| File name: | RDPGuardProxyServer_Install.exe |
| Full analysis: | https://app.any.run/tasks/0638f24a-2caa-4f97-801d-755bafaa4dd1 |
| Verdict: | Malicious activity |
| Analysis date: | December 02, 2023, 13:42:00 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 09BDE3BB861CE3000EE89317AFC5D473 |
| SHA1: | 55CFD448C57ED6D5842D40FAC752967DCD630238 |
| SHA256: | 581CC169F6B3236C06B1C54D805F8950C9DC8BC8D6DF7F7EAB6D50CFFF59B1E8 |
| SSDEEP: | 6144:kCpVej/t9JAy89+J9Wz0p/y7t6nS5LUmoDHFBysLkhKbTi9z+eWExNFlYiZLN/51:ilP39i09QtRUmCFByekh8TA/h1GslP |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2016:04:03 00:14:34+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 114176 |
| InitializedDataSize: | 56320 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1c35f |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1344 | C:\Windows\system32\net1 start RdpGuardService | C:\Windows\System32\net1.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2084 | C:\Windows\system32\net1 stop RdpGuardService | C:\Windows\System32\net1.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2132 | C:\Windows\system32\net1 start RdpGuardProxy | C:\Windows\System32\net1.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2620 | net start RdpGuardProxy | C:\Windows\System32\net.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2908 | net start RdpGuardService | C:\Windows\System32\net.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2920 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\%ProgramFiles(x86)%\RDPGuardProxyServer\Install.cmd" " | C:\Windows\System32\cmd.exe | — | RDPGuardProxyServer_Install.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2928 | .\MSGBOX.EXE "Installation completed" "MessageBox Test" CANCEL | C:\Users\admin\AppData\Local\Temp\%ProgramFiles(x86)%\RDPGuardProxyServer\MSGBOX.EXE | — | cmd.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 2956 | "C:\Users\admin\AppData\Local\Temp\RDPGuardProxyServer_Install.exe" -sfxelevation | C:\Users\admin\AppData\Local\Temp\RDPGuardProxyServer_Install.exe | RDPGuardProxyServer_Install.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3060 | "C:\Users\admin\AppData\Local\Temp\RDPGuardProxyServer_Install.exe" | C:\Users\admin\AppData\Local\Temp\RDPGuardProxyServer_Install.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3784 | net stop RdpGuardService | C:\Windows\System32\net.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3060) RDPGuardProxyServer_Install.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3060) RDPGuardProxyServer_Install.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3060) RDPGuardProxyServer_Install.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3060) RDPGuardProxyServer_Install.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2956) RDPGuardProxyServer_Install.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2956) RDPGuardProxyServer_Install.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2956) RDPGuardProxyServer_Install.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2956) RDPGuardProxyServer_Install.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2956 | RDPGuardProxyServer_Install.exe | C:\Users\admin\AppData\Local\Temp\%ProgramFiles(x86)%\RDPGuardProxyServer\RDPGuardProxyServer.exe.config | xml | |
MD5:C43D8E5E77C3CD8E1FDE7C2FC7881237 | SHA256:5667FC104528BAB9E532FF2487AF8466E8260F043272261AE1399B4AFE393B12 | |||
| 2956 | RDPGuardProxyServer_Install.exe | C:\Users\admin\AppData\Local\Temp\%ProgramFiles(x86)%\RDPGuardProxyServer\Uninstall.cmd | text | |
MD5:8F73C1A2FBB6D2FE1E4880F3D5D943BE | SHA256:4291B478B79507C493A7F953CDC9C4040E125EE4E9FC50E8172F37152446E065 | |||
| 2956 | RDPGuardProxyServer_Install.exe | C:\Users\admin\AppData\Local\Temp\%ProgramFiles(x86)%\RDPGuardProxyServer\Install.cmd | text | |
MD5:C562A7170DD8D8BB77167CBE2BB77D3B | SHA256:4C90ABB8B7449D3A0541FD6AC148F1B885258EDB6D513EEBE758A6F56F59A226 | |||
| 2956 | RDPGuardProxyServer_Install.exe | C:\Users\admin\AppData\Local\Temp\%ProgramFiles(x86)%\RDPGuardProxyServer\RDPGuardProxyServer.exe | executable | |
MD5:B09542F659D6B0B3CC349045BD91FA63 | SHA256:3301A1206A735681DC53B43F4141499CA08AA868EF1B381FE30CC825622D66BD | |||
| 2956 | RDPGuardProxyServer_Install.exe | C:\Users\admin\AppData\Local\Temp\%ProgramFiles(x86)%\RDPGuardProxyServer\MSGBOX.EXE | executable | |
MD5:2819EFA329BC227BE0BA231F286B376D | SHA256:E4757A0522FE679988D869E67908257DC05F207FB948D653AA5905AC7B7AF8D5 | |||
| 2956 | RDPGuardProxyServer_Install.exe | C:\Users\admin\AppData\Local\Temp\%ProgramFiles(x86)%\RDPGuardProxyServer\RestartService.cmd | text | |
MD5:3F44657ED02169B7298F21988FCA5085 | SHA256:92691C3C1273349FD2BF340C0F20C6F348AB20182E1D193910259478070603E5 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |