| File name: | pppp.exe |
| Full analysis: | https://app.any.run/tasks/c38f12a4-956f-46f8-9ea4-f54462a204f9 |
| Verdict: | Malicious activity |
| Analysis date: | July 20, 2024, 20:04:34 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32+ executable (console) x86-64, for MS Windows |
| MD5: | 7F3A738BA2AEF448AD6714C9780237AD |
| SHA1: | 0B0BEE65BEBAB0FFB1C6A19F04195F50647ED3E2 |
| SHA256: | 0BABF6E193C1E19692D7651CE6D2299B9A41A8DDCF4AE0C55C72E212E6BD42C6 |
| SSDEEP: | 98304:qRKcYAddP3kTWSZhPLTNK8D96+Jx75sUst36BeA9T9iplO99rb/GqNM+1Fqi8i31:QUPbyhGj65 |
| .exe | | | Win64 Executable (generic) (87.3) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (6.3) |
| .exe | | | DOS Executable Generic (6.3) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2024:02:25 15:43:03+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 14.37 |
| CodeSize: | 172032 |
| InitializedDataSize: | 153600 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb7d0 |
| OSVersion: | 5.2 |
| ImageVersion: | - |
| SubsystemVersion: | 5.2 |
| Subsystem: | Windows command line |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1456 | "C:\Users\admin\AppData\Local\Temp\pppp.exe" | C:\Users\admin\AppData\Local\Temp\pppp.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 2768 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | pppp.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 4496 | "C:\Users\admin\AppData\Local\Temp\pppp.exe" | C:\Users\admin\AppData\Local\Temp\pppp.exe | — | pppp.exe | |||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1456 | pppp.exe | C:\Users\admin\AppData\Local\Temp\_MEI14562\base_library.zip | compressed | |
MD5:CCEE0EA5BA04AA4FCB1D5A19E976B54F | SHA256:EEB7F0B3E56B03454868411D5F62F23C1832C27270CEE551B9CA7D9D10106B29 | |||
| 1456 | pppp.exe | C:\Users\admin\AppData\Local\Temp\_MEI14562\_hashlib.pyd | executable | |
MD5:8BAEB2BD6E52BA38F445EF71EF43A6B8 | SHA256:6C50C9801A5CAF0BB52B384F9A0D5A4AA182CA835F293A39E8999CF6EDF2F087 | |||
| 1456 | pppp.exe | C:\Users\admin\AppData\Local\Temp\_MEI14562\VCRUNTIME140.dll | executable | |
MD5:BE8DBE2DC77EBE7F88F910C61AEC691A | SHA256:4D292623516F65C80482081E62D5DADB759DC16E851DE5DB24C3CBB57B87DB83 | |||
| 1456 | pppp.exe | C:\Users\admin\AppData\Local\Temp\_MEI14562\_decimal.pyd | executable | |
MD5:F78F9855D2A7CA940B6BE51D68B80BF2 | SHA256:D4AE192BBD4627FC9487A2C1CD9869D1B461C20CFD338194E87F5CF882BBED12 | |||
| 1456 | pppp.exe | C:\Users\admin\AppData\Local\Temp\_MEI14562\libcrypto-3.dll | executable | |
MD5:51E8A5281C2092E45D8C97FBDBF39560 | SHA256:2A234B5AA20C3FAECF725BBB54FB33F3D94543F78FA7045408E905593E49960A | |||
| 1456 | pppp.exe | C:\Users\admin\AppData\Local\Temp\_MEI14562\_lzma.pyd | executable | |
MD5:CF8DE1137F36141AFD9FF7C52A3264EE | SHA256:22D10E2D6AD3E3ED3C49EB79AB69A81AAA9D16AECA7F948DA2FE80877F106C16 | |||
| 1456 | pppp.exe | C:\Users\admin\AppData\Local\Temp\_MEI14562\_bz2.pyd | executable | |
MD5:90F58F625A6655F80C35532A087A0319 | SHA256:BD8621FCC901FA1DE3961D93184F61EA71068C436794AF2A4449738CCF949946 | |||
| 1456 | pppp.exe | C:\Users\admin\AppData\Local\Temp\_MEI14562\select.pyd | executable | |
MD5:E1604AFE8244E1CE4C316C64EA3AA173 | SHA256:74CCA85600E7C17EA6532B54842E26D3CAE9181287CDF5A4A3C50AF4DAB785E5 | |||
| 1456 | pppp.exe | C:\Users\admin\AppData\Local\Temp\_MEI14562\_socket.pyd | executable | |
MD5:439B3AD279BEFA65BB40ECEBDDD6228B | SHA256:24017D664AF20EE3B89514539345CAAC83ECA34825FCF066A23E8A4C99F73E6D | |||
| 1456 | pppp.exe | C:\Users\admin\AppData\Local\Temp\_MEI14562\python312.dll | executable | |
MD5:48EBFEFA21B480A9B0DBFC3364E1D066 | SHA256:0CC4E557972488EB99EA4AEB3D29F3ADE974EF3BCD47C211911489A189A0B6F2 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4032 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4716 | svchost.exe | 40.126.31.73:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
5620 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 4.208.221.206:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
— | — | 4.209.32.198:443 | licensing.mp.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
— | — | 20.83.72.98:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
— | — | 40.126.31.73:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
— | — | 40.113.103.199:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2760 | svchost.exe | 40.113.103.199:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
login.live.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
licensing.mp.microsoft.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
www.bing.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |