analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

0d38d6539416f3ec691355e4f19bc707.exe

Full analysis: https://app.any.run/tasks/2d9d20e0-2f02-4ed6-b81a-52eb5438dc56
Verdict: Malicious activity
Analysis date: May 21, 2022, 03:49:18
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

0D38D6539416F3EC691355E4F19BC707

SHA1:

41B2045ADD9007126EAB5205327B5B5D330525BE

SHA256:

07647E4E915DA95ED799702B07D09E18DC2C9AE13D641E94111E8E3F2336B63A

SSDEEP:

49152:2Rx1mqGk9hP2LgQD2JS9N50bXyTtsBP/OlsLzFmNfW6FJKxxfZA4X:2Rx1uwhPUiXzBP/OlsLzFmNfW6FJKxxF

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • 0d38d6539416f3ec691355e4f19bc707.exe.scr (PID: 1628)
    • Loads the Task Scheduler COM API

      • schtasks.exe (PID: 2528)
      • schtasks.exe (PID: 2852)
      • schtasks.exe (PID: 2732)
      • schtasks.exe (PID: 1536)
      • schtasks.exe (PID: 3732)
      • schtasks.exe (PID: 1676)
      • schtasks.exe (PID: 3264)
      • schtasks.exe (PID: 3136)
      • schtasks.exe (PID: 3568)
      • schtasks.exe (PID: 3436)
      • schtasks.exe (PID: 2908)
      • schtasks.exe (PID: 3288)
      • schtasks.exe (PID: 3900)
      • schtasks.exe (PID: 4032)
      • schtasks.exe (PID: 756)
      • schtasks.exe (PID: 2024)
      • schtasks.exe (PID: 120)
      • schtasks.exe (PID: 2724)
      • schtasks.exe (PID: 2848)
      • schtasks.exe (PID: 2008)
    • Changes the autorun value in the registry

      • 0d38d6539416f3ec691355e4f19bc707.exe.scr (PID: 1628)
  • SUSPICIOUS

    • Checks supported languages

      • 0d38d6539416f3ec691355e4f19bc707.exe.scr (PID: 1912)
      • 0d38d6539416f3ec691355e4f19bc707.exe.scr (PID: 1628)
      • 0d38d6539416f3ec691355e4f19bc707.exe.scr.exe (PID: 340)
      • cmd.exe (PID: 2940)
      • 0d38d6539416f3ec691355e4f19bc707.exe.scr.exe (PID: 3068)
    • Reads the computer name

      • 0d38d6539416f3ec691355e4f19bc707.exe.scr (PID: 1912)
      • 0d38d6539416f3ec691355e4f19bc707.exe.scr (PID: 1628)
      • 0d38d6539416f3ec691355e4f19bc707.exe.scr.exe (PID: 340)
      • 0d38d6539416f3ec691355e4f19bc707.exe.scr.exe (PID: 3068)
    • Application launched itself

      • 0d38d6539416f3ec691355e4f19bc707.exe.scr (PID: 1912)
      • 0d38d6539416f3ec691355e4f19bc707.exe.scr.exe (PID: 3068)
    • Starts application with an unusual extension

      • 0d38d6539416f3ec691355e4f19bc707.exe.scr (PID: 1912)
    • Reads Environment values

      • 0d38d6539416f3ec691355e4f19bc707.exe.scr (PID: 1628)
      • 0d38d6539416f3ec691355e4f19bc707.exe.scr.exe (PID: 340)
    • Creates files in the Windows directory

      • 0d38d6539416f3ec691355e4f19bc707.exe.scr (PID: 1628)
    • Executable content was dropped or overwritten

      • 0d38d6539416f3ec691355e4f19bc707.exe.scr (PID: 1628)
    • Drops a file with a compile date too recent

      • 0d38d6539416f3ec691355e4f19bc707.exe.scr (PID: 1628)
    • Executed via WMI

      • schtasks.exe (PID: 2528)
      • schtasks.exe (PID: 2852)
      • schtasks.exe (PID: 2732)
      • schtasks.exe (PID: 1536)
      • schtasks.exe (PID: 1676)
      • schtasks.exe (PID: 3136)
      • schtasks.exe (PID: 3732)
      • schtasks.exe (PID: 3264)
      • schtasks.exe (PID: 3436)
      • schtasks.exe (PID: 3568)
      • schtasks.exe (PID: 2908)
      • schtasks.exe (PID: 3288)
      • schtasks.exe (PID: 3900)
      • schtasks.exe (PID: 4032)
      • schtasks.exe (PID: 756)
      • schtasks.exe (PID: 2024)
      • schtasks.exe (PID: 2724)
      • schtasks.exe (PID: 120)
      • schtasks.exe (PID: 2848)
      • schtasks.exe (PID: 2008)
    • Creates files in the program directory

      • 0d38d6539416f3ec691355e4f19bc707.exe.scr (PID: 1628)
    • Creates executable files which already exist in Windows

      • 0d38d6539416f3ec691355e4f19bc707.exe.scr (PID: 1628)
    • Starts CMD.EXE for commands execution

      • 0d38d6539416f3ec691355e4f19bc707.exe.scr (PID: 1628)
  • INFO

    • Reads the computer name

      • schtasks.exe (PID: 2528)
      • schtasks.exe (PID: 2732)
      • schtasks.exe (PID: 2852)
      • schtasks.exe (PID: 1676)
      • schtasks.exe (PID: 1536)
      • schtasks.exe (PID: 3264)
      • schtasks.exe (PID: 3136)
      • schtasks.exe (PID: 3732)
      • schtasks.exe (PID: 3436)
      • schtasks.exe (PID: 3568)
      • schtasks.exe (PID: 2908)
      • schtasks.exe (PID: 3900)
      • schtasks.exe (PID: 3288)
      • schtasks.exe (PID: 4032)
      • schtasks.exe (PID: 756)
      • schtasks.exe (PID: 2024)
      • schtasks.exe (PID: 120)
      • schtasks.exe (PID: 2724)
      • schtasks.exe (PID: 2008)
      • schtasks.exe (PID: 2848)
      • w32tm.exe (PID: 3188)
    • Checks supported languages

      • schtasks.exe (PID: 2732)
      • schtasks.exe (PID: 2528)
      • schtasks.exe (PID: 1536)
      • schtasks.exe (PID: 2852)
      • schtasks.exe (PID: 3732)
      • schtasks.exe (PID: 1676)
      • schtasks.exe (PID: 3136)
      • schtasks.exe (PID: 3264)
      • schtasks.exe (PID: 3436)
      • schtasks.exe (PID: 3568)
      • schtasks.exe (PID: 2908)
      • schtasks.exe (PID: 3288)
      • schtasks.exe (PID: 3900)
      • schtasks.exe (PID: 756)
      • schtasks.exe (PID: 4032)
      • schtasks.exe (PID: 2024)
      • schtasks.exe (PID: 120)
      • schtasks.exe (PID: 2724)
      • schtasks.exe (PID: 2848)
      • schtasks.exe (PID: 2008)
      • w32tm.exe (PID: 3188)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.scr | Windows screen saver (46.4)
.dll | Win32 Dynamic Link Library (generic) (23.3)
.exe | Win32 Executable (generic) (15.9)
.exe | Generic Win/DOS Executable (7.1)
.exe | DOS Executable Generic (7)

EXIF

EXE

AssemblyVersion: 1.0.0.0
ProductVersion: 1.0.0.0
ProductName: MooirivierDotNet
OriginalFileName: MooirivierDotNet.exe
LegalTrademarks: -
LegalCopyright: Copyright ©
InternalName: MooirivierDotNet.exe
FileVersion: 1.0.0.0
FileDescription: MooirivierDotNet
CompanyName: -
Comments: -
CharacterSet: Unicode
LanguageCode: Neutral
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 1.0.0.0
FileVersionNumber: 1.0.0.0
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0x1026de
UninitializedDataSize: -
InitializedDataSize: 4096
CodeSize: 1050624
LinkerVersion: 8
PEType: PE32
TimeStamp: 1989:08:31 17:34:09+02:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 31-Aug-1989 15:34:09
Comments: -
CompanyName: -
FileDescription: MooirivierDotNet
FileVersion: 1.0.0.0
InternalName: MooirivierDotNet.exe
LegalCopyright: Copyright ©
LegalTrademarks: -
OriginalFilename: MooirivierDotNet.exe
ProductName: MooirivierDotNet
ProductVersion: 1.0.0.0
Assembly Version: 1.0.0.0

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000080

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 3
Time date stamp: 31-Aug-1989 15:34:09
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00002000
0x001006E4
0x00100800
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.47973
.rsrc
0x00104000
0x00000C93
0x00000E00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.5994
.reloc
0x00106000
0x0000000C
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
0.10191

Resources

Title
Entropy
Size
Codepage
Language
Type
1
4.90047
2211
UNKNOWN
UNKNOWN
RT_MANIFEST

Imports

mscoree.dll
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
26
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start 0d38d6539416f3ec691355e4f19bc707.exe.scr no specs 0d38d6539416f3ec691355e4f19bc707.exe.scr schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs cmd.exe no specs w32tm.exe no specs 0d38d6539416f3ec691355e4f19bc707.exe.scr.exe no specs 0d38d6539416f3ec691355e4f19bc707.exe.scr.exe

Process information

PID
CMD
Path
Indicators
Parent process
1912"C:\Users\admin\AppData\Local\Temp\0d38d6539416f3ec691355e4f19bc707.exe.scr" /SC:\Users\admin\AppData\Local\Temp\0d38d6539416f3ec691355e4f19bc707.exe.scrExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
MooirivierDotNet
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\0d38d6539416f3ec691355e4f19bc707.exe.scr
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1628"C:\Users\admin\AppData\Local\Temp\0d38d6539416f3ec691355e4f19bc707.exe.scr"C:\Users\admin\AppData\Local\Temp\0d38d6539416f3ec691355e4f19bc707.exe.scr
0d38d6539416f3ec691355e4f19bc707.exe.scr
User:
admin
Integrity Level:
MEDIUM
Description:
MooirivierDotNet
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\0d38d6539416f3ec691355e4f19bc707.exe.scr
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2528schtasks.exe /create /tn "taskhost" /sc MINUTE /mo 5 /tr "'C:\ProgramData\Documents\taskhost.exe'" /rl HIGHEST /fC:\Windows\system32\schtasks.exewmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
2732schtasks.exe /create /tn "taskhost" /sc ONLOGON /tr "'C:\ProgramData\Documents\taskhost.exe'" /rl HIGHEST /fC:\Windows\system32\schtasks.exewmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\ole32.dll
c:\windows\system32\usp10.dll
2852schtasks.exe /create /tn "taskhost" /sc ONSTART /tr "'C:\ProgramData\Documents\taskhost.exe'" /rl HIGHEST /fC:\Windows\system32\schtasks.exewmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\lpk.dll
1536schtasks.exe /create /tn "taskhostt" /sc MINUTE /mo 11 /tr "'C:\ProgramData\Documents\taskhost.exe'" /fC:\Windows\system32\schtasks.exewmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
c:\windows\system32\lpk.dll
1676schtasks.exe /create /tn "winlogon" /sc MINUTE /mo 11 /tr "'C:\MSOCache\All Users\{90140000-0018-0C0A-0000-0000000FF1CE}-C\winlogon.exe'" /rl HIGHEST /fC:\Windows\system32\schtasks.exewmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
3732schtasks.exe /create /tn "winlogon" /sc ONLOGON /tr "'C:\MSOCache\All Users\{90140000-0018-0C0A-0000-0000000FF1CE}-C\winlogon.exe'" /rl HIGHEST /fC:\Windows\system32\schtasks.exewmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\schtasks.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\ole32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
3136schtasks.exe /create /tn "winlogon" /sc ONSTART /tr "'C:\MSOCache\All Users\{90140000-0018-0C0A-0000-0000000FF1CE}-C\winlogon.exe'" /rl HIGHEST /fC:\Windows\system32\schtasks.exewmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\schtasks.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\rpcrt4.dll
3264schtasks.exe /create /tn "winlogonw" /sc MINUTE /mo 7 /tr "'C:\MSOCache\All Users\{90140000-0018-0C0A-0000-0000000FF1CE}-C\winlogon.exe'" /fC:\Windows\system32\schtasks.exewmiprvse.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\oleaut32.dll
Total events
2 151
Read events
2 125
Write events
26
Delete events
0

Modification events

(PID) Process:(1628) 0d38d6539416f3ec691355e4f19bc707.exe.scrKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:taskhost
Value:
"C:\ProgramData\Documents\taskhost.exe"
(PID) Process:(1628) 0d38d6539416f3ec691355e4f19bc707.exe.scrKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:winlogon
Value:
"C:\MSOCache\All Users\{90140000-0018-0C0A-0000-0000000FF1CE}-C\winlogon.exe"
(PID) Process:(1628) 0d38d6539416f3ec691355e4f19bc707.exe.scrKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:0d38d6539416f3ec691355e4f19bc707.exe.scr
Value:
"C:\ProgramData\Skype\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}\0d38d6539416f3ec691355e4f19bc707.exe.scr.exe"
(PID) Process:(1628) 0d38d6539416f3ec691355e4f19bc707.exe.scrKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:csrss
Value:
"C:\MSOCache\All Users\csrss.exe"
(PID) Process:(1628) 0d38d6539416f3ec691355e4f19bc707.exe.scrKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:explorer
Value:
"C:\ProgramData\Skype\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}\explorer.exe"
(PID) Process:(1628) 0d38d6539416f3ec691355e4f19bc707.exe.scrKey:HKEY_CURRENT_USER\Software\8aa51b8d38f1a84033cb8b8b954cc119c792d037
Operation:writeName:a3ccea43b819db978789828123b5ff6e162ccd24
Value:
WyJDOlxcVXNlcnNcXGFkbWluXFxBcHBEYXRhXFxMb2NhbFxcVGVtcFxcMGQzOGQ2NTM5NDE2ZjNlYzY5MTM1NWU0ZjE5YmM3MDcuZXhlLnNjciIsIkM6XFxQcm9ncmFtRGF0YVxcRG9jdW1lbnRzXFx0YXNraG9zdC5leGUiLCJDOlxcTVNPQ2FjaGVcXEFsbCBVc2Vyc1xcezkwMTQwMDAwLTAwMTgtMEMwQS0wMDAwLTAwMDAwMDBGRjFDRX0tQ1xcd2lubG9nb24uZXhlIiwiQzpcXFByb2dyYW1EYXRhXFxTa3lwZVxcezdBM0M3RTA1LUVFMzctNDdENi05OUUxLTJFQjA1QTNEQTNGN31cXDBkMzhkNjUzOTQxNmYzZWM2OTEzNTVlNGYxOWJjNzA3LmV4ZS5zY3IuZXhlIiwiQzpcXE1TT0NhY2hlXFxBbGwgVXNlcnNcXGNzcnNzLmV4ZSIsIkM6XFxQcm9ncmFtRGF0YVxcU2t5cGVcXHs3QTNDN0UwNS1FRTM3LTQ3RDYtOTlFMS0yRUIwNUEzREEzRjd9XFxleHBsb3Jlci5leGUiXQ==
(PID) Process:(1628) 0d38d6539416f3ec691355e4f19bc707.exe.scrKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1628) 0d38d6539416f3ec691355e4f19bc707.exe.scrKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1628) 0d38d6539416f3ec691355e4f19bc707.exe.scrKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1628) 0d38d6539416f3ec691355e4f19bc707.exe.scrKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
5
Suspicious files
0
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
16280d38d6539416f3ec691355e4f19bc707.exe.scrC:\MSOCache\All Users\886983d96e3d3etext
MD5:2200CB8A0B515BE4A0D787B7F3DB4C10
SHA256:90B0772EE45F8AA07EB803D969A43A17913C7F57F4B6CAE7EFA993A196E0495A
16280d38d6539416f3ec691355e4f19bc707.exe.scrC:\Users\Public\Documents\b75386f1303e64text
MD5:3C1A624B66EF3B7AC27C28B95037F94A
SHA256:AE037B519B2B474C15E4BD7C1CA8323135652692F42B06337C3494BFC078A520
16280d38d6539416f3ec691355e4f19bc707.exe.scrC:\MSOCache\All Users\csrss.exeexecutable
MD5:0D38D6539416F3EC691355E4F19BC707
SHA256:07647E4E915DA95ED799702B07D09E18DC2C9AE13D641E94111E8E3F2336B63A
16280d38d6539416f3ec691355e4f19bc707.exe.scrC:\Users\Public\Documents\taskhost.exeexecutable
MD5:0D38D6539416F3EC691355E4F19BC707
SHA256:07647E4E915DA95ED799702B07D09E18DC2C9AE13D641E94111E8E3F2336B63A
16280d38d6539416f3ec691355e4f19bc707.exe.scrC:\ProgramData\Skype\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}\explorer.exeexecutable
MD5:0D38D6539416F3EC691355E4F19BC707
SHA256:07647E4E915DA95ED799702B07D09E18DC2C9AE13D641E94111E8E3F2336B63A
16280d38d6539416f3ec691355e4f19bc707.exe.scrC:\ProgramData\Skype\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}\0d38d6539416f3ec691355e4f19bc707.exe.scr.exeexecutable
MD5:0D38D6539416F3EC691355E4F19BC707
SHA256:07647E4E915DA95ED799702B07D09E18DC2C9AE13D641E94111E8E3F2336B63A
16280d38d6539416f3ec691355e4f19bc707.exe.scrC:\MSOCache\All Users\{90140000-0018-0C0A-0000-0000000FF1CE}-C\cc11b995f2a76dtext
MD5:73374B24CA6CDCBF07A20C6CAA9FFEE6
SHA256:92EEF3EB3EC82924ED1CEAD3AE68CD66CDF46816D7CAA6F43BD375C0E7872461
16280d38d6539416f3ec691355e4f19bc707.exe.scrC:\Users\admin\AppData\Local\Temp\2T4biLBTebtext
MD5:A727FAE6754CA676126AF86F6845052D
SHA256:E647535E865EFDCD91100BFAECBD249F3A3AA79808C27B2E1AC8D2F2FE45BEDB
16280d38d6539416f3ec691355e4f19bc707.exe.scrC:\ProgramData\Skype\{7A3C7E05-EE37-47D6-99E1-2EB05A3DA3F7}\8700893f1893fetext
MD5:3518220833E1251A09609F8455F4303E
SHA256:432BFEE2A96CF92BB957A3501B49EA39011DB8BF5D4C8F1707C7A297879C2E62
16280d38d6539416f3ec691355e4f19bc707.exe.scrC:\MSOCache\All Users\{90140000-0018-0C0A-0000-0000000FF1CE}-C\winlogon.exeexecutable
MD5:0D38D6539416F3EC691355E4F19BC707
SHA256:07647E4E915DA95ED799702B07D09E18DC2C9AE13D641E94111E8E3F2336B63A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
340
0d38d6539416f3ec691355e4f19bc707.exe.scr.exe
GET
403
141.8.195.65:80
http://a0655106.xsph.ru/javascripthttp.php?1979FXbI4zd54YHtTg=LQ36Xli7ygWrwVVhgeffRyBAnfaZ&9CdIBaQ8=kXg&a959e711e6aebd4be92392efe31655e5=15cf6047e07acee0d90cffb551279dfa&dcb1e56ec06ef435de864269ba333cf0=AOwgzY1QjMxkDZyI2MjhzYhlDOyI2NzYWZiZ2Y4QGNyY2NmlDOihTN&1979FXbI4zd54YHtTg=LQ36Xli7ygWrwVVhgeffRyBAnfaZ&9CdIBaQ8=kXg
RU
html
55.9 Kb
malicious
340
0d38d6539416f3ec691355e4f19bc707.exe.scr.exe
GET
403
141.8.195.65:80
http://a0655106.xsph.ru/javascripthttp.php?1979FXbI4zd54YHtTg=LQ36Xli7ygWrwVVhgeffRyBAnfaZ&9CdIBaQ8=kXg&a959e711e6aebd4be92392efe31655e5=15cf6047e07acee0d90cffb551279dfa&dcb1e56ec06ef435de864269ba333cf0=AOwgzY1QjMxkDZyI2MjhzYhlDOyI2NzYWZiZ2Y4QGNyY2NmlDOihTN&1979FXbI4zd54YHtTg=LQ36Xli7ygWrwVVhgeffRyBAnfaZ&9CdIBaQ8=kXg
RU
html
55.9 Kb
malicious
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
340
0d38d6539416f3ec691355e4f19bc707.exe.scr.exe
141.8.195.65:80
a0655106.xsph.ru
Sprinthost.ru LLC
RU
malicious

DNS requests

Domain
IP
Reputation
a0655106.xsph.ru
  • 141.8.195.65
malicious

Threats

No threats detected
No debug info