File name: | DOC001.exe |
Full analysis: | https://app.any.run/tasks/f70dc0c7-bd80-4f33-af82-b7d7e95f48ee |
Verdict: | Malicious activity |
Analysis date: | December 18, 2023, 05:51:23 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
MD5: | DF11B3105DF8D7C70E7B501E210E3CC3 |
SHA1: | 01BA101C4355B18EC11652A9AB6F8994279BA769 |
SHA256: | 59F1E69B68DE4839C65B6E6D39AC7A272E2611EC1ED1BF73A4F455E2CA20EEAA |
SSDEEP: | 49152:if4tcOW4mwkylp3yj7SWGpHE3EFBD+njb9ClK:usuZDeJAcBSXUlK |
.exe | | | NSIS - Nullsoft Scriptable Install System (94.8) |
---|---|---|
.exe | | | Win32 Executable MS Visual C++ (generic) (3.4) |
.dll | | | Win32 Dynamic Link Library (generic) (0.7) |
.exe | | | Win32 Executable (generic) (0.5) |
.exe | | | Generic Win/DOS Executable (0.2) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2009:12:05 23:52:12+01:00 |
ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
PEType: | PE32 |
LinkerVersion: | 6 |
CodeSize: | 24064 |
InitializedDataSize: | 308224 |
UninitializedDataSize: | 8192 |
EntryPoint: | 0x30fa |
OSVersion: | 4 |
ImageVersion: | 6 |
SubsystemVersion: | 4 |
Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
296 | "C:\Users\admin\AppData\Roaming\TempoR\DOC001.exe" | C:\Users\admin\AppData\Roaming\TempoR\DOC001.exe | DOC001.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
1776 | "C:\Users\admin\AppData\Local\Temp\DOC001.exe" | C:\Users\admin\AppData\Local\Temp\DOC001.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 2 Modules
| |||||||||||||||
2184 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
|
(PID) Process: | (1776) DOC001.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (1776) DOC001.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (1776) DOC001.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (1776) DOC001.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (296) DOC001.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
(PID) Process: | (296) DOC001.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
Operation: | write | Name: | SavedLegacySettings |
Value: 460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (296) DOC001.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (296) DOC001.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (296) DOC001.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (296) DOC001.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
1776 | DOC001.exe | C:\Users\admin\AppData\Roaming\TempoR\DOC001.exe | executable | |
MD5:DF11B3105DF8D7C70E7B501E210E3CC3 | SHA256:59F1E69B68DE4839C65B6E6D39AC7A272E2611EC1ED1BF73A4F455E2CA20EEAA | |||
296 | DOC001.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\explorer.lnk | binary | |
MD5:128E267BE8679E2FE3481199F030C609 | SHA256:5DF1006CB2D1F92B031569FB5BF50E6873B4DB113179BFC11688BF3D267B83C1 | |||
296 | DOC001.exe | C:\Users\admin\AppData\Roaming\TempoR\NsCpuCNMiner32.exe | executable | |
MD5:E8E50CFA7F6FE0C3B54CB1E11E92960C | SHA256:C4DEB1F76A1A5127964FAB44E4D9B3EBBB36B1FEDFB640DF5A4C428C89CEDB35 | |||
296 | DOC001.exe | C:\Users\admin\AppData\Local\Temp\nsqFE47.tmp\inetc.dll | executable | |
MD5:D7A3FA6A6C738B4A3C40D5602AF20B08 | SHA256:67EFF17C53A78C8EC9A28F392B9BB93DF3E74F96F6ECD87A333A482C36546B3E | |||
296 | DOC001.exe | C:\Users\admin\AppData\Roaming\TempoR\NsCpuCNMiner64.exe | executable | |
MD5:6E6D33D666387647A22A9ABD0DD6D50D | SHA256:55766C74C458D5439688F44CEEF926D27EE57E7CE418B9AF574331ECC54B4816 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
296 | DOC001.exe | GET | 404 | 185.26.112.217:80 | http://kr1s.ru/java.dat | unknown | html | 1.18 Kb | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
296 | DOC001.exe | 185.26.112.217:80 | kr1s.ru | Jsc ru-center | RU | unknown |
Domain | IP | Reputation |
---|---|---|
kr1s.ru |
| unknown |
zcop.ru |
| unknown |
PID | Process | Class | Message |
---|---|---|---|
— | — | Potentially Bad Traffic | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) |