| File name: | a551897ab412f068fb7f78168d68d4ae.exe |
| Full analysis: | https://app.any.run/tasks/c1330ad5-0067-4ad2-be4c-c52948ae986d |
| Verdict: | Malicious activity |
| Threats: | DCrat, also known as Dark Crystal RAT, is a remote access trojan (RAT), which was first introduced in 2018. It is a modular malware that can be customized to perform different tasks. For instance, it can steal passwords, crypto wallet information, hijack Telegram and Steam accounts, and more. Attackers may use a variety of methods to distribute DCrat, but phishing email campaigns are the most common. |
| Analysis date: | January 26, 2025, 12:05:11 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows, 4 sections |
| MD5: | A551897AB412F068FB7F78168D68D4AE |
| SHA1: | 6809074746C56F07925481C3F3C7B8450F4AC511 |
| SHA256: | 638993233AC930A66DD7B5CB27CE295330BD4B3442DB9A4F0141E98865006E0F |
| SSDEEP: | 49152:pOs6PFwZXcfr3SorLDK0Mt8tpckbwqGIJYfBELbaKjd5Gq:1MBtMervb1O5ELf5X |
| .exe | | | Generic CIL Executable (.NET, Mono, etc.) (45.1) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (19.2) |
| .exe | | | Win64 Executable (generic) (17) |
| .scr | | | Windows screen saver (8) |
| .dll | | | Win32 Dynamic Link Library (generic) (4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2022:05:04 16:03:35+00:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 1328640 |
| InitializedDataSize: | 13824 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x14646e |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 5.15.2.0 |
| ProductVersionNumber: | 5.15.2.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| FileVersion: | 5.15.2.0 |
| OriginalFileName: | libGLESv2.dll |
| ProductName: | libGLESv2 |
| ProductVersion: | 5.15.2.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 440 | schtasks.exe /create /tn "OfficeClickToRunO" /sc MINUTE /mo 8 /tr "'C:\Users\Public\OfficeClickToRun.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 536 | schtasks.exe /create /tn "sihosts" /sc MINUTE /mo 5 /tr "'C:\Users\Default\Links\sihost.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 644 | schtasks.exe /create /tn "Memory CompressionM" /sc MINUTE /mo 9 /tr "'C:\Users\Public\Libraries\Memory Compression.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 736 | schtasks.exe /create /tn "lsassl" /sc MINUTE /mo 10 /tr "'C:\Users\admin\lsass.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 880 | schtasks.exe /create /tn "explorere" /sc MINUTE /mo 7 /tr "'C:\Users\Public\Downloads\explorer.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1140 | schtasks.exe /create /tn "dllhost" /sc ONLOGON /tr "'C:\Users\All Users\dllhost.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1344 | schtasks.exe /create /tn "dllhostd" /sc MINUTE /mo 7 /tr "'C:\Users\All Users\dllhost.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1684 | schtasks.exe /create /tn "OfficeClickToRun" /sc ONLOGON /tr "'C:\Users\Public\OfficeClickToRun.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1876 | schtasks.exe /create /tn "OfficeClickToRunO" /sc MINUTE /mo 13 /tr "'C:\Users\Public\OfficeClickToRun.exe'" /rl HIGHEST /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1876 | schtasks.exe /create /tn "SystemSettingsS" /sc MINUTE /mo 13 /tr "'C:\Users\Default\Documents\My Videos\SystemSettings.exe'" /f | C:\Windows\System32\schtasks.exe | — | WmiPrvSE.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Task Scheduler Configuration Tool Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (4684) a551897ab412f068fb7f78168d68d4ae.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\b955694851e981b849669a1883e2200f609e0de0 |
| Operation: | write | Name: | 035678c295b1a68678e30b07c9b1058a73f27034 |
Value: WyJDOlxcVXNlcnNcXGFkbWluXFxEZXNrdG9wXFxhNTUxODk3YWI0MTJmMDY4ZmI3Zjc4MTY4ZDY4ZDRhZS5leGUiLCJDOlxcVXNlcnNcXGFkbWluXFxsc2Fzcy5leGUiLCJDOlxcVXNlcnNcXFB1YmxpY1xcT2ZmaWNlQ2xpY2tUb1J1bi5leGUiLCJDOlxcVXNlcnNcXERlZmF1bHRcXExpbmtzXFxzaWhvc3QuZXhlIiwiQzpcXFVzZXJzXFxBbGwgVXNlcnNcXENvbW1zXFxkbGxob3N0LmV4ZSIsIkM6XFxVc2Vyc1xcYWRtaW5cXFByaW50SG9vZFxcTW9Vc29Db3JlV29ya2VyLmV4ZSIsIkM6XFxVc2Vyc1xcYWRtaW5cXERvd25sb2Fkc1xcc3Bwc3ZjLmV4ZSIsIkM6XFxVc2Vyc1xcYWRtaW5cXFRlbXBsYXRlc1xcUnVudGltZUJyb2tlci5leGUiLCJDOlxcVXNlcnNcXGFkbWluXFwubXMtYWRcXGNzcnNzLmV4ZSIsIkM6XFxVc2Vyc1xcQWxsIFVzZXJzXFxkbGxob3N0LmV4ZSIsIkM6XFxVc2Vyc1xcYWRtaW5cXFRlbXBsYXRlc1xcY3Nyc3MuZXhlIiwiQzpcXFVzZXJzXFxBbGwgVXNlcnNcXE9mZmljZUNsaWNrVG9SdW4uZXhlIiwiQzpcXFdpbmRvd3NcXFRlbXBcXFNlYXJjaEFwcC5leGUiLCJDOlxcVXNlcnNcXGFkbWluXFxjc3Jzcy5leGUiLCJDOlxcVXNlcnNcXGFkbWluXFxTYXZlZCBHYW1lc1xcUnVudGltZUJyb2tlci5leGUiLCJDOlxcVXNlcnNcXFB1YmxpY1xcRG93bmxvYWRzXFxleHBsb3Jlci5leGUiLCJDOlxcVXNlcnNcXERlZmF1bHRcXERvY3VtZW50c1xcTXkgVmlkZW9zXFxTeXN0ZW1TZXR0aW5ncy5leGUiLCJDOlxcVXNlcnNcXEFsbCBVc2Vyc1xcUnVudGltZUJyb2tlci5leGUiLCJDOlxcVXNlcnNcXFB1YmxpY1xcRG9jdW1lbnRzXFxNeSBNdXNpY1xcZm9udGRydmhvc3QuZXhlIiwiQzpcXFVzZXJzXFxQdWJsaWNcXExpYnJhcmllc1xcTWVtb3J5IENvbXByZXNzaW9uLmV4ZSJd | |||
| (PID) Process: | (3172) OfficeClickToRun.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfficeClickToRun_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (3172) OfficeClickToRun.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfficeClickToRun_RASAPI32 |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
| (PID) Process: | (3172) OfficeClickToRun.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfficeClickToRun_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (3172) OfficeClickToRun.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfficeClickToRun_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (3172) OfficeClickToRun.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfficeClickToRun_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
| (PID) Process: | (3172) OfficeClickToRun.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfficeClickToRun_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (3172) OfficeClickToRun.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfficeClickToRun_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
| (PID) Process: | (3172) OfficeClickToRun.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfficeClickToRun_RASMANCS |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (3172) OfficeClickToRun.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\OfficeClickToRun_RASMANCS |
| Operation: | write | Name: | EnableAutoFileTracing |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4684 | a551897ab412f068fb7f78168d68d4ae.exe | C:\Users\Public\e6c9b481da804f | text | |
MD5:984ED6EC084BFCE3C57969CA1E2CEF0F | SHA256:443D5B3F2100B408911C0318B16D516C74E888F924D57A5961DD17A97FB2A833 | |||
| 4684 | a551897ab412f068fb7f78168d68d4ae.exe | C:\Users\admin\lsass.exe | executable | |
MD5:A551897AB412F068FB7F78168D68D4AE | SHA256:638993233AC930A66DD7B5CB27CE295330BD4B3442DB9A4F0141E98865006E0F | |||
| 4684 | a551897ab412f068fb7f78168d68d4ae.exe | C:\Users\admin\6203df4a6bafc7 | text | |
MD5:6B32C0494163DBB8F535B4CA1374AF1F | SHA256:3178671B25A3BE55D3259A403A7AB5DDDFE86A45F5652F2A21259E213883A152 | |||
| 4684 | a551897ab412f068fb7f78168d68d4ae.exe | C:\Users\Public\OfficeClickToRun.exe | executable | |
MD5:A551897AB412F068FB7F78168D68D4AE | SHA256:638993233AC930A66DD7B5CB27CE295330BD4B3442DB9A4F0141E98865006E0F | |||
| 4684 | a551897ab412f068fb7f78168d68d4ae.exe | C:\ProgramData\Comms\5940a34987c991 | text | |
MD5:676C01A62849B8F897D2B0C896DFF2D9 | SHA256:B426F6EEB7B76DC9BC3D4F3FFF9E94D85810BCA13025C6350542C5EECB905C69 | |||
| 4684 | a551897ab412f068fb7f78168d68d4ae.exe | C:\Users\Default\Links\66fc9ff0ee96c2 | text | |
MD5:B92D1CE52E608F12F23A938EDB50CC51 | SHA256:0F525B9FE614E55C3DA8A62C6C3501AE878D504C7E0FD7F91DD8F653E8D9B173 | |||
| 4684 | a551897ab412f068fb7f78168d68d4ae.exe | C:\ProgramData\Comms\dllhost.exe | executable | |
MD5:A551897AB412F068FB7F78168D68D4AE | SHA256:638993233AC930A66DD7B5CB27CE295330BD4B3442DB9A4F0141E98865006E0F | |||
| 4684 | a551897ab412f068fb7f78168d68d4ae.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\MoUsoCoreWorker.exe | executable | |
MD5:A551897AB412F068FB7F78168D68D4AE | SHA256:638993233AC930A66DD7B5CB27CE295330BD4B3442DB9A4F0141E98865006E0F | |||
| 4684 | a551897ab412f068fb7f78168d68d4ae.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Templates\RuntimeBroker.exe | executable | |
MD5:A551897AB412F068FB7F78168D68D4AE | SHA256:638993233AC930A66DD7B5CB27CE295330BD4B3442DB9A4F0141E98865006E0F | |||
| 4684 | a551897ab412f068fb7f78168d68d4ae.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Printer Shortcuts\1f93f77a7f4778 | text | |
MD5:B291C6E4B757E0B1EBEC77D36A7661A0 | SHA256:F941F2436BA6FA279063012FEF6A6CFFB349A73E91BDF9C3786C78F2CEA5D268 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4140 | svchost.exe | GET | 200 | 2.16.241.19:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 2.16.241.19:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | GET | 200 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4140 | svchost.exe | GET | 304 | 2.23.246.101:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
3172 | OfficeClickToRun.exe | GET | 403 | 141.8.192.164:80 | http://a1067734.xsph.ru/L1nc0In.php?AODihBRNV9seTYzcMdeBf80=wG&kfW=8aNUOxqQGNdtMMy&7ecdd0e4d5a7ad89fd48b49cbfb46a5b=ff931770d8eebbc4f9df4455d276a0c8&9951c2a37140171ff58f27833f942e04=AMjJzM3ATZ0gzNiRTOzYmY3Y2YjZWYhRzMmNjZ1kDM5ETYiV2M3kzY&AODihBRNV9seTYzcMdeBf80=wG&kfW=8aNUOxqQGNdtMMy | unknown | — | — | whitelisted |
3172 | OfficeClickToRun.exe | GET | 403 | 141.8.192.164:80 | http://a1067734.xsph.ru/L1nc0In.php?AODihBRNV9seTYzcMdeBf80=wG&kfW=8aNUOxqQGNdtMMy&7ecdd0e4d5a7ad89fd48b49cbfb46a5b=ff931770d8eebbc4f9df4455d276a0c8&9951c2a37140171ff58f27833f942e04=AMjJzM3ATZ0gzNiRTOzYmY3Y2YjZWYhRzMmNjZ1kDM5ETYiV2M3kzY&AODihBRNV9seTYzcMdeBf80=wG&kfW=8aNUOxqQGNdtMMy | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4140 | svchost.exe | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4140 | svchost.exe | 2.16.241.19:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 2.16.241.19:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4712 | MoUsoCoreWorker.exe | 2.23.246.101:80 | www.microsoft.com | Ooredoo Q.S.C. | QA | whitelisted |
4140 | svchost.exe | 2.23.246.101:80 | www.microsoft.com | Ooredoo Q.S.C. | QA | whitelisted |
4712 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4140 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
a1067734.xsph.ru |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2192 | svchost.exe | Misc activity | ET INFO Observed DNS Query to xsph .ru Domain |
3172 | OfficeClickToRun.exe | A Network Trojan was detected | ET MALWARE DCRAT Activity (GET) |