| File name: | rdpHelper.exe_ |
| Full analysis: | https://app.any.run/tasks/a3b783e8-fb00-4765-87da-73847ffe1e5f |
| Verdict: | Malicious activity |
| Threats: | DCrat, also known as Dark Crystal RAT, is a remote access trojan (RAT), which was first introduced in 2018. It is a modular malware that can be customized to perform different tasks. For instance, it can steal passwords, crypto wallet information, hijack Telegram and Steam accounts, and more. Attackers may use a variety of methods to distribute DCrat, but phishing email campaigns are the most common. |
| Analysis date: | November 02, 2023, 07:20:05 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 1E8B35B160FEB419CB6F58B915C11307 |
| SHA1: | 818CF033DE3B72E18B70CA832653E27E54A22302 |
| SHA256: | 13F25202CD0885DFDEB0C24E856A66A920E1FEB0FD87468F928768131C84AB8C |
| SSDEEP: | 49152:RbA3lgViq4EdTp49JkoIoAAeM4hSIW4hxSVkhl0FiHA9nIWAz/FiKJ86RSQMJ3lk:RbfV7dTpholAfhFByien5W8KJ5HMJ3g9 |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:12:01 19:00:55+01:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 201216 |
| InitializedDataSize: | 137728 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1ec40 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 148 | "powershell" -Command Add-MpPreference -ExclusionPath 'C:\Windows\ModemLogs\SearchIndexer.exe' | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | chainportruntime.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 528 | schtasks.exe /create /tn "cmdc" /sc MINUTE /mo 5 /tr "'C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\cmd.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 556 | schtasks.exe /create /tn "IMEDICTUPDATEI" /sc MINUTE /mo 11 /tr "'C:\MsagentIntoPerfCommon\IMEDICTUPDATE.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 712 | "powershell" -Command Add-MpPreference -ExclusionPath 'C:\Recovery\345b46fe-a9f9-11e7-a83c-e8a4f72b1d33\cmd.exe' | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | chainportruntime.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 916 | schtasks.exe /create /tn "wininitw" /sc MINUTE /mo 13 /tr "'C:\Program Files\Microsoft Office\CLIPART\PUB60COR\wininit.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 916 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --first-renderer-process --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2112 --field-trial-handle=1160,i,15269091311998428159,17485035996280840098,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1232 | "powershell" -Command Add-MpPreference -ExclusionPath 'C:\Windows\Panther\setup.exe\IMEDICTUPDATE.exe' | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | chainportruntime.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1344 | "C:\Program Files\Google\Chrome\Application\chrome.exe" --type=renderer --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2144 --field-trial-handle=1160,i,15269091311998428159,17485035996280840098,131072 /prefetch:1 | C:\Program Files\Google\Chrome\Application\chrome.exe | — | chrome.exe | |||||||||||
User: admin Company: Google LLC Integrity Level: LOW Description: Google Chrome Exit code: 0 Version: 109.0.5414.120 Modules
| |||||||||||||||
| 1604 | schtasks.exe /create /tn "IMEDICTUPDATEI" /sc MINUTE /mo 9 /tr "'C:\MsagentIntoPerfCommon\IMEDICTUPDATE.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1612 | "powershell" -Command Add-MpPreference -ExclusionPath 'C:\Program Files\Microsoft Office\CLIPART\PUB60COR\wininit.exe' | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | chainportruntime.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3436) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{A0B066CE-F2EF-45EA-8FF7-26F391F5C737}\{857FCC3A-07A0-40BD-B781-EBA324CC6E41} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3436) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{A0B066CE-F2EF-45EA-8FF7-26F391F5C737} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3436) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{622543A4-75A1-49AC-B1EB-13369586EEDA} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3512) rdpHelper.exe_.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3512) rdpHelper.exe_.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3512) rdpHelper.exe_.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3512) rdpHelper.exe_.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3412) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3412) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3412) wscript.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3756 | chainportruntime.exe | C:\Windows\Panther\setup.exe\dllhost.exe | executable | |
MD5:05B000A3F0E4A4370EFD644162D3685A | SHA256:50F5F76724C901E9A7A8688DCD9ACD00E5E8726C1DEDAF839B67E6E133CC0E12 | |||
| 3756 | chainportruntime.exe | C:\Windows\ModemLogs\SearchIndexer.exe | executable | |
MD5:05B000A3F0E4A4370EFD644162D3685A | SHA256:50F5F76724C901E9A7A8688DCD9ACD00E5E8726C1DEDAF839B67E6E133CC0E12 | |||
| 3756 | chainportruntime.exe | C:\Windows\ModemLogs\4a1145983886ca | text | |
MD5:0DB3122762B205583A613D4B7899849B | SHA256:7870C6BA4BD21CE7F74F291F1258BC7E455F49F2C01551741418B3DF18BD7FCF | |||
| 3756 | chainportruntime.exe | C:\Windows\Panther\setup.exe\1173b9a28a9c10 | text | |
MD5:636CEEA8FC5C1DE13440150105401EBA | SHA256:84D580631FD5F94FE8285849405F0B4DCBCE803E2C48AFDB8858263F2290678D | |||
| 3756 | chainportruntime.exe | C:\MSOCache\All Users\{90140000-001A-040C-0000-0000000FF1CE}-C\96094160f8fe35 | text | |
MD5:499F463ED5342A892912BDFFB87F828F | SHA256:D98F0466F0E28CD6E3D2C16AB13752CA28A0ADB796D36B793ECA92A1A7038FFC | |||
| 3756 | chainportruntime.exe | C:\MsagentIntoPerfCommon\IMEDICTUPDATE.exe | executable | |
MD5:05B000A3F0E4A4370EFD644162D3685A | SHA256:50F5F76724C901E9A7A8688DCD9ACD00E5E8726C1DEDAF839B67E6E133CC0E12 | |||
| 3512 | rdpHelper.exe_.exe | C:\MsagentIntoPerfCommon\gq1DoNGewQk1eSwuMtaNCess40r.bat | text | |
MD5:E3C9CBF2BC8B86B784E1263625CCC058 | SHA256:9611227D74D195C8814595A48213FEFDE2B15286A93B61175CCEC2DC0BFE1D0B | |||
| 3512 | rdpHelper.exe_.exe | C:\MsagentIntoPerfCommon\sPWugGHEh.vbe | binary | |
MD5:3DB9E950B0D9A5DDA15BD27437EF9932 | SHA256:B055E2B1DD6B4C79DB2239504463AC86E8BAF0CD79951E642D765779A9B8B112 | |||
| 3512 | rdpHelper.exe_.exe | C:\MsagentIntoPerfCommon\chainportruntime.exe | executable | |
MD5:05B000A3F0E4A4370EFD644162D3685A | SHA256:50F5F76724C901E9A7A8688DCD9ACD00E5E8726C1DEDAF839B67E6E133CC0E12 | |||
| 3756 | chainportruntime.exe | C:\MSOCache\All Users\{90140000-001A-040C-0000-0000000FF1CE}-C\taskeng.exe | executable | |
MD5:05B000A3F0E4A4370EFD644162D3685A | SHA256:50F5F76724C901E9A7A8688DCD9ACD00E5E8726C1DEDAF839B67E6E133CC0E12 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2316 | taskeng.exe | 80.78.247.7:80 | — | Domain names registrar REG.RU, Ltd | RU | unknown |
3732 | chrome.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3932 | chrome.exe | 142.250.186.109:443 | accounts.google.com | GOOGLE | US | whitelisted |
3932 | chrome.exe | 142.250.185.227:443 | clientservices.googleapis.com | GOOGLE | US | whitelisted |
3932 | chrome.exe | 142.250.186.68:443 | www.google.com | GOOGLE | US | whitelisted |
3932 | chrome.exe | 172.217.18.3:443 | update.googleapis.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
accounts.google.com |
| shared |
clientservices.googleapis.com |
| whitelisted |
www.google.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
optimizationguide-pa.googleapis.com |
| whitelisted |
dns.msftncsi.com |
| shared |