File name:

keyS7.exe

Full analysis: https://app.any.run/tasks/73817e3e-ae6d-486a-85f4-86b5f678e09f
Verdict: Malicious activity
Analysis date: February 19, 2024, 22:21:05
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

B8BC232CA70E2DE1699372F4E508E2C0

SHA1:

BD9B85BB714CA94B4860E8E0F38622A0C55E733F

SHA256:

72F748DB67DF213A69A92C0617B35E537A63292ED3226D421CFBBD17A3429365

SSDEEP:

98304:PaqBqCrNQRm0UQ7AM4KcVvYRf+XAlOfJukyPHQDnYkb+PTRi:FX

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • keyS7.exe (PID: 3700)
      • keyS7.exe (PID: 3536)
    • Unusual execution from MS Outlook

      • OUTLOOK.EXE (PID: 2848)
  • SUSPICIOUS

    • Application launched itself

      • keyS7.exe (PID: 3700)
    • Executable content was dropped or overwritten

      • keyS7.exe (PID: 3536)
    • Reads Internet Explorer settings

      • keyS7.exe (PID: 3536)
    • Reads the Internet Settings

      • keyS7.exe (PID: 3536)
    • Reads Microsoft Outlook installation path

      • keyS7.exe (PID: 3536)
  • INFO

    • Reads the computer name

      • keyS7.exe (PID: 3700)
      • keyS7.exe (PID: 3536)
      • OSPPSVC.EXE (PID: 3180)
    • Checks supported languages

      • keyS7.exe (PID: 3700)
      • keyS7.exe (PID: 3536)
      • OSPPSVC.EXE (PID: 3180)
      • DW20.EXE (PID: 1976)
    • Creates files or folders in the user directory

      • keyS7.exe (PID: 3700)
      • keyS7.exe (PID: 3536)
      • SearchIndexer.exe (PID: 2636)
      • OSPPSVC.EXE (PID: 3180)
      • lsass.exe (PID: 796)
      • DWWIN.EXE (PID: 2156)
      • lsass.exe (PID: 2792)
    • Reads the machine GUID from the registry

      • keyS7.exe (PID: 3536)
      • OSPPSVC.EXE (PID: 3180)
    • Reads Internet Explorer settings

      • OUTLOOK.EXE (PID: 2848)
    • Reads Microsoft Office registry keys

      • OSPPSVC.EXE (PID: 3180)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Thinapp Packaged Portable Application Launcher executable (96.3)
.exe | DOS Executable Borland C++ (2.7)
.exe | Generic Win/DOS Executable (0.4)
.exe | DOS Executable Generic (0.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:08:06 11:48:55+00:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 12288
InitializedDataSize: 4096
UninitializedDataSize: -
EntryPoint: 0x1464
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
11
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start keys7.exe no specs keys7.exe outlook.exe searchindexer.exe no specs svchost.exe no specs lsass.exe no specs osppsvc.exe no specs lsass.exe no specs lsass.exe no specs dw20.exe no specs dwwin.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
796C:\Windows\system32\lsass.exeC:\Windows\System32\lsass.exeOUTLOOK.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Local Security Authority Process
Exit code:
3221225569
Version:
6.1.7601.24545 (win7sp1_ldr_escrow.200102-1707)
Modules
Images
c:\windows\system32\lsass.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
1692C:\Windows\System32\svchost.exe -k LocalServiceC:\Windows\System32\svchost.exeOUTLOOK.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Host Process for Windows Services
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
1976"C:\PROGRA~1\COMMON~1\MICROS~1\DW\DW20.EXE" -x -s 232C:\Program Files\Common Files\microsoft shared\DW\DW20.EXEOUTLOOK.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Application Error Reporting
Exit code:
0
Version:
14.0.6015.1000
Modules
Images
c:\program files\common files\microsoft shared\dw\dw20.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acspecfc.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
2152C:\Windows\system32\lsass.exeC:\Windows\System32\lsass.exeOUTLOOK.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Local Security Authority Process
Exit code:
0
Version:
6.1.7601.24545 (win7sp1_ldr_escrow.200102-1707)
2156C:\Windows\system32\dwwin.exe -x -s 232C:\Windows\System32\DWWIN.EXEDW20.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Watson Client
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\dwwin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2636C:\Windows\system32\SearchIndexer.exe /EmbeddingC:\Windows\System32\SearchIndexer.exeOUTLOOK.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Windows Search Indexer
Exit code:
0
Version:
7.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\searchindexer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
2792C:\Windows\system32\lsass.exeC:\Windows\System32\lsass.exeOUTLOOK.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Local Security Authority Process
Exit code:
3221225569
Version:
6.1.7601.24545 (win7sp1_ldr_escrow.200102-1707)
Modules
Images
c:\windows\system32\lsass.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
2848"C:\PROGRA~1\MICROS~1\Office14\OUTLOOK.EXE" -c IPM.Note /m "mailto:s2kk@rambler.ru"C:\Program Files\Microsoft Office\Office14\OUTLOOK.EXE
keyS7.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Outlook
Exit code:
1
Version:
14.0.6025.1000
Modules
Images
c:\program files\microsoft office\office14\outlook.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3180"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXE"C:\Program Files\Common Files\Microsoft Shared\OfficeSoftwareProtectionPlatform\OSPPSVC.EXEOUTLOOK.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office Software Protection Platform Service
Exit code:
0
Version:
14.0.0370.400 (longhorn(wmbla).090811-1833)
Modules
Images
c:\program files\common files\microsoft shared\officesoftwareprotectionplatform\osppsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
3536"C:\Program Files\keyS7\keyS7.exe" C:\Users\admin\AppData\Local\Temp\keyS7.exe
keyS7.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
1.0.3870.26667
Modules
Images
c:\users\admin\appdata\local\temp\keys7.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
Total events
9 175
Read events
9 168
Write events
7
Delete events
0

Modification events

(PID) Process:(2848) OUTLOOK.EXEKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2848) OUTLOOK.EXEKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:C:\Windows\system32,@tzres.dll,-2670
Value:
(UTC+00:00) Dublin, Edinburgh, Lisbon, London
(PID) Process:(2848) OUTLOOK.EXEKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:C:\Windows\system32,@tzres.dll,-262
Value:
GMT Standard Time
(PID) Process:(2848) OUTLOOK.EXEKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:C:\Windows\system32,@tzres.dll,-261
Value:
GMT Daylight Time
(PID) Process:(2156) DWWIN.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\Windows Error Reporting\Debug\UIHandles
Operation:writeName:FirstLevelConsentDialog
Value:
92020A0000000000
Executable files
4
Suspicious files
7
Text files
27
Unknown types
3

Dropped files

PID
Process
Filename
Type
2848OUTLOOK.EXEC:\Users\admin\AppData\Local\Temp\CVR73c4.tmp.cvr
MD5:
SHA256:
2848OUTLOOK.EXEC:\Users\admin\Documents\Outlook Files\Outlook Data File - NoMail.pst
MD5:
SHA256:
3700keyS7.exeC:\Users\admin\AppData\Roaming\Thinstall\keyS7 v3.10\Registry.tlogbinary
MD5:6DF59352ABCBE4DFA784AA65834FA48C
SHA256:EA0F40A37A5CBA0F0F090E7170B006135B3A65305BBE08D80100221C527A74C7
3700keyS7.exeC:\Users\admin\AppData\Roaming\Thinstall\keyS7 v3.10\Registry.rw.tvr.lckbinary
MD5:317D235AA2A10934E0DEE2DEFD5DECD1
SHA256:F1257CE9FE6CA3588BC00D694F92A82ECEBC382E6FFF852C07DABD5610221EB3
3536keyS7.exeC:\Users\admin\AppData\Roaming\Thinstall\keyS7 v3.10\SKEL\51afecf48ae59b756ae78fdbd477d7b4ca9.SharedTA.f4c.dd0executable
MD5:78C0AF4ABEB15E999B0ADD4DE1190166
SHA256:FB320A42167D9185C240E8DA336D431DB27755093B67CABBBDDDFB160FC88410
3536keyS7.exeC:\Users\admin\AppData\Roaming\Thinstall\keyS7 v3.10\Registry.tlog.cachebinary
MD5:9580C8BED1805A63750C8FE244D255CA
SHA256:586D3703DF920FCAF63E491337C5AD357D1068FFA6585791677F2878CC0B71BD
3700keyS7.exeC:\Users\admin\AppData\Roaming\Thinstall\keyS7 v3.10\Registry.rw.tvr.transactbinary
MD5:EBC8ED3FB8FDE166AEAF38ADB89F346E
SHA256:F905E0171F5EAD0FDAFB2269B854D475A892666D0EA036948C4C723D3B2DED63
3536keyS7.exeC:\Users\admin\AppData\Roaming\Thinstall\keyS7 v3.10\SKEL\51afecf48ae59b756ae78fdbd477d7b4ca9.SharedTAexecutable
MD5:78C0AF4ABEB15E999B0ADD4DE1190166
SHA256:FB320A42167D9185C240E8DA336D431DB27755093B67CABBBDDDFB160FC88410
3536keyS7.exeC:\Users\admin\AppData\Roaming\Thinstall\keyS7 v3.10\SKEL\c37681b7a9928fc28714caec666dfad961b2c63.SharedTAexecutable
MD5:911CA4481A97ACEFF6A0C198C2C9458F
SHA256:EEF559E9024376308A89D1BA259D109D121E14DBDC0C0CBF01E2B198CBC03D06
3536keyS7.exeC:\Users\admin\AppData\Roaming\Thinstall\keyS7 v3.10\SKEL\2852-1.manifestxml
MD5:1397A0C049BF68606EE5153EF551488C
SHA256:CE716DD42748CBCDFBBF6A4CA27403BD94804B49D9EAF47FF949552EE594DF93
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
5
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2848
OUTLOOK.EXE
64.4.26.155:80
config.messenger.msn.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted

DNS requests

Domain
IP
Reputation
config.messenger.msn.com
  • 64.4.26.155
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
Process
Message
keyS7.exe
.reload boot_loader.exe=79bf0000,10000
OUTLOOK.EXE
.reload boot_loader.exe=79bf0000,10000
OUTLOOK.EXE
.reload boot_loader.exe=79bf0000,10000
OUTLOOK.EXE
.reload boot_loader.exe=79bf0000,10000
OUTLOOK.EXE
.reload boot_loader.exe=79bf0000,10000
OUTLOOK.EXE
.reload boot_loader.exe=79bf0000,10000
OUTLOOK.EXE
.reload boot_loader.exe=79bf0000,10000
OUTLOOK.EXE
.reload boot_loader.exe=79bf0000,10000