| File name: | MRT V2.60 KeyGen.exe |
| Full analysis: | https://app.any.run/tasks/978a7ce0-33f6-49f9-b491-bfcbf49fd3f5 |
| Verdict: | Malicious activity |
| Analysis date: | May 31, 2020, 02:27:28 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | MS-DOS executable, MZ for MS-DOS |
| MD5: | D2FD7DFDAAA1B8843EA48621D98C0BD7 |
| SHA1: | 066D5AFA4B09407D099CE865249D78A7016D9A47 |
| SHA256: | 93BFABEB2D294FE924F31F4CA2B244C28135AC239045EFC12FCAC1B60EAF6656 |
| SSDEEP: | 24576:PFOaEALXob0iT+kyudR9g/fm8F8JZwao3XyYVF:tj8rTFyCTbvwaYXy2 |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2013:04:01 09:08:22+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 106496 |
| InitializedDataSize: | 12288 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x290c |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| ProductName: | Project1 |
| FileVersion: | 1 |
| ProductVersion: | 1 |
| InternalName: | TJprojMain |
| OriginalFileName: | TJprojMain.exe |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 01-Apr-2013 07:08:22 |
| Detected languages: |
|
| ProductName: | Project1 |
| FileVersion: | 1.00 |
| ProductVersion: | 1.00 |
| InternalName: | TJprojMain |
| OriginalFilename: | TJprojMain.exe |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000B8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 3 |
| Time date stamp: | 01-Apr-2013 07:08:22 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x000191D4 | 0x0001A000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.7348 |
.data | 0x0001B000 | 0x0000180C | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x0001D000 | 0x000013F0 | 0x00002000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.32303 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 4.71018 | 999 | UNKNOWN | English - United States | RT_MANIFEST |
30001 | 1.6845 | 3280 | Unicode (UTF 16LE) | UNKNOWN | RT_ICON |
MSVBVM60.DLL |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1736 | c:\windows\resources\spoolsv.exe PR | c:\windows\resources\spoolsv.exe | — | svchost.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 2120 | "C:\Users\admin\AppData\Local\Temp\MRT V2.60 KeyGen.exe" | C:\Users\admin\AppData\Local\Temp\MRT V2.60 KeyGen.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Version: 1.00 Modules
| |||||||||||||||
| 2216 | "c:\users\admin\appdata\local\temp\mrt v2.60 keygen.exe " | c:\users\admin\appdata\local\temp\mrt v2.60 keygen.exe | — | MRT V2.60 KeyGen.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2300 | c:\windows\resources\spoolsv.exe SE | c:\windows\resources\spoolsv.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 2496 | C:\Windows\Resources\Themes\icsys.icn.exe | C:\Windows\Resources\Themes\icsys.icn.exe | MRT V2.60 KeyGen.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 2784 | c:\windows\resources\svchost.exe | c:\windows\resources\svchost.exe | spoolsv.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 3448 | "C:\Users\admin\AppData\Local\Temp\MRT V2.60 KeyGen.exe" | C:\Users\admin\AppData\Local\Temp\MRT V2.60 KeyGen.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 3460 | schtasks /create /tn "svchost" /tr "c:\windows\resources\svchost.exe" /sc daily /st 03:29 /f | C:\Windows\system32\schtasks.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 4088 | c:\windows\resources\themes\explorer.exe | c:\windows\resources\themes\explorer.exe | icsys.icn.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| (PID) Process: | (3448) MRT V2.60 KeyGen.exe | Key: | HKEY_CURRENT_USER\Software\VB and VBA Program Settings\Explorer\Process |
| Operation: | write | Name: | LO |
Value: 1 | |||
| (PID) Process: | (2216) mrt v2.60 keygen.exe | Key: | HKEY_CLASSES_ROOT\{1B1F4945-9568-BD7C-5DB7-BDD55EFD5534} |
| Operation: | write | Name: | {ED64A9FE-B2C3-5CBB-3775-524FBB226C0C} |
Value: 421E5465D57C7D97ACEAAEB957372A0EFFFAACFD | |||
| (PID) Process: | (2216) mrt v2.60 keygen.exe | Key: | HKEY_CURRENT_USER\Software\PeCancer\{E53D8354-0502-8E36-FD47-7E5B99C1A020} |
| Operation: | write | Name: | {ED64A9FE-B2C3-5CBB-3775-524FBB226C0C} |
Value: 421E5465D57C7D97ACEAAEB957372A0EFFFAACFD | |||
| (PID) Process: | (2216) mrt v2.60 keygen.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\{CDE6DAC4-3257-882E-C33D-FA35F0873206} |
| Operation: | write | Name: | {ED64A9FE-B2C3-5CBB-3775-524FBB226C0C} |
Value: 421E5465D57C7D97ACEAAEB957372A0EFFFAACFD | |||
| (PID) Process: | (2216) mrt v2.60 keygen.exe | Key: | HKEY_CLASSES_ROOT\{1B1F4945-9568-BD7C-5DB7-BDD55EFD5534} |
| Operation: | write | Name: | {964E496A-F0B1-5984-1501-1EBD119A19EB} |
Value: BFBC8C7BB5C5AE6ADD7D4712ABC77216A8F57BAB | |||
| (PID) Process: | (2216) mrt v2.60 keygen.exe | Key: | HKEY_CURRENT_USER\Software\PeCancer\{E53D8354-0502-8E36-FD47-7E5B99C1A020} |
| Operation: | write | Name: | {964E496A-F0B1-5984-1501-1EBD119A19EB} |
Value: BFBC8C7BB5C5AE6ADD7D4712ABC77216A8F57BAB | |||
| (PID) Process: | (2216) mrt v2.60 keygen.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\{CDE6DAC4-3257-882E-C33D-FA35F0873206} |
| Operation: | write | Name: | {964E496A-F0B1-5984-1501-1EBD119A19EB} |
Value: BFBC8C7BB5C5AE6ADD7D4712ABC77216A8F57BAB | |||
| (PID) Process: | (2216) mrt v2.60 keygen.exe | Key: | HKEY_CLASSES_ROOT\{1B1F4945-9568-BD7C-5DB7-BDD55EFD5534} |
| Operation: | write | Name: | {964E496A-F0B1-5984-1501-1EBD119A19EB} |
Value: 3E67F449DD1B7ADEC3AC2DA1CE0B694DF69BC8C7 | |||
| (PID) Process: | (2216) mrt v2.60 keygen.exe | Key: | HKEY_CURRENT_USER\Software\PeCancer\{E53D8354-0502-8E36-FD47-7E5B99C1A020} |
| Operation: | write | Name: | {964E496A-F0B1-5984-1501-1EBD119A19EB} |
Value: 3E67F449DD1B7ADEC3AC2DA1CE0B694DF69BC8C7 | |||
| (PID) Process: | (2216) mrt v2.60 keygen.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\{CDE6DAC4-3257-882E-C33D-FA35F0873206} |
| Operation: | write | Name: | {964E496A-F0B1-5984-1501-1EBD119A19EB} |
Value: 3E67F449DD1B7ADEC3AC2DA1CE0B694DF69BC8C7 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1736 | spoolsv.exe | C:\Users\admin\AppData\Local\Temp\~DF7A374AA8BD721553.TMP | — | |
MD5:— | SHA256:— | |||
| 2300 | spoolsv.exe | C:\Users\admin\AppData\Local\Temp\~DF327D74BDF932E627.TMP | — | |
MD5:— | SHA256:— | |||
| 2496 | icsys.icn.exe | C:\Users\admin\AppData\Local\Temp\~DF8576B8FF2A11E154.TMP | — | |
MD5:— | SHA256:— | |||
| 3448 | MRT V2.60 KeyGen.exe | C:\Users\admin\AppData\Local\Temp\~DF7F82C8C735904989.TMP | — | |
MD5:— | SHA256:— | |||
| 3448 | MRT V2.60 KeyGen.exe | C:\Windows\Resources\Themes\icsys.icn.exe | executable | |
MD5:04BE0069B0A2896E7178E4192FD08FBB | SHA256:2C6C84E125C7B3809B10263236DFBBC246517387E994F54D7BE01B797A20BECA | |||
| 2300 | spoolsv.exe | C:\windows\resources\svchost.exe | executable | |
MD5:E9EFC53F3DD70A7E70E2BE6C74179476 | SHA256:1D09B0D161D79916D2F854D94CA611A96D1EC1ED09B57653DAF145C8D1C7B4A9 | |||
| 2496 | icsys.icn.exe | C:\windows\resources\themes\explorer.exe | executable | |
MD5:23EB06579EED72875F0F536C8B8E72FF | SHA256:5209031B20532E7B98D7CBCD0C3B0CBAC29AD072AFC59312787CF7C4807DE2DA | |||
| 4088 | explorer.exe | C:\windows\resources\spoolsv.exe | executable | |
MD5:45D59373DEE6C9E556555E18F4F5AFB2 | SHA256:A7A6225B0C82856029CEEFC79A41E4B1EAEA0F88AB93F39CB75BCE673854BF6F | |||
| 3448 | MRT V2.60 KeyGen.exe | C:\users\admin\appdata\local\temp\mrt v2.60 keygen.exe | executable | |
MD5:B0A0C182E82862FED8E89741ABE19A1A | SHA256:AE110060C4DB3454779CCB8FA7396E485C391DCE0F0C267D97CE4F0D10713AB5 | |||