File name:

wire

Full analysis: https://app.any.run/tasks/8bdf0d85-5934-4795-8d63-ace7c5210fc1
Verdict: Malicious activity
Analysis date: January 27, 2024, 17:48:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows
MD5:

85316F113FA3FB8AF8015BBC1206C287

SHA1:

3C3BD4F5BB97E10325DEB16D1E6D114A881494EC

SHA256:

48CCC89A0AA3CC315102548EB55BAA8C7E374739F69E341C3BEC54C4B32F6A0F

SSDEEP:

98304:rxcgoJ/jc7WPwwf1Jge1UZ5yDlbBww/0S7DfYUj12SyH1Hw1yhH17X47VJnlLBZs:0YDEyrcO8D

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • wire.exe (PID: 2580)
    • Actions looks like stealing of personal data

      • wire.exe (PID: 2580)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Reads the machine GUID from the registry

      • wire.exe (PID: 2580)
      • wire.exe (PID: 2904)
    • Reads the computer name

      • wire.exe (PID: 2580)
      • wire.exe (PID: 2904)
    • Checks supported languages

      • wire.exe (PID: 2580)
      • wire.exe (PID: 2904)
    • Manual execution by a user

      • wire.exe (PID: 2904)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:01:27 18:48:28+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 26624
InitializedDataSize: 9216
UninitializedDataSize: -
EntryPoint: 0x82bcd1
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wire.exe wire.exe

Process information

PID
CMD
Path
Indicators
Parent process
2580"C:\Users\admin\Desktop\wire.exe" C:\Users\admin\Desktop\wire.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Modules
Images
c:\users\admin\desktop\wire.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2904"C:\Users\admin\Desktop\wire.exe" C:\Users\admin\Desktop\wire.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\wire.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
4 443
Read events
4 443
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
518
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2580wire.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\AccessMUI.xml.pbinary
MD5:96F879A9ADB8A9212824F407F031D85B
SHA256:EC65643299EEB29AA8531C5A774941A79E118A09BB54674E8FAD26ADDD6E1F9A
2580wire.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\AccessMUI.msibinary
MD5:A83A2202703D50A73CBEB61DE9A05046
SHA256:FE1C6E42313F210F7E611B272E4F911302CAF8C8562DCDBE7F72E2C79217F287
2580wire.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\AccessMUI.xmlbinary
MD5:96F879A9ADB8A9212824F407F031D85B
SHA256:EC65643299EEB29AA8531C5A774941A79E118A09BB54674E8FAD26ADDD6E1F9A
2580wire.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\AccLR.cab
MD5:
SHA256:
2580wire.exeC:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\AccLR.cab
MD5:
SHA256:
2580wire.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\branding.xml.pbinary
MD5:97727C2C9B98539B95CBCE8508134F4C
SHA256:09B32A254DE1F7CBAA9012E9BC16F94350B8AF85CB3A341F4A445505B8197402
2580wire.exeC:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\profile_count_308046B0AF4A39CB.jsonbinary
MD5:1C0E6CDD991A0587DB9741D3449D8127
SHA256:91FDC6E53D8E02D85CEEE5E9CEA5847D79520E075FE498DB503FA2172916D28C
2580wire.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\Setup.xml.pbinary
MD5:3B2669D23191EF6B287E79F356E3DF0D
SHA256:91BDA305C96576BDC96B1C245DA7DF2E54161D85BA6048ABC878B8B3200B3E3D
2580wire.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\AccessMUI.msi.pbinary
MD5:A83A2202703D50A73CBEB61DE9A05046
SHA256:FE1C6E42313F210F7E611B272E4F911302CAF8C8562DCDBE7F72E2C79217F287
2580wire.exeC:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\Setup.xmlbinary
MD5:F3CE4863FCBF7898EC515E5D53668190
SHA256:49F8152C72CFEAC72A4E0F7C52D70D643791A54C5B2A97E84482CBB5CD4C76F8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info