URL:

http://files.myplaycity.com/files_downloader_temp/apothecariumworld_setup.exe

Full analysis: https://app.any.run/tasks/b888a309-705f-4509-ac37-4bc56ac4466d
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: June 14, 2019, 13:24:25
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MD5:

4BD1AC47E3C30BE1BE6318C33354EB78

SHA1:

4AD3D8C4B4FFC46EA69078A6CB5B1FDD738A95B7

SHA256:

87B5BC7FFED738318887BE85BF224E7F04F893CC1CD718E6E9CA6482890098A9

SSDEEP:

3:N1KYyKM6LKKQx4sX6mUUOXRvNu4A:CYyKM6LmUJC4A

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Downloads executable files from the Internet

      • iexplore.exe (PID: 3504)
    • Application was dropped or rewritten from another process

      • Apothecarium World.exe (PID: 3864)
      • PreLoader.exe (PID: 3616)
      • game.exe (PID: 2280)
      • engine.exe (PID: 3324)
    • Loads dropped or rewritten executable

      • engine.exe (PID: 3324)
      • WerFault.exe (PID: 2600)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • apothecariumworld_setup[1].tmp (PID: 2440)
      • apothecariumworld_setup[1].exe (PID: 3500)
      • apothecariumworld_setup[1].exe (PID: 4032)
    • Starts Internet Explorer

      • apothecariumworld_setup[1].tmp (PID: 2440)
    • Creates files in the user directory

      • apothecariumworld_setup[1].tmp (PID: 2440)
      • PreLoader.exe (PID: 3616)
    • Changes IE settings (feature browser emulation)

      • PreLoader.exe (PID: 3616)
    • Reads internet explorer settings

      • PreLoader.exe (PID: 3616)
    • Creates files in the program directory

      • WerFault.exe (PID: 2600)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 2980)
      • iexplore.exe (PID: 3372)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 3504)
      • iexplore.exe (PID: 2980)
    • Creates files in the user directory

      • iexplore.exe (PID: 3504)
    • Application was dropped or rewritten from another process

      • apothecariumworld_setup[1].tmp (PID: 2440)
      • apothecariumworld_setup[1].tmp (PID: 1980)
    • Changes internet zones settings

      • iexplore.exe (PID: 3372)
      • iexplore.exe (PID: 2980)
    • Loads dropped or rewritten executable

      • apothecariumworld_setup[1].tmp (PID: 2440)
    • Creates a software uninstall entry

      • apothecariumworld_setup[1].tmp (PID: 2440)
    • Adds / modifies Windows certificates

      • iexplore.exe (PID: 3560)
    • Changes settings of System certificates

      • iexplore.exe (PID: 3560)
    • Reads internet explorer settings

      • iexplore.exe (PID: 3560)
    • Application was crashed

      • engine.exe (PID: 3324)
    • Creates files in the program directory

      • apothecariumworld_setup[1].tmp (PID: 2440)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
53
Monitored processes
14
Malicious processes
4
Suspicious processes
2

Behavior graph

Click at the process to see the details
start drop and start drop and start drop and start iexplore.exe iexplore.exe apothecariumworld_setup[1].exe apothecariumworld_setup[1].tmp no specs apothecariumworld_setup[1].exe apothecariumworld_setup[1].tmp iexplore.exe iexplore.exe apothecarium world.exe no specs preloader.exe game.exe no specs engine.exe werfault.exe no specs iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
1980"C:\Users\admin\AppData\Local\Temp\is-BR8FJ.tmp\apothecariumworld_setup[1].tmp" /SL5="$401D6,87829034,54272,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\apothecariumworld_setup[1].exe" C:\Users\admin\AppData\Local\Temp\is-BR8FJ.tmp\apothecariumworld_setup[1].tmpapothecariumworld_setup[1].exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.50.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-br8fj.tmp\apothecariumworld_setup[1].tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2280"C:\Program Files\MyPlayCity.com\Apothecarium World\game.exe" C:\Program Files\MyPlayCity.com\Apothecarium World\game.exePreLoader.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\myplaycity.com\apothecarium world\game.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\lpk.dll
2440"C:\Users\admin\AppData\Local\Temp\is-6AMED.tmp\apothecariumworld_setup[1].tmp" /SL5="$6016C,87829034,54272,C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\apothecariumworld_setup[1].exe" /SPAWNWND=$50168 /NOTIFYWND=$401D6 C:\Users\admin\AppData\Local\Temp\is-6AMED.tmp\apothecariumworld_setup[1].tmp
apothecariumworld_setup[1].exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.50.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-6amed.tmp\apothecariumworld_setup[1].tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ole32.dll
2600C:\Windows\system32\WerFault.exe -u -p 3324 -s 220C:\Windows\system32\WerFault.exesvchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Problem Reporting
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\werfault.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2980"C:\Program Files\Internet Explorer\iexplore.exe" http://files.myplaycity.com/files_downloader_temp/apothecariumworld_setup.exeC:\Program Files\Internet Explorer\iexplore.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Exit code:
1
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3240"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:3372 CREDAT:14339C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3324"C:\Program Files\MyPlayCity.com\Apothecarium World\\engine.exe" C:\Program Files\MyPlayCity.com\Apothecarium World\engine.exe
game.exe
User:
admin
Company:
SMI games
Integrity Level:
HIGH
Description:
Search for the Wonderland
Exit code:
3221225477
Version:
1, 0, 0, 1
Modules
Images
c:\program files\myplaycity.com\apothecarium world\engine.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\myplaycity.com\apothecarium world\libcocos2d.dll
c:\program files\myplaycity.com\apothecarium world\sqlite3.dll
c:\windows\system32\msvcr100.dll
c:\program files\myplaycity.com\apothecarium world\libcurl.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
3372"C:\Program Files\Internet Explorer\iexplore.exe" -nohomeC:\Program Files\Internet Explorer\iexplore.exe
apothecariumworld_setup[1].tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3500"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\apothecariumworld_setup[1].exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\apothecariumworld_setup[1].exe
iexplore.exe
User:
admin
Company:
MyPlayCity, Inc.
Integrity Level:
MEDIUM
Description:
Apothecarium World Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\i0488cjo\apothecariumworld_setup[1].exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3504"C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2980 CREDAT:71937C:\Program Files\Internet Explorer\iexplore.exe
iexplore.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Internet Explorer
Exit code:
0
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\internet explorer\iexplore.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
2 085
Read events
1 876
Write events
206
Delete events
3

Modification events

(PID) Process:(2980) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2980) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2980) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2980) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(2980) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2980) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000006E000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2980) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{C2D27B8F-8EA7-11E9-B3B3-5254004A04AF}
Value:
0
(PID) Process:(2980) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(2980) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
1
(PID) Process:(2980) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Time
Value:
E307060005000E000D00180028005601
Executable files
24
Suspicious files
3
Text files
530
Unknown types
35

Dropped files

PID
Process
Filename
Type
2980iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF12C8A57B76023116.TMP
MD5:
SHA256:
2980iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\H6QNMHE9\favicon[1].ico
MD5:
SHA256:
2980iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
3504iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\67ULQ8TS\apothecariumworld_setup[1].exe
MD5:
SHA256:
2980iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\I0488CJO\apothecariumworld_setup[1].exe
MD5:
SHA256:
3504iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:
SHA256:
2980iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\{C2D27B90-8EA7-11E9-B3B3-5254004A04AF}.datbinary
MD5:
SHA256:
3504iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012019061420190615\index.datdat
MD5:
SHA256:
2980iexplore.exeC:\Users\admin\AppData\Local\Temp\~DF3F75A4A10A17E52E.TMP
MD5:
SHA256:
2980iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{C2D27B8F-8EA7-11E9-B3B3-5254004A04AF}.dat
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
14
DNS requests
11
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3616
PreLoader.exe
GET
200
169.63.74.123:80
http://t.myplaycity.com/ingame5/pgame.ini
US
text
190 b
suspicious
3616
PreLoader.exe
GET
200
169.63.74.123:80
http://t.myplaycity.com/ingame5/bg_320x275.jpg
US
image
62.6 Kb
suspicious
3616
PreLoader.exe
GET
200
169.63.74.123:80
http://t.myplaycity.com/ingame5/pads.html?utm_source=ad2games001&utm_medium=ingame01
US
html
2.37 Kb
suspicious
3616
PreLoader.exe
GET
200
169.63.74.123:80
http://t.myplaycity.com/ingame5/loader.gif
US
image
23.2 Kb
suspicious
3616
PreLoader.exe
GET
200
169.63.74.123:80
http://mpcstatic.com/i/banners/mmo/Dreamfields_300x250_en.jpg
US
image
62.1 Kb
whitelisted
3616
PreLoader.exe
GET
200
216.58.207.78:80
http://www.google-analytics.com/r/__utm.gif?utmwv=5.7.2&utms=1&utmn=695548449&utmhn=t.myplaycity.com&utmcs=windows-1251&utmsr=1280x720&utmsc=32-bit&utmul=en-us&utmje=1&utmfl=26.0%20r0&utmdt=MyPlayCity&utmhid=267759861&utmr=-&utmp=%2Fingame5%2Fpads.html%3Futm_source%3Dad2games001%26utm_medium%3Dingame01&utmht=1560518842904&utmac=UA-1217017-15&utmcc=__utma%3D46045153.1632569328.1560518843.1560518843.1560518843.1%3B%2B__utmz%3D46045153.1560518843.1.1.utmcsr%3Dad2games001%7Cutmccn%3D(not%2520set)%7Cutmcmd%3Dingame01%3B&utmjid=817224398&utmredir=1&utmu=DAAAAAAAAAAAAAAAAAAAAAAE~
US
image
35 b
whitelisted
3372
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
3616
PreLoader.exe
GET
200
169.63.74.123:80
http://mpcstatic.com/i/mmo_banners.js
US
text
3.76 Kb
whitelisted
3504
iexplore.exe
GET
200
37.48.104.179:80
http://files.myplaycity.com/files_downloader_temp/apothecariumworld_setup.exe
NL
executable
84.0 Mb
suspicious
2980
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3504
iexplore.exe
37.48.104.179:80
files.myplaycity.com
LeaseWeb Netherlands B.V.
NL
suspicious
2980
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3372
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
3560
iexplore.exe
169.63.74.123:443
www.myplaycity.com
SoftLayer Technologies Inc.
US
unknown
3616
PreLoader.exe
169.63.74.123:80
www.myplaycity.com
SoftLayer Technologies Inc.
US
unknown
3616
PreLoader.exe
216.58.207.78:80
www.google-analytics.com
Google Inc.
US
whitelisted
3240
iexplore.exe
169.63.74.123:443
www.myplaycity.com
SoftLayer Technologies Inc.
US
unknown

DNS requests

Domain
IP
Reputation
files.myplaycity.com
  • 37.48.104.179
  • 95.211.90.145
suspicious
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
www.myplaycity.com
  • 169.63.74.123
suspicious
www.googleadservices.com
  • 172.217.21.194
whitelisted
t.myplaycity.com
  • 169.63.74.123
suspicious
mpcstatic.com
  • 169.63.74.123
unknown
www.google-analytics.com
  • 216.58.207.78
whitelisted

Threats

PID
Process
Class
Message
3504
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
No debug info