File name:

Peer2Profit.exe

Full analysis: https://app.any.run/tasks/d9210399-b676-4c27-9af2-35284bcc068a
Verdict: Malicious activity
Analysis date: March 21, 2024, 19:33:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

5913271D8870CE286D833B737620B0D5

SHA1:

8A6D2B2AD00ABD1764D55EB0E52ED34A3407D883

SHA256:

009145139CE9BDF30F8552A3D635CFEBFFFF402708C6689B45189C4FE788C9D9

SSDEEP:

98304:REaS6p+ce5FAtcNF2kujLkPhJLLIA6WHvCw8VJ8G0lbj2NH1EfOhJaXTrkS+eOmt:EijsWG/hzMYtj

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Peer2Profit.exe (PID: 3500)
    • Changes the autorun value in the registry

      • Peer2Profit.exe (PID: 3936)
  • SUSPICIOUS

    • Application launched itself

      • Peer2Profit.exe (PID: 3500)
    • Reads settings of System Certificates

      • Peer2Profit.exe (PID: 3936)
    • Reads the Internet Settings

      • Peer2Profit.exe (PID: 3936)
    • Starts application with an unusual extension

      • cmd.exe (PID: 3180)
    • Starts CMD.EXE for commands execution

      • Peer2Profit.exe (PID: 3936)
    • Process uses IPCONFIG to discover network configuration

      • cmd.exe (PID: 3180)
    • Uses NSLOOKUP.EXE to check DNS info

      • cmd.exe (PID: 3180)
    • Uses ROUTE.EXE to obtain the routing table information

      • cmd.exe (PID: 3180)
  • INFO

    • Checks supported languages

      • Peer2Profit.exe (PID: 3500)
      • Peer2Profit.exe (PID: 3936)
      • chcp.com (PID: 2256)
      • chcp.com (PID: 1560)
      • chcp.com (PID: 796)
      • chcp.com (PID: 1644)
      • chcp.com (PID: 1576)
    • Process checks computer location settings

      • Peer2Profit.exe (PID: 3500)
      • Peer2Profit.exe (PID: 3936)
    • Reads the time zone

      • Peer2Profit.exe (PID: 3500)
      • Peer2Profit.exe (PID: 3936)
    • Create files in a temporary directory

      • Peer2Profit.exe (PID: 3500)
      • Peer2Profit.exe (PID: 3936)
    • Reads the computer name

      • Peer2Profit.exe (PID: 3936)
    • Reads the machine GUID from the registry

      • Peer2Profit.exe (PID: 3936)
    • Creates files or folders in the user directory

      • Peer2Profit.exe (PID: 3936)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 EXE PECompact compressed (generic) (83)
.exe | Win32 Executable (generic) (9)
.exe | Generic Win/DOS Executable (3.9)
.exe | DOS Executable Generic (3.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:12:26 18:09:27+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 8219648
InitializedDataSize: 8312832
UninitializedDataSize: -
EntryPoint: 0x762cbe
OSVersion: 6
ImageVersion: 0.35
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 0.35.0.0
ProductVersionNumber: 0.35.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: -
FileDescription: -
FileVersion: 0.35.0.0
LegalCopyright: -
OriginalFileName: Peer2Profit.exe
ProductName: Peer2Profit
ProductVersion: 0.35.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
52
Monitored processes
13
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start peer2profit.exe no specs peer2profit.exe cmd.exe no specs chcp.com no specs ping.exe no specs chcp.com no specs ping.exe no specs chcp.com no specs ipconfig.exe no specs chcp.com no specs nslookup.exe chcp.com no specs route.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
796chcp 65001 C:\Windows\System32\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Change CodePage Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\chcp.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1560chcp 65001 C:\Windows\System32\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Change CodePage Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\chcp.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1576chcp 65001 C:\Windows\System32\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Change CodePage Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\chcp.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1644chcp 65001 C:\Windows\System32\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Change CodePage Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\chcp.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1740ping -n 2 api.peer2profit.global C:\Windows\System32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ping.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
1808route PRINTC:\Windows\System32\ROUTE.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Route Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\route.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
1992ipconfig /all C:\Windows\System32\ipconfig.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
IP Configuration Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ipconfig.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
2256chcp 65001 C:\Windows\System32\chcp.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Change CodePage Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\chcp.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2688ping -n 2 check.peer2profit.site C:\Windows\System32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ping.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
2904nslookup check.peer2profit.site C:\Windows\System32\nslookup.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
nslookup
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\nslookup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
Total events
5 595
Read events
5 593
Write events
2
Delete events
0

Modification events

(PID) Process:(3936) Peer2Profit.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Peer2Profit.exe
(PID) Process:(3936) Peer2Profit.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Peer2Profit
Value:
"C:\Users\admin\AppData\Local\Temp\Peer2Profit.exe" --minimized
Executable files
0
Suspicious files
3
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
3936Peer2Profit.exeC:\Users\admin\AppData\Local\Peer2Profit\Peer2Profit\org.peer2profit.peer2profit.ini.lkKruatext
MD5:FF473BAEB6C196B509CC7F283C59EC1A
SHA256:57543D55E2799F10AED06DD3D7011B0BD35F03665FAFCCF749D09FD8F3BD3CBF
3936Peer2Profit.exeC:\Users\admin\AppData\Local\Peer2Profit\Peer2Profit\org.peer2profit.peer2profit.ini.ghjkeztext
MD5:D9243997269B354BB256D0A606E4C75E
SHA256:0972AC1F7EEBFA75829BB96D7A27B37EEB14E7A6E73138AFBA5A181CD89A0B2D
3936Peer2Profit.exeC:\Users\admin\AppData\Local\Temp\Peer2Profit.SnvNEi.zip.00191052compressed
MD5:CBA9E72419A139A808A964B287D61664
SHA256:EFAFF7704AFFFCFC7843CF3581A38303F63EF8539B969898302E124C99D89AF5
3936Peer2Profit.exeC:\Users\admin\Desktop\peer2profit-support-2024-03-21T19-35-00Z.zipcompressed
MD5:CBA9E72419A139A808A964B287D61664
SHA256:EFAFF7704AFFFCFC7843CF3581A38303F63EF8539B969898302E124C99D89AF5
3936Peer2Profit.exeC:\Users\admin\AppData\Local\Temp\Peer2Profit-mONQAs\info.txttext
MD5:AE8AD1B4361DCA09B777F9F907FD82B8
SHA256:B6471DD8AE56C2E64F7B74DD061960E95E0011505DEDA638E999F7547E639BD9
3936Peer2Profit.exeC:\Users\admin\AppData\Local\Temp\Peer2Profit-mONQAs\logs.txttext
MD5:4785963C5CBCC8C19BFB43A6B0236B42
SHA256:F8D6EC716D30165CC4E9F3957CE0364B11F68D5EDBDB476886A7700AF1D90C5F
3936Peer2Profit.exeC:\Users\admin\AppData\Local\Temp\Peer2Profit.SnvNEi.zipcompressed
MD5:CBA9E72419A139A808A964B287D61664
SHA256:EFAFF7704AFFFCFC7843CF3581A38303F63EF8539B969898302E124C99D89AF5
3936Peer2Profit.exeC:\Users\admin\AppData\Local\Temp\Peer2Profit-mONQAs\report.txttext
MD5:58C6EBDA0EE0B681129343530FFC73C1
SHA256:B326389D9DE36AA4C391B9CB6EB22D69B830AF3305959B88F614466F3C5A1D50
3936Peer2Profit.exeC:\Users\admin\AppData\Local\Peer2Profit\Peer2Profit\org.peer2profit.peer2profit.ini.locktext
MD5:59B8B65E7D3CE269A2E9C57C9289256C
SHA256:A97B362493774E1FE93B153166388927FEFDE2FB925371C029FEA0BCDCACFAE8
3936Peer2Profit.exeC:\Users\admin\AppData\Local\Peer2Profit\Peer2Profit\org.peer2profit.peer2profit.initext
MD5:FF473BAEB6C196B509CC7F283C59EC1A
SHA256:57543D55E2799F10AED06DD3D7011B0BD35F03665FAFCCF749D09FD8F3BD3CBF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
11
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
488
lsass.exe
GET
304
2.19.126.163:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?58113e117cf2b140
unknown
unknown
488
lsass.exe
GET
200
2.19.126.163:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?e6619d226d977d1b
unknown
compressed
67.5 Kb
unknown
488
lsass.exe
GET
200
2.19.245.44:80
http://x1.c.lencr.org/
unknown
binary
717 b
unknown
488
lsass.exe
GET
200
2.19.245.44:80
http://x2.c.lencr.org/
unknown
binary
299 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3936
Peer2Profit.exe
188.114.97.3:443
api.peer2profit.global
CLOUDFLARENET
NL
unknown
3936
Peer2Profit.exe
188.114.96.3:443
api.peer2profit.global
CLOUDFLARENET
NL
unknown
488
lsass.exe
2.19.126.163:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
488
lsass.exe
2.19.245.44:80
x1.c.lencr.org
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
api.peer2profit.global
  • 188.114.97.3
  • 188.114.96.3
malicious
ctldl.windowsupdate.com
  • 2.19.126.163
  • 2.19.126.137
whitelisted
x1.c.lencr.org
  • 2.19.245.44
whitelisted
x2.c.lencr.org
  • 2.19.245.44
whitelisted
check.peer2profit.site
  • 188.114.97.3
  • 188.114.96.3
  • 2a06:98c1:3121::3
  • 2a06:98c1:3120::3
unknown
2.100.168.192.in-addr.arpa
unknown

Threats

No threats detected
No debug info