File name:

SpyShredder.exe

Full analysis: https://app.any.run/tasks/ac0712a0-9bd0-4007-81b7-6490ba9a4987
Verdict: Malicious activity
Analysis date: December 11, 2023, 23:28:23
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

9DCE64F7C661E2F81E055C786C69B0E0

SHA1:

297EB2021906A8EC5B6A915C9F97D0D098F23518

SHA256:

39B36F847D3E6327550EFBAF013074EF547D15D20DBEB28BEDC969050E5A0BC0

SSDEEP:

12288:82A/IvLIrWfGFnqVkpjHqFBhYj/9DBhYj/nOT7E5CQV1gJ7+p7xx:82A/IvLvGhqVkpjKZOT7E5CQV1gJw7xx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Scans artifacts that could help determine the target

      • SpyShredder.exe (PID: 3264)
  • SUSPICIOUS

    • Checks for Java to be installed

      • SpyShredder.exe (PID: 3264)
    • Reads security settings of Internet Explorer

      • SpyShredder.exe (PID: 3264)
    • Reads settings of System Certificates

      • SpyShredder.exe (PID: 3264)
    • Reads Internet Explorer settings

      • SpyShredder.exe (PID: 3264)
    • Reads the Internet Settings

      • SpyShredder.exe (PID: 3264)
    • Check the default browser

      • SpyShredder.exe (PID: 3264)
    • Reads the history of recent RDP connections

      • SpyShredder.exe (PID: 3264)
    • Reads Microsoft Outlook installation path

      • SpyShredder.exe (PID: 3264)
    • Checks Windows Trust Settings

      • SpyShredder.exe (PID: 3264)
    • Checks for the .NET to be installed

      • SpyShredder.exe (PID: 3264)
    • Accesses Microsoft Outlook profiles

      • SpyShredder.exe (PID: 3264)
  • INFO

    • Reads the computer name

      • SpyShredder.exe (PID: 3264)
      • wmpnscfg.exe (PID: 1328)
      • wmpnscfg.exe (PID: 3080)
    • Checks supported languages

      • SpyShredder.exe (PID: 3264)
      • wmpnscfg.exe (PID: 1328)
      • SpyShredder.exe (PID: 2764)
      • wmpnscfg.exe (PID: 3080)
      • SpyShredder.exe (PID: 880)
    • Reads mouse settings

      • SpyShredder.exe (PID: 3264)
    • Process checks computer location settings

      • SpyShredder.exe (PID: 3264)
    • Process checks Internet Explorer phishing filters

      • SpyShredder.exe (PID: 3264)
    • Reads Microsoft Office registry keys

      • SpyShredder.exe (PID: 3264)
    • Checks proxy server information

      • SpyShredder.exe (PID: 3264)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1328)
      • wmpnscfg.exe (PID: 3080)
      • SpyShredder.exe (PID: 880)
      • SpyShredder.exe (PID: 2764)
    • Checks transactions between databases Windows and Oracle

      • SpyShredder.exe (PID: 3264)
    • Reads the machine GUID from the registry

      • SpyShredder.exe (PID: 3264)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2007:07:04 12:23:21+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 697856
InitializedDataSize: 806400
UninitializedDataSize: -
EntryPoint: 0x1000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start spyshredder.exe wmpnscfg.exe no specs spyshredder.exe wmpnscfg.exe no specs spyshredder.exe

Process information

PID
CMD
Path
Indicators
Parent process
880"C:\Users\admin\Desktop\SpyShredder.exe" C:\Users\admin\Desktop\SpyShredder.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\spyshredder.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1328"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2764"C:\Users\admin\Desktop\SpyShredder.exe" C:\Users\admin\Desktop\SpyShredder.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\spyshredder.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3080"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3264"C:\Users\admin\Desktop\SpyShredder.exe" C:\Users\admin\Desktop\SpyShredder.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
259
Modules
Images
c:\users\admin\desktop\spyshredder.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
Total events
163 002
Read events
162 997
Write events
5
Delete events
0

Modification events

(PID) Process:(3264) SpyShredder.exeKey:HKEY_CURRENT_USER\Software\SpyShredder
Operation:writeName:PreviousMark
Value:
2
(PID) Process:(880) SpyShredder.exeKey:HKEY_CURRENT_USER\Software\SpyShredder
Operation:writeName:Previous
Value:
A01EA2C1892CDA01
(PID) Process:(880) SpyShredder.exeKey:HKEY_CURRENT_USER\Software\SpyShredder
Operation:writeName:PreviousMark
Value:
2
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
868
svchost.exe
23.35.228.137:80
AKAMAI-AS
DE
unknown
3264
SpyShredder.exe
69.50.175.181:80
SOHOSKYWAY1
CA
unknown
4
System
192.168.100.255:138
whitelisted
868
svchost.exe
23.211.8.250:80
armmf.adobe.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
armmf.adobe.com
  • 23.211.8.250
whitelisted

Threats

No threats detected
No debug info