File name:

pogoskill.exe

Full analysis: https://app.any.run/tasks/5d9fb499-b9af-4e6b-a1a5-ae668e8ad306
Verdict: Malicious activity
Analysis date: March 25, 2024, 16:47:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

E8C033ACC52621503A59FCBFC4D13510

SHA1:

0791607DCC2707A1B22E42626B0AD9FA2128C019

SHA256:

33BFFE84669EE25C54F1347A193CB4AF29BA5D23FDF4C892B91B98183EE8CED0

SSDEEP:

98304:EJZev5NIts7xfXWkQP0TYCUnBGs+FwNfxLxTvMtOXLwIItvS/1zVkmLDprfb5rwC:yJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • pogoskill.exe (PID: 2892)
    • Connects to the CnC server

      • pogoskill.exe (PID: 2892)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • pogoskill.exe (PID: 2892)
    • Reads the Internet Settings

      • pogoskill.exe (PID: 2892)
    • Reads settings of System Certificates

      • pogoskill.exe (PID: 2892)
    • Checks Windows Trust Settings

      • pogoskill.exe (PID: 2892)
    • Checks for external IP

      • pogoskill.exe (PID: 2892)
  • INFO

    • Reads the computer name

      • pogoskill.exe (PID: 2892)
    • Checks supported languages

      • pogoskill.exe (PID: 2892)
    • Checks proxy server information

      • pogoskill.exe (PID: 2892)
    • Create files in a temporary directory

      • pogoskill.exe (PID: 2892)
    • Reads Environment values

      • pogoskill.exe (PID: 2892)
    • Reads the machine GUID from the registry

      • pogoskill.exe (PID: 2892)
    • Creates files or folders in the user directory

      • pogoskill.exe (PID: 2892)
    • Reads the software policy settings

      • pogoskill.exe (PID: 2892)
    • Creates files in the program directory

      • pogoskill.exe (PID: 2892)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (76)
.exe | Win32 Executable (generic) (12.6)
.exe | Generic Win/DOS Executable (5.6)
.exe | DOS Executable Generic (5.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:07:20 06:42:02+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 1818624
InitializedDataSize: 327680
UninitializedDataSize: 2273280
EntryPoint: 0x3e7790
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 2.7.11.0
ProductVersionNumber: 2.7.11.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: PoGoskill Co., Ltd.
FileDescription: PoGoskill
FileVersion: 2.7.11.0
LegalCopyright: Copyright © 2007-2023 PoGoskill Co.,Ltd.
ProductName: 20230720144136
ProductVersion: 2.7.11.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start pogoskill.exe pogoskill.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2892"C:\Users\admin\Downloads\pogoskill.exe" C:\Users\admin\Downloads\pogoskill.exe
explorer.exe
User:
admin
Company:
PoGoskill Co., Ltd.
Integrity Level:
HIGH
Description:
PoGoskill
Version:
2.7.11.0
Modules
Images
c:\users\admin\downloads\pogoskill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
3500"C:\Users\admin\Downloads\pogoskill.exe" C:\Users\admin\Downloads\pogoskill.exeexplorer.exe
User:
admin
Company:
PoGoskill Co., Ltd.
Integrity Level:
MEDIUM
Description:
PoGoskill
Exit code:
3221226540
Version:
2.7.11.0
Modules
Images
c:\users\admin\downloads\pogoskill.exe
c:\windows\system32\ntdll.dll
Total events
6 118
Read events
6 069
Write events
40
Delete events
9

Modification events

(PID) Process:(2892) pogoskill.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Tenorshare\Downloader2.5.0
Operation:writeName:GA_PC
Value:
1
(PID) Process:(2892) pogoskill.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2892) pogoskill.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(2892) pogoskill.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
(PID) Process:(2892) pogoskill.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoConfigURL
Value:
(PID) Process:(2892) pogoskill.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoDetect
Value:
(PID) Process:(2892) pogoskill.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005C010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2892) pogoskill.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2892) pogoskill.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2892) pogoskill.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
Executable files
0
Suspicious files
2
Text files
2
Unknown types
1

Dropped files

PID
Process
Filename
Type
2892pogoskill.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\2K9O13XU.txttext
MD5:DC17C6698D559AD8C89310813A96924B
SHA256:7BD4911C5E9365BF44057269671824885886DABD2C979F5879009E48842A5214
2892pogoskill.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cbinary
MD5:2CE60C0D88D2E3FEBC7A3A4FE6CB92B7
SHA256:BC552E4F1A0B20F0B26405C41B6F96D0FEF680FA27853333197677F7596B7628
2892pogoskill.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\7385IC0P.txttext
MD5:D591A315EBF69C86AC184B49CE470C7C
SHA256:9CAE6264EC2050A9C2E84A72F5C0B0671DECFC90EE917FA687118CCA58E1B6F9
2892pogoskill.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\80237EE4964FC9C409AAF55BF996A292_FB287BEB63DB9E8D59A799779773B97Cder
MD5:DF428E78AE9A465A53035835EBEA8E1F
SHA256:0BB20010AE3FE09E3F23D9806A3F8649B8B9AEA8BE8968E592D1326BD9875AAF
2892pogoskill.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:85A321B55873D59C3E4D7D1D2FABDEFD
SHA256:CDE1F3EF34DEBC5BCEB5D9542E2098B6165922066BBE80A16FABEA17650109D2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
20
TCP/UDP connections
14
DNS requests
7
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2892
pogoskill.exe
GET
301
104.17.192.141:80
http://www.tenorshare.com/downloads/service/softwarelog.txt
unknown
html
245 b
unknown
2892
pogoskill.exe
GET
304
23.216.77.67:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c95f502a893cd837
unknown
unknown
2892
pogoskill.exe
GET
200
208.95.112.1:80
http://ip-api.com/csv
unknown
text
151 b
unknown
2892
pogoskill.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAhflMAthXvozBT%2FU%2B2iPio%3D
unknown
binary
471 b
unknown
2892
pogoskill.exe
POST
200
216.239.38.178:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
2892
pogoskill.exe
POST
200
216.239.38.178:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
2892
pogoskill.exe
POST
200
216.239.38.178:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
2892
pogoskill.exe
POST
200
216.239.38.178:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
2892
pogoskill.exe
POST
200
216.239.38.178:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
2892
pogoskill.exe
POST
200
216.239.38.178:80
http://www.google-analytics.com/collect
unknown
image
35 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
2892
pogoskill.exe
104.17.192.141:80
www.tenorshare.com
CLOUDFLARENET
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2892
pogoskill.exe
104.17.192.141:443
www.tenorshare.com
CLOUDFLARENET
unknown
2892
pogoskill.exe
23.216.77.67:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2892
pogoskill.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2892
pogoskill.exe
208.95.112.1:80
ip-api.com
TUT-AS
US
unknown
2892
pogoskill.exe
216.239.38.178:443
www.google-analytics.com
GOOGLE
US
unknown

DNS requests

Domain
IP
Reputation
www.tenorshare.com
  • 104.17.192.141
  • 104.17.207.155
whitelisted
ctldl.windowsupdate.com
  • 23.216.77.67
  • 23.216.77.54
  • 23.216.77.81
  • 23.216.77.72
  • 23.216.77.62
  • 23.216.77.55
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
ip-api.com
  • 208.95.112.1
shared
www.google-analytics.com
  • 216.239.38.178
  • 216.239.34.178
  • 216.239.32.178
  • 216.239.36.178
whitelisted
update.tenorshare.com
  • 104.18.24.249
  • 104.18.25.249
unknown

Threats

PID
Process
Class
Message
2892
pogoskill.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
2892
pogoskill.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Windows NT Version 5.0
2892
pogoskill.exe
Potential Corporate Privacy Violation
AV POLICY Internal Host Retrieving External IP Address (ip-api. com)
2892
pogoskill.exe
Device Retrieving External IP Address Detected
ET POLICY External IP Lookup ip-api.com
2892
pogoskill.exe
Possibly Unwanted Program Detected
ET ADWARE_PUP Tensorshare Google Analytics Checkin
2 ETPRO signatures available at the full report
No debug info