File name:

SecuriteInfo.com.Rootkit.Agent.26505.18755

Full analysis: https://app.any.run/tasks/6fc6d281-29b3-4580-85dc-b1164fe320b6
Verdict: Malicious activity
Analysis date: October 24, 2023, 21:40:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

6FEDBBAC978A6B78354B8F6D4FD04CDB

SHA1:

2AF9A0D555F2BD78D47D3796AA0CE2D3B83C471A

SHA256:

3D250DC55EE300F45D2EF0A681F68B9ED6CF1E839314209F35AD0964C9ED3AE7

SSDEEP:

98304:SxEH6UXpEUo7vNQd0Db+MUVsPT1iu3uPjLN942E8hJqMCs7TQMekaeWdmux0eHu5:VPJYHKwTI/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • SecuriteInfo.com.Rootkit.Agent.26505.18755.exe (PID: 1492)
      • SecuriteInfo.com.Rootkit.Agent.26505.18755.exe (PID: 2796)
      • SecuriteInfo.com.Rootkit.Agent.26505.18755.tmp (PID: 2660)
    • Loads dropped or rewritten executable

      • SecuriteInfo.com.Rootkit.Agent.26505.18755.tmp (PID: 2660)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • SecuriteInfo.com.Rootkit.Agent.26505.18755.tmp (PID: 2660)
    • Reads the Windows owner or organization settings

      • SecuriteInfo.com.Rootkit.Agent.26505.18755.tmp (PID: 2660)
  • INFO

    • Create files in a temporary directory

      • SecuriteInfo.com.Rootkit.Agent.26505.18755.exe (PID: 1492)
      • SecuriteInfo.com.Rootkit.Agent.26505.18755.exe (PID: 2796)
      • SecuriteInfo.com.Rootkit.Agent.26505.18755.tmp (PID: 2660)
    • Checks supported languages

      • SecuriteInfo.com.Rootkit.Agent.26505.18755.exe (PID: 1492)
      • SecuriteInfo.com.Rootkit.Agent.26505.18755.tmp (PID: 2036)
      • SecuriteInfo.com.Rootkit.Agent.26505.18755.exe (PID: 2796)
      • SecuriteInfo.com.Rootkit.Agent.26505.18755.tmp (PID: 2660)
    • Reads the computer name

      • SecuriteInfo.com.Rootkit.Agent.26505.18755.tmp (PID: 2036)
      • SecuriteInfo.com.Rootkit.Agent.26505.18755.tmp (PID: 2660)
    • Application was dropped or rewritten from another process

      • SecuriteInfo.com.Rootkit.Agent.26505.18755.tmp (PID: 2036)
      • SecuriteInfo.com.Rootkit.Agent.26505.18755.tmp (PID: 2660)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:20 00:22:17+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 37888
InitializedDataSize: 17408
UninitializedDataSize: -
EntryPoint: 0x9b24
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 5.0.21.160
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: 深圳市驱动人生软件技术有限公司
FileDescription:
FileVersion: 5.0.21.160
LegalCopyright:
ProductName:
ProductVersion: 5.0.21.160
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
4
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start securiteinfo.com.rootkit.agent.26505.18755.exe no specs securiteinfo.com.rootkit.agent.26505.18755.tmp no specs securiteinfo.com.rootkit.agent.26505.18755.exe securiteinfo.com.rootkit.agent.26505.18755.tmp no specs

Process information

PID
CMD
Path
Indicators
Parent process
1492"C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.Rootkit.Agent.26505.18755.exe" C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.Rootkit.Agent.26505.18755.exeexplorer.exe
User:
admin
Company:
深圳市驱动人生软件技术有限公司
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
5.0.21.160
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\appdata\local\temp\securiteinfo.com.rootkit.agent.26505.18755.exe
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\wow64.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\imm32.dll
c:\windows\syswow64\ntdll.dll
2036"C:\Users\admin\AppData\Local\Temp\is-AL3IM.tmp\SecuriteInfo.com.Rootkit.Agent.26505.18755.tmp" /SL5="$70136,8668708,53760,C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.Rootkit.Agent.26505.18755.exe" C:\Users\admin\AppData\Local\Temp\is-AL3IM.tmp\SecuriteInfo.com.Rootkit.Agent.26505.18755.tmpSecuriteInfo.com.Rootkit.Agent.26505.18755.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.49.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-al3im.tmp\securiteinfo.com.rootkit.agent.26505.18755.tmp
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernelbase.dll
2660"C:\Users\admin\AppData\Local\Temp\is-2FCGO.tmp\SecuriteInfo.com.Rootkit.Agent.26505.18755.tmp" /SL5="$F0170,8668708,53760,C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.Rootkit.Agent.26505.18755.exe" /SPAWNWND=$140032 /NOTIFYWND=$70136 C:\Users\admin\AppData\Local\Temp\is-2FCGO.tmp\SecuriteInfo.com.Rootkit.Agent.26505.18755.tmpSecuriteInfo.com.Rootkit.Agent.26505.18755.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.49.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-2fcgo.tmp\securiteinfo.com.rootkit.agent.26505.18755.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2796"C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.Rootkit.Agent.26505.18755.exe" /SPAWNWND=$140032 /NOTIFYWND=$70136 C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.Rootkit.Agent.26505.18755.exe
SecuriteInfo.com.Rootkit.Agent.26505.18755.tmp
User:
admin
Company:
深圳市驱动人生软件技术有限公司
Integrity Level:
HIGH
Description:
Exit code:
0
Version:
5.0.21.160
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\syswow64\ntdll.dll
c:\users\admin\appdata\local\temp\securiteinfo.com.rootkit.agent.26505.18755.exe
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\wow64win.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\system32\user32.dll
Total events
1 507
Read events
1 507
Write events
0
Delete events
0

Modification events

No data
Executable files
6
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1492SecuriteInfo.com.Rootkit.Agent.26505.18755.exeC:\Users\admin\AppData\Local\Temp\is-AL3IM.tmp\SecuriteInfo.com.Rootkit.Agent.26505.18755.tmpexecutable
MD5:33D1644041AEE1AD603D0E6BD303834F
SHA256:DC9E9B54B76DBC82451D39E6777E3FB8EE5804559BA90303038149BCA26FBC10
2796SecuriteInfo.com.Rootkit.Agent.26505.18755.exeC:\Users\admin\AppData\Local\Temp\is-2FCGO.tmp\SecuriteInfo.com.Rootkit.Agent.26505.18755.tmpexecutable
MD5:33D1644041AEE1AD603D0E6BD303834F
SHA256:DC9E9B54B76DBC82451D39E6777E3FB8EE5804559BA90303038149BCA26FBC10
2660SecuriteInfo.com.Rootkit.Agent.26505.18755.tmpC:\Users\admin\AppData\Local\Temp\is-000O4.tmp\_isetup\_setup64.tmpexecutable
MD5:D8C5AEEEDFC872DB71E67498DA13DEA7
SHA256:1557AB40277D95E738888002611CB06B109BCA6670B9A05910FB8287BF7395FC
2660SecuriteInfo.com.Rootkit.Agent.26505.18755.tmpC:\Users\admin\AppData\Local\Temp\is-000O4.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
2660SecuriteInfo.com.Rootkit.Agent.26505.18755.tmpC:\Users\admin\AppData\Local\Temp\is-000O4.tmp\uninstall.dllexecutable
MD5:A37718000A433D75881FCD23A8E83764
SHA256:F4DDBD561918075FF9C83A28026BF125B17ACFFC710321FDB38FA8793D5157EA
2660SecuriteInfo.com.Rootkit.Agent.26505.18755.tmpC:\Users\admin\AppData\Local\Temp\is-000O4.tmp\_isetup\_RegDLL.tmpexecutable
MD5:C594B792B9C556EA62A30DE541D2FB03
SHA256:5DCC1E0A197922907BCA2C4369F778BD07EE4B1BBBDF633E987A028A314D548E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
239.255.255.250:1900
unknown
324
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info