download:

/shift/download/shift%20-%20recipes_mkr3j.exe

Full analysis: https://app.any.run/tasks/3bdd34ea-ee22-4abc-af24-5a34b9418ce0
Verdict: Malicious activity
Analysis date: March 01, 2024, 22:51:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

3309BC3CE827067F87C95514729547E7

SHA1:

E16C50DC34F71238C885D72EB247A283DA010BD8

SHA256:

53C620082F8E9AC1C0D3EC4DEF4546BC47410BD3D4FC812F0EA4445E11452F2A

SSDEEP:

98304:C+cD4dnHwICNdt3uMEBitlGX8XsQpZX5vEVpyQn6hHzwOeNO4SPvsm6Puq/GpBjJ:kaB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.exe (PID: 3240)
      • 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp (PID: 3672)
    • Actions looks like stealing of personal data

      • 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp (PID: 3672)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.exe (PID: 3240)
      • 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp (PID: 3672)
    • Reads the Windows owner or organization settings

      • 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp (PID: 3672)
    • Reads settings of System Certificates

      • 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp (PID: 3672)
    • Reads the Internet Settings

      • 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp (PID: 3672)
  • INFO

    • Checks supported languages

      • 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.exe (PID: 3240)
      • 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp (PID: 3672)
    • Create files in a temporary directory

      • 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.exe (PID: 3240)
      • 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp (PID: 3672)
    • Reads the computer name

      • 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp (PID: 3672)
    • Reads the software policy settings

      • 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp (PID: 3672)
    • Reads the machine GUID from the registry

      • 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp (PID: 3672)
    • Reads Environment values

      • 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp (PID: 3672)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:02:15 14:54:16+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 421888
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 118.9.0.0
ProductVersionNumber: 118.9.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Shift
FileDescription: Shift Setup
FileVersion: 118.9.0
LegalCopyright: Copyright Shift. All rights reserved.
OriginalFileName:
ProductName: Shift
ProductVersion: 118.9.0
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.exe 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp

Process information

PID
CMD
Path
Indicators
Parent process
3240"C:\Users\admin\AppData\Local\Temp\3bdd34ea-ee22-4abc-af24-5a34b9418ce0.exe" C:\Users\admin\AppData\Local\Temp\3bdd34ea-ee22-4abc-af24-5a34b9418ce0.exe
explorer.exe
User:
admin
Company:
Shift
Integrity Level:
MEDIUM
Description:
Shift Setup
Exit code:
0
Version:
118.9.0
Modules
Images
c:\users\admin\appdata\local\temp\3bdd34ea-ee22-4abc-af24-5a34b9418ce0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
3672"C:\Users\admin\AppData\Local\Temp\is-OJ0F7.tmp\3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp" /SL5="$E0170,1390925,1164800,C:\Users\admin\AppData\Local\Temp\3bdd34ea-ee22-4abc-af24-5a34b9418ce0.exe" C:\Users\admin\AppData\Local\Temp\is-OJ0F7.tmp\3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp
3bdd34ea-ee22-4abc-af24-5a34b9418ce0.exe
User:
admin
Company:
Shift
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-oj0f7.tmp\3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
3 749
Read events
3 732
Write events
17
Delete events
0

Modification events

(PID) Process:(3672) 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
580E000054C234192B6CDA01
(PID) Process:(3672) 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
8BF1CD131C5DD8B9F467E7F41159D2A2222827A5BC3E7359A4F2DFCD89F62294
(PID) Process:(3672) 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3672) 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
2
Suspicious files
0
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
36723bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmpC:\Users\admin\AppData\Local\Temp\is-SK14K.tmp\shift.pngimage
MD5:0423D0589E58341B5B64C6099F4123B7
SHA256:A1D2C48437058F24A5EA85C323469473AC4430198770794522A32C28783AADB7
32403bdd34ea-ee22-4abc-af24-5a34b9418ce0.exeC:\Users\admin\AppData\Local\Temp\is-OJ0F7.tmp\3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmpexecutable
MD5:8D02EE65163DDEF78FFD93584DD69B7F
SHA256:478F6536B636E432AC2E908335F54E2D5904D07F5F7F78821CA52063130286EE
36723bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmpC:\Users\admin\AppData\Local\Temp\is-SK14K.tmp\shift.bmpimage
MD5:6FD867F79E4C82E47C570F09646E9E2E
SHA256:334779A03F50163C87618856BEF8D8493806CC4B086E460E3189791DB6323796
36723bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmpC:\Users\admin\AppData\Local\Temp\is-SK14K.tmp\min-pressed.bmpimage
MD5:CC62DDE39B9CAA24626A3A0EB93C70FA
SHA256:8D25A76A6552A927407CB0D7BA1E61E8644D76420C2690F8CB3DB90F75ECC1E7
36723bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmpC:\Users\admin\AppData\Local\Temp\is-SK14K.tmp\min-rest.bmpimage
MD5:C32BFC11F1A32BAB6A1ED327C8A89E0E
SHA256:24BEE6D5DA65DC8A65EB639E3C189F257BC4B231940BD078BBEA23BA985EABB5
36723bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmpC:\Users\admin\AppData\Local\Temp\is-SK14K.tmp\min-10-dark.pngimage
MD5:14CA04108E5AC6A1B8C7A2B689382E44
SHA256:9CB22401A923DFECAFC5F51DACEF5CBAE440B53B9932217C6BC4626F04920929
36723bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmpC:\Users\admin\AppData\Local\Temp\is-SK14K.tmp\min-hover.bmpimage
MD5:E08B0A658E4A166C5461C542BE2B0D2F
SHA256:6F696C0C59CEDD0456270BCC868B6B3D7CBCA43911390904014F532CD7B131D5
36723bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmpC:\Users\admin\AppData\Local\Temp\is-SK14K.tmp\Win32Library.dllexecutable
MD5:D82B30898C428A7DBEE81CECEA520F68
SHA256:92AF9D054E3B5DC9F472FF9534060D1C70E2AC77F768AE9E5029E29FCD606198
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
8
DNS requests
4
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3672
3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp
52.34.167.222:443
updates.shiftapis.com
AMAZON-02
US
unknown
3672
3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp
49.13.77.253:443
update.shiftapis.com
Hetzner Online GmbH
DE
unknown
3672
3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp
35.190.25.25:443
api.mixpanel.com
GOOGLE
US
whitelisted
3672
3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp
104.22.77.241:443
downloads.tryshift.com
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
updates.shiftapis.com
  • 52.34.167.222
  • 52.43.18.243
  • 34.216.5.240
  • 35.163.167.83
unknown
update.shiftapis.com
  • 49.13.77.253
unknown
api.mixpanel.com
  • 35.190.25.25
  • 107.178.240.159
  • 130.211.34.183
  • 35.186.241.51
whitelisted
downloads.tryshift.com
  • 104.22.77.241
  • 104.22.76.241
  • 172.67.4.202
unknown

Threats

No threats detected
No debug info