File name:

MM.exe

Full analysis: https://app.any.run/tasks/33085d26-dc7f-4a88-9899-2703c2cba882
Verdict: Malicious activity
Analysis date: October 23, 2023, 17:03:55
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

2CD0D5BB3F14242F5551E9EB152F0A79

SHA1:

69D482A116E6344C2F5280FE7DEA9AA8E2017A69

SHA256:

465FE0F5CABC4066C184C784376111D6E9B62DA34F7E35597503C4D82C3BED14

SSDEEP:

1536:Xq6/2tUbpcz7kBLeJCkGH1cQHxxXcz4sWjcdW8vDHStf9ub7qoEEw:67tspczoLeJdYcQHxx+rrHStf9u3qR

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Unusual connection from system programs

      • rundll32.exe (PID: 3744)
    • Actions looks like stealing of personal data

      • MM.exe (PID: 3208)
  • SUSPICIOUS

    • Reads the Internet Settings

      • rundll32.exe (PID: 3744)
    • Detected use of alternative data streams (AltDS)

      • MM.exe (PID: 3208)
    • Connects to SMTP port

      • MM.exe (PID: 3208)
  • INFO

    • Checks supported languages

      • MM.exe (PID: 3208)
    • Reads the computer name

      • MM.exe (PID: 3208)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:10:23 19:03:44+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 46080
InitializedDataSize: 83456
UninitializedDataSize: -
EntryPoint: 0x617e
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
3
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start runas.exe no specs mm.exe rundll32.exe

Process information

PID
CMD
Path
Indicators
Parent process
2752"C:\Windows\System32\runas.exe" /user:administrator C:\Users\admin\Desktop\MM.exeC:\Windows\System32\runas.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Run As Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\runas.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\credui.dll
3208C:\Users\admin\Desktop\MM.exeC:\Users\admin\Desktop\MM.exe
runas.exe
User:
Administrator
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\windows\system32\ntdll.dll
c:\users\admin\desktop\mm.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3744C:\Windows\system32\rundll32.exe C:\Windows\system32\gameux.dll,GameUXShim {29dfdaf6-2655-4d7d-9dae-112ce811cf33};C:\Users\admin\Desktop\MM.exe;3208C:\Windows\System32\rundll32.exe
MM.exe
User:
Administrator
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\sechost.dll
Total events
733
Read events
733
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
11
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3744rundll32.exeC:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games\Steam Dark Messiah Might and Magic Single Player™.lnkbinary
MD5:BF6158876154CB863F66D7ECA99F0EF8
SHA256:E8059EF712B92E9FB5B98DD4EBC9E72F04D5D396FC1CE30952022A845265331D
3744rundll32.exeC:\Users\Administrator\AppData\Local\Microsoft\Windows\GameExplorer\{F5233468-02FE-421B-AA0C-E0E0739C2D20}\PlayTasks\0\Play.lnkbinary
MD5:A555CEB39BEE28DC8F4D5DEFA2CFBED7
SHA256:2A60CBEF415AE8139ED8D4D117C3C75FBF04620B8243BD0AADE78B624784B31F
3208MM.exeC:\Users\ADMINI~1\AppData\Local\Temp\tmp3DDF.tmpcompressed
MD5:F586456513E861D74AEC5853E52CC082
SHA256:2DBBE0AE258477D5205F35423D0488353448B0015F091844A76C328A40F9491C
3208MM.exeC:\Users\ADMINI~1\AppData\Local\Temp\tmp4227.tmpcompressed
MD5:528C1E2C5A15A62E2CCC266622A13E76
SHA256:13EAB6D1EE581B14E9B36599A4E92E9982A2B6BC4C541F493F5672DF1A83293F
3208MM.exeC:\Users\ADMINI~1\AppData\Local\Temp\tmp3CC4.tmpcompressed
MD5:F96E26C8C06EFDD608CC31730CCFA114
SHA256:E0A5069A2F747327A8C98D95E2737ED97E2DA4AC75740DC70BFDA121384A6D7D
3208MM.exeC:\Users\ADMINI~1\AppData\Local\Temp\tmp4546.tmpcompressed
MD5:A64356CC51BF4C1DE5A2D29E63943F85
SHA256:F23D901B3FBA7CA84A4F916A40C1A2FF469F7AA868DBE15DEACF9396471F56EC
3208MM.exeC:\Users\ADMINI~1\AppData\Local\Temp\tmp475B.tmpcompressed
MD5:16800E2D1B446B507B9656431953F914
SHA256:CF445E14D6EDD3C2EDEA5BAE2257195F0A2E66AFAFA37E0B16E0A2B5F1FBFA55
3208MM.exeC:\Users\ADMINI~1\AppData\Local\Temp\tmp443C.tmpcompressed
MD5:649B1BE10FE96046018628C482CD15F8
SHA256:0D1E0B444FB822656F70C7B861BC702E1FD06D398FE8CAE11017EEA2C29C19C2
3208MM.exeC:\Users\ADMINI~1\AppData\Local\Temp\tmp3CB4.tmpcompressed
MD5:493CBD3287BA8F2C3CEEB874AA51ACE1
SHA256:B73090D5E120CBE0FB375C558166C724F62744AAD84465823050A132A0B815A2
3208MM.exeC:\Users\ADMINI~1\AppData\Local\Temp\tmp4060.tmpcompressed
MD5:B232F7BE1A626EE3C0504C569C820BDD
SHA256:BC4EF146E98A48EB52A780B4D3DD5290C287E44F9955A217956121DBF1CD2A78
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
14
DNS requests
13
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3744
rundll32.exe
GET
302
23.218.210.69:80
http://go.microsoft.com/fwlink?linkid=30219&locale=en-US&clientType=VISTA_GAMES&clientVersion=6.1.2
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2656
svchost.exe
239.255.255.250:1900
whitelisted
3744
rundll32.exe
23.218.210.69:80
go.microsoft.com
AKAMAI-AS
DE
unknown
3744
rundll32.exe
65.55.186.115:80
movie.metaservices.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
3208
MM.exe
74.125.200.26:25
alt2.gmail-smtp-in.l.google.com
GOOGLE
US
whitelisted
3208
MM.exe
67.195.204.79:25
mta5.am0.yahoodns.net
YAHOO-BF1
US
unknown
3208
MM.exe
212.27.48.6:25
mx1.free.fr
Free SAS
FR
unknown
3208
MM.exe
67.195.204.72:25
mta5.am0.yahoodns.net
YAHOO-BF1
US
unknown
3208
MM.exe
212.27.42.58:25
mx2.free.fr
Free SAS
FR
unknown

DNS requests

Domain
IP
Reputation
go.microsoft.com
  • 23.218.210.69
whitelisted
movie.metaservices.microsoft.com
  • 65.55.186.115
whitelisted
gmail.com
unknown
yahoo.com
unknown
alt2.gmail-smtp-in.l.google.com
  • 74.125.200.26
whitelisted
mta5.am0.yahoodns.net
  • 67.195.204.79
  • 67.195.204.74
  • 67.195.204.77
  • 67.195.228.110
  • 67.195.204.72
  • 67.195.228.111
  • 67.195.228.109
  • 98.136.96.76
malicious
free.fr
unknown
mx1.free.fr
  • 212.27.48.6
  • 212.27.48.7
unknown
mta7.am0.yahoodns.net
  • 67.195.204.72
  • 67.195.204.74
  • 98.136.96.77
  • 67.195.204.73
  • 67.195.228.106
  • 67.195.204.79
  • 98.136.96.74
  • 67.195.204.77
whitelisted
mx2.free.fr
  • 212.27.42.58
  • 212.27.42.59
unknown

Threats

No threats detected
No debug info