File name:

SecuriteInfo.com.BACKDOOR.Trojan.6794.1201

Full analysis: https://app.any.run/tasks/7befbed2-a4df-4c0e-a1fb-c2b0982667e3
Verdict: Malicious activity
Analysis date: November 02, 2023, 01:57:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

17A4C0E64A792F3FE2FB2FE9F91CB890

SHA1:

3ED189C07432971251DBFDC6B110282C8182C30A

SHA256:

6E2D8739B47F4D48B5B9F38C824015BD6469A27C3286A63BFA84FE4E1B89DC03

SSDEEP:

49152:CBkhnfa9nS0MalMk6kkfGorao40MlIIjumMxWc4QY4GPss8Ewec+0KMwEUuuVGGH:XH0MalMk6kkfGorao40MlIIjumMxWc4f

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • SecuriteInfo.com.BACKDOOR.Trojan.6794.1201.exe (PID: 2328)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Checks supported languages

      • SecuriteInfo.com.BACKDOOR.Trojan.6794.1201.exe (PID: 2328)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable Microsoft Visual Basic 6 (54.9)
.exe | Win32 Executable MS Visual C++ (generic) (20.8)
.exe | Win64 Executable (generic) (18.4)
.exe | Win32 Executable (generic) (3)
.exe | Generic Win/DOS Executable (1.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2013:04:03 16:23:40+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 1323008
InitializedDataSize: 32768
UninitializedDataSize: -
EntryPoint: 0x4444
OSVersion: 4
ImageVersion: 4.6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 4.6.0.0
ProductVersionNumber: 4.6.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Unicode
CompanyName: 米客宝mikebao.org
FileDescription: 帮助站长抢注已过期的备案域名
LegalCopyright: 米客宝
LegalTrademarks: 米客宝
ProductName: 过期域名查询
FileVersion: 4.06
ProductVersion: 4.06
InternalName: 极速过期域名查询
OriginalFileName: 极速过期域名查询.exe
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
6
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start securiteinfo.com.backdoor.trojan.6794.1201.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs regsvr32.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2328"C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.BACKDOOR.Trojan.6794.1201.exe" C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.BACKDOOR.Trojan.6794.1201.exeexplorer.exe
User:
admin
Company:
米客宝mikebao.org
Integrity Level:
MEDIUM
Description:
帮助站长抢注已过期的备案域名
Exit code:
0
Version:
4.06
Modules
Images
c:\users\admin\appdata\local\temp\securiteinfo.com.backdoor.trojan.6794.1201.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2348regsvr32 /s C:\Windows\system32\stdole2.tlbC:\Windows\SysWOW64\regsvr32.exeSecuriteInfo.com.BACKDOOR.Trojan.6794.1201.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Exit code:
4
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2672regsvr32 /s C:\Windows\system32\COMCAT.DLLC:\Windows\SysWOW64\regsvr32.exeSecuriteInfo.com.BACKDOOR.Trojan.6794.1201.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2688regsvr32 /s C:\Windows\system32\oleaut32.dllC:\Windows\SysWOW64\regsvr32.exeSecuriteInfo.com.BACKDOOR.Trojan.6794.1201.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Exit code:
5
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2844regsvr32 /s C:\Windows\system32\olepro32.dllC:\Windows\SysWOW64\regsvr32.exeSecuriteInfo.com.BACKDOOR.Trojan.6794.1201.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
3020regsvr32 /s C:\Windows\system32\msvbvm60.dllC:\Windows\SysWOW64\regsvr32.exeSecuriteInfo.com.BACKDOOR.Trojan.6794.1201.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft(C) Register Server
Exit code:
5
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
Total events
63
Read events
63
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info