File name:

6tk0f9oaqz8cgskcg.exe

Full analysis: https://app.any.run/tasks/23035642-23da-495b-9d65-ed519b4c6064
Verdict: Malicious activity
Analysis date: August 20, 2019, 05:39:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

B8CE1ED518A516BF2884D7E0FAEDAE3A

SHA1:

57D2DAAC384D2528E49B9C602E7E3F22CFDCC6C0

SHA256:

0B29184A2F2B3FE432F0EA29EA9EBD9724DD0CF943FFD045BC0549D3B711CCCC

SSDEEP:

49152:ojjTsTbYk6iU2Q6+eqB8YSgcojvOS4SDewbLUSbHH3l8SbHH37dCCNcpxfzhEVk:ojjTDkpU2Q6Q8YTcoz74SDJgq3eq3WN1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • sai.exe (PID: 3952)
      • sai.exe (PID: 3104)
      • sai.exe (PID: 2344)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 6tk0f9oaqz8cgskcg.exe (PID: 2272)
    • Creates a software uninstall entry

      • 6tk0f9oaqz8cgskcg.exe (PID: 2272)
    • Creates files in the program directory

      • 6tk0f9oaqz8cgskcg.exe (PID: 2272)
      • sai.exe (PID: 2344)
    • Modifies the open verb of a shell class

      • 6tk0f9oaqz8cgskcg.exe (PID: 2272)
    • Low-level read access rights to disk partition

      • sai.exe (PID: 2344)
  • INFO

    • Manual execution by user

      • sai.exe (PID: 3952)
      • sai.exe (PID: 3104)
      • sai.exe (PID: 2344)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:08:15 15:05:21+02:00
PEType: PE32
LinkerVersion: 6
CodeSize: 28672
InitializedDataSize: 32768
UninitializedDataSize: -
EntryPoint: 0x46d6
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 15-Aug-2012 13:05:21
Detected languages:
  • Japanese - Japan

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000F0

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 4
Time date stamp: 15-Aug-2012 13:05:21
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00006140
0x00007000
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
5.89764
.rdata
0x00008000
0x00003576
0x00004000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
6.4002
.data
0x0000C000
0x00000A94
0x00001000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
2.68398
.rsrc
0x0000D000
0x00002A50
0x00003000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.15518

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.13265
731
UNKNOWN
Japanese - Japan
RT_MANIFEST
2
6.04891
2216
UNKNOWN
Japanese - Japan
RT_ICON
3
5.8807
1128
UNKNOWN
Japanese - Japan
RT_ICON
4
5.3973
4264
UNKNOWN
Japanese - Japan
RT_ICON
102
2.46808
62
UNKNOWN
Japanese - Japan
RT_GROUP_ICON
1000
3.44173
590
UNKNOWN
Japanese - Japan
RT_DIALOG

Imports

ADVAPI32.dll
COMCTL32.dll
IMAGEHLP.dll
KERNEL32.dll
MSVCRT.dll
SHELL32.dll
SHLWAPI.dll
USER32.dll
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
5
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start 6tk0f9oaqz8cgskcg.exe sai.exe no specs sai.exe no specs sai.exe 6tk0f9oaqz8cgskcg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2272"C:\Users\admin\AppData\Local\Temp\6tk0f9oaqz8cgskcg.exe" C:\Users\admin\AppData\Local\Temp\6tk0f9oaqz8cgskcg.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\6tk0f9oaqz8cgskcg.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2344"C:\PaintToolSAI\sai.exe" C:\PaintToolSAI\sai.exe
explorer.exe
User:
admin
Company:
SYSTEMAX Software Development Inc.
Integrity Level:
HIGH
Description:
sai
Exit code:
0
Version:
1, 2, 0, 1
Modules
Images
c:\painttoolsai\sai.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3104"C:\PaintToolSAI\sai.exe" C:\PaintToolSAI\sai.exeexplorer.exe
User:
admin
Company:
SYSTEMAX Software Development Inc.
Integrity Level:
MEDIUM
Description:
sai
Exit code:
0
Version:
1, 2, 0, 1
Modules
Images
c:\painttoolsai\sai.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
3736"C:\Users\admin\AppData\Local\Temp\6tk0f9oaqz8cgskcg.exe" C:\Users\admin\AppData\Local\Temp\6tk0f9oaqz8cgskcg.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\6tk0f9oaqz8cgskcg.exe
c:\systemroot\system32\ntdll.dll
3952"C:\PaintToolSAI\sai.exe" C:\PaintToolSAI\sai.exeexplorer.exe
User:
admin
Company:
SYSTEMAX Software Development Inc.
Integrity Level:
MEDIUM
Description:
sai
Exit code:
0
Version:
1, 2, 0, 1
Modules
Images
c:\painttoolsai\sai.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
Total events
196
Read events
186
Write events
10
Delete events
0

Modification events

(PID) Process:(2272) 6tk0f9oaqz8cgskcg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sai\DefaultIcon
Operation:writeName:
Value:
C:\PaintToolSAI\sai.exe,1
(PID) Process:(2272) 6tk0f9oaqz8cgskcg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sai\Shell\open\command
Operation:writeName:
Value:
C:\PaintToolSAI\sai.exe %1
(PID) Process:(2272) 6tk0f9oaqz8cgskcg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PaintToolSAI
Operation:writeName:DisplayName
Value:
PaintTool SAI Ver.1
(PID) Process:(2272) 6tk0f9oaqz8cgskcg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PaintToolSAI
Operation:writeName:UninstallString
Value:
C:\PaintToolSAI\uninst.exe
(PID) Process:(2272) 6tk0f9oaqz8cgskcg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
65
(PID) Process:(2344) sai.exeKey:HKEY_CURRENT_USER\Software\SYSTEMAX Software Development\Sai
Operation:writeName:CanvasWidth
Value:
512.00000000000000
(PID) Process:(2344) sai.exeKey:HKEY_CURRENT_USER\Software\SYSTEMAX Software Development\Sai
Operation:writeName:CanvasHeight
Value:
512.00000000000000
(PID) Process:(2344) sai.exeKey:HKEY_CURRENT_USER\Software\SYSTEMAX Software Development\Sai
Operation:writeName:CanvasRes
Value:
72.00000000000000
(PID) Process:(2344) sai.exeKey:HKEY_CURRENT_USER\Software\SYSTEMAX Software Development\Sai
Operation:writeName:CanvasUnitSize
Value:
0
(PID) Process:(2344) sai.exeKey:HKEY_CURRENT_USER\Software\SYSTEMAX Software Development\Sai
Operation:writeName:CanvasUnitRes
Value:
0
Executable files
2
Suspicious files
0
Text files
44
Unknown types
3

Dropped files

PID
Process
Filename
Type
22726tk0f9oaqz8cgskcg.exeC:\PaintToolSAI\language.conftext
MD5:62C7E90022901DDE9F394F912660F27B
SHA256:AD287BB0F748A94716B5A801069D741E3D43451D7621D8C919E635DB7E424DA9
22726tk0f9oaqz8cgskcg.exeC:\PaintToolSAI\brushtex.conftext
MD5:3581DFE37330E7399CE4E7616640D591
SHA256:2DD3BB0ED53EC1D3DB814C34F9A22EB56E1488E5B7A618F387652E5281EE7A35
22726tk0f9oaqz8cgskcg.exeC:\PaintToolSAI\uninst.exeexecutable
MD5:A42230592F0F8A018C084CA4F6FAB3E9
SHA256:2BE4E97FBBD333F032B349A0CED5F8C9D694D0FDBDBE5B52A9CD4D4A7F9DB771
22726tk0f9oaqz8cgskcg.exeC:\PaintToolSAI\blotmap\Spread&Noise.bmpimage
MD5:7E313E2D7A64656EF7101D180EFC2DA8
SHA256:75B412BC911F85B71AB0F74648FCA9D8A7B0F88BD2EB65CD9F941CC1CA87FA42
22726tk0f9oaqz8cgskcg.exeC:\PaintToolSAI\brushtex\Paper.bmpimage
MD5:3E940D47505AE20AE27A3023C1E4C5F0
SHA256:6CFC0E01583BFD0A1B1598BB954077ACD3502BC5C24524132E3A17DAC129137C
22726tk0f9oaqz8cgskcg.exeC:\PaintToolSAI\brushtex\Canvas.bmpimage
MD5:77ABF38CEB44FF0D9F32F1A28106CF40
SHA256:56FD2208AC9082C2500B155F5DFD312B3289C53B2E5AE259D6B30E50982A5D76
22726tk0f9oaqz8cgskcg.exeC:\PaintToolSAI\help.chmchm
MD5:6B07AD12686295D20F9989B6D7C1999A
SHA256:23B70C51992D895FB0A103C963D3920E546DAF26C8A1FA64E5A7771E969F3AA9
22726tk0f9oaqz8cgskcg.exeC:\PaintToolSAI\papertex\Canvas.bmpimage
MD5:77ABF38CEB44FF0D9F32F1A28106CF40
SHA256:56FD2208AC9082C2500B155F5DFD312B3289C53B2E5AE259D6B30E50982A5D76
22726tk0f9oaqz8cgskcg.exeC:\PaintToolSAI\papertex\Watercolor B.bmpimage
MD5:9DD71181BA3D048B1A3BCCE15C2C3871
SHA256:7AC03B1F36BD2A0FC257F6A2302F62A97B1098130100E5A7613FA86E1849A499
22726tk0f9oaqz8cgskcg.exeC:\PaintToolSAI\papertex.conftext
MD5:38D40F9C4E6B0810A5E1B6709D277FC2
SHA256:AD422261151F403038ABA095E0C90FA434C97CD9860AB689812277A0A98E9943
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info