File name:

notmyfault.exe

Full analysis: https://app.any.run/tasks/7caee529-e28b-4834-9f0c-5f4f2bf6ebfb
Verdict: Malicious activity
Analysis date: September 26, 2023, 07:30:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

833D5BBDF80D17A384E9B27798EA4D6C

SHA1:

4AB55A97E76FD2CDB55ED305C984D87E9A06B1B1

SHA256:

41DDB886060471D702693CBFF1E7AA73C8ADA5B29D9EE313DE9972AB663A100D

SSDEEP:

6144:whvkHmbGp7MCvRDlfJHbwZCjO0fNg1iyk:whMGbGlR5Pm1i/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Creates a writable file the system directory

      • notmyfault.exe (PID: 2736)
      • notmyfault.exe (PID: 1852)
      • notmyfault.exe (PID: 3088)
      • notmyfault.exe (PID: 2672)
      • notmyfault.exe (PID: 476)
      • notmyfault.exe (PID: 1032)
      • notmyfault.exe (PID: 1200)
  • SUSPICIOUS

    • Creates files in the driver directory

      • notmyfault.exe (PID: 2736)
      • notmyfault.exe (PID: 1852)
      • notmyfault.exe (PID: 1200)
      • notmyfault.exe (PID: 2672)
      • notmyfault.exe (PID: 3088)
      • notmyfault.exe (PID: 476)
      • notmyfault.exe (PID: 1032)
    • Drops a system driver (possible attempt to evade defenses)

      • notmyfault.exe (PID: 2736)
      • notmyfault.exe (PID: 1852)
      • notmyfault.exe (PID: 2672)
      • notmyfault.exe (PID: 3088)
      • notmyfault.exe (PID: 476)
      • notmyfault.exe (PID: 1032)
      • notmyfault.exe (PID: 1200)
  • INFO

    • Reads Environment values

      • notmyfault.exe (PID: 2736)
    • Reads product name

      • notmyfault.exe (PID: 2736)
    • Checks supported languages

      • notmyfault.exe (PID: 2736)
      • notmyfault.exe (PID: 1200)
      • notmyfault.exe (PID: 1852)
      • notmyfault.exe (PID: 3088)
      • notmyfault.exe (PID: 2672)
      • notmyfault.exe (PID: 476)
      • notmyfault.exe (PID: 1032)
    • Manual execution by a user

      • taskmgr.exe (PID: 1860)
      • notmyfault.exe (PID: 1852)
      • notmyfault.exe (PID: 2596)
      • notmyfault.exe (PID: 2672)
      • notmyfault.exe (PID: 3088)
      • notmyfault.exe (PID: 3572)
      • notmyfault.exe (PID: 2044)
      • notmyfault.exe (PID: 476)
      • notmyfault.exe (PID: 1032)
      • notmyfault.exe (PID: 3768)
      • notmyfault.exe (PID: 1200)
      • notmyfault.exe (PID: 2848)
    • Reads the computer name

      • notmyfault.exe (PID: 1852)
      • notmyfault.exe (PID: 2672)
      • notmyfault.exe (PID: 3088)
      • notmyfault.exe (PID: 476)
      • notmyfault.exe (PID: 1032)
      • notmyfault.exe (PID: 2736)
      • notmyfault.exe (PID: 1200)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

ProductVersion: 4.21
ProductName: Sysinternals NotMyfault
OriginalFileName: NotMyfault.exe
LegalCopyright: Copyright (C) 2002-2022 Mark Russinovich
InternalName: Sysinternals NotMyfault
FileVersion: 4.21
FileDescription: Driver Bug Test Program
CompanyName: Sysinternals - www.sysinternals.com
CharacterSet: Unicode
LanguageCode: English (U.S.)
FileSubtype: -
ObjectFileType: Executable application
FileOS: Windows NT 32-bit
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 4.21.0.0
FileVersionNumber: 4.21.0.0
Subsystem: Windows GUI
SubsystemVersion: 6
ImageVersion: -
OSVersion: 6
EntryPoint: 0x3fdb
UninitializedDataSize: -
InitializedDataSize: 165888
CodeSize: 132096
LinkerVersion: 14.33
PEType: PE32
ImageFileCharacteristics: Executable, 32-bit
TimeStamp: 2022:09:29 16:22:37+00:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
65
Monitored processes
14
Malicious processes
0
Suspicious processes
7

Behavior graph

Click at the process to see the details
start notmyfault.exe taskmgr.exe no specs notmyfault.exe no specs notmyfault.exe notmyfault.exe notmyfault.exe no specs notmyfault.exe notmyfault.exe no specs notmyfault.exe notmyfault.exe no specs notmyfault.exe notmyfault.exe no specs notmyfault.exe notmyfault.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
476"C:\Users\admin\AppData\Local\Temp\notmyfault.exe" C:\Users\admin\AppData\Local\Temp\notmyfault.exe
explorer.exe
User:
admin
Company:
Sysinternals - www.sysinternals.com
Integrity Level:
HIGH
Description:
Driver Bug Test Program
Exit code:
0
Version:
4.21
Modules
Images
c:\users\admin\appdata\local\temp\notmyfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\user32.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\lpk.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
1032"C:\Users\admin\Desktop\notmyfault.exe" C:\Users\admin\Desktop\notmyfault.exe
explorer.exe
User:
admin
Company:
Sysinternals - www.sysinternals.com
Integrity Level:
HIGH
Description:
Driver Bug Test Program
Exit code:
0
Version:
4.21
Modules
Images
c:\users\admin\desktop\notmyfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
1200"C:\Users\admin\AppData\Local\Temp\notmyfault.exe" C:\Users\admin\AppData\Local\Temp\notmyfault.exe
explorer.exe
User:
admin
Company:
Sysinternals - www.sysinternals.com
Integrity Level:
HIGH
Description:
Driver Bug Test Program
Exit code:
0
Version:
4.21
Modules
Images
c:\users\admin\appdata\local\temp\notmyfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1852"C:\Users\admin\AppData\Local\Temp\notmyfault.exe" C:\Users\admin\AppData\Local\Temp\notmyfault.exe
explorer.exe
User:
admin
Company:
Sysinternals - www.sysinternals.com
Integrity Level:
HIGH
Description:
Driver Bug Test Program
Exit code:
0
Version:
4.21
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\users\admin\appdata\local\temp\notmyfault.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1860"C:\Windows\system32\taskmgr.exe" /4C:\Windows\System32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\taskmgr.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2044"C:\Users\admin\AppData\Local\Temp\notmyfault.exe" C:\Users\admin\AppData\Local\Temp\notmyfault.exeexplorer.exe
User:
admin
Company:
Sysinternals - www.sysinternals.com
Integrity Level:
MEDIUM
Description:
Driver Bug Test Program
Exit code:
3221226540
Version:
4.21
Modules
Images
c:\users\admin\appdata\local\temp\notmyfault.exe
c:\windows\system32\ntdll.dll
2596"C:\Users\admin\AppData\Local\Temp\notmyfault.exe" C:\Users\admin\AppData\Local\Temp\notmyfault.exeexplorer.exe
User:
admin
Company:
Sysinternals - www.sysinternals.com
Integrity Level:
MEDIUM
Description:
Driver Bug Test Program
Exit code:
3221226540
Version:
4.21
Modules
Images
c:\users\admin\appdata\local\temp\notmyfault.exe
c:\windows\system32\ntdll.dll
2672"C:\Users\admin\AppData\Local\Temp\notmyfault.exe" C:\Users\admin\AppData\Local\Temp\notmyfault.exe
explorer.exe
User:
admin
Company:
Sysinternals - www.sysinternals.com
Integrity Level:
HIGH
Description:
Driver Bug Test Program
Exit code:
0
Version:
4.21
Modules
Images
c:\users\admin\appdata\local\temp\notmyfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
2736"C:\Users\admin\AppData\Local\Temp\notmyfault.exe" C:\Users\admin\AppData\Local\Temp\notmyfault.exe
explorer.exe
User:
admin
Company:
Sysinternals - www.sysinternals.com
Integrity Level:
HIGH
Description:
Driver Bug Test Program
Exit code:
0
Version:
4.21
Modules
Images
c:\users\admin\appdata\local\temp\notmyfault.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2848"C:\Users\admin\AppData\Local\Temp\notmyfault.exe" C:\Users\admin\AppData\Local\Temp\notmyfault.exeexplorer.exe
User:
admin
Company:
Sysinternals - www.sysinternals.com
Integrity Level:
MEDIUM
Description:
Driver Bug Test Program
Exit code:
3221226540
Version:
4.21
Modules
Images
c:\users\admin\appdata\local\temp\notmyfault.exe
c:\windows\system32\ntdll.dll
Total events
1 550
Read events
1 542
Write events
8
Delete events
0

Modification events

(PID) Process:(1860) taskmgr.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\TaskManager
Operation:writeName:UsrColumnSettings
Value:
1C0C0000340400000000000050000000010000001D0C0000350400000000000023000000010000001E0C000036040000000000003C000000010000001F0C000039040000000000004E00000001000000200C000037040000000000004E00000001000000
(PID) Process:(1860) taskmgr.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\TaskManager
Operation:writeName:Preferences
Value:
30030000E803000001000000010000004401000076000000DC0200005C0200000300000001000000000000000000000001000000000000000100000000000000000000000200000004000000090000001D000000FFFFFFFF00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000009C00000040000000210000004600000052000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0000000002000000010000000300000004000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0500000000000000FFFFFFFF00000000020000000300000004000000FFFFFFFF00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000630060003C005A00FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF000000000000010000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0400000000000000FFFFFFFF00000000FFFFFFFF4F00000028000000500000003400000050000000000000000100000002000000030000000400000000000000FFFFFFFF43000000000000000000000001000000
(PID) Process:(1200) notmyfault.exeKey:HKEY_CURRENT_USER\Software\Sysinternals\NotMyFault
Operation:writeName:EulaAccepted
Value:
1
(PID) Process:(1852) notmyfault.exeKey:HKEY_CURRENT_USER\Software\Sysinternals\NotMyFault
Operation:writeName:EulaAccepted
Value:
1
(PID) Process:(2672) notmyfault.exeKey:HKEY_CURRENT_USER\Software\Sysinternals\NotMyFault
Operation:writeName:EulaAccepted
Value:
1
(PID) Process:(3088) notmyfault.exeKey:HKEY_CURRENT_USER\Software\Sysinternals\NotMyFault
Operation:writeName:EulaAccepted
Value:
1
(PID) Process:(476) notmyfault.exeKey:HKEY_CURRENT_USER\Software\Sysinternals\NotMyFault
Operation:writeName:EulaAccepted
Value:
1
(PID) Process:(1032) notmyfault.exeKey:HKEY_CURRENT_USER\Software\Sysinternals\NotMyFault
Operation:writeName:EulaAccepted
Value:
1
Executable files
7
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2672notmyfault.exeC:\Windows\system32\drivers\myfault.sysexecutable
MD5:D5ADEA32410F975EA943521DA0F7F31F
SHA256:49C93B06246D47522E1A9CB9B1F5E0513DB736BC466983EEBFBF4445479D9419
1852notmyfault.exeC:\Windows\system32\drivers\myfault.sysexecutable
MD5:D5ADEA32410F975EA943521DA0F7F31F
SHA256:49C93B06246D47522E1A9CB9B1F5E0513DB736BC466983EEBFBF4445479D9419
476notmyfault.exeC:\Windows\system32\drivers\myfault.sysexecutable
MD5:D5ADEA32410F975EA943521DA0F7F31F
SHA256:49C93B06246D47522E1A9CB9B1F5E0513DB736BC466983EEBFBF4445479D9419
3088notmyfault.exeC:\Windows\system32\drivers\myfault.sysexecutable
MD5:D5ADEA32410F975EA943521DA0F7F31F
SHA256:49C93B06246D47522E1A9CB9B1F5E0513DB736BC466983EEBFBF4445479D9419
1032notmyfault.exeC:\Windows\system32\drivers\myfault.sysexecutable
MD5:D5ADEA32410F975EA943521DA0F7F31F
SHA256:49C93B06246D47522E1A9CB9B1F5E0513DB736BC466983EEBFBF4445479D9419
2736notmyfault.exeC:\Windows\system32\drivers\myfault.sysexecutable
MD5:D5ADEA32410F975EA943521DA0F7F31F
SHA256:49C93B06246D47522E1A9CB9B1F5E0513DB736BC466983EEBFBF4445479D9419
1200notmyfault.exeC:\Windows\system32\drivers\myfault.sysexecutable
MD5:D5ADEA32410F975EA943521DA0F7F31F
SHA256:49C93B06246D47522E1A9CB9B1F5E0513DB736BC466983EEBFBF4445479D9419
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
3284
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info