| File name: | keyS7.exe |
| Full analysis: | https://app.any.run/tasks/73817e3e-ae6d-486a-85f4-86b5f678e09f |
| Verdict: | Malicious activity |
| Analysis date: | February 19, 2024, 22:21:05 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | B8BC232CA70E2DE1699372F4E508E2C0 |
| SHA1: | BD9B85BB714CA94B4860E8E0F38622A0C55E733F |
| SHA256: | 72F748DB67DF213A69A92C0617B35E537A63292ED3226D421CFBBD17A3429365 |
| SSDEEP: | 98304:PaqBqCrNQRm0UQ7AM4KcVvYRf+XAlOfJukyPHQDnYkb+PTRi:FX |
| .exe | | | Thinapp Packaged Portable Application Launcher executable (96.3) |
|---|---|---|
| .exe | | | DOS Executable Borland C++ (2.7) |
| .exe | | | Generic Win/DOS Executable (0.4) |
| .exe | | | DOS Executable Generic (0.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2010:08:06 11:48:55+00:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 12288 |
| InitializedDataSize: | 4096 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1464 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 796 | C:\Windows\system32\lsass.exe | C:\Windows\System32\lsass.exe | — | OUTLOOK.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Local Security Authority Process Exit code: 3221225569 Version: 6.1.7601.24545 (win7sp1_ldr_escrow.200102-1707) Modules
| |||||||||||||||
| 1692 | C:\Windows\System32\svchost.exe -k LocalService | C:\Windows\System32\svchost.exe | — | OUTLOOK.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1976 | "C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE" -x -s 232 | C:\Program Files\Common Files\microsoft shared\DW\DW20.EXE | — | OUTLOOK.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Application Error Reporting Exit code: 0 Version: 14.0.6015.1000 Modules
| |||||||||||||||
| 2152 | C:\Windows\system32\lsass.exe | C:\Windows\System32\lsass.exe | — | OUTLOOK.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Local Security Authority Process Exit code: 0 Version: 6.1.7601.24545 (win7sp1_ldr_escrow.200102-1707) | |||||||||||||||
| 2156 | C:\Windows\system32\dwwin.exe -x -s 232 | C:\Windows\System32\DWWIN.EXE | — | DW20.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Watson Client Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2636 | C:\Windows\system32\SearchIndexer.exe /Embedding | C:\Windows\System32\SearchIndexer.exe | — | OUTLOOK.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Windows Search Indexer Exit code: 0 Version: 7.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2792 | C:\Windows\system32\lsass.exe | C:\Windows\System32\lsass.exe | — | OUTLOOK.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Local Security Authority Process Exit code: 3221225569 Version: 6.1.7601.24545 (win7sp1_ldr_escrow.200102-1707) Modules
| |||||||||||||||
| 2848 | "C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE" -c IPM.Note /m "mailto:s2kk@rambler.ru" | C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE | keyS7.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Outlook Exit code: 1 Version: 14.0.6025.1000 Modules
| |||||||||||||||
| 3180 | "C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE" | C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE | — | OUTLOOK.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Office Software Protection Platform Service Exit code: 0 Version: 14.0.0370.400 (longhorn(wmbla).090811-1833) Modules
| |||||||||||||||
| 3536 | "C:\Program Files\keyS7\keyS7.exe" | C:\Users\admin\AppData\Local\Temp\keyS7.exe | keyS7.exe | ||||||||||||
User: admin Company: Integrity Level: MEDIUM Description: Exit code: 0 Version: 1.0.3870.26667 Modules
| |||||||||||||||
| (PID) Process: | (2848) OUTLOOK.EXE | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2848) OUTLOOK.EXE | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | C:\Windows\system32,@tzres.dll,-2670 |
Value: (UTC+00:00) Dublin, Edinburgh, Lisbon, London | |||
| (PID) Process: | (2848) OUTLOOK.EXE | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | C:\Windows\system32,@tzres.dll,-262 |
Value: GMT Standard Time | |||
| (PID) Process: | (2848) OUTLOOK.EXE | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | C:\Windows\system32,@tzres.dll,-261 |
Value: GMT Daylight Time | |||
| (PID) Process: | (2156) DWWIN.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles |
| Operation: | write | Name: | FirstLevelConsentDialog |
Value: 92020A0000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2848 | OUTLOOK.EXE | C:\Users\admin\AppData\Local\Temp\CVR73c4.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 2848 | OUTLOOK.EXE | C:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst | — | |
MD5:— | SHA256:— | |||
| 3700 | keyS7.exe | C:\Users\admin\AppData\Roaming\Thinstall\keyS7 v3.10\Registry.tlog | binary | |
MD5:6DF59352ABCBE4DFA784AA65834FA48C | SHA256:EA0F40A37A5CBA0F0F090E7170B006135B3A65305BBE08D80100221C527A74C7 | |||
| 3700 | keyS7.exe | C:\Users\admin\AppData\Roaming\Thinstall\keyS7 v3.10\Registry.rw.tvr.lck | binary | |
MD5:317D235AA2A10934E0DEE2DEFD5DECD1 | SHA256:F1257CE9FE6CA3588BC00D694F92A82ECEBC382E6FFF852C07DABD5610221EB3 | |||
| 3536 | keyS7.exe | C:\Users\admin\AppData\Roaming\Thinstall\keyS7 v3.10\SKEL\51afecf48ae59b756ae78fdbd477d7b4ca9.SharedTA.f4c.dd0 | executable | |
MD5:78C0AF4ABEB15E999B0ADD4DE1190166 | SHA256:FB320A42167D9185C240E8DA336D431DB27755093B67CABBBDDDFB160FC88410 | |||
| 3536 | keyS7.exe | C:\Users\admin\AppData\Roaming\Thinstall\keyS7 v3.10\Registry.tlog.cache | binary | |
MD5:9580C8BED1805A63750C8FE244D255CA | SHA256:586D3703DF920FCAF63E491337C5AD357D1068FFA6585791677F2878CC0B71BD | |||
| 3700 | keyS7.exe | C:\Users\admin\AppData\Roaming\Thinstall\keyS7 v3.10\Registry.rw.tvr.transact | binary | |
MD5:EBC8ED3FB8FDE166AEAF38ADB89F346E | SHA256:F905E0171F5EAD0FDAFB2269B854D475A892666D0EA036948C4C723D3B2DED63 | |||
| 3536 | keyS7.exe | C:\Users\admin\AppData\Roaming\Thinstall\keyS7 v3.10\SKEL\51afecf48ae59b756ae78fdbd477d7b4ca9.SharedTA | executable | |
MD5:78C0AF4ABEB15E999B0ADD4DE1190166 | SHA256:FB320A42167D9185C240E8DA336D431DB27755093B67CABBBDDDFB160FC88410 | |||
| 3536 | keyS7.exe | C:\Users\admin\AppData\Roaming\Thinstall\keyS7 v3.10\SKEL\c37681b7a9928fc28714caec666dfad961b2c63.SharedTA | executable | |
MD5:911CA4481A97ACEFF6A0C198C2C9458F | SHA256:EEF559E9024376308A89D1BA259D109D121E14DBDC0C0CBF01E2B198CBC03D06 | |||
| 3536 | keyS7.exe | C:\Users\admin\AppData\Roaming\Thinstall\keyS7 v3.10\SKEL\2852-1.manifest | xml | |
MD5:1397A0C049BF68606EE5153EF551488C | SHA256:CE716DD42748CBCDFBBF6A4CA27403BD94804B49D9EAF47FF949552EE594DF93 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2848 | OUTLOOK.EXE | 64.4.26.155:80 | config.messenger.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
config.messenger.msn.com |
| whitelisted |
dns.msftncsi.com |
| shared |
Process | Message |
|---|---|
keyS7.exe | .reload boot_loader.exe=79bf0000,10000 |
OUTLOOK.EXE | .reload boot_loader.exe=79bf0000,10000 |
OUTLOOK.EXE | .reload boot_loader.exe=79bf0000,10000 |
OUTLOOK.EXE | .reload boot_loader.exe=79bf0000,10000 |
OUTLOOK.EXE | .reload boot_loader.exe=79bf0000,10000 |
OUTLOOK.EXE | .reload boot_loader.exe=79bf0000,10000 |
OUTLOOK.EXE | .reload boot_loader.exe=79bf0000,10000 |
OUTLOOK.EXE | .reload boot_loader.exe=79bf0000,10000 |