File name:

atom.exe

Full analysis: https://app.any.run/tasks/9335209c-3de2-44bf-8d05-2b1f74d5a3e2
Verdict: Malicious activity
Analysis date: January 13, 2024, 18:13:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

59F2AC79F77D882EEF0AD3A9AE12C78B

SHA1:

4855E83407256EDCEE2B131542CE271673FA274A

SHA256:

1672C62639293577DB5745693CB8A0C596A6B3882BD654A04E9DB9F6734221B3

SSDEEP:

49152:33Mn23dXnvwj5Ju7SMpGcuMUdlEe9BxIklWMrD5raghxKtDCwgWAyuFf:33Mn23hnvwFkODVP6qDBxKtDCwMyIf

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • atom.exe (PID: 2184)
      • lrunner0.exe (PID: 956)
      • setup.exe (PID: 696)
    • Actions looks like stealing of personal data

      • atom.exe (PID: 2644)
      • atom.exe (PID: 1816)
    • Steals credentials from Web Browsers

      • atom.exe (PID: 2644)
  • SUSPICIOUS

    • Starts itself from another location

      • atom.exe (PID: 2184)
    • Reads settings of System Certificates

      • loader.exe (PID: 116)
      • setup.exe (PID: 696)
      • atom.exe (PID: 2644)
    • Reads Internet Explorer settings

      • loader.exe (PID: 116)
    • Executable content was dropped or overwritten

      • lrunner0.exe (PID: 956)
      • atom.exe (PID: 2184)
      • setup.exe (PID: 696)
    • Reads Microsoft Outlook installation path

      • loader.exe (PID: 116)
    • Reads the Internet Settings

      • loader.exe (PID: 116)
      • setup.exe (PID: 696)
      • atom.exe (PID: 2644)
    • Application launched itself

      • setup.exe (PID: 696)
      • atom.exe (PID: 2644)
      • atom.exe (PID: 1924)
      • setup.exe (PID: 3000)
    • Reads security settings of Internet Explorer

      • setup.exe (PID: 696)
    • Checks Windows Trust Settings

      • setup.exe (PID: 696)
    • The process creates files with name similar to system file names

      • setup.exe (PID: 696)
    • Reads Mozilla Firefox installation path

      • atom.exe (PID: 2644)
    • Loads DLL from Mozilla Firefox

      • atom.exe (PID: 1816)
    • Reads browser cookies

      • atom.exe (PID: 1816)
  • INFO

    • Checks proxy server information

      • loader.exe (PID: 116)
      • setup.exe (PID: 696)
    • Reads the computer name

      • lrunner0.exe (PID: 956)
      • loader.exe (PID: 116)
      • setup.exe (PID: 696)
      • atom.exe (PID: 2644)
      • atom.exe (PID: 1924)
      • atom.exe (PID: 1860)
      • atom.exe (PID: 2320)
      • atom.exe (PID: 2532)
      • atom.exe (PID: 3420)
      • atom.exe (PID: 1736)
      • atom.exe (PID: 664)
      • atom.exe (PID: 2040)
      • atom.exe (PID: 3832)
      • setup.exe (PID: 3000)
      • atom.exe (PID: 1816)
      • atom.exe (PID: 3032)
      • atom.exe (PID: 3276)
      • atom.exe (PID: 3096)
      • atom.exe (PID: 2156)
    • Reads the machine GUID from the registry

      • loader.exe (PID: 116)
      • setup.exe (PID: 696)
      • atom.exe (PID: 2644)
      • atom.exe (PID: 1736)
      • atom.exe (PID: 2040)
      • atom.exe (PID: 664)
      • atom.exe (PID: 3832)
      • atom.exe (PID: 3032)
      • atom.exe (PID: 3276)
      • atom.exe (PID: 3096)
      • atom.exe (PID: 2156)
    • Create files in a temporary directory

      • loader.exe (PID: 116)
      • lrunner0.exe (PID: 956)
      • atom.exe (PID: 2184)
      • atom.exe (PID: 2644)
      • atom.exe (PID: 1816)
    • Creates files in the program directory

      • loader.exe (PID: 116)
    • Creates files or folders in the user directory

      • loader.exe (PID: 116)
      • setup.exe (PID: 2000)
      • setup.exe (PID: 696)
      • atom.exe (PID: 2320)
      • atom.exe (PID: 2644)
      • setup.exe (PID: 3000)
    • Checks supported languages

      • lrunner0.exe (PID: 956)
      • atom.exe (PID: 2184)
      • loader.exe (PID: 116)
      • setup.exe (PID: 696)
      • setup.exe (PID: 2000)
      • atom.exe (PID: 1924)
      • atom.exe (PID: 2644)
      • atom.exe (PID: 2576)
      • atom.exe (PID: 2320)
      • atom.exe (PID: 2800)
      • atom.exe (PID: 2532)
      • atom.exe (PID: 1812)
      • atom.exe (PID: 2852)
      • atom.exe (PID: 2520)
      • atom.exe (PID: 2436)
      • atom.exe (PID: 3028)
      • atom.exe (PID: 1860)
      • atom.exe (PID: 2940)
      • atom.exe (PID: 2824)
      • atom.exe (PID: 2820)
      • atom.exe (PID: 3016)
      • atom.exe (PID: 1932)
      • atom.exe (PID: 3220)
      • atom.exe (PID: 3040)
      • atom.exe (PID: 3012)
      • atom.exe (PID: 1408)
      • atom.exe (PID: 2752)
      • atom.exe (PID: 3420)
      • atom.exe (PID: 3676)
      • atom.exe (PID: 3664)
      • atom.exe (PID: 1236)
      • atom.exe (PID: 1736)
      • atom.exe (PID: 2000)
      • atom.exe (PID: 2428)
      • atom.exe (PID: 848)
      • atom.exe (PID: 3832)
      • atom.exe (PID: 2040)
      • atom.exe (PID: 664)
      • setup.exe (PID: 3000)
      • setup.exe (PID: 4084)
      • atom.exe (PID: 1816)
      • atom.exe (PID: 2268)
      • atom.exe (PID: 956)
      • atom.exe (PID: 3096)
      • atom.exe (PID: 2460)
      • atom.exe (PID: 1824)
      • atom.exe (PID: 3276)
      • atom.exe (PID: 3032)
      • atom.exe (PID: 3696)
      • atom.exe (PID: 1836)
      • atom.exe (PID: 3772)
      • atom.exe (PID: 3056)
      • atom.exe (PID: 2156)
      • atom.exe (PID: 3652)
      • atom.exe (PID: 2652)
    • Process checks computer location settings

      • atom.exe (PID: 2644)
      • atom.exe (PID: 1812)
      • atom.exe (PID: 2436)
      • atom.exe (PID: 2824)
      • atom.exe (PID: 2940)
      • atom.exe (PID: 3056)
      • atom.exe (PID: 2520)
      • atom.exe (PID: 3016)
      • atom.exe (PID: 1932)
      • atom.exe (PID: 2852)
      • atom.exe (PID: 3676)
      • atom.exe (PID: 2820)
      • atom.exe (PID: 3664)
      • atom.exe (PID: 3028)
      • atom.exe (PID: 1236)
      • atom.exe (PID: 2000)
      • atom.exe (PID: 956)
      • atom.exe (PID: 2268)
      • atom.exe (PID: 2460)
      • atom.exe (PID: 1824)
      • atom.exe (PID: 2652)
      • atom.exe (PID: 1836)
      • atom.exe (PID: 3040)
      • atom.exe (PID: 3012)
      • atom.exe (PID: 1408)
      • atom.exe (PID: 3652)
    • Process checks whether UAC notifications are on

      • atom.exe (PID: 2644)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:12:22 09:05:10+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 376320
InitializedDataSize: 614400
UninitializedDataSize: -
EntryPoint: 0x23466
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 7.0.0.133
ProductVersionNumber: 7.0.0.133
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: VK
FileDescription: Atom Browser
InternalName: Atom Browser
OriginalFileName: Atom Browser
ProductName: Atom Browser
FileVersion: 7.0.0.133
ProductVersion: 7.0.0.133
LegalCopyright: Copyright 2021
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
96
Monitored processes
55
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start atom.exe loader.exe lrunner0.exe setup.exe setup.exe no specs atom.exe atom.exe no specs atom.exe no specs atom.exe atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs setup.exe setup.exe no specs atom.exe atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs atom.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
116"C:\Users\admin\AppData\Local\Temp\\mr914906\loader.exe" --cpC:\Users\admin\AppData\Local\Temp\mr914906\loader.exe
atom.exe
User:
admin
Company:
VK
Integrity Level:
MEDIUM
Description:
Atom Browser
Exit code:
0
Version:
7.0.0.133
Modules
Images
c:\users\admin\appdata\local\temp\mr914906\loader.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
664"C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --field-trial-handle=944,8312308421703697060,9816522057838035789,131072 --enable-features=Dashboard,FeaturePromotion,Marusya,MyAdBlocker,TabSeparators,TaskbarCounter,ToolPanel,VkMusic,WhatsApp --disable-features=Channel,LocationBarPIP,MySearchContext,PwaSupport,UnnamedSearch --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=7672 /prefetch:8C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exeatom.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
MEDIUM
Description:
Atom
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\mail.ru\atom\application\atom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\mail.ru\atom\application\17.0.0.21\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
696"C:\Users\admin\AppData\Local\Temp\mr915671\CR_33FA1.tmp\setup.exe" --install-archive="C:\Users\admin\AppData\Local\Temp\mr915671\CR_33FA1.tmp\CHROME.PACKED.7Z" --arf=1 --rfr=520002 --ga-tid=UA-122680070-1 --ga-cid=GA1.2.1691028016.1643281304 --usagestats=1 --ext_params=IVID=3AYCeP0-qm2700000Z16H4I7%3A%3A%3A0-0-0-6f8308d%3ACAASEGHgAvLfvfiQj-kEZbuPgA8aYM4m01XaRlIlGt9KUmzdXYvCp7wfOc6bMXLH5uEhIOWGiN-Xl-MwRK25YkFzAqHbPySgdZNruhLfVm4nI0NOe-AoK7i2ivWps1q5AYa2iyi8gpBsC9ZBK7A_cPHqM68spg "--ntp-settings={\"feedEnable\": true, \"searchEnable\": true, \"historyEnable\": true, \"noteEnable\": false, \"widgetMailEnable\": true, \"trendsSuggestEnable\": true, \"youTubePanelEnable\": false}" --onboarding-pages=welcome,import,vk,shortcuts --rmt-onboarding=page-5 --force-restore-on-startup-last --enable-features=TaskbarCounter,Dashboard --disable-features=MySearchContextC:\Users\admin\AppData\Local\Temp\mr915671\CR_33FA1.tmp\setup.exe
lrunner0.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
MEDIUM
Description:
Atom Installer
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\temp\mr915671\cr_33fa1.tmp\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\oleaut32.dll
848"C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --field-trial-handle=944,8312308421703697060,9816522057838035789,131072 --enable-features=Dashboard,FeaturePromotion,Marusya,MyAdBlocker,TabSeparators,TaskbarCounter,ToolPanel,VkMusic,WhatsApp --disable-features=Channel,LocationBarPIP,MySearchContext,PwaSupport,UnnamedSearch --lang=en-US --service-sandbox-type=utility --mojo-platform-channel-handle=7648 /prefetch:8C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exeatom.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
LOW
Description:
Atom
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\mail.ru\atom\application\atom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\mail.ru\atom\application\17.0.0.21\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
956"C:\Users\admin\AppData\Local\Temp\\mr915671\lrunner0.exe" --arf=1 --rfr=520002 --ga-tid=UA-122680070-1 --ga-cid=GA1.2.1691028016.1643281304 --usagestats=1 --ext_params=IVID=3AYCeP0-qm2700000Z16H4I7%3A%3A%3A0-0-0-6f8308d%3ACAASEGHgAvLfvfiQj-kEZbuPgA8aYM4m01XaRlIlGt9KUmzdXYvCp7wfOc6bMXLH5uEhIOWGiN-Xl-MwRK25YkFzAqHbPySgdZNruhLfVm4nI0NOe-AoK7i2ivWps1q5AYa2iyi8gpBsC9ZBK7A_cPHqM68spg "--ntp-settings={\"feedEnable\": true, \"searchEnable\": true, \"historyEnable\": true, \"noteEnable\": false, \"widgetMailEnable\": true, \"trendsSuggestEnable\": true, \"youTubePanelEnable\": false}" --onboarding-pages=welcome,import,vk,shortcuts --rmt-onboarding=page-5 --force-restore-on-startup-last --enable-features=TaskbarCounter,Dashboard --disable-features=MySearchContextC:\Users\admin\AppData\Local\Temp\mr915671\lrunner0.exe
loader.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
MEDIUM
Description:
Atom Installer
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\temp\mr915671\lrunner0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
956"C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exe" --type=renderer --display-capture-permissions-policy-allowed --field-trial-handle=944,8312308421703697060,9816522057838035789,131072 --enable-features=Dashboard,FeaturePromotion,Marusya,MyAdBlocker,TabSeparators,TaskbarCounter,ToolPanel,VkMusic,WhatsApp --disable-features=Channel,LocationBarPIP,MySearchContext,PwaSupport,UnnamedSearch --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=39 --mojo-platform-channel-handle=2976 /prefetch:1C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exeatom.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
LOW
Description:
Atom
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\mail.ru\atom\application\atom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\mail.ru\atom\application\17.0.0.21\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1236"C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exe" --type=renderer --display-capture-permissions-policy-allowed --field-trial-handle=944,8312308421703697060,9816522057838035789,131072 --enable-features=Dashboard,FeaturePromotion,Marusya,MyAdBlocker,TabSeparators,TaskbarCounter,ToolPanel,VkMusic,WhatsApp --disable-features=Channel,LocationBarPIP,MySearchContext,PwaSupport,UnnamedSearch --disable-gpu-compositing --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=26 --mojo-platform-channel-handle=3040 /prefetch:1C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exeatom.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
LOW
Description:
Atom
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\mail.ru\atom\application\atom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\mail.ru\atom\application\17.0.0.21\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1408"C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exe" --type=renderer --extension-process --display-capture-permissions-policy-allowed --field-trial-handle=944,8312308421703697060,9816522057838035789,131072 --enable-features=Dashboard,FeaturePromotion,Marusya,MyAdBlocker,TabSeparators,TaskbarCounter,ToolPanel,VkMusic,WhatsApp --disable-features=Channel,LocationBarPIP,MySearchContext,PwaSupport,UnnamedSearch --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=10 --mojo-platform-channel-handle=3576 /prefetch:1C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exeatom.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
LOW
Description:
Atom
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\mail.ru\atom\application\atom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\mail.ru\atom\application\17.0.0.21\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1736"C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --field-trial-handle=944,8312308421703697060,9816522057838035789,131072 --enable-features=Dashboard,FeaturePromotion,Marusya,MyAdBlocker,TabSeparators,TaskbarCounter,ToolPanel,VkMusic,WhatsApp --disable-features=Channel,LocationBarPIP,MySearchContext,PwaSupport,UnnamedSearch --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=7580 /prefetch:8C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exeatom.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
MEDIUM
Description:
Atom
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\mail.ru\atom\application\atom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\mail.ru\atom\application\17.0.0.21\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
1812"C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exe" --type=renderer --extension-process --display-capture-permissions-policy-allowed --field-trial-handle=944,8312308421703697060,9816522057838035789,131072 --enable-features=Dashboard,FeaturePromotion,Marusya,MyAdBlocker,TabSeparators,TaskbarCounter,ToolPanel,VkMusic,WhatsApp --disable-features=Channel,LocationBarPIP,MySearchContext,PwaSupport,UnnamedSearch --lang=en-US --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2004 /prefetch:1C:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\atom.exeatom.exe
User:
admin
Company:
The Atom Authors
Integrity Level:
LOW
Description:
Atom
Exit code:
0
Version:
17.0.0.21
Modules
Images
c:\users\admin\appdata\local\mail.ru\atom\application\atom.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\mail.ru\atom\application\17.0.0.21\chrome_elf.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
31 171
Read events
30 955
Write events
206
Delete events
10

Modification events

(PID) Process:(116) loader.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(116) loader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(116) loader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(116) loader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(116) loader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(116) loader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(116) loader.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(696) setup.exeKey:HKEY_CURRENT_USER\Software\Mail.Ru\AtomInstaller
Operation:writeName:GUID
Value:
{6BCF5CEB-B270-477F-8D33-3F7AEBD6B5FD}
(PID) Process:(696) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(696) setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
12
Suspicious files
452
Text files
137
Unknown types
4

Dropped files

PID
Process
Filename
Type
116loader.exeC:\Users\admin\AppData\Local\Temp\mr915671\lrunner0.exe
MD5:
SHA256:
956lrunner0.exeC:\Users\admin\AppData\Local\Temp\mr915671\CR_33FA1.tmp\CHROME.PACKED.7Z
MD5:
SHA256:
696setup.exeC:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\17.0.0.21\Installer\chrome.7z
MD5:
SHA256:
696setup.exeC:\Users\admin\AppData\Local\Mail.Ru\Atom\Application\eventer.exe
MD5:
SHA256:
2184atom.exeC:\Users\admin\AppData\Local\Temp\mr914906\loader.exeexecutable
MD5:59F2AC79F77D882EEF0AD3A9AE12C78B
SHA256:1672C62639293577DB5745693CB8A0C596A6B3882BD654A04E9DB9F6734221B3
116loader.exeC:\ProgramData\Mail.Ru\Idtext
MD5:8109EC1CBD8B9EF6116885D246B36056
SHA256:EEA107FC65A8EE0662C6B5857EEDE34EBDCFBBBE52B360ABCEA89A6EBF4A4DD8
696setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\B039FEA45CB4CC4BBACFC013C7C55604_50D7940D5D3FEDD8634D83074C7A46A3binary
MD5:EC0A1C1745A1F580714887298AA8E1E9
SHA256:49195AD1371F0069DF52014452FCA77233A25C8157A198E154F443392B96F945
696setup.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:416851945FD9A4CC53AAA25FA884C7B4
SHA256:98899B9E3BFBF19838156DAB1BA8C10BECE97C9F9DAC8E24D9C6D060BB9A83B3
956lrunner0.exeC:\Users\admin\AppData\Local\Temp\mr915671\CR_33FA1.tmp\SETUP.EX_compressed
MD5:C296C5B21CFE6890DA03C9DAF8A66B3F
SHA256:4E052B18946CFB30C003E5D3ACBC29FF3ABD4C7467A9040A7F47EC1DF806AED4
956lrunner0.exeC:\Users\admin\AppData\Local\Temp\mr915671\CR_33FA1.tmp\setup.exeexecutable
MD5:390497FB675CE11512FE92BDFE15F116
SHA256:D113B1E71A3FF049A10408C3555FE97988775A808C41833CCC79E20FAB935844
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
18
TCP/UDP connections
148
DNS requests
78
Threats
10

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
856
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ANlaTV2JH2WK9RCoHi__mxg_1.0.6/S3ybLvFx94Hgn9pWLt24ug
unknown
unknown
2644
atom.exe
GET
200
184.24.77.177:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?34e0f269bc5553d8
unknown
compressed
65.2 Kb
unknown
116
loader.exe
GET
204
95.163.50.150:80
http://mrds.mail.ru/update/2/version.txt?type=loader.install_finished&tool=loader&BID=%7B6BCF5CEB-B270-477F-8D33-3F7AEBD6B5FD%7D&kind=atom&masterid=%7B7D6D87E4-2B0C-4961-96B7-84BBF0C45E4A%7D&rfr=&newrfr=520002&os=6.1&ver=7.0.0.133&IVID=3AYCeP0-qm2700000Z16H4I7%3A%3A%3A0-0-0-6f8308d%3ACAASEGHgAvLfvfiQj-kEZbuPgA8aYM4m01XaRlIlGt9KUmzdXYvCp7wfOc6bMXLH5uEhIOWGiN-Xl-MwRK25YkFzAqHbPySgdZNruhLfVm4nI0NOe-AoK7i2ivWps1q5AYa2iyi8gpBsC9ZBK7A_cPHqM68spg&send_stats=1&app=atom&result=0&error_code=0
unknown
unknown
856
svchost.exe
HEAD
200
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/lr74umajwsn2v43viqlbtrfjuy_429/lmelglejhemejginpboagddgdfbepgmp_429_all_ZZ_ac34mcqmk5bzv344nwcsrmi4taga.crx3
unknown
binary
3.30 Kb
unknown
116
loader.exe
GET
204
95.163.50.150:80
http://mrds.mail.ru/update/2/version.txt?type=loader.exit&tool=loader&BID=%7B6BCF5CEB-B270-477F-8D33-3F7AEBD6B5FD%7D&kind=atom&masterid=%7B7D6D87E4-2B0C-4961-96B7-84BBF0C45E4A%7D&rfr=&newrfr=520002&os=6.1&ver=7.0.0.133&IVID=3AYCeP0-qm2700000Z16H4I7%3A%3A%3A0-0-0-6f8308d%3ACAASEGHgAvLfvfiQj-kEZbuPgA8aYM4m01XaRlIlGt9KUmzdXYvCp7wfOc6bMXLH5uEhIOWGiN-Xl-MwRK25YkFzAqHbPySgdZNruhLfVm4nI0NOe-AoK7i2ivWps1q5AYa2iyi8gpBsC9ZBK7A_cPHqM68spg&send_stats=1&result=0
unknown
unknown
1080
svchost.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?532672b1a10842df
unknown
unknown
116
loader.exe
GET
204
95.163.50.150:80
http://mrds.mail.ru/update/2/version.txt?type=loader.init&tool=loader&BID=%7B6BCF5CEB-B270-477F-8D33-3F7AEBD6B5FD%7D&kind=atom&masterid=%7B7D6D87E4-2B0C-4961-96B7-84BBF0C45E4A%7D&rfr=&newrfr=520002&os=6.1&ver=7.0.0.133&IVID=3AYCeP0-qm2700000Z16H4I7%3A%3A%3A0-0-0-6f8308d%3ACAASEGHgAvLfvfiQj-kEZbuPgA8aYM4m01XaRlIlGt9KUmzdXYvCp7wfOc6bMXLH5uEhIOWGiN-Xl-MwRK25YkFzAqHbPySgdZNruhLfVm4nI0NOe-AoK7i2ivWps1q5AYa2iyi8gpBsC9ZBK7A_cPHqM68spg&send_stats=1&dsa=1
unknown
unknown
116
loader.exe
GET
204
95.163.50.150:80
http://mrds.mail.ru/update/2/version.txt?type=loader.req_check&tool=loader&BID=%7B6BCF5CEB-B270-477F-8D33-3F7AEBD6B5FD%7D&kind=atom&masterid=%7B7D6D87E4-2B0C-4961-96B7-84BBF0C45E4A%7D&rfr=&newrfr=520002&os=6.1&ver=7.0.0.133&IVID=3AYCeP0-qm2700000Z16H4I7%3A%3A%3A0-0-0-6f8308d%3ACAASEGHgAvLfvfiQj-kEZbuPgA8aYM4m01XaRlIlGt9KUmzdXYvCp7wfOc6bMXLH5uEhIOWGiN-Xl-MwRK25YkFzAqHbPySgdZNruhLfVm4nI0NOe-AoK7i2ivWps1q5AYa2iyi8gpBsC9ZBK7A_cPHqM68spg&send_stats=1&result=0
unknown
unknown
116
loader.exe
GET
204
95.163.50.150:80
http://mrds.mail.ru/update/2/version.txt?type=loader.begin&tool=loader&BID=%7B6BCF5CEB-B270-477F-8D33-3F7AEBD6B5FD%7D&kind=atom&masterid=%7B7D6D87E4-2B0C-4961-96B7-84BBF0C45E4A%7D&rfr=&newrfr=520002&os=6.1&ver=7.0.0.133&IVID=3AYCeP0-qm2700000Z16H4I7%3A%3A%3A0-0-0-6f8308d%3ACAASEGHgAvLfvfiQj-kEZbuPgA8aYM4m01XaRlIlGt9KUmzdXYvCp7wfOc6bMXLH5uEhIOWGiN-Xl-MwRK25YkFzAqHbPySgdZNruhLfVm4nI0NOe-AoK7i2ivWps1q5AYa2iyi8gpBsC9ZBK7A_cPHqM68spg&send_stats=1&send_stats=0
unknown
unknown
856
svchost.exe
GET
206
34.104.35.123:80
http://edgedl.me.gvt1.com/edgedl/release2/chrome_component/ANlaTV2JH2WK9RCoHi__mxg_1.0.6/S3ybLvFx94Hgn9pWLt24ug
unknown
binary
6.03 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
116
loader.exe
95.163.50.150:80
mrds.mail.ru
LLC VK
RU
unknown
4
System
192.168.100.255:138
whitelisted
116
loader.exe
142.250.186.142:443
www.google-analytics.com
GOOGLE
US
whitelisted
116
loader.exe
5.181.61.0:443
browser-asset.cdnmail.ru
LLC VK
RU
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
696
setup.exe
5.61.236.211:443
bs.browser.mail.ru
LLC VK
RU
unknown
696
setup.exe
184.24.77.182:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
696
setup.exe
104.18.20.226:80
ocsp.globalsign.com
CLOUDFLARENET
shared
2320
atom.exe
172.217.132.198:443
r1---sn-5hnednss.gvt1.com
unknown

DNS requests

Domain
IP
Reputation
mrds.mail.ru
  • 95.163.50.150
malicious
www.google-analytics.com
  • 142.250.186.142
whitelisted
browser-asset.cdnmail.ru
  • 5.181.61.0
unknown
bs.browser.mail.ru
  • 5.61.236.211
unknown
ctldl.windowsupdate.com
  • 184.24.77.182
  • 184.24.77.210
  • 184.24.77.200
  • 184.24.77.174
  • 184.24.77.205
  • 184.24.77.201
  • 93.184.221.240
  • 184.24.77.177
  • 184.24.77.193
  • 184.24.77.194
  • 184.24.77.186
  • 184.24.77.197
  • 184.24.77.203
  • 184.24.77.191
whitelisted
ocsp.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
ocsp2.globalsign.com
  • 104.18.20.226
  • 104.18.21.226
whitelisted
data.browser.mail.ru
  • 5.61.236.211
unknown
redirector.gvt1.com
  • 142.250.184.238
whitelisted
clients2.google.com
  • 142.250.186.142
whitelisted

Threats

PID
Process
Class
Message
2320
atom.exe
Potential Corporate Privacy Violation
AV POLICY Observed TikTok Domain in TLS SNI (tiktok.com)
2320
atom.exe
Not Suspicious Traffic
INFO [ANY.RUN] Cloudflare Network Error Logging (NEL)
1080
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain (www .mediafire .com) in DNS Lookup
1080
svchost.exe
Potentially Bad Traffic
ET HUNTING File Sharing Related Domain in DNS Lookup (download .mediafire .com)
6 ETPRO signatures available at the full report
No debug info