screen saver (10.1)
.dll | Win32 Dynamic Link Library (generic) (5)
.exe | Win32 Executable (generic) (3.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2046:05:27 04:02:54+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 1829376
InitializedDataSize: 3584
UninitializedDataSize: -
EntryPoint: 0x1c095e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.7.4.0
ProductVersionNumber: 1.7.4.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: -
FileVersion: 1.7.4
InternalName: Client.exe
LegalCopyright: -
LegalTrademarks: -
OriginalFileName: Client.exe
ProductName: -
ProductVersion: 1.7.4
AssemblyVersion: 1.7.4.0
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
160
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details

Process information

PID
CMD
Path
Indicators
Parent process
2428C:\WINDOWS\system32\svchost.exe -k NetworkService -p -s DnscacheC:\Windows\System32\svchost.exe
services.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\combase.dll
c:\windows\system32\kernel.appcore.dll
3264C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\user32.dll
4852"C:\Users\admin\AppData\Roaming\SubDir\Client.exe"C:\Users\admin\AppData\Roaming\SubDir\Client.exe
Ratv2-byEthicalGeek.exe
User:
admin
Integrity Level:
MEDIUM
Version:
1.7.4
Modules
Images
c:\users\admin\appdata\roaming\subdir\client.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
5792"C:\Users\admin\Desktop\Ratv2-byEthicalGeek.exe" C:\Users\admin\Desktop\Ratv2-byEthicalGeek.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3
Version:
1.7.4
Modules
Images
c:\users\admin\desktop\ratv2-byethicalgeek.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
6860"C:\Users\admin\AppData\Roaming\SubDir\Client.exe"C:\Users\admin\AppData\Roaming\SubDir\Client.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
2
Version:
1.7.4
Modules
Images
c:\users\admin\appdata\roaming\subdir\client.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
Total events
4 946
Read events
4 944
Write events
2
Delete events
0

Modification events

(PID) Process:(4852) Client.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Pulsar Client Startup
Value:
"C:\Users\admin\AppData\Roaming\SubDir\Client.exe"
(PID) Process:(5792) Ratv2-byEthicalGeek.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Pulsar Client Startup
Value:
"C:\Users\admin\AppData\Roaming\SubDir\Client.exe"
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
5792Ratv2-byEthicalGeek.exeC:\Users\admin\AppData\Roaming\SubDir\Client.exeexecutable
MD5:B724595E676F5FC8FFADB0780B31B5BD
SHA256:FD71A400853031574FAFA0DA6E7A580C9CFFEFB4FECF50004E118AB338C40109
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
20
DNS requests
9
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
POST
500
4.154.209.85:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
xml
512 b
unknown
POST
500
4.154.185.43:443
https://activation-v2.sls.microsoft.com/SLActivateProduct/SLActivateProduct.asmx?configextension=Retail
US
xml
512 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6016
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2152
RUXIMICS.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2.16.241.205:443
www.bing.com
Akamai International B.V.
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
4852
Client.exe
147.185.221.211:57499
win-mph.gl.at.ply.gg
PLAYIT-GG
US
malicious
6016
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5948
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2364
slui.exe
4.154.185.43:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
3264
slui.exe
4.154.185.43:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.124.78.146
  • 4.231.128.59
whitelisted
www.bing.com
  • 2.16.241.205
  • 2.16.241.201
  • 2.16.241.218
  • 2.16.241.207
  • 2.16.241.222
whitelisted
google.com
  • 216.58.206.46
whitelisted
win-mph.gl.at.ply.gg
  • 147.185.221.211
unknown
dns.msftncsi.com
  • 131.107.255.255
whitelisted
activation-v2.sls.microsoft.com
  • 4.154.185.43
whitelisted

Threats

PID
Process
Class
Message
2428
svchost.exe
A Network Trojan was detected
MALWARE [ANY.RUN] Suspected domain Associated with Malware Distribution (.ply .gg)
2428
svchost.exe
Potentially Bad Traffic
ET INFO playit .gg Tunneling Domain in DNS Lookup
2428
svchost.exe
Misc activity
ET TA_ABUSED_SERVICES Tunneling Service in DNS Lookup (* .ply .gg)
Unknown Traffic
ET USER_AGENTS Microsoft Dr Watson User-Agent (MSDW)
No debug info