File name:

9217f79feca332aeeadabed6b7b0c10bb0cdf9b1d1db5aa83a4e8ac704bf80c0

Full analysis: https://app.any.run/tasks/83e1785a-2d7e-4917-bd38-299eac2e4709
Verdict: Malicious activity
Analysis date: November 15, 2024, 13:06:12
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections
MD5:

2D96E4C716EB0CF915026ED8A7D01AF0

SHA1:

8D793F2EC2B319B9AB4D7D6F12275D15C4C73F88

SHA256:

9217F79FECA332AEEADABED6B7B0C10BB0CDF9B1D1DB5AA83A4E8AC704BF80C0

SSDEEP:

6144:KcGHcbt3OZx9qnGkMQQtbFMO1rWa3NnoyQ77sUGQtygfo:1ocb8qYFZ1P9noJ0Udy+o

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Detected use of alternative data streams (AltDS)

      • 9217f79feca332aeeadabed6b7b0c10bb0cdf9b1d1db5aa83a4e8ac704bf80c0.exe (PID: 2236)
      • 8SPPDJ~1:bin (PID: 7120)
    • Executable content was dropped or overwritten

      • 9217f79feca332aeeadabed6b7b0c10bb0cdf9b1d1db5aa83a4e8ac704bf80c0.exe (PID: 2236)
    • Starts itself from another location

      • 9217f79feca332aeeadabed6b7b0c10bb0cdf9b1d1db5aa83a4e8ac704bf80c0.exe (PID: 2236)
    • Starts application with an unusual extension

      • 9217f79feca332aeeadabed6b7b0c10bb0cdf9b1d1db5aa83a4e8ac704bf80c0.exe (PID: 2236)
    • Reads security settings of Internet Explorer

      • 8SPPDJ~1:bin (PID: 7120)
  • INFO

    • Process checks whether UAC notifications are on

      • 9217f79feca332aeeadabed6b7b0c10bb0cdf9b1d1db5aa83a4e8ac704bf80c0.exe (PID: 2236)
      • 8SPPDJ~1:bin (PID: 7120)
    • Checks supported languages

      • 9217f79feca332aeeadabed6b7b0c10bb0cdf9b1d1db5aa83a4e8ac704bf80c0.exe (PID: 2236)
      • 8SPPDJ~1:bin (PID: 7120)
    • Creates files or folders in the user directory

      • 9217f79feca332aeeadabed6b7b0c10bb0cdf9b1d1db5aa83a4e8ac704bf80c0.exe (PID: 2236)
      • 8SPPDJ~1:bin (PID: 7120)
    • Reads the computer name

      • 9217f79feca332aeeadabed6b7b0c10bb0cdf9b1d1db5aa83a4e8ac704bf80c0.exe (PID: 2236)
      • 8SPPDJ~1:bin (PID: 7120)
    • Create files in a temporary directory

      • 8SPPDJ~1:bin (PID: 7120)
    • The process uses the downloaded file

      • 8SPPDJ~1:bin (PID: 7120)
    • Sends debugging messages

      • mmc.exe (PID: 6392)
    • Reads security settings of Internet Explorer

      • mmc.exe (PID: 6392)
    • Reads the machine GUID from the registry

      • 9217f79feca332aeeadabed6b7b0c10bb0cdf9b1d1db5aa83a4e8ac704bf80c0.exe (PID: 2236)
      • 8SPPDJ~1:bin (PID: 7120)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic Win/DOS Executable (50)
.exe | DOS Executable Generic (49.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:05:01 08:50:32+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 12.1
CodeSize: 102400
InitializedDataSize: 208896
UninitializedDataSize: -
EntryPoint: 0x5907
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 3.7.2150.1013
ProductVersionNumber: 3.7.2150.1013
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Python Software Foundation
FileDescription: Python
FileVersion: 3.7.2
InternalName: Python Console
LegalCopyright: Copyright © 2001-2016 Python Software Foundation. Copyright © 2000 BeOpen.com. Copyright © 1995-2001 CNRI. Copyright © 1991-1995 SMC.
OriginalFileName: python.exe
ProductName: Python
ProductVersion: 3.7.2
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
115
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 9217f79feca332aeeadabed6b7b0c10bb0cdf9b1d1db5aa83a4e8ac704bf80c0.exe 8sppdj~1:bin no specs eventvwr.exe no specs eventvwr.exe mmc.exe

Process information

PID
CMD
Path
Indicators
Parent process
1204"C:\Windows\System32\eventvwr.exe" C:\Windows\System32\eventvwr.exe8SPPDJ~1:bin
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Event Viewer Snapin Launcher
Exit code:
3221226540
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\eventvwr.exe
c:\windows\system32\ntdll.dll
2236"C:\Users\admin\Desktop\9217f79feca332aeeadabed6b7b0c10bb0cdf9b1d1db5aa83a4e8ac704bf80c0.exe" C:\Users\admin\Desktop\9217f79feca332aeeadabed6b7b0c10bb0cdf9b1d1db5aa83a4e8ac704bf80c0.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\9217f79feca332aeeadabed6b7b0c10bb0cdf9b1d1db5aa83a4e8ac704bf80c0.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6392"C:\WINDOWS\system32\mmc.exe" "C:\WINDOWS\system32\eventvwr.msc"C:\Windows\System32\mmc.exe
eventvwr.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Management Console
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\mmc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\acgenral.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
6400"C:\Windows\System32\eventvwr.exe" C:\Windows\System32\eventvwr.exe
8SPPDJ~1:bin
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Event Viewer Snapin Launcher
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\eventvwr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
7120C:\Users\admin\AppData\Roaming\8SPPDJ~1:bin C:\Users\admin\Desktop\9217F7~1.EXEC:\Users\admin\AppData\Roaming\8SPPDJ~1:bin9217f79feca332aeeadabed6b7b0c10bb0cdf9b1d1db5aa83a4e8ac704bf80c0.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\roaming\8sppdj~1:bin
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
2 660
Read events
2 652
Write events
4
Delete events
4

Modification events

(PID) Process:(6392) mmc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MMC\SnapIns\FX:{b05566ad-fe9c-4363-be05-7a4cbb7cb510}
Operation:writeName:HelpTopic
Value:
C:\WINDOWS\Help\eventviewer.chm
(PID) Process:(6392) mmc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MMC\SnapIns\FX:{b05566ad-fe9c-4363-be05-7a4cbb7cb510}
Operation:writeName:LinkedHelpTopics
Value:
C:\WINDOWS\Help\eventviewer.chm
(PID) Process:(6392) mmc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MMC\SnapIns\FX:{b05566ae-fe9c-4363-be05-7a4cbb7cb510}
Operation:writeName:HelpTopic
Value:
C:\WINDOWS\Help\eventviewer.chm
(PID) Process:(6392) mmc.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\MMC\SnapIns\FX:{b05566ae-fe9c-4363-be05-7a4cbb7cb510}
Operation:writeName:LinkedHelpTopics
Value:
C:\WINDOWS\Help\eventviewer.chm
(PID) Process:(7120) 8SPPDJ~1:binKey:HKEY_CLASSES_ROOT\MSCFile\shell\open\command
Operation:delete keyName:(default)
Value:
(PID) Process:(7120) 8SPPDJ~1:binKey:HKEY_CLASSES_ROOT\MSCFile\shell\open
Operation:delete keyName:(default)
Value:
(PID) Process:(7120) 8SPPDJ~1:binKey:HKEY_CLASSES_ROOT\MSCFile\shell
Operation:delete keyName:(default)
Value:
(PID) Process:(7120) 8SPPDJ~1:binKey:HKEY_CLASSES_ROOT\MSCFile
Operation:delete keyName:(default)
Value:
Executable files
1
Suspicious files
2
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
22369217f79feca332aeeadabed6b7b0c10bb0cdf9b1d1db5aa83a4e8ac704bf80c0.exeC:\Users\admin\AppData\Roaming\8SPPDJ~1
MD5:
SHA256:
71208SPPDJ~1:binC:\Users\admin\AppData\Local\Temp\Wetil.cmdtext
MD5:6A0761CA89149B069A4AB6BBA8F5E5B9
SHA256:6E73CBD17F3FD4C62E37FC56C55588F60CC1114E61AF10ECCF7CAAFDF233B642
6392mmc.exeC:\Users\admin\AppData\Local\Microsoft\Event Viewer\RecentViewsbinary
MD5:785FB8E1B562E2FCC8C0C0C6572EE3D7
SHA256:5607B57C3C58070F54B8F68FA22808F9AD14C60BBF05F00DA92A162585C3C562
6392mmc.exeC:\Users\admin\AppData\Roaming\Microsoft\MMC\eventvwrxml
MD5:C4AEFE383AD08188E19D2FBDDC3DAB20
SHA256:3BC5CEBD617E62A939F8434A594F2D8CD30E65EC2EB25FD912F154ABC04CFFC5
71208SPPDJ~1:binC:\Users\admin\AppData\Roaming\0vCBjfNuOQE7kX\IBCSMG~1.EXEbinary
MD5:EB64CE3425E22FA5ED09FC9FB9C9887C
SHA256:3566E15AD2073FCEE9DE878C7FC49F30AAA28D29D8CEBCDF75585700A19D3C46
22369217f79feca332aeeadabed6b7b0c10bb0cdf9b1d1db5aa83a4e8ac704bf80c0.exeC:\Users\admin\AppData\Roaming\8SPPDJ~1:binexecutable
MD5:2D96E4C716EB0CF915026ED8A7D01AF0
SHA256:9217F79FECA332AEEADABED6B7B0C10BB0CDF9B1D1DB5AA83A4E8AC704BF80C0
6392mmc.exeC:\Users\admin\AppData\Local\Microsoft\Event Viewer\Settings.Xmltext
MD5:884320A9B8F018F309F5A96107133F89
SHA256:50FD9D76D1C43BB16B166DE02AAF8ADEC09EB5BC4CEFDCA9D1AF2E0F7B1D8F64
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
12
DNS requests
18
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
51.124.78.146:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4020
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
whitelisted
settings-win.data.microsoft.com
  • 51.124.78.146
whitelisted
google.com
  • 142.250.185.142
whitelisted
dns.msftncsi.com
  • 131.107.255.255
whitelisted

Threats

No threats detected
Process
Message
mmc.exe
ViewerExternalLogsPath = 'C:\ProgramData\Microsoft\Event Viewer\ExternalLogs': Microsoft.Windows.ManagementUI.CombinedControls.EventsNode
mmc.exe
ViewerConfigPath = 'C:\ProgramData\Microsoft\Event Viewer': Microsoft.Windows.ManagementUI.CombinedControls.EventsNode
mmc.exe
ViewerViewsFolderPath = 'C:\ProgramData\Microsoft\Event Viewer\Views': Microsoft.Windows.ManagementUI.CombinedControls.EventsNode
mmc.exe
ViewerAdminViewsPath = 'C:\ProgramData\Microsoft\Event Viewer\Views\ApplicationViewsRootNode': Microsoft.Windows.ManagementUI.CombinedControls.EventsNode
mmc.exe
Failed to get ChannelConfigOwningPublisher -122-The data area passed to a system call is too small
mmc.exe
Getting next publisher from enum failed-259-No more data is available
mmc.exe
Failed to get ChannelConfigOwningPublisher -122-The data area passed to a system call is too small
mmc.exe
ExpandNode:After EventsNode:InsertChildren CountOfChildren = 5
mmc.exe
PublisherMetadataKeywordName failed for not providing enough memory. Trying with the correct memory -122-The data area passed to a system call is too small
mmc.exe
PublisherMetadataKeywordName failed for not providing enough memory. Trying with the correct memory -122-The data area passed to a system call is too small