| download: | /vir/Email-Worm.Win32.Sobig.b |
| Full analysis: | https://app.any.run/tasks/550a91bb-d4b1-41da-aaa1-d552b671cbe7 |
| Verdict: | Malicious activity |
| Analysis date: | November 29, 2024, 19:25:27 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 3 sections |
| MD5: | 4EBF94FB8AFF892D6CF99A651348FF5A |
| SHA1: | 20871CF51FDD67018CD9DFB6860AD35539DBE2CF |
| SHA256: | 32C2857AD572CD2390DEA8CFA12E02D62F4D759C34DFA87994E0F7E5A4E71604 |
| SSDEEP: | 768:jEHuutiVFbJhmU9Nr9R+ci9Vkv2SGTSJ5h27I3BJkwNK/Oq1IHeeHVfwXXUbpPKk:oAVFbJhr7yaiZExKYKj1IHQKZ65ABROo |
| .exe | | | Win64 Executable (generic) (39.8) |
|---|---|---|
| .exe | | | Win32 EXE Yoda's Crypter (38.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (9.4) |
| .exe | | | Win32 Executable (generic) (6.5) |
| .exe | | | Generic Win/DOS Executable (2.8) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2003:05:16 16:16:59+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 49152 |
| InitializedDataSize: | 4096 |
| UninitializedDataSize: | 65536 |
| EntryPoint: | 0x1ca80 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 444 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 848 | "C:\Windows\System32\runas.exe" /user:administrator C:\Users\admin\Desktop\Email-Worm.Win32.Sobig.b.exe | C:\Windows\System32\runas.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Run As Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2276 | C:\Windows\msccn32.exe xcvfd | C:\Windows\msccn32.exe | Email-Worm.Win32.Sobig.b.exe | ||||||||||||
User: Administrator Integrity Level: HIGH Modules
| |||||||||||||||
| 2284 | C:\Users\admin\Desktop\Email-Worm.Win32.Sobig.b.exe | C:\Users\admin\Desktop\Email-Worm.Win32.Sobig.b.exe | runas.exe | ||||||||||||
User: Administrator Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2284) Email-Worm.Win32.Sobig.b.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | System Tray |
Value: C:\Windows\msccn32.exe | |||
| (PID) Process: | (2284) Email-Worm.Win32.Sobig.b.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | System Tray |
Value: C:\Windows\msccn32.exe | |||
| (PID) Process: | (2276) msccn32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | delete value | Name: | ProxyBypass |
Value: | |||
| (PID) Process: | (2276) msccn32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | delete value | Name: | IntranetName |
Value: | |||
| (PID) Process: | (2276) msccn32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2276) msccn32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2276) msccn32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | delete value | Name: | ProxyBypass |
Value: | |||
| (PID) Process: | (2276) msccn32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | delete value | Name: | IntranetName |
Value: | |||
| (PID) Process: | (2276) msccn32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\msccn32_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (2276) msccn32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\msccn32_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2276 | msccn32.exe | C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | compressed | |
MD5:1BFE591A4FE3D91B03CDF26EAACD8F89 | SHA256:9CF94355051BF0F4A45724CA20D1CC02F76371B963AB7D1E38BD8997737B13D8 | |||
| 2284 | Email-Worm.Win32.Sobig.b.exe | C:\Windows\msccn32.exe | executable | |
MD5:4EBF94FB8AFF892D6CF99A651348FF5A | SHA256:32C2857AD572CD2390DEA8CFA12E02D62F4D759C34DFA87994E0F7E5A4E71604 | |||
| 2276 | msccn32.exe | C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EDC238BFF48A31D55A97E1E93892934B_C20E0DA2D0F89FE526E1490F4A2EE5AB | binary | |
MD5:543684C925ECFFC0939806A0D4CC8B8E | SHA256:55F057013DAFCB7470BCB8621158324CC7C6685170B249119E0C9A7F50F399C4 | |||
| 2276 | msccn32.exe | C:\Users\Administrator\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\BFG3Q0C8\0EWM90WT.htm | html | |
MD5:81D41C08354E19D0B1BA31C1EFB29D0F | SHA256:9A7C9E9C7C313E8EF6F2C56BD0884A6D0E3FC892E4D53936C4E915B9E6FAE085 | |||
| 2276 | msccn32.exe | C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\EDC238BFF48A31D55A97E1E93892934B_C20E0DA2D0F89FE526E1490F4A2EE5AB | binary | |
MD5:8E6CE0832C9606D41C77700DA2F97350 | SHA256:18CB7F7AB85EE4458021654D459890D4110B8FD7A1A7381822454FF6D029E69B | |||
| 2276 | msccn32.exe | C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Cookies\KMNUJZKP.txt | text | |
MD5:C5A32321F715A0C63C15911E67CE0719 | SHA256:D1F16DDBF54E13C113DEEF639159E4DAD29DF98773949D3A8C3CB21E3A6E43D4 | |||
| 2276 | msccn32.exe | C:\Users\Administrator\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:81D0A416C5A65FDAEC9C302A7F672AAD | SHA256:707D4E2E2B1BDA88F1479A0949A9CBD9DE59D1F90154A9C31D9AC69CBDF4CF0E | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2276 | msccn32.exe | GET | 301 | 74.6.143.25:80 | http://yahoo.com/ | unknown | — | — | whitelisted |
2276 | msccn32.exe | GET | 301 | 13.248.158.7:80 | http://www.geocities.com/fjgoplsnjs/jane.txt | unknown | — | — | whitelisted |
— | — | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTfqhLjKLEJQZPin0KCzkdAQpVYowQUsT7DaQP4v0cB1JgmGggC72NkK8MCEATh56TcXPLzbcArQrhdFZ8%3D | unknown | — | — | whitelisted |
2276 | msccn32.exe | GET | 200 | 199.232.214.172:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?e054d4eeea0b07ab | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1108 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
2276 | msccn32.exe | 13.248.158.7:80 | www.geocities.com | AMAZON-02 | US | whitelisted |
2276 | msccn32.exe | 74.6.143.25:80 | yahoo.com | YAHOO-BF1 | US | whitelisted |
2276 | msccn32.exe | 74.6.143.25:443 | yahoo.com | YAHOO-BF1 | US | whitelisted |
2276 | msccn32.exe | 199.232.214.172:80 | ctldl.windowsupdate.com | FASTLY | US | whitelisted |
2276 | msccn32.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
2276 | msccn32.exe | 87.248.119.252:443 | www.yahoo.com | Yahoo! UK Services Limited | GB | whitelisted |
2276 | msccn32.exe | 87.248.119.251:443 | www.yahoo.com | Yahoo! UK Services Limited | GB | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
A.ROOT-SERVERS.NET |
| unknown |
B.ROOT-SERVERS.NET |
| unknown |
www.geocities.com |
| whitelisted |
yahoo.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
www.yahoo.com |
| whitelisted |
de.yahoo.com |
| whitelisted |