File name:

Oski Cracked.exe

Full analysis: https://app.any.run/tasks/d2f1160b-09fb-4d66-9d56-9c8afd334613
Verdict: Malicious activity
Analysis date: June 08, 2024, 18:44:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
oski
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

2BD0E61C45D352697C5E16437D8055B0

SHA1:

0B9B24D396A50C2DC13D73E1F2D57C1891DE3F31

SHA256:

71EFC8FC1DEDE4F96E837043AD3CBD38A65BD530CE71AE4D44DDC29843FAB70B

SSDEEP:

98304:EJCbuSMburCaMZh0yEKj+WRvrY1dcZ048HV/bFy8jJ7D:mmMbuQZlFY7KsZPND

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Oski Cracked.exe (PID: 3988)
    • OSKI has been detected (YARA)

      • Oski Cracked.exe (PID: 3988)
  • SUSPICIOUS

    • Reads Internet Explorer settings

      • Oski Cracked.exe (PID: 3988)
    • Reads the Internet Settings

      • Oski Cracked.exe (PID: 3988)
  • INFO

    • Reads the computer name

      • Oski Cracked.exe (PID: 3988)
    • Checks supported languages

      • Oski Cracked.exe (PID: 3988)
    • Reads the machine GUID from the registry

      • Oski Cracked.exe (PID: 3988)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (82.9)
.dll | Win32 Dynamic Link Library (generic) (7.4)
.exe | Win32 Executable (generic) (5.1)
.exe | Generic Win/DOS Executable (2.2)
.exe | DOS Executable Generic (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:07:21 14:39:58+00:00
ImageFileCharacteristics: Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 4060672
InitializedDataSize: 70144
UninitializedDataSize: -
EntryPoint: 0x3e15ee
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: Oski Cracked By Lenskiy
FileVersion: 1.0.0.0
InternalName: Oski Cracked By Lenskiy.exe
LegalCopyright: Copyright © 2020
LegalTrademarks: -
OriginalFileName: Oski Cracked By Lenskiy.exe
ProductName: Oski Cracked By Lenskiy
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #OSKI oski cracked.exe

Process information

PID
CMD
Path
Indicators
Parent process
3988"C:\Users\admin\Desktop\Oski Cracked.exe" C:\Users\admin\Desktop\Oski Cracked.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Oski Cracked By Lenskiy
Exit code:
3221225477
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\oski cracked.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
289
Read events
289
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
1088
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info