File name:

SolarWinds-TFTP-Server.exe

Full analysis: https://app.any.run/tasks/2d0babc3-e00e-4025-8a82-a806fe3f89af
Verdict: Malicious activity
Analysis date: January 04, 2022, 13:55:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

D3F5303D03DEED3F5DD9F9C1D742DB20

SHA1:

9638E750B03F4B16502627DC994A1C3CF9A9F97B

SHA256:

061DD4D26B49EB6AC682ED78EE0A5D2CA1F2A183B27838CA2E8EE7F881F731FE

SSDEEP:

98304:efGAyzsK+ML1y8caRarfbcx95a5KkxmzI5b:efGfz+izMbcx92KkgzQ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • SolarWinds-TFTP-Server.exe (PID: 3424)
    • Registers / Runs the DLL via REGSVR32.EXE

      • SolarWinds-TFTP-Server.exe (PID: 3424)
    • Loads dropped or rewritten executable

      • SolarWinds-TFTP-Server.exe (PID: 3424)
      • GLJE9C8.tmp (PID: 3148)
      • GLJE9C8.tmp (PID: 3000)
      • GLJE9C8.tmp (PID: 3408)
      • GLJE9C8.tmp (PID: 3860)
      • INSTAL~1.EXE (PID: 3340)
      • TFTP-S~1.EXE (PID: 3640)
      • GLJE9C8.tmp (PID: 3492)
    • Application was dropped or rewritten from another process

      • GLJE9C8.tmp (PID: 2704)
      • GLJE9C8.tmp (PID: 2380)
      • GLJE9C8.tmp (PID: 2468)
      • GLJE9C8.tmp (PID: 4056)
      • GLJE9C8.tmp (PID: 2764)
      • GLJE9C8.tmp (PID: 3148)
      • GLJE9C8.tmp (PID: 600)
      • GLJE9C8.tmp (PID: 3000)
      • GLJE9C8.tmp (PID: 3852)
      • SOLARW~1.EXE (PID: 3448)
      • SOLARW~2.EXE (PID: 3940)
      • GLJE9C8.tmp (PID: 2648)
      • GLJE9C8.tmp (PID: 3408)
      • TFTP-S~1.EXE (PID: 3364)
      • GLJE9C8.tmp (PID: 1404)
      • GLJE9C8.tmp (PID: 3172)
      • GLJE9C8.tmp (PID: 3492)
      • TFTP-S~1.EXE (PID: 3640)
      • SOLARW~1.EXE (PID: 956)
      • INSTAL~1.EXE (PID: 3340)
      • GLJE9C8.tmp (PID: 3860)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • SolarWinds-TFTP-Server.exe (PID: 3424)
    • Checks supported languages

      • SolarWinds-TFTP-Server.exe (PID: 3424)
      • GLJE9C8.tmp (PID: 2704)
      • GLJE9C8.tmp (PID: 2380)
      • GLJE9C8.tmp (PID: 2764)
      • GLJE9C8.tmp (PID: 2468)
      • GLJE9C8.tmp (PID: 4056)
      • GLJE9C8.tmp (PID: 3148)
      • GLJE9C8.tmp (PID: 600)
      • GLJE9C8.tmp (PID: 3860)
      • GLJE9C8.tmp (PID: 3852)
      • GLJE9C8.tmp (PID: 2648)
      • SOLARW~1.EXE (PID: 3448)
      • SOLARW~2.EXE (PID: 3940)
      • GLJE9C8.tmp (PID: 3000)
      • TFTP-S~1.EXE (PID: 3364)
      • GLJE9C8.tmp (PID: 3408)
      • GLJE9C8.tmp (PID: 3172)
      • GLJE9C8.tmp (PID: 1404)
      • GLJE9C8.tmp (PID: 3492)
      • SOLARW~1.EXE (PID: 956)
      • TFTP-S~1.EXE (PID: 3640)
      • INSTAL~1.EXE (PID: 3340)
    • Reads the computer name

      • SolarWinds-TFTP-Server.exe (PID: 3424)
      • GLJE9C8.tmp (PID: 2764)
      • GLJE9C8.tmp (PID: 3148)
      • GLJE9C8.tmp (PID: 3000)
      • GLJE9C8.tmp (PID: 3860)
      • GLJE9C8.tmp (PID: 3852)
      • GLJE9C8.tmp (PID: 600)
      • SOLARW~1.EXE (PID: 3448)
      • SOLARW~2.EXE (PID: 3940)
      • TFTP-S~1.EXE (PID: 3364)
      • GLJE9C8.tmp (PID: 3172)
      • GLJE9C8.tmp (PID: 3492)
      • SOLARW~1.EXE (PID: 956)
      • TFTP-S~1.EXE (PID: 3640)
      • INSTAL~1.EXE (PID: 3340)
    • Creates files in the Windows directory

      • SolarWinds-TFTP-Server.exe (PID: 3424)
    • Creates a directory in Program Files

      • SolarWinds-TFTP-Server.exe (PID: 3424)
    • Removes files from Windows directory

      • SolarWinds-TFTP-Server.exe (PID: 3424)
    • Drops a file that was compiled in debug mode

      • SolarWinds-TFTP-Server.exe (PID: 3424)
    • Drops a file with a compile date too recent

      • SolarWinds-TFTP-Server.exe (PID: 3424)
    • Creates a software uninstall entry

      • SolarWinds-TFTP-Server.exe (PID: 3424)
    • Creates files in the program directory

      • SolarWinds-TFTP-Server.exe (PID: 3424)
    • Starts application with an unusual extension

      • SolarWinds-TFTP-Server.exe (PID: 3424)
    • Reads mouse settings

      • GLJE9C8.tmp (PID: 2764)
      • TFTP-S~1.EXE (PID: 3640)
    • Drops a file with too old compile date

      • SolarWinds-TFTP-Server.exe (PID: 3424)
    • Creates/Modifies COM task schedule object

      • GLJE9C8.tmp (PID: 600)
    • Reads Windows owner or organization settings

      • INSTAL~1.EXE (PID: 3340)
    • Executed via COM

      • SOLARW~1.EXE (PID: 956)
    • Reads the Windows organization settings

      • INSTAL~1.EXE (PID: 3340)
  • INFO

    • Checks supported languages

      • regsvr32.exe (PID: 1548)
    • Dropped object may contain Bitcoin addresses

      • SolarWinds-TFTP-Server.exe (PID: 3424)
    • Reads Microsoft Office registry keys

      • TFTP-S~1.EXE (PID: 3640)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Wise Installer executable (96.9)
.dll | Win32 Dynamic Link Library (generic) (1.3)
.exe | Win32 Executable (generic) (0.9)
.exe | Generic Win/DOS Executable (0.4)
.exe | DOS Executable Generic (0.4)

EXIF

EXE

LegalCopyright: Copyright © 1995-2000 SolarWinds.Net
FileVersion: 09-03-2000
FileDescription: SolarWinds TFTP Server
CompanyName: SolarWinds.Net
CharacterSet: Windows, Latin1
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Windows 16-bit
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 9.4455.0.0
FileVersionNumber: 9.4455.0.0
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: 4
OSVersion: 4
EntryPoint: 0x21af
UninitializedDataSize: -
InitializedDataSize: 5632
CodeSize: 8704
LinkerVersion: 6
PEType: PE32
TimeStamp: 2000:04:25 16:37:12+02:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
24
Malicious processes
22
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start start solarwinds-tftp-server.exe regsvr32.exe no specs glje9c8.tmp no specs glje9c8.tmp no specs glje9c8.tmp no specs glje9c8.tmp no specs glje9c8.tmp no specs glje9c8.tmp no specs glje9c8.tmp no specs solarw~1.exe no specs solarw~2.exe no specs glje9c8.tmp no specs glje9c8.tmp no specs glje9c8.tmp no specs glje9c8.tmp no specs glje9c8.tmp no specs glje9c8.tmp no specs tftp-s~1.exe no specs glje9c8.tmp no specs glje9c8.tmp no specs instal~1.exe no specs solarw~1.exe no specs tftp-s~1.exe no specs solarwinds-tftp-server.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
600"C:\Users\admin\AppData\Local\Temp\GLJE9C8.tmp" C:\Program Files\SolarWinds\2001 Standard Edition\Author.dllC:\Users\admin\AppData\Local\Temp\GLJE9C8.tmpSolarWinds-TFTP-Server.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\glje9c8.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
956C:\Windows\System32\SOLARW~1.EXE -EmbeddingC:\Windows\System32\SOLARW~1.EXEsvchost.exe
User:
admin
Company:
SolarWinds.Net
Integrity Level:
HIGH
Description:
SolarWinds 2001 Network Interface
Exit code:
0
Version:
4.01.0028
Modules
Images
c:\windows\system32\solarwinds2001.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1404"C:\Users\admin\AppData\Local\Temp\SolarWinds-TFTP-Server.exe" C:\Users\admin\AppData\Local\Temp\SolarWinds-TFTP-Server.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\solarwinds-tftp-server.exe
c:\windows\system32\ntdll.dll
1404"C:\Users\admin\AppData\Local\Temp\GLJE9C8.tmp" C:\Windows\System32\DNSv50.ocxC:\Users\admin\AppData\Local\Temp\GLJE9C8.tmpSolarWinds-TFTP-Server.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\glje9c8.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
1548"C:\Windows\System32\regsvr32.exe" /s comcat.dllC:\Windows\System32\regsvr32.exeSolarWinds-TFTP-Server.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2380"C:\Users\admin\AppData\Local\Temp\GLJE9C8.tmp" C:\Windows\System32\olepro32.dllC:\Users\admin\AppData\Local\Temp\GLJE9C8.tmpSolarWinds-TFTP-Server.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\glje9c8.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
2468"C:\Users\admin\AppData\Local\Temp\GLJE9C8.tmp" C:\Windows\System32\msvbvm60.dllC:\Users\admin\AppData\Local\Temp\GLJE9C8.tmpSolarWinds-TFTP-Server.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\glje9c8.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
2648"C:\Users\admin\AppData\Local\Temp\GLJE9C8.tmp" C:\Windows\System32\mfc42.dllC:\Users\admin\AppData\Local\Temp\GLJE9C8.tmpSolarWinds-TFTP-Server.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\glje9c8.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
2704"C:\Users\admin\AppData\Local\Temp\GLJE9C8.tmp" C:\Windows\System32\oleaut32.dllC:\Users\admin\AppData\Local\Temp\GLJE9C8.tmpSolarWinds-TFTP-Server.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\glje9c8.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
2764"C:\Users\admin\AppData\Local\Temp\GLJE9C8.tmp" C:\Windows\System32\MSCOMCTL.OCXC:\Users\admin\AppData\Local\Temp\GLJE9C8.tmpSolarWinds-TFTP-Server.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\glje9c8.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
Total events
2 995
Read events
1 686
Write events
1 234
Delete events
75

Modification events

(PID) Process:(3424) SolarWinds-TFTP-Server.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\System32\oleaut32.dll
Value:
2
(PID) Process:(3424) SolarWinds-TFTP-Server.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\System32\olepro32.dll
Value:
2
(PID) Process:(3424) SolarWinds-TFTP-Server.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\System32\asycfilt.dll
Value:
2
(PID) Process:(3424) SolarWinds-TFTP-Server.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\System32\stdole2.tlb
Value:
2
(PID) Process:(3424) SolarWinds-TFTP-Server.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\System32\msvbvm60.dll
Value:
2
(PID) Process:(3424) SolarWinds-TFTP-Server.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Windows\System32\comcat.dll
Value:
2
(PID) Process:(3424) SolarWinds-TFTP-Server.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3424) SolarWinds-TFTP-Server.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3424) SolarWinds-TFTP-Server.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3424) SolarWinds-TFTP-Server.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
77
Suspicious files
1
Text files
18
Unknown types
22

Dropped files

PID
Process
Filename
Type
3424SolarWinds-TFTP-Server.exeC:\Users\admin\AppData\Local\Temp\GLKEBBD.tmpexecutable
MD5:3DF61E5730883B2D338ADDD7ACBE4BC4
SHA256:2EFE9A54C8EB878711D9B6CD18F276838645AFF52FE69D8A864376CB258EC616
3424SolarWinds-TFTP-Server.exeC:\Users\admin\AppData\Local\Temp\~GLH0000.TMPexecutable
MD5:B9B41E50D612E00BF3A49A6405B89D74
SHA256:50E7A30E1825FAB93B94B698C2C6D2CC1787B094C6CEE53EEED5C497F77443C9
3424SolarWinds-TFTP-Server.exeC:\Users\admin\AppData\Local\Temp\GLFF584.tmpexecutable
MD5:B9B41E50D612E00BF3A49A6405B89D74
SHA256:50E7A30E1825FAB93B94B698C2C6D2CC1787B094C6CEE53EEED5C497F77443C9
3424SolarWinds-TFTP-Server.exeC:\Users\admin\AppData\Local\Temp\~GLH0001.TMPtext
MD5:68F129BA51EAF60476492FFCCED19D82
SHA256:F6C6954BD2C45254AF2B8BB74A5F0ECA38DEF58409B8A2E3FC4626F620E24D33
3424SolarWinds-TFTP-Server.exeC:\Windows\system32\temp.002executable
MD5:3E5223A6AC897D866ACBD2D9DB6DB688
SHA256:64F5D862679B697082B42A88DBF500C6DE2438482E3ADFEBFEE0DEEF34B17F1E
3424SolarWinds-TFTP-Server.exeC:\Windows\system32\~GLH0002.TMPexecutable
MD5:DBC403A7D9CE44EBE5F9719BD0749C49
SHA256:1F2C9BF43A5CE0F3592C2485489D57D59BEF2CC0F6AA5CC22FC8014EC6C530E8
3424SolarWinds-TFTP-Server.exeC:\Windows\system32\~GLH0004.TMPexecutable
MD5:3E5223A6AC897D866ACBD2D9DB6DB688
SHA256:64F5D862679B697082B42A88DBF500C6DE2438482E3ADFEBFEE0DEEF34B17F1E
3424SolarWinds-TFTP-Server.exeC:\Windows\system32\~GLH0005.TMPexecutable
MD5:569F738B496FC2CFA9350D6713557250
SHA256:7DC1506747C107312B174FCE1F2C6B8BC6D5ECEA68175465E53FED24D76683C8
3424SolarWinds-TFTP-Server.exeC:\Windows\system32\temp.001executable
MD5:BD7D81E4C5669E6CAAD51C08D5400CA8
SHA256:50A809FD35A280A45157C443C2A39C60D95A074CEB8A7375EBA002268F88D7F0
3424SolarWinds-TFTP-Server.exeC:\Windows\system32\~GLH0003.TMPexecutable
MD5:BD7D81E4C5669E6CAAD51C08D5400CA8
SHA256:50A809FD35A280A45157C443C2A39C60D95A074CEB8A7375EBA002268F88D7F0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info