File name:

Smart Tag.exe

Full analysis: https://app.any.run/tasks/68ed6c94-eb77-4e2d-8c0a-77126c8e5c13
Verdict: Malicious activity
Analysis date: October 05, 2024, 01:24:22
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

512052E4FCD0C226BD78BA87503565E1

SHA1:

01713BD80F21B9C9895E53D409C6C9A06F2225E3

SHA256:

0E8B37D943C42977AB950CC26F3606F27FAF6941C35998630B5D4E719C28925B

SSDEEP:

24576:QxufVbSTjCczCgTFWcZhdVIHl7OoC8HdFJ6:QxudbSTjCczCgTFWcZhdVIHl7OoC8Hdy

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • UAC/LUA settings modification

      • hajwhnbjdnd.exe (PID: 1488)
    • Changes the autorun value in the registry

      • hajwhnbjdnd.exe (PID: 1488)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • Smart Tag.exe (PID: 4804)
      • hajwhnbjdnd.exe (PID: 1488)
    • Reads security settings of Internet Explorer

      • Smart Tag.exe (PID: 4804)
  • INFO

    • Reads the computer name

      • Smart Tag.exe (PID: 4804)
      • hajwhnbjdnd.exe (PID: 1488)
    • Checks supported languages

      • Smart Tag.exe (PID: 4804)
      • hajwhnbjdnd.exe (PID: 1488)
    • Create files in a temporary directory

      • Smart Tag.exe (PID: 4804)
      • hajwhnbjdnd.exe (PID: 1488)
    • Process checks computer location settings

      • Smart Tag.exe (PID: 4804)
    • The process uses the downloaded file

      • Smart Tag.exe (PID: 4804)
    • Process checks whether UAC notifications are on

      • hajwhnbjdnd.exe (PID: 1488)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:04:20 17:36:21+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 7.1
CodeSize: 24576
InitializedDataSize: 442368
UninitializedDataSize: -
EntryPoint: 0x2865
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
165
Monitored processes
24
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start smart tag.exe hajwhnbjdnd.exe zbmqv.exe no specs zbmqv.exe no specs regedit.exe no specs regedit.exe sppextcomobj.exe no specs slui.exe no specs regedit.exe no specs regedit.exe regedit.exe no specs regedit.exe regedit.exe no specs regedit.exe regedit.exe no specs regedit.exe regedit.exe no specs regedit.exe regedit.exe no specs regedit.exe regedit.exe no specs regedit.exe regedit.exe no specs regedit.exe

Process information

PID
CMD
Path
Indicators
Parent process
832"regedit.exe" "C:\Users\admin\AppData\Local\Temp\djygpxkoz.reg"C:\Windows\SysWOW64\regedit.exe
zbmqv.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Editor
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regedit.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1488"C:\Users\admin\AppData\Local\Temp\hajwhnbjdnd.exe" "c:\users\admin\appdata\local\temp\smart tag.exe*"C:\Users\admin\AppData\Local\Temp\hajwhnbjdnd.exe
Smart Tag.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\hajwhnbjdnd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
1568"regedit.exe" "C:\Users\admin\AppData\Local\Temp\djygpxkoz.reg"C:\Windows\SysWOW64\regedit.exe
zbmqv.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Editor
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regedit.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1656"regedit.exe" "C:\Users\admin\AppData\Local\Temp\djygpxkoz.reg"C:\Windows\SysWOW64\regedit.exezbmqv.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Editor
Exit code:
3221226540
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regedit.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
1840"regedit.exe" "C:\Users\admin\AppData\Local\Temp\djygpxkoz.reg"C:\Windows\SysWOW64\regedit.exezbmqv.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Editor
Exit code:
3221226540
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regedit.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
2064"regedit.exe" "C:\Users\admin\AppData\Local\Temp\djygpxkoz.reg"C:\Windows\SysWOW64\regedit.exe
zbmqv.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Editor
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regedit.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2252"regedit.exe" "C:\Users\admin\AppData\Local\Temp\djygpxkoz.reg"C:\Windows\SysWOW64\regedit.exezbmqv.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Editor
Exit code:
3221226540
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regedit.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
2264"regedit.exe" "C:\Users\admin\AppData\Local\Temp\djygpxkoz.reg"C:\Windows\SysWOW64\regedit.exezbmqv.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Editor
Exit code:
3221226540
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regedit.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
2448"regedit.exe" "C:\Users\admin\AppData\Local\Temp\djygpxkoz.reg"C:\Windows\SysWOW64\regedit.exe
zbmqv.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Registry Editor
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regedit.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2456"regedit.exe" "C:\Users\admin\AppData\Local\Temp\djygpxkoz.reg"C:\Windows\SysWOW64\regedit.exezbmqv.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Registry Editor
Exit code:
3221226540
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\regedit.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
Total events
4 239
Read events
4 026
Write events
213
Delete events
0

Modification events

(PID) Process:(1488) hajwhnbjdnd.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
Operation:writeName:EnableLUA
Value:
0
(PID) Process:(1488) hajwhnbjdnd.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:oxpamxnuiicm
Value:
mbzqizviciiyskxshi.exe
(PID) Process:(1488) hajwhnbjdnd.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce
Operation:writeName:nxqcpbsapqlwl
Value:
mbzqizviciiyskxshi.exe .
(PID) Process:(1488) hajwhnbjdnd.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:rdymbpisjmjwncm
Value:
droevlgslqpexoaui.exe
(PID) Process:(1488) hajwhnbjdnd.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Operation:writeName:wjfukztewaymeufy
Value:
mbzqizviciiyskxshi.exe .
(PID) Process:(1488) hajwhnbjdnd.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:mbzqizviciiyskxshi
Value:
C:\Users\admin\AppData\Local\Temp\zrsmhbaqnwzspkayquooa.exe
(PID) Process:(1488) hajwhnbjdnd.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce
Operation:writeName:droevlgslqpexoaui
Value:
C:\Users\admin\AppData\Local\Temp\kbbuohfuqyasoixulohg.exe .
(PID) Process:(1488) hajwhnbjdnd.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:oxpamxnuiicm
Value:
C:\Users\admin\AppData\Local\Temp\kbbuohfuqyasoixulohg.exe
(PID) Process:(1488) hajwhnbjdnd.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Operation:writeName:nxqcpbsapqlwl
Value:
C:\Users\admin\AppData\Local\Temp\zrsmhbaqnwzspkayquooa.exe .
(PID) Process:(1488) hajwhnbjdnd.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
Operation:writeName:DisableRegistryTools
Value:
1
Executable files
9
Suspicious files
5
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
4804Smart Tag.exeC:\Users\admin\AppData\Local\Temp\hajwhnbjdnd.exeexecutable
MD5:EB09C682903ECBD87F30B0366E008D8F
SHA256:C4B122F7BAB30363B472A3DFFB8A7C61604C0EC4719EBD233CCBAC8BE0951BE1
1488hajwhnbjdnd.exeC:\Users\admin\AppData\Local\Temp\zrsmhbaqnwzspkayquooa.exeexecutable
MD5:512052E4FCD0C226BD78BA87503565E1
SHA256:0E8B37D943C42977AB950CC26F3606F27FAF6941C35998630B5D4E719C28925B
1488hajwhnbjdnd.exeC:\Users\admin\AppData\Local\Temp\kbbuohfuqyasoixulohg.exeexecutable
MD5:512052E4FCD0C226BD78BA87503565E1
SHA256:0E8B37D943C42977AB950CC26F3606F27FAF6941C35998630B5D4E719C28925B
1488hajwhnbjdnd.exeC:\Users\admin\AppData\Local\Temp\mbzqizviciiyskxshi.exeexecutable
MD5:512052E4FCD0C226BD78BA87503565E1
SHA256:0E8B37D943C42977AB950CC26F3606F27FAF6941C35998630B5D4E719C28925B
1488hajwhnbjdnd.exeC:\Users\admin\AppData\Local\Temp\qjlgcxxomwausofexcxylp.exeexecutable
MD5:512052E4FCD0C226BD78BA87503565E1
SHA256:0E8B37D943C42977AB950CC26F3606F27FAF6941C35998630B5D4E719C28925B
1488hajwhnbjdnd.exeC:\Users\admin\AppData\Local\Temp\zbmqv.exeexecutable
MD5:EB09C682903ECBD87F30B0366E008D8F
SHA256:C4B122F7BAB30363B472A3DFFB8A7C61604C0EC4719EBD233CCBAC8BE0951BE1
1488hajwhnbjdnd.exeC:\Users\admin\AppData\Local\Temp\droevlgslqpexoaui.exeexecutable
MD5:512052E4FCD0C226BD78BA87503565E1
SHA256:0E8B37D943C42977AB950CC26F3606F27FAF6941C35998630B5D4E719C28925B
1488hajwhnbjdnd.exeC:\Users\admin\AppData\Local\Temp\wjfukztewaymeufy.exeexecutable
MD5:512052E4FCD0C226BD78BA87503565E1
SHA256:0E8B37D943C42977AB950CC26F3606F27FAF6941C35998630B5D4E719C28925B
1488hajwhnbjdnd.exeC:\Users\admin\AppData\Local\Temp\xnmexpmavcdupiwsikc.exeexecutable
MD5:512052E4FCD0C226BD78BA87503565E1
SHA256:0E8B37D943C42977AB950CC26F3606F27FAF6941C35998630B5D4E719C28925B
5984zbmqv.exeC:\Users\admin\AppData\Local\VirtualStore\Windows\edlmopvswmwwaczedopwpzno.zhibinary
MD5:60A8B96C76041736F3FAD73853E7AB0B
SHA256:1781AA0C29D6FA36CD1A52F7EABFFE5323EDA0FCDDF4561E09C2021974332180
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
52
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4824
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
4920
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
4920
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1448
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
184.30.17.189:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
40.126.32.76:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2092
svchost.exe
40.126.32.76:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
go.microsoft.com
  • 184.30.17.189
whitelisted
login.live.com
  • 40.126.32.76
  • 20.190.160.22
  • 40.126.32.138
  • 40.126.32.133
  • 40.126.32.140
  • 40.126.32.134
  • 20.190.160.14
  • 20.190.160.17
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
google.com
  • 142.250.185.110
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
arc.msn.com
  • 20.31.169.57
whitelisted
fd.api.iris.microsoft.com
  • 20.103.156.88
whitelisted
browser.pipe.aria.microsoft.com
  • 20.42.65.94
whitelisted

Threats

No threats detected
No debug info