File name:

3cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin

Full analysis: https://app.any.run/tasks/03047739-6359-4d65-98f1-3974f8984f43
Verdict: Malicious activity
Analysis date: June 02, 2025, 16:26:10
OS: Windows 10 Professional (build: 19044, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 7 sections
MD5:

B6551605761F979D5382AF0DD2D0BD9F

SHA1:

0B4C7C5E625E1378ACF61FEB1B70601147BF9653

SHA256:

3CB7F8C2D8C2DA97CD7753643E200FA4AA1A17C800B651CBA8895FA3191DBACA

SSDEEP:

98304:8dA8q2Zj/3NYiSoVVJKb/I3XLohBNvJrNffyK9yeo1xVzBPL5sHqPYbPDcE1z690:22oMVQi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Starts NET.EXE for service management

      • Extramagic Settings Process.exe (PID: 8172)
      • net.exe (PID: 7348)
    • Executing a file with an untrusted certificate

      • do_not_run.exe (PID: 1764)
    • Changes the autorun value in the registry

      • Extramagic Settings Process.exe (PID: 8172)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 3cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exe (PID: 2600)
      • do_not_run.exe (PID: 1764)
      • drvinst.exe (PID: 4040)
    • Process drops legitimate windows executable

      • 3cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exe (PID: 2600)
      • drvinst.exe (PID: 4040)
      • do_not_run.exe (PID: 1764)
    • Creates a software uninstall entry

      • 3cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exe (PID: 2600)
    • There is functionality for taking screenshot (YARA)

      • 3cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exe (PID: 2600)
    • Searches for installed software

      • 3cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exe (PID: 2600)
    • Reads the date of Windows installation

      • TPP_VERSION_CHOOSER.exe (PID: 4988)
      • Extramagic Installer.exe (PID: 8072)
      • Extramagic Settings Initializer.exe (PID: 7288)
      • Extramagic Settings Process.exe (PID: 8172)
    • Reads security settings of Internet Explorer

      • TPP_VERSION_CHOOSER.exe (PID: 4988)
      • Extramagic Installer.exe (PID: 8072)
      • Extramagic Settings.exe (PID: 672)
      • Extramagic Settings Process.exe (PID: 8172)
      • Extramagic Settings Initializer.exe (PID: 7288)
      • do_not_run.exe (PID: 1764)
    • Creates files in the driver directory

      • drvinst.exe (PID: 4040)
      • postinstall1.exe (PID: 7204)
    • Executing commands from a ".bat" file

      • Extramagic Settings Process.exe (PID: 8172)
    • Starts CMD.EXE for commands execution

      • Extramagic Settings Process.exe (PID: 8172)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 7700)
    • The system shut down or reboot

      • cmd.exe (PID: 7700)
  • INFO

    • Creates files in the program directory

      • 3cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exe (PID: 2600)
    • Create files in a temporary directory

      • 3cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exe (PID: 2600)
      • do_not_run.exe (PID: 1764)
    • The sample compiled with arabic language support

      • 3cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exe (PID: 2600)
    • Creates files or folders in the user directory

      • 3cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exe (PID: 2600)
    • Reads the computer name

      • TPP_VERSION_CHOOSER.exe (PID: 4988)
      • Extramagic Installer.exe (PID: 8072)
      • Extramagic Settings.exe (PID: 672)
      • Extramagic Settings Process.exe (PID: 8172)
      • Extramagic Settings Initializer.exe (PID: 7288)
      • Post_Install.exe (PID: 5408)
      • do_not_run.exe (PID: 1764)
      • postinstall1.exe (PID: 7204)
    • Checks supported languages

      • TPP_VERSION_CHOOSER.exe (PID: 4988)
      • Extramagic Installer.exe (PID: 8072)
      • Extramagic Settings Initializer.exe (PID: 7288)
      • Extramagic Settings.exe (PID: 672)
      • Extramagic Settings Process.exe (PID: 8172)
      • Post_Install.exe (PID: 5408)
      • do_not_run.exe (PID: 1764)
      • drvinst.exe (PID: 4040)
      • postinstall1.exe (PID: 7204)
    • Process checks computer location settings

      • TPP_VERSION_CHOOSER.exe (PID: 4988)
      • Extramagic Installer.exe (PID: 8072)
      • Extramagic Settings Process.exe (PID: 8172)
      • Extramagic Settings.exe (PID: 672)
      • Extramagic Settings Initializer.exe (PID: 7288)
    • Reads the machine GUID from the registry

      • Extramagic Settings Process.exe (PID: 8172)
      • drvinst.exe (PID: 4040)
      • do_not_run.exe (PID: 1764)
    • Reads mouse settings

      • Extramagic Settings Process.exe (PID: 8172)
    • Reads the software policy settings

      • do_not_run.exe (PID: 1764)
      • drvinst.exe (PID: 4040)
    • Launch of the file from Registry key

      • Extramagic Settings Process.exe (PID: 8172)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.1)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2008:02:17 06:10:17+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 3
CodeSize: 3584
InitializedDataSize: 412160
UninitializedDataSize: -
EntryPoint: 0x10b9
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
151
Monitored processes
22
Malicious processes
6
Suspicious processes
1

Behavior graph

Click at the process to see the details
start 3cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exe sppextcomobj.exe no specs tpp_version_chooser.exe no specs extramagic installer.exe no specs extramagic settings.exe no specs extramagic settings initializer.exe no specs extramagic settings process.exe net.exe no specs conhost.exe no specs bcdedit.exe no specs conhost.exe no specs net1.exe no specs cmd.exe no specs conhost.exe no specs post_install.exe no specs do_not_run.exe drvinst.exe timeout.exe no specs postinstall1.exe no specs timeout.exe no specs shutdown.exe no specs 3cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
672"C:\Program Files\Extramagic_64bit\Extramagic Settings.exe" --firstlaunchC:\Program Files\Extramagic_64bit\Extramagic Settings.exeExtramagic Installer.exe
User:
admin
Integrity Level:
HIGH
Description:
Extramagic Settings
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\program files\extramagic_64bit\extramagic settings.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
1764do_not_run /F /SW /SEC:\Program Files\Extramagic_64bit\wmt1\do_not_run.exe
cmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Driver Package Installer
Exit code:
2147549184
Version:
2.1
Modules
Images
c:\program files\extramagic_64bit\wmt1\do_not_run.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
2600"C:\Users\admin\AppData\Local\Temp\3cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exe" C:\Users\admin\AppData\Local\Temp\3cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\windows\syswow64\linkinfo.dll
c:\windows\syswow64\ntshrui.dll
c:\windows\syswow64\sspicli.dll
c:\windows\syswow64\srvcli.dll
c:\windows\syswow64\cscapi.dll
c:\windows\syswow64\netutils.dll
3300"C:\Users\admin\AppData\Local\Temp\3cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exe" C:\Users\admin\AppData\Local\Temp\3cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\3cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4040DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{670dc2c3-27cb-1241-b100-b9149906553f}\extramagic_x64.inf" "9" "46c6ed32f" "00000000000001CC" "WinSta0\Default" "00000000000001DC" "208" "c:\program files\extramagic_64bit\wmt1"C:\Windows\System32\drvinst.exe
svchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Driver Installation Module
Exit code:
3758096971
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\drvinst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\ntmarta.dll
c:\windows\system32\devrtl.dll
c:\windows\system32\drvstore.dll
4988"C:\Program Files\Extramagic_64bit\TPP_VERSION_CHOOSER.exe" --firstlaunchC:\Program Files\Extramagic_64bit\TPP_VERSION_CHOOSER.exe3cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exe
User:
admin
Integrity Level:
HIGH
Description:
TPP_VERSION_CHOOSER_GRAPHICAL
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\program files\extramagic_64bit\tpp_version_chooser.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
5408"C:\Program Files\Extramagic_64bit\post_install.exe" C:\Program Files\Extramagic_64bit\Post_Install.exeExtramagic Settings Process.exe
User:
admin
Company:
Microsoft
Integrity Level:
HIGH
Description:
Post_Install
Version:
1.0.0.0
Modules
Images
c:\program files\extramagic_64bit\post_install.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\mscoree.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
5588C:\WINDOWS\system32\SppExtComObj.exe -EmbeddingC:\Windows\System32\SppExtComObj.Exesvchost.exe
User:
NETWORK SERVICE
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
KMS Connection Broker
Version:
10.0.19041.3996 (WinBuild.160101.0800)
6060shutdown -r -f -t 0C:\Windows\System32\shutdown.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Shutdown and Annotation Tool
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\shutdown.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6208C:\WINDOWS\system32\net1 stop "Program Compatibility Assistant Service"C:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\samcli.dll
c:\windows\system32\ucrtbase.dll
Total events
8 874
Read events
8 812
Write events
62
Delete events
0

Modification events

(PID) Process:(2600) 3cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ExtraMagic
Operation:writeName:UninstallString
Value:
C:\Program Files\Extramagic_64bit\uninstall.exe
(PID) Process:(2600) 3cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ExtraMagic
Operation:writeName:DisplayName
Value:
ExtraMagic
(PID) Process:(2600) 3cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\ExtraMagic
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Extramagic_64bit\uninstall.exe
(PID) Process:(4988) TPP_VERSION_CHOOSER.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Extramagic_64bit
Operation:writeName:MT2
Value:
FALSE
(PID) Process:(8072) Extramagic Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Extramagic_64bit
Operation:writeName:HW
Value:
NOR
(PID) Process:(8072) Extramagic Installer.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Extramagic_64bit
Operation:writeName:BUILD
Value:
24b
(PID) Process:(8100) bcdedit.exeKey:HKEY_LOCAL_MACHINE\BCD00000000\Objects\{7bcdbaa8-85a9-11eb-90a8-9a9b76358421}\Elements\16000049
Operation:writeName:Element
Value:
01
(PID) Process:(8172) Extramagic Settings Process.exeKey:HKEY_CURRENT_USER\Control Panel\Desktop
Operation:writeName:WheelScrollLines
Value:
1
(PID) Process:(8172) Extramagic Settings Process.exeKey:HKEY_CURRENT_USER\Control Panel\Desktop
Operation:writeName:WheelScrollChars
Value:
1
(PID) Process:(8172) Extramagic Settings Process.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Extramagic_64bit
Operation:writeName:Configuration
Value:
1 5 0 0 2 2
Executable files
13
Suspicious files
5
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
26003cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exeC:\Users\admin\AppData\Local\Temp\gentee00\setup_temp.gea
MD5:
SHA256:
26003cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exeC:\Users\admin\AppData\Local\Temp\gentee00\125e9299a788a4c9e800045317b44234c.bmp
MD5:
SHA256:
26003cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exeC:\Program Files\Extramagic_64bit\uninstall.ini
MD5:
SHA256:
26003cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exeC:\Program Files\Extramagic_64bit\3D
MD5:
SHA256:
26003cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exeC:\Program Files\Extramagic_64bit\3L
MD5:
SHA256:
26003cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exeC:\Program Files\Extramagic_64bit\3R
MD5:
SHA256:
26003cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exeC:\Program Files\Extramagic_64bit\3T
MD5:
SHA256:
26003cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exeC:\Program Files\Extramagic_64bit\3U
MD5:
SHA256:
26003cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exeC:\Program Files\Extramagic_64bit\4D
MD5:
SHA256:
26003cb7f8c2d8c2da97cd7753643e200fa4aa1a17c800b651cba8895fa3191dbaca.bin.exeC:\Program Files\Extramagic_64bit\4L
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
10
DNS requests
7
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5496
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7600
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
7600
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2112
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 40.127.240.158
whitelisted
google.com
  • 142.250.74.206
whitelisted
self.events.data.microsoft.com
  • 20.189.173.2
whitelisted

Threats

No threats detected
No debug info