| File name: | MM.exe |
| Full analysis: | https://app.any.run/tasks/33085d26-dc7f-4a88-9899-2703c2cba882 |
| Verdict: | Malicious activity |
| Analysis date: | October 23, 2023, 17:03:55 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 2CD0D5BB3F14242F5551E9EB152F0A79 |
| SHA1: | 69D482A116E6344C2F5280FE7DEA9AA8E2017A69 |
| SHA256: | 465FE0F5CABC4066C184C784376111D6E9B62DA34F7E35597503C4D82C3BED14 |
| SSDEEP: | 1536:Xq6/2tUbpcz7kBLeJCkGH1cQHxxXcz4sWjcdW8vDHStf9ub7qoEEw:67tspczoLeJdYcQHxx+rrHStf9u3qR |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:10:23 19:03:44+02:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 11 |
| CodeSize: | 46080 |
| InitializedDataSize: | 83456 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x617e |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2752 | "C:\Windows\System32\runas.exe" /user:administrator C:\Users\admin\Desktop\MM.exe | C:\Windows\System32\runas.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Run As Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3208 | C:\Users\admin\Desktop\MM.exe | C:\Users\admin\Desktop\MM.exe | runas.exe | ||||||||||||
User: Administrator Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3744 | C:\Windows\system32\rundll32.exe C:\Windows\system32\gameux.dll,GameUXShim {29dfdaf6-2655-4d7d-9dae-112ce811cf33};C:\Users\admin\Desktop\MM.exe;3208 | C:\Windows\System32\rundll32.exe | MM.exe | ||||||||||||
User: Administrator Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3744 | rundll32.exe | C:\Users\Administrator\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Games\Steam Dark Messiah Might and Magic Single Player™.lnk | binary | |
MD5:BF6158876154CB863F66D7ECA99F0EF8 | SHA256:E8059EF712B92E9FB5B98DD4EBC9E72F04D5D396FC1CE30952022A845265331D | |||
| 3744 | rundll32.exe | C:\Users\Administrator\AppData\Local\Microsoft\Windows\GameExplorer\{F5233468-02FE-421B-AA0C-E0E0739C2D20}\PlayTasks\0\Play.lnk | binary | |
MD5:A555CEB39BEE28DC8F4D5DEFA2CFBED7 | SHA256:2A60CBEF415AE8139ED8D4D117C3C75FBF04620B8243BD0AADE78B624784B31F | |||
| 3208 | MM.exe | C:\Users\ADMINI~1\AppData\Local\Temp\tmp3DDF.tmp | compressed | |
MD5:F586456513E861D74AEC5853E52CC082 | SHA256:2DBBE0AE258477D5205F35423D0488353448B0015F091844A76C328A40F9491C | |||
| 3208 | MM.exe | C:\Users\ADMINI~1\AppData\Local\Temp\tmp4227.tmp | compressed | |
MD5:528C1E2C5A15A62E2CCC266622A13E76 | SHA256:13EAB6D1EE581B14E9B36599A4E92E9982A2B6BC4C541F493F5672DF1A83293F | |||
| 3208 | MM.exe | C:\Users\ADMINI~1\AppData\Local\Temp\tmp3CC4.tmp | compressed | |
MD5:F96E26C8C06EFDD608CC31730CCFA114 | SHA256:E0A5069A2F747327A8C98D95E2737ED97E2DA4AC75740DC70BFDA121384A6D7D | |||
| 3208 | MM.exe | C:\Users\ADMINI~1\AppData\Local\Temp\tmp4546.tmp | compressed | |
MD5:A64356CC51BF4C1DE5A2D29E63943F85 | SHA256:F23D901B3FBA7CA84A4F916A40C1A2FF469F7AA868DBE15DEACF9396471F56EC | |||
| 3208 | MM.exe | C:\Users\ADMINI~1\AppData\Local\Temp\tmp475B.tmp | compressed | |
MD5:16800E2D1B446B507B9656431953F914 | SHA256:CF445E14D6EDD3C2EDEA5BAE2257195F0A2E66AFAFA37E0B16E0A2B5F1FBFA55 | |||
| 3208 | MM.exe | C:\Users\ADMINI~1\AppData\Local\Temp\tmp443C.tmp | compressed | |
MD5:649B1BE10FE96046018628C482CD15F8 | SHA256:0D1E0B444FB822656F70C7B861BC702E1FD06D398FE8CAE11017EEA2C29C19C2 | |||
| 3208 | MM.exe | C:\Users\ADMINI~1\AppData\Local\Temp\tmp3CB4.tmp | compressed | |
MD5:493CBD3287BA8F2C3CEEB874AA51ACE1 | SHA256:B73090D5E120CBE0FB375C558166C724F62744AAD84465823050A132A0B815A2 | |||
| 3208 | MM.exe | C:\Users\ADMINI~1\AppData\Local\Temp\tmp4060.tmp | compressed | |
MD5:B232F7BE1A626EE3C0504C569C820BDD | SHA256:BC4EF146E98A48EB52A780B4D3DD5290C287E44F9955A217956121DBF1CD2A78 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3744 | rundll32.exe | GET | 302 | 23.218.210.69:80 | http://go.microsoft.com/fwlink?linkid=30219&locale=en-US&clientType=VISTA_GAMES&clientVersion=6.1.2 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3744 | rundll32.exe | 23.218.210.69:80 | go.microsoft.com | AKAMAI-AS | DE | unknown |
3744 | rundll32.exe | 65.55.186.115:80 | movie.metaservices.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3208 | MM.exe | 74.125.200.26:25 | alt2.gmail-smtp-in.l.google.com | GOOGLE | US | whitelisted |
3208 | MM.exe | 67.195.204.79:25 | mta5.am0.yahoodns.net | YAHOO-BF1 | US | unknown |
3208 | MM.exe | 212.27.48.6:25 | mx1.free.fr | Free SAS | FR | unknown |
3208 | MM.exe | 67.195.204.72:25 | mta5.am0.yahoodns.net | YAHOO-BF1 | US | unknown |
3208 | MM.exe | 212.27.42.58:25 | mx2.free.fr | Free SAS | FR | unknown |
Domain | IP | Reputation |
|---|---|---|
go.microsoft.com |
| whitelisted |
movie.metaservices.microsoft.com |
| whitelisted |
gmail.com |
| unknown |
yahoo.com |
| unknown |
alt2.gmail-smtp-in.l.google.com |
| whitelisted |
mta5.am0.yahoodns.net |
| malicious |
free.fr |
| unknown |
mx1.free.fr |
| unknown |
mta7.am0.yahoodns.net |
| whitelisted |
mx2.free.fr |
| unknown |