File name:

Acunetix Premium Activation Tool.exe

Full analysis: https://app.any.run/tasks/aca3843e-6ca6-452b-a762-0f7e9c9263c9
Verdict: Malicious activity
Analysis date: October 30, 2023, 05:51:29
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

BB612315F3A8DF67C64B933FAD04ED2C

SHA1:

62FF97C94602DE37C1046A5A129EE2C955852084

SHA256:

4C9C43F2EECE93A8996CB614D59E161B4824FF929555FAA3B05142DB49E0A3A3

SSDEEP:

98304:iQR79rMVOV0HTnW1Et5+zu9c/kU/v/EAMsg1W9y/AnUfD4JnMEUvI3v5V5wCqwMt:XqH6n38OctbBoQIZck08Jp9Vfex

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Starts NET.EXE for service management

      • cmd.exe (PID: 1824)
      • net.exe (PID: 284)
      • cmd.exe (PID: 2464)
      • net.exe (PID: 1644)
      • cmd.exe (PID: 712)
      • net.exe (PID: 2600)
      • cmd.exe (PID: 2620)
      • net.exe (PID: 1584)
    • Drops the executable file immediately after the start

      • Acunetix Premium Activation Tool.exe (PID: 2128)
  • SUSPICIOUS

    • Reads the BIOS version

      • Acunetix Premium Activation Tool.exe (PID: 2128)
    • Starts CMD.EXE for commands execution

      • Acunetix Premium Activation Tool.exe (PID: 2128)
  • INFO

    • Checks supported languages

      • Acunetix Premium Activation Tool.exe (PID: 2128)
    • Reads the machine GUID from the registry

      • Acunetix Premium Activation Tool.exe (PID: 2128)
    • Create files in a temporary directory

      • Acunetix Premium Activation Tool.exe (PID: 2128)
    • Process checks are UAC notifies on

      • Acunetix Premium Activation Tool.exe (PID: 2128)
    • Reads mouse settings

      • Acunetix Premium Activation Tool.exe (PID: 2128)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2023:10:29 18:00:56+01:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.16
CodeSize: 734208
InitializedDataSize: 9509888
UninitializedDataSize: -
EntryPoint: 0xfea058
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 23.9.23102.153
ProductVersionNumber: 23.9.23102.153
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (British)
CharacterSet: Unicode
Comments: www.Dr-FarFar.com
CompanyName: Dr.FarFar | www.Dr-FarFar.com
FileDescription: Acunetix Premium Activation Tool (ViP)
FileVersion: 23.9.231020153
InternalName: Acunetix Premium Activation Tool.exe
LegalCopyright: Copyright © Dr.FarFar
LegalTrademarks: www.Dr-FarFar.com
OriginalFileName: Acunetix Premium Activation Tool.exe
ProductName: Acunetix Premium Activation Tool (ViP)
ProductVersion: 23.9.231020153
AssemblyVersion: 23.9.231020153
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
14
Malicious processes
1
Suspicious processes
4

Behavior graph

Click at the process to see the details
start acunetix premium activation tool.exe cmd.exe no specs net.exe no specs net1.exe no specs cmd.exe no specs net.exe no specs net1.exe no specs cmd.exe no specs net.exe no specs net1.exe no specs cmd.exe no specs net.exe no specs net1.exe no specs acunetix premium activation tool.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
244C:\Windows\system32\net1 stop "Acunetix Database"C:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\browcli.dll
284net stop AcunetixC:\Windows\System32\net.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
712C:\Windows\system32\cmd.exe /C net start "Acunetix Database"C:\Windows\System32\cmd.exeAcunetix Premium Activation Tool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1584net start AcunetixC:\Windows\System32\net.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\net.exe
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
1644net stop "Acunetix Database"C:\Windows\System32\net.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\net.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\browcli.dll
c:\windows\system32\netutils.dll
1824C:\Windows\system32\cmd.exe /C net stop AcunetixC:\Windows\System32\cmd.exeAcunetix Premium Activation Tool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\cmd.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\usp10.dll
c:\windows\system32\gdi32.dll
2128"C:\Users\admin\AppData\Local\Temp\Acunetix Premium Activation Tool.exe" C:\Users\admin\AppData\Local\Temp\Acunetix Premium Activation Tool.exe
explorer.exe
User:
admin
Company:
Dr.FarFar | www.Dr-FarFar.com
Integrity Level:
HIGH
Description:
Acunetix Premium Activation Tool (ViP)
Exit code:
0
Version:
23.9.231020153
Modules
Images
c:\users\admin\appdata\local\temp\acunetix premium activation tool.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wsock32.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\version.dll
2160C:\Windows\system32\net1 stop AcunetixC:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\logoncli.dll
2160C:\Windows\system32\net1 start AcunetixC:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\net1.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\logoncli.dll
2464C:\Windows\system32\cmd.exe /C net stop "Acunetix Database"C:\Windows\System32\cmd.exeAcunetix Premium Activation Tool.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
Total events
176
Read events
176
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
3
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2128Acunetix Premium Activation Tool.exeC:\Users\admin\AppData\Local\Temp\autCCA2.tmpimage
MD5:04EF95DECF3B30DDC2BF049451D545D6
SHA256:FE8C6DA36EC29C411567E775CC1C75A4FA832F7ED9AB0522AB227A5027B89FBA
2128Acunetix Premium Activation Tool.exeC:\Users\admin\AppData\Local\Temp\autF740.tmpbinary
MD5:671249B261777F9088F253755032F14B
SHA256:E5011A4047A78E831C722EDDB457BC6B87B7EB0C2035699069EE0C0476A4E636
2128Acunetix Premium Activation Tool.exeC:\Users\admin\AppData\Local\Temp\autF72F.tmpbinary
MD5:081FBCDD9C513495381C2C338581A5FD
SHA256:E878736860D7D2956FBEC4FB73ADA9F02DF85D904A67751A7304938E27CEB918
2128Acunetix Premium Activation Tool.exeC:\Windows\system32\drivers\etc\hoststext
MD5:55A51E982C31EED6B268CF59726DBBCE
SHA256:DF21AFD6FADFA147E2E7C3A0AFFCBB1D01B8F1F146503A82FC8E379CCCEA968A
2128Acunetix Premium Activation Tool.exeC:\Users\admin\AppData\Local\Temp\autF71F.tmpbinary
MD5:F57011712B73FA6490F4C5DD91A5554F
SHA256:2FAE4C200D455166F1C1322B9EDCEC741F99D388D67AFA3FC5329A6E6C423D00
2128Acunetix Premium Activation Tool.exeC:\Users\admin\AppData\Local\Temp\autF49D.tmpexecutable
MD5:55AC1B23AEFEFE768CCEFE58264B07A9
SHA256:EA812DC5CD875C0DD4D52E8E7C53F8D5CF372A982DED00BBFA6CC1C2605864C9
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
324
svchost.exe
224.0.0.252:5355
unknown
1956
svchost.exe
239.255.255.250:1900
unknown
4
System
192.168.100.255:138
unknown

DNS requests

Domain
IP
Reputation
teredo.ipv6.microsoft.com
unknown

Threats

No threats detected
No debug info