File name:

wire

Full analysis: https://app.any.run/tasks/8bdf0d85-5934-4795-8d63-ace7c5210fc1
Verdict: Malicious activity
Analysis date: January 27, 2024, 17:48:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows
MD5:

85316F113FA3FB8AF8015BBC1206C287

SHA1:

3C3BD4F5BB97E10325DEB16D1E6D114A881494EC

SHA256:

48CCC89A0AA3CC315102548EB55BAA8C7E374739F69E341C3BEC54C4B32F6A0F

SSDEEP:

98304:rxcgoJ/jc7WPwwf1Jge1UZ5yDlbBww/0S7DfYUj12SyH1Hw1yhH17X47VJnlLBZs:0YDEyrcO8D

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • wire.exe (PID: 2580)
    • Actions looks like stealing of personal data

      • wire.exe (PID: 2580)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Checks supported languages

      • wire.exe (PID: 2580)
      • wire.exe (PID: 2904)
    • Reads the computer name

      • wire.exe (PID: 2580)
      • wire.exe (PID: 2904)
    • Reads the machine GUID from the registry

      • wire.exe (PID: 2580)
      • wire.exe (PID: 2904)
    • Manual execution by a user

      • wire.exe (PID: 2904)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:01:27 18:48:28+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 26624
InitializedDataSize: 9216
UninitializedDataSize: -
EntryPoint: 0x82bcd1
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start wire.exe wire.exe

Process information

PID
CMD
Path
Indicators
Parent process
2580"C:\Users\admin\Desktop\wire.exe" C:\Users\admin\Desktop\wire.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Modules
Images
c:\users\admin\desktop\wire.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2904"C:\Users\admin\Desktop\wire.exe" C:\Users\admin\Desktop\wire.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\wire.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
4 443
Read events
4 443
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
518
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2580wire.exeC:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\profile_count_308046B0AF4A39CB.json.pbinary
MD5:1C0E6CDD991A0587DB9741D3449D8127
SHA256:91FDC6E53D8E02D85CEEE5E9CEA5847D79520E075FE498DB503FA2172916D28C
2580wire.exeC:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\UpdateLock-308046B0AF4A39CB.pbinary
MD5:CC39E419265DF0725933E37D315441B8
SHA256:DE4DFEE9A2D86F97595A4BC5DF024DAEA6E36C2A82ADACBFCC4D6EF778C9C851
2580wire.exeC:\ProgramData\Mozilla-1de4eec8-1241-4177-a864-e594e8d1fb38\profile_count_308046B0AF4A39CB.jsonbinary
MD5:1C0E6CDD991A0587DB9741D3449D8127
SHA256:91FDC6E53D8E02D85CEEE5E9CEA5847D79520E075FE498DB503FA2172916D28C
2580wire.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\AccLR.cab
MD5:
SHA256:
2580wire.exeC:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\AccLR.cab
MD5:
SHA256:
2580wire.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\AccessMUI.msi.pbinary
MD5:A83A2202703D50A73CBEB61DE9A05046
SHA256:FE1C6E42313F210F7E611B272E4F911302CAF8C8562DCDBE7F72E2C79217F287
2580wire.exeC:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\AccessMUI.msibinary
MD5:554E55A28B116E0AD9B0CB057F3758E4
SHA256:B59D97C4D957B09167BAE14786B3F77C7A59AA4193E7488B737B6DA879EBB1B6
2580wire.exeC:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\AccessMUI.xmlbinary
MD5:7170CA2D610CD0688EA9E2DC5F135F76
SHA256:A59EC972B33EF7A1553F63D5C52F4596ED039F702B873C809EC4C4A8A9EE2A49
2580wire.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\AccessMUI.msibinary
MD5:A83A2202703D50A73CBEB61DE9A05046
SHA256:FE1C6E42313F210F7E611B272E4F911302CAF8C8562DCDBE7F72E2C79217F287
2580wire.exeC:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\branding.xml.pbinary
MD5:96AEBEB10E309290A64BEDA4DB2EC71E
SHA256:6552E99F14CCB1EEBA9F99D994CCC8E1B7F0DEA9D3E7C0291E25F6D6820D20F8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info