File name:

ctfmon.exe

Full analysis: https://app.any.run/tasks/73c2a4fd-28bb-4ae7-adc8-3a91b5238f90
Verdict: Malicious activity
Analysis date: October 18, 2023, 09:12:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

74DBD545CF6DC5D006325CC3E4658A12

SHA1:

9E6B92ED3D29A46611234836D4D493F226CE5FA7

SHA256:

316C85917832C66AC0071F73A880D5E40099A16E419F7813FBE39EE0A851D1C7

SSDEEP:

192:L0v9/blXo4IQtPcwPUSobHM9EFFelPNWWNWP:L0v9/n9WWNWP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • ctfmon.exe (PID: 2464)
    • Create files in the Startup directory

      • ctfmon.exe (PID: 2464)
    • Drops the executable file immediately after the start

      • ctfmon.exe (PID: 2464)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • ctfmon.exe (PID: 2464)
    • The process creates files with name similar to system file names

      • ctfmon.exe (PID: 2464)
    • Write to the desktop.ini file (may be used to cloak folders)

      • ctfmon.exe (PID: 2464)
  • INFO

    • Checks supported languages

      • ctfmon.exe (PID: 2464)
    • Reads the machine GUID from the registry

      • ctfmon.exe (PID: 2464)
    • Reads the computer name

      • ctfmon.exe (PID: 2464)
    • Creates files or folders in the user directory

      • ctfmon.exe (PID: 2464)
    • Create files in a temporary directory

      • ctfmon.exe (PID: 2464)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Microsoft Visual Basic 6 (84.4)
.dll | Win32 Dynamic Link Library (generic) (6.7)
.exe | Win32 Executable (generic) (4.6)
.exe | Generic Win/DOS Executable (2)
.exe | DOS Executable Generic (2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2006:06:27 08:23:40+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 12288
InitializedDataSize: 8192
UninitializedDataSize: -
EntryPoint: 0x109c
OSVersion: 4
ImageVersion: 51.21
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 51.2100.0.2690
ProductVersionNumber: 51.2100.0.2690
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
Comments: CTF Loader
CompanyName: Microsoft Corporation
FileDescription: CTF Loader
LegalCopyright: @ Microsoft Corporation. All rights reserved.
LegalTrademarks: CTF Loader
ProductName: Microsoft@ Windows@ Operating System
FileVersion: 51.2100.2690
ProductVersion: 51.2100.2690
InternalName: ctfmon
OriginalFileName: ctfmon.exe
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start ctfmon.exe

Process information

PID
CMD
Path
Indicators
Parent process
2464"C:\Users\admin\AppData\Local\Temp\ctfmon.exe" C:\Users\admin\AppData\Local\Temp\ctfmon.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CTF Loader
Exit code:
0
Version:
51.2100.2690
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\users\admin\appdata\local\temp\ctfmon.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
136
Read events
136
Write events
0
Delete events
0

Modification events

No data
Executable files
3
Suspicious files
2
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2464ctfmon.exeC:\Recycled\INFO2binary
MD5:5101F3AC57F684F2AE0868645A9AFB6A
SHA256:420DC76D37A1AB821E587D703AC5E629281149E78744288F9D43A8FEB885A236
2464ctfmon.exeC:\Users\admin\AppData\Local\Temp\~DF19D30C4AD1093B6E.TMPbinary
MD5:1D6D4C5F84F9D1EDBB2E4FEC778BDE19
SHA256:7FAEE2F8E86AD3516636BF1FD82541FAD875851870E168BF356DE4A26B9851FB
2464ctfmon.exeC:\Recycled\desktop.initext
MD5:AD0B0B4416F06AF436328A3C12DC491B
SHA256:23521DE51CA1DB2BC7B18E41DE7693542235284667BF85F6C31902547A947416
2464ctfmon.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\ctfmon.exeexecutable
MD5:74DBD545CF6DC5D006325CC3E4658A12
SHA256:316C85917832C66AC0071F73A880D5E40099A16E419F7813FBE39EE0A851D1C7
2464ctfmon.exeC:\Recycled\Recycled\ctfmon.exeexecutable
MD5:74DBD545CF6DC5D006325CC3E4658A12
SHA256:316C85917832C66AC0071F73A880D5E40099A16E419F7813FBE39EE0A851D1C7
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1088
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2656
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info