| File name: | Release.exe |
| Full analysis: | https://app.any.run/tasks/bad9e613-e44e-42c5-b73f-3eb6195a1f9a |
| Verdict: | Malicious activity |
| Analysis date: | February 10, 2024, 09:25:03 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | B25A3878793963A4479E74FDF60AE03E |
| SHA1: | 68B511E35868F8C7D7868198D20DC978E4E3A3A3 |
| SHA256: | 2B1A022CEE7D88FAB206A4F355E8EFABEDEB319EDABFE3784A8750E3C8971B75 |
| SSDEEP: | 12288:EjV8Uox9oUFydRxsQPyhv7qtoc3J851Jq//mq//06yl+XEw:rAY5qtPJ85PnLJl+Uw |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:06:11 09:16:47+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 201728 |
| InitializedDataSize: | 79872 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1eef0 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 844 | sysproxy off tyo1.madhacker.biz 8118 | C:\Users\admin\AppData\Local\Temp\proxy2\sysproxy.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 980 | sysproxy off dal1.madhacker.biz 8118 | C:\Users\admin\AppData\Local\Temp\proxy2\sysproxy.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2096 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\proxy2\tokyo.bat" " | C:\Windows\System32\cmd.exe | — | proxy2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2256 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\proxy2\warsaw-off.bat" " | C:\Windows\System32\cmd.exe | — | proxy2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2644 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\proxy2\dallas.bat" " | C:\Windows\System32\cmd.exe | — | proxy2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2692 | sysproxy on ams3.madhacker.biz 8118 | C:\Users\admin\AppData\Local\Temp\proxy2\sysproxy.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2728 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\proxy2\dallas-off.bat" " | C:\Windows\System32\cmd.exe | — | proxy2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2772 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\proxy2\tokyo-off.bat" " | C:\Windows\System32\cmd.exe | — | proxy2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2832 | sysproxy on dal1.madhacker.biz 8118 | C:\Users\admin\AppData\Local\Temp\proxy2\sysproxy.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2856 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\proxy2\warsaw.bat" " | C:\Windows\System32\cmd.exe | — | proxy2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (3672) Release.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3672) Release.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3672) Release.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3672) Release.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3536) proxy2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3536) proxy2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3536) proxy2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3536) proxy2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3536) proxy2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3536) proxy2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyServer |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3672 | Release.exe | C:\Users\admin\AppData\Local\Temp\proxy2\dallas.bat | text | |
MD5:70037C73F14AC22D218B82B333918594 | SHA256:DB9166DE287BEF8D6CFA1D8A3E1F7892D0EF4CCC6996406F5AB28104477E0CF9 | |||
| 3672 | Release.exe | C:\Users\admin\AppData\Local\Temp\proxy2\tokyo-off.bat | text | |
MD5:F89A8509BA39FCB1A0EDE5289810E3C3 | SHA256:5DBF5582D046F8B2B2DE4E6A17D64ABADCA238FBEE1C13947ECBEA3F1E0025D7 | |||
| 3672 | Release.exe | C:\Users\admin\AppData\Local\Temp\proxy2\dallas-off.bat | text | |
MD5:AC347D2EFCBBB2FF0EEF8EF07E1F250F | SHA256:F84E6CA9C1BAE6443BBBA93FF2551A805B1B55D00923B523059C99424ABB22E6 | |||
| 3672 | Release.exe | C:\Users\admin\AppData\Local\Temp\proxy2\tokyo.bat | text | |
MD5:4A02329C4CCF6D8DB159F51CF2423A6C | SHA256:F0B512BE81F1A379AA121974A977603002017E238E68A8F8415D57C5DC89BEDB | |||
| 3672 | Release.exe | C:\Users\admin\AppData\Local\Temp\proxy2\sysproxy.exe | executable | |
MD5:380D58A33FAF71547FB97C3FC12A38A9 | SHA256:A918AA182DD57A545B0416E406432A6D09D1232AA0C33A0969DCD39A432D0D6B | |||
| 3536 | proxy2.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\line[1].txt | text | |
MD5:0C6D2B229F73F8A641F74D4F6512F204 | SHA256:A7D2595589083E6EACA3772908F1B7DCBC5B574F42779FE5B3A425ED83E7C7EF | |||
| 3672 | Release.exe | C:\Users\admin\AppData\Local\Temp\proxy2\warsaw.bat | text | |
MD5:829C4553AC0215C7CC76BB5FA9C01B26 | SHA256:7E225A2D5C51769C400CCD13B75F01C675317CE560F662699121D60160E5A110 | |||
| 3536 | proxy2.exe | C:\Users\admin\AppData\Local\Temp\TarF609.tmp | cat | |
MD5:9C0C641C06238516F27941AA1166D427 | SHA256:4276AF3669A141A59388BC56A87F6614D9A9BDDDF560636C264219A7EB11256F | |||
| 3536 | proxy2.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:EFC2DDAEF2A08E793DA4ED56C6455F0B | SHA256:7F057C6369FE04A574790714DC9E7F508198FBA0A22D2A68C90E8F8DA52B421A | |||
| 3536 | proxy2.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 | binary | |
MD5:D6DF751D73A120FC5E625007B135E505 | SHA256:3476561E5632A38DDEA4085626380FBA98DA7A7BBA62823EE9EE11EEE6DDE276 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3536 | proxy2.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?a8eff655f4df9ffc | unknown | — | — | unknown |
3536 | proxy2.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/line | unknown | text | 171 b | unknown |
3536 | proxy2.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?9f073e77455bfaf9 | unknown | compressed | 65.2 Kb | unknown |
3536 | proxy2.exe | GET | 200 | 69.192.161.44:80 | http://x1.c.lencr.org/ | unknown | binary | 717 b | unknown |
3536 | proxy2.exe | GET | 200 | 95.101.54.114:80 | http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgTA2ZbveOPYUdm86t%2FX4bavGw%3D%3D | unknown | binary | 503 b | unknown |
3536 | proxy2.exe | GET | 200 | 64.176.66.218:8118 | http://ip-api.com/line | unknown | text | 173 b | unknown |
3536 | proxy2.exe | GET | 200 | 208.95.112.1:80 | http://ip-api.com/line | unknown | text | 171 b | unknown |
3536 | proxy2.exe | GET | 200 | 45.32.193.109:8118 | http://ip-api.com/line | unknown | text | 155 b | unknown |
3536 | proxy2.exe | GET | 200 | 202.182.105.101:8118 | http://ip-api.com/line | unknown | text | 157 b | unknown |
1080 | svchost.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e90c163b6659448e | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3536 | proxy2.exe | 208.95.112.1:80 | ip-api.com | TUT-AS | US | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3536 | proxy2.exe | 64.176.66.218:443 | ams3.madhacker.biz | — | US | unknown |
3536 | proxy2.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
3536 | proxy2.exe | 69.192.161.44:80 | x1.c.lencr.org | AKAMAI-AS | DE | unknown |
3536 | proxy2.exe | 95.101.54.114:80 | r3.o.lencr.org | Akamai International B.V. | DE | unknown |
3536 | proxy2.exe | 64.176.66.218:8118 | ams3.madhacker.biz | — | US | unknown |
3536 | proxy2.exe | 45.32.193.109:8118 | dal1.madhacker.biz | AS-CHOOPA | US | unknown |
Domain | IP | Reputation |
|---|---|---|
ip-api.com |
| shared |
ams3.madhacker.biz |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
r3.o.lencr.org |
| shared |
dal1.madhacker.biz |
| unknown |
tyo1.madhacker.biz |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Potentially Bad Traffic | ET INFO DYNAMIC_DNS Query to a *.madhacker .biz Domain |
1080 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .biz TLD |
3536 | proxy2.exe | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
3536 | proxy2.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |
3536 | proxy2.exe | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
3536 | proxy2.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |
3536 | proxy2.exe | Potential Corporate Privacy Violation | AV POLICY Internal Host Retrieving External IP Address (ip-api. com) |
3536 | proxy2.exe | Device Retrieving External IP Address Detected | ET POLICY External IP Lookup ip-api.com |
1080 | svchost.exe | Potentially Bad Traffic | ET INFO Observed DNS Query to .biz TLD |
1080 | svchost.exe | Potentially Bad Traffic | ET INFO DYNAMIC_DNS Query to a *.madhacker .biz Domain |