File name:

HSN21FE305X.EXE

Full analysis: https://app.any.run/tasks/3bc6ccc4-76c5-445c-ad48-821c4e6ea5c5
Verdict: Malicious activity
Analysis date: March 20, 2024, 10:53:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

959E6D23C48F43FA081396F599F0201D

SHA1:

BB717B07C96F02F078C00DE788CBF82B39CC0D6A

SHA256:

9650A7AA4B23C0B46FF5B82DD7CAD824036BEE9209F3192A47B446940ADCCFE2

SSDEEP:

49152:ssQGh7KD20hrMvtXkM2td78DC9tbZO1U+WtRzt5fykQMBQxWnxFU/Zfdbyd8GoPs:5v7KDcYxFUBfdbyd8Pe33yXzeA0Mrzw5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • HSN21FE305X.EXE.exe (PID: 3392)
    • Create files in the Startup directory

      • HSN21FE305X.EXE.exe (PID: 3392)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • HSN21FE305X.EXE.exe (PID: 3392)
    • Creates a software uninstall entry

      • HSN21FE305X.EXE.exe (PID: 3392)
  • INFO

    • Checks supported languages

      • HSN21FE305X.EXE.exe (PID: 3392)
      • Husen2K.exe (PID: 956)
    • Creates files in the program directory

      • HSN21FE305X.EXE.exe (PID: 3392)
    • Reads the computer name

      • HSN21FE305X.EXE.exe (PID: 3392)
      • Husen2K.exe (PID: 956)
    • Creates files or folders in the user directory

      • HSN21FE305X.EXE.exe (PID: 3392)
    • Create files in a temporary directory

      • HSN21FE305X.EXE.exe (PID: 3392)
    • Reads the machine GUID from the registry

      • Husen2K.exe (PID: 956)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2011:02:07 06:35:56+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 155648
InitializedDataSize: 151552
UninitializedDataSize: -
EntryPoint: 0x15061
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 5.23.0.0
ProductVersionNumber: 5.23.0.0
FileFlagsMask: 0x003f
FileFlags: Private build, Special build
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Japanese
CharacterSet: Unicode
Comments: Self Extractable Archive by EXEpress CX Copyright(C) 1998-2011 Web Technology Corp. http://www.webtech.co.jp/
FileDescription: Self Extractable Archive
FileVersion: 5.23
InternalName: EPSFX
OriginalFileName: EPSFX.EXE
ProductVersion: 5.23
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start hsn21fe305x.exe.exe husen2k.exe no specs hsn21fe305x.exe.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
956"C:\Program Files\husen2K\Husen2K.exe" C:\Program Files\husen2K\Husen2K.exeHSN21FE305X.EXE.exe
User:
admin
Company:
ROTO
Integrity Level:
HIGH
Description:
付箋紙21FE
Exit code:
0
Version:
3.0.5.2911
Modules
Images
c:\program files\husen2k\husen2k.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3392"C:\Users\admin\AppData\Local\Temp\HSN21FE305X.EXE.exe" C:\Users\admin\AppData\Local\Temp\HSN21FE305X.EXE.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Self Extractable Archive
Exit code:
0
Version:
5.23
Modules
Images
c:\users\admin\appdata\local\temp\hsn21fe305x.exe.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3992"C:\Users\admin\AppData\Local\Temp\HSN21FE305X.EXE.exe" C:\Users\admin\AppData\Local\Temp\HSN21FE305X.EXE.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Self Extractable Archive
Exit code:
3221226540
Version:
5.23
Modules
Images
c:\users\admin\appdata\local\temp\hsn21fe305x.exe.exe
c:\windows\system32\ntdll.dll
Total events
7 494
Read events
7 456
Write events
35
Delete events
3

Modification events

(PID) Process:(3392) HSN21FE305X.EXE.exeKey:HKEY_CURRENT_USER\Software\Husen2000\Config
Operation:writeName:path
Value:
C:\Program Files\husen2K\
(PID) Process:(3392) HSN21FE305X.EXE.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\husen2000
Operation:writeName:DisplayName
Value:
•tⳎ†21FE
(PID) Process:(3392) HSN21FE305X.EXE.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\husen2000
Operation:writeName:UninstallString
Value:
"C:\Program Files\husen2K\epuninst.exe" /s
(PID) Process:(3392) HSN21FE305X.EXE.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\husen2000
Operation:writeName:InstallLocation
Value:
C:\Program Files\husen2K\
(PID) Process:(3392) HSN21FE305X.EXE.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\husen2000
Operation:writeName:DisplayIcon
Value:
C:\Program Files\husen2K\Husen2K.exe,0
(PID) Process:(3392) HSN21FE305X.EXE.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\husen2000
Operation:writeName:Publisher
Value:
ROTO
(PID) Process:(3392) HSN21FE305X.EXE.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\husen2000
Operation:writeName:HelpLink
Value:
http://www.roto21.net/husen/index.html
(PID) Process:(956) Husen2K.exeKey:HKEY_CURRENT_USER\Software\Husen2000\Config
Operation:writeName:PATH
Value:
C:\Program Files\husen2K\
(PID) Process:(956) Husen2K.exeKey:HKEY_CURRENT_USER\Software\Husen2000\Config
Operation:writeName:MultiUser
Value:
1
(PID) Process:(956) Husen2K.exeKey:HKEY_CURRENT_USER\Software\Husen2000\Config
Operation:writeName:UseNetwork
Value:
0
Executable files
2
Suspicious files
5
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
3392HSN21FE305X.EXE.exeC:\Program Files\husen2K\FAQ.txttext
MD5:BD350DC0C51E02728A26E717515A0796
SHA256:E6EA0F70E20DBB85FAC0523703BDF227F68639D8704375B3C2B6C4F19D60C01B
3392HSN21FE305X.EXE.exeC:\Program Files\husen2K\History.txttext
MD5:15FEEECC04D1726C25CE2EAC99DDC295
SHA256:5E859770C75DD7E3F6C5B492FC625FE4A3A598FB380C06F664CCE93B0877F30C
3392HSN21FE305X.EXE.exeC:\Users\admin\AppData\Local\Temp\cabBF34.tmpexecutable
MD5:93B72C947554A7CF084F6C8520936275
SHA256:AB99FBBC47A664CDF04325BABD2259657B25DE614E43077989DE27408E82DF2E
3392HSN21FE305X.EXE.exeC:\Program Files\husen2K\epuninst.execompressed
MD5:0BF8B269DA5203D8D1DDB319F3151E5A
SHA256:C723F7AD4D6BDE8AFF4F5CADD15D9D50C5AB47AE4D85E4089B80D3E89B96756F
3392HSN21FE305X.EXE.exeC:\Program Files\husen2K\HUSEN2K.CHMchm
MD5:268CD8FFFBAD2C145181C5D4AC04BA41
SHA256:572474AD6EDAF107C0849635BA32CB970FB5653112267B09B010826A592FB669
3392HSN21FE305X.EXE.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\•tⳎ†21FE\•tⳎ†21.lnklnk
MD5:97B918AF017767D771F6F2795BC886C3
SHA256:83AB8E7428E5642509F2F3865D5CC6C42C275D05432277E47AEAD9A9D3AA1C29
3392HSN21FE305X.EXE.exeC:\Program Files\husen2K\Husen2K.exeexecutable
MD5:00013663C589F00353DFC1B0AF5E47BA
SHA256:E1BE961A925A3FCF6DD772523A88C6D86DE6112D4C966B6E5E16FF24B1B6B723
3392HSN21FE305X.EXE.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\•tⳎ†21FE\•tⳎ†21ƒwƒ‹ƒv.lnklnk
MD5:79885A974E27FFF9F2554CD0FBF443FC
SHA256:769252CFDF61368B160B51EF370391AD705F4E87CFDC0335F2D3646814756D59
3392HSN21FE305X.EXE.exeC:\Program Files\husen2K\husen2k.exe.manifestxml
MD5:44A55D2253AEE809F0C00CFEA3190955
SHA256:BC2FC21DA9263AC73CBA88465D0AE3D187F3A8BFE346401580E8A39145C1930D
3392HSN21FE305X.EXE.exeC:\Program Files\husen2K\README.TXTtext
MD5:93EC7A5E5C68950773B5C9703968236D
SHA256:558574DB33C930CEACA93D2EF389556F21F4CBB4CAC359410121BD5E82144FAF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info