File name:

DCRatBuild.exe

Full analysis: https://app.any.run/tasks/9e4bdbc9-192f-4770-a57b-2a47ea712d62
Verdict: Malicious activity
Analysis date: December 02, 2023, 14:56:02
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

2613F8FFB2321DFC3F81CC00E6F19723

SHA1:

2BEBAC1B99E40DCDF3B23A152965CABA60FF2708

SHA256:

92E236AA4BE3692A0D1F37A8A0140198CD43C7DB2803A583BF40ACA7491A8495

SSDEEP:

98304:ZFrKdQ4Dz1FvhQ0ivlaOjz1xFkjmWVig3IbyIzaiIV0TAwChgv65NuUE6OuW1rVS:Z0DRg0l

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • DCRatBuild.exe (PID: 2428)
    • Uses sleep, probably for evasion detection (SCRIPT)

      • wscript.exe (PID: 2956)
  • SUSPICIOUS

    • Reads the Internet Settings

      • DCRatBuild.exe (PID: 2428)
      • wscript.exe (PID: 2956)
    • Starts CMD.EXE for commands execution

      • wscript.exe (PID: 2956)
    • Executing commands from a ".bat" file

      • wscript.exe (PID: 2956)
    • Runs shell command (SCRIPT)

      • wscript.exe (PID: 2956)
  • INFO

    • Checks supported languages

      • DCRatBuild.exe (PID: 2428)
      • Drivernet.exe (PID: 3784)
      • wmpnscfg.exe (PID: 3832)
    • Reads the computer name

      • DCRatBuild.exe (PID: 2428)
      • Drivernet.exe (PID: 3784)
      • wmpnscfg.exe (PID: 3832)
    • Reads the machine GUID from the registry

      • Drivernet.exe (PID: 3784)
    • Reads Environment values

      • Drivernet.exe (PID: 3784)
    • Reads product name

      • Drivernet.exe (PID: 3784)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3832)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:12:01 19:00:55+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 201216
InitializedDataSize: 114176
UninitializedDataSize: -
EntryPoint: 0x1ec40
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
6
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start dcratbuild.exe wscript.exe no specs cmd.exe no specs drivernet.exe no specs wmpnscfg.exe no specs dcratbuild.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
844"C:\Users\admin\AppData\Local\Temp\DCRatBuild.exe" C:\Users\admin\AppData\Local\Temp\DCRatBuild.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\dcratbuild.exe
c:\windows\system32\ntdll.dll
2428"C:\Users\admin\AppData\Local\Temp\DCRatBuild.exe" C:\Users\admin\AppData\Local\Temp\DCRatBuild.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\dcratbuild.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.gdiplus_6595b64144ccf1df_1.1.7601.24542_none_5c0717c7a00ddc6d\gdiplus.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2632C:\Windows\system32\cmd.exe /c ""C:\ComContainercrtSvc\Tow0aSB60Ag.bat" "C:\Windows\System32\cmd.exewscript.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2956"C:\Windows\System32\WScript.exe" "C:\ComContainercrtSvc\uwlUR1X4eNm0bsAfa.vbe" C:\Windows\System32\wscript.exeDCRatBuild.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft ® Windows Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\wscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3784"C:\ComContainercrtSvc\Drivernet.exe"C:\ComContainercrtSvc\Drivernet.execmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
5.15.2.0
Modules
Images
c:\comcontainercrtsvc\drivernet.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3832"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
452
Read events
436
Write events
16
Delete events
0

Modification events

(PID) Process:(2428) DCRatBuild.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2428) DCRatBuild.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2428) DCRatBuild.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2428) DCRatBuild.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2956) wscript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2956) wscript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2956) wscript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2956) wscript.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
1
Suspicious files
1
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2428DCRatBuild.exeC:\ComContainercrtSvc\Tow0aSB60Ag.battext
MD5:3086B3E8C4C9FA4005AB9DDE34F7806D
SHA256:C76752883C7DFA55E7D60AC61FC096B1D5F73421039237FBB9E30C14F4AB423F
2428DCRatBuild.exeC:\ComContainercrtSvc\uwlUR1X4eNm0bsAfa.vbebinary
MD5:32884176745E4BB89DE949FF88EF8D2E
SHA256:D16B91FD3FEC31B12392D3B8BB2C1E0A5213EB25EBD20FB757DA89B992B95F62
2428DCRatBuild.exeC:\ComContainercrtSvc\Drivernet.exeexecutable
MD5:3A8D8D997CA390FDFA00F8DF365EBADF
SHA256:AF2965690915B97806A0BA50A1411E8301317B387EF5D2A74BFC68F017B6B1EF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
868
svchost.exe
23.35.228.137:80
AKAMAI-AS
DE
unknown
4
System
192.168.100.255:138
whitelisted
868
svchost.exe
23.32.184.135:80
armmf.adobe.com
AKAMAI-AS
BR
unknown
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
armmf.adobe.com
  • 23.32.184.135
whitelisted

Threats

No threats detected
No debug info