File name:

Alphalist Data Entry and Validation 7.2.exe

Full analysis: https://app.any.run/tasks/72567139-0408-480f-88ca-be9ed211747a
Verdict: Malicious activity
Analysis date: February 16, 2024, 05:42:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

190DCAE583B93316F6DE92AC5DCF84E9

SHA1:

0CB4EC30782B998C34A0A81C5767A43B5FCE703C

SHA256:

54016447C57AB4AF2233E8B899028007179624028C5B7053471826D99BB6F645

SSDEEP:

98304:p6mIuV8fM0lFh2Ii+Sy9j51ybGBWwr8ADHzSpgsfM86xFynh1XcWrEtBJSiUdbXZ:Z0spE7g85GqhsrhQPFc81WBQ1zmMk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Alphalist Data Entry and Validation 7.2.exe (PID: 3784)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • Alphalist Data Entry and Validation 7.2.exe (PID: 3784)
    • Executable content was dropped or overwritten

      • Alphalist Data Entry and Validation 7.2.exe (PID: 3784)
  • INFO

    • Reads the computer name

      • Alphalist Data Entry and Validation 7.2.exe (PID: 3784)
    • Checks supported languages

      • Alphalist Data Entry and Validation 7.2.exe (PID: 3784)
    • Creates files in the program directory

      • Alphalist Data Entry and Validation 7.2.exe (PID: 3784)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:25 21:57:46+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27136
InitializedDataSize: 186880
UninitializedDataSize: 2048
EntryPoint: 0x352d
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start alphalist data entry and validation 7.2.exe alphalist data entry and validation 7.2.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3240"C:\Users\admin\AppData\Local\Temp\Alphalist Data Entry and Validation 7.2.exe" C:\Users\admin\AppData\Local\Temp\Alphalist Data Entry and Validation 7.2.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\alphalist data entry and validation 7.2.exe
c:\windows\system32\ntdll.dll
3784"C:\Users\admin\AppData\Local\Temp\Alphalist Data Entry and Validation 7.2.exe" C:\Users\admin\AppData\Local\Temp\Alphalist Data Entry and Validation 7.2.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\alphalist data entry and validation 7.2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
Total events
2 382
Read events
2 382
Write events
0
Delete events
0

Modification events

No data
Executable files
8
Suspicious files
382
Text files
44
Unknown types
8

Dropped files

PID
Process
Filename
Type
3784Alphalist Data Entry and Validation 7.2.exeC:\BIRALPHA72\Alphalist Data Entry.exeexecutable
MD5:FEFCA7EFCB66E4E520FC39FDD469D32F
SHA256:7939EFF792B6C5F21FF8AAACFBD9BC8CFCAADDF8B19A111C886A6FC7930208F6
3784Alphalist Data Entry and Validation 7.2.exeC:\BIRALPHA72\FOXUSER.DBFbinary
MD5:6A94F38581C67C2BAD3176AD98498301
SHA256:CE150B019841B32FF7BC042EC42EDACC96DFE3A712ABB3465447A1A9A51756C1
3784Alphalist Data Entry and Validation 7.2.exeC:\BIRALPHA72\VFP6RENU.DLLexecutable
MD5:67C5FD2305AF277134E00C76F3E5BCE5
SHA256:FB89F70273870D5BAA75BE62F2905A0A87453C915D5173F2231DA37783441B3B
3784Alphalist Data Entry and Validation 7.2.exeC:\BIRALPHA72\VFP6R.DLLexecutable
MD5:02B892076244E5BAE12FC62297ED0502
SHA256:2F12D7CC09D1B966991010D098A20D6B39B400525EEC98FF90316569BF22542A
3784Alphalist Data Entry and Validation 7.2.exeC:\BIRALPHA72\4_ICO_3.ICOimage
MD5:3B88B2ED9833F61C43F1E53A10690155
SHA256:D69E45A04B52FCA45641F6C1398590590F56BACF6AB228D0C14CB4DD9492BE10
3784Alphalist Data Entry and Validation 7.2.exeC:\BIRALPHA72\val16041.exeexecutable
MD5:6010DA6CA482359D92856D42D4E1A986
SHA256:D3F803B9152CB255003E1653EC668FFFA709F78EE9E4D0A29F1612C5193BB494
3784Alphalist Data Entry and Validation 7.2.exeC:\BIRALPHA72\VALID.ICOimage
MD5:BD14D1A6DB2006DFC25ECB9D17708F74
SHA256:6FA76C15B12B1E9FA9F1DC1310E688ECA34D32A39B33AE9C97E1F3482944C1E2
3784Alphalist Data Entry and Validation 7.2.exeC:\BIRALPHA72\signatoryb.txttext
MD5:81051BCC2CF1BEDF378224B0A93E2877
SHA256:7EB70257593DA06F682A3DDDA54A9D260D4FC514F645237F5CA74B08F8DA61A6
3784Alphalist Data Entry and Validation 7.2.exeC:\BIRALPHA72\BITMAPS\BIR.GIFimage
MD5:0848D81178726105333EE648D584EF60
SHA256:F2ECBAB9852C0F7424D3CAA7F7E104029C47AA224D0980FB3F2882A763F8B719
3784Alphalist Data Entry and Validation 7.2.exeC:\BIRALPHA72\valrlf.exeexecutable
MD5:09A480C119EC5B846F1B545F81FC9104
SHA256:4F216A14F56A4AB63EC171134E0D0B3D367B0D4E87E5573F5E22FB28FB6DFA89
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info