File name:

TARISMiniLoader_official.wg.intl.exe

Full analysis: https://app.any.run/tasks/86109239-e6aa-49d4-b046-235373572d9f
Verdict: Malicious activity
Analysis date: February 06, 2024, 07:31:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A6D216E97168B658F3FBE40A7EED10D0

SHA1:

20E968CFB5F9A7C95E73839F04DA0354674922D7

SHA256:

43004A7DC6450C717539479070F2AF9FCD443A0C5486A0B1E34A9727F2A044FE

SSDEEP:

98304:b/AgWgaX8+UcVHJaF1VkSBbqvTu1WMO+bERPFEgt1wo6kL1/2UbXScCKaxMSl2Jn:kNGZEAoB8uBbOF7Cse0XVKr

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • TARISMiniLoader_official.wg.intl.exe (PID: 2088)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • TARISMiniLoader_official.wg.intl.exe (PID: 2088)
  • INFO

    • Create files in a temporary directory

      • TARISMiniLoader_official.wg.intl.exe (PID: 2088)
    • Checks supported languages

      • TARISMiniLoader_official.wg.intl.exe (PID: 2088)
      • TARISMiniloader.exe (PID: 668)
    • Reads the computer name

      • TARISMiniLoader_official.wg.intl.exe (PID: 2088)
      • TARISMiniloader.exe (PID: 668)
    • Creates files in the program directory

      • TARISMiniloader.exe (PID: 668)
    • Creates files or folders in the user directory

      • TARISMiniLoader_official.wg.intl.exe (PID: 2088)
      • TARISMiniloader.exe (PID: 668)
    • Reads the machine GUID from the registry

      • TARISMiniloader.exe (PID: 668)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:02:24 20:19:59+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 28672
InitializedDataSize: 445952
UninitializedDataSize: 16896
EntryPoint: 0x39e3
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 0.0.6.183
ProductVersionNumber: 0.0.6.183
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Windows, Chinese (Simplified)
Comments: -
CompanyName: PROXIMA BETA PTE. LIMITED
FileDescription: -
FileVersion: 0.0.6.183
LegalCopyright: -
LegalTrademarks: -
ProductName: TARISMiniloader
ProductVersion: 0.0.6.183
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start tarisminiloader_official.wg.intl.exe tarisminiloader.exe tarisminiloader_official.wg.intl.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
668"C:\Users\admin\AppData\Local\TARISMiniloader\TARISMiniloader.exe" C:\Users\admin\AppData\Local\TARISMiniloader\TARISMiniloader.exe
TARISMiniLoader_official.wg.intl.exe
User:
admin
Integrity Level:
HIGH
Description:
Tarisland Minidown.exe
Exit code:
0
Version:
0.0.6.183
Modules
Images
c:\users\admin\appdata\local\tarisminiloader\tarisminiloader.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
1380"C:\Users\admin\AppData\Local\Temp\TARISMiniLoader_official.wg.intl.exe" C:\Users\admin\AppData\Local\Temp\TARISMiniLoader_official.wg.intl.exeexplorer.exe
User:
admin
Company:
PROXIMA BETA PTE. LIMITED
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
0.0.6.183
Modules
Images
c:\users\admin\appdata\local\temp\tarisminiloader_official.wg.intl.exe
c:\windows\system32\ntdll.dll
2088"C:\Users\admin\AppData\Local\Temp\TARISMiniLoader_official.wg.intl.exe" C:\Users\admin\AppData\Local\Temp\TARISMiniLoader_official.wg.intl.exe
explorer.exe
User:
admin
Company:
PROXIMA BETA PTE. LIMITED
Integrity Level:
HIGH
Exit code:
0
Version:
0.0.6.183
Modules
Images
c:\users\admin\appdata\local\temp\tarisminiloader_official.wg.intl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
1 122
Read events
1 122
Write events
0
Delete events
0

Modification events

No data
Executable files
4
Suspicious files
5
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
2088TARISMiniLoader_official.wg.intl.exeC:\Users\admin\AppData\Local\TARISMiniloader\Minidown.xmlbinary
MD5:7119E680F016E29E9C3B53FBCD3A35E1
SHA256:534A2323B3E0A4DFAC1CA732A040C0AD1989F50FE3882FF8D08B0D59CA93BB2B
2088TARISMiniLoader_official.wg.intl.exeC:\Users\admin\AppData\Local\TARISMiniloader\bugreport.initext
MD5:27EC1E105337C0AD4BDDB8F2A9551F6C
SHA256:ED60CA6895464814F9E5BC132F41645630CC785FAE9FC7DA6362B5690B3A97CD
2088TARISMiniLoader_official.wg.intl.exeC:\Users\admin\AppData\Local\TARISMiniloader\LogConfig.initext
MD5:1E8CF5946A37D9A084BE613554260815
SHA256:E8A59173F505DBEDF4DD37EEC210E5E539A243E46F521A8BA8D2EC13FD99D29F
2088TARISMiniLoader_official.wg.intl.exeC:\Users\admin\AppData\Local\TARISMiniloader\tiny_dl\VersionService.exeexecutable
MD5:78EFACAF95634FD334317881E5EFC42A
SHA256:BB7F9755DF89150971FA59B0A2FA7E80534768BA3208800E915B01EE3630B173
2088TARISMiniLoader_official.wg.intl.exeC:\Users\admin\AppData\Local\TARISMiniloader\install_script.datbinary
MD5:4B825D933E87A697A663F3E30FCB31CB
SHA256:AFB0049FD6DDD8A90AA44DFFDDDD9ACEA89D6A59134F2E3C8774F2767C9684C0
2088TARISMiniLoader_official.wg.intl.exeC:\Users\admin\AppData\Local\Temp\nsz425F.tmp\NSISPlugin.dllexecutable
MD5:7C1B00E82C60C4850FCB098D48C40410
SHA256:1B9A09720AB5F6FED43D366CDF1D314B15E29E4EEABEFDC528BF4053A0C1B0EF
2088TARISMiniLoader_official.wg.intl.exeC:\Users\admin\AppData\Local\TARISMiniloader\TARISMiniloader.exeexecutable
MD5:28D87AF6054AC8A7BBE18A1A158D9510
SHA256:9B1B5FD08FCC105B912C9D506BE0506335AADC6151B96CA83F3692DE71F57569
2088TARISMiniLoader_official.wg.intl.exeC:\Users\admin\AppData\Local\TARISMiniloader\tiny_dl\VersionServiceProxy.dllexecutable
MD5:4B5D8A43647EB765B6AE2A56DEB38EE1
SHA256:3ECD7166EDE3DA12FD2CC0CA2891B5FB7DCBE3D2505E52D068947336C5259C60
668TARISMiniloader.exeC:\ProgramData\intl_ua\29175\official.wg.intltext
MD5:C74F86F208C466B66E5057A3C347CF78
SHA256:6896191A14F6C66534BAC457F50996B9330CD702CB6DBAAE4C08D1D213E93D98
668TARISMiniloader.exeC:\Users\admin\AppData\Roaming\Tencent\TenioDL\Common.initext
MD5:B560F0B1E3E599C771A75A9BDC8BD1A9
SHA256:086457569AE58F3096A6131C9369756F4C5F8391A884F644A943AD8F4F80558D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
11
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
2088
TARISMiniLoader_official.wg.intl.exe
116.130.229.213:8000
ied-tqos.qq.com
unknown
668
TARISMiniloader.exe
52.52.74.151:443
www.jupiterlauncher.com
AMAZON-02
US
unknown
668
TARISMiniloader.exe
116.130.229.213:8000
ied-tqos.qq.com
unknown
668
TARISMiniloader.exe
50.18.118.13:443
na.fleetlogd.com
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
ied-tqos.qq.com
  • 116.130.229.213
unknown
www.jupiterlauncher.com
  • 52.52.74.151
  • 54.183.3.214
unknown
na.fleetlogd.com
  • 50.18.118.13
  • 54.241.119.115
unknown

Threats

No threats detected
Process
Message
TARISMiniLoader_official.wg.intl.exe
[NSISPlugin][ResetModuleName] NSIS Plugin Start, Version=V1.02.007.0
TARISMiniLoader_official.wg.intl.exe
[NSISPlugin][ResetModuleName] MINILOADER
TARISMiniLoader_official.wg.intl.exe
[NSISPlugin][TQosReport] TQos Server Address: ied-tqos.qq.com, Port: 8000, TQos ID: 2003
TARISMiniLoader_official.wg.intl.exe
[NSISPlugin][AddQosData] str[1]
TARISMiniLoader_official.wg.intl.exe
[NSISPlugin][AddQosData] int[10] 0
TARISMiniLoader_official.wg.intl.exe
[NSISPlugin][AddQosData] int[1] 0
TARISMiniLoader_official.wg.intl.exe
[NSISPlugin][AddQosData] str[2] 8000001
TARISMiniLoader_official.wg.intl.exe
[NSISPlugin][AddQosData] str[4]
TARISMiniLoader_official.wg.intl.exe
[NSISPlugin][AddQosData] int[2] 0
TARISMiniLoader_official.wg.intl.exe
[NSISPlugin][AddQosData] int[5] 0