File name:

RDPGuardProxyServer_Install.exe

Full analysis: https://app.any.run/tasks/0638f24a-2caa-4f97-801d-755bafaa4dd1
Verdict: Malicious activity
Analysis date: December 02, 2023, 13:42:00
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

09BDE3BB861CE3000EE89317AFC5D473

SHA1:

55CFD448C57ED6D5842D40FAC752967DCD630238

SHA256:

581CC169F6B3236C06B1C54D805F8950C9DC8BC8D6DF7F7EAB6D50CFFF59B1E8

SSDEEP:

6144:kCpVej/t9JAy89+J9Wz0p/y7t6nS5LUmoDHFBysLkhKbTi9z+eWExNFlYiZLN/51:ilP39i09QtRUmCFByekh8TA/h1GslP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • RDPGuardProxyServer_Install.exe (PID: 2956)
    • Starts NET.EXE for service management

      • net.exe (PID: 2620)
      • cmd.exe (PID: 2920)
      • net.exe (PID: 3784)
      • net.exe (PID: 2908)
  • SUSPICIOUS

    • Reads the Internet Settings

      • RDPGuardProxyServer_Install.exe (PID: 2956)
      • RDPGuardProxyServer_Install.exe (PID: 3060)
    • Starts CMD.EXE for commands execution

      • RDPGuardProxyServer_Install.exe (PID: 2956)
    • Application launched itself

      • RDPGuardProxyServer_Install.exe (PID: 3060)
    • Executing commands from ".cmd" file

      • RDPGuardProxyServer_Install.exe (PID: 2956)
  • INFO

    • Checks supported languages

      • RDPGuardProxyServer_Install.exe (PID: 2956)
      • MSGBOX.EXE (PID: 2928)
      • RDPGuardProxyServer_Install.exe (PID: 3060)
    • Reads the computer name

      • RDPGuardProxyServer_Install.exe (PID: 2956)
      • RDPGuardProxyServer_Install.exe (PID: 3060)
    • Create files in a temporary directory

      • RDPGuardProxyServer_Install.exe (PID: 2956)
    • The executable file from the user directory is run by the CMD process

      • MSGBOX.EXE (PID: 2928)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:04:03 00:14:34+02:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 114176
InitializedDataSize: 56320
UninitializedDataSize: -
EntryPoint: 0x1c35f
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
10
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start rdpguardproxyserver_install.exe no specs rdpguardproxyserver_install.exe cmd.exe no specs net.exe no specs net1.exe no specs net.exe no specs net1.exe no specs net.exe no specs net1.exe no specs msgbox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1344C:\Windows\system32\net1 start RdpGuardServiceC:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
2084C:\Windows\system32\net1 stop RdpGuardServiceC:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
2132C:\Windows\system32\net1 start RdpGuardProxyC:\Windows\System32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
2620net start RdpGuardProxyC:\Windows\System32\net.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
2908net start RdpGuardServiceC:\Windows\System32\net.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
2920C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\%ProgramFiles(x86)%\RDPGuardProxyServer\Install.cmd" "C:\Windows\System32\cmd.exeRDPGuardProxyServer_Install.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2928.\MSGBOX.EXE "Installation completed" "MessageBox Test" CANCELC:\Users\admin\AppData\Local\Temp\%ProgramFiles(x86)%\RDPGuardProxyServer\MSGBOX.EXEcmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\users\admin\appdata\local\temp\%programfiles(x86)%\rdpguardproxyserver\msgbox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
2956"C:\Users\admin\AppData\Local\Temp\RDPGuardProxyServer_Install.exe" -sfxelevation C:\Users\admin\AppData\Local\Temp\RDPGuardProxyServer_Install.exe
RDPGuardProxyServer_Install.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rdpguardproxyserver_install.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3060"C:\Users\admin\AppData\Local\Temp\RDPGuardProxyServer_Install.exe" C:\Users\admin\AppData\Local\Temp\RDPGuardProxyServer_Install.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\rdpguardproxyserver_install.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3784net stop RdpGuardServiceC:\Windows\System32\net.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
2
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
Total events
1 585
Read events
1 569
Write events
16
Delete events
0

Modification events

(PID) Process:(3060) RDPGuardProxyServer_Install.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3060) RDPGuardProxyServer_Install.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3060) RDPGuardProxyServer_Install.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3060) RDPGuardProxyServer_Install.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2956) RDPGuardProxyServer_Install.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2956) RDPGuardProxyServer_Install.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2956) RDPGuardProxyServer_Install.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2956) RDPGuardProxyServer_Install.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
2
Suspicious files
0
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
2956RDPGuardProxyServer_Install.exeC:\Users\admin\AppData\Local\Temp\%ProgramFiles(x86)%\RDPGuardProxyServer\RDPGuardProxyServer.exe.configxml
MD5:C43D8E5E77C3CD8E1FDE7C2FC7881237
SHA256:5667FC104528BAB9E532FF2487AF8466E8260F043272261AE1399B4AFE393B12
2956RDPGuardProxyServer_Install.exeC:\Users\admin\AppData\Local\Temp\%ProgramFiles(x86)%\RDPGuardProxyServer\Uninstall.cmdtext
MD5:8F73C1A2FBB6D2FE1E4880F3D5D943BE
SHA256:4291B478B79507C493A7F953CDC9C4040E125EE4E9FC50E8172F37152446E065
2956RDPGuardProxyServer_Install.exeC:\Users\admin\AppData\Local\Temp\%ProgramFiles(x86)%\RDPGuardProxyServer\Install.cmdtext
MD5:C562A7170DD8D8BB77167CBE2BB77D3B
SHA256:4C90ABB8B7449D3A0541FD6AC148F1B885258EDB6D513EEBE758A6F56F59A226
2956RDPGuardProxyServer_Install.exeC:\Users\admin\AppData\Local\Temp\%ProgramFiles(x86)%\RDPGuardProxyServer\RDPGuardProxyServer.exeexecutable
MD5:B09542F659D6B0B3CC349045BD91FA63
SHA256:3301A1206A735681DC53B43F4141499CA08AA868EF1B381FE30CC825622D66BD
2956RDPGuardProxyServer_Install.exeC:\Users\admin\AppData\Local\Temp\%ProgramFiles(x86)%\RDPGuardProxyServer\MSGBOX.EXEexecutable
MD5:2819EFA329BC227BE0BA231F286B376D
SHA256:E4757A0522FE679988D869E67908257DC05F207FB948D653AA5905AC7B7AF8D5
2956RDPGuardProxyServer_Install.exeC:\Users\admin\AppData\Local\Temp\%ProgramFiles(x86)%\RDPGuardProxyServer\RestartService.cmdtext
MD5:3F44657ED02169B7298F21988FCA5085
SHA256:92691C3C1273349FD2BF340C0F20C6F348AB20182E1D193910259478070603E5
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info