File name:

YUMI-2.0.9.4.exe

Full analysis: https://app.any.run/tasks/33b56afb-a3a6-4b3c-bdb3-3ce44f09abcd
Verdict: Malicious activity
Analysis date: February 09, 2024, 20:59:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

8D47F1F9FBBBE4F61ED13A461F6BCB75

SHA1:

7063D881EC2D0C7CF39AA5B2CB05BEB18FA74C44

SHA256:

168A7FD30817E07EFECBD1805FF1E8629A62BE137B74D0B77958472F0993D134

SSDEEP:

49152:FEtHEek1Py6RURqIA1Dqml/v55Ng69nZlh+y/aSh+q10yNHTJzNQRORZcYibBy6Y:FEtHhk1Py6+RqVOml/v57g69nZP+ySrk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • YUMI-2.0.9.4.exe (PID: 3736)
  • SUSPICIOUS

    • Drops 7-zip archiver for unpacking

      • YUMI-2.0.9.4.exe (PID: 3736)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • YUMI-2.0.9.4.exe (PID: 3736)
    • The process creates files with name similar to system file names

      • YUMI-2.0.9.4.exe (PID: 3736)
    • Executable content was dropped or overwritten

      • YUMI-2.0.9.4.exe (PID: 3736)
  • INFO

    • Reads the computer name

      • YUMI-2.0.9.4.exe (PID: 3736)
    • Create files in a temporary directory

      • YUMI-2.0.9.4.exe (PID: 3736)
    • Manual execution by a user

      • msedge.exe (PID: 3944)
    • Application launched itself

      • msedge.exe (PID: 3944)
    • Checks supported languages

      • YUMI-2.0.9.4.exe (PID: 3736)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:08:01 02:44:18+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26112
InitializedDataSize: 141824
UninitializedDataSize: 2048
EntryPoint: 0x35d8
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.0.9.4
ProductVersionNumber: 2.0.9.4
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: pendrivelinux.com
FileDescription: YUMI
FileVersion: 2.0.9.4
LegalCopyright: Copyright © Pendrivelinux.com
License: GPL Version 2
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
68
Monitored processes
30
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start yumi-2.0.9.4.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs yumi-2.0.9.4.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
492"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3784 --field-trial-handle=1340,i,1156008643247336998,5788250300909157991,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
548"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=21 --mojo-platform-channel-handle=4132 --field-trial-handle=1340,i,1156008643247336998,5788250300909157991,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
604"C:\Users\admin\AppData\Local\Temp\YUMI-2.0.9.4.exe" C:\Users\admin\AppData\Local\Temp\YUMI-2.0.9.4.exeexplorer.exe
User:
admin
Company:
pendrivelinux.com
Integrity Level:
MEDIUM
Description:
YUMI
Exit code:
3221226540
Version:
2.0.9.4
Modules
Images
c:\users\admin\appdata\local\temp\yumi-2.0.9.4.exe
c:\windows\system32\ntdll.dll
764"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3596 --field-trial-handle=1340,i,1156008643247336998,5788250300909157991,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1392"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=20 --mojo-platform-channel-handle=4344 --field-trial-handle=1340,i,1156008643247336998,5788250300909157991,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1544"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3524 --field-trial-handle=1340,i,1156008643247336998,5788250300909157991,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1876"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6bcdf598,0x6bcdf5a8,0x6bcdf5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1932"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=23 --mojo-platform-channel-handle=4436 --field-trial-handle=1340,i,1156008643247336998,5788250300909157991,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2108"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=17 --mojo-platform-channel-handle=2160 --field-trial-handle=1340,i,1156008643247336998,5788250300909157991,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2112"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=3692 --field-trial-handle=1340,i,1156008643247336998,5788250300909157991,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
6 949
Read events
6 900
Write events
43
Delete events
6

Modification events

(PID) Process:(3736) YUMI-2.0.9.4.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager
Operation:writeName:PendingFileRenameOperations
Value:
\??\C:\Users\admin\AppData\Local\Temp\nsuF232.tmp\
(PID) Process:(3944) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(3944) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(3944) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(3944) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(3944) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(3944) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:dr
Value:
1
(PID) Process:(3944) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(3944) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge
Operation:writeName:UsageStatsInSample
Value:
1
(PID) Process:(3944) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:usagestats
Value:
1
Executable files
39
Suspicious files
99
Text files
182
Unknown types
402

Dropped files

PID
Process
Filename
Type
3736YUMI-2.0.9.4.exeC:\Users\admin\AppData\Local\Temp\nsuF232.tmp\diskpartdetach.txttext
MD5:7DB3A9D4C5E308EC27997829B50F0A9B
SHA256:F5AEB338A52788F9D58140A487C0BA9751879E207A234615A9EB75A1FECFC6FB
3736YUMI-2.0.9.4.exeC:\Users\admin\AppData\Local\Temp\nsuF232.tmp\diskpart.txttext
MD5:C2DD6D67EABDC21CF599B6858432CA2A
SHA256:522E554325FCDAB06669173DB657F63F0CF9C475D12072248A738B2828D0CCC6
3736YUMI-2.0.9.4.exeC:\Users\admin\AppData\Local\Temp\nsuF232.tmp\w2gdiskpart.txttext
MD5:27460E6F2B35B067EE26BA5ED01CFC08
SHA256:C707E60918F4236E1F85416B7661DB0C37C7247552211B733D74340885CC7619
3736YUMI-2.0.9.4.exeC:\Users\admin\AppData\Local\Temp\nsuF232.tmp\dd-diskpart.txttext
MD5:814209DD3CB4F219B7986E32C24C2EEA
SHA256:28F37A21DA104E03755507864B19C253A012544568CB0A9884B9DF7EE90D226C
3736YUMI-2.0.9.4.exeC:\Users\admin\AppData\Local\Temp\nsuF232.tmp\grubram.lsttext
MD5:430484D91BEC79E7208CACE852F6A78C
SHA256:9BF81120ABBC0EC9DBC7F831B3BFBF9723E203C1D96F97E3FDB5B0E888424721
3736YUMI-2.0.9.4.exeC:\Users\admin\AppData\Local\Temp\nsuF232.tmp\autounattend.xmlxml
MD5:B74F7534A1BA470DF96710174D6C2833
SHA256:3512102FB79F459B795F848F0DC57CDF949C4C9B56B4E110D7DF4C5D9D712478
3736YUMI-2.0.9.4.exeC:\Users\admin\AppData\Local\Temp\nsuF232.tmp\grubpart4.lsttext
MD5:B5FFE24A81C6C4C9B192C8298BD7A799
SHA256:CBB7CDFE105484FA3B05AC569AF0F7A1A9D394C307B85DCB5DCB70174C3F4E7E
3736YUMI-2.0.9.4.exeC:\Users\admin\AppData\Local\Temp\nsuF232.tmp\syslinux.exeexecutable
MD5:D2922AD355EA02A59E563F327521A888
SHA256:AC389246CD45E69C1E41F88EF87F4083A817A97E0FEAA153BA677CA703D36FAB
3736YUMI-2.0.9.4.exeC:\Users\admin\AppData\Local\Temp\nsuF232.tmp\syslinux.cfgtext
MD5:E6A8A3509B9E931DB90ED2582CF12D9F
SHA256:A557583F6F67B6AE7D3AB04FC006E3A284F34F19F6F80EB297020700773C7C78
3736YUMI-2.0.9.4.exeC:\Users\admin\AppData\Local\Temp\nsuF232.tmp\vhd.lsttext
MD5:6BC5DEF24486A776AF30743790126E77
SHA256:31D8691E4F6A91F5C1366E3A32924B359531E6A0D8F7E1ED28B6A6782FF397C8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
80
DNS requests
102
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3944
msedge.exe
239.255.255.250:1900
unknown
4044
msedge.exe
204.79.197.203:443
ntp.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4044
msedge.exe
13.107.21.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4044
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4044
msedge.exe
2.16.241.151:443
assets.msn.com
Akamai International B.V.
DE
unknown
4044
msedge.exe
204.79.197.200:443
c.bing.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4044
msedge.exe
2.16.164.74:443
img-s-msn-com.akamaized.net
Akamai International B.V.
NL
unknown

DNS requests

Domain
IP
Reputation
ntp.msn.com
  • 204.79.197.203
whitelisted
edge.microsoft.com
  • 13.107.21.239
  • 204.79.197.239
  • 131.253.33.239
  • 13.107.22.239
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
assets.msn.com
  • 2.16.241.151
  • 2.16.241.162
whitelisted
img-s-msn-com.akamaized.net
  • 2.16.164.74
  • 2.16.164.32
whitelisted
sb.scorecardresearch.com
  • 13.249.9.34
  • 13.249.9.46
  • 13.249.9.65
  • 13.249.9.35
shared
th.bing.com
  • 2.16.241.138
  • 2.16.241.157
whitelisted
www.bing.com
  • 2.16.241.138
  • 2.16.241.157
whitelisted
c.msn.com
  • 68.219.88.97
whitelisted
api.msn.com
  • 204.79.197.203
whitelisted

Threats

No threats detected
No debug info