| download: | OpenMe.bat |
| Full analysis: | https://app.any.run/tasks/4c09588e-1074-4a6f-ae52-6f2e6d17f4c3 |
| Verdict: | Malicious activity |
| Analysis date: | November 29, 2020, 17:39:56 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/x-msdos-batch |
| File info: | DOS batch file, ASCII text, with very long lines |
| MD5: | 997DD0666FF4531F230ECFA1C82A8727 |
| SHA1: | CBB0C985669A028DE0559B20B0815F39AD48415B |
| SHA256: | 90783B1907D0907CEFFE0653C2831D69FBB759B324652ACA890EB5EE07783C23 |
| SSDEEP: | 24:qdH7grM8OQzMX8VQiu+5DD9l6eGv9gggggggggnMwRJ7:gmrOrsDfrMI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 444 | cmd.exe | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 552 | cmd.exe | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 668 | cmd.exe | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 736 | cmd.exe | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 848 | cmd.exe | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 852 | cmd.exe | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 952 | cmd.exe | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 956 | cmd.exe | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1076 | cmd.exe | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1204 | cmd.exe | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (2376) reg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | Zipped |
Value: C:\Users\admin\AppData\Local\Temp\OpenMe.bat | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2452 | cmd.exe | C:\Users\admin\AppData\Local\Temp\2831612012173261017927175563415501268102081647721029.txt | text | |
MD5:— | SHA256:— | |||
| 2452 | cmd.exe | C:\Users\admin\AppData\Local\Temp\2919037871887199492114516385143861390820480118267080.txt | text | |
MD5:— | SHA256:— | |||
| 2452 | cmd.exe | C:\Users\admin\AppData\Local\Temp\289616130710814196325452645070916202318262045619914.txt | text | |
MD5:— | SHA256:— | |||
| 2452 | cmd.exe | C:\Users\admin\AppData\Local\Temp\15594665772825066271681911516692189602887426920491.txt | text | |
MD5:— | SHA256:— | |||
| 2452 | cmd.exe | C:\Users\admin\AppData\Local\Temp\124501981327269738931965315352328619038130812726427701.txt | text | |
MD5:— | SHA256:— | |||
| 2452 | cmd.exe | C:\Users\admin\AppData\Local\Temp\25882182661992014781901175643846191964124592631351.txt | text | |
MD5:— | SHA256:— | |||
| 2452 | cmd.exe | C:\Users\admin\AppData\Local\Temp\98342342226181231301882916272247991852528497253772775.txt | text | |
MD5:— | SHA256:— | |||
| 2452 | cmd.exe | C:\Users\admin\AppData\Local\Temp\270292138769641613322467441536611052178792033812283.txt | text | |
MD5:— | SHA256:— | |||
| 2452 | cmd.exe | C:\Users\admin\AppData\Local\Temp\290025179236516801160083595254884805169042279721312.txt | text | |
MD5:— | SHA256:— | |||
| 2452 | cmd.exe | C:\Users\admin\AppData\Local\Temp\1640716440276402105522787300461383431676308961028113683.txt | text | |
MD5:— | SHA256:— | |||