File name:

tela azul.bat

Full analysis: https://app.any.run/tasks/002c25f8-bd49-455a-9128-49d8f41954c3
Verdict: Malicious activity
Analysis date: December 05, 2022, 21:26:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/plain
File info: ASCII text, with CRLF line terminators
MD5:

4F62FE594A8D97775E80C8FCD251F28D

SHA1:

ED7DE7E18006579FF128C8AA3D05276211A8FA11

SHA256:

87AF7310A324F05CBAFB337B491454C513324F64723391D64D1CE521DC8E8108

SSDEEP:

3:nnWsTaXACoviAnWscWmIn:nWyaKvnW0/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Uses TASKKILL.EXE to terminate process

      • cmd.exe (PID: 1580)
      • cmd.exe (PID: 2256)
      • cmd.exe (PID: 3372)
      • cmd.exe (PID: 3392)
      • cmd.exe (PID: 3152)
      • cmd.exe (PID: 3436)
      • cmd.exe (PID: 2760)
  • INFO

    • Manual execution by a user

      • NOTEPAD.EXE (PID: 2296)
      • cmd.exe (PID: 2256)
      • cmd.exe (PID: 3392)
      • cmd.exe (PID: 3372)
      • NOTEPAD.EXE (PID: 3724)
      • cmd.exe (PID: 3152)
      • cmd.exe (PID: 3436)
      • cmd.exe (PID: 2760)
      • opera.exe (PID: 3352)
      • opera.exe (PID: 3376)
      • opera.exe (PID: 3844)
      • opera.exe (PID: 3508)
      • opera.exe (PID: 736)
      • opera.exe (PID: 2328)
      • opera.exe (PID: 2488)
      • opera.exe (PID: 2460)
      • opera.exe (PID: 1444)
      • firefox.exe (PID: 4044)
      • firefox.exe (PID: 3248)
      • firefox.exe (PID: 3180)
    • Application launched itself

      • firefox.exe (PID: 4044)
      • firefox.exe (PID: 4000)
      • firefox.exe (PID: 3248)
      • firefox.exe (PID: 2792)
      • firefox.exe (PID: 3180)
      • firefox.exe (PID: 2924)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
104
Monitored processes
50
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start cmd.exe no specs taskkill.exe no specs taskkill.exe no specs notepad.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe taskkill.exe no specs taskkill.exe no specs notepad.exe no specs cmd.exe no specs taskkill.exe no specs cmd.exe taskkill.exe no specs cmd.exe taskkill.exe no specs opera.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
588taskkill /f /im systemC:\Windows\system32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
736"C:\Program Files\Opera\opera.exe" C:\Program Files\Opera\opera.exeExplorer.EXE
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Internet Browser
Exit code:
0
Version:
1748
Modules
Images
c:\program files\opera\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\psapi.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\user32.dll
912"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2924.0.1944441618\1886435504" -parentBuildID 20201112153044 -prefsHandle 1124 -prefMapHandle 1116 -prefsLen 1 -prefMapSize 239273 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2924 "\\.\pipe\gecko-crash-server-pipe.2924" 1196 gpuC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
1
Version:
83.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\rpcrt4.dll
1444"C:\Program Files\Opera\opera.exe" C:\Program Files\Opera\opera.exeExplorer.EXE
User:
admin
Company:
Opera Software
Integrity Level:
MEDIUM
Description:
Opera Internet Browser
Exit code:
0
Version:
1748
Modules
Images
c:\program files\opera\opera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\psapi.dll
c:\windows\system32\wintrust.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msasn1.dll
c:\windows\system32\rpcrt4.dll
1580C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\tela azul.bat" "C:\Windows\system32\cmd.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\cmd.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1668taskkill f im svchost.exeC:\Windows\system32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\gdi32.dll
1684taskkill systemC:\Windows\system32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
1952"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2924.21.63168902\1765810093" -childID 4 -isForBrowser -prefsHandle 3588 -prefMapHandle 3572 -prefsLen 7381 -prefMapSize 239273 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2924 "\\.\pipe\gecko-crash-server-pipe.2924" 3684 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\crypt32.dll
1996"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2924.13.776119601\1547511580" -childID 2 -isForBrowser -prefsHandle 3032 -prefMapHandle 3028 -prefsLen 6647 -prefMapSize 239273 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2924 "\\.\pipe\gecko-crash-server-pipe.2924" 3044 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
2040"C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel="2924.20.1711889019\1628222552" -childID 3 -isForBrowser -prefsHandle 3548 -prefMapHandle 1728 -prefsLen 7381 -prefMapSize 239273 -parentBuildID 20201112153044 -appdir "C:\Program Files\Mozilla Firefox\browser" - 2924 "\\.\pipe\gecko-crash-server-pipe.2924" 3564 tabC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
LOW
Description:
Firefox
Exit code:
0
Version:
83.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
Total events
19 296
Read events
19 114
Write events
182
Delete events
0

Modification events

(PID) Process:(3352) opera.exeKey:HKEY_CURRENT_USER\Software\Opera Software
Operation:writeName:Last CommandLine v2
Value:
C:\Program Files\Opera\opera.exe
(PID) Process:(3352) opera.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3248) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
A9368C7E0E000000
(PID) Process:(4000) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
96E18D7E0E000000
(PID) Process:(4044) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
ED0D9E7E0E000000
(PID) Process:(2792) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
3E6EA07E0E000000
(PID) Process:(3180) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
E350B87E0E000000
(PID) Process:(2924) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
20F8B97E0E000000
(PID) Process:(4000) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
(PID) Process:(4000) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
Executable files
0
Suspicious files
172
Text files
285
Unknown types
52

Dropped files

PID
Process
Filename
Type
3352opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.initext
MD5:
SHA256:
2296NOTEPAD.EXEC:\Users\admin\Desktop\New Text Document.txttext
MD5:
SHA256:
3352opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xmlxml
MD5:
SHA256:
3352opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\opr36A8.tmpxml
MD5:
SHA256:
3352opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\opr3659.tmptext
MD5:
SHA256:
3352opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.datbinary
MD5:
SHA256:
3352opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.datbinary
MD5:1AA8644C9261DC10F7247F6A145C1DD2
SHA256:58A8933F65361633C6AB194000D312DC9D566F717B1A16814A0DBEE24A60EBE3
3352opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\opicacrt6.datbinary
MD5:82F1A2B1176A5ECC457D32301E2AD833
SHA256:A783052804DD4C232BE2ED3DC00C430CB67A20370890E235562ED2B27B5A602E
4000firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin
MD5:
SHA256:
3352opera.exeC:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00003.tmphtml
MD5:7F077F1FCE3D566040B0D69EB1F27D8F
SHA256:487AD0D2CF075F4328A1ADF57EF428759AD4E2C873A8EBD2AD9653990829C9CF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
40
TCP/UDP connections
127
DNS requests
80
Threats
6

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3352
opera.exe
GET
301
23.35.238.110:80
http://www.amazon.co.uk/exec/obidos/redirect-home/opspeeddial-norway-21
US
whitelisted
3352
opera.exe
GET
23.35.238.110:80
http://www.amazon.co.uk/exec/obidos/redirect-home/opspeeddial-norway-21
US
whitelisted
3352
opera.exe
GET
301
23.35.238.110:80
http://www.amazon.co.uk/exec/obidos/redirect-home/opspeeddial-norway-21
US
whitelisted
3352
opera.exe
GET
301
23.35.238.110:80
http://www.amazon.co.uk/exec/obidos/redirect-home/opspeeddial-norway-21
US
whitelisted
3352
opera.exe
GET
200
93.184.220.29:80
http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl
US
der
740 b
whitelisted
3352
opera.exe
GET
200
93.184.220.29:80
http://s.symcb.com/pca3-g5.crl
US
der
834 b
whitelisted
3352
opera.exe
GET
200
93.184.220.29:80
http://crl4.digicert.com/DigiCertGlobalRootG2.crl
US
der
926 b
whitelisted
4000
firefox.exe
POST
200
172.217.18.99:80
http://ocsp.pki.goog/gts1c3
US
der
472 b
whitelisted
4000
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
4000
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3352
opera.exe
143.204.209.194:443
m.media-amazon.com
AMAZON-02
US
unknown
4000
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
4000
firefox.exe
34.102.187.140:443
firefox.settings.services.mozilla.com
GOOGLE-CLOUD-PLATFORM
US
suspicious
3352
opera.exe
185.26.182.94:443
certs.opera.com
Opera Software AS
whitelisted
3352
opera.exe
93.184.220.29:80
crl3.digicert.com
EDGECAST
GB
whitelisted
3352
opera.exe
185.26.182.94:80
certs.opera.com
Opera Software AS
whitelisted
3352
opera.exe
185.26.182.109:80
redir.opera.com
Opera Software AS
unknown
3352
opera.exe
23.35.238.110:443
www.amazon.co.uk
AKAMAI-AS
DE
unknown
3352
opera.exe
23.35.238.110:80
www.amazon.co.uk
AKAMAI-AS
DE
unknown
4000
firefox.exe
172.217.18.99:80
ocsp.pki.goog
GOOGLE
US
whitelisted

DNS requests

Domain
IP
Reputation
certs.opera.com
  • 185.26.182.94
  • 185.26.182.93
whitelisted
crl3.digicert.com
  • 93.184.220.29
whitelisted
redir.opera.com
  • 185.26.182.109
  • 185.26.182.110
whitelisted
sitecheck2.opera.com
  • 185.26.182.94
  • 185.26.182.93
  • 185.26.182.118
  • 185.26.182.112
  • 185.26.182.106
  • 185.26.182.111
whitelisted
www.amazon.co.uk
  • 23.35.238.110
whitelisted
crl4.digicert.com
  • 93.184.220.29
whitelisted
s.symcb.com
  • 93.184.220.29
whitelisted
m.media-amazon.com
  • 143.204.209.194
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted

Threats

PID
Process
Class
Message
4000
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
4000
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
2792
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
2792
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
2924
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
2924
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
No debug info