File name:

0f3743781a2904dbabae873bc363c61a04ee92eeedb1569be78e847f9cca536b.exe

Full analysis: https://app.any.run/tasks/ee7c8a2d-8cf6-4b27-a6bd-e922f4464372
Verdict: Malicious activity
Analysis date: March 20, 2024, 11:22:40
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

AA270811CF303DAC8B74A7992209BB58

SHA1:

7906282DF70367DD18F318E88FC4330D50D7FF51

SHA256:

0F3743781A2904DBABAE873BC363C61A04EE92EEEDB1569BE78E847F9CCA536B

SSDEEP:

49152:VDKwy06A6wUZcR5mrnkBN8CmZDh/BCKUVwAGh2uGKQuYQJVL6pdS5yeO3uXc:VDKwy06VwUZcR5iKyxlwKrAGh2jKQuYt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • 0f3743781a2904dbabae873bc363c61a04ee92eeedb1569be78e847f9cca536b.exe (PID: 6484)
      • setup.exe (PID: 6360)
    • Actions looks like stealing of personal data

      • EacCleaner.exe (PID: 1640)
  • SUSPICIOUS

    • Changes the title of the Internet Explorer window

      • EacCleaner.exe (PID: 1640)
    • Changes the Home page of Internet Explorer

      • EacCleaner.exe (PID: 1640)
    • Creates file in the systems drive root

      • EacCleaner.exe (PID: 1640)
    • Executes application which crashes

      • EacCleaner.exe (PID: 1640)
    • Executable content was dropped or overwritten

      • 0f3743781a2904dbabae873bc363c61a04ee92eeedb1569be78e847f9cca536b.exe (PID: 6484)
      • setup.exe (PID: 6360)
  • INFO

    • Checks supported languages

      • setup.exe (PID: 6360)
      • EacCleaner.exe (PID: 5488)
      • 0f3743781a2904dbabae873bc363c61a04ee92eeedb1569be78e847f9cca536b.exe (PID: 6484)
      • EacCleaner.exe (PID: 1640)
    • Checks proxy server information

      • WerFault.exe (PID: 6588)
    • Creates files in the program directory

      • setup.exe (PID: 6360)
    • Create files in a temporary directory

      • 0f3743781a2904dbabae873bc363c61a04ee92eeedb1569be78e847f9cca536b.exe (PID: 6484)
      • EacCleaner.exe (PID: 1640)
    • Reads the machine GUID from the registry

      • EacCleaner.exe (PID: 5488)
      • EacCleaner.exe (PID: 1640)
    • Creates files or folders in the user directory

      • WerFault.exe (PID: 6588)
    • Reads the software policy settings

      • WerFault.exe (PID: 6588)
    • Reads the computer name

      • EacCleaner.exe (PID: 1640)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:02:19 18:32:36+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 81408
InitializedDataSize: 66560
UninitializedDataSize: -
EntryPoint: 0xcd95
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.50
ProductVersionNumber: 1.0.0.50
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: eAcceleration Corp
FileDescription: StopSign Installer
FileVersion: 1, 0, 0, 50
InternalName: eAc Installer
LegalCopyright: Copyright© 2000-2010 eAcceleration Corp. All Rights Reserved.
LegalTrademarks: ...
OriginalFileName: sfx.exe
PrivateBuild: ...
ProductName: StopSign Installer
ProductVersion: 1, 0, 0, 50
SpecialBuild: ...
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
135
Monitored processes
7
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 0f3743781a2904dbabae873bc363c61a04ee92eeedb1569be78e847f9cca536b.exe setup.exe eaccleaner.exe no specs eaccleaner.exe werfault.exe slui.exe no specs 0f3743781a2904dbabae873bc363c61a04ee92eeedb1569be78e847f9cca536b.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1640C:\PROGRA~2\ACCELE~1\ANTI-V~1\CUSTOM~1\Eaccleaner.exeC:\Program Files (x86)\Acceleration Software\Anti-Virus\customcleaner\EacCleaner.exe
setup.exe
User:
admin
Company:
eAcceleration
Integrity Level:
HIGH
Description:
Custom Cure
Exit code:
3221225725
Version:
1, 0, 0, 7
Modules
Images
c:\program files (x86)\acceleration software\anti-virus\customcleaner\eaccleaner.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
5488C:\Users\admin\AppData\Local\Temp\EAC406~1\Eaccleaner.exe -dC:\Users\admin\AppData\Local\Temp\EAC4069794111_00000000\EacCleaner.exesetup.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\eac4069794111_00000000\eaccleaner.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shlwapi.dll
6360C:\Users\admin\AppData\Local\Temp\EAC4069794111_00000000\setup.exe /Cmd C:\Users\admin\AppData\Local\Temp\0F3743~1.EXE "C:\Users\admin\AppData\Local\Temp\0f3743781a2904dbabae873bc363c61a04ee92eeedb1569be78e847f9cca536b.exe" C:\Users\admin\AppData\Local\Temp\EAC4069794111_00000000\setup.exe
0f3743781a2904dbabae873bc363c61a04ee92eeedb1569be78e847f9cca536b.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\eac4069794111_00000000\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\acgenral.dll
6480"C:\Users\admin\AppData\Local\Temp\0f3743781a2904dbabae873bc363c61a04ee92eeedb1569be78e847f9cca536b.exe" C:\Users\admin\AppData\Local\Temp\0f3743781a2904dbabae873bc363c61a04ee92eeedb1569be78e847f9cca536b.exeexplorer.exe
User:
admin
Company:
eAcceleration Corp
Integrity Level:
MEDIUM
Description:
StopSign Installer
Exit code:
3221226540
Version:
1, 0, 0, 50
Modules
Images
c:\users\admin\appdata\local\temp\0f3743781a2904dbabae873bc363c61a04ee92eeedb1569be78e847f9cca536b.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6484"C:\Users\admin\AppData\Local\Temp\0f3743781a2904dbabae873bc363c61a04ee92eeedb1569be78e847f9cca536b.exe" C:\Users\admin\AppData\Local\Temp\0f3743781a2904dbabae873bc363c61a04ee92eeedb1569be78e847f9cca536b.exe
explorer.exe
User:
admin
Company:
eAcceleration Corp
Integrity Level:
HIGH
Description:
StopSign Installer
Exit code:
0
Version:
1, 0, 0, 50
Modules
Images
c:\users\admin\appdata\local\temp\0f3743781a2904dbabae873bc363c61a04ee92eeedb1569be78e847f9cca536b.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6588C:\WINDOWS\SysWOW64\WerFault.exe -u -p 1640 -s 3780C:\Windows\SysWOW64\WerFault.exe
EacCleaner.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.1081 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
6960C:\WINDOWS\System32\slui.exe -EmbeddingC:\Windows\System32\slui.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Activation Client
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\slui.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
Total events
5 424
Read events
5 356
Write events
56
Delete events
12

Modification events

(PID) Process:(1640) EacCleaner.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:Binkiland
Value:
(PID) Process:(1640) EacCleaner.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:Binkiland
Value:
(PID) Process:(1640) EacCleaner.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\RunOnce
Operation:delete valueName:Binkiland
Value:
(PID) Process:(1640) EacCleaner.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce
Operation:delete valueName:Binkiland
Value:
(PID) Process:(1640) EacCleaner.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main
Operation:writeName:Default_Page_URL
Value:
(PID) Process:(1640) EacCleaner.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main
Operation:writeName:Default_Search_URL
Value:
(PID) Process:(1640) EacCleaner.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main
Operation:writeName:Search Bar
Value:
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
(PID) Process:(1640) EacCleaner.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main
Operation:writeName:Search Page
Value:
http://www.microsoft.com/isapi/redir.dll?prd=ie&ar=iesearch
(PID) Process:(1640) EacCleaner.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Main
Operation:writeName:Start Page
Value:
about:blank
(PID) Process:(1640) EacCleaner.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Internet Explorer\Search
Operation:writeName:CustomizeSearch
Value:
http://ie.search.msn.com/{SUB_RFC1766}/srchasst/srchcust.htm
Executable files
10
Suspicious files
6
Text files
5
Unknown types
1

Dropped files

PID
Process
Filename
Type
64840f3743781a2904dbabae873bc363c61a04ee92eeedb1569be78e847f9cca536b.exeC:\Users\admin\AppData\Local\Temp\EAC4069794111_00000000\EacCleaner.exeexecutable
MD5:E59296FBD02590C3B596C45E4F0FB1C6
SHA256:1E9574F3E8C5013F971D8FA9DBA0DFA56466F1A06D44E95C83D149B9041EE380
64840f3743781a2904dbabae873bc363c61a04ee92eeedb1569be78e847f9cca536b.exeC:\Users\admin\AppData\Local\Temp\EAC4069794111_00000000\stops_dlg_header_tm.gifbinary
MD5:C415DBA8F9A7FC0939E50460DA171AC1
SHA256:300B17E374D0170F7D4B8AFEFE09D57AEAA4354B952026305E7FCFDFA5A17FF3
6588WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Eaccleaner.exe_0cac887ec1aa5c616a52361fcff84bf8b851998_4c3c3855_0a0367fb-854a-48b4-a548-5a111d7af965\Report.wer
MD5:
SHA256:
64840f3743781a2904dbabae873bc363c61a04ee92eeedb1569be78e847f9cca536b.exeC:\Users\admin\AppData\Local\Temp\EAC4069794111_00000000\stops_dlg_header_tl.gifbinary
MD5:ADDD5DB15ABAB9EFE2426177913C175C
SHA256:81D2F3AC9A5024AB72F71C6C4DD6D39A8D87E7383249FD63287108CEE9668220
6360setup.exeC:\PROGRA~2\ACCELE~1\ANTI-V~1\CUSTOM~1\vclnr.dllexecutable
MD5:93ED06BFE1454A396824A638C2BB89F1
SHA256:433368DB62ED5320C639FBF39106BA6C7C262211C2D9CDB845C86B56A985E6F4
6360setup.exeC:\PROGRA~2\ACCELE~1\ANTI-V~1\CUSTOM~1\EacCleaner.exeexecutable
MD5:E59296FBD02590C3B596C45E4F0FB1C6
SHA256:1E9574F3E8C5013F971D8FA9DBA0DFA56466F1A06D44E95C83D149B9041EE380
64840f3743781a2904dbabae873bc363c61a04ee92eeedb1569be78e847f9cca536b.exeC:\Users\admin\AppData\Local\Temp\EAC4069794111_00000000\setup.exeexecutable
MD5:3B81D4123064A71453E6CB120A695C8E
SHA256:320EC75AAD0ED0C77A9EB13442F97FA38847230F33BC7FE6352075CCC0C524E1
6360setup.exeC:\PROGRA~2\ACCELE~1\ANTI-V~1\CUSTOM~1\setup.iniini
MD5:27D6F0C769F6FCB4D31ABAEFEE7AA41B
SHA256:0C898B0BDF2DDCDEA1813E701BCD2BFCE3C5204F62982BAB40C3932675DD16CA
64840f3743781a2904dbabae873bc363c61a04ee92eeedb1569be78e847f9cca536b.exeC:\Users\admin\AppData\Local\Temp\EAC4069794111_00000000\vclnr.dllexecutable
MD5:93ED06BFE1454A396824A638C2BB89F1
SHA256:433368DB62ED5320C639FBF39106BA6C7C262211C2D9CDB845C86B56A985E6F4
6360setup.exeC:\PROGRA~2\ACCELE~1\ANTI-V~1\CUSTOM~1\setup.exeexecutable
MD5:3B81D4123064A71453E6CB120A695C8E
SHA256:320EC75AAD0ED0C77A9EB13442F97FA38847230F33BC7FE6352075CCC0C524E1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
31
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3996
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
unknown
6296
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D
unknown
binary
471 b
unknown
7128
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
binary
409 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4828
svchost.exe
239.255.255.250:1900
unknown
5508
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
3996
svchost.exe
40.126.32.74:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
1280
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
3996
svchost.exe
192.229.221.95:80
EDGECAST
US
unknown
6588
WerFault.exe
13.89.179.12:443
umwatson.events.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3996
svchost.exe
40.126.32.138:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1528
backgroundTaskHost.exe
184.86.251.21:443
www.bing.com
Akamai International B.V.
DE
unknown
1528
backgroundTaskHost.exe
184.86.251.25:443
www.bing.com
Akamai International B.V.
DE
unknown
7128
SIHClient.exe
40.127.169.103:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
whitelisted
umwatson.events.data.microsoft.com
  • 13.89.179.12
whitelisted
www.bing.com
  • 184.86.251.21
  • 184.86.251.25
  • 184.86.251.16
  • 184.86.251.19
  • 184.86.251.18
  • 184.86.251.20
  • 184.86.251.24
  • 184.86.251.22
  • 184.86.251.23
whitelisted
slscr.update.microsoft.com
  • 40.127.169.103
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted
arc.msn.com
  • 20.223.36.55
whitelisted
activation-v2.sls.microsoft.com
  • 40.91.76.224
whitelisted
nexusrules.officeapps.live.com
  • 52.111.243.31
whitelisted

Threats

No threats detected
No debug info