| File name: | aware.exe |
| Full analysis: | https://app.any.run/tasks/fe78c835-eb2b-4375-8ffa-1656c55d734a |
| Verdict: | Malicious activity |
| Analysis date: | July 29, 2024, 19:27:08 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32+ executable (console) x86-64, for MS Windows |
| MD5: | AA6AEBC3EF0359F1A24D9A619828AC59 |
| SHA1: | D36E07B993C4B668C0DBFE2DA5A998E3787E20DD |
| SHA256: | 7A829D30AF8752B8CB46328AB7DE4FC462287062280B5F9A3824F39D35C22B4C |
| SSDEEP: | 98304:Jl70XCl+KLTAHNMl/v0TqKJtT9IFLdZJULG8/Gkmu/ndyHGBMi0Ya/pNkLdANBHw:uPuM1U/VOmpGujpX9F7zZ5KD |
| .exe | | | Win64 Executable (generic) (87.3) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (6.3) |
| .exe | | | DOS Executable Generic (6.3) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2024:07:29 19:26:37+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 14.4 |
| CodeSize: | 172032 |
| InitializedDataSize: | 151040 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb220 |
| OSVersion: | 5.2 |
| ImageVersion: | - |
| SubsystemVersion: | 5.2 |
| Subsystem: | Windows command line |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 752 | ipconfig /all | C:\Windows\System32\ipconfig.exe | — | aware.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: IP Configuration Utility Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 1476 | driverquery /v | C:\Windows\System32\driverquery.exe | — | aware.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Queries the drivers on a system Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2300 | "C:\Users\admin\Desktop\aware.exe" | C:\Users\admin\Desktop\aware.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| 2496 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 2692 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | aware.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 3400 | "C:\Users\admin\Desktop\aware.exe" | C:\Users\admin\Desktop\aware.exe | aware.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2300 | aware.exe | C:\Users\admin\AppData\Local\Temp\_MEI23002\VCRUNTIME140.dll | executable | |
MD5:BE8DBE2DC77EBE7F88F910C61AEC691A | SHA256:4D292623516F65C80482081E62D5DADB759DC16E851DE5DB24C3CBB57B87DB83 | |||
| 2300 | aware.exe | C:\Users\admin\AppData\Local\Temp\_MEI23002\Pythonwin\win32ui.pyd | executable | |
MD5:39C17A3F9C8064AB1D17213172424CE1 | SHA256:E376B270E4CA00C9B3D8F47A03994161949A82304D57C7848FAC4F60E533A7CD | |||
| 2300 | aware.exe | C:\Users\admin\AppData\Local\Temp\_MEI23002\Pythonwin\mfc140u.dll | executable | |
MD5:03A161718F1D5E41897236D48C91AE3C | SHA256:E06C4BD078F4690AA8874A3DEB38E802B2A16CCB602A7EDC2E077E98C05B5807 | |||
| 2300 | aware.exe | C:\Users\admin\AppData\Local\Temp\_MEI23002\_ctypes.pyd | executable | |
MD5:E72BDB1F065056F3D7068219592C7100 | SHA256:C17904B56720E127E910AC9071D6B402686DEA682B885910502CA35AD236F7FF | |||
| 2300 | aware.exe | C:\Users\admin\AppData\Local\Temp\_MEI23002\VCRUNTIME140_1.dll | executable | |
MD5:F8DFA78045620CF8A732E67D1B1EB53D | SHA256:A113F192195F245F17389E6ECBED8005990BCB2476DDAD33F7C4C6C86327AFE5 | |||
| 2300 | aware.exe | C:\Users\admin\AppData\Local\Temp\_MEI23002\_bz2.pyd | executable | |
MD5:48D518E37202553414F2192D78CEFB58 | SHA256:419AC8C3795F8BFA9363ADD917E477CAA1C0CE7139FA0903E8F4863166F907E9 | |||
| 2300 | aware.exe | C:\Users\admin\AppData\Local\Temp\_MEI23002\api-ms-win-core-file-l1-1-0.dll | executable | |
MD5:8F6227DA012EF0717C06820962B801EE | SHA256:F3D260008FAE0C5501FDF4F8D5B50FFC578964DFCB7039B5E2232FA53BAC39DB | |||
| 2300 | aware.exe | C:\Users\admin\AppData\Local\Temp\_MEI23002\_queue.pyd | executable | |
MD5:B5B5A5E8720D50AD91E06CDACEC3D5A4 | SHA256:AB437EFBE3F1C8BFEA5DEDA1613DF0EC8161E94A0852E8DF35CD9ECAACB8EA43 | |||
| 2300 | aware.exe | C:\Users\admin\AppData\Local\Temp\_MEI23002\_socket.pyd | executable | |
MD5:54033C133DCE045E7BA56C8DAFB5A333 | SHA256:BC9BF1DBCEEFAD62216F14968F4617AD6D6E526481F02A13D3220E9159B9DDF6 | |||
| 2300 | aware.exe | C:\Users\admin\AppData\Local\Temp\_MEI23002\api-ms-win-core-console-l1-1-0.dll | executable | |
MD5:A7EC2CA3BC14DBB6931F1A69EF0A4E57 | SHA256:DBECB3528DA74D472D07246975D803EA1ADE7C414CA5E1076EE6F0B0033DA578 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5368 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D | unknown | — | — | whitelisted |
5368 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
4424 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
3676 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 2.23.209.143:443 | www.bing.com | Akamai International B.V. | GB | unknown |
5812 | slui.exe | 20.83.72.98:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
5368 | SearchApp.exe | 131.253.33.254:443 | a-ring-fallback.msedge.net | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
6012 | MoUsoCoreWorker.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6220 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
3948 | RUXIMICS.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
488 | slui.exe | 20.83.72.98:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
— | — | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
a-ring-fallback.msedge.net |
| unknown |
www.bing.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
discord.com |
| whitelisted |
fp-afd-nocache-ccp.azureedge.net |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
3400 | aware.exe | Misc activity | ET INFO Observed Discord Domain (discord .com in TLS SNI) |
2284 | svchost.exe | Misc activity | ET INFO Observed Discord Domain in DNS Lookup (discord .com) |