File name:

dControl.exe

Full analysis: https://app.any.run/tasks/fc0c2c85-68f8-46ec-aada-a5903cd7e18f
Verdict: Malicious activity
Analysis date: March 23, 2024, 00:29:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

58008524A6473BDF86C1040A9A9E39C3

SHA1:

CB704D2E8DF80FD3500A5B817966DC262D80DDB8

SHA256:

1EF6C1A4DFDC39B63BFE650CA81AB89510DE6C0D3D7C608AC5BE80033E559326

SSDEEP:

6144:Vzv+kSn74iCmfianQGDM3OXTWRDy9GYQDUmJFXIXHrsUBnBTF8JJCYrYNsQJzfgu:Vzcn7EanlQiWtYhmJFSwUBLcQZfgiD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • dControl.exe (PID: 2892)
    • Creates or modifies Windows services

      • dControl.exe (PID: 696)
    • Disables Windows Defender

      • dControl.exe (PID: 696)
  • SUSPICIOUS

    • Application launched itself

      • dControl.exe (PID: 2892)
      • dControl.exe (PID: 2672)
      • dControl.exe (PID: 696)
    • Explorer used for Indirect Command Execution

      • explorer.exe (PID: 3224)
  • INFO

    • Reads mouse settings

      • dControl.exe (PID: 2892)
      • dControl.exe (PID: 2672)
      • dControl.exe (PID: 696)
      • dControl.exe (PID: 2040)
      • dControl.exe (PID: 3528)
    • Reads the computer name

      • dControl.exe (PID: 2892)
      • dControl.exe (PID: 2672)
      • dControl.exe (PID: 696)
      • dControl.exe (PID: 3528)
      • dControl.exe (PID: 2040)
    • Checks supported languages

      • dControl.exe (PID: 2892)
      • dControl.exe (PID: 2672)
      • dControl.exe (PID: 696)
      • dControl.exe (PID: 2040)
      • MSASCui.exe (PID: 3444)
      • dControl.exe (PID: 3528)
    • Create files in a temporary directory

      • dControl.exe (PID: 2892)
      • dControl.exe (PID: 696)
    • Reads security settings of Internet Explorer

      • explorer.exe (PID: 3616)
    • Reads the Internet Settings

      • explorer.exe (PID: 316)
      • explorer.exe (PID: 764)
      • explorer.exe (PID: 3616)
    • Application launched itself

      • msedge.exe (PID: 2052)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (28.6)
.exe | UPX compressed Win32 Executable (28)
.exe | Win32 EXE Yoda's Crypter (27.5)
.dll | Win32 Dynamic Link Library (generic) (6.8)
.exe | Win32 Executable (generic) (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2011:12:23 10:59:31+00:00
ImageFileCharacteristics: No relocs, Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 270336
InitializedDataSize: 61440
UninitializedDataSize: 503808
EntryPoint: 0xbd650
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 2.1.0.0
ProductVersionNumber: 2.1.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (British)
CharacterSet: Unicode
FileVersion: 2.1.0.0
Comments: dControl v2.1
FileDescription: dControl v2.1
LegalCopyright: Copyright © 2015-2022 www.sordum.org All Rights Reserved.
CompanyName: www.sordum.org
ProductVersion: 2.1.0.0
OriginalFileName: dControl.exe
Coder: By BlueLife
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
64
Monitored processes
22
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start dcontrol.exe dcontrol.exe dcontrol.exe no specs dcontrol.exe no specs explorer.exe no specs explorer.exe no specs msascui.exe no specs explorer.exe no specs dcontrol.exe no specs explorer.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs dcontrol.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
316"C:\Windows\Explorer.exe" https://www.sordum.org/C:\Windows\explorer.exedControl.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
696"C:\Users\admin\AppData\Local\Temp\dControl.exe" /TI C:\Users\admin\AppData\Local\Temp\dControl.exedControl.exe
User:
SYSTEM
Company:
www.sordum.org
Integrity Level:
SYSTEM
Description:
dControl v2.1
Version:
2.1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\dcontrol.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
764C:\Windows\explorer.exe /factory,{75dff2b7-6936-4c06-a8bb-676a7b00b24b} -EmbeddingC:\Windows\explorer.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
952"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x6bcdf598,0x6bcdf5a8,0x6bcdf5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1392"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2232 --field-trial-handle=1376,i,14091723454230080401,7558278538881757821,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2040"C:\Users\admin\AppData\Local\Temp\dControl.exe" /EXP |1164|C:\Users\admin\AppData\Local\Temp\dControl.exedControl.exe
User:
SYSTEM
Company:
www.sordum.org
Integrity Level:
SYSTEM
Description:
dControl v2.1
Exit code:
0
Version:
2.1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\dcontrol.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
2052"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.sordum.org/C:\Program Files\Microsoft\Edge\Application\msedge.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2672C:\Users\admin\AppData\Local\Temp\dControl.exeC:\Users\admin\AppData\Local\Temp\dControl.exe
dControl.exe
User:
SYSTEM
Company:
www.sordum.org
Integrity Level:
SYSTEM
Description:
dControl v2.1
Exit code:
0
Version:
2.1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\dcontrol.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
2828"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2212 --field-trial-handle=1376,i,14091723454230080401,7558278538881757821,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2892"C:\Users\admin\AppData\Local\Temp\dControl.exe" C:\Users\admin\AppData\Local\Temp\dControl.exe
explorer.exe
User:
admin
Company:
www.sordum.org
Integrity Level:
HIGH
Description:
dControl v2.1
Exit code:
0
Version:
2.1.0.0
Modules
Images
c:\users\admin\appdata\local\temp\dcontrol.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
Total events
4 377
Read events
4 262
Write events
98
Delete events
17

Modification events

(PID) Process:(696) dControl.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings\Windows.SystemToast.SecurityAndMaintenance
Operation:writeName:Enabled
Value:
0
(PID) Process:(696) dControl.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender
Operation:writeName:DisableAntiSpyware
Value:
1
(PID) Process:(696) dControl.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender
Operation:writeName:DisableAntiVirus
Value:
1
(PID) Process:(696) dControl.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender
Operation:writeName:DisableAntiSpyware
Value:
1
(PID) Process:(696) dControl.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender
Operation:writeName:DisableAntiVirus
Value:
1
(PID) Process:(696) dControl.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender\Real-Time Protection
Operation:writeName:DisableRealtimeMonitoring
Value:
1
(PID) Process:(696) dControl.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\WinDefend
Operation:writeName:Start
Value:
4
(PID) Process:(696) dControl.exeKey:HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\Windows\CurrentVersion\Notifications\Settings\Windows.SystemToast.SecurityAndMaintenance
Operation:delete valueName:Enabled
Value:
(PID) Process:(696) dControl.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Policies\Microsoft\Windows Defender
Operation:delete keyName:(default)
Value:
(PID) Process:(696) dControl.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Defender
Operation:delete valueName:DisableAntiSpyware
Value:

Executable files
3
Suspicious files
43
Text files
61
Unknown types
31

Dropped files

PID
Process
Filename
Type
2892dControl.exeC:\Users\admin\AppData\Local\Temp\aut1F5C.tmpbinary
MD5:ECFFD3E81C5F2E3C62BCDC122442B5F2
SHA256:9874AB363B07DCC7E9CD6022A380A64102C1814343642295239A9F120CB941C5
2892dControl.exeC:\Users\admin\AppData\Local\Temp\2e8w9w2u.tmptext
MD5:E00DCC76E4DCD90994587375125DE04B
SHA256:C8709F5A8B971D136E2273D66E65449791CA8EBA1F47DD767733EA52EE635447
2672dControl.exeC:\Windows\TEMP\2e6w7w2u.tmptext
MD5:E00DCC76E4DCD90994587375125DE04B
SHA256:C8709F5A8B971D136E2273D66E65449791CA8EBA1F47DD767733EA52EE635447
2892dControl.exeC:\Users\admin\AppData\Local\Temp\aut1F4B.tmpbinary
MD5:9D5A0EF18CC4BB492930582064C5330F
SHA256:8F5BBCC572BC62FEB13A669F856D21886A61888FD6288AFD066272A27EA79BB3
696dControl.exeC:\Users\admin\AppData\Local\Temp\dControl.initext
MD5:7AC7CE63AA943D7A57D036244F74F6C9
SHA256:B8346C38785C48588BD71F5AC0E46F035E99C01B247251FE8E43E59997E74E71
2892dControl.exeC:\Users\admin\AppData\Local\Temp\aut1F4C.tmpbinary
MD5:EFE44D9F6E4426A05E39F99AD407D3E7
SHA256:5EA3B26C6B1B71EDAEF17CE365D50BE963AE9F4CB79B39EC723FE6E9E4054366
696dControl.exeC:\Windows\TEMP\aut2121.tmpbinary
MD5:ECFFD3E81C5F2E3C62BCDC122442B5F2
SHA256:9874AB363B07DCC7E9CD6022A380A64102C1814343642295239A9F120CB941C5
2040dControl.exeC:\Windows\TEMP\autCAAF.tmpbinary
MD5:EFE44D9F6E4426A05E39F99AD407D3E7
SHA256:5EA3B26C6B1B71EDAEF17CE365D50BE963AE9F4CB79B39EC723FE6E9E4054366
696dControl.exeC:\Windows\System32\GroupPolicy\gpt.initext
MD5:18BD917DCFE60A77F3BDA05E1A35B407
SHA256:657581D7C48DDB8643C3396C49A00C7177ACD7B4922CEC22D6F45F30A606DB7A
696dControl.exeC:\Windows\System32\GroupPolicy\Machine\Registry.polbinary
MD5:D15A332CBA4FC6D5062F42728CF751B4
SHA256:9C064D5E80AB78FF046430CB6A6CA1B32266AF43500313CC13AD092534EE4A6F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
34
DNS requests
26
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2052
msedge.exe
239.255.255.250:1900
unknown
4064
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4064
msedge.exe
52.123.243.75:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
DE
unknown
4064
msedge.exe
185.146.22.240:443
www.sordum.org
A2HOSTING
US
unknown
4064
msedge.exe
142.250.185.136:443
www.googletagmanager.com
GOOGLE
US
unknown
4064
msedge.exe
142.250.186.98:443
pagead2.googlesyndication.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
www.sordum.org
  • 185.146.22.240
unknown
config.edge.skype.com
  • 52.123.243.75
  • 52.123.243.198
  • 52.123.243.85
  • 52.123.243.80
whitelisted
edge.microsoft.com
  • 204.79.197.239
  • 13.107.21.239
whitelisted
www.googletagmanager.com
  • 142.250.185.136
whitelisted
pagead2.googlesyndication.com
  • 142.250.186.98
whitelisted
googleads.g.doubleclick.net
  • 142.250.186.98
whitelisted
www.google-analytics.com
  • 216.239.36.178
  • 216.239.38.178
  • 216.239.32.178
  • 216.239.34.178
whitelisted
fundingchoicesmessages.google.com
  • 142.250.184.206
whitelisted
www.bing.com
  • 2.19.96.107
  • 2.19.96.128
whitelisted
region1.google-analytics.com
  • 216.239.34.36
  • 216.239.32.36
whitelisted

Threats

No threats detected
No debug info