File name:

Flying Globes.scr

Full analysis: https://app.any.run/tasks/823a1fb8-a159-4cba-a660-8f4c2fea7187
Verdict: Malicious activity
Analysis date: December 09, 2023, 21:48:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

EA7E7903C53EDB4A608E1DEA2CBCE8DF

SHA1:

FF3FD181D32F7A5C7C29F370C0168B775F177ACF

SHA256:

692A40DCAB019F0209DCEFBB11073D7192D9D960D93389087802E6EE232F69DB

SSDEEP:

192:+BmHxdVxEjMy5KDbF7vNVJUL4GdUYxXjjmjjGcipcJaYYYYYmvz:bTVyAeOF7visGdUYXjjmjjGQy

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • cmd.exe (PID: 3996)
  • SUSPICIOUS

    • Executing commands from ".cmd" file

      • cmd.exe (PID: 3996)
    • Application launched itself

      • cmd.exe (PID: 3996)
    • Starts CMD.EXE for commands execution

      • cmd.exe (PID: 3996)
    • Starts application with an unusual extension

      • cmd.exe (PID: 3996)
  • INFO

    • Manual execution by a user

      • Flying Globes.scr.exe (PID: 2084)
      • Flying Globes.scr (PID: 1988)
      • Flying Globes.scr (PID: 2332)
      • Flying Globes.scr (PID: 2108)
      • Flying Globes.scr (PID: 3216)
      • fg.cmd (PID: 1844)
      • cmd.exe (PID: 3996)
    • Checks supported languages

      • Flying Globes.scr.exe (PID: 280)
      • Flying Globes.scr.exe (PID: 2084)
      • Flying Globes.scr (PID: 2108)
      • Flying Globes.scr (PID: 1988)
      • Flying Globes.scr (PID: 2332)
      • Flying Globes.scr (PID: 3216)
      • fg.cmd (PID: 1844)
      • fg.pif (PID: 1004)
      • rrrrrrrrrrrrrrrrrrrrrrrrrrrrr.rr (PID: 3928)
      • fg.pif (PID: 900)
      • rrrrrrrrrrrrrrrrrrrrrrrrrrrrr.rr (PID: 3608)
      • rrrrrrrrrrrrrrrrrrrrrrrrrrrrr.rr (PID: 3604)
      • fg.pif (PID: 3632)
    • Creates files or folders in the user directory

      • rrrrrrrrrrrrrrrrrrrrrrrrrrrrr.rr (PID: 3608)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ 4.x (60.1)
.exe | Win32 Executable MS Visual C++ (generic) (13.9)
.exe | Win64 Executable (generic) (12.3)
.scr | Windows screen saver (5.8)
.dll | Win32 Dynamic Link Library (generic) (2.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1998:04:23 04:56:10+02:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 3.1
CodeSize: 6144
InitializedDataSize: 107520
UninitializedDataSize: -
EntryPoint: 0x23b9
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 4.10.0.1998
ProductVersionNumber: 4.10.0.1998
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: inefficiento
FileDescription: Flying Globes screen saver
FileVersion: 6.2.9200
InternalName: FLYGLO
LegalCopyright: Copyleft 2023 inefficiento
OriginalFileName: FLYGLO.SCR
ProductName: Screensaver
ProductVersion: 6.2.9200
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
58
Monitored processes
15
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start flying globes.scr.exe no specs flying globes.scr.exe no specs flying globes.scr no specs flying globes.scr no specs flying globes.scr no specs flying globes.scr no specs fg.cmd no specs cmd.exe no specs cmd.exe no specs fg.pif no specs fg.pif no specs fg.pif no specs rrrrrrrrrrrrrrrrrrrrrrrrrrrrr.rr no specs rrrrrrrrrrrrrrrrrrrrrrrrrrrrr.rr no specs rrrrrrrrrrrrrrrrrrrrrrrrrrrrr.rr no specs

Process information

PID
CMD
Path
Indicators
Parent process
280"C:\Users\admin\Desktop\Flying Globes.scr.exe" C:\Users\admin\Desktop\Flying Globes.scr.exeexplorer.exe
User:
admin
Company:
inefficiento
Integrity Level:
MEDIUM
Description:
Flying Globes screen saver
Exit code:
0
Version:
6.2.9200
Modules
Images
c:\users\admin\desktop\flying globes.scr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
900fg.pif /sC:\Users\admin\Desktop\fg.pifcmd.exe
User:
admin
Company:
inefficiento
Integrity Level:
MEDIUM
Description:
Flying Globes screen saver
Exit code:
0
Version:
6.2.9200
Modules
Images
c:\users\admin\desktop\fg.pif
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
1004fg.pif /sC:\Users\admin\Desktop\fg.pifcmd.exe
User:
admin
Company:
inefficiento
Integrity Level:
MEDIUM
Description:
Flying Globes screen saver
Exit code:
0
Version:
6.2.9200
Modules
Images
c:\users\admin\desktop\fg.pif
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
1844"C:\Users\admin\Desktop\fg.cmd" C:\Users\admin\Desktop\fg.cmdexplorer.exe
User:
admin
Company:
inefficiento
Integrity Level:
MEDIUM
Description:
Flying Globes screen saver
Exit code:
0
Version:
6.2.9200
Modules
Images
c:\users\admin\desktop\fg.cmd
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
1988"C:\Users\admin\Desktop\Flying Globes.scr" /SC:\Users\admin\Desktop\Flying Globes.screxplorer.exe
User:
admin
Company:
inefficiento
Integrity Level:
MEDIUM
Description:
Flying Globes screen saver
Exit code:
0
Version:
6.2.9200
Modules
Images
c:\users\admin\desktop\flying globes.scr
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
2084"C:\Users\admin\Desktop\Flying Globes.scr.exe" C:\Users\admin\Desktop\Flying Globes.scr.exeexplorer.exe
User:
admin
Company:
inefficiento
Integrity Level:
MEDIUM
Description:
Flying Globes screen saver
Exit code:
0
Version:
6.2.9200
Modules
Images
c:\users\admin\desktop\flying globes.scr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
2108"C:\Users\admin\Desktop\Flying Globes.scr" /SC:\Users\admin\Desktop\Flying Globes.screxplorer.exe
User:
admin
Company:
inefficiento
Integrity Level:
MEDIUM
Description:
Flying Globes screen saver
Exit code:
0
Version:
6.2.9200
Modules
Images
c:\users\admin\desktop\flying globes.scr
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
2332"C:\Users\admin\Desktop\Flying Globes.scr" /SC:\Users\admin\Desktop\Flying Globes.screxplorer.exe
User:
admin
Company:
inefficiento
Integrity Level:
MEDIUM
Description:
Flying Globes screen saver
Exit code:
0
Version:
6.2.9200
Modules
Images
c:\users\admin\desktop\flying globes.scr
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
2984C:\Windows\system32\cmd.exe /K fg.cmd /sC:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
9009
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3216"C:\Users\admin\Desktop\Flying Globes.scr" /SC:\Users\admin\Desktop\Flying Globes.screxplorer.exe
User:
admin
Company:
inefficiento
Integrity Level:
MEDIUM
Description:
Flying Globes screen saver
Exit code:
0
Version:
6.2.9200
Modules
Images
c:\users\admin\desktop\flying globes.scr
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_5.82.7601.18837_none_ec86b8d6858ec0bc\comctl32.dll
Total events
206
Read events
206
Write events
0
Delete events
0

Modification events

No data
Executable files
2
Suspicious files
0
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3996cmd.exeC:\Users\admin\Desktop\rrrrrrrrrrrrrrrrrrrrrrrrrrrrr.rrexecutable
MD5:EA7E7903C53EDB4A608E1DEA2CBCE8DF
SHA256:692A40DCAB019F0209DCEFBB11073D7192D9D960D93389087802E6EE232F69DB
3608rrrrrrrrrrrrrrrrrrrrrrrrrrrrr.rrC:\Users\admin\AppData\Local\VirtualStore\Windows\control.initext
MD5:07BF9741AFE26C4B7012455B9D4C50E9
SHA256:33C99399313C1B807D63F79D644C45D36611F8980B45ECB7CEDACD7249CCED12
3996cmd.exeC:\Users\admin\Desktop\fg.pifexecutable
MD5:EA7E7903C53EDB4A608E1DEA2CBCE8DF
SHA256:692A40DCAB019F0209DCEFBB11073D7192D9D960D93389087802E6EE232F69DB
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info