| File name: | P.exe |
| Full analysis: | https://app.any.run/tasks/d36e9697-60dc-480a-9ba4-c030b56c2c9b |
| Verdict: | Malicious activity |
| Analysis date: | November 09, 2023, 12:08:24 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (console) Intel 80386, for MS Windows |
| MD5: | 08C87F0CFC72026FF8D62C6DD617C49A |
| SHA1: | 5115074AB8231015519233AE081675CD9B7C8571 |
| SHA256: | 6597C7C5C4F70F7F92163232BCD06894DC6825B3D92172AF02A0353F98486EEC |
| SSDEEP: | 3072:zcYQcwGuA5RmZeDUZe2BWM5MnCO90dRcKKi1wzVPx+WTyZP:jAGUnBdO9ERcTiuDyZP |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:11:09 13:08:08+01:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 11 |
| CodeSize: | 48640 |
| InitializedDataSize: | 13086208 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x494d |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows command line |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3404 | "C:\Users\admin\Desktop\P.exe" | C:\Users\admin\Desktop\P.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3460 | "C:\Windows\System32\runas.exe" /user:administrator C:\Users\admin\Desktop\P.exe | C:\Windows\System32\runas.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Run As Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3504 | C:\Users\admin\Desktop\P.exe | C:\Users\admin\Desktop\P.exe | runas.exe | ||||||||||||
User: Administrator Integrity Level: HIGH Exit code: 3221225786 Modules
| |||||||||||||||
| 3876 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3876) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{F8413BEE-5986-4D02-8464-3F165808C92E}\{45BFB7A9-7D09-4EF4-BF26-4408977D921B} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3876) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{F8413BEE-5986-4D02-8464-3F165808C92E} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3876) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{F41DF772-75C5-4392-AB61-9667513AB578} |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3404 | P.exe | C:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\AccLR.cab | — | |
MD5:— | SHA256:— | |||
| 3404 | P.exe | C:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\AccLR.cab | — | |
MD5:— | SHA256:— | |||
| 3404 | P.exe | C:\MSOCache\All Users\{90140000-0015-0410-0000-0000000FF1CE}-C\AccLR.cab | — | |
MD5:— | SHA256:— | |||
| 3404 | P.exe | C:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\AccessMUI.msi | binary | |
MD5:669E869F1B41A738757DDB43C577A1A6 | SHA256:0D3CD083A6588F9694BA6FCFB6E67E7CAE89BB6E818846F2E2AACE38B100340B | |||
| 3404 | P.exe | C:\MSOCache\All Users\{90140000-0015-0410-0000-0000000FF1CE}-C\AccessMUI.msi | binary | |
MD5:3FFB094A9FDE6F2DEE37FA04F2ACBFFA | SHA256:A2475E3EE5CD68FEBEE61A955303E3585E7D4D1564887EACAE3763C00A0593F7 | |||
| 3404 | P.exe | C:\MSOCache\All Users\{90140000-0015-0411-0000-0000000FF1CE}-C\AccLR.cab | — | |
MD5:— | SHA256:— | |||
| 3404 | P.exe | C:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\AccessMUI.xml | binary | |
MD5:2911CC48E9855D72DA7461F309A5706B | SHA256:5FDE20A9ED99A1A52036F270FA98887A40A75B784B66351EE51D5623350F4AA9 | |||
| 3404 | P.exe | C:\MSOCache\All Users\{90140000-0015-0410-0000-0000000FF1CE}-C\AccessMUI.xml | binary | |
MD5:833061B1CE092555B0C55386C7393311 | SHA256:16F1C4C927D24DE5BC4EF722378F8A41BEB2B72FAB4FE0306E2101F4411ACE71 | |||
| 3404 | P.exe | C:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\Setup.xml | binary | |
MD5:86E3F6E08874E420E99A80D45CDE4DEE | SHA256:076966860A886AC02C0DE8E2961B453B7E33C7FBCCC8ADC85E4EBF21013512C9 | |||
| 3404 | P.exe | C:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\branding.xml | binary | |
MD5:73FC78748FD4FEF030FD2FC90AD2B107 | SHA256:0E6744DCAE95AAAF9EBF00DCA2A4F200B1468C22BD475A59D3C72A4865654B97 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |