File name: | Kiddion's Modest Menu v1.0.0.exe |
Full analysis: | https://app.any.run/tasks/fbde2be6-11c6-4870-8f94-67965eb22704 |
Verdict: | Malicious activity |
Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
Analysis date: | February 13, 2025, 18:44:23 |
OS: | Windows 10 Professional (build: 19045, 64 bit) |
Tags: | |
Indicators: | |
MIME: | application/vnd.microsoft.portable-executable |
File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 4 sections |
MD5: | 1B42AE72244FE478315D9872AC67FE14 |
SHA1: | 0B014D2B53C86645ADC9BCA61DC1A82DCE05BD2D |
SHA256: | 17D0FA1CC832785514EAE5E04801B0C20BB9BCAC25E75E406B31BE628D30036B |
SSDEEP: | 12288:2/BTUw8EVCEx6WdMK5+MAcEqOKbWNh8JN7BNe8CRIV8:2pTUwdVCExjdMK5XA7vuWNhAN7BNe8CD |
.dll | | | Win32 Dynamic Link Library (generic) (38.3) |
---|---|---|
.exe | | | Win32 Executable (generic) (26.2) |
.exe | | | Win16/32 Executable Delphi generic (12) |
.exe | | | Generic Win/DOS Executable (11.6) |
.exe | | | DOS Executable Generic (11.6) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2062:07:01 12:33:16+00:00 |
ImageFileCharacteristics: | Executable, Large address aware |
PEType: | PE32 |
LinkerVersion: | 48 |
CodeSize: | 8704 |
InitializedDataSize: | 2048 |
UninitializedDataSize: | - |
EntryPoint: | 0x3ab6 |
OSVersion: | 4 |
ImageVersion: | - |
SubsystemVersion: | 6 |
Subsystem: | Windows GUI |
FileVersionNumber: | 1.0.0.0 |
ProductVersionNumber: | 1.0.0.0 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | Neutral |
CharacterSet: | Unicode |
Comments: | - |
CompanyName: | - |
FileDescription: | Purpose |
FileVersion: | 1.0.0.0 |
InternalName: | Purpose.exe |
LegalCopyright: | Copyright © 2025 |
LegalTrademarks: | - |
OriginalFileName: | Purpose.exe |
ProductName: | Purpose |
ProductVersion: | 1.0.0.0 |
AssemblyVersion: | 1.0.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2212 | "C:\Users\admin\AppData\Local\Temp\Kiddion's Modest Menu v1.0.0.exe" | C:\Users\admin\AppData\Local\Temp\Kiddion's Modest Menu v1.0.0.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Purpose Exit code: 3221226505 Version: 1.0.0.0 Modules
| |||||||||||||||
4052 | "C:\Users\admin\AppData\Local\Temp\Kiddion's Modest Menu v1.0.0.exe" | C:\Users\admin\AppData\Local\Temp\Kiddion's Modest Menu v1.0.0.exe | Kiddion's Modest Menu v1.0.0.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Purpose Version: 1.0.0.0 Modules
| |||||||||||||||
6180 | C:\WINDOWS\SysWOW64\WerFault.exe -u -p 2212 -s 828 | C:\Windows\SysWOW64\WerFault.exe | Kiddion's Modest Menu v1.0.0.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Problem Reporting Exit code: 0 Version: 10.0.19041.3996 (WinBuild.160101.0800) Modules
| |||||||||||||||
7044 | "C:\Users\admin\AppData\Local\Temp\3JB7RDDEPI5F6OWT269SXOSHX.exe" | C:\Users\admin\AppData\Local\Temp\3JB7RDDEPI5F6OWT269SXOSHX.exe | — | Kiddion's Modest Menu v1.0.0.exe | |||||||||||
User: admin Company: Microsoft® Windows® Integrity Level: MEDIUM Description: Programs Engine Exit code: 3221226540 Version: 10.0.19041.746 Modules
|
PID | Process | Filename | Type | |
---|---|---|---|---|
6180 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_Kiddion's Modest_6624a91e860e36fa24ce1ca3923c44462676bb_3c9d8d7b_bb9a342b-d643-4d59-8b71-e34e502971b6\Report.wer | — | |
MD5:— | SHA256:— | |||
6180 | WerFault.exe | C:\Users\admin\AppData\Local\CrashDumps\Kiddion's Modest Menu v1.0.0.exe.2212.dmp | — | |
MD5:— | SHA256:— | |||
6180 | WerFault.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\21253908F3CB05D51B1C2DA8B681A785 | binary | |
MD5:0425BE550E212D86A15DBD3DD5E77C15 | SHA256:B4A70DAEB5ECB6D8E29D25332C0276F37C90B87857D682C07A48D406B5F9752C | |||
6180 | WerFault.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\37C951188967C8EB88D99893D9D191FE | binary | |
MD5:FA84E4BCC92AA5DB735AB50711040CDE | SHA256:6D7205E794FDE4219A62D9692ECDDF612663A5CF20399E79BE87B851FCA4CA33 | |||
6180 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WERC76C.tmp.xml | xml | |
MD5:E9EFBF1249AB2FB7DB85AF0E68F5AF0F | SHA256:B961FFBD2CBEBC8088A905CCEAFB4F946AF215C82F107D3545CB935136C46D7A | |||
6180 | WerFault.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\21253908F3CB05D51B1C2DA8B681A785 | binary | |
MD5:680B0331A3CC8FCCE16367586EC7A721 | SHA256:19F1B5D2C7F62663C14D97578411DC610E5F33E6CE4165977314442435F15305 | |||
6180 | WerFault.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FE | binary | |
MD5:81584A78725A115D9096BBC7E2CCF784 | SHA256:B4AFF790CA692C6B2AA704D47022CCABCD367E8804E786FC29B96AABAF9E1280 | |||
6180 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WERC49B.tmp.dmp | binary | |
MD5:631CA750BB2FB8306F1FF759464D0881 | SHA256:0E8CACFDF678AB6C1434DC63DA47B5CDA3D667513191FB316B125F36EA7D8EFD | |||
6180 | WerFault.exe | C:\ProgramData\Microsoft\Windows\WER\Temp\WERC6EE.tmp.WERInternalMetadata.xml | binary | |
MD5:21B5156C78F760B9A67BC5C163D7E3E3 | SHA256:1D825B32F5AF4F24D282C5B5D09A631EBAEB6EA77B239FF5A6340C194EF5BC64 | |||
4052 | Kiddion's Modest Menu v1.0.0.exe | C:\Users\admin\AppData\Local\Temp\3JB7RDDEPI5F6OWT269SXOSHX.exe | executable | |
MD5:C11A82D699A06D9B8BA4296E0C562AE4 | SHA256:483B1D7DAC70DE82E9B22A0C1ED775CF7E10B0A3790C5AA1B9215DBCD1754302 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
4052 | Kiddion's Modest Menu v1.0.0.exe | GET | 200 | 185.215.113.51:80 | http://185.215.113.51/conhost.exe | unknown | — | — | malicious |
1176 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7128 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
7128 | SIHClient.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
6180 | WerFault.exe | GET | 200 | 23.35.229.160:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
6180 | WerFault.exe | GET | 200 | 2.19.198.104:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 51.104.136.2:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4052 | Kiddion's Modest Menu v1.0.0.exe | 104.21.64.1:443 | friendseforever.help | CLOUDFLARENET | — | malicious |
1176 | svchost.exe | 20.190.160.132:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1176 | svchost.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
1076 | svchost.exe | 2.19.106.8:443 | go.microsoft.com | AKAMAI-AS | DE | whitelisted |
4052 | Kiddion's Modest Menu v1.0.0.exe | 185.215.113.51:80 | — | 1337team Limited | SC | malicious |
7128 | SIHClient.exe | 4.175.87.197:443 | slscr.update.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
7128 | SIHClient.exe | 23.35.229.160:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
Domain | IP | Reputation |
---|---|---|
friendseforever.help |
| malicious |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
watson.events.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
— | — | Potentially Bad Traffic | ET INFO Executable Download from dotted-quad Host |
— | — | Misc Attack | ET DROP Spamhaus DROP Listed Traffic Inbound group 32 |
— | — | Potential Corporate Privacy Violation | ET INFO PE EXE or DLL Windows file download HTTP |
— | — | Potentially Bad Traffic | ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response |