File name:

yin yang.bat

Full analysis: https://app.any.run/tasks/3e87fe9e-095c-44c8-a3f3-7900273b5915
Verdict: Malicious activity
Analysis date: April 12, 2024, 20:50:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/plain
File info: ASCII text, with very long lines (31424), with CRLF line terminators
MD5:

DC7885C57316E39E0D7B29922D2ED9D0

SHA1:

A8A5C67480CF13B5BB72F4C099650C3F5EDE65A8

SHA256:

86806F07D86CA6D01D408DE609ED1E3738E4E41FA91769BA713E8C98311FBFE2

SSDEEP:

768:3CF8vW8Oh8aLlCGi1Cj1G2M4bTjRhGlwQJg8y8+M4bTjRhGlwQJFoRT9Rllj:3F+8aLI/gI2MGTjewQJgNrMGTjewQJFi

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Gets path to any of the special folders (SCRIPT)

      • cscript.exe (PID: 1844)
      • cscript.exe (PID: 2856)
    • Detects the decoding of a binary file from Base64 (SCRIPT)

      • cscript.exe (PID: 1844)
      • cscript.exe (PID: 2856)
    • Uses base64 encoding (SCRIPT)

      • cscript.exe (PID: 1844)
      • cscript.exe (PID: 2856)
    • Changes the autorun value in the registry

      • file.exe (PID: 3392)
    • Drops the executable file immediately after the start

      • autumn.exe (PID: 2076)
    • Actions looks like stealing of personal data

      • file.exe (PID: 3392)
  • SUSPICIOUS

    • Creates XML DOM element (SCRIPT)

      • cscript.exe (PID: 1844)
      • cscript.exe (PID: 2856)
    • Using 'findstr.exe' to search for text patterns in files and output

      • cmd.exe (PID: 2100)
      • cmd.exe (PID: 3936)
    • The process executes VB scripts

      • cmd.exe (PID: 2100)
      • cmd.exe (PID: 3936)
    • Creates FileSystem object to access computer's file system (SCRIPT)

      • cscript.exe (PID: 1844)
      • cscript.exe (PID: 2856)
    • Sets XML DOM element text (SCRIPT)

      • cscript.exe (PID: 1844)
      • cscript.exe (PID: 2856)
    • Writes binary data to a Stream object (SCRIPT)

      • cscript.exe (PID: 1844)
      • cscript.exe (PID: 2856)
    • Saves data to a binary file (SCRIPT)

      • cscript.exe (PID: 1844)
      • cscript.exe (PID: 2856)
    • Creates a Stream, which may work with files, input/output devices, pipes, or TCP/IP sockets (SCRIPT)

      • cscript.exe (PID: 1844)
      • cscript.exe (PID: 2856)
    • Executable content was dropped or overwritten

      • file.exe (PID: 2968)
      • cscript.exe (PID: 2856)
      • autumn.exe (PID: 2076)
    • The process executes via Task Scheduler

      • ctfmon.exe (PID: 1460)
      • sipnotify.exe (PID: 1680)
    • Reads the Internet Settings

      • sipnotify.exe (PID: 1680)
      • control.exe (PID: 796)
    • Reads settings of System Certificates

      • sipnotify.exe (PID: 1680)
    • Creates file in the systems drive root

      • autumn.exe (PID: 2076)
      • file.exe (PID: 3392)
    • The executable file from the user directory is run by the CMD process

      • file.exe (PID: 3392)
    • Uses RUNDLL32.EXE to load library

      • control.exe (PID: 796)
  • INFO

    • Manual execution by a user

      • IMEKLMG.EXE (PID: 1952)
      • IMEKLMG.EXE (PID: 2056)
      • wmpnscfg.exe (PID: 2328)
      • autumn.exe (PID: 2076)
      • wmpnscfg.exe (PID: 2348)
      • taskmgr.exe (PID: 2528)
      • control.exe (PID: 796)
    • Reads the computer name

      • IMEKLMG.EXE (PID: 1952)
      • autumn.exe (PID: 2076)
      • wmpnscfg.exe (PID: 2328)
      • wmpnscfg.exe (PID: 2348)
      • IMEKLMG.EXE (PID: 2056)
      • file.exe (PID: 3392)
    • Reads security settings of Internet Explorer

      • sipnotify.exe (PID: 1680)
      • cscript.exe (PID: 2856)
      • control.exe (PID: 796)
    • Checks supported languages

      • IMEKLMG.EXE (PID: 2056)
      • autumn.exe (PID: 2076)
      • wmpnscfg.exe (PID: 2328)
      • IMEKLMG.EXE (PID: 1952)
      • wmpnscfg.exe (PID: 2348)
      • file.exe (PID: 3392)
    • Process checks whether UAC notifications are on

      • IMEKLMG.EXE (PID: 1952)
      • IMEKLMG.EXE (PID: 2056)
    • Reads the machine GUID from the registry

      • autumn.exe (PID: 2076)
      • file.exe (PID: 3392)
    • Reads the software policy settings

      • sipnotify.exe (PID: 1680)
    • Drops the executable file immediately after the start

      • cscript.exe (PID: 2856)
    • Creates files or folders in the user directory

      • autumn.exe (PID: 2076)
    • Create files in a temporary directory

      • cscript.exe (PID: 2856)
    • Reads the time zone

      • rundll32.exe (PID: 1740)
    • Checks transactions between databases Windows and Oracle

      • rundll32.exe (PID: 1740)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
119
Monitored processes
22
Malicious processes
7
Suspicious processes
1

Behavior graph

Click at the process to see the details
start ctfmon.exe no specs sipnotify.exe imeklmg.exe no specs imeklmg.exe no specs autumn.exe wmpnscfg.exe no specs wmpnscfg.exe no specs taskmgr.exe no specs cmd.exe no specs findstr.exe no specs cscript.exe file.exe msg.exe no specs control.exe no specs rundll32.exe no specs timedate.cpl no specs findstr.exe no specs cscript.exe no specs taskmgr.exe no specs cmd.exe no specs msg.exe no specs file.exe

Process information

PID
CMD
Path
Indicators
Parent process
796"C:\Windows\System32\control.exe" "C:\Windows\system32\timedate.cpl",C:\Windows\System32\control.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Control Panel
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\control.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1340FINDSTR /E "'VBS" "C:\Users\admin\Desktop\yin yang.bat" C:\Windows\System32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (QGREP) Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
1460C:\Windows\System32\ctfmon.exe C:\Windows\System32\ctfmon.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CTF Loader
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctfmonitor.dll
c:\windows\system32\msctf.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
1680C:\Windows\system32\sipnotify.exe -LogonOrUnlockC:\Windows\System32\sipnotify.exe
taskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
sipnotify
Exit code:
0
Version:
6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716)
Modules
Images
c:\windows\system32\sipnotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1740"C:\Windows\system32\rundll32.exe" Shell32.dll,Control_RunDLL "C:\Windows\system32\timedate.cpl",C:\Windows\System32\rundll32.execontrol.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\tzres.dll
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1844cscript //nologo "C:\Users\admin\AppData\Local\Temp\bbin.vbs"C:\Windows\System32\cscript.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft ® Console Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
1848"C:\Windows\system32\taskmgr.exe" /4C:\Windows\System32\taskmgr.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Task Manager
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskmgr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1952"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
2056"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
2076"C:\Users\admin\autumn.exe" C:\Users\admin\autumn.exe
explorer.exe
User:
admin
Company:
Microsoft
Integrity Level:
MEDIUM
Description:
YinYang
Version:
1.0.0.0
Modules
Images
c:\users\admin\autumn.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
5 106
Read events
5 060
Write events
33
Delete events
13

Modification events

(PID) Process:(3392) file.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:WinDoctor
Value:
C:\Users\admin\autumn.exe
(PID) Process:(796) control.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(796) control.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(796) control.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(796) control.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1460) ctfmon.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:internat.exe
Value:
(PID) Process:(1952) IMEKLMG.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\IMEJP\14.0
Operation:writeName:SetPreload
Value:
1
(PID) Process:(2056) IMEKLMG.EXEKey:HKEY_CURRENT_USER\Software\Microsoft\IMEKR\14.0
Operation:writeName:SetPreload
Value:
1
(PID) Process:(1680) sipnotify.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1680) sipnotify.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates
Operation:delete valueName:9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Value:
Executable files
2 816
Suspicious files
1
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
2968file.exeC:\$Recycle.Bin\S-1-5-21-1302019708-1500728564-335382590-1000\desktop.ini.exeexecutable
MD5:
SHA256:
2968file.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\AccessMUI.msi.exeexecutable
MD5:
SHA256:
2968file.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\AccessMUI.xml.exeexecutable
MD5:
SHA256:
2968file.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\AccLR.cab.exeexecutable
MD5:
SHA256:
2968file.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\branding.xml.exeexecutable
MD5:
SHA256:
2968file.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\Setup.xml.exeexecutable
MD5:
SHA256:
2968file.exeC:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\AccessMUI.msi.exeexecutable
MD5:
SHA256:
2968file.exeC:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\AccessMUI.xml.exeexecutable
MD5:
SHA256:
2968file.exeC:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\AccLR.cab.exeexecutable
MD5:
SHA256:
2968file.exeC:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\branding.xml.exeexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
9
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1680
sipnotify.exe
HEAD
200
88.221.61.151:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133564820178120000
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
unknown
4
System
192.168.100.255:137
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
1680
sipnotify.exe
88.221.61.151:80
query.prod.cms.rt.microsoft.com
AKAMAI-AS
DE
unknown
1132
svchost.exe
224.0.0.252:5355
unknown

DNS requests

Domain
IP
Reputation
query.prod.cms.rt.microsoft.com
  • 88.221.61.151
whitelisted

Threats

No threats detected
No debug info