File name:

psiphon3.exe

Full analysis: https://app.any.run/tasks/82a875fb-cbd9-4308-96ae-870a331d7668
Verdict: Malicious activity
Analysis date: April 12, 2024, 21:26:50
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

59FB0E6F8A26D0EF7D21990D9CA82183

SHA1:

0D491983D723A4A26F3B965F8450B50745314B95

SHA256:

43BF4FF23895F157FAD228EA41D8BF23B76A8D5866D95B6BF605CF7CC05D2558

SSDEEP:

98304:nJZ9N313pa/V+beW1s8YHb8tvjMoUeQrHNWqaxlY79eWirDL2U1XllonTbO4bCva:DCaZbnCwuW0Lrna6

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • psiphon3.exe (PID: 2124)
  • SUSPICIOUS

    • Reads Microsoft Outlook installation path

      • psiphon3.exe (PID: 2124)
    • Reads the Internet Settings

      • psiphon3.exe (PID: 2124)
    • Reads security settings of Internet Explorer

      • psiphon3.exe (PID: 2124)
    • Reads Internet Explorer settings

      • psiphon3.exe (PID: 2124)
    • Executable content was dropped or overwritten

      • psiphon3.exe (PID: 2124)
    • Reads settings of System Certificates

      • psiphon3.exe (PID: 2124)
    • Connects to SSH

      • psiphon-tunnel-core.exe (PID: 2364)
    • Connects to unusual port

      • psiphon-tunnel-core.exe (PID: 2364)
  • INFO

    • Checks supported languages

      • psiphon3.exe (PID: 2124)
      • psiphon-tunnel-core.exe (PID: 2364)
    • Reads the computer name

      • psiphon3.exe (PID: 2124)
      • psiphon-tunnel-core.exe (PID: 2364)
    • Checks proxy server information

      • psiphon3.exe (PID: 2124)
    • Creates files or folders in the user directory

      • psiphon3.exe (PID: 2124)
      • psiphon-tunnel-core.exe (PID: 2364)
    • Reads the machine GUID from the registry

      • psiphon3.exe (PID: 2124)
    • Create files in a temporary directory

      • psiphon3.exe (PID: 2124)
    • Reads the software policy settings

      • psiphon3.exe (PID: 2124)
    • Application launched itself

      • msedge.exe (PID: 3068)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (43.5)
.exe | Win32 EXE Yoda's Crypter (42.7)
.exe | Win32 Executable (generic) (7.2)
.exe | Generic Win/DOS Executable (3.2)
.exe | DOS Executable Generic (3.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:04:11 14:43:35+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 8228864
InitializedDataSize: 90112
UninitializedDataSize: 16478208
EntryPoint: 0x178dc20
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
58
Monitored processes
20
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start psiphon3.exe psiphon-tunnel-core.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
240"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=crashpad-handler "--user-data-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad" "--metrics-dir=C:\Users\admin\AppData\Local\Microsoft\Edge\User Data" --annotation=IsOfficialBuild=1 --annotation=channel= --annotation=chromium-version=109.0.5414.149 "--annotation=exe=C:\Program Files\Microsoft\Edge\Application\msedge.exe" --annotation=plat=Win32 "--annotation=prod=Microsoft Edge" --annotation=ver=109.0.1518.115 --initial-client-data=0xc8,0xcc,0xd0,0x9c,0xd8,0x699bf598,0x699bf5a8,0x699bf5b4C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
752"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3612 --field-trial-handle=1200,i,12061209141310624875,11701734703555174049,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
896"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1980 --field-trial-handle=1200,i,12061209141310624875,11701734703555174049,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1316"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3708 --field-trial-handle=1200,i,12061209141310624875,11701734703555174049,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2024"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3636 --field-trial-handle=1200,i,12061209141310624875,11701734703555174049,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2124"C:\Users\admin\AppData\Local\Temp\psiphon3.exe" C:\Users\admin\AppData\Local\Temp\psiphon3.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\psiphon3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
c:\windows\system32\gdi32.dll
2192"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3584 --field-trial-handle=1200,i,12061209141310624875,11701734703555174049,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2320"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1240 --field-trial-handle=1200,i,12061209141310624875,11701734703555174049,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2364C:\Users\admin\AppData\Local\Temp\psiphon-tunnel-core.exe --config "C:\Users\admin\AppData\Local\Psiphon3\psiphon.config" --serverList "C:\Users\admin\AppData\Local\Psiphon3\server_list.dat"C:\Users\admin\AppData\Local\Temp\psiphon-tunnel-core.exe
psiphon3.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\users\admin\appdata\local\temp\psiphon-tunnel-core.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\winmm.dll
c:\windows\system32\user32.dll
2560"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --use-gl=angle --use-angle=swiftshader-webgl --mojo-platform-channel-handle=1464 --field-trial-handle=1200,i,12061209141310624875,11701734703555174049,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
7 960
Read events
7 854
Write events
90
Delete events
16

Modification events

(PID) Process:(2124) psiphon3.exeKey:HKEY_CURRENT_USER\Software\Psiphon3
Operation:writeName:SkipProxySettings
Value:
0
(PID) Process:(2124) psiphon3.exeKey:HKEY_CURRENT_USER\Software\Psiphon3
Operation:writeName:SkipAutoConnect
Value:
0
(PID) Process:(2124) psiphon3.exeKey:HKEY_CLASSES_ROOT\psiphon
Operation:writeName:URL Protocol
Value:
(PID) Process:(2124) psiphon3.exeKey:HKEY_CURRENT_USER\Software\Psiphon3
Operation:writeName:SSHParentProxyHost
Value:
(PID) Process:(2124) psiphon3.exeKey:HKEY_CURRENT_USER\Software\Psiphon3
Operation:writeName:SSHParentProxyUsername
Value:
(PID) Process:(2124) psiphon3.exeKey:HKEY_CURRENT_USER\Software\Psiphon3
Operation:writeName:SSHParentProxyPassword
Value:
(PID) Process:(2124) psiphon3.exeKey:HKEY_CURRENT_USER\Software\Psiphon3
Operation:writeName:SSHParentProxyDomain
Value:
(PID) Process:(2124) psiphon3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2124) psiphon3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2124) psiphon3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
Executable files
3
Suspicious files
29
Text files
52
Unknown types
13

Dropped files

PID
Process
Filename
Type
2124psiphon3.exeC:\Users\admin\AppData\Local\Temp\dat23EE.tmpeot
MD5:
SHA256:
2124psiphon3.exeC:\Users\admin\AppData\Local\Psiphon3\psicash\psicashdatastore.prod.temptext
MD5:
SHA256:
2124psiphon3.exeC:\Users\admin\AppData\Local\Psiphon3\psicash\psicashdatastore.prod.committext
MD5:
SHA256:
2124psiphon3.exeC:\Users\admin\AppData\Local\Psiphon3\psicash\psicashdatastore.prodbinary
MD5:
SHA256:
2124psiphon3.exeC:\Users\admin\AppData\Local\Psiphon3\psicash\psicashdatastore.prod.2.temptext
MD5:
SHA256:
2124psiphon3.exeC:\Users\admin\AppData\Local\Psiphon3\psicash\psicashdatastore.prod.2.committext
MD5:
SHA256:
2124psiphon3.exeC:\Users\admin\AppData\Local\Psiphon3\psicash\psicashdatastore.prod.2binary
MD5:
SHA256:
2124psiphon3.exeC:\Users\admin\AppData\Local\Psiphon3\psiphon.configbinary
MD5:
SHA256:
2124psiphon3.exeC:\Users\admin\AppData\Local\Psiphon3\server_list.dattext
MD5:
SHA256:
2124psiphon3.exeC:\Users\admin\AppData\Local\Temp\psiphon-tunnel-core.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
27
DNS requests
1
Threats
5

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
2364
psiphon-tunnel-core.exe
169.150.247.35:443
b-cdn.net
GB
unknown
2364
psiphon-tunnel-core.exe
172.104.158.39:443
unknown
2364
psiphon-tunnel-core.exe
196.245.157.26:554
unknown
2364
psiphon-tunnel-core.exe
37.120.153.139:53
M247 Ltd
SE
unknown
2364
psiphon-tunnel-core.exe
5.254.31.236:22
Voxility LLP
ES
unknown
2364
psiphon-tunnel-core.exe
196.245.172.53:22
Packet Exchange Limited
ES
unknown

DNS requests

Domain
IP
Reputation
b-cdn.net
  • 169.150.247.35
whitelisted

Threats

PID
Process
Class
Message
2364
psiphon-tunnel-core.exe
Misc activity
ET INFO SSH-2.0-Go version string Observed in Network Traffic
2364
psiphon-tunnel-core.exe
Attempted Information Leak
ET SCAN Potential SSH Scan OUTBOUND
2364
psiphon-tunnel-core.exe
Potential Corporate Privacy Violation
ET DNS Non-DNS or Non-Compliant DNS traffic on DNS port Opcode 8 through 15 set
Unknown Traffic
ET JA3 Hash - Possible Malware - Fake Firefox Font Update
Potential Corporate Privacy Violation
ET DNS Non-DNS or Non-Compliant DNS traffic on DNS port Opcode 6 or 7 set
Process
Message
psiphon3.exe
psiphon3.exe
2024-04-12T21:27:00.895Z:
psiphon3.exe
2024-04-12T21:27:00.895Z:
psiphon3.exe
Psiphon Tunnel connecting...
psiphon3.exe
Client Version: 182
psiphon3.exe
psiphon3.exe
psiphon3.exe
psiphon3.exe
psiphon3.exe
{"data":{"data":{"message":"Config migration: need migration"},"noticeType":"Info","timestamp":"2024-04-12T21:27:01.748Z"},"msg":"CoreNotice","timestamp!!timestamp":"2024-04-12T21:27:01.792Z"}