| File name: | Defender.exe |
| Full analysis: | https://app.any.run/tasks/2365d8a3-dc23-4da1-982c-643587fa31b7 |
| Verdict: | Malicious activity |
| Analysis date: | August 18, 2024, 00:34:13 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | B3353FE84B5E8DE4E5E2E0E64B7CF625 |
| SHA1: | A8BB2D5917E61C566308CB68D80066A5E23450B9 |
| SHA256: | 888C74512D59E6F5890BFF6424E73D72245A3DF2BB6D2BD3A8B31D55E541D1AE |
| SSDEEP: | 49152:lh1JIGYsUlmFFkN1CrsrUXoaqUHtmmtNybxdKEd0tima5oUtJnfSf8wQpU5NjI1e:lh1JIGYvl4FkN1RA4a/HtmmXybxdL5PU |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2012:02:24 19:20:04+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 10 |
| CodeSize: | 29696 |
| InitializedDataSize: | 491008 |
| UninitializedDataSize: | 16896 |
| EntryPoint: | 0x38af |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.5.0.726 |
| ProductVersionNumber: | 1.5.0.726 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | SHADOWDEFENDER.COM |
| FileDescription: | Shadow Defender Application |
| FileVersion: | 1.5.0.726 |
| InternalName: | Defender.exe |
| LegalCopyright: | Copyright (C) 2007-2020, SHADOWDEFENDER.COM. All rights reserved. |
| OriginalFileName: | Defender.exe |
| ProductName: | Shadow Defender |
| ProductVersion: | 1.5.0.726 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 6348 | "C:\Users\admin\AppData\Local\Temp\Defender.exe" | C:\Users\admin\AppData\Local\Temp\Defender.exe | — | explorer.exe | |||||||||||
User: admin Company: SHADOWDEFENDER.COM Integrity Level: MEDIUM Description: Shadow Defender Application Exit code: 0 Version: 1.5.0.726 Modules
| |||||||||||||||
| 6408 | "C:\Windows\System32\cmd.exe" /k move Centered Centered.cmd & Centered.cmd & exit | C:\Windows\SysWOW64\cmd.exe | Defender.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 9009 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6416 | \??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1 | C:\Windows\System32\conhost.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Console Window Host Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6476 | tasklist | C:\Windows\SysWOW64\tasklist.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Lists the current running tasks Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6488 | findstr /I "wrsa.exe opssvc.exe" | C:\Windows\SysWOW64\findstr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Find String (QGREP) Utility Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6704 | tasklist | C:\Windows\SysWOW64\tasklist.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Lists the current running tasks Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6712 | findstr /I "avastui.exe avgui.exe bdservicehost.exe ekrn.exe nswscsvc.exe sophoshealth.exe" | C:\Windows\SysWOW64\findstr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Find String (QGREP) Utility Exit code: 1 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6772 | cmd /c md 552459 | C:\Windows\SysWOW64\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6792 | findstr /V "EDINBURGHCOMPARISONSCHRISTOPHERSURPRISE" Congo | C:\Windows\SysWOW64\findstr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Find String (QGREP) Utility Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6816 | cmd /c copy /b ..\Providence + ..\Counties + ..\Committees + ..\Median + ..\Ion + ..\Signing + ..\Unusual + ..\Treat a | C:\Windows\SysWOW64\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 10.0.19041.3636 (WinBuild.160101.0800) Modules
| |||||||||||||||
| (PID) Process: | (6348) Defender.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (6348) Defender.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (6348) Defender.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (6348) Defender.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (6948) Dive.pif | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (6948) Dive.pif | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (6948) Dive.pif | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (6948) Dive.pif | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (6948) Dive.pif | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (6948) Dive.pif | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6348 | Defender.exe | C:\Users\admin\AppData\Local\Temp\Congo | binary | |
MD5:F1B31EF4ABA242A3B771A17E26BF2292 | SHA256:46E15D27891C23CDE64C1A08623635CC61CE8328A9E9FBA64E49D29E854107C6 | |||
| 6348 | Defender.exe | C:\Users\admin\AppData\Local\Temp\Treat | binary | |
MD5:904914D5928274D6B53428D32D477F39 | SHA256:7C31266EB14AAF65A6E0C86975FB8A2E4D376F003A5EA61EA6D7F42249E5FCAC | |||
| 6348 | Defender.exe | C:\Users\admin\AppData\Local\Temp\Median | binary | |
MD5:78F3EC02BBBE0184B9940BB638B76F37 | SHA256:51360C1A04A0EB2DFA42AB93601B397B1EFD64C2C4F41ECDF13DF5ACD58287AC | |||
| 6348 | Defender.exe | C:\Users\admin\AppData\Local\Temp\Seeking | binary | |
MD5:A9FC4F9A828FEF13E1FC07DEF62624E0 | SHA256:EBACB5BDFEC14F1405EB85636621F7B423C0E395E5EE01DDD28F7F99A5B232C8 | |||
| 6348 | Defender.exe | C:\Users\admin\AppData\Local\Temp\Ion | binary | |
MD5:7607F305E8DCA1834EFA39D70491CCFA | SHA256:091AEEA7B5BF473766F771DB79C592E6A048E9A3A1D88877B33319488AB737C9 | |||
| 6348 | Defender.exe | C:\Users\admin\AppData\Local\Temp\Counties | binary | |
MD5:95308E91E8D25858622C241E878CBB1D | SHA256:55DDE2DA0A191F0A49C8DC0E379A824BE154DA7D2F07FD2B7135E4129411850A | |||
| 6348 | Defender.exe | C:\Users\admin\AppData\Local\Temp\Providence | binary | |
MD5:B2D67B8312D5E5C0BCAB6BFF228194C7 | SHA256:A8BAF58C072872FFB3395A2E2EC44DB115AD6F41CBB5A5C873C0E4498505F727 | |||
| 6816 | cmd.exe | C:\Users\admin\AppData\Local\Temp\552459\a | binary | |
MD5:5A79A92BF5AC70C8288CFBC454470242 | SHA256:0B171DEBFBEDC7B14451F18C1B35A850A03635296AC7CDCAB338013FD387CE57 | |||
| 6348 | Defender.exe | C:\Users\admin\AppData\Local\Temp\Committees | binary | |
MD5:6F9A0F23A5B4F13FAF934BD5430A7289 | SHA256:48347E33CD3F50E1B40B938E50F31E79191A72B4A00C2D56840C073002955C24 | |||
| 6408 | cmd.exe | C:\Users\admin\AppData\Local\Temp\Centered.cmd | text | |
MD5:A561C17D4FB241DD4EA914FEF1A47BDB | SHA256:2BC6E4395C9F0925357D316A50A802496420C4AD0285B6AA6B8BEEE7688E1062 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6948 | Dive.pif | GET | 200 | 88.221.221.194:80 | http://r10.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRpD%2BQVZ%2B1vf7U0RGQGBm8JZwdxcgQUdKR2KRcYVIUxN75n5gZYwLzFBXICEgOVU8rM4D7NcaYYp12nRNaAnw%3D%3D | unknown | — | — | whitelisted |
2968 | svchost.exe | GET | 304 | 104.108.145.136:80 | http://x1.c.lencr.org/ | unknown | — | — | whitelisted |
6328 | SIHClient.exe | GET | 200 | 23.58.217.29:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4088 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
— | — | 192.168.100.255:138 | — | — | — | whitelisted |
4088 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
6948 | Dive.pif | 193.43.104.208:443 | dotnetisnotforchildren.com | — | — | unknown |
6948 | Dive.pif | 88.221.221.194:80 | r10.o.lencr.org | Akamai International B.V. | DE | unknown |
2968 | svchost.exe | 104.108.145.136:80 | x1.c.lencr.org | AKAMAI-AS | DE | unknown |
6328 | SIHClient.exe | 40.68.123.157:443 | slscr.update.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
6328 | SIHClient.exe | 23.58.217.29:80 | www.microsoft.com | AKAMAI-AS | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
GWnedjqdKILRPXOoh.GWnedjqdKILRPXOoh |
| unknown |
dotnetisnotforchildren.com |
| unknown |
r10.o.lencr.org |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |