File name:

Embedit.exe

Full analysis: https://app.any.run/tasks/1123c034-4f2d-464c-95cb-511a3e3392b0
Verdict: Malicious activity
Analysis date: December 10, 2023, 11:26:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

688E3439D196B920936A08D5D70FBFA2

SHA1:

C27598EF95E6C2F5E12B9F13673DD4C371D83317

SHA256:

973351C6E94EF6A171E914BFF05861091CCF76AC1F4D38A81FAA25B8E0CD8038

SSDEEP:

393216:qupm/0nLqp5bG2aVt9S0H3b/MKkUyrGOJYXv7ik4:qa9qLbGbrXb/vkgOJiik

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Embedit.exe (PID: 2780)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • Embedit.exe (PID: 2780)
    • The process drops C-runtime libraries

      • Embedit.exe (PID: 2780)
    • Executing commands from a ".bat" file

      • Embedit.exe (PID: 2780)
    • Starts CMD.EXE for commands execution

      • Embedit.exe (PID: 2780)
    • Starts application with an unusual extension

      • cmd.exe (PID: 996)
    • Using 'findstr.exe' to search for text patterns in files and output

      • cmd.exe (PID: 996)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 996)
    • Get information on the list of running processes

      • cmd.exe (PID: 996)
    • Uses ATTRIB.EXE to modify file attributes

      • cmd.exe (PID: 996)
  • INFO

    • Checks supported languages

      • Embedit.exe (PID: 2780)
      • chcp.com (PID: 972)
      • Isass.exe (PID: 924)
      • Isass.exe (PID: 544)
      • Isass.exe (PID: 2284)
      • Isass.exe (PID: 1104)
    • Create files in a temporary directory

      • Embedit.exe (PID: 2780)
      • Isass.exe (PID: 924)
      • Isass.exe (PID: 544)
      • Isass.exe (PID: 2284)
      • Isass.exe (PID: 1104)
    • Reads the computer name

      • Embedit.exe (PID: 2780)
      • Isass.exe (PID: 924)
      • Isass.exe (PID: 544)
      • Isass.exe (PID: 2284)
      • Isass.exe (PID: 1104)
    • The executable file from the user directory is run by the CMD process

      • Isass.exe (PID: 924)
      • Isass.exe (PID: 544)
      • Isass.exe (PID: 1104)
      • Isass.exe (PID: 2284)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (38.3)
.exe | Win32 Executable (generic) (26.2)
.exe | Win16/32 Executable Delphi generic (12)
.exe | Generic Win/DOS Executable (11.6)
.exe | DOS Executable Generic (11.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2012:11:16 23:57:03+01:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 35840
InitializedDataSize: 15872
UninitializedDataSize: -
EntryPoint: 0x393ce4
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 10.2.0.0
ProductVersionNumber: 10.2.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Brother Industries, Ltd.
LegalCopyright: Copyright 1996-2016 Brother Industries, Ltd.
ProductName: PE-DESIGN 10
LegalTrademarks: PE-DESIGN 10
FileDescription: Layout & Editing
InternalName: Embedit.exe
OriginalFileName: Embedit.exe
FileVersion: 10.2.0.0
ProductVersion: 10.2.0.0
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
78
Monitored processes
45
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start embedit.exe no specs cmd.exe no specs chcp.com no specs findstr.exe no specs tasklist.exe no specs tasklist.exe no specs findstr.exe no specs isass.exe no specs timeout.exe no specs timeout.exe no specs attrib.exe no specs attrib.exe no specs attrib.exe no specs attrib.exe no specs attrib.exe no specs tasklist.exe no specs findstr.exe no specs tasklist.exe no specs findstr.exe no specs isass.exe no specs timeout.exe no specs timeout.exe no specs attrib.exe no specs attrib.exe no specs attrib.exe no specs attrib.exe no specs attrib.exe no specs tasklist.exe no specs findstr.exe no specs tasklist.exe no specs findstr.exe no specs isass.exe no specs timeout.exe no specs timeout.exe no specs attrib.exe no specs attrib.exe no specs attrib.exe no specs attrib.exe no specs attrib.exe no specs tasklist.exe no specs findstr.exe no specs tasklist.exe no specs findstr.exe no specs isass.exe no specs timeout.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
280TASKLIST C:\Windows\SysWOW64\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
304attrib +s +h "C:\Users\admin\.mysterium-node"C:\Windows\SysWOW64\attrib.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Attribute Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\attrib.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
340FINDSTR /I "Isass.exe"C:\Windows\SysWOW64\findstr.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (QGREP) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\findstr.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
392TASKLIST C:\Windows\SysWOW64\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
544"C:\Users\admin\AppData\Local\Temp\Isass.exe" -autorunC:\Users\admin\AppData\Local\Temp\Isass.execmd.exe
User:
admin
Company:
Mysterium Network
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\isass.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
572attrib +s +h "C:\Users\admin\.mysterium-bin"C:\Windows\SysWOW64\attrib.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Attribute Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\attrib.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
616TASKLIST C:\Windows\SysWOW64\tasklist.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Lists the current running tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\tasklist.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
688TIMEOUT /T 3C:\Windows\SysWOW64\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
752attrib +s +h .myst_node_launcherC:\Windows\SysWOW64\attrib.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Attribute Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\attrib.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
924"C:\Users\admin\AppData\Local\Temp\Isass.exe" -autorunC:\Users\admin\AppData\Local\Temp\Isass.execmd.exe
User:
admin
Company:
Mysterium Network
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\isass.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
1 422
Read events
1 422
Write events
0
Delete events
0

Modification events

No data
Executable files
31
Suspicious files
30
Text files
21
Unknown types
0

Dropped files

PID
Process
Filename
Type
2780Embedit.exeC:\users\admin\appdata\local\temp\.mysterium-docs\awscli\botocore\data\codedeploy\2014-10-06\waiters-2.jsonbinary
MD5:586FC5E09AF4369571A855490F6B4747
SHA256:380441C417994D152E8B55B3B6456D527ED0DA5021DFE05E99CCE0938E793064
2780Embedit.exeC:\users\admin\appdata\local\temp\.mysterium-docs\awscli\botocore\.changes\next-release\api-change-connect-59117.jsonbinary
MD5:008E0FC2F8B165B6C174FBFC05099B78
SHA256:4E762394AC2FD26FE570A7ADE41D60DE1B0CD9637B17A8A1D78A56E708BDE3E7
2780Embedit.exeC:\users\admin\appdata\local\temp\.mysterium-docs\aws.exeexecutable
MD5:7125B6F81D48368AE803CD1A0A16A1EA
SHA256:F5936CDF78518521CD74D5F4D63E481A1E2C1665A9D8AF1313FD46C718909C78
2780Embedit.exeC:\users\admin\appdata\local\temp\.mysterium-docs\awscli\botocore\data\codedeploy\2014-10-06\paginators-1.jsonbinary
MD5:19376E83B1D2ED5DC482F0C30C095910
SHA256:AE2C8CBA178F5EFCE3C77940A0788868E8B453ABF694255DEB9A97E1458FA31A
2780Embedit.exeC:\users\admin\appdata\local\temp\.mysterium-docs\awscli\botocore\cacert.pemtext
MD5:FD09AA361BC728EB4D8C208C1EE6950B
SHA256:EC21177CB1F10F0BC3A7056ED32FF695F25893ADDC53E294288FC32F52EAF14A
2780Embedit.exeC:\users\admin\appdata\local\temp\.mysterium-docs\awscli\botocore\data\codedeploy\2014-10-06\endpoint-rule-set-1.jsontext
MD5:7663D58ED8D107FD428A44B08E7A8380
SHA256:C9403FFD439EC8DDD6366C4A3D5A6A165DB249A95F77733FA69A04FFCD9A4A15
2780Embedit.exeC:\users\admin\appdata\local\temp\.mysterium-docs\awscli\botocore\data\config\2014-11-12\endpoint-rule-set-1.jsontext
MD5:8C4AFB7EAADA7B8828D4FF936D2FD90A
SHA256:754447927B5F8F777C3D9DDF4C1D03E4C836C5A8517BF689A1A8ED10A13CCA41
2780Embedit.exeC:\users\admin\appdata\local\temp\.mysterium-docs\awscli\botocore\data\opsworkscm\2016-11-01\endpoint-rule-set-1.jsontext
MD5:5ABB632A177D8A679E77BEA9677729AE
SHA256:A816DBB4247DA1C68D81C32286088D6D0D36B3FA1F8ED10DE45E99FB6F96F048
2780Embedit.exeC:\users\admin\appdata\local\temp\.mysterium-docs\awscli\botocore\data\opsworks\2013-02-18\waiters-2.jsonbinary
MD5:5618701317F62106DE766B0FA72B4311
SHA256:D9CAE616E01D166D67D605DFADB04783FC3E6F469A08FB41897C47CE9D4DF8B2
2780Embedit.exeC:\users\admin\appdata\local\temp\.mysterium-docs\awscli\botocore\data\opsworkscm\2016-11-01\waiters-2.jsonbinary
MD5:75CC59D984AA23B67BF978F819FAEB5C
SHA256:9D39C5B5E983EC7E1827DF4FAA650B5CD7D978D6F5F13D6CC62B505C39ED276A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info