File name:

gvim90.exe

Full analysis: https://app.any.run/tasks/bd4f1e8f-bce2-4f07-b010-6a0a9e3ae70f
Verdict: Malicious activity
Analysis date: December 08, 2023, 12:05:49
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

A237391F169CAE4F29137A5AE3ADDEF6

SHA1:

AB499B9044DF5F8B8FF1777D1AECD21E5BB18C41

SHA256:

57A5B0D3E42695EAECA962364CDE3F257227E967436821B81C19434BF4E1042C

SSDEEP:

98304:Se60k6iXen34jbfGBWgWIV9Rab/tEic357PUjWws9NcSd2rf7UQg533L+zBEC5FS:TZbB+cf0iRXlb++3uMRsgB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • gvim90.exe (PID: 2600)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • gvim90.exe (PID: 2600)
    • Starts application with an unusual extension

      • gvim90.exe (PID: 2600)
    • Starts CMD.EXE for commands execution

      • install.exe (PID: 1696)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • gvim90.exe (PID: 2600)
  • INFO

    • Checks supported languages

      • gvim90.exe (PID: 2600)
      • nsC021.tmp (PID: 4036)
      • wmpnscfg.exe (PID: 600)
      • install.exe (PID: 1696)
      • gvim.exe (PID: 880)
      • gvim.exe (PID: 3600)
      • wmpnscfg.exe (PID: 3732)
      • vim.exe (PID: 3424)
    • Reads the computer name

      • gvim90.exe (PID: 2600)
      • wmpnscfg.exe (PID: 600)
      • gvim.exe (PID: 880)
      • install.exe (PID: 1696)
      • wmpnscfg.exe (PID: 3732)
      • gvim.exe (PID: 3600)
      • vim.exe (PID: 3424)
    • Create files in a temporary directory

      • gvim90.exe (PID: 2600)
    • Creates files in the program directory

      • gvim90.exe (PID: 2600)
      • install.exe (PID: 1696)
    • Manual execution by a user

      • gvim.exe (PID: 3600)
      • vim.exe (PID: 3424)
      • wmpnscfg.exe (PID: 600)
      • wmpnscfg.exe (PID: 3732)
    • Reads the machine GUID from the registry

      • gvim90.exe (PID: 2600)
      • gvim.exe (PID: 3600)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:01:30 04:57:41+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 26112
InitializedDataSize: 141824
UninitializedDataSize: 2048
EntryPoint: 0x34a5
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 9.0.0.0
ProductVersionNumber: 9.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Vim Developers
FileDescription: Vi Improved - A Text Editor
FileVersion: 9.0.0.0
LegalCopyright: Copyright (C) 1996
LegalTrademarks: Vim
ProductName: Vim
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
10
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start gvim90.exe wmpnscfg.exe no specs nsc021.tmp no specs install.exe no specs cmd.exe no specs gvim.exe no specs gvim.exe no specs vim.exe no specs wmpnscfg.exe no specs gvim90.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
600"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
880"C:\Program Files\Vim\vim90\gvim.exe" -silent -registerC:\Program Files\Vim\vim90\gvim.execmd.exe
User:
admin
Company:
Vim Developers
Integrity Level:
HIGH
Description:
Vi Improved - A Text Editor
Exit code:
0
Version:
9.0.0
Modules
Images
c:\program files\vim\vim90\gvim.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
1696"C:\Program Files\Vim\vim90\install.exe" -register-OLE -install-icons -add-start-menu -install-popup -install-openwith -create-vimrc -vimrc-compat all -vimrc-remap no -vimrc-behave default -create-directories homeC:\Program Files\Vim\vim90\install.exensC021.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\vim\vim90\install.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1864"C:\Users\admin\AppData\Local\Temp\gvim90.exe" C:\Users\admin\AppData\Local\Temp\gvim90.exeexplorer.exe
User:
admin
Company:
Vim Developers
Integrity Level:
MEDIUM
Description:
Vi Improved - A Text Editor
Exit code:
3221226540
Version:
9.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\gvim90.exe
c:\windows\system32\ntdll.dll
2600"C:\Users\admin\AppData\Local\Temp\gvim90.exe" C:\Users\admin\AppData\Local\Temp\gvim90.exe
explorer.exe
User:
admin
Company:
Vim Developers
Integrity Level:
HIGH
Description:
Vi Improved - A Text Editor
Exit code:
0
Version:
9.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\gvim90.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2896C:\Windows\system32\cmd.exe /c "C:\Program Files\Vim\vim90\gvim.exe" -silent -registerC:\Windows\System32\cmd.exeinstall.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3424"C:\Program Files\Vim\vim90\vim.exe" C:\Program Files\Vim\vim90\vim.exeexplorer.exe
User:
admin
Company:
Vim Developers
Integrity Level:
MEDIUM
Description:
Vi Improved - A Text Editor
Exit code:
1
Version:
9.0.0
Modules
Images
c:\program files\vim\vim90\vim.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3600"C:\Program Files\Vim\vim90\gvim.exe" -R "C:\Program Files\Vim\vim90\README.txt"C:\Program Files\Vim\vim90\gvim.exeexplorer.exe
User:
admin
Company:
Vim Developers
Integrity Level:
MEDIUM
Description:
Vi Improved - A Text Editor
Exit code:
0
Version:
9.0.0
Modules
Images
c:\program files\vim\vim90\gvim.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shell32.dll
c:\windows\system32\shlwapi.dll
3732"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
4036"C:\Users\admin\AppData\Local\Temp\nst29FF.tmp\nsC021.tmp" C:\Program Files\Vim\vim90\install.exe -register-OLE -install-icons -add-start-menu -install-popup -install-openwith -create-vimrc -vimrc-compat all -vimrc-remap no -vimrc-behave default -create-directories homeC:\Users\admin\AppData\Local\Temp\nst29FF.tmp\nsC021.tmpgvim90.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nst29ff.tmp\nsc021.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
1 131
Read events
1 130
Write events
1
Delete events
0

Modification events

(PID) Process:(2600) gvim90.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
115
Executable files
24
Suspicious files
70
Text files
1 780
Unknown types
0

Dropped files

PID
Process
Filename
Type
2600gvim90.exeC:\Users\admin\AppData\Local\Temp\nst29FF.tmp\LangDLL.dllexecutable
MD5:3DD80DFF583544514EEB3A5ED851A519
SHA256:86CFF5EACA76C49F924CB123D242FDCFD45AB99C4B638D3B8F4A8CFB1970AB5B
2600gvim90.exeC:\Program Files\Vim\vim90\install.exeexecutable
MD5:8A1E15D93F3AD8D5DC65D24CA5501478
SHA256:683364D52C6A922D1BB62EE799EACB05A40A820D5065AB9144095EB2CADA749B
2600gvim90.exeC:\Program Files\Vim\vim90\uninstall.exeexecutable
MD5:14F96FE579F263F9751A38AD19A0F965
SHA256:2312A408505FE9FBE45779CDB49199F1BCD14CADB2B70A11CB6FFDD6EC852330
2600gvim90.exeC:\Program Files\Vim\vim90\uninstall.txttext
MD5:8EB6EDB768C37F5D227DA5957AA225E5
SHA256:E1682B812E1A93C50DF9F3CE441070E50589BFC3C363B7AE177918A09FE63775
2600gvim90.exeC:\Program Files\Vim\vim90\README.txttext
MD5:4603761042D72F93F51A448F8B4BFC1D
SHA256:4AFAE7C984AB1A4CCD0B474A695F316E7435AB6ED46537648AF925C18835D853
2600gvim90.exeC:\Program Files\Vim\vim90\ftoff.vimtext
MD5:B2AA3D9712C9DCED6C8EB2E84891EE65
SHA256:FA327FACE3B42AA667F61F49843A556C84CCC25C331FE88061688B4589E16B93
2600gvim90.exeC:\Program Files\Vim\vim90\gvim.exeexecutable
MD5:A2B3299404FB3F261036ABAEC39BC744
SHA256:4C401A10CC00F8E9BA290E317F9897B3D686349B6FF4191CD0C8B14C3526E0F9
2600gvim90.exeC:\Users\admin\AppData\Local\Temp\nst29FF.tmp\modern-header.bmpimage
MD5:FE8C446A2DEC2ACBCD9BEC066324E0A6
SHA256:DD03C1262BDEA02A366C59F41E5F766C078AD08DC7531FA0087D7371296BE095
2600gvim90.exeC:\Program Files\Vim\vim90\vimtutor.battext
MD5:BDFF04D6E570A0498B5F535428BD53C0
SHA256:C8543ED17D386F34CDC32CB8095CA9BEC44697CCD59DABB10DD394BD0467E13F
2600gvim90.exeC:\Users\admin\AppData\Local\Temp\nst29FF.tmp\nsDialogs.dllexecutable
MD5:CA95C9DA8CEF7062813B989AB9486201
SHA256:FEB6364375D0AB081E9CDF11271C40CB966AF295C600903383B0730F0821C0BE
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
868
svchost.exe
95.101.148.135:80
armmf.adobe.com
Akamai International B.V.
NL
unknown
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
armmf.adobe.com
  • 95.101.148.135
whitelisted

Threats

No threats detected
Process
Message
gvim90.exe
ExecShellAsUser: got desktop
gvim90.exe
ExecShellAsUser: elevated process detected
gvim90.exe
ExecShellAsUser: thread finished
gvim90.exe
ExecShellAsUser: DLL_PROCESS_DETACH