File name:

atom.exe

Full analysis: https://app.any.run/tasks/9335209c-3de2-44bf-8d05-2b1f74d5a3e2
Verdict: Malicious activity
Analysis date: January 13, 2024, 18:13:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

59F2AC79F77D882EEF0AD3A9AE12C78B

SHA1:

4855E83407256EDCEE2B131542CE271673FA274A

SHA256:

1672C62639293577DB5745693CB8A0C596A6B3882BD654A04E9DB9F6734221B3

SSDEEP:

49152:33Mn23dXnvwj5Ju7SMpGcuMUdlEe9BxIklWMrD5raghxKtDCwgWAyuFf:33Mn23hnvwFkODVP6qDBxKtDCwMyIf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • atom.exe (PID: 2184)
      • lrunner0.exe (PID: 956)
      • setup.exe (PID: 696)
    • Steals credentials from Web Browsers

      • atom.exe (PID: 2644)
    • Actions looks like stealing of personal data

      • atom.exe (PID: 2644)
      • atom.exe (PID: 1816)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • atom.exe (PID: 2184)
      • lrunner0.exe (PID: 956)
      • setup.exe (PID: 696)
    • Starts itself from another location

      • atom.exe (PID: 2184)
    • Reads the Internet Settings

      • loader.exe (PID: 116)
      • setup.exe (PID: 696)
      • atom.exe (PID: 2644)
    • Reads Microsoft Outlook installation path

      • loader.exe (PID: 116)
    • Reads settings of System Certificates

      • loader.exe (PID: 116)
      • setup.exe (PID: 696)
      • atom.exe (PID: 2644)
    • Reads Internet Explorer settings

      • loader.exe (PID: 116)
    • Checks Windows Trust Settings

      • setup.exe (PID: 696)
    • Reads security settings of Internet Explorer

      • setup.exe (PID: 696)
    • The process creates files with name similar to system file names

      • setup.exe (PID: 696)
    • Application launched itself

      • atom.exe (PID: 2644)
      • setup.exe (PID: 696)
      • atom.exe (PID: 1924)
      • setup.exe (PID: 3000)
    • Loads DLL from Mozilla Firefox

      • atom.exe (PID: 1816)
    • Reads browser cookies

      • atom.exe (PID: 1816)
    • Reads Mozilla Firefox installation path

      • atom.exe (PID: 2644)
  • INFO

    • Checks supported languages

      • atom.exe (PID: 2184)
      • loader.exe (PID: 116)
      • lrunner0.exe (PID: 956)
      • setup.exe (PID: 696)
      • setup.exe (PID: 2000)
      • atom.exe (PID: 1924)
      • atom.exe (PID: 2644)
      • atom.exe (PID: 2436)
      • atom.exe (PID: 1812)
      • atom.exe (PID: 2532)
      • atom.exe (PID: 2852)
      • atom.exe (PID: 2520)
      • atom.exe (PID: 2576)
      • atom.exe (PID: 2320)
      • atom.exe (PID: 1860)
      • atom.exe (PID: 2800)
      • atom.exe (PID: 1932)
      • atom.exe (PID: 2940)
      • atom.exe (PID: 3016)
      • atom.exe (PID: 2824)
      • atom.exe (PID: 3012)
      • atom.exe (PID: 3040)
      • atom.exe (PID: 1408)
      • atom.exe (PID: 3056)
      • atom.exe (PID: 2752)
      • atom.exe (PID: 3220)
      • atom.exe (PID: 3028)
      • atom.exe (PID: 2820)
      • atom.exe (PID: 3420)
      • atom.exe (PID: 3664)
      • atom.exe (PID: 3676)
      • atom.exe (PID: 1236)
      • atom.exe (PID: 1736)
      • atom.exe (PID: 848)
      • atom.exe (PID: 2000)
      • atom.exe (PID: 2428)
      • atom.exe (PID: 3832)
      • atom.exe (PID: 664)
      • atom.exe (PID: 2040)
      • setup.exe (PID: 3000)
      • atom.exe (PID: 1824)
      • atom.exe (PID: 3276)
      • setup.exe (PID: 4084)
      • atom.exe (PID: 1816)
      • atom.exe (PID: 956)
      • atom.exe (PID: 2268)
      • atom.exe (PID: 2460)
      • atom.exe (PID: 3096)
      • atom.exe (PID: 1836)
      • atom.exe (PID: 3772)
      • atom.exe (PID: 2156)
      • atom.exe (PID: 3696)
      • atom.exe (PID: 3032)
      • atom.exe (PID: 2652)
      • atom.exe (PID: 3652)
    • Create files in a temporary directory

      • atom.exe (PID: 2184)
      • loader.exe (PID: 116)
      • lrunner0.exe (PID: 956)
      • atom.exe (PID: 2644)
      • atom.exe (PID: 1816)
    • Reads the machine GUID from the registry

      • loader.exe (PID: 116)
      • setup.exe (PID: 696)
      • atom.exe (PID: 2644)
      • atom.exe (PID: 1736)
      • atom.exe (PID: 2040)
      • atom.exe (PID: 664)
      • atom.exe (PID: 3832)
      • atom.exe (PID: 3276)
      • atom.exe (PID: 3096)
      • atom.exe (PID: 3032)
      • atom.exe (PID: 2156)
    • Reads the computer name

      • loader.exe (PID: 116)
      • lrunner0.exe (PID: 956)
      • setup.exe (PID: 696)
      • atom.exe (PID: 2644)
      • atom.exe (PID: 1924)
      • atom.exe (PID: 2320)
      • atom.exe (PID: 1860)
      • atom.exe (PID: 2532)
      • atom.exe (PID: 3420)
      • atom.exe (PID: 1736)
      • atom.exe (PID: 2040)
      • atom.exe (PID: 664)
      • atom.exe (PID: 3832)
      • setup.exe (PID: 3000)
      • atom.exe (PID: 1816)
      • atom.exe (PID: 3276)
      • atom.exe (PID: 3096)
      • atom.exe (PID: 3032)
      • atom.exe (PID: 2156)
    • Creates files in the program directory

      • loader.exe (PID: 116)
    • Checks proxy server information

      • loader.exe (PID: 116)
      • setup.exe (PID: 696)
    • Creates files or folders in the user directory

      • loader.exe (PID: 116)
      • setup.exe (PID: 2000)
      • setup.exe (PID: 696)
      • atom.exe (PID: 2644)
      • atom.exe (PID: 2320)
      • setup.exe (PID: 3000)
    • Process checks computer location settings

      • atom.exe (PID: 1812)
      • atom.exe (PID: 2644)
      • atom.exe (PID: 2436)
      • atom.exe (PID: 2940)
      • atom.exe (PID: 3040)
      • atom.exe (PID: 3056)
      • atom.exe (PID: 3016)
      • atom.exe (PID: 1932)
      • atom.exe (PID: 2520)
      • atom.exe (PID: 2852)
      • atom.exe (PID: 3676)
      • atom.exe (PID: 3028)
      • atom.exe (PID: 2820)
      • atom.exe (PID: 3664)
      • atom.exe (PID: 1236)
      • atom.exe (PID: 1408)
      • atom.exe (PID: 2824)
      • atom.exe (PID: 3012)
      • atom.exe (PID: 2000)
      • atom.exe (PID: 1824)
      • atom.exe (PID: 956)
      • atom.exe (PID: 2268)
      • atom.exe (PID: 2460)
      • atom.exe (PID: 1836)
      • atom.exe (PID: 2652)
      • atom.exe (PID: 3652)
    • Process checks whether UAC notifications are on

      • atom.exe (PID: 2644)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:12:22 09:05:10+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 376320
InitializedDataSize: 614400
UninitializedDataSize: -
EntryPoint: 0x23466
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 7.0.0.133
ProductVersionNumber: 7.0.0.133
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: VK
FileDescription: Atom Browser
InternalName: Atom Browser
OriginalFileName: Atom Browser
ProductName: Atom Browser
FileVersion: 7.0.0.133
ProductVersion: 7.0.0.133
LegalCopyright: Copyright 2021
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
96
Monitored processes
55
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start atom.exe loader.exe lrunner0.exe setup.exe setup.exe no specs atom.exe atom.exe no specs atom.exe no specs atom.exe atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs setup.exe setup.exe no specs atom.exe atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Users\admin\AppData\Local\Temp\\mr914906\loader.exe" --cpC:\Users\admin\AppData\Local\Temp\mr914906\loader.exe
atom.exe
User:
admin
Company:
VK
Integrity Level:
MEDIUM
Description:
Atom Browser
Exit code:
0
Version:
7.0.0.133
Modules
Images
c:\users\admin\appdata\local\temp\mr914906\loader.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
664"C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --field-trial-handle=944,8312308421703697060,9816522057838035789,131072 --enable-features=Dashboard,FeaturePromotion,Marusya,MyAdBlocker,TabSeparators,TaskbarCounter,ToolPanel,VkMusic,WhatsApp --disable-features=Channel,LocationBarPIP,MySearchContext,PwaSupport,UnnamedSearch --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=7672 /prefetch:8C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exeatom.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
MEDIUM
Description:
Atom
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\mail.ru\atom\application\atom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\mail.ru\atom\application\17.0.0.21\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
696"C:\Users\admin\AppData\Local\Temp\mr915671\CR_33FA1.tmp\setup.exe" --install-archive="C:\Users\admin\AppData\Local\Temp\mr915671\CR_33FA1.tmp\CHROME.PACKED.7Z" --arf=1 --rfr=520002 --ga-tid=UA-122680070-1 --ga-cid=GA1.2.1691028016.1643281304 --usagestats=1 --ext_params=IVID=3AYCeP0-qm2700000Z16H4I7%3A%3A%3A0-0-0-6f8308d%3ACAASEGHgAvLfvfiQj-kEZbuPgA8aYM4m01XaRlIlGt9KUmzdXYvCp7wfOc6bMXLH5uEhIOWGiN-Xl-MwRK25YkFzAqHbPySgdZNruhLfVm4nI0NOe-AoK7i2ivWps1q5AYa2iyi8gpBsC9ZBK7A_cPHqM68spg "--ntp-settings={\"feedEnable\": true, \"searchEnable\": true, \"historyEnable\": true, \"noteEnable\": false, \"widgetMailEnable\": true, \"trendsSuggestEnable\": true, \"youTubePanelEnable\": false}" --onboarding-pages=welcome,import,vk,shortcuts --rmt-onboarding=page-5 --force-restore-on-startup-last --enable-features=TaskbarCounter,Dashboard --disable-features=MySearchContextC:\Users\admin\AppData\Local\Temp\mr915671\CR_33FA1.tmp\setup.exe
lrunner0.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
MEDIUM
Description:
Atom Installer
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\temp\mr915671\cr_33fa1.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\oleaut32.dll
848"C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --field-trial-handle=944,8312308421703697060,9816522057838035789,131072 --enable-features=Dashboard,FeaturePromotion,Marusya,MyAdBlocker,TabSeparators,TaskbarCounter,ToolPanel,VkMusic,WhatsApp --disable-features=Channel,LocationBarPIP,MySearchContext,PwaSupport,UnnamedSearch --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=7648 /prefetch:8C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exeatom.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
LOW
Description:
Atom
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\mail.ru\atom\application\atom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\mail.ru\atom\application\17.0.0.21\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
956"C:\Users\admin\AppData\Local\Temp\\mr915671\lrunner0.exe" --arf=1 --rfr=520002 --ga-tid=UA-122680070-1 --ga-cid=GA1.2.1691028016.1643281304 --usagestats=1 --ext_params=IVID=3AYCeP0-qm2700000Z16H4I7%3A%3A%3A0-0-0-6f8308d%3ACAASEGHgAvLfvfiQj-kEZbuPgA8aYM4m01XaRlIlGt9KUmzdXYvCp7wfOc6bMXLH5uEhIOWGiN-Xl-MwRK25YkFzAqHbPySgdZNruhLfVm4nI0NOe-AoK7i2ivWps1q5AYa2iyi8gpBsC9ZBK7A_cPHqM68spg "--ntp-settings={\"feedEnable\": true, \"searchEnable\": true, \"historyEnable\": true, \"noteEnable\": false, \"widgetMailEnable\": true, \"trendsSuggestEnable\": true, \"youTubePanelEnable\": false}" --onboarding-pages=welcome,import,vk,shortcuts --rmt-onboarding=page-5 --force-restore-on-startup-last --enable-features=TaskbarCounter,Dashboard --disable-features=MySearchContextC:\Users\admin\AppData\Local\Temp\mr915671\lrunner0.exe
loader.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
MEDIUM
Description:
Atom Installer
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\temp\mr915671\lrunner0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
956"C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exe" --type=renderer --display-capture-permissions-policy-allowed --field-trial-handle=944,8312308421703697060,9816522057838035789,131072 --enable-features=Dashboard,FeaturePromotion,Marusya,MyAdBlocker,TabSeparators,TaskbarCounter,ToolPanel,VkMusic,WhatsApp --disable-features=Channel,LocationBarPIP,MySearchContext,PwaSupport,UnnamedSearch --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=39 --mojo-platform-channel-handle=2976 /prefetch:1C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exeatom.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
LOW
Description:
Atom
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\mail.ru\atom\application\atom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\mail.ru\atom\application\17.0.0.21\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1236"C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exe" --type=renderer --display-capture-permissions-policy-allowed --field-trial-handle=944,8312308421703697060,9816522057838035789,131072 --enable-features=Dashboard,FeaturePromotion,Marusya,MyAdBlocker,TabSeparators,TaskbarCounter,ToolPanel,VkMusic,WhatsApp --disable-features=Channel,LocationBarPIP,MySearchContext,PwaSupport,UnnamedSearch --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=26 --mojo-platform-channel-handle=3040 /prefetch:1C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exeatom.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
LOW
Description:
Atom
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\mail.ru\atom\application\atom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\mail.ru\atom\application\17.0.0.21\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1408"C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exe" --type=renderer --extension-process --display-capture-permissions-policy-allowed --field-trial-handle=944,8312308421703697060,9816522057838035789,131072 --enable-features=Dashboard,FeaturePromotion,Marusya,MyAdBlocker,TabSeparators,TaskbarCounter,ToolPanel,VkMusic,WhatsApp --disable-features=Channel,LocationBarPIP,MySearchContext,PwaSupport,UnnamedSearch --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --mojo-platform-channel-handle=3576 /prefetch:1C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exeatom.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
LOW
Description:
Atom
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\mail.ru\atom\application\atom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\mail.ru\atom\application\17.0.0.21\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1736"C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --field-trial-handle=944,8312308421703697060,9816522057838035789,131072 --enable-features=Dashboard,FeaturePromotion,Marusya,MyAdBlocker,TabSeparators,TaskbarCounter,ToolPanel,VkMusic,WhatsApp --disable-features=Channel,LocationBarPIP,MySearchContext,PwaSupport,UnnamedSearch --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=7580 /prefetch:8C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exeatom.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
MEDIUM
Description:
Atom
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\mail.ru\atom\application\atom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\mail.ru\atom\application\17.0.0.21\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1812"C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exe" --type=renderer --extension-process --display-capture-permissions-policy-allowed --field-trial-handle=944,8312308421703697060,9816522057838035789,131072 --enable-features=Dashboard,FeaturePromotion,Marusya,MyAdBlocker,TabSeparators,TaskbarCounter,ToolPanel,VkMusic,WhatsApp --disable-features=Channel,LocationBarPIP,MySearchContext,PwaSupport,UnnamedSearch --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2004 /prefetch:1C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exeatom.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
LOW
Description:
Atom
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\mail.ru\atom\application\atom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\mail.ru\atom\application\17.0.0.21\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
31 171
Read events
30 955
Write events
206
Delete events
10

Modification events

(PID) Process:(116) loader.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(116) loader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(116) loader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(116) loader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(116) loader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(116) loader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(116) loader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(696) setup.exeKey:HKEY_CURRENT_USER\Software\Mail.Ru\AtomInstaller
Operation:writeName:GUID
Value:
{6BCF5CEB-B270-477F-8D33-3F7AEBD6B5FD}
(PID) Process:(696) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(696) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
12
Suspicious files
452
Text files
137
Unknown types
4

Dropped files

PID
Process
Filename
Type
116loader.exeC:\Users\admin\AppData\Local\Temp\mr915671\lrunner0.exe
MD5:
SHA256:
956lrunner0.exeC:\Users\admin\AppData\Local\Temp\mr915671\CR_33FA1.tmp\CHROME.PACKED.7Z
MD5:
SHA256:
696setup.exeC:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\17.0.0.21\Installer\chrome.7z
MD5:
SHA256:
696setup.exeC:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\eventer.exe
MD5:
SHA256:
956lrunner0.exeC:\Users\admin\AppData\Local\Temp\mr915671\CR_33FA1.tmp\setup.exeexecutable
MD5:390497FB675CE11512FE92BDFE15F116
SHA256:D113B1E71A3FF049A10408C3555FE97988775A808C41833CCC79E20FAB935844
696setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157compressed
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89
SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8
2184atom.exeC:\Users\admin\AppData\Local\Temp\mr914906\loader.exeexecutable
MD5:59F2AC79F77D882EEF0AD3A9AE12C78B
SHA256:1672C62639293577DB5745693CB8A0C596A6B3882BD654A04E9DB9F6734221B3
116loader.exeC:\ProgramData\Mail.Ru\Idtext
MD5:8109EC1CBD8B9EF6116885D246B36056
SHA256:EEA107FC65A8EE0662C6B5857EEDE34EBDCFBBBE52B360ABCEA89A6EBF4A4DD8
696setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0DA515F703BB9B49479E8697ADB0B955_4136D3715888E22D65EBE484B233D81Bbinary
MD5:85A10904B86D6E60E856762E24EFF919
SHA256:C83A99DEA1A4EE30977A87735789C99D3CFEB00DC30FEB9F756D9A2C0A5BFD8E
2000setup.exeC:\Users\admin\AppData\Local\Mail.Ru\Atom\User Data\Crashpad\settings.datbinary
MD5:B52BFF3B1E58742FC66B6AB56DA8B6FA
SHA256:20CB3655EF82623F6B7634513DB9334E3A232DDC50A6276E999699E38851375B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
18
TCP/UDP connections
148
DNS requests
78
Threats
10

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
116
loader.exe
GET
204
95.163.50.150:80
http://mrds.mail.ru/update/2/version.txt?type=loader.req_check&tool=loader&BID=%7B6BCF5CEB-B270-477F-8D33-3F7AEBD6B5FD%7D&kind=atom&masterid=%7B7D6D87E4-2B0C-4961-96B7-84BBF0C45E4A%7D&rfr=&newrfr=520002&os=6.1&ver=7.0.0.133&IVID=3AYCeP0-qm2700000Z16H4I7%3A%3A%3A0-0-0-6f8308d%3ACAASEGHgAvLfvfiQj-kEZbuPgA8aYM4m01XaRlIlGt9KUmzdXYvCp7wfOc6bMXLH5uEhIOWGiN-Xl-MwRK25YkFzAqHbPySgdZNruhLfVm4nI0NOe-AoK7i2ivWps1q5AYa2iyi8gpBsC9ZBK7A_cPHqM68spg&send_stats=1&result=0
RU
unknown
116
loader.exe
GET
204
95.163.50.150:80
http://mrds.mail.ru/update/2/version.txt?type=loader.download_finished&tool=loader&BID=%7B6BCF5CEB-B270-477F-8D33-3F7AEBD6B5FD%7D&kind=atom&masterid=%7B7D6D87E4-2B0C-4961-96B7-84BBF0C45E4A%7D&rfr=&newrfr=520002&os=6.1&ver=7.0.0.133&IVID=3AYCeP0-qm2700000Z16H4I7%3A%3A%3A0-0-0-6f8308d%3ACAASEGHgAvLfvfiQj-kEZbuPgA8aYM4m01XaRlIlGt9KUmzdXYvCp7wfOc6bMXLH5uEhIOWGiN-Xl-MwRK25YkFzAqHbPySgdZNruhLfVm4nI0NOe-AoK7i2ivWps1q5AYa2iyi8gpBsC9ZBK7A_cPHqM68spg&send_stats=1&app=atom&error=0
RU
unknown
696
setup.exe
GET
200
184.24.77.182:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d8de85c850918a88
DE
compressed
4.66 Kb
unknown
696
setup.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCDQHuXxad%2F5c1K2Rl1mo%3D
unknown
binary
1.41 Kb
unknown
696
setup.exe
GET
200
104.18.20.226:80
http://ocsp2.globalsign.com/rootr3/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCDQHuXyId%2FGI71DM6hVc%3D
unknown
binary
1.40 Kb
unknown
116
loader.exe
GET
204
95.163.50.150:80
http://mrds.mail.ru/update/2/version.txt?type=loader.install_finished&tool=loader&BID=%7B6BCF5CEB-B270-477F-8D33-3F7AEBD6B5FD%7D&kind=atom&masterid=%7B7D6D87E4-2B0C-4961-96B7-84BBF0C45E4A%7D&rfr=&newrfr=520002&os=6.1&ver=7.0.0.133&IVID=3AYCeP0-qm2700000Z16H4I7%3A%3A%3A0-0-0-6f8308d%3ACAASEGHgAvLfvfiQj-kEZbuPgA8aYM4m01XaRlIlGt9KUmzdXYvCp7wfOc6bMXLH5uEhIOWGiN-Xl-MwRK25YkFzAqHbPySgdZNruhLfVm4nI0NOe-AoK7i2ivWps1q5AYa2iyi8gpBsC9ZBK7A_cPHqM68spg&send_stats=1&app=atom&result=0&error_code=0
RU
unknown
116
loader.exe
GET
204
95.163.50.150:80
http://mrds.mail.ru/update/2/version.txt?type=loader.exit&tool=loader&BID=%7B6BCF5CEB-B270-477F-8D33-3F7AEBD6B5FD%7D&kind=atom&masterid=%7B7D6D87E4-2B0C-4961-96B7-84BBF0C45E4A%7D&rfr=&newrfr=520002&os=6.1&ver=7.0.0.133&IVID=3AYCeP0-qm2700000Z16H4I7%3A%3A%3A0-0-0-6f8308d%3ACAASEGHgAvLfvfiQj-kEZbuPgA8aYM4m01XaRlIlGt9KUmzdXYvCp7wfOc6bMXLH5uEhIOWGiN-Xl-MwRK25YkFzAqHbPySgdZNruhLfVm4nI0NOe-AoK7i2ivWps1q5AYa2iyi8gpBsC9ZBK7A_cPHqM68spg&send_stats=1&result=0
RU
unknown
1080
svchost.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?532672b1a10842df
GB
unknown
856
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ANlaTV2JH2WK9RCoHi__mxg_1.0.6/S3ybLvFx94Hgn9pWLt24ug
US
unknown
856
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ANlaTV2JH2WK9RCoHi__mxg_1.0.6/S3ybLvFx94Hgn9pWLt24ug
US
binary
6.03 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
116
loader.exe
95.163.50.150:80
mrds.mail.ru
LLC VK
RU
unknown
4
System
192.168.100.255:138
whitelisted
116
loader.exe
142.250.186.142:443
www.google-analytics.com
GOOGLE
US
whitelisted
116
loader.exe
5.181.61.0:443
browser-asset.cdnmail.ru
LLC VK
RU
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
696
setup.exe
5.61.236.211:443
bs.browser.mail.ru
LLC VK
RU
unknown
696
setup.exe
184.24.77.182:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
696
setup.exe
104.18.20.226:80
ocsp.globalsign.com
CLOUDFLARENET
shared
2320
atom.exe
172.217.132.198:443
r1---sn-5hnednss.gvt1.com
unknown

DNS requests

Domain
IP
Reputation
mrds.mail.ru
  • 95.163.50.150
malicious
www.google-analytics.com
  • 142.250.186.142
whitelisted
browser-asset.cdnmail.ru
  • 5.181.61.0
unknown
bs.browser.mail.ru
  • 5.61.236.211
unknown
ctldl.windowsupdate.com
  • 184.24.77.182
  • 184.24.77.210
  • 184.24.77.200
  • 184.24.77.174
  • 184.24.77.205
  • 184.24.77.201
  • 93.184.221.240
  • 184.24.77.177
  • 184.24.77.193
  • 184.24.77.194
  • 184.24.77.186
  • 184.24.77.197
  • 184.24.77.203
  • 184.24.77.191
whitelisted
ocsp.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
ocsp2.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
data.browser.mail.ru
  • 5.61.236.211
unknown
redirector.gvt1.com
  • 142.250.184.238
whitelisted
clients2.google.com
  • 142.250.186.142
whitelisted

Threats

PID
Process
Class
Message
2320
atom.exe
Potential Corporate Privacy Violation
AV POLICY Observed TikTok Domain in TLS SNI (tiktok.com)
2320
atom.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
1080
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
1080
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com)
6 ETPRO signatures available at the full report
No debug info