File name:

mb-support-1.9.2.982.exe

Full analysis: https://app.any.run/tasks/4e825a0f-1dce-4971-9682-36fa4d8b3ccf
Verdict: Malicious activity
Analysis date: November 20, 2023, 22:25:34
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

C82A2CC9E8E79C844F3624681375559C

SHA1:

54684CF73F7887C3026D14C4886DA3156618FF7B

SHA256:

596D5BDFCCBE94A9EE90DE56AD3E9C67DBEA0B8E72F1A0BD4364F10B3B9A4080

SSDEEP:

196608:gBaLQTFY5WxLDgEjz2UpozDSIIOAsmGFgaiyZYk:5LQhNnH2UpSSce29d

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • mbstub.exe (PID: 3512)
      • mb-support-1.9.3.992.exe.download (PID: 3668)
      • mb-support-1.9.2.982.exe (PID: 2424)
      • mbstub.exe (PID: 3640)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • mb-support-1.9.2.982.exe (PID: 2424)
      • mbstub.exe (PID: 3640)
      • mb-support-1.9.3.992.exe.download (PID: 3668)
    • Drops 7-zip archiver for unpacking

      • mb-support-1.9.2.982.exe (PID: 2424)
      • mb-support-1.9.3.992.exe.download (PID: 3668)
      • mbstub.exe (PID: 3640)
    • The process drops C-runtime libraries

      • mb-support-1.9.2.982.exe (PID: 2424)
      • mb-support-1.9.3.992.exe.download (PID: 3668)
      • mbstub.exe (PID: 3640)
    • Starts application with an unusual extension

      • mbstub.exe (PID: 3512)
    • Checks Windows Trust Settings

      • mb-support.exe (PID: 3880)
    • Reads the Internet Settings

      • mb-support.exe (PID: 3880)
    • Reads security settings of Internet Explorer

      • mb-support.exe (PID: 3880)
    • Adds/modifies Windows certificates

      • mbstub.exe (PID: 3640)
    • Searches for installed software

      • mb-support.exe (PID: 3880)
    • Reads the BIOS version

      • mb-support.exe (PID: 3880)
    • Reads settings of System Certificates

      • mb-support.exe (PID: 3880)
    • The process verifies whether the antivirus software is installed

      • mb-support.exe (PID: 3880)
  • INFO

    • Checks supported languages

      • mb-support-1.9.2.982.exe (PID: 2424)
      • mbstub.exe (PID: 3512)
      • wmpnscfg.exe (PID: 3276)
      • mb-support-1.9.3.992.exe.download (PID: 3668)
      • mbstub.exe (PID: 3640)
      • mb-support.exe (PID: 3880)
    • Create files in a temporary directory

      • mb-support-1.9.2.982.exe (PID: 2424)
      • mbstub.exe (PID: 3512)
      • mb-support-1.9.3.992.exe.download (PID: 3668)
      • mbstub.exe (PID: 3640)
      • mb-support.exe (PID: 3880)
    • Reads the computer name

      • mbstub.exe (PID: 3512)
      • wmpnscfg.exe (PID: 3276)
      • mbstub.exe (PID: 3640)
      • mb-support.exe (PID: 3880)
    • Reads the machine GUID from the registry

      • mbstub.exe (PID: 3512)
      • wmpnscfg.exe (PID: 3276)
      • mbstub.exe (PID: 3640)
      • mb-support.exe (PID: 3880)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3276)
    • Creates files in the program directory

      • mb-support.exe (PID: 3880)
    • Creates files or folders in the user directory

      • mb-support.exe (PID: 3880)
    • Reads Environment values

      • mb-support.exe (PID: 3880)
    • Reads product name

      • mb-support.exe (PID: 3880)
    • Reads Windows Product ID

      • mb-support.exe (PID: 3880)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:11:18 17:27:35+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 104960
InitializedDataSize: 607744
UninitializedDataSize: -
EntryPoint: 0x14b04
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.9.2.982
ProductVersionNumber: 1.9.2.982
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: Malwarebytes Support Tool
FileVersion: 1.9.2.982
LegalCopyright: Copyright (c) 2017, Malwarebytes
OriginalFileName: mb-support.exe
ProductName: Malwarebytes Support Tool
ProductVersion: 1.9.2.982
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
9
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start mb-support-1.9.2.982.exe mbstub.exe wmpnscfg.exe no specs mb-support-1.9.3.992.exe.download no specs mbstub.exe mb-support.exe wisptis.exe no specs wisptis.exe no specs mb-support-1.9.2.982.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2424"C:\Users\admin\AppData\Local\Temp\mb-support-1.9.2.982.exe" C:\Users\admin\AppData\Local\Temp\mb-support-1.9.2.982.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Malwarebytes Support Tool
Exit code:
0
Version:
1.9.2.982
Modules
Images
c:\users\admin\appdata\local\temp\mb-support-1.9.2.982.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3212"C:\Users\admin\AppData\Local\Temp\mb-support-1.9.2.982.exe" C:\Users\admin\AppData\Local\Temp\mb-support-1.9.2.982.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Malwarebytes Support Tool
Exit code:
3221226540
Version:
1.9.2.982
Modules
Images
c:\users\admin\appdata\local\temp\mb-support-1.9.2.982.exe
c:\windows\system32\ntdll.dll
3276"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3512.\mbstub.exeC:\Users\admin\AppData\Local\Temp\7zS84F4.tmp\mbstub.exe
mb-support-1.9.2.982.exe
User:
admin
Company:
Malwarebytes Corporation
Integrity Level:
HIGH
Exit code:
0
Version:
1.9.2.982
Modules
Images
c:\users\admin\appdata\local\temp\7zs84f4.tmp\mbstub.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3640.\mbstub.exeC:\Users\admin\AppData\Local\Temp\7zSB8D5.tmp\mbstub.exe
mb-support-1.9.3.992.exe.download
User:
admin
Company:
Malwarebytes Corporation
Integrity Level:
HIGH
Exit code:
0
Version:
1.9.3.992
Modules
Images
c:\users\admin\appdata\local\temp\7zsb8d5.tmp\mbstub.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3668C:\Users\admin\AppData\Local\Temp\7zS84F4.tmp\mb-support-1.9.3.992.exe.download C:\Users\admin\AppData\Local\Temp\7zS84F4.tmp\mb-support-1.9.3.992.exe.downloadmbstub.exe
User:
admin
Integrity Level:
HIGH
Description:
Malwarebytes Support Tool
Exit code:
0
Version:
1.9.3.992
Modules
Images
c:\users\admin\appdata\local\temp\7zs84f4.tmp\mb-support-1.9.3.992.exe.download
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3880C:\Users\admin\AppData\Local\Temp\mwbD7A8.tmp\mb-support.exe C:\Users\admin\AppData\Local\Temp\mwbD7A8.tmp\mb-support.exe
mbstub.exe
User:
admin
Company:
Malwarebytes Corporation
Integrity Level:
HIGH
Description:
mb-support
Exit code:
0
Version:
1.9.3.992
Modules
Images
c:\users\admin\appdata\local\temp\mwbd7a8.tmp\mb-support.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3948"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\System32\wisptis.exemb-support.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
3221226540
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
4004"C:\Windows\SYSTEM32\WISPTIS.EXE" /ManualLaunch;C:\Windows\System32\wisptis.exemb-support.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Pen and Touch Input Component
Exit code:
24
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\wisptis.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
Total events
10 578
Read events
10 544
Write events
31
Delete events
3

Modification events

(PID) Process:(3276) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{6795B525-54E7-4B67-9904-9578937BE973}\{887EF30A-394B-4556-A1F0-DD9F128739A2}
Operation:delete keyName:(default)
Value:
(PID) Process:(3276) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{6795B525-54E7-4B67-9904-9578937BE973}
Operation:delete keyName:(default)
Value:
(PID) Process:(3276) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{526E136E-7AC2-4B77-8B06-6434DC660AB8}
Operation:delete keyName:(default)
Value:
(PID) Process:(3640) mbstub.exeKey:HKEY_CURRENT_USER\Software\Malwarebytes Support Tool
Operation:writeName:LogfileDir
Value:
C:\Users\admin\AppData\Local\Temp\
(PID) Process:(3880) mb-support.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Explorer.EXE
(PID) Process:(3880) mb-support.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3880) mb-support.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3880) mb-support.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3880) mb-support.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(4004) wisptis.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
mb-support.exe
Executable files
210
Suspicious files
15
Text files
31
Unknown types
0

Dropped files

PID
Process
Filename
Type
2424mb-support-1.9.2.982.exeC:\Users\admin\AppData\Local\Temp\7zS84F4.tmp\api-ms-win-core-console-l1-2-0.dllexecutable
MD5:9B630E1445F1E687284077EECD999B03
SHA256:EFD664C9F87B370A530CEA5FCAEC3D248F5C9D79E749862B3EB63448292AB20F
2424mb-support-1.9.2.982.exeC:\Users\admin\AppData\Local\Temp\7zS84F4.tmp\ERUNT.LOCtext
MD5:02187B1B6F37B3D0030791C802A6174C
SHA256:FB96FB9575FAD8DF03DF5E48B7EC0BD9A151EBABC9DD949867B087EA925F33DA
2424mb-support-1.9.2.982.exeC:\Users\admin\AppData\Local\Temp\7zS84F4.tmp\mb-support.exe.configxml
MD5:98F89BB9A633013AB63D68BEB251FBA8
SHA256:50B55DD61E74F8E9D9EC62EC1B3D509E92EB310C1778AD62BFA044998C6FDCEA
2424mb-support-1.9.2.982.exeC:\Users\admin\AppData\Local\Temp\7zS84F4.tmp\mbstub.iobjbinary
MD5:39F756AC7952510FCD61BD911AA38452
SHA256:5737E98CD6CEB453CF3DB8BE8D700F35B7A6929F43AE9E5974BAEFFAA6A2F86A
2424mb-support-1.9.2.982.exeC:\Users\admin\AppData\Local\Temp\7zS84F4.tmp\7z.dllexecutable
MD5:04E4F293970589EAD1DC19FC8BE60C92
SHA256:6CD22F513CE36B4727BB6C353C58182C7CC8A14CBE3EEFDCA85C2A25906A0077
2424mb-support-1.9.2.982.exeC:\Users\admin\AppData\Local\Temp\7zS84F4.tmp\mbstub.ipdbbinary
MD5:B2FB8AB3D2858E367EDD158F9B8F46B2
SHA256:12C74BA627B7612AC04F9C8CA03A52D74F8457D6468629AB34A7A5999ED239B9
2424mb-support-1.9.2.982.exeC:\Users\admin\AppData\Local\Temp\7zS84F4.tmp\api-ms-win-core-console-l1-1-0.dllexecutable
MD5:A47A7084D4ED2FB6B9181075F91729A0
SHA256:9490C5938112242CADC2C676F82B60FDCC7E5F56CAA7AA2D2BA3A6ED358683D4
2424mb-support-1.9.2.982.exeC:\Users\admin\AppData\Local\Temp\7zS84F4.tmp\Malwarebytes EULA.rtftext
MD5:51A2CD07C31DCA35BFA81DBD89BEE80F
SHA256:D9B5D2EF035B82722AE426171A46A855066AB6F83DCB2785917BE27A1D441820
2424mb-support-1.9.2.982.exeC:\Users\admin\AppData\Local\Temp\7zS84F4.tmp\ERDNT.E_Eexecutable
MD5:89AFDD29832AA923926BDD4B5F5243D5
SHA256:A559F249FC0E56BC925609773F6CC9CD1826BF70916BE1D6370CE4707A6DFD84
2424mb-support-1.9.2.982.exeC:\Users\admin\AppData\Local\Temp\7zS84F4.tmp\ERDNTDOS.LOCbinary
MD5:F9650A5C954D2A9F8844DE99E8577F93
SHA256:3C3BA112731C697B8700DE546195C4A02F96F4FE28D39A75551F932985E0C15E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
17
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3880
mb-support.exe
GET
200
23.50.131.216:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?4f7dc9825258e478
unknown
compressed
61.6 Kb
unknown
3880
mb-support.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/certs/Microsoft%20Identity%20Verification%20Root%20Certificate%20Authority%202020.crt
unknown
binary
1.45 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2588
svchost.exe
239.255.255.250:1900
whitelisted
3512
mbstub.exe
3.221.172.153:443
ark.mwbsys.com
AMAZON-AES
US
unknown
3512
mbstub.exe
99.86.4.25:443
cdn.mwbsys.com
AMAZON-02
US
unknown
3640
mbstub.exe
3.221.172.153:443
ark.mwbsys.com
AMAZON-AES
US
unknown
3640
mbstub.exe
13.32.121.10:443
mbst.mwbsys.com
AMAZON-02
US
unknown
3640
mbstub.exe
52.222.214.43:443
downloads.malwarebytes.com
AMAZON-02
US
unknown
3640
mbstub.exe
104.20.184.56:443
download.bleepingcomputer.com
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
ark.mwbsys.com
  • 54.87.77.136
  • 34.204.128.6
  • 3.221.172.153
unknown
cdn.mwbsys.com
  • 99.86.4.118
  • 99.86.4.25
  • 99.86.4.35
  • 99.86.4.72
whitelisted
mbst.mwbsys.com
  • 13.32.121.16
  • 13.32.121.10
  • 13.32.121.93
  • 13.32.121.97
unknown
downloads.malwarebytes.com
  • 52.222.214.90
  • 52.222.214.121
  • 52.222.214.43
  • 52.222.214.71
whitelisted
download.bleepingcomputer.com
  • 104.20.185.56
  • 172.67.2.229
  • 104.20.184.56
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
ctldl.windowsupdate.com
  • 23.50.131.216
  • 23.50.131.200
whitelisted
telemetry.malwarebytes.com
  • 35.85.71.64
  • 44.238.168.181
  • 54.148.127.188
  • 52.27.99.226
  • 52.89.141.64
  • 35.81.239.22
whitelisted

Threats

No threats detected
Process
Message
mb-support.exe
Application_Startup
mb-support.exe
Starting TaskReadLogFile thread
mb-support.exe
WebRequestClient
mb-support.exe
Disposing of managed resources.
mb-support.exe
*****Call Dispose ****
mb-support.exe
Disposing of unmanaged resources.
mb-support.exe
Disposing of managed resources.
mb-support.exe
*****Call Dispose ****
mb-support.exe
Disposing of unmanaged resources.
mb-support.exe
WebRequestClient