| File name: | Синий экран(удаление системы).exe |
| Full analysis: | https://app.any.run/tasks/89b559e1-f98f-4f58-858c-4f706122f8aa |
| Verdict: | Malicious activity |
| Analysis date: | June 12, 2024, 16:24:15 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 0B1D512BEE47FC64067F743763CD840D |
| SHA1: | 6441A289F36775FED609001E25820A30DA40DDC8 |
| SHA256: | 51B773B8DA399FC0A14F2CD9A4CF1D1B3A24F143B71E2AF320277EF2D9C9967A |
| SSDEEP: | 49152:9TEoXJMkQn75SAy9PD86GwUssZqtkytqFGoXLMqXrrn0wcoLgGdddddddddddddc:xEWQby9q9ZY7AUowtPZWVVpDrlw |
| .exe | | | Win32 Executable Borland Delphi 7 (44) |
|---|---|---|
| .exe | | | Win32 Executable Borland Delphi 5 (29.9) |
| .exe | | | Win32 Executable Borland Delphi 6 (17.4) |
| .exe | | | InstallShield setup (2.8) |
| .exe | | | Win32 EXE PECompact compressed (generic) (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:19 22:22:17+00:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 29696 |
| InitializedDataSize: | 10752 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x80e4 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 856 | "C:\Users\admin\Desktop\Удаление Windows 3.0.exe" | C:\Users\admin\Desktop\Удаление Windows 3.0.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1116 | "C:\Users\admin\Desktop\форматирование реальное.exe" | C:\Users\admin\Desktop\форматирование реальное.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1284 | "C:\Users\admin\Desktop\Синий экран(удаление системы).exe" | C:\Users\admin\Desktop\Синий экран(удаление системы).exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1380 | "C:\Users\admin\Desktop\Удаление Windows 3.0.exe" | C:\Users\admin\Desktop\Удаление Windows 3.0.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1620 | "C:\Users\admin\Desktop\Синий экран(удаление системы).exe" | C:\Users\admin\Desktop\Синий экран(удаление системы).exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1680 | "C:\Users\admin\Desktop\Porno!.exe" | C:\Users\admin\Desktop\Porno!.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2080 | "C:\Users\admin\Desktop\PacMan.exe" | C:\Users\admin\Desktop\PacMan.exe | — | explorer.exe | |||||||||||
User: admin Company: BSG Integrity Level: MEDIUM Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 2204 | "C:\Windows\system32\ntvdm.exe" -i1 -ws | C:\Windows\System32\ntvdm.exe | — | Porno!.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: NTVDM.EXE Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2232 | "C:\Users\admin\Desktop\New folder\Синий экран(удаление системы).exe" | C:\Users\admin\Desktop\New folder\Синий экран(удаление системы).exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2240 | "C:\Users\admin\Desktop\New folder\Синий экран(удаление системы).exe" | C:\Users\admin\Desktop\New folder\Синий экран(удаление системы).exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (1680) Porno!.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1680) Porno!.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1680) Porno!.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1680) Porno!.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3964 | Синий экран(удаление системы).exe | C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\setup.exe | atn | |
MD5:56009AA0F6743D9C4848839C72DDDA4A | SHA256:3A77AE222C7EC13CAAF7965412F1709FD98BC1D0C41FF5F30A2187B33E468908 | |||
| 3964 | Синий экран(удаление системы).exe | C:\MSOCache\All Users\{90140000-006E-040C-0000-0000000FF1CE}-C\dwtrig20.exe | atn | |
MD5:F2E5CFB8F498639BAF77B6A55FB9325E | SHA256:51FADBA4DEBB9030662F2593EDE938F175656208AAA30C9B214FA580114613E0 | |||
| 3964 | Синий экран(удаление системы).exe | C:\MSOCache\All Users\{90140000-006E-0410-0000-0000000FF1CE}-C\dwtrig20.exe | binary | |
MD5:F2E5CFB8F498639BAF77B6A55FB9325E | SHA256:51FADBA4DEBB9030662F2593EDE938F175656208AAA30C9B214FA580114613E0 | |||
| 3964 | Синий экран(удаление системы).exe | C:\MSOCache\All Users\{90140000-006E-0410-0000-0000000FF1CE}-C\DW20.EXE | atn | |
MD5:885455EE948E2CC8EF2CFD9F2FEA572C | SHA256:AB7EC60B102ABEAEFC347A96DC443FEE562873413D0C3EAEFB254C8E3DB6A181 | |||
| 3964 | Синий экран(удаление системы).exe | C:\MSOCache\All Users\{90140000-006E-0411-0000-0000000FF1CE}-C\DW20.EXE | atn | |
MD5:885455EE948E2CC8EF2CFD9F2FEA572C | SHA256:AB7EC60B102ABEAEFC347A96DC443FEE562873413D0C3EAEFB254C8E3DB6A181 | |||
| 3964 | Синий экран(удаление системы).exe | C:\MSOCache\All Users\{90140000-006E-0412-0000-0000000FF1CE}-C\DW20.EXE | binary | |
MD5:885455EE948E2CC8EF2CFD9F2FEA572C | SHA256:AB7EC60B102ABEAEFC347A96DC443FEE562873413D0C3EAEFB254C8E3DB6A181 | |||
| 3964 | Синий экран(удаление системы).exe | C:\MSOCache\All Users\{90140000-006E-0411-0000-0000000FF1CE}-C\dwtrig20.exe | atn | |
MD5:F2E5CFB8F498639BAF77B6A55FB9325E | SHA256:51FADBA4DEBB9030662F2593EDE938F175656208AAA30C9B214FA580114613E0 | |||
| 3964 | Синий экран(удаление системы).exe | C:\MSOCache\All Users\{90140000-006E-0407-0000-0000000FF1CE}-C\DW20.EXE | atn | |
MD5:885455EE948E2CC8EF2CFD9F2FEA572C | SHA256:AB7EC60B102ABEAEFC347A96DC443FEE562873413D0C3EAEFB254C8E3DB6A181 | |||
| 3964 | Синий экран(удаление системы).exe | C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\ose.exe | atn | |
MD5:94952DDE7F498F9AFF1475FC94052D88 | SHA256:6160D2F75B0F51E72A58CB89BBDE082FB6154568E6EEAD7EACDD1FBE3952E6F3 | |||
| 3964 | Синий экран(удаление системы).exe | C:\MSOCache\All Users\{90140000-006E-041F-0000-0000000FF1CE}-C\dwtrig20.exe | atn | |
MD5:F2E5CFB8F498639BAF77B6A55FB9325E | SHA256:51FADBA4DEBB9030662F2593EDE938F175656208AAA30C9B214FA580114613E0 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |