File name:

Advanced Dolly Cams.exe

Full analysis: https://app.any.run/tasks/1e986e7b-bac8-443c-a13b-498f8841741f
Verdict: Malicious activity
Analysis date: November 26, 2023, 10:33:03
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

81C0B0572C171874A60DBE72329A4E4C

SHA1:

1DFC5F0F56B874ABE403364073FFFB6778E396D8

SHA256:

0C6FD59ACB76661D437BECCA77EAC11BB2E41BD004821D5F33F8FC01758961CF

SSDEEP:

49152:B1UXEv/DR+exX8b1Pyw0/lDwIHDLOsNKLY3zgCCSMGqwqURF4HlLu+Es5yuI/Zc8:B/zkrrmvOsNgY3sCCQqiFmlpEs5yuIhw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads settings of System Certificates

      • Advanced Dolly Cams.exe (PID: 2516)
    • Reads the Internet Settings

      • Advanced Dolly Cams.exe (PID: 2516)
  • INFO

    • Checks supported languages

      • Advanced Dolly Cams.exe (PID: 2516)
      • wmpnscfg.exe (PID: 1736)
    • Reads the computer name

      • Advanced Dolly Cams.exe (PID: 2516)
      • wmpnscfg.exe (PID: 1736)
    • Reads Environment values

      • Advanced Dolly Cams.exe (PID: 2516)
    • Reads the machine GUID from the registry

      • Advanced Dolly Cams.exe (PID: 2516)
      • wmpnscfg.exe (PID: 1736)
    • Create files in a temporary directory

      • Advanced Dolly Cams.exe (PID: 2516)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1736)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (41)
.exe | Win64 Executable (generic) (36.3)
.dll | Win32 Dynamic Link Library (generic) (8.6)
.exe | Win32 Executable (generic) (5.9)
.exe | Win16/32 Executable Delphi generic (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:12:07 08:01:42+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 816128
InitializedDataSize: 1219072
UninitializedDataSize: -
EntryPoint: 0x1f600a
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: Roll Mod Loader
FileVersion: 1.0.0.0
InternalName: Roll Mod Loader.exe
LegalCopyright: Copyright © 2018
LegalTrademarks: -
OriginalFileName: Roll Mod Loader.exe
ProductName: Roll Mod Loader
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start advanced dolly cams.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1736"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
2516"C:\Users\admin\AppData\Local\Temp\Advanced Dolly Cams.exe" C:\Users\admin\AppData\Local\Temp\Advanced Dolly Cams.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Roll Mod Loader
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\advanced dolly cams.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
4 340
Read events
4 325
Write events
12
Delete events
3

Modification events

(PID) Process:(2516) Advanced Dolly Cams.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1736) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{025F23AB-4BEA-4CAB-9B74-5FD223D056E8}\{BAFBAFEB-75EC-4DAF-8215-91382E0B13FF}
Operation:delete keyName:(default)
Value:
(PID) Process:(1736) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{025F23AB-4BEA-4CAB-9B74-5FD223D056E8}
Operation:delete keyName:(default)
Value:
(PID) Process:(1736) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{8EE630AD-E4F2-4842-8944-76BB9E31F4AA}
Operation:delete keyName:(default)
Value:
Executable files
0
Suspicious files
4
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2516Advanced Dolly Cams.exeC:\Users\admin\AppData\Local\Temp\CabEB47.tmpcompressed
MD5:F3441B8572AAE8801C04F3060B550443
SHA256:6720349E7D82EE0A8E73920D3C2B7CB2912D9FCF2EDB6FD98F2F12820158B0BF
2516Advanced Dolly Cams.exeC:\Users\admin\AppData\Local\Temp\TarEB48.tmpbinary
MD5:9441737383D21192400ECA82FDA910EC
SHA256:BC3A6E84E41FAEB57E7C21AA3B60C2A64777107009727C5B7C0ED8FE658909E5
2516Advanced Dolly Cams.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:F3441B8572AAE8801C04F3060B550443
SHA256:6720349E7D82EE0A8E73920D3C2B7CB2912D9FCF2EDB6FD98F2F12820158B0BF
2516Advanced Dolly Cams.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:604508B2345F2F90BB1126CAB46DBF87
SHA256:F610FB330BB5FA23E9097A246DDB3A8A4CAC0EBF425013AB71CB845F28B6318E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
7
DNS requests
2
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2516
Advanced Dolly Cams.exe
GET
301
172.67.161.171:80
http://airyz.xyz/toolversions.txt
unknown
unknown
2516
Advanced Dolly Cams.exe
GET
200
67.27.159.254:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?7c3f5f771d8e7226
unknown
compressed
61.6 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2588
svchost.exe
239.255.255.250:1900
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2516
Advanced Dolly Cams.exe
172.67.161.171:80
airyz.xyz
CLOUDFLARENET
US
unknown
2516
Advanced Dolly Cams.exe
172.67.161.171:443
airyz.xyz
CLOUDFLARENET
US
unknown
2516
Advanced Dolly Cams.exe
67.27.159.254:80
ctldl.windowsupdate.com
LEVEL3
US
unknown

DNS requests

Domain
IP
Reputation
airyz.xyz
  • 172.67.161.171
  • 104.21.34.139
unknown
ctldl.windowsupdate.com
  • 67.27.159.254
  • 8.241.121.126
  • 8.253.207.121
  • 67.27.235.126
  • 8.248.115.254
whitelisted

Threats

PID
Process
Class
Message
2516
Advanced Dolly Cams.exe
Potentially Bad Traffic
ET HUNTING Observed Let's Encrypt Certificate for Suspicious TLD (.xyz)
2516
Advanced Dolly Cams.exe
Potentially Bad Traffic
ET HUNTING Request to .XYZ Domain with Minimal Headers
2516
Advanced Dolly Cams.exe
Potentially Bad Traffic
AV INFO HTTP Request to a *.xyz domain
1 ETPRO signatures available at the full report
Process
Message
Advanced Dolly Cams.exe
C:\Users\admin\AppData\Local\Temp\themes.xml
Advanced Dolly Cams.exe
SessionSwitch, reason=OnLoad, terminalServerSession=False, aeroThemeEnabled=False, dropShadowSupported=False