| File name: | Smart Tag.exe |
| Full analysis: | https://app.any.run/tasks/68ed6c94-eb77-4e2d-8c0a-77126c8e5c13 |
| Verdict: | Malicious activity |
| Analysis date: | October 05, 2024, 01:24:22 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 512052E4FCD0C226BD78BA87503565E1 |
| SHA1: | 01713BD80F21B9C9895E53D409C6C9A06F2225E3 |
| SHA256: | 0E8B37D943C42977AB950CC26F3606F27FAF6941C35998630B5D4E719C28925B |
| SSDEEP: | 24576:QxufVbSTjCczCgTFWcZhdVIHl7OoC8HdFJ6:QxudbSTjCczCgTFWcZhdVIHl7OoC8Hdy |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2009:04:20 17:36:21+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 7.1 |
| CodeSize: | 24576 |
| InitializedDataSize: | 442368 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x2865 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 832 | "regedit.exe" "C:\Users\admin\AppData\Local\Temp\djygpxkoz.reg" | C:\Windows\SysWOW64\regedit.exe | zbmqv.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Editor Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1488 | "C:\Users\admin\AppData\Local\Temp\hajwhnbjdnd.exe" "c:\users\admin\appdata\local\temp\smart tag.exe*" | C:\Users\admin\AppData\Local\Temp\hajwhnbjdnd.exe | Smart Tag.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1568 | "regedit.exe" "C:\Users\admin\AppData\Local\Temp\djygpxkoz.reg" | C:\Windows\SysWOW64\regedit.exe | zbmqv.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Editor Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1656 | "regedit.exe" "C:\Users\admin\AppData\Local\Temp\djygpxkoz.reg" | C:\Windows\SysWOW64\regedit.exe | — | zbmqv.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Editor Exit code: 3221226540 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1840 | "regedit.exe" "C:\Users\admin\AppData\Local\Temp\djygpxkoz.reg" | C:\Windows\SysWOW64\regedit.exe | — | zbmqv.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Editor Exit code: 3221226540 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2064 | "regedit.exe" "C:\Users\admin\AppData\Local\Temp\djygpxkoz.reg" | C:\Windows\SysWOW64\regedit.exe | zbmqv.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Editor Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2252 | "regedit.exe" "C:\Users\admin\AppData\Local\Temp\djygpxkoz.reg" | C:\Windows\SysWOW64\regedit.exe | — | zbmqv.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Editor Exit code: 3221226540 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2264 | "regedit.exe" "C:\Users\admin\AppData\Local\Temp\djygpxkoz.reg" | C:\Windows\SysWOW64\regedit.exe | — | zbmqv.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Editor Exit code: 3221226540 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2448 | "regedit.exe" "C:\Users\admin\AppData\Local\Temp\djygpxkoz.reg" | C:\Windows\SysWOW64\regedit.exe | zbmqv.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Editor Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2456 | "regedit.exe" "C:\Users\admin\AppData\Local\Temp\djygpxkoz.reg" | C:\Windows\SysWOW64\regedit.exe | — | zbmqv.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Registry Editor Exit code: 3221226540 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (1488) hajwhnbjdnd.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System |
| Operation: | write | Name: | EnableLUA |
Value: 0 | |||
| (PID) Process: | (1488) hajwhnbjdnd.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | oxpamxnuiicm |
Value: mbzqizviciiyskxshi.exe | |||
| (PID) Process: | (1488) hajwhnbjdnd.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce |
| Operation: | write | Name: | nxqcpbsapqlwl |
Value: mbzqizviciiyskxshi.exe . | |||
| (PID) Process: | (1488) hajwhnbjdnd.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | rdymbpisjmjwncm |
Value: droevlgslqpexoaui.exe | |||
| (PID) Process: | (1488) hajwhnbjdnd.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce |
| Operation: | write | Name: | wjfukztewaymeufy |
Value: mbzqizviciiyskxshi.exe . | |||
| (PID) Process: | (1488) hajwhnbjdnd.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | mbzqizviciiyskxshi |
Value: C:\Users\admin\AppData\Local\Temp\zrsmhbaqnwzspkayquooa.exe | |||
| (PID) Process: | (1488) hajwhnbjdnd.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce |
| Operation: | write | Name: | droevlgslqpexoaui |
Value: C:\Users\admin\AppData\Local\Temp\kbbuohfuqyasoixulohg.exe . | |||
| (PID) Process: | (1488) hajwhnbjdnd.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | oxpamxnuiicm |
Value: C:\Users\admin\AppData\Local\Temp\kbbuohfuqyasoixulohg.exe | |||
| (PID) Process: | (1488) hajwhnbjdnd.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce |
| Operation: | write | Name: | nxqcpbsapqlwl |
Value: C:\Users\admin\AppData\Local\Temp\zrsmhbaqnwzspkayquooa.exe . | |||
| (PID) Process: | (1488) hajwhnbjdnd.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System |
| Operation: | write | Name: | DisableRegistryTools |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4804 | Smart Tag.exe | C:\Users\admin\AppData\Local\Temp\hajwhnbjdnd.exe | executable | |
MD5:EB09C682903ECBD87F30B0366E008D8F | SHA256:C4B122F7BAB30363B472A3DFFB8A7C61604C0EC4719EBD233CCBAC8BE0951BE1 | |||
| 1488 | hajwhnbjdnd.exe | C:\Users\admin\AppData\Local\Temp\zrsmhbaqnwzspkayquooa.exe | executable | |
MD5:512052E4FCD0C226BD78BA87503565E1 | SHA256:0E8B37D943C42977AB950CC26F3606F27FAF6941C35998630B5D4E719C28925B | |||
| 1488 | hajwhnbjdnd.exe | C:\Users\admin\AppData\Local\Temp\kbbuohfuqyasoixulohg.exe | executable | |
MD5:512052E4FCD0C226BD78BA87503565E1 | SHA256:0E8B37D943C42977AB950CC26F3606F27FAF6941C35998630B5D4E719C28925B | |||
| 1488 | hajwhnbjdnd.exe | C:\Users\admin\AppData\Local\Temp\mbzqizviciiyskxshi.exe | executable | |
MD5:512052E4FCD0C226BD78BA87503565E1 | SHA256:0E8B37D943C42977AB950CC26F3606F27FAF6941C35998630B5D4E719C28925B | |||
| 1488 | hajwhnbjdnd.exe | C:\Users\admin\AppData\Local\Temp\qjlgcxxomwausofexcxylp.exe | executable | |
MD5:512052E4FCD0C226BD78BA87503565E1 | SHA256:0E8B37D943C42977AB950CC26F3606F27FAF6941C35998630B5D4E719C28925B | |||
| 1488 | hajwhnbjdnd.exe | C:\Users\admin\AppData\Local\Temp\zbmqv.exe | executable | |
MD5:EB09C682903ECBD87F30B0366E008D8F | SHA256:C4B122F7BAB30363B472A3DFFB8A7C61604C0EC4719EBD233CCBAC8BE0951BE1 | |||
| 1488 | hajwhnbjdnd.exe | C:\Users\admin\AppData\Local\Temp\droevlgslqpexoaui.exe | executable | |
MD5:512052E4FCD0C226BD78BA87503565E1 | SHA256:0E8B37D943C42977AB950CC26F3606F27FAF6941C35998630B5D4E719C28925B | |||
| 1488 | hajwhnbjdnd.exe | C:\Users\admin\AppData\Local\Temp\wjfukztewaymeufy.exe | executable | |
MD5:512052E4FCD0C226BD78BA87503565E1 | SHA256:0E8B37D943C42977AB950CC26F3606F27FAF6941C35998630B5D4E719C28925B | |||
| 1488 | hajwhnbjdnd.exe | C:\Users\admin\AppData\Local\Temp\xnmexpmavcdupiwsikc.exe | executable | |
MD5:512052E4FCD0C226BD78BA87503565E1 | SHA256:0E8B37D943C42977AB950CC26F3606F27FAF6941C35998630B5D4E719C28925B | |||
| 5984 | zbmqv.exe | C:\Users\admin\AppData\Local\VirtualStore\Windows\edlmopvswmwwaczedopwpzno.zhi | binary | |
MD5:60A8B96C76041736F3FAD73853E7AB0B | SHA256:1781AA0C29D6FA36CD1A52F7EABFFE5323EDA0FCDDF4561E09C2021974332180 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
— | — | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4824 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
4920 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
4920 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1448 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
— | — | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
— | — | 184.30.17.189:443 | go.microsoft.com | AKAMAI-AS | DE | whitelisted |
— | — | 40.126.32.76:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
— | — | 40.113.110.67:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2092 | svchost.exe | 40.126.32.76:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
google.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
arc.msn.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
browser.pipe.aria.microsoft.com |
| whitelisted |