File name:

autodocksuite-4.2.6.i86Windows.exe

Full analysis: https://app.any.run/tasks/83e8e15e-72c2-41af-965c-6d071cb3a0fc
Verdict: Malicious activity
Analysis date: April 18, 2024, 05:22:24
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

8DACD08691EC206060BA7E84D32A1CFA

SHA1:

5174C46DA68280D5DDF64F7A5DC9519E8D4B643A

SHA256:

306DC72A06E80A2DA6F3C410AC6ABA7EBDAEEF6B702ECA42DE44C7C6C9D48755

SSDEEP:

24576:BnUCXUQwfULY5b0V0/yxD4vyA0ca5BQlaZJ4xEJuw5u0J9:BnUCXUQwfULY5oVUyxEvyA0ca5BaaZJ5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • autodocksuite-4.2.6.i86Windows.exe (PID: 3004)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • autodocksuite-4.2.6.i86Windows.exe (PID: 3004)
  • INFO

    • Reads the computer name

      • autodocksuite-4.2.6.i86Windows.exe (PID: 3004)
    • Checks supported languages

      • autodocksuite-4.2.6.i86Windows.exe (PID: 3004)
    • Creates files in the program directory

      • autodocksuite-4.2.6.i86Windows.exe (PID: 3004)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | NSIS - Nullsoft Scriptable Install System (94.8)
.exe | Win32 Executable MS Visual C++ (generic) (3.4)
.dll | Win32 Dynamic Link Library (generic) (0.7)
.exe | Win32 Executable (generic) (0.5)
.exe | Generic Win/DOS Executable (0.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:06:06 21:41:48+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 23040
InitializedDataSize: 119808
UninitializedDataSize: 1024
EntryPoint: 0x30cb
OSVersion: 4
ImageVersion: 6.1
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start autodocksuite-4.2.6.i86windows.exe autodocksuite-4.2.6.i86windows.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
668"C:\Users\admin\AppData\Local\Temp\autodocksuite-4.2.6.i86Windows.exe" C:\Users\admin\AppData\Local\Temp\autodocksuite-4.2.6.i86Windows.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\autodocksuite-4.2.6.i86windows.exe
c:\windows\system32\ntdll.dll
3004"C:\Users\admin\AppData\Local\Temp\autodocksuite-4.2.6.i86Windows.exe" C:\Users\admin\AppData\Local\Temp\autodocksuite-4.2.6.i86Windows.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\autodocksuite-4.2.6.i86windows.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
2 357
Read events
2 357
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3004autodocksuite-4.2.6.i86Windows.exeC:\Program Files\The Scripps Research Institute\Autodock\4.2.6\autodock4.exeexecutable
MD5:052576A87455C30DF8EF8BDD951D65AB
SHA256:36C0B16C04D7DF8E6225737BAE65BB04058D1F4C90ACCFAF2D230DBC913954BF
3004autodocksuite-4.2.6.i86Windows.exeC:\Program Files\The Scripps Research Institute\Autodock\4.2.6\autogrid4.exeexecutable
MD5:9EF694A508215D5C46AB072FBA59E035
SHA256:797EFCE687D1AE82DF59726461E0E1966B3D8EDB0F8B187F982FA1AB0C12DA9E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info