File name:

4108277feb47e70ea76dea706b8a8e7ed1dc94575c1ed200e78073b4d97185a2

Full analysis: https://app.any.run/tasks/17262a0a-b636-429b-812e-d52fe2684648
Verdict: Malicious activity
Analysis date: January 10, 2025, 18:26:11
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, 3 sections
MD5:

AC26BAF5B7B03AA4046B2C2413A4C2C2

SHA1:

4CC0593D71B377A7B5FFC9FA578DCB8DD374F4EA

SHA256:

4108277FEB47E70EA76DEA706B8A8E7ED1DC94575C1ED200E78073B4D97185A2

SSDEEP:

24576:NHlMd5NJ7WRR/ezNwvsMDOSAeRoCqEydSFpVIJ0+v1gQjT7wel+TYuZ5gTtIoNcs:xlMd5NJ7WRR/eksMDOSAeRoCqEydSFp0

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Create files in the Startup directory

      • lecheries.exe (PID: 6716)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 4108277feb47e70ea76dea706b8a8e7ed1dc94575c1ed200e78073b4d97185a2.exe (PID: 6684)
    • Starts itself from another location

      • 4108277feb47e70ea76dea706b8a8e7ed1dc94575c1ed200e78073b4d97185a2.exe (PID: 6684)
    • Application launched itself

      • lecheries.exe (PID: 6716)
      • lecheries.exe (PID: 6740)
      • lecheries.exe (PID: 6764)
      • lecheries.exe (PID: 6788)
      • lecheries.exe (PID: 6812)
      • lecheries.exe (PID: 6844)
      • lecheries.exe (PID: 6868)
      • lecheries.exe (PID: 6892)
      • lecheries.exe (PID: 6916)
      • lecheries.exe (PID: 6940)
      • lecheries.exe (PID: 6964)
      • lecheries.exe (PID: 7012)
      • lecheries.exe (PID: 6988)
      • lecheries.exe (PID: 7060)
      • lecheries.exe (PID: 7036)
      • lecheries.exe (PID: 7084)
      • lecheries.exe (PID: 7108)
      • lecheries.exe (PID: 7164)
      • lecheries.exe (PID: 7140)
      • lecheries.exe (PID: 6096)
      • lecheries.exe (PID: 3612)
      • lecheries.exe (PID: 2324)
      • lecheries.exe (PID: 6056)
      • lecheries.exe (PID: 5696)
      • lecheries.exe (PID: 4992)
      • lecheries.exe (PID: 4876)
      • lecheries.exe (PID: 4724)
      • lecheries.exe (PID: 4244)
      • lecheries.exe (PID: 2212)
      • lecheries.exe (PID: 1144)
      • lecheries.exe (PID: 5472)
      • lecheries.exe (PID: 5000)
      • lecheries.exe (PID: 6556)
      • lecheries.exe (PID: 4672)
      • lecheries.exe (PID: 3508)
      • lecheries.exe (PID: 6348)
      • lecheries.exe (PID: 6380)
      • lecheries.exe (PID: 6384)
      • lecheries.exe (PID: 6324)
      • lecheries.exe (PID: 6592)
      • lecheries.exe (PID: 372)
      • lecheries.exe (PID: 6068)
      • lecheries.exe (PID: 6756)
      • lecheries.exe (PID: 6796)
      • lecheries.exe (PID: 2996)
      • lecheries.exe (PID: 6676)
      • lecheries.exe (PID: 6832)
      • lecheries.exe (PID: 6856)
      • lecheries.exe (PID: 6912)
      • lecheries.exe (PID: 6928)
      • lecheries.exe (PID: 7000)
      • lecheries.exe (PID: 6984)
      • lecheries.exe (PID: 7072)
      • lecheries.exe (PID: 7056)
      • lecheries.exe (PID: 5200)
      • lecheries.exe (PID: 6312)
      • lecheries.exe (PID: 2744)
      • lecheries.exe (PID: 7148)
      • lecheries.exe (PID: 1520)
      • lecheries.exe (PID: 2844)
      • lecheries.exe (PID: 3552)
      • lecheries.exe (PID: 3992)
      • lecheries.exe (PID: 1488)
      • lecheries.exe (PID: 3092)
      • lecheries.exe (PID: 3876)
      • lecheries.exe (PID: 5864)
      • lecheries.exe (PID: 1296)
      • lecheries.exe (PID: 5192)
      • lecheries.exe (PID: 5308)
      • lecheries.exe (PID: 5892)
      • lecheries.exe (PID: 6600)
      • lecheries.exe (PID: 6004)
      • lecheries.exe (PID: 2776)
      • lecheries.exe (PID: 6636)
      • lecheries.exe (PID: 4872)
      • lecheries.exe (PID: 3628)
      • lecheries.exe (PID: 648)
      • lecheries.exe (PID: 6640)
      • lecheries.exe (PID: 6368)
      • lecheries.exe (PID: 5652)
      • lecheries.exe (PID: 6432)
      • lecheries.exe (PID: 5236)
      • lecheries.exe (PID: 3884)
      • lecheries.exe (PID: 1796)
      • lecheries.exe (PID: 6712)
      • lecheries.exe (PID: 6748)
      • lecheries.exe (PID: 6804)
      • lecheries.exe (PID: 6840)
      • lecheries.exe (PID: 5452)
      • lecheries.exe (PID: 6880)
      • lecheries.exe (PID: 6960)
      • lecheries.exe (PID: 7008)
      • lecheries.exe (PID: 7076)
      • lecheries.exe (PID: 7116)
      • lecheries.exe (PID: 7132)
      • lecheries.exe (PID: 4804)
      • lecheries.exe (PID: 5112)
      • lecheries.exe (PID: 5968)
      • lecheries.exe (PID: 2928)
      • lecheries.exe (PID: 2380)
      • lecheries.exe (PID: 1868)
      • lecheries.exe (PID: 5604)
      • lecheries.exe (PID: 4648)
      • lecheries.exe (PID: 4668)
      • lecheries.exe (PID: 5836)
      • lecheries.exe (PID: 3040)
      • lecheries.exe (PID: 1944)
      • lecheries.exe (PID: 4144)
      • lecheries.exe (PID: 1704)
      • lecheries.exe (PID: 968)
      • lecheries.exe (PID: 4764)
      • lecheries.exe (PID: 640)
      • lecheries.exe (PID: 6604)
      • lecheries.exe (PID: 2680)
      • lecheries.exe (PID: 3524)
      • lecheries.exe (PID: 6360)
      • lecheries.exe (PID: 1556)
      • lecheries.exe (PID: 1576)
      • lecheries.exe (PID: 3920)
      • lecheries.exe (PID: 2132)
      • lecheries.exe (PID: 6544)
      • lecheries.exe (PID: 6452)
      • lecheries.exe (PID: 4012)
      • lecheries.exe (PID: 2736)
      • lecheries.exe (PID: 6532)
      • lecheries.exe (PID: 488)
      • lecheries.exe (PID: 4392)
      • lecheries.exe (PID: 2008)
      • lecheries.exe (PID: 6864)
      • lecheries.exe (PID: 6772)
      • lecheries.exe (PID: 6936)
      • lecheries.exe (PID: 7032)
      • lecheries.exe (PID: 5992)
      • lecheries.exe (PID: 3560)
      • lecheries.exe (PID: 7128)
      • lecheries.exe (PID: 6180)
      • lecheries.exe (PID: 4996)
      • lecheries.exe (PID: 6260)
      • lecheries.exe (PID: 2012)
      • lecheries.exe (PID: 6284)
      • lecheries.exe (PID: 6160)
      • lecheries.exe (PID: 3544)
      • lecheries.exe (PID: 6176)
      • lecheries.exe (PID: 2088)
      • lecheries.exe (PID: 1076)
      • lecheries.exe (PID: 5712)
      • lecheries.exe (PID: 880)
      • lecheries.exe (PID: 1688)
      • lecheries.exe (PID: 3824)
      • lecheries.exe (PID: 5788)
      • lecheries.exe (PID: 5740)
      • lecheries.exe (PID: 5556)
      • lecheries.exe (PID: 5916)
      • lecheries.exe (PID: 6204)
      • lecheries.exe (PID: 6184)
      • lecheries.exe (PID: 6076)
      • lecheries.exe (PID: 3792)
      • lecheries.exe (PID: 3076)
      • lecheries.exe (PID: 3632)
      • lecheries.exe (PID: 6612)
      • lecheries.exe (PID: 2904)
      • lecheries.exe (PID: 6372)
      • lecheries.exe (PID: 6548)
      • lecheries.exe (PID: 5456)
      • lecheries.exe (PID: 1580)
      • lecheries.exe (PID: 2292)
      • lecheries.exe (PID: 6780)
      • lecheries.exe (PID: 6952)
      • lecheries.exe (PID: 6824)
      • lecheries.exe (PID: 7068)
  • INFO

    • Reads mouse settings

      • 4108277feb47e70ea76dea706b8a8e7ed1dc94575c1ed200e78073b4d97185a2.exe (PID: 6684)
      • lecheries.exe (PID: 6716)
      • lecheries.exe (PID: 6740)
      • lecheries.exe (PID: 6788)
      • lecheries.exe (PID: 6764)
      • lecheries.exe (PID: 6812)
      • lecheries.exe (PID: 6844)
      • lecheries.exe (PID: 6892)
      • lecheries.exe (PID: 6868)
      • lecheries.exe (PID: 6964)
      • lecheries.exe (PID: 6916)
      • lecheries.exe (PID: 6940)
      • lecheries.exe (PID: 7012)
      • lecheries.exe (PID: 6988)
      • lecheries.exe (PID: 7036)
      • lecheries.exe (PID: 7060)
      • lecheries.exe (PID: 7084)
      • lecheries.exe (PID: 7140)
      • lecheries.exe (PID: 7108)
      • lecheries.exe (PID: 3612)
      • lecheries.exe (PID: 7164)
      • lecheries.exe (PID: 6096)
      • lecheries.exe (PID: 6056)
      • lecheries.exe (PID: 2324)
      • lecheries.exe (PID: 4992)
      • lecheries.exe (PID: 4876)
      • lecheries.exe (PID: 5696)
      • lecheries.exe (PID: 4244)
      • lecheries.exe (PID: 2212)
      • lecheries.exe (PID: 1144)
      • lecheries.exe (PID: 4724)
      • lecheries.exe (PID: 5000)
      • lecheries.exe (PID: 5472)
      • lecheries.exe (PID: 4672)
      • lecheries.exe (PID: 3508)
      • lecheries.exe (PID: 6556)
      • lecheries.exe (PID: 6348)
      • lecheries.exe (PID: 6384)
      • lecheries.exe (PID: 6380)
      • lecheries.exe (PID: 6324)
      • lecheries.exe (PID: 6592)
      • lecheries.exe (PID: 6068)
      • lecheries.exe (PID: 6676)
      • lecheries.exe (PID: 6756)
      • lecheries.exe (PID: 6796)
      • lecheries.exe (PID: 372)
      • lecheries.exe (PID: 2996)
      • lecheries.exe (PID: 6832)
      • lecheries.exe (PID: 6928)
      • lecheries.exe (PID: 6856)
      • lecheries.exe (PID: 6984)
      • lecheries.exe (PID: 6912)
      • lecheries.exe (PID: 7000)
      • lecheries.exe (PID: 7056)
      • lecheries.exe (PID: 6312)
      • lecheries.exe (PID: 7072)
      • lecheries.exe (PID: 7148)
      • lecheries.exe (PID: 5200)
      • lecheries.exe (PID: 2744)
      • lecheries.exe (PID: 3552)
      • lecheries.exe (PID: 2844)
      • lecheries.exe (PID: 3992)
      • lecheries.exe (PID: 1488)
      • lecheries.exe (PID: 3092)
      • lecheries.exe (PID: 3876)
      • lecheries.exe (PID: 5864)
      • lecheries.exe (PID: 1296)
      • lecheries.exe (PID: 5192)
      • lecheries.exe (PID: 5308)
      • lecheries.exe (PID: 5892)
      • lecheries.exe (PID: 6600)
      • lecheries.exe (PID: 6004)
      • lecheries.exe (PID: 2776)
      • lecheries.exe (PID: 6636)
      • lecheries.exe (PID: 6368)
      • lecheries.exe (PID: 4872)
      • lecheries.exe (PID: 3628)
      • lecheries.exe (PID: 5652)
      • lecheries.exe (PID: 6432)
      • lecheries.exe (PID: 5236)
      • lecheries.exe (PID: 1796)
      • lecheries.exe (PID: 3884)
      • lecheries.exe (PID: 6712)
      • lecheries.exe (PID: 6748)
      • lecheries.exe (PID: 6840)
      • lecheries.exe (PID: 6960)
      • lecheries.exe (PID: 7008)
      • lecheries.exe (PID: 7116)
      • lecheries.exe (PID: 7132)
      • lecheries.exe (PID: 4804)
      • lecheries.exe (PID: 5968)
      • lecheries.exe (PID: 2928)
      • lecheries.exe (PID: 1868)
      • lecheries.exe (PID: 4648)
      • lecheries.exe (PID: 4668)
      • lecheries.exe (PID: 3040)
      • lecheries.exe (PID: 4144)
      • lecheries.exe (PID: 1704)
      • lecheries.exe (PID: 640)
      • lecheries.exe (PID: 4764)
      • lecheries.exe (PID: 1556)
      • lecheries.exe (PID: 6360)
      • lecheries.exe (PID: 1576)
      • lecheries.exe (PID: 2132)
      • lecheries.exe (PID: 6544)
      • lecheries.exe (PID: 2736)
      • lecheries.exe (PID: 6532)
      • lecheries.exe (PID: 6772)
      • lecheries.exe (PID: 7032)
      • lecheries.exe (PID: 6180)
      • lecheries.exe (PID: 4996)
      • lecheries.exe (PID: 6176)
      • lecheries.exe (PID: 3544)
      • lecheries.exe (PID: 2088)
      • lecheries.exe (PID: 880)
      • lecheries.exe (PID: 3824)
      • lecheries.exe (PID: 5788)
      • lecheries.exe (PID: 5916)
      • lecheries.exe (PID: 3792)
      • lecheries.exe (PID: 6076)
      • lecheries.exe (PID: 3076)
      • lecheries.exe (PID: 6612)
      • lecheries.exe (PID: 2904)
      • lecheries.exe (PID: 6372)
      • lecheries.exe (PID: 5456)
      • lecheries.exe (PID: 6824)
    • The sample compiled with english language support

      • 4108277feb47e70ea76dea706b8a8e7ed1dc94575c1ed200e78073b4d97185a2.exe (PID: 6684)
    • Reads the machine GUID from the registry

      • 4108277feb47e70ea76dea706b8a8e7ed1dc94575c1ed200e78073b4d97185a2.exe (PID: 6684)
    • Checks supported languages

      • lecheries.exe (PID: 6716)
      • 4108277feb47e70ea76dea706b8a8e7ed1dc94575c1ed200e78073b4d97185a2.exe (PID: 6684)
      • lecheries.exe (PID: 6740)
      • lecheries.exe (PID: 6764)
      • lecheries.exe (PID: 6812)
      • lecheries.exe (PID: 6788)
      • lecheries.exe (PID: 6844)
      • lecheries.exe (PID: 6868)
      • lecheries.exe (PID: 6892)
      • lecheries.exe (PID: 6916)
      • lecheries.exe (PID: 6940)
      • lecheries.exe (PID: 6964)
      • lecheries.exe (PID: 6988)
      • lecheries.exe (PID: 7036)
      • lecheries.exe (PID: 7012)
      • lecheries.exe (PID: 7060)
      • lecheries.exe (PID: 7084)
      • lecheries.exe (PID: 7108)
      • lecheries.exe (PID: 7140)
      • lecheries.exe (PID: 7164)
      • lecheries.exe (PID: 6096)
      • lecheries.exe (PID: 6056)
      • lecheries.exe (PID: 3612)
      • lecheries.exe (PID: 5696)
      • lecheries.exe (PID: 4992)
      • lecheries.exe (PID: 4876)
      • lecheries.exe (PID: 2324)
      • lecheries.exe (PID: 4724)
      • lecheries.exe (PID: 4244)
      • lecheries.exe (PID: 1144)
      • lecheries.exe (PID: 5472)
      • lecheries.exe (PID: 2212)
      • lecheries.exe (PID: 5000)
      • lecheries.exe (PID: 3508)
      • lecheries.exe (PID: 6556)
      • lecheries.exe (PID: 4672)
      • lecheries.exe (PID: 6384)
      • lecheries.exe (PID: 6380)
      • lecheries.exe (PID: 6348)
      • lecheries.exe (PID: 6324)
      • lecheries.exe (PID: 6592)
      • lecheries.exe (PID: 6068)
      • lecheries.exe (PID: 372)
      • lecheries.exe (PID: 6676)
      • lecheries.exe (PID: 2996)
      • lecheries.exe (PID: 6796)
      • lecheries.exe (PID: 6756)
      • lecheries.exe (PID: 6856)
      • lecheries.exe (PID: 6832)
      • lecheries.exe (PID: 6928)
      • lecheries.exe (PID: 6912)
      • lecheries.exe (PID: 6984)
      • lecheries.exe (PID: 7000)
      • lecheries.exe (PID: 7056)
      • lecheries.exe (PID: 6312)
      • lecheries.exe (PID: 7072)
      • lecheries.exe (PID: 5200)
      • lecheries.exe (PID: 2744)
      • lecheries.exe (PID: 7148)
      • lecheries.exe (PID: 1520)
      • lecheries.exe (PID: 2844)
      • lecheries.exe (PID: 3552)
      • lecheries.exe (PID: 3992)
      • lecheries.exe (PID: 1488)
      • lecheries.exe (PID: 3092)
      • lecheries.exe (PID: 3876)
      • lecheries.exe (PID: 1296)
      • lecheries.exe (PID: 5192)
      • lecheries.exe (PID: 5308)
      • lecheries.exe (PID: 5892)
      • lecheries.exe (PID: 6600)
      • lecheries.exe (PID: 6004)
      • lecheries.exe (PID: 2776)
      • lecheries.exe (PID: 6636)
      • lecheries.exe (PID: 4872)
      • lecheries.exe (PID: 6368)
      • lecheries.exe (PID: 3628)
      • lecheries.exe (PID: 648)
      • lecheries.exe (PID: 5652)
      • lecheries.exe (PID: 6432)
      • lecheries.exe (PID: 6640)
      • lecheries.exe (PID: 5236)
      • lecheries.exe (PID: 1796)
      • lecheries.exe (PID: 6712)
      • lecheries.exe (PID: 3884)
      • lecheries.exe (PID: 6748)
      • lecheries.exe (PID: 6804)
      • lecheries.exe (PID: 6840)
      • lecheries.exe (PID: 5452)
      • lecheries.exe (PID: 6880)
      • lecheries.exe (PID: 7008)
      • lecheries.exe (PID: 6960)
      • lecheries.exe (PID: 7076)
      • lecheries.exe (PID: 7116)
      • lecheries.exe (PID: 7132)
      • lecheries.exe (PID: 5112)
      • lecheries.exe (PID: 4804)
      • lecheries.exe (PID: 5968)
      • lecheries.exe (PID: 2928)
      • lecheries.exe (PID: 2380)
      • lecheries.exe (PID: 1868)
      • lecheries.exe (PID: 5604)
      • lecheries.exe (PID: 4648)
      • lecheries.exe (PID: 5836)
      • lecheries.exe (PID: 3040)
      • lecheries.exe (PID: 1944)
      • lecheries.exe (PID: 4144)
      • lecheries.exe (PID: 1704)
      • lecheries.exe (PID: 968)
      • lecheries.exe (PID: 640)
      • lecheries.exe (PID: 4764)
      • lecheries.exe (PID: 6604)
      • lecheries.exe (PID: 3524)
      • lecheries.exe (PID: 1556)
      • lecheries.exe (PID: 6360)
      • lecheries.exe (PID: 2680)
      • lecheries.exe (PID: 1576)
      • lecheries.exe (PID: 3920)
      • lecheries.exe (PID: 2132)
      • lecheries.exe (PID: 2736)
      • lecheries.exe (PID: 4012)
      • lecheries.exe (PID: 6452)
      • lecheries.exe (PID: 4392)
      • lecheries.exe (PID: 6772)
      • lecheries.exe (PID: 2008)
      • lecheries.exe (PID: 5992)
      • lecheries.exe (PID: 7128)
      • lecheries.exe (PID: 3560)
      • lecheries.exe (PID: 7032)
      • lecheries.exe (PID: 6180)
      • lecheries.exe (PID: 2012)
      • lecheries.exe (PID: 6176)
      • lecheries.exe (PID: 3544)
      • lecheries.exe (PID: 6160)
      • lecheries.exe (PID: 1076)
      • lecheries.exe (PID: 880)
      • lecheries.exe (PID: 1688)
      • lecheries.exe (PID: 3824)
      • lecheries.exe (PID: 5712)
      • lecheries.exe (PID: 5740)
      • lecheries.exe (PID: 5788)
      • lecheries.exe (PID: 5556)
      • lecheries.exe (PID: 5916)
      • lecheries.exe (PID: 6184)
      • lecheries.exe (PID: 3792)
      • lecheries.exe (PID: 6076)
      • lecheries.exe (PID: 3076)
      • lecheries.exe (PID: 3632)
      • lecheries.exe (PID: 2904)
      • lecheries.exe (PID: 6612)
      • lecheries.exe (PID: 6372)
      • lecheries.exe (PID: 6548)
      • lecheries.exe (PID: 5456)
      • lecheries.exe (PID: 1580)
      • lecheries.exe (PID: 2292)
      • lecheries.exe (PID: 6824)
      • lecheries.exe (PID: 6952)
      • lecheries.exe (PID: 7068)
      • lecheries.exe (PID: 4544)
    • Creates files or folders in the user directory

      • lecheries.exe (PID: 6716)
    • Create files in a temporary directory

      • lecheries.exe (PID: 6740)
      • lecheries.exe (PID: 6716)
      • lecheries.exe (PID: 6788)
      • lecheries.exe (PID: 6764)
      • lecheries.exe (PID: 6812)
      • lecheries.exe (PID: 6844)
      • lecheries.exe (PID: 6868)
      • lecheries.exe (PID: 6892)
      • lecheries.exe (PID: 6940)
      • lecheries.exe (PID: 6916)
      • lecheries.exe (PID: 7036)
      • lecheries.exe (PID: 6964)
      • lecheries.exe (PID: 6988)
      • lecheries.exe (PID: 7012)
      • lecheries.exe (PID: 7060)
      • lecheries.exe (PID: 7084)
      • lecheries.exe (PID: 7108)
      • lecheries.exe (PID: 7140)
      • lecheries.exe (PID: 6096)
      • lecheries.exe (PID: 6056)
      • lecheries.exe (PID: 4876)
      • lecheries.exe (PID: 5696)
      • lecheries.exe (PID: 4992)
      • lecheries.exe (PID: 1144)
      • lecheries.exe (PID: 2212)
      • lecheries.exe (PID: 4244)
      • lecheries.exe (PID: 5472)
      • lecheries.exe (PID: 6556)
      • lecheries.exe (PID: 4672)
      • lecheries.exe (PID: 3508)
      • lecheries.exe (PID: 6348)
      • lecheries.exe (PID: 6384)
      • lecheries.exe (PID: 6592)
      • lecheries.exe (PID: 6068)
      • lecheries.exe (PID: 6676)
      • lecheries.exe (PID: 6756)
      • lecheries.exe (PID: 6984)
      • lecheries.exe (PID: 7056)
      • lecheries.exe (PID: 6312)
      • lecheries.exe (PID: 6928)
      • lecheries.exe (PID: 7148)
      • lecheries.exe (PID: 2844)
      • lecheries.exe (PID: 1296)
      • lecheries.exe (PID: 5192)
      • lecheries.exe (PID: 5308)
      • lecheries.exe (PID: 6004)
      • lecheries.exe (PID: 6636)
      • lecheries.exe (PID: 2776)
      • lecheries.exe (PID: 6368)
      • lecheries.exe (PID: 6640)
      • lecheries.exe (PID: 5236)
      • lecheries.exe (PID: 6748)
      • lecheries.exe (PID: 6960)
      • lecheries.exe (PID: 7076)
      • lecheries.exe (PID: 7132)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (39.3)
.exe | Win32 EXE Yoda's Crypter (38.6)
.dll | Win32 Dynamic Link Library (generic) (9.5)
.exe | Win32 Executable (generic) (6.5)
.exe | Generic Win/DOS Executable (2.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:12:02 07:08:56+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 12
CodeSize: 352256
InitializedDataSize: 499712
UninitializedDataSize: 1028096
EntryPoint: 0x151a40
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (British)
CharacterSet: Unicode
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
289
Monitored processes
172
Malicious processes
2
Suspicious processes
148

Behavior graph

Click at the process to see the details
start 4108277feb47e70ea76dea706b8a8e7ed1dc94575c1ed200e78073b4d97185a2.exe lecheries.exe lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs lecheries.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6684"C:\Users\admin\AppData\Local\Temp\4108277feb47e70ea76dea706b8a8e7ed1dc94575c1ed200e78073b4d97185a2.exe" C:\Users\admin\AppData\Local\Temp\4108277feb47e70ea76dea706b8a8e7ed1dc94575c1ed200e78073b4d97185a2.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\4108277feb47e70ea76dea706b8a8e7ed1dc94575c1ed200e78073b4d97185a2.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6716"C:\Users\admin\AppData\Local\Temp\4108277feb47e70ea76dea706b8a8e7ed1dc94575c1ed200e78073b4d97185a2.exe" C:\Users\admin\AppData\Local\differences\lecheries.exe
4108277feb47e70ea76dea706b8a8e7ed1dc94575c1ed200e78073b4d97185a2.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\differences\lecheries.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6740"C:\Users\admin\AppData\Local\differences\lecheries.exe"C:\Users\admin\AppData\Local\differences\lecheries.exelecheries.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\differences\lecheries.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6764"C:\Users\admin\AppData\Local\differences\lecheries.exe"C:\Users\admin\AppData\Local\differences\lecheries.exelecheries.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\differences\lecheries.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6788"C:\Users\admin\AppData\Local\differences\lecheries.exe"C:\Users\admin\AppData\Local\differences\lecheries.exelecheries.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\differences\lecheries.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6812"C:\Users\admin\AppData\Local\differences\lecheries.exe"C:\Users\admin\AppData\Local\differences\lecheries.exelecheries.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\differences\lecheries.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6844"C:\Users\admin\AppData\Local\differences\lecheries.exe"C:\Users\admin\AppData\Local\differences\lecheries.exelecheries.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\differences\lecheries.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6868"C:\Users\admin\AppData\Local\differences\lecheries.exe"C:\Users\admin\AppData\Local\differences\lecheries.exelecheries.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\differences\lecheries.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6892"C:\Users\admin\AppData\Local\differences\lecheries.exe"C:\Users\admin\AppData\Local\differences\lecheries.exelecheries.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\differences\lecheries.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
6916"C:\Users\admin\AppData\Local\differences\lecheries.exe"C:\Users\admin\AppData\Local\differences\lecheries.exelecheries.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\differences\lecheries.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
3 962
Read events
3 962
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
174
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
66844108277feb47e70ea76dea706b8a8e7ed1dc94575c1ed200e78073b4d97185a2.exeC:\Users\admin\AppData\Local\Temp\intemerationbinary
MD5:B330D054750C618EA270434FEC0B3A6F
SHA256:BD39655DC196287079FA8F554A938E2D77BC50E8987E974BFEB2795AB7099F9C
6716lecheries.exeC:\Users\admin\AppData\Local\Temp\aut6380.tmpbinary
MD5:3BB2DEC320628996095338A819DD9B7B
SHA256:26AE89457FF05DF72B7EDE7450FFAE2185018168E42C1501CD2779D84528372B
6716lecheries.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\lecheries.vbsbinary
MD5:4DC02633994996279ECC5B083429D884
SHA256:17EAE59DAA5D79033366273BE87FEF79D274FD1BB7A23125E543617289F06332
6740lecheries.exeC:\Users\admin\AppData\Local\Temp\aut662F.tmpbinary
MD5:3BB2DEC320628996095338A819DD9B7B
SHA256:26AE89457FF05DF72B7EDE7450FFAE2185018168E42C1501CD2779D84528372B
66844108277feb47e70ea76dea706b8a8e7ed1dc94575c1ed200e78073b4d97185a2.exeC:\Users\admin\AppData\Local\differences\lecheries.exeexecutable
MD5:AC26BAF5B7B03AA4046B2C2413A4C2C2
SHA256:4108277FEB47E70EA76DEA706B8A8E7ED1DC94575C1ED200E78073B4D97185A2
66844108277feb47e70ea76dea706b8a8e7ed1dc94575c1ed200e78073b4d97185a2.exeC:\Users\admin\AppData\Local\Temp\aut60A1.tmpbinary
MD5:3BB2DEC320628996095338A819DD9B7B
SHA256:26AE89457FF05DF72B7EDE7450FFAE2185018168E42C1501CD2779D84528372B
6916lecheries.exeC:\Users\admin\AppData\Local\Temp\aut787F.tmpbinary
MD5:3BB2DEC320628996095338A819DD9B7B
SHA256:26AE89457FF05DF72B7EDE7450FFAE2185018168E42C1501CD2779D84528372B
6788lecheries.exeC:\Users\admin\AppData\Local\Temp\aut6B6F.tmpbinary
MD5:3BB2DEC320628996095338A819DD9B7B
SHA256:26AE89457FF05DF72B7EDE7450FFAE2185018168E42C1501CD2779D84528372B
6940lecheries.exeC:\Users\admin\AppData\Local\Temp\aut7B2E.tmpbinary
MD5:3BB2DEC320628996095338A819DD9B7B
SHA256:26AE89457FF05DF72B7EDE7450FFAE2185018168E42C1501CD2779D84528372B
6764lecheries.exeC:\Users\admin\AppData\Local\Temp\aut68CF.tmpbinary
MD5:3BB2DEC320628996095338A819DD9B7B
SHA256:26AE89457FF05DF72B7EDE7450FFAE2185018168E42C1501CD2779D84528372B
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
26
DNS requests
14
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
5236
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
1176
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
5236
SIHClient.exe
GET
200
2.23.246.101:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
6200
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
GET
200
69.192.161.161:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
69.192.161.161:80
AKAMAI-AS
DE
unknown
4
System
192.168.100.255:137
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
92.123.104.62:443
www.bing.com
Akamai International B.V.
DE
whitelisted
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1176
svchost.exe
40.126.32.133:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
1076
svchost.exe
23.35.238.131:443
go.microsoft.com
AKAMAI-AS
DE
whitelisted
5340
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.238
whitelisted
www.bing.com
  • 92.123.104.62
  • 92.123.104.34
  • 92.123.104.38
  • 92.123.104.33
  • 92.123.104.28
  • 92.123.104.31
  • 92.123.104.32
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.133
  • 40.126.32.74
  • 20.190.160.22
  • 40.126.32.136
  • 20.190.160.14
  • 40.126.32.134
  • 40.126.32.72
  • 20.190.160.17
whitelisted
go.microsoft.com
  • 23.35.238.131
whitelisted
settings-win.data.microsoft.com
  • 4.231.128.59
whitelisted
arc.msn.com
  • 20.103.156.88
whitelisted
fd.api.iris.microsoft.com
  • 20.223.36.55
whitelisted
slscr.update.microsoft.com
  • 172.202.163.200
whitelisted
www.microsoft.com
  • 2.23.246.101
whitelisted

Threats

No threats detected
No debug info