File name:

MailAccess Checker by xRisky CRACKED VERSION.exe

Full analysis: https://app.any.run/tasks/d212dc50-bcc1-4153-b63d-80f2bea922b6
Verdict: Malicious activity
Threats:

RedLine Stealer is a malicious program that collects users’ confidential data from browsers, systems, and installed software. It also infects operating systems with other malware.

Analysis date: April 16, 2024, 13:13:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
redline
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows
MD5:

F97C16BFEE0937814AE3C4675B4E0306

SHA1:

B07505448AF68AEA8BA8A928857BDA36F39C6408

SHA256:

39A35C9C8BFC9062B5DD09AE5ACC3E79CED530ECF94961AB2511F19E1BA48020

SSDEEP:

98304:t+94ja6ldp2U2BdHU0aZbYxZzQlX3VoJcFkdG6DeoyCwPE1nwQOHEFvsONSJvGJr:ccF5ha

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • MailAccess Checker by xRisky CRACKED VERSION.exe (PID: 1020)
    • REDLINE has been detected (YARA)

      • AppLaunch.exe (PID: 3260)
  • SUSPICIOUS

    • Connects to unusual port

      • AppLaunch.exe (PID: 3260)
  • INFO

    • Checks supported languages

      • AppLaunch.exe (PID: 3260)
      • MailAccess Checker by xRisky CRACKED VERSION.exe (PID: 1020)
    • Reads the computer name

      • AppLaunch.exe (PID: 3260)
    • Reads the machine GUID from the registry

      • AppLaunch.exe (PID: 3260)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report

RedLine

(PID) Process(3260) AppLaunch.exe
C2 (1)2.56.56.112:45710
Botnet@A7_acc
Options
ErrorMessage
Keys
XorGentians
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (38.3)
.exe | Win32 Executable (generic) (26.2)
.exe | Win16/32 Executable Delphi generic (12)
.exe | Generic Win/DOS Executable (11.6)
.exe | DOS Executable Generic (11.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:02:25 13:22:50+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 240640
InitializedDataSize: 185856
UninitializedDataSize: -
EntryPoint: 0x1f2000
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start mailaccess checker by xrisky cracked version.exe no specs #REDLINE applaunch.exe

Process information

PID
CMD
Path
Indicators
Parent process
1020"C:\Users\admin\AppData\Local\Temp\MailAccess Checker by xRisky CRACKED VERSION.exe" C:\Users\admin\AppData\Local\Temp\MailAccess Checker by xRisky CRACKED VERSION.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\mailaccess checker by xrisky cracked version.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3260"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe"C:\Windows\Microsoft.NET\Framework\v4.0.30319\AppLaunch.exe
MailAccess Checker by xRisky CRACKED VERSION.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft .NET ClickOnce Launch Utility
Version:
4.8.3761.0 built by: NET48REL1
Modules
Images
c:\windows\microsoft.net\framework\v4.0.30319\applaunch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\aclayers.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
RedLine
(PID) Process(3260) AppLaunch.exe
C2 (1)2.56.56.112:45710
Botnet@A7_acc
Options
ErrorMessage
Keys
XorGentians
Total events
658
Read events
658
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
7
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
3260
AppLaunch.exe
2.56.56.112:45710
AS-SERVERION
NL
unknown
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

Domain
IP
Reputation
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info