File name:

stopabit.exe

Full analysis: https://app.any.run/tasks/7d777114-5038-4528-a165-e91baf96fc9b
Verdict: Malicious activity
Analysis date: June 15, 2024, 18:43:05
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
evasion
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

F48B8DCA81A54EE64C43A1DB389636D1

SHA1:

CAFE60B0A29AFDFF230A367F34D29BB574213970

SHA256:

9397BF27C48BE348EF2DB687475BA5AA44DFC3A85E8AFF2F891123C44A34FE55

SSDEEP:

98304:l+cD4dnE+zc4rAG/xKN2sPGE9IPDVAAWXHUFcTdNuKKkQFuUoYepyk2dqBXOrasG:5BiMbzRJyJs

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • stopabit.exe (PID: 3992)
      • stopabit.tmp (PID: 4008)
      • unins000.exe (PID: 1936)
    • Changes the autorun value in the registry

      • Stopabit.exe (PID: 4076)
  • SUSPICIOUS

    • Reads the Windows owner or organization settings

      • stopabit.tmp (PID: 4008)
      • _unins.tmp (PID: 2524)
    • Reads settings of System Certificates

      • stopabit.tmp (PID: 4008)
      • Stopabit.exe (PID: 4076)
      • _unins.tmp (PID: 2524)
    • Executable content was dropped or overwritten

      • stopabit.tmp (PID: 4008)
    • Process drops legitimate windows executable

      • stopabit.tmp (PID: 4008)
    • Reads security settings of Internet Explorer

      • Stopabit.exe (PID: 4076)
    • Checks Windows Trust Settings

      • Stopabit.exe (PID: 4076)
    • Reads the Internet Settings

      • Stopabit.exe (PID: 4076)
    • Reads Microsoft Outlook installation path

      • Stopabit.exe (PID: 4076)
    • Reads Internet Explorer settings

      • Stopabit.exe (PID: 4076)
    • Starts CMD.EXE for commands execution

      • _unins.tmp (PID: 2524)
    • Get information on the list of running processes

      • _unins.tmp (PID: 2524)
      • cmd.exe (PID: 2340)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 2556)
    • Using 'findstr.exe' to search for text patterns in files and output

      • cmd.exe (PID: 2340)
    • Starts application with an unusual extension

      • unins000.exe (PID: 1936)
    • Starts itself from another location

      • unins000.exe (PID: 1936)
    • Reads the date of Windows installation

      • _unins.tmp (PID: 2524)
  • INFO

    • Checks supported languages

      • stopabit.exe (PID: 3992)
      • stopabit.tmp (PID: 4008)
      • Stopabit.exe (PID: 4076)
      • _unins.tmp (PID: 2524)
      • unins000.exe (PID: 1936)
    • Reads the computer name

      • stopabit.tmp (PID: 4008)
      • Stopabit.exe (PID: 4076)
      • _unins.tmp (PID: 2524)
      • unins000.exe (PID: 1936)
    • Create files in a temporary directory

      • stopabit.exe (PID: 3992)
      • stopabit.tmp (PID: 4008)
      • unins000.exe (PID: 1936)
    • Reads the machine GUID from the registry

      • stopabit.tmp (PID: 4008)
      • Stopabit.exe (PID: 4076)
      • _unins.tmp (PID: 2524)
    • Reads the software policy settings

      • stopabit.tmp (PID: 4008)
      • Stopabit.exe (PID: 4076)
      • _unins.tmp (PID: 2524)
    • Creates files or folders in the user directory

      • stopabit.tmp (PID: 4008)
      • Stopabit.exe (PID: 4076)
    • Creates a software uninstall entry

      • stopabit.tmp (PID: 4008)
    • Disables trace logs

      • Stopabit.exe (PID: 4076)
    • Reads Environment values

      • Stopabit.exe (PID: 4076)
    • Reads the time zone

      • Stopabit.exe (PID: 4076)
    • Reads product name

      • Stopabit.exe (PID: 4076)
    • Checks proxy server information

      • Stopabit.exe (PID: 4076)
    • Manual execution by a user

      • unins000.exe (PID: 1936)
      • control.exe (PID: 2060)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (65.1)
.exe | Win32 EXE PECompact compressed (generic) (24.6)
.dll | Win32 Dynamic Link Library (generic) (3.9)
.exe | Win32 Executable (generic) (2.6)
.exe | Win16/32 Executable Delphi generic (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:04:14 16:10:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 74240
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.9.0
ProductVersionNumber: 1.0.9.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Globalhop
FileDescription: Stopabit installer
FileVersion: 1.0.9.0
LegalCopyright: © Globalhop
OriginalFileName: Stopabit.exe
ProductName: Stopabit
ProductVersion: 1.0.9.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
11
Malicious processes
5
Suspicious processes
0

Behavior graph

Click at the process to see the details
start stopabit.exe no specs stopabit.tmp stopabit.exe control.exe no specs unins000.exe no specs _unins.tmp cmd.exe no specs taskkill.exe no specs cmd.exe no specs tasklist.exe no specs findstr.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1936"C:\Users\admin\AppData\Local\Programs\Stopabit\unins000.exe" C:\Users\admin\AppData\Local\Programs\Stopabit\unins000.exeexplorer.exe
User:
admin
Company:
Globalhop
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\programs\stopabit\unins000.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2060"C:\Windows\System32\control.exe" C:\Windows\System32\control.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Control Panel
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\control.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2340"C:\Windows\system32\cmd.exe" /C tasklist | findstr Stopabit.exeC:\Windows\System32\cmd.exe_unins.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2468tasklist C:\Windows\System32\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
2524"C:\Users\admin\AppData\Local\Temp\iu-14D2N.tmp\_unins.tmp" /SECONDPHASE="C:\Users\admin\AppData\Local\Programs\Stopabit\unins000.exe" /FIRSTPHASEWND=$10212 C:\Users\admin\AppData\Local\Temp\iu-14D2N.tmp\_unins.tmp
unins000.exe
User:
admin
Company:
Globalhop
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\iu-14d2n.tmp\_unins.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2556"C:\Windows\system32\cmd.exe" /C taskkill /T /IM Stopabit.exeC:\Windows\System32\cmd.exe_unins.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2620taskkill /T /IM Stopabit.exeC:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Terminates Processes
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
2648findstr Stopabit.exeC:\Windows\System32\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (QGREP) Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\imm32.dll
3992"C:\Users\admin\Desktop\stopabit.exe" C:\Users\admin\Desktop\stopabit.exeexplorer.exe
User:
admin
Company:
Globalhop
Integrity Level:
MEDIUM
Description:
Stopabit installer
Exit code:
0
Version:
1.0.9.0
Modules
Images
c:\users\admin\desktop\stopabit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
4008"C:\Users\admin\AppData\Local\Temp\is-5MCK6.tmp\stopabit.tmp" /SL5="$20138,3291176,817152,C:\Users\admin\Desktop\stopabit.exe" C:\Users\admin\AppData\Local\Temp\is-5MCK6.tmp\stopabit.tmp
stopabit.exe
User:
admin
Company:
Globalhop
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-5mck6.tmp\stopabit.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
17 869
Read events
17 610
Write events
248
Delete events
11

Modification events

(PID) Process:(4008) stopabit.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
A80F0000B6E4B1E153BFDA01
(PID) Process:(4008) stopabit.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
F0615175FBD98034042CDA1A1FCDA4781CECEA44363F0314D5DE87BEC5E7F16B
(PID) Process:(4008) stopabit.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(4008) stopabit.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(4008) stopabit.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFiles0000
Value:
C:\Users\admin\AppData\Local\Programs\Stopabit\Stopabit.exe
(PID) Process:(4008) stopabit.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:RegFilesHash
Value:
962CA330C3B08E7E7ACC9E612B441D7F6226FDF5F66565053235D06A6669944F
(PID) Process:(4008) stopabit.tmpKey:HKEY_CURRENT_USER\Software\SlowJobber
Operation:writeName:version
Value:
1.0.9.0
(PID) Process:(4008) stopabit.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FD04524F-249D-425E-81DF-1A30526751D1}_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.2.1
(PID) Process:(4008) stopabit.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FD04524F-249D-425E-81DF-1A30526751D1}_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Users\admin\AppData\Local\Programs\Stopabit
(PID) Process:(4008) stopabit.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{FD04524F-249D-425E-81DF-1A30526751D1}_is1
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\Programs\Stopabit\
Executable files
20
Suspicious files
3
Text files
8
Unknown types
0

Dropped files

PID
Process
Filename
Type
4008stopabit.tmpC:\Users\admin\AppData\Local\Programs\Stopabit\is-AMRDI.tmpexecutable
MD5:C52DA72F8D82116756F30B6FBD2B18C1
SHA256:25BC7911BFAB63D64FD722937260FE3240608277CF90FE5859DE041DB63674E4
4008stopabit.tmpC:\Users\admin\AppData\Local\Programs\Stopabit\unins000.exeexecutable
MD5:115968165DEAF7D78BFE2FD013955198
SHA256:E6B67DF4F83ADE3042E6BA7C6CC5DD64E5C4A06818013BE0B82A178A17F74823
4008stopabit.tmpC:\Users\admin\AppData\Local\Programs\Stopabit\Modules\classic.dllexecutable
MD5:EE6B93C13EC66A61FE85120E3932727E
SHA256:34F6FB8B54AD939F6833B9A915A56222925B2BCF1141C943558E2450DC4CAA71
4008stopabit.tmpC:\Users\admin\AppData\Local\Programs\Stopabit\Modules\is-F409M.tmpexecutable
MD5:EE6B93C13EC66A61FE85120E3932727E
SHA256:34F6FB8B54AD939F6833B9A915A56222925B2BCF1141C943558E2450DC4CAA71
4008stopabit.tmpC:\Users\admin\AppData\Local\Programs\Stopabit\Stopabit.exeexecutable
MD5:C52DA72F8D82116756F30B6FBD2B18C1
SHA256:25BC7911BFAB63D64FD722937260FE3240608277CF90FE5859DE041DB63674E4
4008stopabit.tmpC:\Users\admin\AppData\Local\Programs\Stopabit\is-9IPMM.tmpxml
MD5:3E8F51C2B6FD8149C32819EADEC0CA72
SHA256:0E7ACBB755E5161D596D65BC357EC09EE0F82017D15F65504E4EEC47DAC927BD
3992stopabit.exeC:\Users\admin\AppData\Local\Temp\is-5MCK6.tmp\stopabit.tmpexecutable
MD5:115968165DEAF7D78BFE2FD013955198
SHA256:E6B67DF4F83ADE3042E6BA7C6CC5DD64E5C4A06818013BE0B82A178A17F74823
4008stopabit.tmpC:\Users\admin\AppData\Local\Programs\Stopabit\is-ESJOI.tmpexecutable
MD5:115968165DEAF7D78BFE2FD013955198
SHA256:E6B67DF4F83ADE3042E6BA7C6CC5DD64E5C4A06818013BE0B82A178A17F74823
4008stopabit.tmpC:\Users\admin\AppData\Local\Programs\Stopabit\is-8EBA2.tmpexecutable
MD5:83222120C8095B8623FE827FB70FAF6B
SHA256:EFF79DE319CA8941A2E62FB573230D82B79B80958E5A26AB1A4E87193EB13503
4008stopabit.tmpC:\Users\admin\AppData\Local\Programs\Stopabit\is-74T06.tmpexecutable
MD5:E1129D3DFD0E6A932B2776658135B90C
SHA256:346B9AB2515995475699021C381B1AC93114F437BC49010EE6E9B5424CCBCC67
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
14
DNS requests
8
Threats
1

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
1088
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
4008
stopabit.tmp
104.21.82.170:443
stats.stopabit.com
CLOUDFLARENET
unknown
4008
stopabit.tmp
172.67.159.214:443
stats.stopabit.com
CLOUDFLARENET
US
unknown
4076
Stopabit.exe
104.21.82.170:443
stats.stopabit.com
CLOUDFLARENET
unknown
4076
Stopabit.exe
46.4.79.62:5001
quickyapongia.org
unknown
4076
Stopabit.exe
136.243.130.37:5001
trippinglyfast.com
unknown
4076
Stopabit.exe
104.16.123.96:443
www.cloudflare.com
CLOUDFLARENET
unknown
4076
Stopabit.exe
104.16.60.8:443
speed.cloudflare.com
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
stats.stopabit.com
  • 104.21.82.170
  • 172.67.159.214
unknown
track.stopabit.com
  • 172.67.159.214
  • 104.21.82.170
unknown
trippinglyfast.com
  • 136.243.130.37
  • 88.99.115.32
  • 46.4.68.50
  • 46.4.68.51
  • 46.4.105.181
  • 148.251.184.150
  • 148.251.184.143
  • 148.251.184.186
  • 188.40.23.171
  • 176.9.20.82
  • 144.76.137.185
  • 116.202.83.222
  • 116.202.83.221
  • 188.40.60.220
  • 148.251.184.159
  • 148.251.184.167
unknown
quickyapongia.org
  • 46.4.79.62
  • 213.133.98.140
  • 88.99.242.212
  • 178.63.14.102
  • 188.40.63.34
  • 157.90.208.43
  • 176.9.41.56
  • 88.99.115.184
  • 116.202.232.105
  • 159.69.138.94
  • 88.198.64.137
  • 138.201.83.67
  • 116.202.237.235
  • 88.198.62.169
  • 188.40.126.181
  • 188.40.64.154
unknown
www.cloudflare.com
  • 104.16.123.96
  • 104.16.124.96
whitelisted
speed.cloudflare.com
  • 104.16.60.8
  • 104.16.61.8
unknown
api6.ipify.org
unknown
www.vrbo.com
  • 95.100.146.9
  • 95.100.146.17
whitelisted

Threats

PID
Process
Class
Message
1088
svchost.exe
Misc activity
ET INFO External IP Lookup Domain (ipify .org) in DNS Lookup
No debug info