File name:

Profit.exe

Full analysis: https://app.any.run/tasks/4b9aa00b-969d-40f9-96eb-9700a5f1f645
Verdict: Malicious activity
Analysis date: March 26, 2024, 18:40:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

33F45F6648DF64FAEF65A54DC3155644

SHA1:

D0EA0A92480B6F1C35D72572669965DFBA09F62A

SHA256:

5B1C74FA97815506FE923F656E34E08A3260A29CB02693E58B3A105E5A8F13AF

SSDEEP:

98304:VkKEIjkxdolUDdWZHHG1suY9lR+/ZXZUNHy4KnFDlPIECh+BFhU/vBSMIavicKqq:pPCS1lrqx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Profit.exe (PID: 4008)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • Profit.exe (PID: 4008)
    • The process checks if it is being run in the virtual environment

      • Profit.exe (PID: 4008)
    • Reads the Windows owner or organization settings

      • Profit.exe (PID: 4008)
    • Reads the Internet Settings

      • Profit.exe (PID: 4008)
  • INFO

    • Creates files or folders in the user directory

      • Profit.exe (PID: 4008)
    • Checks supported languages

      • Profit.exe (PID: 4008)
    • Reads the computer name

      • Profit.exe (PID: 4008)
    • Create files in a temporary directory

      • Profit.exe (PID: 4008)
    • Reads the machine GUID from the registry

      • Profit.exe (PID: 4008)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:25 21:23:08+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 5461504
InitializedDataSize: 4696576
UninitializedDataSize: -
EntryPoint: 0x5367e4
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.64.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Portuguese (Brazilian)
CharacterSet: Windows, Latin1
CompanyName: Nelogica
ProductVersion: 1.0.0.0
FileDescription: v1.64.0.0
FileVersion: 1.64.0.0
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start profit.exe

Process information

PID
CMD
Path
Indicators
Parent process
4008"C:\Users\admin\AppData\Local\Temp\Profit.exe" C:\Users\admin\AppData\Local\Temp\Profit.exe
explorer.exe
User:
admin
Company:
Nelogica
Integrity Level:
MEDIUM
Description:
v1.64.0.0
Version:
1.64.0.0
Modules
Images
c:\users\admin\appdata\local\temp\profit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\winspool.drv
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
618
Read events
618
Write events
0
Delete events
0

Modification events

No data
Executable files
25
Suspicious files
3
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
4008Profit.exeC:\Users\admin\AppData\Local\Temp\Nelogica_2024-03-26_18-41-06\libeay32.dllexecutable
MD5:
SHA256:
4008Profit.exeC:\Users\admin\AppData\Local\Temp\Nelogica_2024-03-26_18-41-06\ssleay32.dllexecutable
MD5:
SHA256:
4008Profit.exeC:\Users\admin\AppData\Roaming\Nelogica\temp_install_pro\ResourceDlls\x86\ImageResources.dllexecutable
MD5:
SHA256:
4008Profit.exeC:\Users\admin\AppData\Roaming\Nelogica\temp_install_pro\Edge114.0.1823.43\resources.pak
MD5:
SHA256:
4008Profit.exeC:\Users\admin\AppData\Roaming\Nelogica\temp_install_pro\LibAV\avcodec-58.dllexecutable
MD5:
SHA256:
4008Profit.exeC:\Users\admin\AppData\Roaming\Nelogica\temp_install_pro\ResourceDlls\x86\GifResources.dllexecutable
MD5:
SHA256:
4008Profit.exeC:\Users\admin\AppData\Roaming\Nelogica\temp_install_pro\Edge114.0.1823.43\WidevineCdm\_platform_specific\win_x86\widevinecdm.dllexecutable
MD5:
SHA256:
4008Profit.exeC:\Users\admin\AppData\Roaming\Nelogica\temp_install_pro\profitchart.exe
MD5:
SHA256:
4008Profit.exeC:\Users\admin\AppData\Roaming\Nelogica\temp_install_pro\Edge114.0.1823.43\icudtl.dat
MD5:
SHA256:
4008Profit.exeC:\Users\admin\AppData\Roaming\Nelogica\temp_install_pro\ProfitChart.chm
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
36
TCP/UDP connections
16
DNS requests
10
Threats
44

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4008
Profit.exe
GET
200
13.32.121.64:80
http://downloadserver-cdn.nelogica.com.br/produtos/bin/newprofit/version.txt
unknown
unknown
4008
Profit.exe
GET
200
3.161.82.68:80
http://versionsdownloadserver-cdn.nelogica.com.br/version/pro/alpha/to/stable/pt-br
unknown
unknown
4008
Profit.exe
GET
200
3.161.82.16:80
http://versionsdownloadserver-cdn.nelogica.com.br/files/8a34f42c23991a4a8739ccc49ce37ffb
unknown
unknown
4008
Profit.exe
GET
3.161.82.16:80
http://versionsdownloadserver-cdn.nelogica.com.br/files/4d55ca3435ac586a31885292fa3e5239
unknown
unknown
4008
Profit.exe
GET
200
3.161.82.113:80
http://versionsdownloadserver-cdn.nelogica.com.br/files/d2461fbb2ee54a1ac2e2c7c70034c588
unknown
unknown
4008
Profit.exe
GET
200
3.161.82.12:80
http://versionsdownloadserver-cdn.nelogica.com.br/files/6c63ad28ae18b52717acd4307a844331
unknown
unknown
4008
Profit.exe
GET
200
3.161.82.113:80
http://versionsdownloadserver-cdn.nelogica.com.br/files/6fb01ea7ad404b031c2187cfe9b1e177
unknown
unknown
4008
Profit.exe
GET
200
3.161.82.113:80
http://versionsdownloadserver-cdn.nelogica.com.br/files/538325692a6685e825116530955e2c47
unknown
unknown
4008
Profit.exe
GET
200
3.161.82.12:80
http://versionsdownloadserver-cdn.nelogica.com.br/files/3811b387102dc2051e640459be8cc03e
unknown
unknown
4008
Profit.exe
GET
200
3.161.82.12:80
http://versionsdownloadserver-cdn.nelogica.com.br/files/ed961e27567efe328d4d759c0c23872b
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown
4008
Profit.exe
13.32.121.64:80
downloadserver-cdn.nelogica.com.br
AMAZON-02
US
unknown
4008
Profit.exe
3.161.82.68:80
versionsdownloadserver-cdn.nelogica.com.br
US
unknown
4008
Profit.exe
3.161.82.16:80
versionsdownloadserver-cdn.nelogica.com.br
US
unknown
4008
Profit.exe
3.161.82.113:80
versionsdownloadserver-cdn.nelogica.com.br
US
unknown
4008
Profit.exe
3.161.82.12:80
versionsdownloadserver-cdn.nelogica.com.br
US
unknown

DNS requests

Domain
IP
Reputation
downloadserver-cdn.nelogica.com.br
  • 13.32.121.64
  • 13.32.121.127
  • 13.32.121.44
  • 13.32.121.106
unknown
versionsdownloadserver-cdn.nelogica.com.br
  • 3.161.82.68
  • 3.161.82.113
  • 3.161.82.12
  • 3.161.82.16
whitelisted

Threats

PID
Process
Class
Message
4008
Profit.exe
Potentially Bad Traffic
ET USER_AGENTS Suspicious User-Agent (Embarcadero URI Client/1.0)
Potentially Bad Traffic
ET HUNTING Suspicious Mozilla User-Agent - Likely Fake (Mozilla/4.0)
Potentially Bad Traffic
ET USER_AGENTS Suspicious User-Agent (Embarcadero URI Client/1.0)
Potentially Bad Traffic
ET USER_AGENTS Suspicious User-Agent (Embarcadero URI Client/1.0)
Potentially Bad Traffic
ET USER_AGENTS Suspicious User-Agent (Embarcadero URI Client/1.0)
Potentially Bad Traffic
ET USER_AGENTS Suspicious User-Agent (Embarcadero URI Client/1.0)
Potentially Bad Traffic
ET USER_AGENTS Suspicious User-Agent (Embarcadero URI Client/1.0)
Potentially Bad Traffic
ET USER_AGENTS Suspicious User-Agent (Embarcadero URI Client/1.0)
Potentially Bad Traffic
ET USER_AGENTS Suspicious User-Agent (Embarcadero URI Client/1.0)
Potentially Bad Traffic
ET USER_AGENTS Suspicious User-Agent (Embarcadero URI Client/1.0)
Process
Message
Profit.exe
CreateMachineID:midDrives C:\ \Device\HarddiskVolume2