File name:

1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exe

Full analysis: https://app.any.run/tasks/c8851403-f869-4979-a5b1-ec8529f0c78d
Verdict: Malicious activity
Analysis date: January 10, 2025, 19:35:33
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
tiwi
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

1B2A088D73132C8DE93AAF8BA6BAC7A0

SHA1:

2D530106544C2FECC8B7DC14BC27ACA9F2E03D7B

SHA256:

1672C49B05A9C954DFBF1E352B3D5BFFDA08550D5C76E0B2240A5713404C1AC6

SSDEEP:

1536:UE/nTk/l9GtUrjK9/MjfbbNDpUYQVVVVVV+VVVUMm:tTk/+DFYfb1aYQVVVVVV+VVVUv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • TIWI has been detected

      • 1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exe (PID: 6224)
    • Changes the autorun value in the registry

      • 1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exe (PID: 6224)
  • SUSPICIOUS

    • Changes the title of the Internet Explorer window

      • 1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exe (PID: 6224)
    • Changes the Home page of Internet Explorer

      • 1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exe (PID: 6224)
    • Executable content was dropped or overwritten

      • 1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exe (PID: 6224)
    • Creates file in the systems drive root

      • 1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exe (PID: 6224)
    • The process creates files with name similar to system file names

      • 1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exe (PID: 6224)
  • INFO

    • Creates files or folders in the user directory

      • 1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exe (PID: 6224)
    • Create files in a temporary directory

      • 1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exe (PID: 6224)
    • Checks supported languages

      • 1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exe (PID: 6224)
    • Failed to create an executable file in Windows directory

      • 1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exe (PID: 6224)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | kkrunchy compressed Win32 Executable (95.7)
.exe | DOS Executable Generic (4.2)

EXIF

EXE

Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: 22.7
OSVersion: 4
EntryPoint: 0x8101
UninitializedDataSize: 143360
InitializedDataSize: 24576
CodeSize: 36864
LinkerVersion: 3.189
PEType: PE32
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
TimeStamp: 0000:00:00 00:00:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
116
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exe

Process information

PID
CMD
Path
Indicators
Parent process
6224"C:\Users\admin\Desktop\1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exe" C:\Users\admin\Desktop\1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvbvm60.dll
Total events
81
Read events
57
Write events
24
Delete events
0

Modification events

(PID) Process:(6224) 1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exeKey:HKEY_CURRENT_USER\Control Panel\Desktop
Operation:writeName:SCRNSAVE.EXE
Value:
C:\WINDOWS\system32\tiwi.SCR
(PID) Process:(6224) 1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exeKey:HKEY_CURRENT_USER\Control Panel\Desktop
Operation:writeName:ScreenSaverIsSecure
Value:
0
(PID) Process:(6224) 1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exeKey:HKEY_CURRENT_USER\Control Panel\Desktop
Operation:writeName:ScreenSaveTimeOut
Value:
600
(PID) Process:(6224) 1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:tiwi
Value:
C:\WINDOWS\tiwi
(PID) Process:(6224) 1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:MSMSGS
Value:
C:\Users\admin\Local Settings\Application Data\WINDOWS\winlogon.exe
(PID) Process:(6224) 1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Logonadmin
Value:
C:\Users\admin\Local Settings\Application Data\WINDOWS\imoet.exe
(PID) Process:(6224) 1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:System Monitoring
Value:
C:\Users\admin\Local Settings\Application Data\WINDOWS\cute.exe
(PID) Process:(6224) 1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Operation:writeName:Start Page
Value:
http://www.google.com
(PID) Process:(6224) 1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Operation:writeName:Search Page
Value:
http://www.google.com
(PID) Process:(6224) 1672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main
Operation:writeName:Windows Title
Value:
Princess Tiwi is Here..
Executable files
6
Suspicious files
2
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
62241672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exeC:\Users\admin\AppData\Local\winlogon.exeexecutable
MD5:1B2A088D73132C8DE93AAF8BA6BAC7A0
SHA256:1672C49B05A9C954DFBF1E352B3D5BFFDA08550D5C76E0B2240A5713404C1AC6
62241672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exeC:\Users\admin\AppData\Local\WINDOWS\cute.exeexecutable
MD5:1B2A088D73132C8DE93AAF8BA6BAC7A0
SHA256:1672C49B05A9C954DFBF1E352B3D5BFFDA08550D5C76E0B2240A5713404C1AC6
62241672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exeC:\Users\admin\AppData\Local\smss.exeexecutable
MD5:1B2A088D73132C8DE93AAF8BA6BAC7A0
SHA256:1672C49B05A9C954DFBF1E352B3D5BFFDA08550D5C76E0B2240A5713404C1AC6
62241672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exeC:\Users\admin\AppData\Local\WINDOWS\lsass.exebinary
MD5:BD4ACDCB4EC5E0938F88380CC723A18F
SHA256:41D29F96C3242C1B07E5617DD3DA8F604146BA6C3451FD0EF2ED605A3D08C918
62241672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exeC:\Users\admin\AppData\Local\WINDOWS\winlogon.exeexecutable
MD5:1B2A088D73132C8DE93AAF8BA6BAC7A0
SHA256:1672C49B05A9C954DFBF1E352B3D5BFFDA08550D5C76E0B2240A5713404C1AC6
62241672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exeC:\Users\admin\AppData\Local\WINDOWS\imoet.exeexecutable
MD5:1B2A088D73132C8DE93AAF8BA6BAC7A0
SHA256:1672C49B05A9C954DFBF1E352B3D5BFFDA08550D5C76E0B2240A5713404C1AC6
62241672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exeC:\Users\admin\AppData\Local\WINDOWS\smss.exeexecutable
MD5:1B2A088D73132C8DE93AAF8BA6BAC7A0
SHA256:1672C49B05A9C954DFBF1E352B3D5BFFDA08550D5C76E0B2240A5713404C1AC6
62241672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exeC:\Users\admin\AppData\Local\Temp\~DFC9EAFA4FED793223.TMPbinary
MD5:B3650A6774FF5E807A4C625DCF907C00
SHA256:D5FED1F6C096ADE802BB1DC50B0AF719BFAD5A001701F6FA486F1D9CBCD13DCC
62241672c49b05a9c954dfbf1e352b3d5bffda08550d5c76e0b2240a5713404c1ac6.exeC:\Users\admin\AppData\Local\VirtualStore\present.txttext
MD5:8E3C734E8DD87D639FB51500D42694B5
SHA256:574A3A546332854D82E4F5B54CC5E8731FE9828E14E89A728BE7E53ED21F6BAD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
20
DNS requests
7
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4712
MoUsoCoreWorker.exe
GET
200
2.16.164.51:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
svchost.exe
GET
200
2.16.164.51:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
5496
svchost.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4712
MoUsoCoreWorker.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2.23.227.215:443
www.bing.com
Ooredoo Q.S.C.
QA
whitelisted
4
System
192.168.100.255:137
whitelisted
5496
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4712
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5496
svchost.exe
2.16.164.51:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
4712
MoUsoCoreWorker.exe
2.16.164.51:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
5496
svchost.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted
4712
MoUsoCoreWorker.exe
2.23.246.101:80
www.microsoft.com
Ooredoo Q.S.C.
QA
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 2.23.227.215
  • 2.23.227.208
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.238
whitelisted
crl.microsoft.com
  • 2.16.164.51
  • 2.16.164.98
  • 2.16.164.49
  • 2.16.164.88
  • 2.16.164.99
  • 2.16.164.40
  • 2.16.164.67
  • 2.16.164.97
  • 2.16.164.82
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted
self.events.data.microsoft.com
  • 52.168.117.168
whitelisted

Threats

No threats detected
No debug info