File name:

1SpywareKillerV21_466026.exe

Full analysis: https://app.any.run/tasks/8d6dcc6a-dce6-43fb-8545-1d2e4db3cbf5
Verdict: Malicious activity
Analysis date: July 08, 2024, 22:36:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

27409BA811F88E30166AE702EDC33FF2

SHA1:

4EA8D1D8431E86FE80DF5C6EBAD5429FB25C9660

SHA256:

337C3CC4105263D0AE1EF3BD9E913A17DA89E900D18A8012055819FAD56BF1C3

SSDEEP:

98304:Hd9ckfAlr9SMhYjz1X86j8gOnCuybygjG/+GJgXs/BZTF8AYhC8mjw4UZCXrYAGg:LZJq

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • 1SpywareKillerV21_466026.exe (PID: 3208)
    • Creates a writable file in the system directory

      • 1SpywareKillerV21_466026.exe (PID: 3208)
    • Changes the autorun value in the registry

      • 1SpywareKillerV21_466026.exe (PID: 3208)
      • #1SpywareKiller.exe (PID: 3124)
    • Steals credentials from Web Browsers

      • #1SpywareKiller.exe (PID: 3124)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • 1SpywareKillerV21_466026.exe (PID: 3208)
    • Executable content was dropped or overwritten

      • 1SpywareKillerV21_466026.exe (PID: 3208)
    • Creates/Modifies COM task schedule object

      • 1SpywareKillerV21_466026.exe (PID: 3208)
    • Reads security settings of Internet Explorer

      • 1SpywareKillerV21_466026.exe (PID: 3208)
    • Creates a software uninstall entry

      • 1SpywareKillerV21_466026.exe (PID: 3208)
    • Reads the Internet Settings

      • 1SpywareKillerV21_466026.exe (PID: 3208)
    • Changes the Home page of Internet Explorer

      • #1SpywareKiller.exe (PID: 3124)
    • Changes the title of the Internet Explorer window

      • #1SpywareKiller.exe (PID: 3124)
  • INFO

    • Create files in a temporary directory

      • 1SpywareKillerV21_466026.exe (PID: 3208)
      • #1SpywareKiller.exe (PID: 3124)
    • Checks supported languages

      • 1SpywareKillerV21_466026.exe (PID: 3208)
      • #1SpywareKiller.exe (PID: 3124)
    • Reads the computer name

      • 1SpywareKillerV21_466026.exe (PID: 3208)
    • Creates files in the program directory

      • 1SpywareKillerV21_466026.exe (PID: 3208)
    • Reads the machine GUID from the registry

      • 1SpywareKillerV21_466026.exe (PID: 3208)
      • #1SpywareKiller.exe (PID: 3124)
    • Reads mouse settings

      • 1SpywareKillerV21_466026.exe (PID: 3208)
      • #1SpywareKiller.exe (PID: 3124)
    • Reads Microsoft Office registry keys

      • #1SpywareKiller.exe (PID: 3124)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1999:06:09 21:57:29+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 49152
InitializedDataSize: 20480
UninitializedDataSize: -
EntryPoint: 0x71a0
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 1spywarekillerv21_466026.exe #1spywarekiller.exe 1spywarekillerv21_466026.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3124"C:\PROGRA~1\#1SPYW~1.1\#1SpywareKiller.exe" C:\Program Files\#1SpywareKillerv2.1\#1SpywareKiller.exe
1SpywareKillerV21_466026.exe
User:
admin
Company:
www.1SpywareKiller.com
Integrity Level:
HIGH
Description:
#1 Spyware Killer
Version:
2.01
Modules
Images
c:\program files\#1spywarekillerv2.1\#1spywarekiller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3208"C:\Users\admin\AppData\Local\Temp\1SpywareKillerV21_466026.exe" C:\Users\admin\AppData\Local\Temp\1SpywareKillerV21_466026.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\1spywarekillerv21_466026.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3416"C:\Users\admin\AppData\Local\Temp\1SpywareKillerV21_466026.exe" C:\Users\admin\AppData\Local\Temp\1SpywareKillerV21_466026.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\1spywarekillerv21_466026.exe
c:\windows\system32\ntdll.dll
Total events
12 809
Read events
9 349
Write events
3 418
Delete events
42

Modification events

(PID) Process:(3208) 1SpywareKillerV21_466026.exeKey:HKEY_CURRENT_USER\Software\VB and VBA Program Settings\1spywarekillerAFF\Affiliate
Operation:writeName:Code
Value:
"C:\Users\admin\AppData\Local\Temp\1SpywareKillerV21_466026.exe"
(PID) Process:(3208) 1SpywareKillerV21_466026.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
0202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
(PID) Process:(3208) 1SpywareKillerV21_466026.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:MRUListEx
Value:
01000000070000000000000002000000060000000B0000000C0000000D0000000A0000000900000008000000030000000500000004000000FFFFFFFF
(PID) Process:(3208) 1SpywareKillerV21_466026.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
Operation:writeName:MRUListEx
Value:
040000000000000001000000020000000500000003000000FFFFFFFF
(PID) Process:(3208) 1SpywareKillerV21_466026.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4
Operation:writeName:MRUListEx
Value:
000000000500000004000000030000000200000001000000FFFFFFFF
(PID) Process:(3208) 1SpywareKillerV21_466026.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0
Operation:writeName:1
Value:
800031000000000000000000100023312053707977617265204B696C6C65722076322E3100005A0008000400EFBE00000000000000002A00000000000000000000000000000000000000000000000000230031002000530070007900770061007200650020004B0069006C006C00650072002000760032002E003100000026000000
(PID) Process:(3208) 1SpywareKillerV21_466026.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0\1
Operation:delete valueName:MRUList
Value:
(PID) Process:(3208) 1SpywareKillerV21_466026.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0
Operation:writeName:MRUListEx
Value:
0100000000000000FFFFFFFF
(PID) Process:(3208) 1SpywareKillerV21_466026.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
(PID) Process:(3208) 1SpywareKillerV21_466026.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\4\0\0\0\0\1
Operation:writeName:NodeSlot
Value:
228
Executable files
13
Suspicious files
10
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
32081SpywareKillerV21_466026.exeC:\Users\admin\AppData\Local\Temp\~vis0000\vise32ex.dllexecutable
MD5:DB798587868984EB838A71338F6FFE53
SHA256:6D4209A51DEDB0AEDCDFD5CBED6FC80DBC34B51CD1DC176D788F07B5CDF06642
32081SpywareKillerV21_466026.exeC:\Users\admin\AppData\Local\Temp\~vis0000\English.vlgini
MD5:707E3B6418526ED6729DEB4A1307F1F2
SHA256:75081F741B450B8049D3A0106121516745BBA675681FB490E78B7978238258D5
32081SpywareKillerV21_466026.exeC:\Users\admin\AppData\Local\Temp\~vis0000\miscdata.xyzbinary
MD5:64A5DF7D62EC9B03C0A75E18297D41D3
SHA256:08C637371BCF2D779AE302810601BB208DC516C16084C27E92DE7EE828990D58
32081SpywareKillerV21_466026.exeC:\Users\admin\AppData\Local\Temp\~vis0000\UninstallDLL.dllexecutable
MD5:7D18C0F2E417F84CF6981B5B042633A5
SHA256:497E82B877750CEF26D22878DEB18E01AF1C0507C2BE16FB50A1EA42C6BDCAE4
32081SpywareKillerV21_466026.exeC:\Users\admin\AppData\Local\Temp\~vis0000\rebootnt.exeexecutable
MD5:C459E252866435ED8B928D1509C28DE2
SHA256:4887FF02F8E45F5E03E351CB5156111659CC1B04FDCA9DAE3BD75CB99381DEDE
32081SpywareKillerV21_466026.exeC:\Users\admin\AppData\Local\Temp\~vis0000\uninst32.exeexecutable
MD5:84B4F61F59A421BD85D97B35D194B42B
SHA256:F241F37D423DD5C192B22CA1D4655DBF9E9B861487A6AC0F958B190E975934DC
32081SpywareKillerV21_466026.exeC:\Users\admin\AppData\Local\Temp\~vis0000\default.bmpbinary
MD5:F372B11FF99BFFED4CD279C0155ADEDE
SHA256:D9D5E28EB445E7986BDEF4D409868AF205D525F2F0729427DFE3E33A7251B15D
32081SpywareKillerV21_466026.exeC:\Program Files\#1SpywareKillerv2.1\RegistrySpylisttext
MD5:EEC81BEBB7A2BB8D022537ADDCDEF4F2
SHA256:7EB08C88BD0C6F26131B20DCA164800E79056DFB41C00064440C101A7EEFACC1
32081SpywareKillerV21_466026.exeC:\Users\admin\AppData\Local\Temp\~vis0000\rollback.logtext
MD5:3783EF4316B11BB8A61B4398894EF5EA
SHA256:574C582884DF06F9730AD7CD80888DBEFE64D685ECF73676C2A34827103AA92E
32081SpywareKillerV21_466026.exeC:\Users\admin\AppData\Local\Temp\~vis0000\uninstal.logtext
MD5:CD6B96EF2FD43D89F3C5711891229B78
SHA256:D43352D308558A6D192FB2BCAE2C10D65B8FBAF84323E9C3E6091661B2965F65
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
8
DNS requests
5
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
unknown
unknown
1372
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
unknown
1372
svchost.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1060
svchost.exe
224.0.0.252:5355
whitelisted
1372
svchost.exe
4.231.128.59:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
1372
svchost.exe
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1372
svchost.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted
1372
svchost.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
1372
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
unknown

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
shared
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
ctldl.windowsupdate.com
  • 93.184.221.240
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted

Threats

No threats detected
No debug info