File name:

336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exe

Full analysis: https://app.any.run/tasks/da30114a-5443-4eeb-9d60-f8b0bc5c7320
Verdict: Malicious activity
Analysis date: January 20, 2024, 15:28:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

15EE2EFB6FE685D6D5217C58C33D98E2

SHA1:

4A6B8FCB5C21621A81C35CD367E186985044408C

SHA256:

336C6F0D9DE3DE21F971C92E2239DAC504580B4259602F9D602D0C4D7A2DACCE

SSDEEP:

393216:SgQyhCkfw41e0GaHilcPPiBBKjYLudqmI:SgQyl44g+C+SBYEidE

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 1492)
      • 336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exe (PID: 3056)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 1928)
    • Reads the BIOS version

      • 336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exe (PID: 3056)
  • INFO

    • Drops the executable file immediately after the start

      • 336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exe (PID: 3056)
    • Checks supported languages

      • 336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exe (PID: 3056)
    • Reads the computer name

      • 336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exe (PID: 3056)
    • Application launched itself

      • cmd.exe (PID: 1492)
    • Process checks whether UAC notifications are on

      • 336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exe (PID: 3056)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2023:12:06 23:21:39+01:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.38
CodeSize: 1301504
InitializedDataSize: 1647616
UninitializedDataSize: -
EntryPoint: 0x2afe058
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
9
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exe cmd.exe no specs certutil.exe no specs find.exe no specs find.exe no specs cmd.exe no specs cmd.exe no specs timeout.exe no specs 336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
756certutil -hashfile "C:\Users\admin\AppData\Local\Temp\336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exe" MD5 C:\Windows\System32\certutil.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
CertUtil.exe
Exit code:
0
Version:
6.1.7601.18151 (win7sp1_gdr.130512-1533)
Modules
Images
c:\windows\system32\certutil.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\certcli.dll
c:\windows\system32\atl.dll
1492C:\Windows\system32\cmd.exe /c start cmd /C "color b && title Error && echo Signature checksum failed. Request was tampered with or session ended most likely. & echo: & echo Message: Error: Connection refused && timeout /t 5"C:\Windows\System32\cmd.exe336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1928cmd /C "color b && title Error && echo Signature checksum failed. Request was tampered with or session ended most likely. & echo: & echo Message: Error: Connection refused && timeout /t 5"C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2012find /i /v "certutil"C:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2300C:\Windows\system32\cmd.exe /c certutil -hashfile "C:\Users\admin\AppData\Local\Temp\336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exe" MD5 | find /i /v "md5" | find /i /v "certutil"C:\Windows\System32\cmd.exe336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2936"C:\Users\admin\AppData\Local\Temp\336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exe" C:\Users\admin\AppData\Local\Temp\336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exe
c:\windows\system32\ntdll.dll
3016find /i /v "md5" C:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3044timeout /t 5C:\Windows\System32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
timeout - pauses command processing
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
3056"C:\Users\admin\AppData\Local\Temp\336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exe" C:\Users\admin\AppData\Local\Temp\336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3221225477
Modules
Images
c:\users\admin\appdata\local\temp\336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\urlmon.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\api-ms-win-downlevel-ole32-l1-1-0.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
261
Read events
261
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
9
DNS requests
4
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
492
lsass.exe
GET
200
2.19.217.103:80
http://x2.c.lencr.org/
NL
binary
300 b
unknown
352
svchost.exe
GET
304
2.19.105.18:80
http://x1.c.lencr.org/
DE
unknown
492
lsass.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d08926ec3acba225
GB
compressed
4.66 Kb
unknown
492
lsass.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?af231d232ecdafd8
GB
compressed
65.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
352
svchost.exe
224.0.0.252:5355
unknown
1220
svchost.exe
239.255.255.250:3702
whitelisted
3056
336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exe
104.26.1.5:443
keyauth.win
CLOUDFLARENET
US
unknown
492
lsass.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
492
lsass.exe
2.19.217.103:80
x2.c.lencr.org
Akamai International B.V.
NL
unknown
352
svchost.exe
2.19.105.18:80
x1.c.lencr.org
AKAMAI-AS
DE
unknown

DNS requests

Domain
IP
Reputation
keyauth.win
  • 104.26.1.5
  • 172.67.72.57
  • 104.26.0.5
malicious
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
x2.c.lencr.org
  • 2.19.217.103
whitelisted
x1.c.lencr.org
  • 2.19.105.18
whitelisted

Threats

PID
Process
Class
Message
352
svchost.exe
Potentially Bad Traffic
ET INFO Fake Game Cheat Related Domain in DNS Lookup (keyauth .win)
3056
336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exe
Potentially Bad Traffic
ET INFO Fake Game Cheat Related Domain (keyauth .win) in TLS SNI
Process
Message
336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exe
Security
336c6f0d9de3de21f971c92e2239dac504580b4259602f9d602d0c4d7a2dacce.exe
Security