File name:

Plants vs Zombies main.pak Patcherer.exe

Full analysis: https://app.any.run/tasks/81af8a3c-e495-43ff-8b5b-e922037e1ffd
Verdict: Malicious activity
Analysis date: November 23, 2023, 01:18:19
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, RAR self-extracting archive
MD5:

657DC36A147ED82180F35BCDBA675643

SHA1:

749B0A637DC66E2A0E70E211EE43C16055F4063D

SHA256:

4A65B0E6984EEB5028002F744785DDC64F55FE98A9CA5E5DD32CC544BF1A1574

SSDEEP:

49152:ppmPNrHbLXKBijhg+dHTjlPElvD6P+1mozKMZ8pxFlyB6k1pQbgBJ9oh+aIJncXZ:pY9KstgiT58D6mIouMKpblyB62yMJGhb

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Plants vs Zombies main.pak Patcherer.exe (PID: 3460)
  • SUSPICIOUS

    • Reads the Internet Settings

      • Plants vs Zombies main.pak Patcherer.exe (PID: 3460)
    • Reads Microsoft Outlook installation path

      • Plants vs Zombies main.pak Patcherer.exe (PID: 3460)
    • Reads Internet Explorer settings

      • Plants vs Zombies main.pak Patcherer.exe (PID: 3460)
    • Executing commands from a ".bat" file

      • Plants vs Zombies main.pak Patcherer.exe (PID: 3460)
    • Starts CMD.EXE for commands execution

      • Plants vs Zombies main.pak Patcherer.exe (PID: 3460)
  • INFO

    • Reads the computer name

      • Plants vs Zombies main.pak Patcherer.exe (PID: 3460)
      • PATCH.exe (PID: 3488)
    • Checks supported languages

      • Plants vs Zombies main.pak Patcherer.exe (PID: 3460)
      • PATCH.exe (PID: 3488)
      • quickbms.exe (PID: 3444)
    • Checks proxy server information

      • Plants vs Zombies main.pak Patcherer.exe (PID: 3460)
    • Reads the machine GUID from the registry

      • Plants vs Zombies main.pak Patcherer.exe (PID: 3460)
    • Manual execution by a user

      • notepad.exe (PID: 3020)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2009:12:12 11:11:36+01:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 67584
InitializedDataSize: 37376
UninitializedDataSize: -
EntryPoint: 0xa7cb
OSVersion: 5
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start plants vs zombies main.pak patcherer.exe no specs cmd.exe no specs patch.exe no specs quickbms.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3020"C:\Windows\System32\NOTEPAD.EXE" C:\Users\admin\Desktop\PVZ\Patcher.batC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3404C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\PVZ\Patcher.bat" "C:\Windows\System32\cmd.exePlants vs Zombies main.pak Patcherer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3444quickbms patchmain.exe main.pak .C:\Users\admin\Desktop\PVZ\quickbms.execmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
4294967295
Modules
Images
c:\users\admin\desktop\pvz\quickbms.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\shlwapi.dll
3460"C:\Users\admin\Desktop\Plants vs Zombies main.pak Patcherer.exe" C:\Users\admin\Desktop\Plants vs Zombies main.pak Patcherer.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\plants vs zombies main.pak patcherer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3488PATCH.exe C:\Users\admin\Desktop\PVZ\PATCH.execmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\pvz\patch.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
664
Read events
652
Write events
12
Delete events
0

Modification events

(PID) Process:(3460) Plants vs Zombies main.pak Patcherer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3460) Plants vs Zombies main.pak Patcherer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000059010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3460) Plants vs Zombies main.pak Patcherer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3460) Plants vs Zombies main.pak Patcherer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3460) Plants vs Zombies main.pak Patcherer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3460) Plants vs Zombies main.pak Patcherer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3460) Plants vs Zombies main.pak Patcherer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3460) Plants vs Zombies main.pak Patcherer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
Executable files
2
Suspicious files
5
Text files
184
Unknown types
0

Dropped files

PID
Process
Filename
Type
3460Plants vs Zombies main.pak Patcherer.exeC:\Users\admin\Desktop\PVZ\quickbms.exeexecutable
MD5:B6F8E7509107F5E4D4AB37A33C861F67
SHA256:F54B1ABE028E339766B50DBC7E8990C3DAFE83E2DF7F4D25303D43B8F942B328
3460Plants vs Zombies main.pak Patcherer.exeC:\Users\admin\Desktop\PVZ\Patcher.battext
MD5:D46B9AAA1F980A0FD00A218EA901A242
SHA256:7600974A335E7B6AF9100B7CD229754BFCEC9C3F19F959559E31F633E63081FF
3460Plants vs Zombies main.pak Patcherer.exeC:\Users\admin\Desktop\PVZ\PATCH.exeexecutable
MD5:694770374EF672C697E23DA747F5A925
SHA256:A1E8679C9D01443E85AD95AB1578619D9624A4AC2FE7981FC705E9249AB8EE15
3460Plants vs Zombies main.pak Patcherer.exeC:\Users\admin\Desktop\PVZ\src\bcl\bcltest.ctext
MD5:0A3C6D6EC0BEDEE4A502351D116FD4B6
SHA256:180139D828E2C08CB5C07753B57A1B9F26C4ED195FB2906F7C91B4B2E6656AE1
3460Plants vs Zombies main.pak Patcherer.exeC:\Users\admin\Desktop\PVZ\patchmain.exetext
MD5:E0F55B71E82C97F2634B00A4C7A117C8
SHA256:1545885C31E354359375608B30FC35AB94A86EC138FE974422DCC3A7961618BA
3460Plants vs Zombies main.pak Patcherer.exeC:\Users\admin\Desktop\PVZ\src\bcl\huffman.htext
MD5:9B810309D5A549F0678AC57C648D561D
SHA256:48F32686F177C1AA0D12AAEDE5762A8680B59F2F38C4588AFA5317387131E881
3460Plants vs Zombies main.pak Patcherer.exeC:\Users\admin\Desktop\PVZ\PopCap_Logo.jpgimage
MD5:153E5E26CE390F1C67F295D41588BDF7
SHA256:2F8A5F2CD13AB79280B7335001642547F5DCA39FCFBB90E2EFCBF1ABF2394ACF
3460Plants vs Zombies main.pak Patcherer.exeC:\Users\admin\Desktop\PVZ\src\bcl\huffman.ctext
MD5:D056F0A3D00F635134817B9610F1259A
SHA256:CEE0511995A3221244CF1FA1ED200B98C0D6E7A9BB0B5E6A9009175CE0FF5592
3460Plants vs Zombies main.pak Patcherer.exeC:\Users\admin\Desktop\PVZ\src\bcl\Makefiletext
MD5:49C1943DB59DEB19EB8F06B1C8A9C9ED
SHA256:DD5C7DC1AA68901C41A0591848EBCE06B99EFBB84207B0E245A17096D0D70E8E
3460Plants vs Zombies main.pak Patcherer.exeC:\Users\admin\Desktop\PVZ\src\bcl\rice.htext
MD5:561E7C4236DE5A3AAB36108A051F9EBF
SHA256:6142094A182EB3F1446CF467E89E34B63372578C0147DE9CFB680E90C7215156
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info