| File name: | Cow and chicken Season 1.exe |
| Full analysis: | https://app.any.run/tasks/3e87c56d-e842-4d80-82a0-85599bf7731c |
| Verdict: | Malicious activity |
| Analysis date: | October 18, 2023, 15:40:55 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 1C5FE79233C49389E4F2A7A6E3382CA0 |
| SHA1: | E36FC4D4A909271C21A9F61DCB50A483A574FE4D |
| SHA256: | 5A4EFF64FB4B0ABE28B640EEC4842F4C8E8F0C8499715D6869416DEE6A2FCC4D |
| SSDEEP: | 98304:u+QqZ8fNTYoRZMcXS5j+pge6FYOsaqroNGA25lDkYrRdPAVqVS1967C3ZIAcHs+X:hPx2 |
| .exe | | | Inno Setup installer (67.7) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (25.6) |
| .exe | | | Win32 Executable (generic) (2.7) |
| .exe | | | Win16/32 Executable Delphi generic (1.2) |
| .exe | | | Generic Win/DOS Executable (1.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:09:13 11:00:51+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741376 |
| InitializedDataSize: | 95232 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6.1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Sordum |
| FileDescription: | Reduce Memory Setup |
| FileVersion: | |
| LegalCopyright: | |
| OriginalFileName: | |
| ProductName: | Reduce Memory |
| ProductVersion: | 1.6.2 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 276 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2244 --field-trial-handle=1292,i,4771818203919975876,16191931371084666738,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1016 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.PageScreenshotProcessor --lang=en-US --service-sandbox-type=entity_extraction --mojo-platform-channel-handle=3392 --field-trial-handle=1292,i,4771818203919975876,16191931371084666738,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1016 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.PageScreenshotProcessor --lang=en-US --service-sandbox-type=entity_extraction --mojo-platform-channel-handle=4840 --field-trial-handle=1292,i,4771818203919975876,16191931371084666738,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1052 | "C:\Users\admin\AppData\Local\Temp\is-SUNSP.tmp\Cow and chicken Season 1.tmp" /SL5="$1001CA,1688766,837632,C:\Users\admin\AppData\Local\Temp\Cow and chicken Season 1.exe" | C:\Users\admin\AppData\Local\Temp\is-SUNSP.tmp\Cow and chicken Season 1.tmp | — | Cow and chicken Season 1.exe | |||||||||||
User: admin Company: Sordum Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1164 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1256 --field-trial-handle=1292,i,4771818203919975876,16191931371084666738,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1740 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=28 --mojo-platform-channel-handle=1572 --field-trial-handle=1292,i,4771818203919975876,16191931371084666738,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1872 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4072 --field-trial-handle=1292,i,4771818203919975876,16191931371084666738,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1872 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=22 --mojo-platform-channel-handle=1196 --field-trial-handle=1292,i,4771818203919975876,16191931371084666738,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2096 | sc start ServiceUI | C:\Windows\System32\sc.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: A tool to aid in developing services for WindowsNT Exit code: 1060 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2100 | "C:\Users\admin\AppData\Local\Temp\is-F9MTI.tmp\Cow and chicken Season 1.tmp" /SL5="$B01D0,1688766,837632,C:\Users\admin\AppData\Local\Temp\Cow and chicken Season 1.exe" /SPAWNWND=$140220 /NOTIFYWND=$1001CA | C:\Users\admin\AppData\Local\Temp\is-F9MTI.tmp\Cow and chicken Season 1.tmp | — | Cow and chicken Season 1.exe | |||||||||||
User: admin Company: Sordum Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| (PID) Process: | (2100) Cow and chicken Season 1.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFilesHash |
Value: 0F5A107B7CD94AAC42989600A5C5A83DA5136B2A245557EC0B26FF85635A4B0B | |||
| (PID) Process: | (2100) Cow and chicken Season 1.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFiles0000 |
Value: C:\Windows\system32\UITheme.exe | |||
| (PID) Process: | (2100) Cow and chicken Season 1.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (2100) Cow and chicken Season 1.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | SessionHash |
Value: 6C22066131C661F4A6FF4E7E7B9D1B9F28D358703478649BEC1E746C7FB9F983 | |||
| (PID) Process: | (2100) Cow and chicken Season 1.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Owner |
Value: 34080000EEBFA383D901DA01 | |||
| (PID) Process: | (2100) Cow and chicken Season 1.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3180) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (3180) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (3180) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (3180) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2752 | Cow and chicken Season 1.exe | C:\Users\admin\AppData\Local\Temp\is-SUNSP.tmp\Cow and chicken Season 1.tmp | executable | |
MD5:BEB79419FD55E1F3613D7374621EE2C6 | SHA256:24867B793C3118A9466B5EDC67AA28BF002CBC157BF4C920B1B0E495F08E748E | |||
| 2100 | Cow and chicken Season 1.tmp | C:\Users\admin\AppData\Local\Temp\is-JLVKN.tmp\_isetup\_isdecmp.dll | executable | |
MD5:C6AE924AD02500284F7E4EFA11FA7CFC | SHA256:31D04C1E4BFDFA34704C142FA98F80C0A3076E4B312D6ADA57C4BE9D9C7DCF26 | |||
| 2100 | Cow and chicken Season 1.tmp | C:\Windows\system32\is-2FGTQ.tmp | executable | |
MD5:2A7A5E836B4038F65F6266E23826449D | SHA256:A5A1A452D86B2F1DC120BCD764C479DA00A57D070595AEFAB57BEF9B85CFA8E2 | |||
| 2100 | Cow and chicken Season 1.tmp | C:\Program Files\Reduce Memory\unins000.exe | executable | |
MD5:B0726E54238426D226426505D5ADCDDE | SHA256:8BF3370E459922ECBC858D2A55D7E33DE9893CCAC7E3C67898107AF266CC1824 | |||
| 2100 | Cow and chicken Season 1.tmp | C:\Program Files\Reduce Memory\is-158NA.tmp | executable | |
MD5:B0726E54238426D226426505D5ADCDDE | SHA256:8BF3370E459922ECBC858D2A55D7E33DE9893CCAC7E3C67898107AF266CC1824 | |||
| 2100 | Cow and chicken Season 1.tmp | C:\Users\admin\AppData\Local\Temp\is-JLVKN.tmp\update.bat | text | |
MD5:7750D3957B8D273A0E7ED2F286271C9C | SHA256:E954A52EB9053A5810BD794746C53B83D845DC8BDC1C7C5BA7529DE58BCD9B9E | |||
| 2100 | Cow and chicken Season 1.tmp | C:\Windows\system32\is-3OVOO.tmp | text | |
MD5:83AF222B4BEEFE0AC1933962BB0AD69B | SHA256:6D6846C5A7D4C4F4E25AD1E2FEE681CF8BEE4B0208D5263C1B8667B767A13A5B | |||
| 2100 | Cow and chicken Season 1.tmp | C:\Users\admin\AppData\Local\Sordum\first.json | text | |
MD5:83A0339E495CAFCFC2C18AD4797DD252 | SHA256:A74E0E0FB1D7F8C2904624170CD1D04A8CDE57E0BF15AFB1A27B6C9BE39FA002 | |||
| 2100 | Cow and chicken Season 1.tmp | C:\Users\admin\AppData\Local\Sordum\is-UO5KS.tmp | text | |
MD5:83AF222B4BEEFE0AC1933962BB0AD69B | SHA256:6D6846C5A7D4C4F4E25AD1E2FEE681CF8BEE4B0208D5263C1B8667B767A13A5B | |||
| 2100 | Cow and chicken Season 1.tmp | C:\Users\admin\AppData\Local\Sordum\update.json | text | |
MD5:83AF222B4BEEFE0AC1933962BB0AD69B | SHA256:6D6846C5A7D4C4F4E25AD1E2FEE681CF8BEE4B0208D5263C1B8667B767A13A5B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3180 | msedge.exe | GET | 200 | 151.101.2.133:80 | http://secure.globalsign.com/cacert/codesigningrootr45.crt | unknown | binary | 1.37 Kb | unknown |
3220 | msedge.exe | GET | 301 | 165.22.37.71:80 | http://ziptechapp.com/wp-content/uploads/sites/24/2023/06/ziptechlogo-1-1024x252.png | unknown | text | 17 b | unknown |
3180 | msedge.exe | GET | 200 | 209.197.3.8:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?cf615d9a96dec79e | unknown | compressed | 61.6 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3220 | msedge.exe | 13.107.43.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
3180 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3220 | msedge.exe | 185.146.22.240:443 | www.sordum.org | A2HOSTING | US | unknown |
3220 | msedge.exe | 20.105.95.163:443 | nav-edge.smartscreen.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
3220 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
3220 | msedge.exe | 172.217.17.104:443 | www.googletagmanager.com | GOOGLE | US | whitelisted |
3220 | msedge.exe | 142.250.184.130:443 | pagead2.googlesyndication.com | GOOGLE | US | unknown |
Domain | IP | Reputation |
|---|---|---|
www.sordum.org |
| unknown |
config.edge.skype.com |
| whitelisted |
nav-edge.smartscreen.microsoft.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
data-edge.smartscreen.microsoft.com |
| whitelisted |
www.googletagmanager.com |
| whitelisted |
pagead2.googlesyndication.com |
| whitelisted |
www.bing.com |
| whitelisted |
www.google-analytics.com |
| whitelisted |
googleads.g.doubleclick.net |
| whitelisted |