File name:

02382059_2

Full analysis: https://app.any.run/tasks/099a40c1-a874-49a3-a3b0-24d37cc2105b
Verdict: Malicious activity
Analysis date: January 22, 2021, 01:39:01
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

4D816DA1A45EC20618A3330A700FD90D

SHA1:

C5E0156C66B1938E66AE5B2246D6DA8FC68FB81A

SHA256:

1E086C109CDE1EB15785806E9F7EA0F70607047C4E12BAD585E500D5ACBB8CF6

SSDEEP:

196608:zJRN/CytB9UML2Gsq8asB0eY1d9f0gWHYb1UmfQsuGGycQDq8eq:zJRRP9UQAat/f98gWHSTQPLQDXb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops a file that was compiled in debug mode

      • 02382059_2.exe (PID: 2688)
    • Starts CMD.EXE for commands execution

      • 02382059_2.exe (PID: 2688)
    • Executable content was dropped or overwritten

      • 02382059_2.exe (PID: 2688)
    • Drops a file with a compile date too recent

      • 02382059_2.exe (PID: 2688)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:06:28 01:52:26+02:00
PEType: PE32
LinkerVersion: 14.16
CodeSize: 249856
InitializedDataSize: 166912
UninitializedDataSize: -
EntryPoint: 0x15015
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.5.81.0
ProductVersionNumber: 6.85.81.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Fujitsu Technology Solutions
LegalCopyright: (c) 2019 Fujitsu Technology Solutions
ProductName: DVNC
ProductVersion: 6.85.0081.0
FeatureName: BIOS Management (Update & Archive)
FileDescription: DeskFlash self-extractor
FileVersion: 1.05
InternalName: DeskFlashSfxWin.exe
OriginalFileName: DeskFlashSfxWin.exe

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 27-Jun-2019 23:52:26
Detected languages:
  • English - United States
  • German - Germany
Debug artifacts:
  • C:\sourcecontrol\deskviewclient\binaries\win32\Release\DeskFlashSfxWin.pdb
CompanyName: Fujitsu Technology Solutions
LegalCopyright: (c) 2019 Fujitsu Technology Solutions
ProductName: DVNC
ProductVersion: 6.85.0081.0
FeatureName: BIOS Management (Update & Archive)
FileDescription: DeskFlash self-extractor
FileVersion: 1.05
InternalName: DeskFlashSfxWin.exe
OriginalFilename: DeskFlashSfxWin.exe

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000130

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 27-Jun-2019 23:52:26
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x0003CE19
0x0003D000
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.54577
.rdata
0x0003E000
0x0001A74C
0x0001A800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.81148
.data
0x00059000
0x00004394
0x00001600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.23969
.rsrc
0x0005E000
0x00006E30
0x00007000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.36918
.reloc
0x00065000
0x00003000
0x00003000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
6.71975

Resources

Title
Entropy
Size
Codepage
Language
Type
1
4.91161
381
UNKNOWN
English - United States
RT_MANIFEST
2
2.89005
744
UNKNOWN
English - United States
RT_ICON
3
2.54353
296
UNKNOWN
English - United States
RT_ICON
4
4.35478
3752
UNKNOWN
English - United States
RT_ICON
5
5.17501
2216
UNKNOWN
English - United States
RT_ICON
6
3.47748
1384
UNKNOWN
English - United States
RT_ICON
7
2.44565
92
UNKNOWN
English - United States
RT_STRING
8
3.44197
4264
UNKNOWN
English - United States
RT_ICON
9
4.05874
1128
UNKNOWN
English - United States
RT_ICON
102
3.13082
234
UNKNOWN
English - United States
RT_DIALOG

Imports

ADVAPI32.dll
KERNEL32.dll
USER32.dll

Exports

Title
Ordinal
Address
gg_ptrc
1
0x0005C08C
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
2
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start 02382059_2.exe cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2688"C:\Users\admin\AppData\Local\Temp\02382059_2.exe" C:\Users\admin\AppData\Local\Temp\02382059_2.exe
explorer.exe
User:
admin
Company:
Fujitsu Technology Solutions
Integrity Level:
MEDIUM
Description:
DeskFlash self-extractor
Exit code:
12
Version:
1.05
Modules
Images
c:\users\admin\appdata\local\temp\02382059_2.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
4092C:\Windows\system32\cmd.exe /C "C:\Users\admin\AppData\Local\Temp\DfSfx2\DskFLsh2.bat"C:\Windows\system32\cmd.exe02382059_2.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
3221225786
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
6
Read events
6
Write events
0
Delete events
0

Modification events

No data
Executable files
3
Suspicious files
1
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
268802382059_2.exeC:\Users\admin\AppData\Local\Temp\DfSfx2\DskFlash.datexecutable
MD5:E98E0FBD2F69F70BD33B64834EA546CE
SHA256:529F09B2A55BBDC39254DF3E4E5662FE26ED07109793948EBC1287ABD0E06B71
268802382059_2.exeC:\Users\admin\AppData\Local\Temp\DfSfx2\DeskView.initext
MD5:2D5C96D13F3837EADB8B50D8DA529CAF
SHA256:E79074E81DB25823D10A1BB8CFA3D46B280D3787A8F1085C94D9631D92C8AD88
268802382059_2.exeC:\Users\admin\AppData\Local\Temp\DfSfx2\DskFlash.exeexecutable
MD5:7CA903F0B38C26F6ADD51358D8652A16
SHA256:99119A45CA179B9E688107D4AF1818571936C363FD3A9225817CFC05E28C5917
268802382059_2.exeC:\Users\admin\AppData\Local\Temp\DfSfx2\D3603-A1x.R1.24.0.bupcompressed
MD5:6338BDACF19C768565AEC219D52305F6
SHA256:3E9E4FFBFB08B0C4D464226770B37808335711E6F62DEAAEA2B3840EFAF78E5B
268802382059_2.exeC:\Users\admin\AppData\Local\Temp\DfSfx2\DATA\DF_COFF.exeexecutable
MD5:F9FA9ECA88FE1393B9CB0AE23F3E4623
SHA256:8A71AE5315D437252C1B4E63DCED8CEDBE598481CCF12DA1814C83F773FB681D
268802382059_2.exeC:\Users\admin\AppData\Local\Temp\DfSfx2\DskFlsh2.battext
MD5:2E8D1D918A34019EEF06A4E68284427C
SHA256:81ACC4FFECBB84467887867C0D32BEF80B5E7246063A98C5633016CE3CE7C6D7
268802382059_2.exeC:\Users\admin\AppData\Local\Temp\DfSfx2\ThirdPartyLicenseReadme.txttext
MD5:0C69D070EEC23D01FD46B87F74DC1A64
SHA256:BE1A2A090171F770D3F50D98E62B7B7188FF49F6BEC642A7EF981D7690AE8A8B
268802382059_2.exeC:\Users\admin\AppData\Local\Temp\DfSfx2\License.txttext
MD5:C116C94BF0D3A167B5FF45C7DCB68AE0
SHA256:4384AF22B3757E160A9B9F05A7775D463106AE2B9E37D5E7D1B59A0DD0BAAA34
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info