File name:

data0.exe

Full analysis: https://app.any.run/tasks/b2c1b92a-96f0-415b-83dd-222a79acce3b
Verdict: Malicious activity
Analysis date: December 15, 2023, 07:26:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

1FEE514A431AC91DD741D8894C225510

SHA1:

3A17DDC7235DC4371F477250DDC0F4A0C3E250A0

SHA256:

51D10DF5579E6BBE527875A968EDCCD8FAB80E9724D5C7C8DE4B181E1F850BCE

SSDEEP:

98304:gV0FeEEM7ncqFIG7xn8Oy2uyCNxIHCrrHk+4kq65lPFkyusiq4sVZwXqtGagPJAW:V3AF+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • data0.exe (PID: 1352)
      • data0.tmp (PID: 2928)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • data0.tmp (PID: 2928)
    • Reads the Windows owner or organization settings

      • data0.tmp (PID: 2928)
  • INFO

    • Checks supported languages

      • data0.exe (PID: 1352)
      • data0.tmp (PID: 2928)
    • Create files in a temporary directory

      • data0.exe (PID: 1352)
      • data0.tmp (PID: 2928)
    • Reads the computer name

      • data0.tmp (PID: 2928)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (81.5)
.exe | Win32 Executable Delphi generic (10.5)
.exe | Win32 Executable (generic) (3.3)
.exe | Win16/32 Executable Delphi generic (1.5)
.exe | Generic Win/DOS Executable (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:10:02 07:04:04+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 86016
InitializedDataSize: 244736
UninitializedDataSize: -
EntryPoint: 0x16478
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.5
ProductVersionNumber: 1.0.0.5
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: torrent-igruha.org
FileDescription: Elden Ring Setup
FileVersion: 1.0.0.5
LegalCopyright: © Mail
ProductName: Elden Ring
ProductVersion: 1.0.0.5
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
3
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start data0.exe data0.tmp no specs data0.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1352"C:\Users\admin\AppData\Local\Temp\data0.exe" C:\Users\admin\AppData\Local\Temp\data0.exe
explorer.exe
User:
admin
Company:
torrent-igruha.org
Integrity Level:
HIGH
Description:
Elden Ring Setup
Exit code:
0
Version:
1.0.0.5
Modules
Images
c:\users\admin\appdata\local\temp\data0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1864"C:\Users\admin\AppData\Local\Temp\data0.exe" C:\Users\admin\AppData\Local\Temp\data0.exeexplorer.exe
User:
admin
Company:
torrent-igruha.org
Integrity Level:
MEDIUM
Description:
Elden Ring Setup
Exit code:
3221226540
Version:
1.0.0.5
Modules
Images
c:\users\admin\appdata\local\temp\data0.exe
c:\windows\system32\ntdll.dll
2928"C:\Users\admin\AppData\Local\Temp\is-4C7IB.tmp\data0.tmp" /SL5="$1C0142,1843014,331776,C:\Users\admin\AppData\Local\Temp\data0.exe" C:\Users\admin\AppData\Local\Temp\is-4C7IB.tmp\data0.tmpdata0.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-4c7ib.tmp\data0.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
48
Read events
48
Write events
0
Delete events
0

Modification events

No data
Executable files
7
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2928data0.tmpC:\Users\admin\AppData\Local\Temp\is-KHPLD.tmp\CallbackCtrl.dllexecutable
MD5:F07E819BA2E46A897CFABF816D7557B2
SHA256:68F42A7823ED7EE88A5C59020AC52D4BBCADF1036611E96E470D986C8FAA172D
2928data0.tmpC:\Users\admin\AppData\Local\Temp\is-KHPLD.tmp\ISDone.dllexecutable
MD5:4FEAFA8B5E8CDB349125C8AF0AC43974
SHA256:BB8A0245DCC5C10A1C7181BAD509B65959855009A8105863EF14F2BB5B38AC71
2928data0.tmpC:\Users\admin\AppData\Local\Temp\is-KHPLD.tmp\b2p.dllexecutable
MD5:AB35386487B343E3E82DBD2671FF9DAB
SHA256:C3729545522FCFF70DB61046C0EFD962DF047D40E3B5CCD2272866540FC872B2
2928data0.tmpC:\Users\admin\AppData\Local\Temp\is-KHPLD.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
1352data0.exeC:\Users\admin\AppData\Local\Temp\is-4C7IB.tmp\data0.tmpexecutable
MD5:281314DBCEF5D093ACFF59A9A7F17CA4
SHA256:B184A22569596966B66308685C854C97039227E03460CD21DD91C62C9EC7D2B9
2928data0.tmpC:\Users\admin\AppData\Local\Temp\is-KHPLD.tmp\WinTB.dllexecutable
MD5:A2EEE508E6A51C6335650532E05AC550
SHA256:75FB2984E1B06F4278FB7B3C77E9FEC84E02A3B4BF82D35120F8CBE7BDBC76BF
2928data0.tmpC:\Users\admin\AppData\Local\Temp\is-KHPLD.tmp\botva2.dllexecutable
MD5:67965A5957A61867D661F05AE1F4773E
SHA256:450B9B0BA25BF068AFBC2B23D252585A19E282939BF38326384EA9112DFD0105
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info