File name:

SuperPI.exe

Full analysis: https://app.any.run/tasks/4310e8ad-18a1-4db8-a618-f5e55543fe07
Verdict: Malicious activity
Analysis date: May 03, 2024, 06:29:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

476913AC70A2BD132445459217CE1F89

SHA1:

546C4C176A34D982C5B1C1E48789104D744E0FBD

SHA256:

514EA6C2E4CE676865811206AF45055DFCB3F43F901392F0E7469A7DA6118EC0

SSDEEP:

98304:ku9velLv0Uw1MgJlk7904xgFx0ZpW0+rq7:tD6904g0ZZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • SuperPI.exe (PID: 4068)
    • Registers / Runs the DLL via REGSVR32.EXE

      • SuperPI.exe (PID: 4068)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • SuperPI.exe (PID: 4068)
  • INFO

    • Checks supported languages

      • SuperPI.exe (PID: 4068)
    • Reads the machine GUID from the registry

      • SuperPI.exe (PID: 4068)
    • Create files in a temporary directory

      • SuperPI.exe (PID: 4068)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Microsoft Visual Basic 6 (44.4)
.exe | InstallShield setup (23.3)
.exe | Win32 Executable MS Visual C++ (generic) (16.9)
.exe | DOS Executable Borland C++ (7)
.dll | Win32 Dynamic Link Library (generic) (3.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:05:17 04:28:05+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 94208
InitializedDataSize: 4681728
UninitializedDataSize: -
EntryPoint: 0x1910
OSVersion: 4
ImageVersion: 2.1
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.1.0.0
ProductVersionNumber: 2.1.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: wPrime Systems
ProductName: Super PI Mod 2.1 WP
FileVersion: 2.01
ProductVersion: 2.01
InternalName: SuperPI
OriginalFileName: SuperPI.exe
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start superpi.exe regsvr32.exe no specs regsvr32.exe no specs superpi.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2072regsvr32 -s"C:\Users\admin\AppData\Local\Temp\cpuz201.exe"C:\Windows\System32\regsvr32.exeSuperPI.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3964"C:\Users\admin\Downloads\SuperPI.exe" C:\Users\admin\Downloads\SuperPI.exeexplorer.exe
User:
admin
Company:
wPrime Systems
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
2.01
Modules
Images
c:\users\admin\downloads\superpi.exe
c:\windows\system32\ntdll.dll
4068"C:\Users\admin\Downloads\SuperPI.exe" C:\Users\admin\Downloads\SuperPI.exe
explorer.exe
User:
admin
Company:
wPrime Systems
Integrity Level:
HIGH
Version:
2.01
Modules
Images
c:\users\admin\downloads\superpi.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
4084regsvr32 -s"C:\Users\admin\AppData\Local\Temp\cpuz.ini"C:\Windows\System32\regsvr32.exeSuperPI.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
132
Read events
132
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
4068SuperPI.exeC:\Users\admin\AppData\Local\Temp\cpuz.initext
MD5:2AF51B3094BA7841794F2B02809DE6C8
SHA256:5275210A42EAC9E9524361FC3CE4BAE0378DB8C8285DA88EAF4A7DA7AB820A4C
4068SuperPI.exeC:\Users\admin\AppData\Local\Temp\cpuz201.exeexecutable
MD5:53C98C1EED7AE91C64408FDD891555BF
SHA256:07F99E1A3F046B26F70199EB329834815878D48E6D5034644FC75FEE7027ADA3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info