File name:

DefenderRemover.exe

Full analysis: https://app.any.run/tasks/24df1f53-a30a-46b3-a73a-c5aa3a8061bf
Verdict: Malicious activity
Analysis date: October 22, 2023, 02:16:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

0CA124641117A60490958117D60B3CED

SHA1:

73ACE6C707D29E2D16E8385AE9C17BA4142D0917

SHA256:

19C09FAD30C786CC22FB38D3F97021C0B35AAA9CD288D44970A45B5D1CB86070

SSDEEP:

24576:+hUhnNLRsf4mZQjzbQOLIArg79Ie2cLKifsRHFhU4Ccqpzz4hzh0:+hUhnNLWf4mZQjzcOLIArg79Ie2cLKib

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • DefenderRemover.exe (PID: 3328)
  • SUSPICIOUS

    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 2504)
    • Starts CMD.EXE for commands execution

      • DefenderRemover.exe (PID: 3328)
    • The process executes via Task Scheduler

      • sipnotify.exe (PID: 776)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 2504)
    • Reads the Internet Settings

      • sipnotify.exe (PID: 776)
    • The system shut down or reboot

      • cmd.exe (PID: 2504)
    • Executing commands from a ".bat" file

      • DefenderRemover.exe (PID: 3328)
    • Reads settings of System Certificates

      • sipnotify.exe (PID: 776)
  • INFO

    • Manual execution by a user

      • IMEKLMG.EXE (PID: 1880)
      • IMEKLMG.EXE (PID: 552)
      • wmpnscfg.exe (PID: 3304)
      • wmpnscfg.exe (PID: 3808)
    • Create files in a temporary directory

      • DefenderRemover.exe (PID: 3328)
    • Checks supported languages

      • DefenderRemover.exe (PID: 3328)
      • IMEKLMG.EXE (PID: 1880)
      • IMEKLMG.EXE (PID: 552)
      • wmpnscfg.exe (PID: 3304)
      • wmpnscfg.exe (PID: 3808)
    • Reads the computer name

      • IMEKLMG.EXE (PID: 1880)
      • IMEKLMG.EXE (PID: 552)
      • wmpnscfg.exe (PID: 3304)
      • wmpnscfg.exe (PID: 3808)
    • Process checks are UAC notifies on

      • IMEKLMG.EXE (PID: 1880)
      • IMEKLMG.EXE (PID: 552)
    • Reads security settings of Internet Explorer

      • sipnotify.exe (PID: 776)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3304)
      • wmpnscfg.exe (PID: 3808)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:11:18 17:27:35+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 104960
InitializedDataSize: 91136
UninitializedDataSize: -
EntryPoint: 0x14b04
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 12.5.6.0
ProductVersionNumber: 12.5.6.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Gallery Inc
FileDescription: Defender Remover
FileVersion: 12.5.6
LegalCopyright: Gallery Inc.
ProductName: Defender Remover
ProductVersion: 12.5.6
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
105
Monitored processes
20
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start defenderremover.exe cmd.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs taskkill.exe no specs timeout.exe no specs shutdown.exe no specs sipnotify.exe no specs imeklmg.exe no specs imeklmg.exe no specs wmpnscfg.exe no specs wmpnscfg.exe no specs defenderremover.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
148taskkill.exe /f /im "SecurityHealthSystray.exe"C:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
372"C:\Users\admin\AppData\Local\Temp\DefenderRemover.exe" C:\Users\admin\AppData\Local\Temp\DefenderRemover.exeexplorer.exe
User:
admin
Company:
Gallery Inc
Integrity Level:
MEDIUM
Description:
Defender Remover
Exit code:
3221226540
Version:
12.5.6
Modules
Images
c:\users\admin\appdata\local\temp\defenderremover.exe
c:\windows\system32\ntdll.dll
552"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
c:\windows\system32\profapi.dll
c:\windows\system32\gdi32.dll
776C:\Windows\system32\sipnotify.exe -LogonOrUnlockC:\Windows\System32\sipnotify.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
sipnotify
Exit code:
0
Version:
6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716)
Modules
Images
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\atl.dll
c:\windows\system32\lpk.dll
1880"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
1928taskkill.exe /f /im "smartscreen.exe"C:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2504C:\Windows\system32\cmd.exe /c .\Script_Run.batC:\Windows\System32\cmd.exeDefenderRemover.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2592taskkill.exe /f /im "explorer.exe"C:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2628taskkill.exe /f /im "CompatTelRunner.exe"C:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2708taskkill.exe /f /im "MsMpEng.exe"C:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
Total events
3 730
Read events
3 707
Write events
14
Delete events
9

Modification events

(PID) Process:(1880) IMEKLMG.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\IMEJP\14.0
Operation:writeName:SetPreload
Value:
1
(PID) Process:(552) IMEKLMG.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\IMEKR\14.0
Operation:writeName:SetPreload
Value:
1
(PID) Process:(776) sipnotify.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3808) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{069C3E2E-1475-4C7C-807F-825FD013EEE9}\{99B9D879-3B18-4E14-8EC9-714219FE5D0B}
Operation:delete keyName:(default)
Value:
(PID) Process:(3808) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{E64E2FF4-6241-4299-8EC1-2B46F6DA71B7}\{99B9D879-3B18-4E14-8EC9-714219FE5D0B}
Operation:delete keyName:(default)
Value:
(PID) Process:(3808) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{E64E2FF4-6241-4299-8EC1-2B46F6DA71B7}
Operation:delete keyName:(default)
Value:
(PID) Process:(3808) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{069C3E2E-1475-4C7C-807F-825FD013EEE9}
Operation:delete keyName:(default)
Value:
(PID) Process:(3808) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{2D0359F0-0873-4314-9D7A-C3B47B2EB783}
Operation:delete keyName:(default)
Value:
(PID) Process:(3304) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{9B6B7F81-C3B6-45F6-A698-3293772B0432}\{99B9D879-3B18-4E14-8EC9-714219FE5D0B}
Operation:delete keyName:(default)
Value:
(PID) Process:(3304) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{9B6B7F81-C3B6-45F6-A698-3293772B0432}\{C860D197-F12B-4F0B-8E4D-E7BBFC9E5D46}
Operation:delete keyName:(default)
Value:
Executable files
1
Suspicious files
1
Text files
47
Unknown types
0

Dropped files

PID
Process
Filename
Type
3328DefenderRemover.exeC:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\app_icon.icoimage
MD5:7D5F541A9A9D34F590D7B2D6EC0679C9
SHA256:41E74B6217B1E44F8EA07EDC3C2677E28EEFCDF84E0B8A8299FE7601840B15BA
3328DefenderRemover.exeC:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\Disabler\Disable.regtext
MD5:829F09083D98F7997276052600B46CDB
SHA256:0CD173050E2C8DC4C57FAD2CB2DD539E8B2EC240C83CC1D0EAAD06686FF05FC6
3328DefenderRemover.exeC:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\licensetext
MD5:B7D8C78F833C8E135126A40AF0A61EFD
SHA256:B39F865F1B11CFFEC80DB73944CDCA7B578EB4581316302B1A8EC9312E584F29
3328DefenderRemover.exeC:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\README.mdtext
MD5:04D3BF0CE437FFE372DC6677D7550930
SHA256:3A7CE9A038E9AF620122868C492D10E691B97469E56B8A4B0BF8DD64E4A4478B
3328DefenderRemover.exeC:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\Disabler\Enable.regtext
MD5:756C953F88FF4CC6909A8F95DEEDB93C
SHA256:B3D07AAEA97D861C1D7354409896E326C42A3702491B1B6A89986BC63F44D274
3328DefenderRemover.exeC:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\DisablerS\Enable.regtext
MD5:62DE041AA55EC42385B147C8ED78497F
SHA256:6A3C6CA0DF2BB5A67B1D7348F6D6B22023E0D9839FEEC9393DB1C0B4BA767D88
3328DefenderRemover.exeC:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\Remover\REGS\Antivirus_d.regtext
MD5:24931D8EE11E4410C19CFDD37CD0E18C
SHA256:6B305D80101FAC4333095FED6B3F88403D1B097E9DDA6A8157AF5DD38615F343
3328DefenderRemover.exeC:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\Remover\FDL.txttext
MD5:2307412AED450AF11898C14C41DD352C
SHA256:6D7A32E601EE3061B7244ADE529C5508C0667DB866BAD8EFFBCA0B88D1F0747C
3328DefenderRemover.exeC:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\Remover\REGS\Disable Antivirus Protection.regtext
MD5:1ED85B1FD58EAF5B12F230E9F861EFA5
SHA256:BB5E1CD5973932797A7C3C1706255C7314FD0843558CE270E296C735C1BB256F
3328DefenderRemover.exeC:\Users\admin\AppData\Local\Temp\7zSB5D1.tmp\DisablerS\Disable.regtext
MD5:4C1B99671D4DFDAB576F815F68703407
SHA256:9CE7E4665026E6FCD3BB0178F37F251652109DFCAB25B90C968801A8494DBB45
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
11
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
HEAD
200
23.212.215.38:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133424182173750000
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1088
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2656
svchost.exe
239.255.255.250:1900
whitelisted
23.212.215.38:80
query.prod.cms.rt.microsoft.com
AKAMAI-AS
AU
unknown
224.0.0.252:5355
unknown
239.255.255.250:1900
unknown

DNS requests

Domain
IP
Reputation
query.prod.cms.rt.microsoft.com
  • 23.212.215.38
whitelisted

Threats

No threats detected
No debug info