File name: | ymsgres.exe |
Full analysis: | https://app.any.run/tasks/01e7c6c3-f140-4b46-a356-cfd3031b016e |
Verdict: | Malicious activity |
Analysis date: | January 16, 2024, 18:45:21 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | C93DC3397F828D0080466250B3BC69CE |
SHA1: | 61814880C79DAADDFC87FBEB501EF9F87AE7D055 |
SHA256: | 47992A3EFBA1DB0A465322C5D227E2E48E6BF3E65D21FA201DF82860F147EC7D |
SSDEEP: | 98304:03/jJcWr3O87TR8jdED3yXj4nxVJHwVFXFxgcQnEy5WaEu6Svu52D+eB6QpvvWWU:Uy+U |
.exe | | | Win32 Executable MS Visual C++ 4.x (88.6) |
---|---|---|
.dll | | | Win32 Dynamic Link Library (generic) (4.3) |
.exe | | | Win32 Executable (generic) (2.9) |
.exe | | | Win16/32 Executable Delphi generic (1.3) |
.exe | | | Generic Win/DOS Executable (1.3) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 1997:06:16 23:32:11+02:00 |
ImageFileCharacteristics: | Executable, No line numbers, No symbols, 32-bit |
PEType: | PE32 |
LinkerVersion: | 4.2 |
CodeSize: | 512 |
InitializedDataSize: | 2491392 |
UninitializedDataSize: | - |
EntryPoint: | 0x1000 |
OSVersion: | 4 |
ImageVersion: | - |
SubsystemVersion: | 4 |
Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
120 | "C:\Users\admin\AppData\Local\Temp\ymsgres.exe" | C:\Users\admin\AppData\Local\Temp\ymsgres.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
188 | C:\Windows\regedit.exe /s "C:\PROGRA~1\Yahoo!\MESSEN~1\Default.reg" | C:\Windows\regedit.exe | — | YPager.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Editor Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
712 | "C:\Users\admin\AppData\Local\Temp\~GLJ3069.TMP" C:\PROGRA~1\Yahoo!\MESSEN~1\ft.dll | C:\Users\admin\AppData\Local\Temp\~GLJ3069.TMP | — | ntvdm.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
1112 | "C:\Users\admin\AppData\Local\Temp\~GLJ3069.TMP" C:\PROGRA~1\Yahoo!\MESSEN~1\MyYahoo.dll | C:\Users\admin\AppData\Local\Temp\~GLJ3069.TMP | — | ntvdm.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
1264 | "C:\Users\admin\AppData\Local\Temp\~GLJ3069.TMP" C:\PROGRA~1\Yahoo!\MESSEN~1\ypagerps.dll | C:\Users\admin\AppData\Local\Temp\~GLJ3069.TMP | — | ntvdm.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
1344 | C:\Windows\regedit.exe /s "C:\Program Files\Yahoo!\Messenger\intl.reg" | C:\Windows\regedit.exe | — | ntvdm.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Editor Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1544 | C:\Windows\regedit.exe /s "C:\PROGRA~1\Yahoo!\MESSEN~1\default.reg" | C:\Windows\regedit.exe | — | ntvdm.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Registry Editor Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1576 | "C:\Users\admin\AppData\Local\Temp\~GLJ3069.TMP" C:\PROGRA~1\Yahoo!\MESSEN~1\proxy.dll | C:\Users\admin\AppData\Local\Temp\~GLJ3069.TMP | — | ntvdm.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
1588 | "C:\Users\admin\AppData\Local\Temp\~GLJ3069.TMP" C:\PROGRA~1\Yahoo!\MESSEN~1\yacscom.dll | C:\Users\admin\AppData\Local\Temp\~GLJ3069.TMP | — | ntvdm.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
1592 | C:\PROGRA~1\Yahoo!\MESSEN~1\YServer.exe /REGSERVER | C:\Program Files\Yahoo!\Messenger\YServer.exe | — | ntvdm.exe | |||||||||||
User: admin Company: Yahoo! Inc. Integrity Level: HIGH Description: YServer Module Exit code: 0 Version: 2, 0, 0, 6 Modules
|
(PID) Process: | (2420) ntvdm.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (2420) ntvdm.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (2420) ntvdm.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (2420) ntvdm.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (1344) regedit.exe | Key: | HKEY_CURRENT_USER\Software\Yahoo\Pager |
Operation: | write | Name: | PreLogin |
Value: http://msg.edit.yahoo.com/config/ | |||
(PID) Process: | (1344) regedit.exe | Key: | HKEY_CURRENT_USER\Software\Yahoo\Pager\IMUnified |
Operation: | write | Name: | Disable Imip |
Value: 1 | |||
(PID) Process: | (1344) regedit.exe | Key: | HKEY_CURRENT_USER\Software\Yahoo\Pager\yurl |
Operation: | write | Name: | Finance Disclaimer |
Value: http://msg.edit.yahoo.com/config/jlb | |||
(PID) Process: | (1576) ~GLJ3069.TMP | Key: | HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\CLSID\{CAFEEFAC-0017-0000-0129-ABCDEFFEDCBC}\InprocServer32 |
Operation: | write | Name: | ThreadingModel |
Value: Apartment | |||
(PID) Process: | (1576) ~GLJ3069.TMP | Key: | HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\CLSID\{CAFEEFAC-0017-0000-0130-ABCDEFFEDCBB}\InprocServer32 |
Operation: | write | Name: | ThreadingModel |
Value: Apartment | |||
(PID) Process: | (1576) ~GLJ3069.TMP | Key: | HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-500_CLASSES\CLSID\{CAFEEFAC-0017-0000-0131-ABCDEFFEDCBB}\InprocServer32 |
Operation: | write | Name: | ThreadingModel |
Value: Apartment |
PID | Process | Filename | Type | |
---|---|---|---|---|
2420 | ntvdm.exe | C:\Windows\~GLC0000.TMP | executable | |
MD5:AE81A06701829CF7822192A9391966A0 | SHA256:4E05684FBD317AC64DC575246ACCB4BA9F1FB5ABB1C55F8A927E171BEB3B62DE | |||
2420 | ntvdm.exe | C:\USERS\ADMIN\APPDATA\LOCAL\TEMP\~GLJ3069.TMP | executable | |
MD5:6F608D264503796BEBD7CD66B687BE92 | SHA256:49833D2820AFB1D7409DFBD916480F2CDF5787D2E2D94166725BEB9064922D5D | |||
2208 | ymsgres.exe | C:\Users\admin\AppData\Local\Temp\GLB12B8.tmp | executable | |
MD5:2E95CF9158819AB5528CB6EFADADFB2E | SHA256:1808F34FC73295E66506D0E97DB0DF936A822855421D7CC57A5DD117F5037F50 | |||
2420 | ntvdm.exe | C:\Users\admin\AppData\Local\Temp\scs1308.tmp | text | |
MD5:4C361DEA398F7AEEF49953BDC0AB4A9B | SHA256:06D61C23E6CA59B9DDAD1796ECCC42C032CD8F6F424AF6CFEE5D085D36FF7DFD | |||
2420 | ntvdm.exe | C:\Users\admin\AppData\Local\Temp\scs1307.tmp | text | |
MD5:8CF6DDB5AA59B49F34B967CD46F013B6 | SHA256:EE06792197C3E025B84860A72460EAF628C66637685F8C52C5A08A9CC35D376C | |||
2420 | ntvdm.exe | C:\Program Files\Yahoo!\Messenger\~GLH0007.TMP | executable | |
MD5:5380019F74F323C2BAA2498457A2BA7E | SHA256:47D01ECCADF01F4173ED8B2CA2FC8751633094AE5C1154B87BCA8B9F53CD6CB5 | |||
2420 | ntvdm.exe | C:\Users\admin\AppData\Local\Temp\~GLH0003.TMP | text | |
MD5:FECB28A59A84DC11340AA93B9438D17C | SHA256:2B2C0CA252EF3C3E4612E5CA6B96DEAB3DAD7F7A08A47D00BB86A368EA5FE643 | |||
2420 | ntvdm.exe | C:\Program Files\Yahoo!\Messenger\~GLH0006.TMP | text | |
MD5:F75488B1D6EDF55BE39557E20D915715 | SHA256:B04933660A1D01503D0C6AD2E578EC47F0BD1C618CE4689813B121CC568D817F | |||
2420 | ntvdm.exe | C:\Program Files\Yahoo!\Messenger\UNWISE.INI | text | |
MD5:F75488B1D6EDF55BE39557E20D915715 | SHA256:B04933660A1D01503D0C6AD2E578EC47F0BD1C618CE4689813B121CC568D817F | |||
2420 | ntvdm.exe | C:\Program Files\Yahoo!\Messenger\UNWISE.EXE | executable | |
MD5:0938040C3F7EA59B340CBA84BBF1D875 | SHA256:EB89C26F108B4806920A5089C472C7F89C616D56AAE8D6F95594ABA55AF45C8C |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |