File name:

Application bomber.bat

Full analysis: https://app.any.run/tasks/ea663afc-e4b4-423a-827e-58b7e36bd390
Verdict: Malicious activity
Analysis date: September 30, 2020, 01:08:00
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/x-msdos-batch
File info: DOS batch file, ASCII text, with CRLF line terminators
MD5:

262DF7604ED5DBB13CA653B07C3CD3B0

SHA1:

032238A9F4444C27D74DB76F90591F74FF637FC4

SHA256:

2EFB0CA1D80F8DF7D2369E2DC89F59D8576653136408A6BE24585A919BD1E860

SSDEEP:

3:mKDDc1lRJM1wDzaz2jizkMmoORKfe7zYEXCREzdLlORKTIoBRCn:hel/MsOCjiRmFc2PSRExL1VBUn

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Runs app for hidden code execution

      • cmd.exe (PID: 3836)
  • SUSPICIOUS

    • Starts Microsoft Office Application

      • cmd.exe (PID: 3836)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 3836)
    • Application launched itself

      • cmd.exe (PID: 3836)
  • INFO

    • Creates files in the user directory

      • WINWORD.EXE (PID: 3932)
    • Reads Microsoft Office registry keys

      • WINWORD.EXE (PID: 1524)
      • WINWORD.EXE (PID: 3932)
      • WINWORD.EXE (PID: 4472)
      • WINWORD.EXE (PID: 4048)
      • WINWORD.EXE (PID: 2536)
      • WINWORD.EXE (PID: 3036)
      • WINWORD.EXE (PID: 4388)
      • WINWORD.EXE (PID: 4252)
      • WINWORD.EXE (PID: 4548)
      • WINWORD.EXE (PID: 5960)
      • WINWORD.EXE (PID: 5176)
      • WINWORD.EXE (PID: 5076)
      • WINWORD.EXE (PID: 5784)
      • WINWORD.EXE (PID: 3112)
      • WINWORD.EXE (PID: 2620)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
276
Monitored processes
215
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start cmd.exe no specs winword.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs explorer.exe no specs calc.exe no specs control.exe no specs winword.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs winword.exe no specs wordpad.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs winword.exe no specs wordpad.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs winword.exe no specs wordpad.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs winword.exe no specs wordpad.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs wordpad.exe no specs winword.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs winword.exe no specs wordpad.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs wordpad.exe no specs winword.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs wordpad.exe no specs winword.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs winword.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs wordpad.exe no specs winword.exe no specs mspaint.exe no specs wordpad.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs wordpad.exe no specs winword.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs winword.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs wordpad.exe no specs winword.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs wordpad.exe no specs winword.exe no specs wordpad.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs winword.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs wordpad.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs winword.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs wordpad.exe no specs winword.exe no specs wordpad.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs winword.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs wordpad.exe no specs winword.exe no specs wordpad.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs winword.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs wordpad.exe no specs cmd.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs winword.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs wordpad.exe no specs winword.exe no specs mspaint.exe no specs notepad.exe no specs write.exe no specs cmd.exe no specs explorer.exe no specs control.exe no specs calc.exe no specs wordpad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
612calc C:\Windows\system32\calc.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Calculator
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\calc.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
724notepad C:\Windows\system32\notepad.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
748write C:\Windows\system32\write.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Write
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\write.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
792"C:\Program Files\Windows NT\Accessories\wordpad.exe" C:\Program Files\Windows NT\Accessories\wordpad.exewrite.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Wordpad Application
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows nt\accessories\wordpad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1020explorer C:\Windows\explorer.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1072notepad C:\Windows\system32\notepad.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1092control C:\Windows\system32\control.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Control Panel
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\control.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1136mspaint C:\Windows\system32\mspaint.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Paint
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\mspaint.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1152write C:\Windows\system32\write.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Write
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\write.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1352cmd C:\Windows\system32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
8 765
Read events
7 152
Write events
1 364
Delete events
249

Modification events

(PID) Process:(3836) cmd.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3836) cmd.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(612) calc.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Calc
Operation:writeName:Window_Placement
Value:
2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF2C0000002C0000004C03000084020000
(PID) Process:(3932) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Word\Resiliency\StartupItems
Operation:writeName:%`c
Value:
256063005C0F0000010000000000000000000000
(PID) Process:(3932) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1033
Value:
Off
(PID) Process:(3932) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1041
Value:
Off
(PID) Process:(3932) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1046
Value:
Off
(PID) Process:(3932) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1036
Value:
Off
(PID) Process:(3932) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1031
Value:
Off
(PID) Process:(3932) WINWORD.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Office\14.0\Common\LanguageResources\EnabledLanguages
Operation:writeName:1040
Value:
Off
Executable files
0
Suspicious files
0
Text files
0
Unknown types
1

Dropped files

PID
Process
Filename
Type
3932WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRA885.tmp.cvr
MD5:
SHA256:
1524WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRAC3E.tmp.cvr
MD5:
SHA256:
3036WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRB0E2.tmp.cvr
MD5:
SHA256:
4048WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRB6CD.tmp.cvr
MD5:
SHA256:
2380WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRBD75.tmp.cvr
MD5:
SHA256:
2620WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRC4C8.tmp.cvr
MD5:
SHA256:
2824WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRCCB7.tmp.cvr
MD5:
SHA256:
2536WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRD458.tmp.cvr
MD5:
SHA256:
3784WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRDBAB.tmp.cvr
MD5:
SHA256:
3112WINWORD.EXEC:\Users\admin\AppData\Local\Temp\CVRE35C.tmp.cvr
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info