File name:

ServicesRepair.exe

Full analysis: https://app.any.run/tasks/a809229e-e825-422e-98f3-02cc481abcc3
Verdict: Malicious activity
Analysis date: September 27, 2024, 00:39:45
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

FFF0BD7669C420AF07BF6E6C1DF7CA3D

SHA1:

0342FE4E93ECA8929CCA6ECE39FC708233723FD6

SHA256:

8CABC5DFDA708D6C6FB7E3EAEE83C050DD913DA623012CFE2D50C3709F7038C5

SSDEEP:

98304:eZJ3XNrYQ9Om9OLkYrD79ZWL98WvQnC9qi1PfvLKMMjWnOhJgsPfhltJQ/trv9It:ilakXnI0k

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • ServicesRepair.exe (PID: 6692)
    • Application launched itself

      • ServicesRepair.exe (PID: 6692)
      • cmd.exe (PID: 6676)
    • Executable content was dropped or overwritten

      • ServicesRepair.exe (PID: 6800)
      • ServicesRepair_x64.exe (PID: 6892)
    • Likely accesses (executes) a file from the Public directory

      • ServicesRepair_x64.exe (PID: 6892)
      • cmd.exe (PID: 6676)
    • Starts CMD.EXE for commands execution

      • ServicesRepair_x64.exe (PID: 6892)
      • cmd.exe (PID: 6676)
    • Using 'findstr.exe' to search for text patterns in files and output

      • cmd.exe (PID: 6676)
    • The process executes via Task Scheduler

      • PLUGScheduler.exe (PID: 2836)
    • Executing commands from a ".bat" file

      • ServicesRepair_x64.exe (PID: 6892)
  • INFO

    • Reads mouse settings

      • ServicesRepair.exe (PID: 6692)
      • ServicesRepair.exe (PID: 6800)
      • ServicesRepair_x64.exe (PID: 6892)
    • Checks supported languages

      • ServicesRepair.exe (PID: 6692)
      • ServicesRepair.exe (PID: 6800)
      • ServicesRepair_x64.exe (PID: 6892)
    • The process uses the downloaded file

      • ServicesRepair.exe (PID: 6692)
    • Process checks computer location settings

      • ServicesRepair.exe (PID: 6692)
    • Reads the computer name

      • ServicesRepair.exe (PID: 6692)
      • ServicesRepair.exe (PID: 6800)
      • ServicesRepair_x64.exe (PID: 6892)
    • Create files in a temporary directory

      • ServicesRepair.exe (PID: 6800)
    • Checks operating system version

      • cmd.exe (PID: 6676)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:01:29 21:32:28+00:00
ImageFileCharacteristics: No relocs, Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 10
CodeSize: 526336
InitializedDataSize: 449536
UninitializedDataSize: -
EntryPoint: 0x165c1
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.3
ProductVersionNumber: 3.3.8.1
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (British)
CharacterSet: Unicode
FileVersion: 1.0.0.3
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
255
Monitored processes
16
Malicious processes
2
Suspicious processes
2

Behavior graph

Click at the process to see the details
start servicesrepair.exe no specs servicesrepair.exe servicesrepair_x64.exe cmd.exe no specs conhost.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs cmd.exe no specs findstr.exe no specs plugscheduler.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2056C:\WINDOWS\system32\cmd.exe /S /D /c" ver "C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
2464C:\WINDOWS\system32\cmd.exe /S /D /c" ver "C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
2836"C:\Program Files\RUXIM\PLUGscheduler.exe"C:\Program Files\RUXIM\PLUGScheduler.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Update LifeCycle Component Scheduler
Exit code:
0
Version:
10.0.19041.3623 (WinBuild.160101.0800)
Modules
Images
c:\program files\ruxim\plugscheduler.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
3040C:\WINDOWS\system32\cmd.exe /S /D /c" ver "C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
3568findstr /i "5\.2\." C:\Windows\System32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
5080\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
5592findstr /i "6\.0\." C:\Windows\System32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
5760C:\WINDOWS\system32\cmd.exe /S /D /c" ver "C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
6552findstr /i "5\.1\." C:\Windows\System32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
6640findstr /i "5\.0\." C:\Windows\System32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
Total events
3 030
Read events
3 029
Write events
1
Delete events
0

Modification events

(PID) Process:(6892) ServicesRepair_x64.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Cached
Operation:writeName:{2781761E-28E0-4109-99FE-B9D127C57AFE} {56FFCC30-D398-11D0-B2AE-00A0C908FA49} 0xFFFF
Value:
0100000000000000C4B0C7C87510DB01
Executable files
2
Suspicious files
18
Text files
42
Unknown types
16

Dropped files

PID
Process
Filename
Type
6892ServicesRepair_x64.exeC:\Users\Public\Desktop\CC Support\Tools\ServicesRepair\Pieces\SetACL.exeexecutable
MD5:5D016811B09A66158CAE1E18095F9E74
SHA256:56E111D239244FF81E952C018995BD50FBA99E058D8BD38F0197C9D404584C0B
6892ServicesRepair_x64.exeC:\Users\Public\Desktop\CC Support\Tools\ServicesRepair\Pieces\Vista\MpsSvc.regtext
MD5:9A9B4947097FF4A7C70239A104B7A393
SHA256:087FF8469B6FE6214911173D18910609766ECC8AB0F00D43B3FCBDF963ED8C80
6892ServicesRepair_x64.exeC:\Users\Public\Desktop\CC Support\Tools\ServicesRepair\Pieces\Vista\BITS.sddlcsv
MD5:577096DEA76E3E93153BB8D8F347FE8D
SHA256:D1E2E5F769D83ECD5E158B0BE0341FD05D2E97B898BCC45BE052398B6B7500E2
6892ServicesRepair_x64.exeC:\Users\Public\Desktop\CC Support\Tools\ServicesRepair\Pieces\Vista\BFE.sddlcsv
MD5:083E8AFCA00C81ABD12299598CCD8FD7
SHA256:13BCA2D3AA1D23F3F5588150E460DE7D64FCC7C2ED8F3E612A1F01D5A4260B66
6800ServicesRepair.exeC:\Users\admin\AppData\Local\Temp\aut96FC.tmpbinary
MD5:8325AC325F2578553805F5B37776FD53
SHA256:199BDB022C83FC0EC1A62B874B4494B8B96734505A3E989BCD1E7B0A9A32C6FC
6892ServicesRepair_x64.exeC:\Users\Public\Desktop\CC Support\Tools\ServicesRepair\Pieces\Vista\BITS.regtext
MD5:5D98D98CE0B5194C7A8CDC2C26664EF5
SHA256:8CB65B887A98CCEC084E2E6A3E224C9D34562939BE53752954F559CE387A0303
6800ServicesRepair.exeC:\Users\Public\Desktop\CC Support\Tools\ServicesRepair\ServicesRepair_x64.exeexecutable
MD5:59607B33D860CF4D337A4E4851738A76
SHA256:403835920FD16B7AB6D0A7D22353F82173C69D184D6FF1CC7BC21B5E6BF52D6C
6892ServicesRepair_x64.exeC:\Users\admin\AppData\Local\Temp\autA2E3.tmpcompressed
MD5:CAC0A919FE55CAAFFAC56BAEFC037444
SHA256:F0C2B05BABF6298623DA73D62A289BE9A3408D30E982E5875D385617C15CA775
6892ServicesRepair_x64.exeC:\Users\Public\Desktop\CC Support\Tools\ServicesRepair\Pieces\Vista\iphlpsvc.sddlcsv
MD5:497297A89AFE5E8213343C068C4AE3A2
SHA256:6929A657D7339093366F03A477A2EA533C907C91A21FDC20C3EC5C86DD872D98
6892ServicesRepair_x64.exeC:\Users\Public\Desktop\CC Support\Tools\ServicesRepair\Pieces\Vista\iphlpsvc.regtext
MD5:66D5F63D8E7D4673663CB5C49C2BAEDB
SHA256:20B8E119DD37AD3EA22D13CFAA98567905B871671AC0B1FF375EA882FBF3476E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
68
TCP/UDP connections
41
DNS requests
12
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5104
svchost.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2120
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
4524
RUXIMICS.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
GET
404
92.123.104.34:443
https://r.bing.com/rb/4N/jnc,nj/WHBHN5CD2X9iLHkLc7Ck-5t1mtg.js?bu=FpIs1Cr8AeQq5yrqKuwqkSuaLOAr5RH6K4Asniz8AfwBgyjDK-MR2hHXK8gr&or=w
unknown
GET
200
92.123.104.32:443
https://www.bing.com/fd/ls/l?IG=12D4DA20593B441E9948ECCCCB117A2E&Type=Event.ClientInst&DATA=[{%22T%22:%22CI.ClientInst%22,%22FID%22:%22CI%22,%22Name%22:%22max%20errors%20reached%22}]
unknown
GET
200
92.123.104.32:443
https://r.bing.com/rp/-UAIppANYxiGpRWJy2NDph4qOEw.gz.js
unknown
s
20.3 Kb
whitelisted
GET
200
52.109.89.18:443
https://officeclient.microsoft.com/config16/?syslcid=1033&build=16.0.16026&crev=3
unknown
xml
172 Kb
whitelisted
POST
200
20.42.73.28:443
https://browser.pipe.aria.microsoft.com/Collector/3.0/?qsp=true&content-type=application%2Fbond-compact-binary&client-id=NO_AUTH&sdk-version=AWT-Web-CJS-1.2.0&x-apikey=33d70a864599496b982a39f036f71122-2064703e-3a9d-4d90-8362-eec08dffe8e8-7176
unknown
whitelisted
GET
200
92.123.104.34:443
https://r.bing.com/rp/-lxTjronWiCCazqIxFTp4HrDoXc.gz.js
unknown
binary
950 b
whitelisted
GET
200
92.123.104.34:443
https://r.bing.com/rb/6j/ortl,cc,nc/QNBBNqWD9F_Blep-UqQSqnMp-FI.css?bu=AbwK&or=w
unknown
text
6 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5104
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:137
whitelisted
4524
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
4524
RUXIMICS.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2120
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5104
svchost.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.238
whitelisted
www.microsoft.com
  • 23.35.229.160
whitelisted
browser.pipe.aria.microsoft.com
  • 20.50.201.201
whitelisted
self.events.data.microsoft.com
  • 52.168.117.168
  • 20.52.64.201
whitelisted
officeclient.microsoft.com
  • 52.109.89.18
whitelisted
ecs.office.com
  • 52.113.194.132
whitelisted
r.bing.com
  • 2.23.209.149
  • 2.23.209.133
  • 2.23.209.140
  • 2.23.209.187
  • 2.23.209.130
  • 2.23.209.182
whitelisted
www.bing.com
  • 2.23.209.149
  • 2.23.209.133
  • 2.23.209.182
  • 2.23.209.187
  • 2.23.209.140
  • 2.23.209.130
whitelisted

Threats

No threats detected
No debug info