analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

tela azul.bat

Full analysis: https://app.any.run/tasks/002c25f8-bd49-455a-9128-49d8f41954c3
Verdict: Malicious activity
Analysis date: December 05, 2022, 21:26:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/plain
File info: ASCII text, with CRLF line terminators
MD5:

4F62FE594A8D97775E80C8FCD251F28D

SHA1:

ED7DE7E18006579FF128C8AA3D05276211A8FA11

SHA256:

87AF7310A324F05CBAFB337B491454C513324F64723391D64D1CE521DC8E8108

SSDEEP:

3:nnWsTaXACoviAnWscWmIn:nWyaKvnW0/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Uses TASKKILL.EXE to terminate process

      • cmd.exe (PID: 3372)
      • cmd.exe (PID: 1580)
      • cmd.exe (PID: 2256)
      • cmd.exe (PID: 3392)
      • cmd.exe (PID: 3152)
      • cmd.exe (PID: 3436)
      • cmd.exe (PID: 2760)
  • INFO

    • Manual execution by a user

      • cmd.exe (PID: 3372)
      • cmd.exe (PID: 2256)
      • NOTEPAD.EXE (PID: 2296)
      • NOTEPAD.EXE (PID: 3724)
      • cmd.exe (PID: 3392)
      • cmd.exe (PID: 3152)
      • cmd.exe (PID: 3436)
      • cmd.exe (PID: 2760)
      • opera.exe (PID: 3352)
      • opera.exe (PID: 2328)
      • opera.exe (PID: 3376)
      • opera.exe (PID: 736)
      • opera.exe (PID: 3844)
      • opera.exe (PID: 3508)
      • opera.exe (PID: 1444)
      • firefox.exe (PID: 4044)
      • firefox.exe (PID: 3180)
      • opera.exe (PID: 2488)
      • firefox.exe (PID: 3248)
      • opera.exe (PID: 2460)
    • Application launched itself

      • firefox.exe (PID: 3248)
      • firefox.exe (PID: 4044)
      • firefox.exe (PID: 3180)
      • firefox.exe (PID: 2924)
      • firefox.exe (PID: 2792)
      • firefox.exe (PID: 4000)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
104
Monitored processes
50
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start cmd.exe no specs taskkill.exe no specs taskkill.exe no specs notepad.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe no specs taskkill.exe no specs taskkill.exe no specs cmd.exe taskkill.exe no specs taskkill.exe no specs notepad.exe no specs cmd.exe no specs taskkill.exe no specs cmd.exe taskkill.exe no specs cmd.exe taskkill.exe no specs opera.exe opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs opera.exe no specs firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs firefox.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1580C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\tela azul.bat" "C:\Windows\system32\cmd.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\cmd.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2480taskkill /f /im svchost.exeC:\Windows\system32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
588taskkill /f /im systemC:\Windows\system32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2296"C:\Windows\System32\NOTEPAD.EXE" C:\Users\admin\Desktop\New Text Document.batC:\Windows\System32\NOTEPAD.EXEExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3372C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\New Text Document.bat" "C:\Windows\system32\cmd.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3804taskkill svchost.exeC:\Windows\system32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2952taskkill systemC:\Windows\system32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\gdi32.dll
2256C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\New Text Document.bat" "C:\Windows\system32\cmd.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\cmd.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2660taskkill svchost.exeC:\Windows\system32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\gdi32.dll
1684taskkill systemC:\Windows\system32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
Total events
19 296
Read events
19 114
Write events
182
Delete events
0

Modification events

(PID) Process:(3352) opera.exeKey:HKEY_CURRENT_USER\Software\Opera Software
Operation:writeName:Last CommandLine v2
Value:
C:\Program Files\Opera\opera.exe
(PID) Process:(3352) opera.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\16D\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3248) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
A9368C7E0E000000
(PID) Process:(4000) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
96E18D7E0E000000
(PID) Process:(4044) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
ED0D9E7E0E000000
(PID) Process:(2792) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
3E6EA07E0E000000
(PID) Process:(3180) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Launcher
Value:
E350B87E0E000000
(PID) Process:(2924) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Browser
Value:
20F8B97E0E000000
(PID) Process:(4000) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\Launcher
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe|Telemetry
Value:
0
(PID) Process:(4000) firefox.exeKey:HKEY_CURRENT_USER\Software\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
Executable files
0
Suspicious files
172
Text files
285
Unknown types
52

Dropped files

PID
Process
Filename
Type
2296NOTEPAD.EXEC:\Users\admin\Desktop\New Text Document.txttext
MD5:804EEA9917D99A77038E796139BCF009
SHA256:B79994368B4367AB18C14DE2C848D6AD5AE0048B7941B84A055DAD34F73FD52C
3352opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\operaprefs.initext
MD5:A085B872B8A36D007530C6E515680AA1
SHA256:A72D5ADDF56AB9B36C12865D7A759B02250E025F90626C8327DEC33CA5469BE3
3352opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\opr3659.tmptext
MD5:A085B872B8A36D007530C6E515680AA1
SHA256:A72D5ADDF56AB9B36C12865D7A759B02250E025F90626C8327DEC33CA5469BE3
3352opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\opssl6.datbinary
MD5:89A0E0E38999A1C615A64056E7AC34B8
SHA256:790D5340BABE18030E433D241B5D169E231F2B9A4BB56A5812E04BC735BD46B3
3352opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\tasks.xmlxml
MD5:4482829514E248F5B4F5A922338C7B75
SHA256:9C979EA1EE0F862B6C3B4611EF6C81756A5E635F98D65AC2E1898D059A1DAC40
3352opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\opr36A8.tmpxml
MD5:4482829514E248F5B4F5A922338C7B75
SHA256:9C979EA1EE0F862B6C3B4611EF6C81756A5E635F98D65AC2E1898D059A1DAC40
3352opera.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\16ec093b8f51508f.customDestinations-ms~RF1094165.TMPbinary
MD5:DBC8C3C79F0DFF4745A5E25E13611AEF
SHA256:70C54F2C53CF246603B8DE4755D95C5AA51BF4B232340BEA5879724A1F84F675
3352opera.exeC:\Users\admin\AppData\Roaming\Opera\Opera\opuntrust.datbinary
MD5:1AA8644C9261DC10F7247F6A145C1DD2
SHA256:58A8933F65361633C6AB194000D312DC9D566F717B1A16814A0DBEE24A60EBE3
3352opera.exeC:\Users\admin\AppData\Local\Opera\Opera\cache\sesn\opr00003.tmphtml
MD5:7F077F1FCE3D566040B0D69EB1F27D8F
SHA256:487AD0D2CF075F4328A1ADF57EF428759AD4E2C873A8EBD2AD9653990829C9CF
4000firefox.exeC:\Users\admin\AppData\Local\Mozilla\Firefox\Profiles\qldyz51w.default\startupCache\scriptCache-current.bin
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
40
TCP/UDP connections
127
DNS requests
80
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3352
opera.exe
GET
301
23.35.238.110:80
http://www.amazon.co.uk/exec/obidos/redirect-home/opspeeddial-norway-21
US
whitelisted
3352
opera.exe
GET
23.35.238.110:80
http://www.amazon.co.uk/exec/obidos/redirect-home/opspeeddial-norway-21
US
whitelisted
3352
opera.exe
GET
301
23.35.238.110:80
http://www.amazon.co.uk/exec/obidos/redirect-home/opspeeddial-norway-21
US
whitelisted
3352
opera.exe
GET
301
23.35.238.110:80
http://www.amazon.co.uk/exec/obidos/redirect-home/opspeeddial-norway-21
US
whitelisted
4000
firefox.exe
POST
200
93.184.220.29:80
http://ocsp.digicert.com/
US
der
471 b
whitelisted
3352
opera.exe
GET
200
93.184.220.29:80
http://s.symcb.com/pca3-g5.crl
US
der
834 b
whitelisted
3352
opera.exe
GET
400
185.26.182.94:80
http://sitecheck2.opera.com/?host=redir.opera.com&hdn=H0WKpMbVXsif0I8OJoRVZA==
unknown
html
150 b
whitelisted
3352
opera.exe
GET
302
185.26.182.109:80
http://redir.opera.com/speeddials/amazon/
unknown
html
329 b
whitelisted
3352
opera.exe
GET
400
185.26.182.94:80
http://sitecheck2.opera.com/?host=www.amazon.co.uk&hdn=GnMPVW003l2SdK9PNfwsSg==
unknown
html
150 b
whitelisted
3352
opera.exe
GET
200
93.184.220.29:80
http://crl3.digicert.com/DigiCertHighAssuranceEVRootCA.crl
US
der
740 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3352
opera.exe
185.26.182.94:443
certs.opera.com
Opera Software AS
whitelisted
3352
opera.exe
93.184.220.29:80
crl3.digicert.com
EDGECAST
GB
whitelisted
3352
opera.exe
185.26.182.109:80
redir.opera.com
Opera Software AS
unknown
3352
opera.exe
143.204.209.194:443
m.media-amazon.com
AMAZON-02
US
unknown
3352
opera.exe
23.35.238.110:80
www.amazon.co.uk
AKAMAI-AS
DE
unknown
3352
opera.exe
23.35.238.110:443
www.amazon.co.uk
AKAMAI-AS
DE
unknown
4000
firefox.exe
34.107.221.82:80
detectportal.firefox.com
GOOGLE
US
whitelisted
3352
opera.exe
185.26.182.94:80
certs.opera.com
Opera Software AS
whitelisted
4000
firefox.exe
93.184.220.29:80
crl3.digicert.com
EDGECAST
GB
whitelisted
4000
firefox.exe
35.161.188.203:443
location.services.mozilla.com
AMAZON-02
US
unknown

DNS requests

Domain
IP
Reputation
certs.opera.com
  • 185.26.182.94
  • 185.26.182.93
whitelisted
crl3.digicert.com
  • 93.184.220.29
whitelisted
redir.opera.com
  • 185.26.182.109
  • 185.26.182.110
whitelisted
sitecheck2.opera.com
  • 185.26.182.94
  • 185.26.182.93
  • 185.26.182.118
  • 185.26.182.112
  • 185.26.182.106
  • 185.26.182.111
whitelisted
www.amazon.co.uk
  • 23.35.238.110
whitelisted
crl4.digicert.com
  • 93.184.220.29
whitelisted
s.symcb.com
  • 93.184.220.29
whitelisted
m.media-amazon.com
  • 143.204.209.194
whitelisted
detectportal.firefox.com
  • 34.107.221.82
whitelisted
prod.detectportal.prod.cloudops.mozgcp.net
  • 34.107.221.82
  • 2600:1901:0:38d7::
whitelisted

Threats

PID
Process
Class
Message
4000
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
4000
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
2792
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
2792
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
2924
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
2924
firefox.exe
Potentially Bad Traffic
ET INFO Terse Request for .txt - Likely Hostile
No debug info