File name:

pidrpizda.bat

Full analysis: https://app.any.run/tasks/ada4fdd8-9014-4373-9e04-3c9e4b51ea37
Verdict: Malicious activity
Analysis date: March 05, 2024, 19:33:48
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: text/plain
File info: ASCII text, with no line terminators
MD5:

CD7C9D053A913B1261DBBC69880208E7

SHA1:

EB0459B57EB92784637A7F13F27D89528408EA7C

SHA256:

923E8AFDCE56B99DC3072DEE422719D267A0788AFDF0899904CE6E32155E9B5D

SSDEEP:

3:3Jv+W:3Jv+W

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Manual execution by a user

      • explorer.exe (PID: 3732)
      • cmd.exe (PID: 2120)
      • cmd.exe (PID: 2248)
      • cmd.exe (PID: 1728)
      • cmd.exe (PID: 2128)
      • cmd.exe (PID: 2020)
      • cmd.exe (PID: 2068)
      • cmd.exe (PID: 1936)
      • cmd.exe (PID: 2640)
      • cmd.exe (PID: 3088)
    • Checks supported languages

      • curl.exe (PID: 3348)
      • curl.exe (PID: 1692)
      • curl.exe (PID: 1232)
      • curl.exe (PID: 1608)
      • curl.exe (PID: 764)
      • curl.exe (PID: 2808)
      • curl.exe (PID: 948)
      • curl.exe (PID: 3504)
      • curl.exe (PID: 3984)
      • curl.exe (PID: 2324)
    • Reads the computer name

      • curl.exe (PID: 3348)
      • curl.exe (PID: 1232)
      • curl.exe (PID: 1608)
      • curl.exe (PID: 764)
      • curl.exe (PID: 3504)
      • curl.exe (PID: 2808)
      • curl.exe (PID: 948)
      • curl.exe (PID: 3984)
      • curl.exe (PID: 1692)
      • curl.exe (PID: 2324)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
68
Monitored processes
21
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start cmd.exe no specs curl.exe explorer.exe no specs cmd.exe no specs curl.exe cmd.exe no specs curl.exe cmd.exe no specs curl.exe cmd.exe no specs curl.exe cmd.exe no specs curl.exe cmd.exe no specs curl.exe cmd.exe no specs curl.exe cmd.exe no specs curl.exe cmd.exe no specs curl.exe

Process information

PID
CMD
Path
Indicators
Parent process
764curl parrot.liveC:\Windows\System32\curl.exe
cmd.exe
User:
admin
Company:
curl, https://curl.se/
Integrity Level:
MEDIUM
Description:
The curl executable
Exit code:
0
Version:
8.5.0
Modules
Images
c:\windows\system32\curl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
948curl parrot.liveC:\Windows\System32\curl.exe
cmd.exe
User:
admin
Company:
curl, https://curl.se/
Integrity Level:
MEDIUM
Description:
The curl executable
Exit code:
0
Version:
8.5.0
Modules
Images
c:\windows\system32\curl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
1232curl parrot.liveC:\Windows\System32\curl.exe
cmd.exe
User:
admin
Company:
curl, https://curl.se/
Integrity Level:
MEDIUM
Description:
The curl executable
Exit code:
0
Version:
8.5.0
Modules
Images
c:\windows\system32\curl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
1608curl parrot.liveC:\Windows\System32\curl.exe
cmd.exe
User:
admin
Company:
curl, https://curl.se/
Integrity Level:
MEDIUM
Description:
The curl executable
Exit code:
0
Version:
8.5.0
Modules
Images
c:\windows\system32\curl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
1692curl parrot.liveC:\Windows\System32\curl.exe
cmd.exe
User:
admin
Company:
curl, https://curl.se/
Integrity Level:
MEDIUM
Description:
The curl executable
Exit code:
3221225786
Version:
8.5.0
Modules
Images
c:\windows\system32\curl.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\crypt32.dll
1728C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\pidrpizda - Copy (42).bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1936C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\pidrpizda - Copy (42).bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2020C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\pidrpizda - Copy (42).bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2068C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\pidrpizda - Copy (42).bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2120C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\pidrpizda.bat" "C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
3221225547
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
2 520
Read events
2 520
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
10
TCP/UDP connections
14
DNS requests
1
Threats
10

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3348
curl.exe
GET
206.189.36.145:80
http://parrot.live/
unknown
unknown
3984
curl.exe
GET
206.189.36.145:80
http://parrot.live/
unknown
unknown
1692
curl.exe
GET
206.189.36.145:80
http://parrot.live/
unknown
unknown
1232
curl.exe
GET
206.189.36.145:80
http://parrot.live/
unknown
unknown
2324
curl.exe
GET
206.189.36.145:80
http://parrot.live/
unknown
unknown
2808
curl.exe
GET
206.189.36.145:80
http://parrot.live/
unknown
unknown
1608
curl.exe
GET
206.189.36.145:80
http://parrot.live/
unknown
unknown
764
curl.exe
GET
206.189.36.145:80
http://parrot.live/
unknown
unknown
948
curl.exe
GET
206.189.36.145:80
http://parrot.live/
unknown
unknown
3504
curl.exe
GET
206.189.36.145:80
http://parrot.live/
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3348
curl.exe
206.189.36.145:80
parrot.live
DIGITALOCEAN-ASN
SG
unknown
1692
curl.exe
206.189.36.145:80
parrot.live
DIGITALOCEAN-ASN
SG
unknown
3984
curl.exe
206.189.36.145:80
parrot.live
DIGITALOCEAN-ASN
SG
unknown
2324
curl.exe
206.189.36.145:80
parrot.live
DIGITALOCEAN-ASN
SG
unknown
1232
curl.exe
206.189.36.145:80
parrot.live
DIGITALOCEAN-ASN
SG
unknown
1608
curl.exe
206.189.36.145:80
parrot.live
DIGITALOCEAN-ASN
SG
unknown
764
curl.exe
206.189.36.145:80
parrot.live
DIGITALOCEAN-ASN
SG
unknown

DNS requests

Domain
IP
Reputation
parrot.live
  • 206.189.36.145
unknown

Threats

PID
Process
Class
Message
3348
curl.exe
Attempted Information Leak
ET POLICY curl User-Agent Outbound
1692
curl.exe
Attempted Information Leak
ET POLICY curl User-Agent Outbound
3984
curl.exe
Attempted Information Leak
ET POLICY curl User-Agent Outbound
2324
curl.exe
Attempted Information Leak
ET POLICY curl User-Agent Outbound
1232
curl.exe
Attempted Information Leak
ET POLICY curl User-Agent Outbound
1608
curl.exe
Attempted Information Leak
ET POLICY curl User-Agent Outbound
764
curl.exe
Attempted Information Leak
ET POLICY curl User-Agent Outbound
2808
curl.exe
Attempted Information Leak
ET POLICY curl User-Agent Outbound
3504
curl.exe
Attempted Information Leak
ET POLICY curl User-Agent Outbound
948
curl.exe
Attempted Information Leak
ET POLICY curl User-Agent Outbound
No debug info