analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

674123der.exe

Full analysis: https://app.any.run/tasks/0f92c23f-7aff-43fa-9bdf-31ca19f1139a
Verdict: Malicious activity
Analysis date: March 14, 2019, 20:07:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

FF85BE45690CF0A6F0CAD6C24EC59D7C

SHA1:

6DEE907C6A7FB93BA6ADEA946DDF764FD00336CF

SHA256:

8FF9A8A043CEB2E95D7F83F6317F3F777EC4B0CEBADB3A4DB37C5C2D95061A48

SSDEEP:

6144:s1czBpLibza+uGBBR44o3uO3CbU15996uUPG4u8uCYKVf2PuMdx1:oczP04GBBR4+OqOmPluDqp4vx

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Writes to a start menu file

      • DllHost.exe (PID: 2456)
    • Uses SVCHOST.EXE for hidden code execution

      • WerFault.exe (PID: 3732)
  • SUSPICIOUS

    • Creates files in the user directory

      • DllHost.exe (PID: 2456)
      • WerFault.exe (PID: 3732)
    • Executable content was dropped or overwritten

      • DllHost.exe (PID: 2456)
    • Connects to unusual port

      • WerFault.exe (PID: 3732)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0x1098c
UninitializedDataSize: -
InitializedDataSize: 344064
CodeSize: 159744
LinkerVersion: 6
PEType: PE32
TimeStamp: 2016:12:06 12:29:17+01:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 06-Dec-2016 11:29:17
Detected languages:
  • English - United States
CompanyName: 3Dfx Interactive, Inc.
FileDescription: 3Dfx Interactive, Inc. OpenGL DLL
FileVersion: 3Dfx OpenGL 1.1 For Quake(TM)
InternalName: opengl32.dll
LegalCopyright: Copyright © 3Dfx Interactive, Inc. 1996
OriginalFilename: opengl32.dll
ProductName: OpenGL For Quake(tm)© and Windows® 95
ProductVersion: 3Dfx OpenGL 1.1 For Quake(TM)

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000E0

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 06-Dec-2016 11:29:17
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x0002661D
0x00027000
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.37747
.rdata
0x00028000
0x0001470E
0x00015000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
6.28858
.data
0x0003D000
0x0000C488
0x00008000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
6.90631
.EdwinX
0x0004A000
0x00024E78
0x00025000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.2421
.headm
0x0006F000
0x0001191A
0x00012000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
7.94262

Resources

Title
Entropy
Size
Codepage
Language
Type
1
3.5368
952
UNKNOWN
English - United States
RT_VERSION
2
2.35221
67624
UNKNOWN
UNKNOWN
RT_ICON
3
2.48725
16936
UNKNOWN
UNKNOWN
RT_ICON
4
2.63003
9640
UNKNOWN
UNKNOWN
RT_ICON
5
2.67415
4264
UNKNOWN
UNKNOWN
RT_ICON
6
2.91132
1128
UNKNOWN
UNKNOWN
RT_ICON
129
5.19613
37412
UNKNOWN
English - United States
WAVE
3841
2.81705
130
UNKNOWN
English - United States
RT_STRING
3842
0.960953
42
UNKNOWN
English - United States
RT_STRING
3843
3.04939
330
UNKNOWN
English - United States
RT_STRING

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.dll
USER32.dll
WINSPOOL.DRV
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
56
Monitored processes
27
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 674123der.exe no specs Copy/Move/Rename/Delete/Link Object werfault.exe svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs svchost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2840"C:\Users\admin\AppData\Local\Temp\674123der.exe" C:\Users\admin\AppData\Local\Temp\674123der.exeexplorer.exe
User:
admin
Company:
3Dfx Interactive, Inc.
Integrity Level:
MEDIUM
Description:
3Dfx Interactive, Inc. OpenGL DLL
Exit code:
0
Version:
3Dfx OpenGL 1.1 For Quake(TM)
2456C:\Windows\system32\DllHost.exe /Processid:{3AD05575-8857-4850-9277-11B85BDB8E09}C:\Windows\system32\DllHost.exe
svchost.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
COM Surrogate
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3732"C:\Windows\System32\WerFault.exe"C:\Windows\System32\WerFault.exe
674123der.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2736C:\Windows\system32\svchost.exeC:\Windows\system32\svchost.exeWerFault.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Host Process for Windows Services
Exit code:
3221225784
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3540C:\Windows\system32\svchost.exeC:\Windows\system32\svchost.exeWerFault.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Host Process for Windows Services
Exit code:
3221225784
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
4064C:\Windows\system32\svchost.exeC:\Windows\system32\svchost.exeWerFault.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Host Process for Windows Services
Exit code:
3221225784
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2520C:\Windows\system32\svchost.exeC:\Windows\system32\svchost.exeWerFault.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Host Process for Windows Services
Exit code:
3221225784
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3144C:\Windows\system32\svchost.exeC:\Windows\system32\svchost.exeWerFault.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Host Process for Windows Services
Exit code:
3221225784
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
3628C:\Windows\system32\svchost.exeC:\Windows\system32\svchost.exeWerFault.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Host Process for Windows Services
Exit code:
3221225784
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
2128C:\Windows\system32\svchost.exeC:\Windows\system32\svchost.exeWerFault.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Host Process for Windows Services
Exit code:
3221225784
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
423
Read events
398
Write events
25
Delete events
0

Modification events

(PID) Process:(3732) WerFault.exeKey:HKEY_CURRENT_USER\Software\gh7jdsj73-35UPFN
Operation:writeName:exepath
Value:
D1F761B712DBA07C0E88ED76B2079B4E93A2BA04B6C233148FF11B9BD10293C6B8BFE6043E915DD451B623F539C0832F50356FBC3713182AB25CBAFD8D83B1E5A05D
(PID) Process:(3732) WerFault.exeKey:HKEY_CURRENT_USER\Software\gh7jdsj73-35UPFN
Operation:writeName:licence
Value:
832AB669F46A10EF3A725B712278A456
(PID) Process:(3732) WerFault.exeKey:HKEY_CURRENT_USER\Software\gh7jdsj73-35UPFN
Operation:writeName:WD
Value:
3732
Executable files
1
Suspicious files
1
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2840674123der.exeC:\Users\admin\AppData\Local\Temp\Liebert.bmp
MD5:
SHA256:
2456DllHost.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\3dfxgl.exeexecutable
MD5:FF85BE45690CF0A6F0CAD6C24EC59D7C
SHA256:8FF9A8A043CEB2E95D7F83F6317F3F777EC4B0CEBADB3A4DB37C5C2D95061A48
3732WerFault.exeC:\Users\admin\AppData\Roaming\fb8ehdww\logs.datbinary
MD5:8772EFABF8053CA0052899778AC58F41
SHA256:56A306E4468B0B30D7CDA88CEEFABD02BA73D5847B5F7AB73AB8210305F04E09
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
2
DNS requests
4
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3732
WerFault.exe
206.123.145.133:24045
activation.litttlecg.com
Nobis Technology Group, LLC
US
unknown

DNS requests

Domain
IP
Reputation
activation.litttlecg.com
  • 206.123.145.133
unknown
dns.msftncsi.com
shared

Threats

No threats detected
No debug info