File name:

kontur.plugin.002143.exe

Full analysis: https://app.any.run/tasks/c2ff7fc2-a7a7-444f-bedc-32298e062cf0
Verdict: Malicious activity
Analysis date: August 28, 2024, 02:19:56
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

66A914561659C5AF2197F33A203BC088

SHA1:

410DBC8A389C8FE37BC41A1699E0F9FA95080FB3

SHA256:

193A92D67D2721CF5CE88E4CA88882BEEA085201E42041E483D8DC1FEF62588A

SSDEEP:

98304:AjcmWnqIun3YdLvfAgQJVrElDgID87u5oEzg23ZAhsZM+qpBSVNf+VN2yxIBBjfc:9Vbp7U/QWFCu1wwaSiiL

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Uses Task Scheduler to run other applications

      • kontur.updater.exe (PID: 5000)
      • kontur.plugin.002143.exe (PID: 4292)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • kontur.plugin.002143.exe (PID: 4292)
      • kontur.updater.exe (PID: 5000)
    • Drops the executable file immediately after the start

      • kontur.plugin.002143.exe (PID: 4292)
      • kontur.updater.exe (PID: 5000)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • kontur.plugin.002143.exe (PID: 4292)
      • kontur.updater.exe (PID: 5000)
    • Executable content was dropped or overwritten

      • kontur.plugin.002143.exe (PID: 4292)
      • kontur.updater.exe (PID: 5000)
    • Deletes scheduled task without confirmation

      • schtasks.exe (PID: 1480)
      • schtasks.exe (PID: 1156)
    • Creates/Modifies COM task schedule object

      • kontur.plugin.002143.exe (PID: 4292)
    • Creates a software uninstall entry

      • kontur.plugin.002143.exe (PID: 4292)
  • INFO

    • Checks supported languages

      • kontur.plugin.002143.exe (PID: 4292)
      • kontur.updater.exe (PID: 5000)
      • pkcs11check.exe (PID: 7144)
      • pkcs11check.exe (PID: 2584)
      • pkcs11check.exe (PID: 1172)
    • Reads Environment values

      • kontur.plugin.002143.exe (PID: 4292)
      • kontur.updater.exe (PID: 5000)
    • Creates files or folders in the user directory

      • kontur.plugin.002143.exe (PID: 4292)
      • kontur.updater.exe (PID: 5000)
    • Create files in a temporary directory

      • kontur.plugin.002143.exe (PID: 4292)
      • kontur.updater.exe (PID: 5000)
    • Reads the computer name

      • kontur.plugin.002143.exe (PID: 4292)
      • kontur.updater.exe (PID: 5000)
      • pkcs11check.exe (PID: 7144)
      • pkcs11check.exe (PID: 1172)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:25 22:12:18+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 28672
InitializedDataSize: 152576
UninitializedDataSize: 2048
EntryPoint: 0x3ac2
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 4.5.0.679
ProductVersionNumber: 4.5.0.679
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Russian
CharacterSet: Windows, Cyrillic
Comments: Инсталляционный пакет для установки Контур.Плагин 4.5.0.679
CompanyName: АО «ПФ «СКБ Контур»
FileDescription: Контур.Плагин 4.5.0.679
FileVersion: 4.5.0.679
LegalCopyright: © 2012-2024 АО «ПФ «СКБ Контур»
ProductName: Контур.Плагин
ProductVersion: 4.5.0.679
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
145
Monitored processes
16
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start kontur.plugin.002143.exe kontur.updater.exe schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs schtasks.exe no specs conhost.exe no specs pkcs11check.exe no specs conhost.exe no specs pkcs11check.exe no specs conhost.exe no specs pkcs11check.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1048\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeschtasks.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
1156"C:\WINDOWS\system32\schtasks.exe" /Delete /TN "Kontur.Plugin.Assistant-v4.5.0.679-S-1-5-21-1693682860-607145093-2874071422-1001" /F /HRESULTC:\Windows\SysWOW64\schtasks.exekontur.plugin.002143.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Scheduler Configuration Tool
Exit code:
2147942402
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
1172"C:\Users\admin\AppData\Local\SkbKontur\Plugin\4.5.0.679\pkcs11check.exe" jcpkcs11-2C:\Users\admin\AppData\Local\SkbKontur\Plugin\4.5.0.679\pkcs11check.exekontur.plugin.002143.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\skbkontur\plugin\4.5.0.679\pkcs11check.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
1480"C:\WINDOWS\system32\schtasks.exe" /Delete /TN "Kontur.Updater-v1.3.0.267-S-1-5-21-1693682860-607145093-2874071422-1001" /F /HRESULTC:\Windows\SysWOW64\schtasks.exekontur.updater.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Task Scheduler Configuration Tool
Exit code:
2147942402
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
2132\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepkcs11check.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2584"C:\Users\admin\AppData\Local\SkbKontur\Plugin\4.5.0.679\pkcs11check.exe" rtpkcs11C:\Users\admin\AppData\Local\SkbKontur\Plugin\4.5.0.679\pkcs11check.exekontur.plugin.002143.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
4294967294
Modules
Images
c:\users\admin\appdata\local\skbkontur\plugin\4.5.0.679\pkcs11check.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\shell32.dll
4276\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepkcs11check.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
4292"C:\Users\admin\AppData\Local\Temp\kontur.plugin.002143.exe" C:\Users\admin\AppData\Local\Temp\kontur.plugin.002143.exe
explorer.exe
User:
admin
Company:
АО «ПФ «СКБ Контур»
Integrity Level:
MEDIUM
Description:
Контур.Плагин 4.5.0.679
Exit code:
0
Version:
4.5.0.679
Modules
Images
c:\users\admin\appdata\local\temp\kontur.plugin.002143.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5000"C:\Users\admin\AppData\Local\SkbKontur\Plugin\4.5.0.679\kontur.updater.exe" /SC:\Users\admin\AppData\Local\SkbKontur\Plugin\4.5.0.679\kontur.updater.exe
kontur.plugin.002143.exe
User:
admin
Company:
АО «ПФ «СКБ Контур»
Integrity Level:
MEDIUM
Description:
Контур.Автообновления 1.3.0.267
Exit code:
0
Version:
1.3.0.267
Modules
Images
c:\users\admin\appdata\local\skbkontur\plugin\4.5.0.679\kontur.updater.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
5244\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepkcs11check.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
9 064
Read events
9 024
Write events
40
Delete events
0

Modification events

(PID) Process:(5000) kontur.updater.exeKey:HKEY_CURRENT_USER\SOFTWARE\SkbKontur\Updater
Operation:writeName:Path
Value:
C:\Users\admin\AppData\Local\SkbKontur\Updater\1.3.0.267
(PID) Process:(5000) kontur.updater.exeKey:HKEY_CURRENT_USER\SOFTWARE\SkbKontur\Updater
Operation:writeName:Version
Value:
1.3.0.267
(PID) Process:(4292) kontur.plugin.002143.exeKey:HKEY_CURRENT_USER\SOFTWARE\SkbKontur\Plugin\TrustedSites
Operation:writeName:https://*.kontur-ca.ru
Value:
0
(PID) Process:(4292) kontur.plugin.002143.exeKey:HKEY_CURRENT_USER\SOFTWARE\SkbKontur\Plugin\TrustedSites
Operation:writeName:https://*.kontur.ru
Value:
0
(PID) Process:(4292) kontur.plugin.002143.exeKey:HKEY_CURRENT_USER\SOFTWARE\SkbKontur\Plugin\TrustedSites
Operation:writeName:https://*.skbkontur.ru
Value:
0
(PID) Process:(4292) kontur.plugin.002143.exeKey:HKEY_CURRENT_USER\SOFTWARE\SkbKontur\Plugin\TrustedSites
Operation:writeName:https://*.testkontur.ru
Value:
0
(PID) Process:(4292) kontur.plugin.002143.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\kontur-ca.ru
Operation:writeName:https
Value:
2
(PID) Process:(4292) kontur.plugin.002143.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\kontur.ru
Operation:writeName:https
Value:
2
(PID) Process:(4292) kontur.plugin.002143.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\Domains\testkontur.ru
Operation:writeName:https
Value:
2
(PID) Process:(4292) kontur.plugin.002143.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap\EscDomains\kontur-ca.ru
Operation:writeName:https
Value:
2
Executable files
19
Suspicious files
5
Text files
7
Unknown types
0

Dropped files

PID
Process
Filename
Type
4292kontur.plugin.002143.exeC:\Users\admin\AppData\Local\Temp\nsyA17A.tmp\LockedList.dllexecutable
MD5:C9A339036BDC5205A4C1BB532C61C81F
SHA256:2C78F2AC46946CBE807CE66D6297D3EC355A9CCBED8A8F858D044456F73B7A2E
5000kontur.updater.exeC:\Users\admin\AppData\Local\Temp\nseB0BC.tmp\nsExec.dllexecutable
MD5:675C4948E1EFC929EDCABFE67148EDDD
SHA256:1076CA39C449ED1A968021B76EF31F22A5692DFAFEEA29460E8D970A63C59906
4292kontur.plugin.002143.exeC:\Users\admin\AppData\Local\Temp\nsyA17A.tmp\System.dllexecutable
MD5:CFF85C549D536F651D4FB8387F1976F2
SHA256:8DC562CDA7217A3A52DB898243DE3E2ED68B80E62DDCB8619545ED0B4E7F65A8
5000kontur.updater.exeC:\Users\admin\AppData\Local\SkbKontur\Updater\1.3.0.267\icon.icoimage
MD5:6CBAEC4411CC81008E688D0ED3AB3162
SHA256:24C81D883F825129B745F7FF1A8A528213338A19B47EEB0D566217C3A72EFB7F
4292kontur.plugin.002143.exeC:\Users\admin\AppData\Local\Temp\nsyA17A.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
5000kontur.updater.exeC:\Users\admin\AppData\Local\SkbKontur\Updater\1.3.0.267\uninstaller.exeexecutable
MD5:95880F25F45D9477396151D0DFDB830D
SHA256:C1EE1ACAE6962105346D2FBFE44001B2D116EE8483177CA737D13B662BAA5E69
5000kontur.updater.exeC:\Users\admin\AppData\Local\SkbKontur\Updater\1.3.0.267\nsuB0CD.tmpxml
MD5:9DD9F5EE4FC965245D3F636994230117
SHA256:BB335635822E611E2EDB640252C4FA2CAD6B2E1D1992BD685CBD3555E1C78173
5000kontur.updater.exeC:\Users\admin\AppData\Local\SkbKontur\Updater\1.3.0.267\install.logbinary
MD5:A2094B59FAABD4E704E6FD8AB749C861
SHA256:B332CA2C7D9D9CA0A6BE555C1697B4FFCDA0FF7BEDF02400F685134E03FB8C78
4292kontur.plugin.002143.exeC:\Users\admin\AppData\Local\SkbKontur\Plugin\4.5.0.679\kontur.plugin.assistant.exeexecutable
MD5:8080190CAB1A96FFED291478DCB59B91
SHA256:C32E7B43ACB38711CB7CA0C22A0FCD497CCD9436E517D6A3816D82EE1F5D7B87
4292kontur.plugin.002143.exeC:\Users\admin\AppData\Local\SkbKontur\Plugin\4.5.0.679\kontur.plugin.host.exeexecutable
MD5:E87446E38F383DC4F4D93249248D48CB
SHA256:6D6719CE2BCD0BD48787F2C2E47E3C2CB5D415F6666E99BDEAEA5CDB1738B45E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
20
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1064
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
3112
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
3112
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
6052
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6440
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6052
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3260
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1064
svchost.exe
20.190.160.22:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1064
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3112
SIHClient.exe
52.165.165.26:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 20.73.194.208
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.238
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
login.live.com
  • 20.190.160.22
  • 40.126.32.136
  • 40.126.32.138
  • 20.190.160.14
  • 40.126.32.133
  • 20.190.160.17
  • 40.126.32.76
  • 40.126.32.140
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
slscr.update.microsoft.com
  • 52.165.165.26
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.166.126.56
whitelisted

Threats

No threats detected
No debug info