File name:

DefenderRemover.exe

Full analysis: https://app.any.run/tasks/24df1f53-a30a-46b3-a73a-c5aa3a8061bf
Verdict: Malicious activity
Analysis date: October 22, 2023, 02:16:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

0CA124641117A60490958117D60B3CED

SHA1:

73ACE6C707D29E2D16E8385AE9C17BA4142D0917

SHA256:

19C09FAD30C786CC22FB38D3F97021C0B35AAA9CD288D44970A45B5D1CB86070

SSDEEP:

24576:+hUhnNLRsf4mZQjzbQOLIArg79Ie2cLKifsRHFhU4Ccqpzz4hzh0:+hUhnNLWf4mZQjzcOLIArg79Ie2cLKib

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • DefenderRemover.exe (PID: 3328)
  • SUSPICIOUS

    • The process executes via Task Scheduler

      • sipnotify.exe (PID: 776)
    • Executing commands from a ".bat" file

      • DefenderRemover.exe (PID: 3328)
    • Starts CMD.EXE for commands execution

      • DefenderRemover.exe (PID: 3328)
    • The system shut down or reboot

      • cmd.exe (PID: 2504)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 2504)
    • Reads the Internet Settings

      • sipnotify.exe (PID: 776)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 2504)
    • Reads settings of System Certificates

      • sipnotify.exe (PID: 776)
  • INFO

    • Checks supported languages

      • DefenderRemover.exe (PID: 3328)
      • wmpnscfg.exe (PID: 3304)
      • wmpnscfg.exe (PID: 3808)
      • IMEKLMG.EXE (PID: 1880)
      • IMEKLMG.EXE (PID: 552)
    • Manual execution by a user

      • IMEKLMG.EXE (PID: 552)
      • IMEKLMG.EXE (PID: 1880)
      • wmpnscfg.exe (PID: 3304)
      • wmpnscfg.exe (PID: 3808)
    • Reads the computer name

      • IMEKLMG.EXE (PID: 1880)
      • wmpnscfg.exe (PID: 3808)
      • IMEKLMG.EXE (PID: 552)
      • wmpnscfg.exe (PID: 3304)
    • Reads security settings of Internet Explorer

      • sipnotify.exe (PID: 776)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3808)
      • wmpnscfg.exe (PID: 3304)
    • Process checks are UAC notifies on

      • IMEKLMG.EXE (PID: 552)
      • IMEKLMG.EXE (PID: 1880)
    • Create files in a temporary directory

      • DefenderRemover.exe (PID: 3328)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:11:18 17:27:35+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 104960
InitializedDataSize: 91136
UninitializedDataSize: -
EntryPoint: 0x14b04
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 12.5.6.0
ProductVersionNumber: 12.5.6.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Gallery Inc
FileDescription: Defender Remover
FileVersion: 12.5.6
LegalCopyright: Gallery Inc.
ProductName: Defender Remover
ProductVersion: 12.5.6
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
105
Monitored processes
20
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start defenderremover.exe cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs timeout.exe no specs shutdown.exe no specs sipnotify.exe no specs imeklmg.exe no specs imeklmg.exe no specs wmpnscfg.exe no specs wmpnscfg.exe no specs defenderremover.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
148taskkill.exe /f /im "SecurityHealthSystray.exe"C:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
372"C:\Users\admin\AppData\Local\Temp\DefenderRemover.exe" C:\Users\admin\AppData\Local\Temp\DefenderRemover.exeexplorer.exe
User:
admin
Company:
Gallery Inc
Integrity Level:
MEDIUM
Description:
Defender Remover
Exit code:
3221226540
Version:
12.5.6
Modules
Images
c:\users\admin\appdata\local\temp\defenderremover.exe
c:\windows\system32\ntdll.dll
552"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gdi32.dll
776C:\Windows\system32\sipnotify.exe -LogonOrUnlockC:\Windows\System32\sipnotify.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
sipnotify
Exit code:
0
Version:
6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716)
Modules
Images
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\atl.dll
c:\windows\system32\lpk.dll
1880"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
1928taskkill.exe /f /im "smartscreen.exe"C:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2504C:\Windows\system32\cmd.exe /c .\Script_Run.batC:\Windows\System32\cmd.exeDefenderRemover.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2592taskkill.exe /f /im "explorer.exe"C:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2628taskkill.exe /f /im "CompatTelRunner.exe"C:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2708taskkill.exe /f /im "MsMpEng.exe"C:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
Total events
3 730
Read events
3 707
Write events
14
Delete events
9

Modification events

(PID) Process:(1880) IMEKLMG.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\IMEJP\14.0
Operation:writeName:SetPreload
Value:
1
(PID) Process:(552) IMEKLMG.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\IMEKR\14.0
Operation:writeName:SetPreload
Value:
1
(PID) Process:(776) sipnotify.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3808) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{069C3E2E-1475-4C7C-807F-825FD013EEE9}\{99B9D879-3B18-4E14-8EC9-714219FE5D0B}
Operation:delete keyName:(default)
Value:
(PID) Process:(3808) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{E64E2FF4-6241-4299-8EC1-2B46F6DA71B7}\{99B9D879-3B18-4E14-8EC9-714219FE5D0B}
Operation:delete keyName:(default)
Value:
(PID) Process:(3808) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{E64E2FF4-6241-4299-8EC1-2B46F6DA71B7}
Operation:delete keyName:(default)
Value:
(PID) Process:(3808) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{069C3E2E-1475-4C7C-807F-825FD013EEE9}
Operation:delete keyName:(default)
Value:
(PID) Process:(3808) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{2D0359F0-0873-4314-9D7A-C3B47B2EB783}
Operation:delete keyName:(default)
Value:
(PID) Process:(3304) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{9B6B7F81-C3B6-45F6-A698-3293772B0432}\{99B9D879-3B18-4E14-8EC9-714219FE5D0B}
Operation:delete keyName:(default)
Value:
(PID) Process:(3304) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{9B6B7F81-C3B6-45F6-A698-3293772B0432}\{C860D197-F12B-4F0B-8E4D-E7BBFC9E5D46}
Operation:delete keyName:(default)
Value:
Executable files
1
Suspicious files
1
Text files
47
Unknown types
0

Dropped files

PID
Process
Filename
Type
3328DefenderRemover.exeC:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\Disabler\Disable.regtext
MD5:829F09083D98F7997276052600B46CDB
SHA256:0CD173050E2C8DC4C57FAD2CB2DD539E8B2EC240C83CC1D0EAAD06686FF05FC6
3328DefenderRemover.exeC:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\licensetext
MD5:B7D8C78F833C8E135126A40AF0A61EFD
SHA256:B39F865F1B11CFFEC80DB73944CDCA7B578EB4581316302B1A8EC9312E584F29
3328DefenderRemover.exeC:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\Remover\REGS\Disable Defender and Security Center Notifications.regtext
MD5:27D6FF90F0AC39314BDF634EC5E30828
SHA256:16D513C42B3851AC0C7DD50411E65ABF71CDD321D0F4E09DFFC3E8D0B8D3B3D0
3328DefenderRemover.exeC:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\Remover\REGS\Disable Defender Policies.regtext
MD5:1C47710A69E61B9C68DA2629C3EF5D33
SHA256:68DAD1D7067BB7AC3B983866843ED71C46656E0918D5139241BB6D702516481F
3328DefenderRemover.exeC:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\Remover\REGS\Disable Dev Drive Protection.regtext
MD5:9FDF23C1A9D5C83D2915760E28C361CC
SHA256:48AFB9652ABD7EC73B375692A20558476F316A1CBD4B29802D0B760B203636F7
3328DefenderRemover.exeC:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\Remover\REGS\Disable LSA Protection.regtext
MD5:EBA762017AB33C896EA6B4AEBC13C8CA
SHA256:E71CE14CF0E4F74FE758BA3CFA45B41DA96BF8FDD8B34EF0A50867BC77252F65
3328DefenderRemover.exeC:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\Remover\REGS\Disable SmartScreen.regtext
MD5:1661861B318233AC53A0953F4A275CAC
SHA256:8BB02EDC6439C86DF129E788F9E7FE040495C53D20F20CBC02000652FFE937BD
3328DefenderRemover.exeC:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\README.mdtext
MD5:04D3BF0CE437FFE372DC6677D7550930
SHA256:3A7CE9A038E9AF620122868C492D10E691B97469E56B8A4B0BF8DD64E4A4478B
3328DefenderRemover.exeC:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\DisablerS\Enable.regtext
MD5:62DE041AA55EC42385B147C8ED78497F
SHA256:6A3C6CA0DF2BB5A67B1D7348F6D6B22023E0D9839FEEC9393DB1C0B4BA767D88
3328DefenderRemover.exeC:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\DisablerS\Disable.regtext
MD5:4C1B99671D4DFDAB576F815F68703407
SHA256:9CE7E4665026E6FCD3BB0178F37F251652109DFCAB25B90C968801A8494DBB45
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
11
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
HEAD
200
23.212.215.38:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133424182173750000
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1088
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2656
svchost.exe
239.255.255.250:1900
whitelisted
23.212.215.38:80
query.prod.cms.rt.microsoft.com
AKAMAI-AS
AU
unknown
224.0.0.252:5355
unknown
239.255.255.250:1900
unknown

DNS requests

Domain
IP
Reputation
query.prod.cms.rt.microsoft.com
  • 23.212.215.38
whitelisted

Threats

No threats detected
No debug info