File name:

Synapse X.exe

Full analysis: https://app.any.run/tasks/8b610dfd-da00-4fcb-863b-5fc090498606
Verdict: Malicious activity
Analysis date: October 08, 2023, 06:42:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

9D7E890FA455DB955AE5A6C06AA3DDF7

SHA1:

57CCE98AA0345CB46BF228DE73BAECB0185696B1

SHA256:

37DDFB13F666CFC4814D75B52F8AAB3A385BC209A98EF0FFAAE77A5B425ED7B0

SSDEEP:

98304:VD7Me2jCudywOAZEAScKusfKv/BBOcotV6AsY+2IoPfL7Vt+BAr614WL2OZ7qJMo:C/2UxN/m

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Synapse X.exe (PID: 3980)
      • SynAntiTumper.exe (PID: 124)
      • SynapseX.exe (PID: 4012)
    • Application was dropped or rewritten from another process

      • SynAntiTumper.exe (PID: 124)
      • Synapse Bootstrapper.exe (PID: 1412)
      • driverperf.exe (PID: 3104)
      • driverperf.exe (PID: 3480)
      • SynapseX.exe (PID: 4012)
    • Loads dropped or rewritten executable

      • Synapse Bootstrapper.exe (PID: 1412)
  • SUSPICIOUS

    • Reads the Internet Settings

      • SynAntiTumper.exe (PID: 124)
      • SynapseX.exe (PID: 4012)
      • wscript.exe (PID: 1988)
    • Executing commands from a ".bat" file

      • wscript.exe (PID: 1988)
    • Starts CMD.EXE for commands execution

      • wscript.exe (PID: 1988)
  • INFO

    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3964)
      • Synapse Bootstrapper.exe (PID: 1412)
    • Creates files or folders in the user directory

      • Synapse X.exe (PID: 3980)
    • Checks supported languages

      • wmpnscfg.exe (PID: 3964)
      • Synapse X.exe (PID: 3980)
      • SynAntiTumper.exe (PID: 124)
      • SynapseX.exe (PID: 4012)
      • Synapse Bootstrapper.exe (PID: 1412)
      • driverperf.exe (PID: 3480)
      • driverperf.exe (PID: 3104)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3964)
      • Synapse X.exe (PID: 3980)
      • SynAntiTumper.exe (PID: 124)
      • SynapseX.exe (PID: 4012)
      • Synapse Bootstrapper.exe (PID: 1412)
      • driverperf.exe (PID: 3104)
      • driverperf.exe (PID: 3480)
    • Create files in a temporary directory

      • SynapseX.exe (PID: 4012)
    • Manual execution by a user

      • explorer.exe (PID: 1120)
      • driverperf.exe (PID: 3480)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:07:02 04:09:48+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27136
InitializedDataSize: 184832
UninitializedDataSize: 2048
EntryPoint: 0x3532
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
10
Malicious processes
6
Suspicious processes
2

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start synapse x.exe no specs synantitumper.exe no specs synapsex.exe no specs wscript.exe no specs synapse bootstrapper.exe no specs cmd.exe no specs driverperf.exe explorer.exe no specs driverperf.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
124C:\Users\admin\AppData\Roaming\SynAntiTumper.exeC:\Users\admin\AppData\Roaming\SynAntiTumper.exeSynapse X.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\synantitumper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1120"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
1412"C:\Users\admin\AppData\Local\Temp\RarSFX0\Synapse Bootstrapper.exe" C:\Users\admin\AppData\Local\Temp\RarSFX0\Synapse Bootstrapper.exeSynapseX.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rarsfx0\synapse bootstrapper.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
c:\windows\system32\rpcrt4.dll
1988"C:\Windows\System32\WScript.exe" "C:\providersessionHost\fZTmQsLEkwl7nRf153UIPUc0N3XmssS8kBJw4hMIlvPVaMwgL.vbe" C:\Windows\System32\wscript.exeSynAntiTumper.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2340C:\Windows\system32\cmd.exe /c ""C:\providersessionHost\V4346E2d2Txcr9cNEWLx9bVjvFECZV6h.bat" "C:\Windows\System32\cmd.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
3221225477
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\imm32.dll
3104"C:\providersessionHost/driverperf.exe"C:\providersessionHost\driverperf.exe
cmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Version:
16.10.31418.88
Modules
Images
c:\providersessionhost\driverperf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3480"C:\providersessionHost\driverperf.exe" C:\providersessionHost\driverperf.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Version:
16.10.31418.88
Modules
Images
c:\providersessionhost\driverperf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3964"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3980"C:\Users\admin\AppData\Local\Temp\Synapse X.exe" C:\Users\admin\AppData\Local\Temp\Synapse X.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\synapse x.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\rpcrt4.dll
4012C:\Users\admin\AppData\Roaming\SynapseX.exeC:\Users\admin\AppData\Roaming\SynapseX.exeSynapse X.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\synapsex.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
1 893
Read events
1 866
Write events
24
Delete events
3

Modification events

(PID) Process:(3964) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{4E36C455-3ADE-42F3-930E-9E6E409B41EE}\{AFD3766B-39CD-4008-82C4-F4159BBBEBD0}
Operation:delete keyName:(default)
Value:
(PID) Process:(3964) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{4E36C455-3ADE-42F3-930E-9E6E409B41EE}
Operation:delete keyName:(default)
Value:
(PID) Process:(3964) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{BE032C21-AD49-413C-B1FC-9D07019A5544}
Operation:delete keyName:(default)
Value:
(PID) Process:(124) SynAntiTumper.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(124) SynAntiTumper.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(124) SynAntiTumper.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(124) SynAntiTumper.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(4012) SynapseX.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4012) SynapseX.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(4012) SynapseX.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
Executable files
5
Suspicious files
1
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
124SynAntiTumper.exeC:\providersessionHost\driverperf.exeexecutable
MD5:3169BB6C966B671685CCE1CDA63B5C21
SHA256:F7D69E825BFADA33F5124D8212A0891E8633B2234E7B94647D1A6FC699C1064F
124SynAntiTumper.exeC:\providersessionHost\fZTmQsLEkwl7nRf153UIPUc0N3XmssS8kBJw4hMIlvPVaMwgL.vbebinary
MD5:90D4CB72B70B71740FAFC9899048393E
SHA256:720570DD783BC4553C4A2571FB18227F306F5183EB688B82C0F24F332DFD3BD9
4012SynapseX.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\Synapse Bootstrapper.exeexecutable
MD5:5B33D097E1A9B8B7A98299237B08DB04
SHA256:7EBD32885C150210E9E94F3D7A668A4235D318071CCF3613D9B1FAAC7CB816CB
124SynAntiTumper.exeC:\providersessionHost\V4346E2d2Txcr9cNEWLx9bVjvFECZV6h.battext
MD5:0B87C85D0D2D412C87C390BC8DE380BA
SHA256:6C624F7616E40DD91FA9B514EDC0D8B324A82397CA3FC4FBA9B81FF4143EC053
3980Synapse X.exeC:\Users\admin\AppData\Roaming\SynAntiTumper.exeexecutable
MD5:F9AC09CE02CA6B42BF3E375D96375E69
SHA256:FB86BA213888892A82C4F54A74480BE1A381C92EEBE8C937922B39CA45DC4C05
3980Synapse X.exeC:\Users\admin\AppData\Roaming\SynapseX.exeexecutable
MD5:825E31D06BB085683FDD248496C4083D
SHA256:0A9783ACE4737BFA6A5D00776059FCAC55EF4E5D880FBD1D6367B6D2E5D04B53
4012SynapseX.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\Newtonsoft.Json.xmlxml
MD5:002B6E4720F86BFA2B6098522CFC7E6E
SHA256:C8CF955C563BDD25645D88130EAE335BC5EEA5E9D5AE71628FB46D7466204847
4012SynapseX.exeC:\Users\admin\AppData\Local\Temp\RarSFX0\Newtonsoft.Json.dllexecutable
MD5:5AFDA7C7D4F7085E744C2E7599279DB3
SHA256:F58C374FFCAAE4E36D740D90FBF7FE70D0ABB7328CD9AF3A0A7B70803E994BA4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2656
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info