File name:

Content Manager.exe

Full analysis: https://app.any.run/tasks/b8f2c122-75c0-43da-ac02-22226accfe5f
Verdict: Malicious activity
Analysis date: July 18, 2024, 12:14:53
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

60ED4BFBD48A0D1C161D123749BA6586

SHA1:

F21F2D4B038602EBF923FADCB4CBE07CD3B4979A

SHA256:

2367612DB7C754BF4F07A0F71188C0CC7ED0E39BEF12B7DC3F4AF3D0B3EC5BD4

SSDEEP:

98304:whhE1x5HHrsEs4deFIls0LoaRLlFmzH0Fcwa6PoI+49U2ay8iACS+9yBrS7caHfX:sSKGijKU02asxc

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Content Manager.exe (PID: 4936)
    • Actions looks like stealing of personal data

      • Content Manager.exe (PID: 4936)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Content Manager.exe (PID: 4936)
    • Drops 7-zip archiver for unpacking

      • Content Manager.exe (PID: 4936)
    • Process drops legitimate windows executable

      • Content Manager.exe (PID: 4936)
    • Executable content was dropped or overwritten

      • Content Manager.exe (PID: 4936)
    • Creates file in the systems drive root

      • Content Manager.exe (PID: 4936)
    • Changes Internet Explorer settings (feature browser emulation)

      • Content Manager.exe (PID: 4936)
  • INFO

    • Checks supported languages

      • Content Manager.exe (PID: 4936)
    • Create files in a temporary directory

      • Content Manager.exe (PID: 4936)
    • Reads the machine GUID from the registry

      • Content Manager.exe (PID: 4936)
    • Creates files or folders in the user directory

      • Content Manager.exe (PID: 4936)
    • Reads Environment values

      • Content Manager.exe (PID: 4936)
    • Reads the computer name

      • Content Manager.exe (PID: 4936)
    • Reads the software policy settings

      • Content Manager.exe (PID: 4936)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:10:17 23:21:18+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 48
CodeSize: 11182080
InitializedDataSize: 114176
UninitializedDataSize: -
EntryPoint: 0xaabe6e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.8.2594.39678
ProductVersionNumber: 0.8.2594.39678
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Custom launcher and content manager for Assetto Corsa
CompanyName: AcClub
FileDescription: Content Manager
FileVersion: 0.8.2594.39678
InternalName: Content Manager.exe
LegalCopyright: Copyright © AcClub, 2015-2023
LegalTrademarks: -
OriginalFileName: Content Manager.exe
ProductName: Content Manager
ProductVersion: 0.8.2594.39678
AssemblyVersion: 0.8.2594.39678
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
117
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start content manager.exe

Process information

PID
CMD
Path
Indicators
Parent process
4936"C:\Users\admin\Downloads\Content Manager.exe" C:\Users\admin\Downloads\Content Manager.exe
explorer.exe
User:
admin
Company:
AcClub
Integrity Level:
MEDIUM
Description:
Content Manager
Version:
0.8.2594.39678
Modules
Images
c:\users\admin\downloads\content manager.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
Total events
7 096
Read events
7 074
Write events
22
Delete events
0

Modification events

(PID) Process:(4936) Content Manager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4936) Content Manager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(4936) Content Manager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(4936) Content Manager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(4936) Content Manager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
Operation:writeName:Content Manager.exe
Value:
11999
(PID) Process:(4936) Content Manager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_96DPI_PIXEL
Operation:writeName:Content Manager.exe
Value:
1
(PID) Process:(4936) Content Manager.exeKey:HKEY_CLASSES_ROOT\acmanager
Operation:writeName:URL Protocol
Value:
(PID) Process:(4936) Content Manager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kn5\OpenWithProgids
Operation:writeName:acmanager.kn5
Value:
(PID) Process:(4936) Content Manager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.kn5\UserChoice
Operation:writeName:Progid
Value:
acmanager.kn5
(PID) Process:(4936) Content Manager.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.acreplay\OpenWithProgids
Operation:writeName:acmanager.acreplay
Value:
Executable files
32
Suspicious files
123
Text files
957
Unknown types
8

Dropped files

PID
Process
Filename
Type
4936Content Manager.exeC:\Users\admin\AppData\Local\Temp\Costura\80020E73785608EBC4CC66D86D9D69C2\32\interop.d3dimageex.dllexecutable
MD5:D924C109DA0F7A9E1DEBC63CB6D9B30B
SHA256:D9EAB44547374B7A7AC21FE4A36BF79049B3373865FA319C371578368E716AB5
4936Content Manager.exeC:\Users\admin\AppData\Local\AcTools Content Manager\Temporary\Patch\Manifest.jsontext
MD5:631267FD6BC10B8B3F4A8BD802A526CE
SHA256:2A87BC3012D56984C297D9B334BE7B40D6C772CEB7522702ECF4469702A51F32
4936Content Manager.exeC:\Users\admin\AppData\Local\AcTools Content Manager\Values.data.newbinary
MD5:9236ED59446BDE5E052650CDA0A483DE
SHA256:6B0965EE59B6FEC551B0CF47D4BCE27E20F6E60729614742EAC173D39365A1C3
4936Content Manager.exeC:\Users\admin\AppData\Local\AcTools Content Manager\Temporary\CUP\71cde14f3bfec1d96045b0d8e6a604372c351f15binary
MD5:05EA4D929EA5EC359082C0DBE07F8B8D
SHA256:628B34040A7D7E54BB45985C85D77643973C9B373F6C1572E721D7CD88E553FB
4936Content Manager.exeC:\Users\admin\AppData\Local\AcTools Content Manager\Websites.databinary
MD5:BBC48D16849630A83B3B7B0215FBBE80
SHA256:495EF03E18BB5BBD17CDD26E86A05B7127D6D4A7CACA4058589688B11422252F
4936Content Manager.exeC:\Users\admin\AppData\Local\AcTools Content Manager\Data\Brand Badges\AGS.pngimage
MD5:D9A99D68B071EBCC919249E38BC9218E
SHA256:4FDD325048D8B1D25DA6037379EA2665613063A1B03F7823580B856EF8709E4D
4936Content Manager.exeC:\Users\admin\AppData\Local\Temp\Costura\80020E73785608EBC4CC66D86D9D69C2\32\nvidia.texturetools.compress.dllexecutable
MD5:74654ED00F7E89F80DD1BBBF4D02C402
SHA256:D8ED3A09E150D8608940497267AB6BCBD3CDC9D59FE4B50B849E1FF8344141BA
4936Content Manager.exeC:\Users\admin\AppData\Local\AcTools Content Manager\Values.databinary
MD5:9236ED59446BDE5E052650CDA0A483DE
SHA256:6B0965EE59B6FEC551B0CF47D4BCE27E20F6E60729614742EAC173D39365A1C3
4936Content Manager.exeC:\Users\admin\Downloads\Content Manager.update.exeexecutable
MD5:D48C675087F429215B952677689DE8A3
SHA256:BEA0987C14327047456959EE1382648DB20AE33E47CE32676862BEC4D4C9F8F6
4936Content Manager.exeC:\Users\admin\AppData\Local\AcTools Content Manager\Logs\Main Log_240718_121503.logtext
MD5:5823B388AB1A5CBAD6D5C8486694B7E1
SHA256:A6347463943E523759EDD5B20DF6B1B57A7FA4C803397CF38D58277851D3EA90
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
16
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4936
Content Manager.exe
GET
301
172.67.71.70:80
http://acstuff.ru/f/api/posts/content-extra?filter[discussion]=24&filter[type]=comment&sort=-time&page[size]=99999
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
7856
svchost.exe
4.209.32.67:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4
System
192.168.100.255:137
whitelisted
20.74.47.205:443
MICROSOFT-CORP-MSN-AS-BLOCK
FR
unknown
4716
svchost.exe
40.126.32.68:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
4
System
192.168.100.255:138
whitelisted
4032
svchost.exe
239.255.255.250:1900
whitelisted
1796
backgroundTaskHost.exe
20.223.35.26:443
fd.api.iris.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
2760
svchost.exe
40.115.3.253:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4936
Content Manager.exe
172.67.71.70:443
acstuff.ru
CLOUDFLARENET
US
unknown
4936
Content Manager.exe
172.67.71.70:80
acstuff.ru
CLOUDFLARENET
US
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.186.46
whitelisted
fd.api.iris.microsoft.com
  • 20.223.35.26
whitelisted
acstuff.ru
  • 172.67.71.70
  • 104.26.9.2
  • 104.26.8.2
unknown
www.bing.com
  • 92.123.104.62
  • 92.123.104.59
  • 92.123.104.61
  • 92.123.104.53
  • 92.123.104.65
  • 92.123.104.60
  • 92.123.104.64
  • 92.123.104.52
  • 92.123.104.58
whitelisted

Threats

No threats detected
No debug info