File name:

Quarknova.exe

Full analysis: https://app.any.run/tasks/b61a60fc-f0d3-4429-9f18-35c9bd2e5faf
Verdict: Malicious activity
Analysis date: January 02, 2025, 17:22:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 3 sections
MD5:

5EB279CC197F50092C08F262FB78257B

SHA1:

57C0E12F579AEBB6EC715DADA048CB95A8011942

SHA256:

51BE71B29050A31DC622FF2BA1F6C8EEDDCC29E6021919F0A1176585F99D27EB

SSDEEP:

98304:7vbR7L+4mNMipvN2v3G5RxrtzANTn5mGb5TVBY7YnqEnRYf2Dq/u7XWCuzvm9DwM:7YVZwB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Starts CMD.EXE for self-deleting

      • Quarknova.exe (PID: 3016)
  • SUSPICIOUS

    • Starts a Microsoft application from unusual location

      • Quarknova.exe (PID: 1560)
      • Quarknova.exe (PID: 3016)
    • Starts itself from another location

      • Quarknova.exe (PID: 3016)
    • Reads security settings of Internet Explorer

      • Quarknova.exe (PID: 3016)
      • Quarknova.exe (PID: 1560)
    • Executable content was dropped or overwritten

      • Quarknova.exe (PID: 3016)
      • quarknova.exe (PID: 2276)
    • Reads the Internet Settings

      • Quarknova.exe (PID: 3016)
      • control.exe (PID: 120)
      • Quarknova.exe (PID: 1560)
    • Process drops legitimate windows executable

      • quarknova.exe (PID: 2276)
      • Quarknova.exe (PID: 3016)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 188)
    • Starts CMD.EXE for commands execution

      • Quarknova.exe (PID: 3016)
    • Uses RUNDLL32.EXE to load library

      • control.exe (PID: 120)
    • Application launched itself

      • Quarknova.exe (PID: 1560)
  • INFO

    • Checks supported languages

      • Quarknova.exe (PID: 1560)
      • Quarknova.exe (PID: 3016)
      • quarknova.exe (PID: 2276)
    • The process uses the downloaded file

      • Quarknova.exe (PID: 1560)
      • Quarknova.exe (PID: 3016)
      • control.exe (PID: 120)
    • Reads the computer name

      • Quarknova.exe (PID: 1560)
      • quarknova.exe (PID: 2276)
      • Quarknova.exe (PID: 3016)
    • Reads the machine GUID from the registry

      • quarknova.exe (PID: 2276)
      • Quarknova.exe (PID: 1560)
      • Quarknova.exe (PID: 3016)
    • Manual execution by a user

      • control.exe (PID: 120)
    • Reads security settings of Internet Explorer

      • control.exe (PID: 120)
    • Reads the time zone

      • rundll32.exe (PID: 1176)
    • Checks transactions between databases Windows and Oracle

      • rundll32.exe (PID: 1176)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (63.1)
.exe | Win64 Executable (generic) (23.8)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2074:08:10 14:54:14+00:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32
LinkerVersion: 48
CodeSize: 4232192
InitializedDataSize: 142336
UninitializedDataSize: -
EntryPoint: 0x40b2ce
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 6.1.7601.23537
ProductVersionNumber: 6.1.7601.23537
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: Windows Explorer
CompanyName: Microsoft Corporation
FileDescription: EXPLORER.EXE
FileVersion: 6.1.7601.23537
InternalName: Quarknova.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
LegalTrademarks: -
OriginalFileName: Quarknova.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 6.1.7601.23537
AssemblyVersion: 6.1.7601.23537
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
8
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start quarknova.exe no specs quarknova.exe quarknova.exe cmd.exe no specs taskkill.exe no specs control.exe no specs rundll32.exe no specs timedate.cpl no specs

Process information

PID
CMD
Path
Indicators
Parent process
120"C:\Windows\System32\control.exe" "C:\Windows\System32\timedate.cpl",C:\Windows\System32\control.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Control Panel
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\control.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
188"C:\Windows\System32\cmd.exe" /c taskkill /f /pid 3016 & del /f /q "C:\Users\admin\Desktop\Quarknova.exe"C:\Windows\System32\cmd.exeQuarknova.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
952C:\Windows\system32\DllHost.exe /Processid:{9DF523B0-A6C0-4EA9-B5F1-F4565C3AC8B8}C:\Windows\System32\dllhost.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
COM Surrogate
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dllhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1176"C:\Windows\system32\rundll32.exe" Shell32.dll,Control_RunDLL "C:\Windows\System32\timedate.cpl",C:\Windows\System32\rundll32.execontrol.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
1560"C:\Users\admin\Desktop\Quarknova.exe" C:\Users\admin\Desktop\Quarknova.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
EXPLORER.EXE
Exit code:
0
Version:
6.1.7601.23537
Modules
Images
c:\users\admin\desktop\quarknova.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
1776taskkill /f /pid 3016 C:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2276"C:\windows\quarknova.exe" -startuproutineC:\Windows\quarknova.exe
Quarknova.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
EXPLORER.EXE
Version:
6.1.7601.23537
Modules
Images
c:\windows\quarknova.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3016"C:\Users\admin\Desktop\Quarknova.exe" C:\Users\admin\Desktop\Quarknova.exe
Quarknova.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
EXPLORER.EXE
Exit code:
1
Version:
6.1.7601.23537
Modules
Images
c:\users\admin\desktop\quarknova.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
1 527
Read events
1 503
Write events
24
Delete events
0

Modification events

(PID) Process:(1560) Quarknova.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(1560) Quarknova.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(1560) Quarknova.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(1560) Quarknova.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3016) Quarknova.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3016) Quarknova.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3016) Quarknova.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3016) Quarknova.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(120) control.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(120) control.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
4
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2276quarknova.exeC:\Windows_7_Loader.exeexecutable
MD5:5EB279CC197F50092C08F262FB78257B
SHA256:51BE71B29050A31DC622FF2BA1F6C8EEDDCC29E6021919F0A1176585F99D27EB
3016Quarknova.exeC:\Windows\Microsoft.Win32.TaskScheduler.dllexecutable
MD5:782C3D132E535F51E94433F5747099B5
SHA256:C25B77353F7178386FFB28CCA0EBB8DB7F18F0D78514BAB8F175F1C637D651D9
3016Quarknova.exeC:\Windows\quarknova.exeexecutable
MD5:5EB279CC197F50092C08F262FB78257B
SHA256:51BE71B29050A31DC622FF2BA1F6C8EEDDCC29E6021919F0A1176585F99D27EB
3016Quarknova.exeC:\Windows\NAudio.dllexecutable
MD5:6CA17ABCCAE3050F391401B2955F9333
SHA256:3AD5D09B4C8C3146D15955A564A9F1A57D7C795B189A25C6F722A738D95EF89C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info