| File name: | Verstecki 2.0.exe |
| Full analysis: | https://app.any.run/tasks/5dd7e409-4d43-4b6d-9513-53161cdd2900 |
| Verdict: | Malicious activity |
| Analysis date: | February 10, 2024, 21:14:41 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | B25A3878793963A4479E74FDF60AE03E |
| SHA1: | 68B511E35868F8C7D7868198D20DC978E4E3A3A3 |
| SHA256: | 2B1A022CEE7D88FAB206A4F355E8EFABEDEB319EDABFE3784A8750E3C8971B75 |
| SSDEEP: | 12288:EjV8Uox9oUFydRxsQPyhv7qtoc3J851Jq//mq//06yl+XEw:rAY5qtPJ85PnLJl+Uw |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:06:11 09:16:47+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 201728 |
| InitializedDataSize: | 79872 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1eef0 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 124 | sysproxy on ams3.madhacker.biz 8118 | C:\Users\admin\AppData\Local\Temp\proxy2\sysproxy.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 752 | sysproxy on dal1.madhacker.biz 8118 | C:\Users\admin\AppData\Local\Temp\proxy2\sysproxy.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1608 | sysproxy off tyo1.madhacker.biz 8118 | C:\Users\admin\AppData\Local\Temp\proxy2\sysproxy.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1644 | sysproxy on tyo1.madhacker.biz 8118 | C:\Users\admin\AppData\Local\Temp\proxy2\sysproxy.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2128 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\proxy2\tokyo-off.bat" " | C:\Windows\System32\cmd.exe | — | proxy2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2160 | "C:\Users\admin\Desktop\Verstecki 2.0.exe" | C:\Users\admin\Desktop\Verstecki 2.0.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2244 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\proxy2\tokyo-off.bat" " | C:\Windows\System32\cmd.exe | — | proxy2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2384 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\proxy2\tokyo.bat" " | C:\Windows\System32\cmd.exe | — | proxy2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2396 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\proxy2\warsaw.bat" " | C:\Windows\System32\cmd.exe | — | proxy2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2596 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\proxy2\tokyo.bat" " | C:\Windows\System32\cmd.exe | — | proxy2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (2160) Verstecki 2.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2160) Verstecki 2.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2160) Verstecki 2.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2160) Verstecki 2.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3736) proxy2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3736) proxy2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3736) proxy2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3736) proxy2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3736) proxy2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3736) proxy2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyServer |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2160 | Verstecki 2.0.exe | C:\Users\admin\AppData\Local\Temp\proxy2\dallas.bat | text | |
MD5:70037C73F14AC22D218B82B333918594 | SHA256:DB9166DE287BEF8D6CFA1D8A3E1F7892D0EF4CCC6996406F5AB28104477E0CF9 | |||
| 2160 | Verstecki 2.0.exe | C:\Users\admin\AppData\Local\Temp\proxy2\tokyo.bat | text | |
MD5:4A02329C4CCF6D8DB159F51CF2423A6C | SHA256:F0B512BE81F1A379AA121974A977603002017E238E68A8F8415D57C5DC89BEDB | |||
| 2160 | Verstecki 2.0.exe | C:\Users\admin\AppData\Local\Temp\proxy2\dallas-off.bat | text | |
MD5:AC347D2EFCBBB2FF0EEF8EF07E1F250F | SHA256:F84E6CA9C1BAE6443BBBA93FF2551A805B1B55D00923B523059C99424ABB22E6 | |||
| 2160 | Verstecki 2.0.exe | C:\Users\admin\AppData\Local\Temp\proxy2\proxy2.exe | executable | |
MD5:43063D30F8A5DC9C6C8EED52AAC20F9C | SHA256:A3D7F85CC0CD373C6B8C14010468009C5B1E757D5D5D427079701BB639C5AF78 | |||
| 2160 | Verstecki 2.0.exe | C:\Users\admin\AppData\Local\Temp\proxy2\sysproxy.exe | executable | |
MD5:380D58A33FAF71547FB97C3FC12A38A9 | SHA256:A918AA182DD57A545B0416E406432A6D09D1232AA0C33A0969DCD39A432D0D6B | |||
| 2160 | Verstecki 2.0.exe | C:\Users\admin\AppData\Local\Temp\proxy2\tokyo-off.bat | text | |
MD5:F89A8509BA39FCB1A0EDE5289810E3C3 | SHA256:5DBF5582D046F8B2B2DE4E6A17D64ABADCA238FBEE1C13947ECBEA3F1E0025D7 | |||
| 3736 | proxy2.exe | C:\Users\admin\AppData\Local\Temp\TarCAE.tmp | binary | |
MD5:9C0C641C06238516F27941AA1166D427 | SHA256:4276AF3669A141A59388BC56A87F6614D9A9BDDDF560636C264219A7EB11256F | |||
| 3736 | proxy2.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 | compressed | |
MD5:AC05D27423A85ADC1622C714F2CB6184 | SHA256:C6456E12E5E53287A547AF4103E0397CB9697E466CF75844312DC296D43D144D | |||
| 2160 | Verstecki 2.0.exe | C:\Users\admin\AppData\Local\Temp\proxy2\warsaw-off.bat | text | |
MD5:D6A72512B7299CD617C46921DE2E3E57 | SHA256:839B3CC35C26B6BD03A15A1CB9DCD663CF18E40408233270F609C87DB40A1BB4 | |||
| 2160 | Verstecki 2.0.exe | C:\Users\admin\AppData\Local\Temp\proxy2\warsaw.bat | text | |
MD5:829C4553AC0215C7CC76BB5FA9C01B26 | SHA256:7E225A2D5C51769C400CCD13B75F01C675317CE560F662699121D60160E5A110 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3736 | proxy2.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/line | unknown | text | 172 b | unknown |
3736 | proxy2.exe | GET | 304 | 95.101.63.96:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?85790e01c324149a | unknown | — | — | unknown |
3736 | proxy2.exe | GET | 200 | 95.101.63.96:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?8771f4e6f85bff9e | unknown | compressed | 65.2 Kb | unknown |
3736 | proxy2.exe | GET | 200 | 104.81.141.81:80 | http://x1.c.lencr.org/ | unknown | binary | 717 b | unknown |
2896 | proxy2.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/line | unknown | text | 172 b | unknown |
1080 | svchost.exe | GET | 304 | 95.101.63.72:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?3e412f7b4eff0943 | unknown | — | — | unknown |
3736 | proxy2.exe | GET | 200 | 23.72.252.147:80 | http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgTA2ZbveOPYUdm86t%2FX4bavGw%3D%3D | unknown | binary | 503 b | unknown |
2896 | proxy2.exe | GET | — | 202.182.105.101:8118 | http://ip-api.com/line | unknown | — | — | unknown |
2896 | proxy2.exe | GET | — | 208.95.112.1:80 | http://ip-api.com/line | unknown | — | — | unknown |
2896 | proxy2.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/line | unknown | text | 172 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3736 | proxy2.exe | 208.95.112.1:80 | ip-api.com | TUT-AS | US | unknown |
3736 | proxy2.exe | 64.176.66.218:443 | ams3.madhacker.biz | — | US | unknown |
3736 | proxy2.exe | 95.101.63.96:80 | ctldl.windowsupdate.com | Akamai International B.V. | GB | unknown |
3736 | proxy2.exe | 104.81.141.81:80 | x1.c.lencr.org | AKAMAI-AS | NL | unknown |
3736 | proxy2.exe | 23.72.252.147:80 | r3.o.lencr.org | Akamai International B.V. | NL | unknown |
2896 | proxy2.exe | 208.95.112.1:80 | ip-api.com | TUT-AS | US | unknown |
2896 | proxy2.exe | 64.176.66.218:443 | ams3.madhacker.biz | — | US | unknown |
Domain | IP | Reputation |
|---|---|---|
ip-api.com |
| shared |
ams3.madhacker.biz |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
r3.o.lencr.org |
| shared |
tyo1.madhacker.biz |
| unknown |
dal1.madhacker.biz |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .biz TLD |
1080 | svchost.exe | Potentially Bad Traffic | ET INFO DYNAMIC_DNS Query to a *.madhacker .biz Domain |
3736 | proxy2.exe | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
3736 | proxy2.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |
2896 | proxy2.exe | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
2896 | proxy2.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |
1080 | svchost.exe | Potentially Bad Traffic | ET INFO DYNAMIC_DNS Query to a *.madhacker .biz Domain |
1080 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .biz TLD |
2896 | proxy2.exe | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
2896 | proxy2.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |