File name:

Alphalist Data Entry and Validation 7.2.exe

Full analysis: https://app.any.run/tasks/72567139-0408-480f-88ca-be9ed211747a
Verdict: Malicious activity
Analysis date: February 16, 2024, 05:42:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

190DCAE583B93316F6DE92AC5DCF84E9

SHA1:

0CB4EC30782B998C34A0A81C5767A43B5FCE703C

SHA256:

54016447C57AB4AF2233E8B899028007179624028C5B7053471826D99BB6F645

SSDEEP:

98304:p6mIuV8fM0lFh2Ii+Sy9j51ybGBWwr8ADHzSpgsfM86xFynh1XcWrEtBJSiUdbXZ:Z0spE7g85GqhsrhQPFc81WBQ1zmMk

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Alphalist Data Entry and Validation 7.2.exe (PID: 3784)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • Alphalist Data Entry and Validation 7.2.exe (PID: 3784)
    • Executable content was dropped or overwritten

      • Alphalist Data Entry and Validation 7.2.exe (PID: 3784)
  • INFO

    • Checks supported languages

      • Alphalist Data Entry and Validation 7.2.exe (PID: 3784)
    • Reads the computer name

      • Alphalist Data Entry and Validation 7.2.exe (PID: 3784)
    • Creates files in the program directory

      • Alphalist Data Entry and Validation 7.2.exe (PID: 3784)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2021:09:25 21:57:46+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 27136
InitializedDataSize: 186880
UninitializedDataSize: 2048
EntryPoint: 0x352d
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start alphalist data entry and validation 7.2.exe no specs alphalist data entry and validation 7.2.exe

Process information

PID
CMD
Path
Indicators
Parent process
3240"C:\Users\admin\AppData\Local\Temp\Alphalist Data Entry and Validation 7.2.exe" C:\Users\admin\AppData\Local\Temp\Alphalist Data Entry and Validation 7.2.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\alphalist data entry and validation 7.2.exe
c:\windows\system32\ntdll.dll
3784"C:\Users\admin\AppData\Local\Temp\Alphalist Data Entry and Validation 7.2.exe" C:\Users\admin\AppData\Local\Temp\Alphalist Data Entry and Validation 7.2.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\appdata\local\temp\alphalist data entry and validation 7.2.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
Total events
2 382
Read events
2 382
Write events
0
Delete events
0

Modification events

No data
Executable files
8
Suspicious files
382
Text files
44
Unknown types
8

Dropped files

PID
Process
Filename
Type
3784Alphalist Data Entry and Validation 7.2.exeC:\BIRALPHA72\Alphalist Validation.exeexecutable
MD5:0C1D33BF9BD889F907F9DD3E3227DEF9
SHA256:A36BB0102664F81678EA41F8175D8EF00146CF4793FD523F4D79CFC13D938FEC
3784Alphalist Data Entry and Validation 7.2.exeC:\BIRALPHA72\valrlf.pjtbinary
MD5:E765638C3F65A176672E17A1CDC86AD4
SHA256:B1BAED41565BD6F1D4F737A59251B06F196BCAD8050C9491D41D663E5BB8D60F
3784Alphalist Data Entry and Validation 7.2.exeC:\BIRALPHA72\FOXUSER.DBFbinary
MD5:6A94F38581C67C2BAD3176AD98498301
SHA256:CE150B019841B32FF7BC042EC42EDACC96DFE3A712ABB3465447A1A9A51756C1
3784Alphalist Data Entry and Validation 7.2.exeC:\BIRALPHA72\val16041.exeexecutable
MD5:6010DA6CA482359D92856D42D4E1A986
SHA256:D3F803B9152CB255003E1653EC668FFFA709F78EE9E4D0A29F1612C5193BB494
3784Alphalist Data Entry and Validation 7.2.exeC:\BIRALPHA72\valrlf.pjxbinary
MD5:CDAB6AE5856A524381786A5CADDC3BEB
SHA256:A946A79035CDB2B4A93BEAA3530978EC90AD20EE04FCD3499C0C2022E8B76A77
3784Alphalist Data Entry and Validation 7.2.exeC:\BIRALPHA72\valrlf.exeexecutable
MD5:09A480C119EC5B846F1B545F81FC9104
SHA256:4F216A14F56A4AB63EC171134E0D0B3D367B0D4E87E5573F5E22FB28FB6DFA89
3784Alphalist Data Entry and Validation 7.2.exeC:\BIRALPHA72\Alphalist Data Entry.exeexecutable
MD5:FEFCA7EFCB66E4E520FC39FDD469D32F
SHA256:7939EFF792B6C5F21FF8AAACFBD9BC8CFCAADDF8B19A111C886A6FC7930208F6
3784Alphalist Data Entry and Validation 7.2.exeC:\BIRALPHA72\VFP6T.DLLexecutable
MD5:2F164251C6FEEAEB34E9EFA23524332F
SHA256:0C797A486F460ACBC1098D149E027AD90802E7812F409904A7079DD7CD2851F3
3784Alphalist Data Entry and Validation 7.2.exeC:\BIRALPHA72\BITMAPS\ADD.BMPimage
MD5:D0E9E628898548A5E41B8BC9E3183F37
SHA256:05814594EEDA1D916F786703A619CF443EEBE2EC3A2788DB770B2875DDA44562
3784Alphalist Data Entry and Validation 7.2.exeC:\BIRALPHA72\signatory.txttext
MD5:81051BCC2CF1BEDF378224B0A93E2877
SHA256:7EB70257593DA06F682A3DDDA54A9D260D4FC514F645237F5CA74B08F8DA61A6
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
unknown
4
System
192.168.100.255:138
unknown
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info