File name:

REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe

Full analysis: https://app.any.run/tasks/5786d454-7550-4e7e-8fac-095ecb26c9ee
Verdict: Malicious activity
Analysis date: November 03, 2023, 14:11:28
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

836010DBC8F20F92CDCC7CDF4F064564

SHA1:

AF3187D7BBC9E5EF9EC2123F01AD53C8A15E859D

SHA256:

8EAA864DF45064794EAF9A42F6436678F8AB128B3E0EB37035A56C69F8ED0ABD

SSDEEP:

192:4c9VcgfTD+4Zfz9C5nls/Ibk/D0GUwhsYPBExnCp1LpcsWZlN:jfTJZd/Io/bZht20uZl

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads settings of System Certificates

      • REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe (PID: 988)
    • Reads the Internet Settings

      • REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe (PID: 988)
  • INFO

    • Checks supported languages

      • REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe (PID: 988)
    • Reads the machine GUID from the registry

      • REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe (PID: 988)
    • Reads Environment values

      • REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe (PID: 988)
    • Reads the computer name

      • REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe (PID: 988)
    • Create files in a temporary directory

      • REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe (PID: 988)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (82.9)
.dll | Win32 Dynamic Link Library (generic) (7.4)
.exe | Win32 Executable (generic) (5.1)
.exe | Generic Win/DOS Executable (2.2)
.exe | DOS Executable Generic (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:08:31 10:10:21+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 3584
InitializedDataSize: 167936
UninitializedDataSize: -
EntryPoint: 0x2d2e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: -
FileVersion: 1.0.0.0
InternalName: REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe
LegalCopyright: -
LegalTrademarks: -
OriginalFileName: REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe
ProductName: -
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
32
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start reminder-purchse _네파fw23-아2023.8월 선적분-서울청구분 (2).exe

Process information

PID
CMD
Path
Indicators
Parent process
988"C:\Users\admin\AppData\Local\Temp\REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe" C:\Users\admin\AppData\Local\Temp\REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\reminder-purchse _네파fw23-아2023.8월 선적분-서울청구분 (2).exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\mscoree.dll
Total events
853
Read events
848
Write events
5
Delete events
0

Modification events

(PID) Process:(988) REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\156\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
Executable files
0
Suspicious files
4
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
988REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506compressed
MD5:F3441B8572AAE8801C04F3060B550443
SHA256:6720349E7D82EE0A8E73920D3C2B7CB2912D9FCF2EDB6FD98F2F12820158B0BF
988REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exeC:\Users\admin\AppData\Local\Temp\CabA32B.tmpcompressed
MD5:F3441B8572AAE8801C04F3060B550443
SHA256:6720349E7D82EE0A8E73920D3C2B7CB2912D9FCF2EDB6FD98F2F12820158B0BF
988REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exeC:\Users\admin\AppData\Local\Temp\TarA32C.tmpbinary
MD5:9441737383D21192400ECA82FDA910EC
SHA256:BC3A6E84E41FAEB57E7C21AA3B60C2A64777107009727C5B7C0ED8FE658909E5
988REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506binary
MD5:1D132794F93D095B16A5C687BE18F909
SHA256:0ABDACBE5F1958C13BD0E4CCBD4EC97F9AC092C60D79D5300C1390F02D6FBF52
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
181
DNS requests
2
Threats
348

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
988
REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe
GET
200
2.19.198.64:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?bc94162ffeea0ca3
unknown
compressed
61.6 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
988
REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe
108.181.20.35:443
files.catbox.moe
TELUS Communications
CA
unknown
1956
svchost.exe
239.255.255.250:1900
whitelisted
988
REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe
2.19.198.64:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
324
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted

DNS requests

Domain
IP
Reputation
files.catbox.moe
  • 108.181.20.35
malicious
ctldl.windowsupdate.com
  • 2.19.198.64
  • 23.32.238.113
  • 23.32.238.121
  • 23.32.238.144
  • 2.19.198.51
  • 2.19.198.41
whitelisted

Threats

PID
Process
Class
Message
988
REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe
Potentially Bad Traffic
ET INFO Observed File Sharing Service Download Domain (files .catbox .moe in TLS SNI)
988
REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe
Potentially Bad Traffic
ET INFO Observed File Sharing Service Download Domain (files .catbox .moe in TLS SNI)
988
REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe
Potentially Bad Traffic
ET INFO Observed File Sharing Service Download Domain (files .catbox .moe in TLS SNI)
988
REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe
Potentially Bad Traffic
ET INFO Observed File Sharing Service Download Domain (files .catbox .moe in TLS SNI)
988
REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe
Potentially Bad Traffic
ET INFO Observed File Sharing Service Download Domain (files .catbox .moe in TLS SNI)
988
REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe
Potentially Bad Traffic
ET INFO Observed File Sharing Service Download Domain (files .catbox .moe in TLS SNI)
988
REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe
Potentially Bad Traffic
ET INFO Observed File Sharing Service Download Domain (files .catbox .moe in TLS SNI)
988
REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe
Potentially Bad Traffic
ET INFO Observed File Sharing Service Download Domain (files .catbox .moe in TLS SNI)
988
REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe
Potentially Bad Traffic
ET INFO Observed File Sharing Service Download Domain (files .catbox .moe in TLS SNI)
988
REMINDER-PURCHSE _네파FW23-아2023.8월 선적분-서울청구분 (2).exe
Potentially Bad Traffic
ET INFO Observed File Sharing Service Download Domain (files .catbox .moe in TLS SNI)
174 ETPRO signatures available at the full report
No debug info