analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1

Full analysis: https://app.any.run/tasks/4913ffd2-ac87-4520-bffe-e88e9ff7dd65
Verdict: Malicious activity
Analysis date: October 05, 2022, 04:04:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
blacknet
evasion
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

10E6C5653D2929236947CA08594F0F55

SHA1:

9ED6646EF7F0815D02066B60CD7BBC8D27CBF360

SHA256:

851266DA3FFDF9C37B139611382B30710AB960B761125CDDE6CBA1EEAEBF24E1

SSDEEP:

6144:mQvE/UVPy/oCa+LDZWC9z5NUb+knq1diDmN:3vzPygCa+DZCnq1c+

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Uses Task Scheduler to run other applications

      • 851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe (PID: 3188)
    • BLACKNET detected by memory dumps

      • 851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe (PID: 3188)
      • SystemPropertiesPerformance.exe (PID: 3448)
    • Changes the Startup folder

      • 851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe (PID: 3188)
    • Loads the Task Scheduler COM API

      • schtasks.exe (PID: 3568)
      • schtasks.exe (PID: 3632)
      • schtasks.exe (PID: 3200)
      • schtasks.exe (PID: 3700)
      • schtasks.exe (PID: 1980)
    • Application was dropped or rewritten from another process

      • iscsicli.exe (PID: 3460)
  • SUSPICIOUS

    • Checks supported languages

      • 851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe (PID: 3188)
      • SystemPropertiesPerformance.exe (PID: 3448)
      • cmd.exe (PID: 2488)
      • iscsicli.exe (PID: 3460)
      • cmd.exe (PID: 2704)
    • Reads the computer name

      • 851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe (PID: 3188)
      • SystemPropertiesPerformance.exe (PID: 3448)
      • iscsicli.exe (PID: 3460)
    • Creates files in the user directory

      • 851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe (PID: 3188)
      • SystemPropertiesPerformance.exe (PID: 3448)
    • Writes to a desktop.ini file (may be used to cloak folders)

      • 851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe (PID: 3188)
    • Reads Environment values

      • 851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe (PID: 3188)
      • SystemPropertiesPerformance.exe (PID: 3448)
    • Changes tracing settings of the file or console

      • 851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe (PID: 3188)
    • Starts itself from another location

      • 851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe (PID: 3188)
    • Starts CMD.EXE for commands execution

      • SystemPropertiesPerformance.exe (PID: 3448)
    • Uses ATTRIB.EXE to modify file attributes

      • cmd.exe (PID: 2488)
      • cmd.exe (PID: 2704)
  • INFO

    • Reads the computer name

      • explorer.exe (PID: 772)
      • schtasks.exe (PID: 3568)
      • schtasks.exe (PID: 3200)
      • schtasks.exe (PID: 3632)
      • schtasks.exe (PID: 1980)
      • schtasks.exe (PID: 3700)
    • Checks supported languages

      • explorer.exe (PID: 772)
      • schtasks.exe (PID: 3568)
      • schtasks.exe (PID: 3200)
      • schtasks.exe (PID: 3700)
      • schtasks.exe (PID: 3632)
      • schtasks.exe (PID: 1980)
      • attrib.exe (PID: 2908)
      • attrib.exe (PID: 2812)
      • attrib.exe (PID: 2984)
      • attrib.exe (PID: 2860)
    • Manual execution by user

      • explorer.exe (PID: 772)
    • Reads settings of System Certificates

      • SystemPropertiesPerformance.exe (PID: 3448)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (56.7)
.exe | Win64 Executable (generic) (21.3)
.scr | Windows screen saver (10.1)
.dll | Win32 Dynamic Link Library (generic) (5)
.exe | Win32 Executable (generic) (3.4)

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 2021-Apr-04 22:20:05
FileDescription: -
FileVersion: 0.0.0.0
InternalName: ServiceHub.exe
LegalCopyright: -
OriginalFilename: ServiceHub.exe
ProductVersion: 0.0.0.0
Assembly Version: 0.0.0.0

DOS Header

e_magic: MZ
e_cblp: 144
e_cp: 3
e_crlc: -
e_cparhdr: 4
e_minalloc: -
e_maxalloc: 65535
e_ss: -
e_sp: 184
e_csum: -
e_ip: -
e_cs: -
e_ovno: -
e_oemid: -
e_oeminfo: -
e_lfanew: 128

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
NumberofSections: 3
TimeDateStamp: 2021-Apr-04 22:20:05
PointerToSymbolTable: -
NumberOfSymbols: -
SizeOfOptionalHeader: 224
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
8192
242180
242688
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
5.60311
.rsrc
253952
3848
4096
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
4.89935
.reloc
262144
12
512
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
0.0815394

Resources

Title
Entropy
Size
Codepage
Language
Type
1
3.17246
596
UNKNOWN
UNKNOWN
RT_VERSION
1 (#2)
4.96259
3087
UNKNOWN
UNKNOWN
RT_MANIFEST

Imports

mscoree.dll
No data.
screenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
57
Monitored processes
15
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start drop and start #BLACKNET 851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe explorer.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs schtasks.exe no specs #BLACKNET systempropertiesperformance.exe cmd.exe no specs cmd.exe no specs attrib.exe no specs attrib.exe no specs attrib.exe no specs attrib.exe no specs iscsicli.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3188"C:\Users\admin\Desktop\851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe" C:\Users\admin\Desktop\851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe
Explorer.EXE
User:
admin
Integrity Level:
MEDIUM
Description:
Exit code:
0
Version:
0.0.0.0
Modules
Images
c:\users\admin\desktop\851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
772"C:\Windows\explorer.exe" C:\Windows\explorer.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3568schtasks /create /f /st "17:41" /sc daily /mo "5" /tn "Intel TXE" /tr "'explorer'http://bit.ly/2Q7XObq"C:\Windows\system32\schtasks.exe851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
3632schtasks /create /f /st "11:42" /sc daily /mo "5" /tn "Intel TXE" /tr "'explorer'http://bit.ly/2Q7XObq"C:\Windows\system32\schtasks.exe851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
3700schtasks /create /f /st "18:29" /sc daily /mo "3" /tn "Intel TXE" /tr "'explorer'http://bit.ly/2Q7XObq"C:\Windows\system32\schtasks.exe851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\kernelbase.dll
c:\windows\system32\schtasks.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
3200schtasks /create /f /st "13:52" /sc weekly /mo "4" /d "Thu" /tn "Intel TXE" /tr "'explorer'http://bit.ly/2Q7XObq"C:\Windows\system32\schtasks.exe851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\schtasks.exe
c:\windows\system32\clbcatq.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\cryptbase.dll
c:\windows\system32\version.dll
c:\windows\system32\imm32.dll
1980schtasks /create /f /st "06:57" /sc monthly /m "may" /tn "Intel TXE" /tr "'explorer'http://bit.ly/2Q7XObq"C:\Windows\system32\schtasks.exe851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\usp10.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\ktmw32.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
3448"C:\Users\admin\AppData\Roaming\addins\SystemPropertiesPerformance.exe" C:\Users\admin\AppData\Roaming\addins\SystemPropertiesPerformance.exe
851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Version:
0.0.0.0
Modules
Images
c:\users\admin\appdata\roaming\addins\systempropertiesperformance.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2488cmd /c attrib -H -R -S "C:\Users\admin\AppData\Roaming\addins\\iscsicli.exe" & attrib -H -R -S "C:\Users\admin\AppData\Roaming\addins\\iscsicli.exe\*" /S /DC:\Windows\system32\cmd.exeSystemPropertiesPerformance.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2704cmd /c attrib +H +R +S "C:\Users\admin\AppData\Roaming\addins\\iscsicli.exe" & attrib +H +R +S "C:\Users\admin\AppData\Roaming\addins\\iscsicli.exe\*" /S /DC:\Windows\system32\cmd.exeSystemPropertiesPerformance.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
5 963
Read events
5 898
Write events
65
Delete events
0

Modification events

(PID) Process:(3188) 851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(3188) 851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000003C010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A80164000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3188) 851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\User Shell Folders
Operation:writeName:Startup
Value:
C:\Users\admin\AppData\Roaming\LinkM
(PID) Process:(3188) 851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Reboot
Operation:writeName:ADX
Value:
U3VjY2Vzc2Z1bGx5IFJlYWR5IQ==
(PID) Process:(3188) 851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3188) 851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3188) 851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RASAPI32
Operation:writeName:FileTracingMask
Value:
(PID) Process:(3188) 851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
(PID) Process:(3188) 851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(3188) 851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
Executable files
2
Suspicious files
0
Text files
1
Unknown types
1

Dropped files

PID
Process
Filename
Type
3188851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exeC:\Users\admin\AppData\Roaming\addins\SystemPropertiesPerformance.exeexecutable
MD5:10E6C5653D2929236947CA08594F0F55
SHA256:851266DA3FFDF9C37B139611382B30710AB960B761125CDDE6CBA1EEAEBF24E1
3448SystemPropertiesPerformance.exeC:\Users\admin\AppData\Roaming\addins\iscsicli.exeexecutable
MD5:14EFEF5A091B2E4189B9103DDB849936
SHA256:A1E65E10AE43F8E437AB824E29231B69A8458B4AEBD8A77AC27D22B70169DAE6
3188851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exeC:\Users\admin\AppData\Roaming\LinkM\SystemPropertiesPerformance.exe.lnklnk
MD5:EDF525E996C9023553346AFFE0CE7DF4
SHA256:9649ADB29F61181EA9D000DC8028DE8781658E11AC1117FFAA84128CE8FE33F3
3188851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exeC:\Users\admin\AppData\Roaming\LinkM\desktop.initext
MD5:7F1698BAB066B764A314A589D338DAAE
SHA256:CDB11958506A5BA5478E22ED472FA3AE422FE9916D674F290207E1FC29AE5A76
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
7
DNS requests
4
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3188
851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe
64.40.144.30:21
ftp.encompossoftware.com
1P-WSS
DE
suspicious
3188
851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe
148.251.234.83:443
iplogger.org
Hetzner Online GmbH
DE
malicious
64.40.144.30:49669
ftp.encompossoftware.com
1P-WSS
DE
suspicious
3448
SystemPropertiesPerformance.exe
35.173.69.207:443
dpaste.com
AMAZON-AES
US
malicious
3448
SystemPropertiesPerformance.exe
172.67.34.170:443
pastebin.com
CLOUDFLARENET
US
malicious

DNS requests

Domain
IP
Reputation
iplogger.org
  • 148.251.234.83
shared
ftp.encompossoftware.com
  • 64.40.144.30
suspicious
pastebin.com
  • 172.67.34.170
  • 104.20.68.143
  • 104.20.67.143
shared
dpaste.com
  • 35.173.69.207
whitelisted

Threats

PID
Process
Class
Message
Potential Corporate Privacy Violation
ET POLICY IP Check Domain (iplogger .org in DNS Lookup)
3188
851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe
Potential Corporate Privacy Violation
ET POLICY IP Check Domain (iplogger .org in TLS SNI)
3188
851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe
Generic Protocol Command Decode
SURICATA Applayer Detect protocol only one direction
3188
851266da3ffdf9c37b139611382b30710ab960b761125cdde6cba1eeaebf24e1.exe
Potential Corporate Privacy Violation
ET INFO .exe File requested over FTP
No debug info