File name:

Macromedia Flash Player 6 for Pocket PC 2003.exe

Full analysis: https://app.any.run/tasks/c0fdd330-b2b5-471a-98e6-7ed6bf0e82c4
Verdict: Malicious activity
Analysis date: May 14, 2024, 17:49:59
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

514CB4BC0DD4D2D3B93FE015079B36CD

SHA1:

1AA710A784BECCBF028E31EC2F4DBEF4C0493AE1

SHA256:

6ADE75057911F79CC45610A7AF85015FB07747BDD0CC750FA0F67007955B3790

SSDEEP:

24576:tzBQ2SuQULD5GnEQnPunifgaBa7K2EvCp6Z:pBQ2SuQULMn1PuifzBa7K2EvCpG

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Macromedia Flash Player 6 for Pocket PC 2003.exe (PID: 4072)
      • Macromedia Flash Player 6 for Pocket PC 2003.exe (PID: 2340)
      • Macromedia Flash Player 6 for Pocket PC 2003.exe (PID: 1996)
  • SUSPICIOUS

    • Starts application with an unusual extension

      • Macromedia Flash Player 6 for Pocket PC 2003.exe (PID: 4072)
      • Macromedia Flash Player 6 for Pocket PC 2003.exe (PID: 2340)
      • Macromedia Flash Player 6 for Pocket PC 2003.exe (PID: 1996)
    • Executable content was dropped or overwritten

      • Macromedia Flash Player 6 for Pocket PC 2003.exe (PID: 4072)
      • Macromedia Flash Player 6 for Pocket PC 2003.exe (PID: 2340)
      • Macromedia Flash Player 6 for Pocket PC 2003.exe (PID: 1996)
  • INFO

    • Checks supported languages

      • Macromedia Flash Player 6 for Pocket PC 2003.exe (PID: 4072)
      • sxe3E07.tmp (PID: 4088)
      • sxeA811.tmp (PID: 1880)
      • Macromedia Flash Player 6 for Pocket PC 2003.exe (PID: 2340)
      • sxe54B2.tmp (PID: 664)
      • Macromedia Flash Player 6 for Pocket PC 2003.exe (PID: 1996)
    • Create files in a temporary directory

      • Macromedia Flash Player 6 for Pocket PC 2003.exe (PID: 4072)
    • Manual execution by a user

      • explorer.exe (PID: 1116)
      • explorer.exe (PID: 1080)
      • Macromedia Flash Player 6 for Pocket PC 2003.exe (PID: 2332)
      • Macromedia Flash Player 6 for Pocket PC 2003.exe (PID: 2340)
      • Macromedia Flash Player 6 for Pocket PC 2003.exe (PID: 2548)
      • Macromedia Flash Player 6 for Pocket PC 2003.exe (PID: 1996)
      • taskmgr.exe (PID: 2384)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | CExe compressed Win32 executable (91.9)
.exe | Win32 Executable MS Visual C++ (generic) (5.4)
.dll | Win32 Dynamic Link Library (generic) (1.1)
.exe | Win32 Executable (generic) (0.7)
.exe | Generic Win/DOS Executable (0.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1999:06:11 22:05:21+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 2048
InitializedDataSize: 479232
UninitializedDataSize: -
EntryPoint: 0x1404
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
60
Monitored processes
12
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start macromedia flash player 6 for pocket pc 2003.exe sxe3e07.tmp no specs explorer.exe no specs explorer.exe no specs macromedia flash player 6 for pocket pc 2003.exe no specs macromedia flash player 6 for pocket pc 2003.exe sxe54b2.tmp no specs macromedia flash player 6 for pocket pc 2003.exe no specs macromedia flash player 6 for pocket pc 2003.exe sxea811.tmp no specs taskmgr.exe no specs macromedia flash player 6 for pocket pc 2003.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
664"C:\Users\admin\Desktop\sxe54B2.tmp" C:\Users\admin\Desktop\sxe54B2.tmpMacromedia Flash Player 6 for Pocket PC 2003.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\sxe54b2.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1080"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1116"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1880"C:\Users\admin\Desktop\sxeA811.tmp" C:\Users\admin\Desktop\sxeA811.tmpMacromedia Flash Player 6 for Pocket PC 2003.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\sxea811.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1996"C:\Users\admin\Desktop\Macromedia Flash Player 6 for Pocket PC 2003.exe" C:\Users\admin\Desktop\Macromedia Flash Player 6 for Pocket PC 2003.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\macromedia flash player 6 for pocket pc 2003.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lz32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2332"C:\Users\admin\Desktop\Macromedia Flash Player 6 for Pocket PC 2003.exe" C:\Users\admin\Desktop\Macromedia Flash Player 6 for Pocket PC 2003.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\macromedia flash player 6 for pocket pc 2003.exe
c:\windows\system32\ntdll.dll
2340"C:\Users\admin\Desktop\Macromedia Flash Player 6 for Pocket PC 2003.exe" C:\Users\admin\Desktop\Macromedia Flash Player 6 for Pocket PC 2003.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\macromedia flash player 6 for pocket pc 2003.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\lz32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2384"C:\Windows\system32\taskmgr.exe" /4C:\Windows\System32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2548"C:\Users\admin\Desktop\Macromedia Flash Player 6 for Pocket PC 2003.exe" C:\Users\admin\Desktop\Macromedia Flash Player 6 for Pocket PC 2003.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\macromedia flash player 6 for pocket pc 2003.exe
c:\windows\system32\ntdll.dll
3968"C:\Users\admin\AppData\Local\Temp\Macromedia Flash Player 6 for Pocket PC 2003.exe" C:\Users\admin\AppData\Local\Temp\Macromedia Flash Player 6 for Pocket PC 2003.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\macromedia flash player 6 for pocket pc 2003.exe
c:\windows\system32\ntdll.dll
Total events
756
Read events
754
Write events
2
Delete events
0

Modification events

(PID) Process:(2384) taskmgr.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\TaskManager
Operation:writeName:UsrColumnSettings
Value:
1C0C0000340400000000000050000000010000001D0C0000350400000000000023000000010000001E0C000036040000000000003C000000010000001F0C000039040000000000004E00000001000000200C000037040000000000004E00000001000000
(PID) Process:(2384) taskmgr.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\TaskManager
Operation:writeName:Preferences
Value:
30030000E803000001000000010000007E01000077000000160300005C0200000100000001000000000000000000000001000000000000000100000000000000000000000200000004000000090000001D000000FFFFFFFF00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000009C00000040000000210000004600000052000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0000000002000000010000000300000004000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0500000000000000FFFFFFFF00000000020000000300000004000000FFFFFFFF00000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000630060003C005A00FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF000000000000010000000200000003000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF0400000000000000FFFFFFFF02000000FFFFFFFF4F00000028000000970000003400000050000000000000000100000002000000030000000400000000000000FFFFFFFF43000000000000000000000001000000
Executable files
6
Suspicious files
3
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2340Macromedia Flash Player 6 for Pocket PC 2003.exeC:\Users\admin\Desktop\sxe5424.tmpbinary
MD5:782AB495C935AE51084BC51E464E1993
SHA256:3E2E95F164BF17C8C966412A1604367A36710D75C2A5686555936BF6FDBA5373
4072Macromedia Flash Player 6 for Pocket PC 2003.exeC:\Users\admin\AppData\Local\Temp\sxe3DF5.tmpexecutable
MD5:BD815B61F9948F93AFACE4033FBB4423
SHA256:B018BF9E9F8B6D945E6A2A25984970634884AFABC580AF2B4E855730520D5D76
1996Macromedia Flash Player 6 for Pocket PC 2003.exeC:\Users\admin\Desktop\sxeA800.tmpexecutable
MD5:BD815B61F9948F93AFACE4033FBB4423
SHA256:B018BF9E9F8B6D945E6A2A25984970634884AFABC580AF2B4E855730520D5D76
4072Macromedia Flash Player 6 for Pocket PC 2003.exeC:\Users\admin\AppData\Local\Temp\sxe3E07.tmpexecutable
MD5:577F40784E3ED0D40C092C7D7C886861
SHA256:A1029BA6999E4CD957154B5889645D570FF4BBB69EE509356B7A5F9CAC15F104
2340Macromedia Flash Player 6 for Pocket PC 2003.exeC:\Users\admin\Desktop\sxe54B2.tmpexecutable
MD5:577F40784E3ED0D40C092C7D7C886861
SHA256:A1029BA6999E4CD957154B5889645D570FF4BBB69EE509356B7A5F9CAC15F104
1996Macromedia Flash Player 6 for Pocket PC 2003.exeC:\Users\admin\Desktop\sxeA810.tmpex_
MD5:782AB495C935AE51084BC51E464E1993
SHA256:3E2E95F164BF17C8C966412A1604367A36710D75C2A5686555936BF6FDBA5373
4072Macromedia Flash Player 6 for Pocket PC 2003.exeC:\Users\admin\AppData\Local\Temp\sxe3DF6.tmpex_
MD5:782AB495C935AE51084BC51E464E1993
SHA256:3E2E95F164BF17C8C966412A1604367A36710D75C2A5686555936BF6FDBA5373
2340Macromedia Flash Player 6 for Pocket PC 2003.exeC:\Users\admin\Desktop\sxe5423.tmpexecutable
MD5:BD815B61F9948F93AFACE4033FBB4423
SHA256:B018BF9E9F8B6D945E6A2A25984970634884AFABC580AF2B4E855730520D5D76
1996Macromedia Flash Player 6 for Pocket PC 2003.exeC:\Users\admin\Desktop\sxeA811.tmpexecutable
MD5:577F40784E3ED0D40C092C7D7C886861
SHA256:A1029BA6999E4CD957154B5889645D570FF4BBB69EE509356B7A5F9CAC15F104
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info