File name:

Ogulniega Minecraft.exe

Full analysis: https://app.any.run/tasks/78a27074-bf04-4eea-87d2-f056bb15801d
Verdict: Malicious activity
Analysis date: November 21, 2023, 14:46:02
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
opendir
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

66AF661080535A8BD4B193C37B1A4C24

SHA1:

ACEA6875C1049907B533AE91C501D13239BFD2DB

SHA256:

6D7331336BD37B0F54BBC01EEB2A2896003E0F34A445E82F00A6214B0BEE2F22

SSDEEP:

6144:2IalilHjcJeMDK1srg/trwvMYfETz/z20GW1nHB1npo6hC:QliheeMB8BwvhETz/q0Xnh1np3hC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Internet Settings

      • Ogulniega Minecraft.exe (PID: 3440)
    • Reads settings of System Certificates

      • Ogulniega Minecraft.exe (PID: 3440)
    • Reads security settings of Internet Explorer

      • Ogulniega Minecraft.exe (PID: 3440)
    • Checks Windows Trust Settings

      • Ogulniega Minecraft.exe (PID: 3440)
    • Starts CMD.EXE for commands execution

      • Ogulniega Minecraft.exe (PID: 3440)
  • INFO

    • Checks supported languages

      • Ogulniega Minecraft.exe (PID: 3440)
      • wmpnscfg.exe (PID: 3464)
    • Checks proxy server information

      • Ogulniega Minecraft.exe (PID: 3440)
    • Reads the computer name

      • Ogulniega Minecraft.exe (PID: 3440)
      • wmpnscfg.exe (PID: 3464)
    • Reads the machine GUID from the registry

      • Ogulniega Minecraft.exe (PID: 3440)
      • wmpnscfg.exe (PID: 3464)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3464)
    • Creates files or folders in the user directory

      • Ogulniega Minecraft.exe (PID: 3440)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:11:09 00:48:14+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.37
CodeSize: 292352
InitializedDataSize: 119296
UninitializedDataSize: -
EntryPoint: 0x26b69
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.2
ProductVersionNumber: 0.0.0.2
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Unknown (0)
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: Ogulniega
FileVersion: 2
InternalName: Ogulniega Minecraft
OriginalFileName: Ogulniega Minecraft
ProductName: Ogulniega Minecraft
ProductVersion: 2
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
5
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start ogulniega minecraft.exe wmpnscfg.exe no specs where.exe no specs where.exe no specs cmd.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3440"C:\Users\admin\AppData\Local\Temp\Ogulniega Minecraft.exe" C:\Users\admin\AppData\Local\Temp\Ogulniega Minecraft.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\ogulniega minecraft.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3464"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3488where cmd.exeC:\Windows\System32\where.exeOgulniega Minecraft.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Where - Lists location of files
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\where.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ws2_32.dll
3604where tar.exeC:\Windows\System32\where.exeOgulniega Minecraft.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Where - Lists location of files
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\where.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ws2_32.dll
3680/C INFO: Could not find files for the given pattern(s). -xf "C:\Users\admin\AppData\Roaming\.ogulniega\java\java_temp" -C "C:\Users\admin\AppData\Roaming\.ogulniega\java"C:\Windows\System32\cmd.exeOgulniega Minecraft.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
4 865
Read events
4 838
Write events
24
Delete events
3

Modification events

(PID) Process:(3440) Ogulniega Minecraft.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3440) Ogulniega Minecraft.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000059010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3440) Ogulniega Minecraft.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3440) Ogulniega Minecraft.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3440) Ogulniega Minecraft.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3440) Ogulniega Minecraft.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3440) Ogulniega Minecraft.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(3440) Ogulniega Minecraft.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(3440) Ogulniega Minecraft.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3464) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{80B0269C-547A-41DD-AD60-99B17B702C31}\{03BA301B-6FE6-43B6-A7C9-03A08DE591CE}
Operation:delete keyName:(default)
Value:
Executable files
0
Suspicious files
13
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
3440Ogulniega Minecraft.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\launcher_stable[1].jsonbinary
MD5:F9EC13574BDA573013E064063D374794
SHA256:664630587C2F253760C30700583D61DB46A20938C93513ACC734F00AAD493F66
3440Ogulniega Minecraft.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\E2C6CBAF0AF08CF203BA74BF0D0AB6D5_0FB9553B978E7F00C6B2309507DEB64Abinary
MD5:C5A6FB7053DAE46770B235E59CFD6207
SHA256:FB2D8C93B78C4EFEEC6689CAFE5FDD8001A9F0A53A7DBBD4A8F8E9237F91B14B
3440Ogulniega Minecraft.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAF4703619713E3F18D8A9D5D88D6288_F2DAF19C1F776537105D08FC8D978464binary
MD5:B0B81783B18C13698C46278AA7406AD6
SHA256:5B28940BA263567FA6C8D8CC9A72F0A4F07765A2248FE0D8103E0AF1450DE30E
3440Ogulniega Minecraft.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:83E95247685D79423ECB74245741DFA2
SHA256:87825A5D7EA813025A8055D2C774C35CBFCDE2782B83A34079F3B9FCAB77269C
3440Ogulniega Minecraft.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776binary
MD5:9514843726460D23C6D8784CA41CF755
SHA256:5D9C521D5FD2969D8820FAAE22CAA7435B954F68D3D47CBA6FA795997E33F68B
3440Ogulniega Minecraft.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\7423F88C7F265F0DEFC08EA88C3BDE45_AA1E8580D4EBC816148CE81268683776binary
MD5:60633903D1716025BF50E2B9C37C7FF4
SHA256:D312F9F067C47C49193017CC35F47E2EF7C082EBC84F825B173C54AA9FC0235A
3440Ogulniega Minecraft.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\CAF4703619713E3F18D8A9D5D88D6288_F2DAF19C1F776537105D08FC8D978464binary
MD5:8202A1CD02E7D69597995CABBE881A12
SHA256:58F381C3A0A0ACE6321DA22E40BD44A597BD98B9C9390AB9258426B5CF75A7A5
3440Ogulniega Minecraft.exeC:\Users\admin\AppData\Roaming\.ogulniega\java\java_tempcompressed
MD5:DF3BF680FBCE2071A37A864D1C152B26
SHA256:E0ED4F4C65EB6EED6E016A405A6CC2578AF3F20B7442148E444363C72DB7731F
3440Ogulniega Minecraft.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\microsoft-jdk-17.0.8.1-windows-x64[1].zipcompressed
MD5:DF3BF680FBCE2071A37A864D1C152B26
SHA256:E0ED4F4C65EB6EED6E016A405A6CC2578AF3F20B7442148E444363C72DB7731F
3440Ogulniega Minecraft.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:BC382247EEACC846757141389A1C43DF
SHA256:35B0D19D50DD31810E6FA66444838FB89FE6EF6310085345D2DD0CEAD6637092
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
11
DNS requests
7
Threats
5

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3440
Ogulniega Minecraft.exe
GET
136.243.156.120:80
http://cdn.ogulniega.ct8.pl/files/quilt-loader-0.21.0-1.20.1.zip
unknown
unknown
3440
Ogulniega Minecraft.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
binary
471 b
unknown
3440
Ogulniega Minecraft.exe
GET
200
142.250.186.163:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFCjJ1PwkYAi7fE%3D
unknown
binary
724 b
unknown
3440
Ogulniega Minecraft.exe
GET
200
142.250.186.163:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
3440
Ogulniega Minecraft.exe
GET
200
46.228.146.0:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f7dc0100f9e8fe1a
unknown
compressed
4.66 Kb
unknown
3440
Ogulniega Minecraft.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
binary
471 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
3440
Ogulniega Minecraft.exe
188.114.97.3:443
ogulnie.ga
CLOUDFLARENET
NL
unknown
4
System
192.168.100.255:138
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
3440
Ogulniega Minecraft.exe
46.228.146.0:80
ctldl.windowsupdate.com
LLNW
US
unknown
3440
Ogulniega Minecraft.exe
142.250.186.163:80
ocsp.pki.goog
GOOGLE
US
whitelisted
3440
Ogulniega Minecraft.exe
104.119.110.121:443
aka.ms
AKAMAI-AS
DE
unknown
3440
Ogulniega Minecraft.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
3440
Ogulniega Minecraft.exe
68.232.34.200:443
download.visualstudio.microsoft.com
EDGECAST
US
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

Domain
IP
Reputation
ogulnie.ga
  • 188.114.97.3
  • 188.114.96.3
unknown
ctldl.windowsupdate.com
  • 46.228.146.0
  • 46.228.146.128
whitelisted
ocsp.pki.goog
  • 142.250.186.163
whitelisted
aka.ms
  • 104.119.110.121
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
download.visualstudio.microsoft.com
  • 68.232.34.200
whitelisted
cdn.ogulniega.ct8.pl
  • 136.243.156.120
unknown

Threats

PID
Process
Class
Message
1080
svchost.exe
Misc activity
ET INFO DNS Query for Suspicious .ga Domain
3440
Ogulniega Minecraft.exe
Misc activity
ET INFO Suspicious Domain (*.ga) in TLS SNI
1080
svchost.exe
Misc activity
ET INFO DNS Query to a Free Hosting Domain Domain (*.ct8 pl)
3440
Ogulniega Minecraft.exe
Misc activity
ET INFO HTTP Request to Free Hosting Domain (*.ct8 .pl)
1 ETPRO signatures available at the full report
No debug info