| File name: | Verstecki 2.0.exe |
| Full analysis: | https://app.any.run/tasks/5dd7e409-4d43-4b6d-9513-53161cdd2900 |
| Verdict: | Malicious activity |
| Analysis date: | February 10, 2024, 21:14:41 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | B25A3878793963A4479E74FDF60AE03E |
| SHA1: | 68B511E35868F8C7D7868198D20DC978E4E3A3A3 |
| SHA256: | 2B1A022CEE7D88FAB206A4F355E8EFABEDEB319EDABFE3784A8750E3C8971B75 |
| SSDEEP: | 12288:EjV8Uox9oUFydRxsQPyhv7qtoc3J851Jq//mq//06yl+XEw:rAY5qtPJ85PnLJl+Uw |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:06:11 09:16:47+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 201728 |
| InitializedDataSize: | 79872 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1eef0 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 124 | sysproxy on ams3.madhacker.biz 8118 | C:\Users\admin\AppData\Local\Temp\proxy2\sysproxy.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 752 | sysproxy on dal1.madhacker.biz 8118 | C:\Users\admin\AppData\Local\Temp\proxy2\sysproxy.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1608 | sysproxy off tyo1.madhacker.biz 8118 | C:\Users\admin\AppData\Local\Temp\proxy2\sysproxy.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1644 | sysproxy on tyo1.madhacker.biz 8118 | C:\Users\admin\AppData\Local\Temp\proxy2\sysproxy.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2128 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\proxy2\tokyo-off.bat" " | C:\Windows\System32\cmd.exe | — | proxy2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2160 | "C:\Users\admin\Desktop\Verstecki 2.0.exe" | C:\Users\admin\Desktop\Verstecki 2.0.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2244 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\proxy2\tokyo-off.bat" " | C:\Windows\System32\cmd.exe | — | proxy2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2384 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\proxy2\tokyo.bat" " | C:\Windows\System32\cmd.exe | — | proxy2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2396 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\proxy2\warsaw.bat" " | C:\Windows\System32\cmd.exe | — | proxy2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2596 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\proxy2\tokyo.bat" " | C:\Windows\System32\cmd.exe | — | proxy2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (2160) Verstecki 2.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2160) Verstecki 2.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2160) Verstecki 2.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2160) Verstecki 2.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3736) proxy2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3736) proxy2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3736) proxy2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3736) proxy2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3736) proxy2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3736) proxy2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyServer |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2160 | Verstecki 2.0.exe | C:\Users\admin\AppData\Local\Temp\proxy2\sysproxy.exe | executable | |
MD5:380D58A33FAF71547FB97C3FC12A38A9 | SHA256:A918AA182DD57A545B0416E406432A6D09D1232AA0C33A0969DCD39A432D0D6B | |||
| 2160 | Verstecki 2.0.exe | C:\Users\admin\AppData\Local\Temp\proxy2\proxy2.exe | executable | |
MD5:43063D30F8A5DC9C6C8EED52AAC20F9C | SHA256:A3D7F85CC0CD373C6B8C14010468009C5B1E757D5D5D427079701BB639C5AF78 | |||
| 2160 | Verstecki 2.0.exe | C:\Users\admin\AppData\Local\Temp\proxy2\dallas-off.bat | text | |
MD5:AC347D2EFCBBB2FF0EEF8EF07E1F250F | SHA256:F84E6CA9C1BAE6443BBBA93FF2551A805B1B55D00923B523059C99424ABB22E6 | |||
| 2160 | Verstecki 2.0.exe | C:\Users\admin\AppData\Local\Temp\proxy2\dallas.bat | text | |
MD5:70037C73F14AC22D218B82B333918594 | SHA256:DB9166DE287BEF8D6CFA1D8A3E1F7892D0EF4CCC6996406F5AB28104477E0CF9 | |||
| 3736 | proxy2.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:59110F18374CD63E46C44FBDE1047424 | SHA256:DFE8C6A4DB9CA9BB0892B3AF5778DBFDD7EB4D6079ABA9518A08B01B92E7A344 | |||
| 3736 | proxy2.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 | binary | |
MD5:FDC0A0C663450249789F5CE6C6E786DA | SHA256:8D9570D7D81C8B12128DEA9311473FDAD702E0195A798EC3E545C1A9F8938061 | |||
| 3736 | proxy2.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\line[1].txt | text | |
MD5:C1FD280EE0C43F6753305C5696B6E249 | SHA256:C4B07D907543CFEEACE5C536F35051E52003FD14F097B66EDAD8FDEE4D097F26 | |||
| 2160 | Verstecki 2.0.exe | C:\Users\admin\AppData\Local\Temp\proxy2\warsaw-off.bat | text | |
MD5:D6A72512B7299CD617C46921DE2E3E57 | SHA256:839B3CC35C26B6BD03A15A1CB9DCD663CF18E40408233270F609C87DB40A1BB4 | |||
| 3736 | proxy2.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\103621DE9CD5414CC2538780B4B75751 | binary | |
MD5:FE10E0EDFB7AD7B8452FB5CAB2C84F43 | SHA256:459DD0F420E4869F9CF32BDB2296376CFBD2B6B87F25710451F4700CB3BA1B31 | |||
| 3736 | proxy2.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\103621DE9CD5414CC2538780B4B75751 | binary | |
MD5:60FE01DF86BE2E5331B0CDBE86165686 | SHA256:C08CCBC876CD5A7CDFA9670F9637DA57F6A1282198A9BC71FC7D7247A6E5B7A8 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3736 | proxy2.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/line | unknown | text | 172 b | unknown |
2896 | proxy2.exe | GET | 200 | 202.182.105.101:8118 | http://ip-api.com/line | unknown | text | 157 b | unknown |
2896 | proxy2.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/line | unknown | text | 172 b | unknown |
2896 | proxy2.exe | GET | 200 | 64.176.66.218:8118 | http://ip-api.com/line | unknown | text | 173 b | unknown |
2896 | proxy2.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/line | unknown | text | 172 b | unknown |
2896 | proxy2.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/line | unknown | text | 172 b | unknown |
2896 | proxy2.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/line | unknown | text | 172 b | unknown |
2896 | proxy2.exe | GET | 200 | 45.32.193.109:8118 | http://ip-api.com/line | unknown | text | 155 b | unknown |
3736 | proxy2.exe | GET | 304 | 95.101.63.96:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?85790e01c324149a | unknown | — | — | unknown |
3736 | proxy2.exe | GET | 200 | 95.101.63.96:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?8771f4e6f85bff9e | unknown | compressed | 65.2 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3736 | proxy2.exe | 208.95.112.1:80 | ip-api.com | TUT-AS | US | unknown |
3736 | proxy2.exe | 64.176.66.218:443 | ams3.madhacker.biz | — | US | unknown |
3736 | proxy2.exe | 95.101.63.96:80 | ctldl.windowsupdate.com | Akamai International B.V. | GB | unknown |
3736 | proxy2.exe | 104.81.141.81:80 | x1.c.lencr.org | AKAMAI-AS | NL | unknown |
3736 | proxy2.exe | 23.72.252.147:80 | r3.o.lencr.org | Akamai International B.V. | NL | unknown |
2896 | proxy2.exe | 208.95.112.1:80 | ip-api.com | TUT-AS | US | unknown |
2896 | proxy2.exe | 64.176.66.218:443 | ams3.madhacker.biz | — | US | unknown |
Domain | IP | Reputation |
|---|---|---|
ip-api.com |
| shared |
ams3.madhacker.biz |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
r3.o.lencr.org |
| shared |
tyo1.madhacker.biz |
| unknown |
dal1.madhacker.biz |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .biz TLD |
1080 | svchost.exe | Potentially Bad Traffic | ET INFO DYNAMIC_DNS Query to a *.madhacker .biz Domain |
3736 | proxy2.exe | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
3736 | proxy2.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |
2896 | proxy2.exe | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
2896 | proxy2.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |
1080 | svchost.exe | Potentially Bad Traffic | ET INFO DYNAMIC_DNS Query to a *.madhacker .biz Domain |
1080 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .biz TLD |
2896 | proxy2.exe | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
2896 | proxy2.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |