| File name: | 554a804cd725c2094b2738f991faec6d |
| Full analysis: | https://app.any.run/tasks/3d28bac7-0673-4ffb-8d05-8e33c84479e5 |
| Verdict: | Malicious activity |
| Analysis date: | May 07, 2024, 12:26:16 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 554A804CD725C2094B2738F991FAEC6D |
| SHA1: | DC1F4B825B788DE547BF31304AEC3A148BBB6342 |
| SHA256: | 6500290EA5831EAB67B7F90F6564BFB3B6364BB2295863F9D8425BB2F33CEAA7 |
| SSDEEP: | 768:98UYSo4xeXqBNjsWfQVtaBIvlfH/Vg1DFWwMv+tiVbnlRg+w:64rRsWz2/2/WwMv+titnlRgj |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2011:11:26 17:53:47+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 20480 |
| InitializedDataSize: | 24576 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x291b |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1180 | C:\Windows\Explorer.EXE | C:\Windows\explorer.exe | — | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3980 | "C:\Users\admin\AppData\Local\Temp\554a804cd725c2094b2738f991faec6d.exe" | C:\Users\admin\AppData\Local\Temp\554a804cd725c2094b2738f991faec6d.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3996 | C:\Users\admin\AppData\Local\Temp\554a804cd725c2094b2738f991faec6d.exe | C:\Users\admin\AppData\Local\Temp\554a804cd725c2094b2738f991faec6d.exe | — | 554a804cd725c2094b2738f991faec6d.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (1180) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0 |
| Operation: | write | Name: | CheckSetting |
Value: 01000000D08C9DDF0115D1118C7A00C04FC297EB01000000F4B94FCAEEC58D4CA28961DDC8B6534C0000000002000000000010660000000100002000000047F62728A2E8728A7736614CB1A109E76DA0AD685247B109CB3AFA9880BA3608000000000E80000000020000200000003651FBD6740C58E510ABE3B51C416D59D284EB02CDCD60E92E9494CA78EA8B133000000041D3EA9270EBEBE0FA7FB530EE4C8BD7277C78B8D926D58029556F02493742EE1E1870F3CBD995BB70908C143C738F2B40000000C11D80EC27D769FAC4C2A3BEEE248753A44EC3EBDF76687F316A37493367FCF23C622CBD9A3996138560FAE24CBDDEC81091A4BB4D6CC8E1973887B6096837AC | |||
| (PID) Process: | (1180) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | Firewall Security Service |
Value: c:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\ecleaner.exe | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1180 | explorer.exe | C:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\ecleaner.exe | executable | |
MD5:554A804CD725C2094B2738F991FAEC6D | SHA256:6500290EA5831EAB67B7F90F6564BFB3B6364BB2295863F9D8425BB2F33CEAA7 | |||
| 1180 | explorer.exe | C:\RECYCLER\R-1-5-21-1482476501-1644491937-682003330-1013\Desktop.ini | text | |
MD5:7457A5DF1FF47C957ACF1FA000D7D9AD | SHA256:6F40B80A787EAE165D17211DC4A12F9697BEEFEEBD662322D852FDC5F2B07FB3 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1180 | explorer.exe | 76.223.54.146:3321 | dl.ka3ek.com | AMAZON-02 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
dl.ka3ek.com |
| whitelisted |