File name:

CentraSize.exe

Full analysis: https://app.any.run/tasks/1a5225af-02ca-4ef2-b2df-0d5c59f2c2ca
Verdict: Malicious activity
Analysis date: November 09, 2023, 18:03:21
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows, UPX compressed
MD5:

1ADF3A6B149E2CFFE43AC39260360609

SHA1:

6D3635E93854DDDBECA11048850363F7FCBF1035

SHA256:

333826DC55DC76E092BB7EA236C3B49D9E221F1BB2B23A7B2640DA09CAB592DC

SSDEEP:

24576:jo4Y2qJ1wlJRfEB5CExEf7BswBB8T0sqDV0fdzr7k:s4Y2A1wjRsB5CExEf7BswBaTn2V0fdzE

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • CentraSize.exe (PID: 3308)
    • Actions looks like stealing of personal data

      • disksum.exe (PID: 2900)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • CentraSize.exe (PID: 3308)
  • INFO

    • Checks supported languages

      • CentraSize.exe (PID: 3308)
      • disksum.exe (PID: 2900)
    • Create files in a temporary directory

      • CentraSize.exe (PID: 3308)
    • Reads mouse settings

      • CentraSize.exe (PID: 3308)
    • Reads the computer name

      • CentraSize.exe (PID: 3308)
    • The executable file from the user directory is run by the CMD process

      • disksum.exe (PID: 2900)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | AutoIt3 compiled script executable (88.1)
.exe | UPX compressed Win32 Executable (4.6)
.exe | Win32 EXE Yoda's Crypter (4.5)
.dll | Win32 Dynamic Link Library (generic) (1.1)
.exe | Win32 Executable (generic) (0.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:01:29 22:32:28+01:00
ImageFileCharacteristics: No relocs, Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 274432
InitializedDataSize: 180224
UninitializedDataSize: 630784
EntryPoint: 0xdceb0
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows command line
FileVersionNumber: 3.3.8.1
ProductVersionNumber: 3.3.8.1
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (British)
CharacterSet: Unicode
FileDescription: -
FileVersion: 3, 3, 8, 1
CompiledScript: AutoIt v3 Script: 3, 3, 8, 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
4
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start centrasize.exe no specs cmd.exe no specs disksum.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2900disksum \C:\Users\admin\AppData\Local\Temp\disksum.exe
cmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\disksum.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
2904C:\Windows\system32\cmd.exe /c disksum \C:\Windows\System32\cmd.exeCentraSize.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3208"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3308"C:\Users\admin\AppData\Local\Temp\CentraSize.exe" C:\Users\admin\AppData\Local\Temp\CentraSize.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
3, 3, 8, 1
Modules
Images
c:\users\admin\appdata\local\temp\centrasize.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
Total events
71
Read events
71
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
1
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3308CentraSize.exeC:\Users\admin\AppData\Local\Temp\disksum.exeexecutable
MD5:6077AD23837093C9EDE540DF1C949AB2
SHA256:ADBA3007387B90057A985D49F0192D56DB20F99F2C61C58463356A0F076CA7F5
3308CentraSize.exeC:\Users\admin\AppData\Local\Temp\aut95CC.tmpbinary
MD5:2AD8303ACAE164C2468FBA254E20B79A
SHA256:40914F7C6D4AAF517EA0408BF70231256F6EF6BED349E354C196BDB0E2D54024
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
4
System
192.168.100.255:138
unknown

DNS requests

No data

Threats

No threats detected
No debug info