File name:

Cortana.exe

Full analysis: https://app.any.run/tasks/171448d3-c956-47ed-8512-e176869cc618
Verdict: Malicious activity
Analysis date: January 31, 2024, 20:51:33
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

D3FD37594BFE7E39C2A4D5B07CB47FA6

SHA1:

669C6E0F485B071A9685B72D425ABCAA4A81DDC3

SHA256:

18224CBB171DDD80103F0DC357B0098C987F3310E1C6BFDA15C35B231C98B194

SSDEEP:

192:WxFC9NwVa+b5q5EpwJ3zlM1puG8z7a66u+38wnc:cFtE8OEpuji1puG8S66u+38wn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Cortana.exe (PID: 752)
    • Starts NET.EXE to view/add/change user profiles

      • cmd.exe (PID: 3968)
      • net.exe (PID: 3688)
      • net.exe (PID: 1812)
      • cmd.exe (PID: 3868)
    • Connects to the CnC server

      • Cortana.exe (PID: 3420)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Cortana.exe (PID: 3420)
    • Starts CMD.EXE for commands execution

      • Cortana.exe (PID: 3420)
  • INFO

    • Reads the computer name

      • Cortana.exe (PID: 752)
      • Cortana.exe (PID: 3420)
      • Cortana.exe (PID: 3148)
    • Checks supported languages

      • Cortana.exe (PID: 752)
      • Cortana.exe (PID: 3420)
      • Cortana.exe (PID: 3148)
    • Reads the machine GUID from the registry

      • Cortana.exe (PID: 752)
      • Cortana.exe (PID: 3420)
      • Cortana.exe (PID: 3148)
    • Reads Environment values

      • Cortana.exe (PID: 752)
      • Cortana.exe (PID: 3420)
      • Cortana.exe (PID: 3148)
    • Manual execution by a user

      • explorer.exe (PID: 3244)
      • Cortana.exe (PID: 3420)
      • Cortana.exe (PID: 3148)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (82.9)
.dll | Win32 Dynamic Link Library (generic) (7.4)
.exe | Win32 Executable (generic) (5.1)
.exe | Generic Win/DOS Executable (2.2)
.exe | DOS Executable Generic (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2105:11:20 23:41:15+01:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 6656
InitializedDataSize: 2560
UninitializedDataSize: -
EntryPoint: 0x3916
OSVersion: 4
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Sprachrecognition Service
CompanyName: CyberCyberCyber
FileDescription: Sprachrecognition Service
FileVersion: 1.0.0.0
InternalName: Cortana.exe
LegalCopyright: © CyberCyberCyber Corporation. Alle Rechte vorbehalten.
LegalTrademarks: CyberCyberCyber Corporation
OriginalFileName: Cortana.exe
ProductName: Sprachrecognition Service
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
10
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start cortana.exe explorer.exe no specs cortana.exe cmd.exe no specs net.exe no specs net1.exe no specs cmd.exe no specs net.exe no specs net1.exe no specs cortana.exe

Process information

PID
CMD
Path
Indicators
Parent process
752"C:\Users\admin\AppData\Local\Temp\Cortana.exe" C:\Users\admin\AppData\Local\Temp\Cortana.exe
explorer.exe
User:
admin
Company:
CyberCyberCyber
Integrity Level:
MEDIUM
Description:
Sprachrecognition Service
Exit code:
3762504530
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\cortana.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1812net user AbcDefGh SecUreP$a!ass! addC:\Windows\System32\net.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
3148"C:\Users\admin\AppData\Local\Temp\Cortana.exe" C:\Users\admin\AppData\Local\Temp\Cortana.exe
explorer.exe
User:
admin
Company:
CyberCyberCyber
Integrity Level:
HIGH
Description:
Sprachrecognition Service
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\cortana.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3244"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3420"C:\Users\admin\AppData\Local\Temp\Cortana.exe" C:\Users\admin\AppData\Local\Temp\Cortana.exe
explorer.exe
User:
admin
Company:
CyberCyberCyber
Integrity Level:
HIGH
Description:
Sprachrecognition Service
Exit code:
3221225786
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\cortana.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3688net user AbcDefGh SecUreP$a!ass! addC:\Windows\System32\net.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
3868"cmd.exe" cmd /c net user AbcDefGh SecUreP$a!ass! addC:\Windows\System32\cmd.exeCortana.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3968"cmd.exe" cmd /c net user AbcDefGh SecUreP$a!ass! addC:\Windows\System32\cmd.exeCortana.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
4032C:\Windows\system32\net1 user AbcDefGh SecUreP$a!ass! addC:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
4040C:\Windows\system32\net1 user AbcDefGh SecUreP$a!ass! addC:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
Total events
1 005
Read events
1 005
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
6
DNS requests
2
Threats
3

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3420
Cortana.exe
GET
200
132.226.207.129:80
http://haxxorterm.ryanlab.cc/command.txt
unknown
text
38 b
unknown
3420
Cortana.exe
GET
200
132.226.207.129:80
http://haxxorterm.ryanlab.cc/command.txt
unknown
text
38 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
584
WerFault.exe
104.208.16.93:443
watson.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
3420
Cortana.exe
132.226.207.129:80
haxxorterm.ryanlab.cc
ORACLE-BMC-31898
DE
unknown

DNS requests

Domain
IP
Reputation
watson.microsoft.com
  • 104.208.16.93
whitelisted
haxxorterm.ryanlab.cc
  • 132.226.207.129
unknown

Threats

PID
Process
Class
Message
1080
svchost.exe
Potentially Bad Traffic
ET DNS Query for .cc TLD
2 ETPRO signatures available at the full report
No debug info