File name:

atom.exe

Full analysis: https://app.any.run/tasks/9335209c-3de2-44bf-8d05-2b1f74d5a3e2
Verdict: Malicious activity
Analysis date: January 13, 2024, 18:13:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

59F2AC79F77D882EEF0AD3A9AE12C78B

SHA1:

4855E83407256EDCEE2B131542CE271673FA274A

SHA256:

1672C62639293577DB5745693CB8A0C596A6B3882BD654A04E9DB9F6734221B3

SSDEEP:

49152:33Mn23dXnvwj5Ju7SMpGcuMUdlEe9BxIklWMrD5raghxKtDCwgWAyuFf:33Mn23hnvwFkODVP6qDBxKtDCwMyIf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • atom.exe (PID: 2184)
      • lrunner0.exe (PID: 956)
      • setup.exe (PID: 696)
    • Steals credentials from Web Browsers

      • atom.exe (PID: 2644)
    • Actions looks like stealing of personal data

      • atom.exe (PID: 1816)
      • atom.exe (PID: 2644)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • atom.exe (PID: 2184)
      • lrunner0.exe (PID: 956)
      • setup.exe (PID: 696)
    • Starts itself from another location

      • atom.exe (PID: 2184)
    • Reads settings of System Certificates

      • loader.exe (PID: 116)
      • setup.exe (PID: 696)
      • atom.exe (PID: 2644)
    • Reads the Internet Settings

      • loader.exe (PID: 116)
      • setup.exe (PID: 696)
      • atom.exe (PID: 2644)
    • Reads Internet Explorer settings

      • loader.exe (PID: 116)
    • Reads Microsoft Outlook installation path

      • loader.exe (PID: 116)
    • Application launched itself

      • setup.exe (PID: 696)
      • atom.exe (PID: 1924)
      • atom.exe (PID: 2644)
      • setup.exe (PID: 3000)
    • Reads security settings of Internet Explorer

      • setup.exe (PID: 696)
    • Checks Windows Trust Settings

      • setup.exe (PID: 696)
    • The process creates files with name similar to system file names

      • setup.exe (PID: 696)
    • Reads Mozilla Firefox installation path

      • atom.exe (PID: 2644)
    • Reads browser cookies

      • atom.exe (PID: 1816)
    • Loads DLL from Mozilla Firefox

      • atom.exe (PID: 1816)
  • INFO

    • Checks supported languages

      • atom.exe (PID: 2184)
      • loader.exe (PID: 116)
      • lrunner0.exe (PID: 956)
      • setup.exe (PID: 696)
      • atom.exe (PID: 2644)
      • setup.exe (PID: 2000)
      • atom.exe (PID: 1924)
      • atom.exe (PID: 2320)
      • atom.exe (PID: 2576)
      • atom.exe (PID: 1860)
      • atom.exe (PID: 2436)
      • atom.exe (PID: 2800)
      • atom.exe (PID: 1812)
      • atom.exe (PID: 2532)
      • atom.exe (PID: 2852)
      • atom.exe (PID: 2520)
      • atom.exe (PID: 2820)
      • atom.exe (PID: 1932)
      • atom.exe (PID: 2940)
      • atom.exe (PID: 3040)
      • atom.exe (PID: 2824)
      • atom.exe (PID: 3016)
      • atom.exe (PID: 3012)
      • atom.exe (PID: 1408)
      • atom.exe (PID: 2752)
      • atom.exe (PID: 3028)
      • atom.exe (PID: 3056)
      • atom.exe (PID: 3220)
      • atom.exe (PID: 3420)
      • atom.exe (PID: 3664)
      • atom.exe (PID: 3676)
      • atom.exe (PID: 1236)
      • atom.exe (PID: 848)
      • atom.exe (PID: 2428)
      • atom.exe (PID: 1736)
      • atom.exe (PID: 2000)
      • atom.exe (PID: 2040)
      • atom.exe (PID: 3832)
      • setup.exe (PID: 4084)
      • setup.exe (PID: 3000)
      • atom.exe (PID: 664)
      • atom.exe (PID: 1816)
      • atom.exe (PID: 3276)
      • atom.exe (PID: 3696)
      • atom.exe (PID: 1824)
      • atom.exe (PID: 3032)
      • atom.exe (PID: 956)
      • atom.exe (PID: 2268)
      • atom.exe (PID: 3096)
      • atom.exe (PID: 3772)
      • atom.exe (PID: 2652)
      • atom.exe (PID: 2156)
      • atom.exe (PID: 1836)
      • atom.exe (PID: 3652)
      • atom.exe (PID: 2460)
    • Create files in a temporary directory

      • atom.exe (PID: 2184)
      • loader.exe (PID: 116)
      • lrunner0.exe (PID: 956)
      • atom.exe (PID: 2644)
      • atom.exe (PID: 1816)
    • Reads the computer name

      • loader.exe (PID: 116)
      • lrunner0.exe (PID: 956)
      • setup.exe (PID: 696)
      • atom.exe (PID: 2644)
      • atom.exe (PID: 1924)
      • atom.exe (PID: 1860)
      • atom.exe (PID: 2320)
      • atom.exe (PID: 2532)
      • atom.exe (PID: 3420)
      • atom.exe (PID: 1736)
      • atom.exe (PID: 2040)
      • atom.exe (PID: 664)
      • atom.exe (PID: 1816)
      • atom.exe (PID: 3276)
      • atom.exe (PID: 3032)
      • atom.exe (PID: 3096)
      • atom.exe (PID: 3832)
      • setup.exe (PID: 3000)
      • atom.exe (PID: 2156)
    • Reads the machine GUID from the registry

      • loader.exe (PID: 116)
      • setup.exe (PID: 696)
      • atom.exe (PID: 2644)
      • atom.exe (PID: 1736)
      • atom.exe (PID: 664)
      • atom.exe (PID: 2040)
      • atom.exe (PID: 3832)
      • atom.exe (PID: 3276)
      • atom.exe (PID: 3032)
      • atom.exe (PID: 3096)
      • atom.exe (PID: 2156)
    • Creates files in the program directory

      • loader.exe (PID: 116)
    • Checks proxy server information

      • loader.exe (PID: 116)
      • setup.exe (PID: 696)
    • Creates files or folders in the user directory

      • loader.exe (PID: 116)
      • setup.exe (PID: 2000)
      • setup.exe (PID: 696)
      • atom.exe (PID: 2644)
      • atom.exe (PID: 2320)
      • setup.exe (PID: 3000)
    • Process checks computer location settings

      • atom.exe (PID: 1812)
      • atom.exe (PID: 2436)
      • atom.exe (PID: 2940)
      • atom.exe (PID: 1408)
      • atom.exe (PID: 3040)
      • atom.exe (PID: 3012)
      • atom.exe (PID: 2824)
      • atom.exe (PID: 3016)
      • atom.exe (PID: 3056)
      • atom.exe (PID: 1932)
      • atom.exe (PID: 2852)
      • atom.exe (PID: 2520)
      • atom.exe (PID: 3676)
      • atom.exe (PID: 2820)
      • atom.exe (PID: 3028)
      • atom.exe (PID: 3664)
      • atom.exe (PID: 1236)
      • atom.exe (PID: 2000)
      • atom.exe (PID: 2644)
      • atom.exe (PID: 1824)
      • atom.exe (PID: 956)
      • atom.exe (PID: 2268)
      • atom.exe (PID: 2652)
      • atom.exe (PID: 2460)
      • atom.exe (PID: 1836)
      • atom.exe (PID: 3652)
    • Process checks whether UAC notifications are on

      • atom.exe (PID: 2644)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:12:22 09:05:10+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 376320
InitializedDataSize: 614400
UninitializedDataSize: -
EntryPoint: 0x23466
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 7.0.0.133
ProductVersionNumber: 7.0.0.133
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: VK
FileDescription: Atom Browser
InternalName: Atom Browser
OriginalFileName: Atom Browser
ProductName: Atom Browser
FileVersion: 7.0.0.133
ProductVersion: 7.0.0.133
LegalCopyright: Copyright 2021
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
96
Monitored processes
55
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start atom.exe loader.exe lrunner0.exe setup.exe setup.exe no specs atom.exe atom.exe no specs atom.exe no specs atom.exe atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs setup.exe setup.exe no specs atom.exe atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Users\admin\AppData\Local\Temp\\mr914906\loader.exe" --cpC:\Users\admin\AppData\Local\Temp\mr914906\loader.exe
atom.exe
User:
admin
Company:
VK
Integrity Level:
MEDIUM
Description:
Atom Browser
Exit code:
0
Version:
7.0.0.133
Modules
Images
c:\users\admin\appdata\local\temp\mr914906\loader.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
664"C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --field-trial-handle=944,8312308421703697060,9816522057838035789,131072 --enable-features=Dashboard,FeaturePromotion,Marusya,MyAdBlocker,TabSeparators,TaskbarCounter,ToolPanel,VkMusic,WhatsApp --disable-features=Channel,LocationBarPIP,MySearchContext,PwaSupport,UnnamedSearch --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=7672 /prefetch:8C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exeatom.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
MEDIUM
Description:
Atom
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\mail.ru\atom\application\atom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\mail.ru\atom\application\17.0.0.21\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
696"C:\Users\admin\AppData\Local\Temp\mr915671\CR_33FA1.tmp\setup.exe" --install-archive="C:\Users\admin\AppData\Local\Temp\mr915671\CR_33FA1.tmp\CHROME.PACKED.7Z" --arf=1 --rfr=520002 --ga-tid=UA-122680070-1 --ga-cid=GA1.2.1691028016.1643281304 --usagestats=1 --ext_params=IVID=3AYCeP0-qm2700000Z16H4I7%3A%3A%3A0-0-0-6f8308d%3ACAASEGHgAvLfvfiQj-kEZbuPgA8aYM4m01XaRlIlGt9KUmzdXYvCp7wfOc6bMXLH5uEhIOWGiN-Xl-MwRK25YkFzAqHbPySgdZNruhLfVm4nI0NOe-AoK7i2ivWps1q5AYa2iyi8gpBsC9ZBK7A_cPHqM68spg "--ntp-settings={\"feedEnable\": true, \"searchEnable\": true, \"historyEnable\": true, \"noteEnable\": false, \"widgetMailEnable\": true, \"trendsSuggestEnable\": true, \"youTubePanelEnable\": false}" --onboarding-pages=welcome,import,vk,shortcuts --rmt-onboarding=page-5 --force-restore-on-startup-last --enable-features=TaskbarCounter,Dashboard --disable-features=MySearchContextC:\Users\admin\AppData\Local\Temp\mr915671\CR_33FA1.tmp\setup.exe
lrunner0.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
MEDIUM
Description:
Atom Installer
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\temp\mr915671\cr_33fa1.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\oleaut32.dll
848"C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --field-trial-handle=944,8312308421703697060,9816522057838035789,131072 --enable-features=Dashboard,FeaturePromotion,Marusya,MyAdBlocker,TabSeparators,TaskbarCounter,ToolPanel,VkMusic,WhatsApp --disable-features=Channel,LocationBarPIP,MySearchContext,PwaSupport,UnnamedSearch --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=7648 /prefetch:8C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exeatom.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
LOW
Description:
Atom
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\mail.ru\atom\application\atom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\mail.ru\atom\application\17.0.0.21\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
956"C:\Users\admin\AppData\Local\Temp\\mr915671\lrunner0.exe" --arf=1 --rfr=520002 --ga-tid=UA-122680070-1 --ga-cid=GA1.2.1691028016.1643281304 --usagestats=1 --ext_params=IVID=3AYCeP0-qm2700000Z16H4I7%3A%3A%3A0-0-0-6f8308d%3ACAASEGHgAvLfvfiQj-kEZbuPgA8aYM4m01XaRlIlGt9KUmzdXYvCp7wfOc6bMXLH5uEhIOWGiN-Xl-MwRK25YkFzAqHbPySgdZNruhLfVm4nI0NOe-AoK7i2ivWps1q5AYa2iyi8gpBsC9ZBK7A_cPHqM68spg "--ntp-settings={\"feedEnable\": true, \"searchEnable\": true, \"historyEnable\": true, \"noteEnable\": false, \"widgetMailEnable\": true, \"trendsSuggestEnable\": true, \"youTubePanelEnable\": false}" --onboarding-pages=welcome,import,vk,shortcuts --rmt-onboarding=page-5 --force-restore-on-startup-last --enable-features=TaskbarCounter,Dashboard --disable-features=MySearchContextC:\Users\admin\AppData\Local\Temp\mr915671\lrunner0.exe
loader.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
MEDIUM
Description:
Atom Installer
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\temp\mr915671\lrunner0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
956"C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exe" --type=renderer --display-capture-permissions-policy-allowed --field-trial-handle=944,8312308421703697060,9816522057838035789,131072 --enable-features=Dashboard,FeaturePromotion,Marusya,MyAdBlocker,TabSeparators,TaskbarCounter,ToolPanel,VkMusic,WhatsApp --disable-features=Channel,LocationBarPIP,MySearchContext,PwaSupport,UnnamedSearch --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=39 --mojo-platform-channel-handle=2976 /prefetch:1C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exeatom.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
LOW
Description:
Atom
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\mail.ru\atom\application\atom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\mail.ru\atom\application\17.0.0.21\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1236"C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exe" --type=renderer --display-capture-permissions-policy-allowed --field-trial-handle=944,8312308421703697060,9816522057838035789,131072 --enable-features=Dashboard,FeaturePromotion,Marusya,MyAdBlocker,TabSeparators,TaskbarCounter,ToolPanel,VkMusic,WhatsApp --disable-features=Channel,LocationBarPIP,MySearchContext,PwaSupport,UnnamedSearch --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=26 --mojo-platform-channel-handle=3040 /prefetch:1C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exeatom.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
LOW
Description:
Atom
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\mail.ru\atom\application\atom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\mail.ru\atom\application\17.0.0.21\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1408"C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exe" --type=renderer --extension-process --display-capture-permissions-policy-allowed --field-trial-handle=944,8312308421703697060,9816522057838035789,131072 --enable-features=Dashboard,FeaturePromotion,Marusya,MyAdBlocker,TabSeparators,TaskbarCounter,ToolPanel,VkMusic,WhatsApp --disable-features=Channel,LocationBarPIP,MySearchContext,PwaSupport,UnnamedSearch --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --mojo-platform-channel-handle=3576 /prefetch:1C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exeatom.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
LOW
Description:
Atom
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\mail.ru\atom\application\atom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\mail.ru\atom\application\17.0.0.21\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1736"C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --field-trial-handle=944,8312308421703697060,9816522057838035789,131072 --enable-features=Dashboard,FeaturePromotion,Marusya,MyAdBlocker,TabSeparators,TaskbarCounter,ToolPanel,VkMusic,WhatsApp --disable-features=Channel,LocationBarPIP,MySearchContext,PwaSupport,UnnamedSearch --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=7580 /prefetch:8C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exeatom.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
MEDIUM
Description:
Atom
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\mail.ru\atom\application\atom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\mail.ru\atom\application\17.0.0.21\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1812"C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exe" --type=renderer --extension-process --display-capture-permissions-policy-allowed --field-trial-handle=944,8312308421703697060,9816522057838035789,131072 --enable-features=Dashboard,FeaturePromotion,Marusya,MyAdBlocker,TabSeparators,TaskbarCounter,ToolPanel,VkMusic,WhatsApp --disable-features=Channel,LocationBarPIP,MySearchContext,PwaSupport,UnnamedSearch --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2004 /prefetch:1C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exeatom.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
LOW
Description:
Atom
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\mail.ru\atom\application\atom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\mail.ru\atom\application\17.0.0.21\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
31 171
Read events
30 955
Write events
206
Delete events
10

Modification events

(PID) Process:(116) loader.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(116) loader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(116) loader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(116) loader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(116) loader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(116) loader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(116) loader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(696) setup.exeKey:HKEY_CURRENT_USER\Software\Mail.Ru\AtomInstaller
Operation:writeName:GUID
Value:
{6BCF5CEB-B270-477F-8D33-3F7AEBD6B5FD}
(PID) Process:(696) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(696) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
12
Suspicious files
452
Text files
137
Unknown types
4

Dropped files

PID
Process
Filename
Type
116loader.exeC:\Users\admin\AppData\Local\Temp\mr915671\lrunner0.exe
MD5:
SHA256:
956lrunner0.exeC:\Users\admin\AppData\Local\Temp\mr915671\CR_33FA1.tmp\CHROME.PACKED.7Z
MD5:
SHA256:
696setup.exeC:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\17.0.0.21\Installer\chrome.7z
MD5:
SHA256:
696setup.exeC:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\eventer.exe
MD5:
SHA256:
2184atom.exeC:\Users\admin\AppData\Local\Temp\mr914906\loader.exeexecutable
MD5:59F2AC79F77D882EEF0AD3A9AE12C78B
SHA256:1672C62639293577DB5745693CB8A0C596A6B3882BD654A04E9DB9F6734221B3
696setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\B039FEA45CB4CC4BBACFC013C7C55604_50D7940D5D3FEDD8634D83074C7A46A3binary
MD5:B05919685D956513343CE01E5673C9BD
SHA256:34C744D97C095047556CE71EFFF770470918448151895D790E95E097D9B5121D
116loader.exeC:\ProgramData\Mail.Ru\Idtext
MD5:8109EC1CBD8B9EF6116885D246B36056
SHA256:EEA107FC65A8EE0662C6B5857EEDE34EBDCFBBBE52B360ABCEA89A6EBF4A4DD8
696setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\0DA515F703BB9B49479E8697ADB0B955_4136D3715888E22D65EBE484B233D81Bbinary
MD5:85A10904B86D6E60E856762E24EFF919
SHA256:C83A99DEA1A4EE30977A87735789C99D3CFEB00DC30FEB9F756D9A2C0A5BFD8E
696setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\DF6129E66859A5D026F5D611C59A131Bbinary
MD5:E70C3108125CDA653F004205D5D6076D
SHA256:0A6E69BBCCB95B58ED7E94226AA4401C50343DF45523F1A26AC025DBB54F5983
696setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\0DA515F703BB9B49479E8697ADB0B955_4136D3715888E22D65EBE484B233D81Bbinary
MD5:D8E1C3DD39E97D067BD16D1BF18796DA
SHA256:C6013404513774712B282D877905B04619D9C19AAB8927C959B284BBC0C3EBDD
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
18
TCP/UDP connections
148
DNS requests
78
Threats
10

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
116
loader.exe
GET
204
95.163.50.150:80
http://mrds.mail.ru/update/2/version.txt?type=loader.init&tool=loader&BID=%7B6BCF5CEB-B270-477F-8D33-3F7AEBD6B5FD%7D&kind=atom&masterid=%7B7D6D87E4-2B0C-4961-96B7-84BBF0C45E4A%7D&rfr=&newrfr=520002&os=6.1&ver=7.0.0.133&IVID=3AYCeP0-qm2700000Z16H4I7%3A%3A%3A0-0-0-6f8308d%3ACAASEGHgAvLfvfiQj-kEZbuPgA8aYM4m01XaRlIlGt9KUmzdXYvCp7wfOc6bMXLH5uEhIOWGiN-Xl-MwRK25YkFzAqHbPySgdZNruhLfVm4nI0NOe-AoK7i2ivWps1q5AYa2iyi8gpBsC9ZBK7A_cPHqM68spg&send_stats=1&dsa=1
unknown
unknown
696
setup.exe
GET
200
184.24.77.182:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d8de85c850918a88
unknown
compressed
4.66 Kb
unknown
116
loader.exe
GET
204
95.163.50.150:80
http://mrds.mail.ru/update/2/version.txt?type=loader.req_check&tool=loader&BID=%7B6BCF5CEB-B270-477F-8D33-3F7AEBD6B5FD%7D&kind=atom&masterid=%7B7D6D87E4-2B0C-4961-96B7-84BBF0C45E4A%7D&rfr=&newrfr=520002&os=6.1&ver=7.0.0.133&IVID=3AYCeP0-qm2700000Z16H4I7%3A%3A%3A0-0-0-6f8308d%3ACAASEGHgAvLfvfiQj-kEZbuPgA8aYM4m01XaRlIlGt9KUmzdXYvCp7wfOc6bMXLH5uEhIOWGiN-Xl-MwRK25YkFzAqHbPySgdZNruhLfVm4nI0NOe-AoK7i2ivWps1q5AYa2iyi8gpBsC9ZBK7A_cPHqM68spg&send_stats=1&result=0
unknown
unknown
696
setup.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/gsrsaovsslca2018/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBRrcGT%2BanRD3C1tW3nsrKeuXC7DPwQU%2BO9%2F8s14Z6jeb48kjYjxhwMCs%2BsCDF9XhWYmj23gB1h1OQ%3D%3D
unknown
binary
1.40 Kb
unknown
116
loader.exe
GET
204
95.163.50.150:80
http://mrds.mail.ru/update/2/version.txt?type=loader.begin&tool=loader&BID=%7B6BCF5CEB-B270-477F-8D33-3F7AEBD6B5FD%7D&kind=atom&masterid=%7B7D6D87E4-2B0C-4961-96B7-84BBF0C45E4A%7D&rfr=&newrfr=520002&os=6.1&ver=7.0.0.133&IVID=3AYCeP0-qm2700000Z16H4I7%3A%3A%3A0-0-0-6f8308d%3ACAASEGHgAvLfvfiQj-kEZbuPgA8aYM4m01XaRlIlGt9KUmzdXYvCp7wfOc6bMXLH5uEhIOWGiN-Xl-MwRK25YkFzAqHbPySgdZNruhLfVm4nI0NOe-AoK7i2ivWps1q5AYa2iyi8gpBsC9ZBK7A_cPHqM68spg&send_stats=1&send_stats=0
unknown
unknown
696
setup.exe
GET
200
104.18.20.226:80
http://ocsp.globalsign.com/rootr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCDQHuXxad%2F5c1K2Rl1mo%3D
unknown
binary
1.41 Kb
unknown
856
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ANlaTV2JH2WK9RCoHi__mxg_1.0.6/S3ybLvFx94Hgn9pWLt24ug
unknown
unknown
116
loader.exe
GET
204
95.163.50.150:80
http://mrds.mail.ru/update/2/version.txt?type=loader.install_finished&tool=loader&BID=%7B6BCF5CEB-B270-477F-8D33-3F7AEBD6B5FD%7D&kind=atom&masterid=%7B7D6D87E4-2B0C-4961-96B7-84BBF0C45E4A%7D&rfr=&newrfr=520002&os=6.1&ver=7.0.0.133&IVID=3AYCeP0-qm2700000Z16H4I7%3A%3A%3A0-0-0-6f8308d%3ACAASEGHgAvLfvfiQj-kEZbuPgA8aYM4m01XaRlIlGt9KUmzdXYvCp7wfOc6bMXLH5uEhIOWGiN-Xl-MwRK25YkFzAqHbPySgdZNruhLfVm4nI0NOe-AoK7i2ivWps1q5AYa2iyi8gpBsC9ZBK7A_cPHqM68spg&send_stats=1&app=atom&result=0&error_code=0
unknown
unknown
116
loader.exe
GET
204
95.163.50.150:80
http://mrds.mail.ru/update/2/version.txt?type=loader.download_finished&tool=loader&BID=%7B6BCF5CEB-B270-477F-8D33-3F7AEBD6B5FD%7D&kind=atom&masterid=%7B7D6D87E4-2B0C-4961-96B7-84BBF0C45E4A%7D&rfr=&newrfr=520002&os=6.1&ver=7.0.0.133&IVID=3AYCeP0-qm2700000Z16H4I7%3A%3A%3A0-0-0-6f8308d%3ACAASEGHgAvLfvfiQj-kEZbuPgA8aYM4m01XaRlIlGt9KUmzdXYvCp7wfOc6bMXLH5uEhIOWGiN-Xl-MwRK25YkFzAqHbPySgdZNruhLfVm4nI0NOe-AoK7i2ivWps1q5AYa2iyi8gpBsC9ZBK7A_cPHqM68spg&send_stats=1&app=atom&error=0
unknown
unknown
696
setup.exe
GET
200
104.18.20.226:80
http://ocsp2.globalsign.com/rootr3/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBT1nGh%2FJBjWKnkPdZIzB1bqhelHBwQUj%2FBLf6guRSSuTVD6Y5qL3uLdG7wCDQHuXyId%2FGI71DM6hVc%3D
unknown
binary
1.40 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
116
loader.exe
95.163.50.150:80
mrds.mail.ru
LLC VK
RU
unknown
4
System
192.168.100.255:138
whitelisted
116
loader.exe
142.250.186.142:443
www.google-analytics.com
GOOGLE
US
whitelisted
116
loader.exe
5.181.61.0:443
browser-asset.cdnmail.ru
LLC VK
RU
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
696
setup.exe
5.61.236.211:443
bs.browser.mail.ru
LLC VK
RU
unknown
696
setup.exe
184.24.77.182:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
696
setup.exe
104.18.20.226:80
ocsp.globalsign.com
CLOUDFLARENET
shared
2320
atom.exe
172.217.132.198:443
r1---sn-5hnednss.gvt1.com
unknown

DNS requests

Domain
IP
Reputation
mrds.mail.ru
  • 95.163.50.150
malicious
www.google-analytics.com
  • 142.250.186.142
whitelisted
browser-asset.cdnmail.ru
  • 5.181.61.0
unknown
bs.browser.mail.ru
  • 5.61.236.211
unknown
ctldl.windowsupdate.com
  • 184.24.77.182
  • 184.24.77.210
  • 184.24.77.200
  • 184.24.77.174
  • 184.24.77.205
  • 184.24.77.201
  • 93.184.221.240
  • 184.24.77.177
  • 184.24.77.193
  • 184.24.77.194
  • 184.24.77.186
  • 184.24.77.197
  • 184.24.77.203
  • 184.24.77.191
whitelisted
ocsp.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
ocsp2.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
data.browser.mail.ru
  • 5.61.236.211
unknown
redirector.gvt1.com
  • 142.250.184.238
whitelisted
clients2.google.com
  • 142.250.186.142
whitelisted

Threats

PID
Process
Class
Message
2320
atom.exe
Potential Corporate Privacy Violation
AV POLICY Observed TikTok Domain in TLS SNI (tiktok.com)
2320
atom.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
1080
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
1080
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com)
6 ETPRO signatures available at the full report
No debug info