| File name: | Embedit.exe |
| Full analysis: | https://app.any.run/tasks/1123c034-4f2d-464c-95cb-511a3e3392b0 |
| Verdict: | Malicious activity |
| Analysis date: | December 10, 2023, 11:26:36 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 688E3439D196B920936A08D5D70FBFA2 |
| SHA1: | C27598EF95E6C2F5E12B9F13673DD4C371D83317 |
| SHA256: | 973351C6E94EF6A171E914BFF05861091CCF76AC1F4D38A81FAA25B8E0CD8038 |
| SSDEEP: | 393216:qupm/0nLqp5bG2aVt9S0H3b/MKkUyrGOJYXv7ik4:qa9qLbGbrXb/vkgOJiik |
| .dll | | | Win32 Dynamic Link Library (generic) (38.3) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (26.2) |
| .exe | | | Win16/32 Executable Delphi generic (12) |
| .exe | | | Generic Win/DOS Executable (11.6) |
| .exe | | | DOS Executable Generic (11.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2012:11:16 23:57:03+01:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 35840 |
| InitializedDataSize: | 15872 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x393ce4 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 10.2.0.0 |
| ProductVersionNumber: | 10.2.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| CompanyName: | Brother Industries, Ltd. |
| LegalCopyright: | Copyright 1996-2016 Brother Industries, Ltd. |
| ProductName: | PE-DESIGN 10 |
| LegalTrademarks: | PE-DESIGN 10 |
| FileDescription: | Layout & Editing |
| InternalName: | Embedit.exe |
| OriginalFileName: | Embedit.exe |
| FileVersion: | 10.2.0.0 |
| ProductVersion: | 10.2.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 280 | TASKLIST | C:\Windows\SysWOW64\tasklist.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Lists the current running tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 304 | attrib +s +h "C:\Users\admin\.mysterium-node" | C:\Windows\SysWOW64\attrib.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Attribute Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 340 | FINDSTR /I "Isass.exe" | C:\Windows\SysWOW64\findstr.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Find String (QGREP) Utility Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 392 | TASKLIST | C:\Windows\SysWOW64\tasklist.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Lists the current running tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 544 | "C:\Users\admin\AppData\Local\Temp\Isass.exe" -autorun | C:\Users\admin\AppData\Local\Temp\Isass.exe | — | cmd.exe | |||||||||||
User: admin Company: Mysterium Network Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 572 | attrib +s +h "C:\Users\admin\.mysterium-bin" | C:\Windows\SysWOW64\attrib.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Attribute Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 616 | TASKLIST | C:\Windows\SysWOW64\tasklist.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Lists the current running tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 688 | TIMEOUT /T 3 | C:\Windows\SysWOW64\timeout.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: timeout - pauses command processing Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 752 | attrib +s +h .myst_node_launcher | C:\Windows\SysWOW64\attrib.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Attribute Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 924 | "C:\Users\admin\AppData\Local\Temp\Isass.exe" -autorun | C:\Users\admin\AppData\Local\Temp\Isass.exe | — | cmd.exe | |||||||||||
User: admin Company: Mysterium Network Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2780 | Embedit.exe | C:\users\admin\appdata\local\temp\.mysterium-docs\awscli\botocore\data\codedeploy\2014-10-06\waiters-2.json | binary | |
MD5:586FC5E09AF4369571A855490F6B4747 | SHA256:380441C417994D152E8B55B3B6456D527ED0DA5021DFE05E99CCE0938E793064 | |||
| 2780 | Embedit.exe | C:\users\admin\appdata\local\temp\.mysterium-docs\awscli\botocore\.changes\next-release\api-change-connect-59117.json | binary | |
MD5:008E0FC2F8B165B6C174FBFC05099B78 | SHA256:4E762394AC2FD26FE570A7ADE41D60DE1B0CD9637B17A8A1D78A56E708BDE3E7 | |||
| 2780 | Embedit.exe | C:\users\admin\appdata\local\temp\.mysterium-docs\aws.exe | executable | |
MD5:7125B6F81D48368AE803CD1A0A16A1EA | SHA256:F5936CDF78518521CD74D5F4D63E481A1E2C1665A9D8AF1313FD46C718909C78 | |||
| 2780 | Embedit.exe | C:\users\admin\appdata\local\temp\.mysterium-docs\awscli\botocore\data\codedeploy\2014-10-06\paginators-1.json | binary | |
MD5:19376E83B1D2ED5DC482F0C30C095910 | SHA256:AE2C8CBA178F5EFCE3C77940A0788868E8B453ABF694255DEB9A97E1458FA31A | |||
| 2780 | Embedit.exe | C:\users\admin\appdata\local\temp\.mysterium-docs\awscli\botocore\cacert.pem | text | |
MD5:FD09AA361BC728EB4D8C208C1EE6950B | SHA256:EC21177CB1F10F0BC3A7056ED32FF695F25893ADDC53E294288FC32F52EAF14A | |||
| 2780 | Embedit.exe | C:\users\admin\appdata\local\temp\.mysterium-docs\awscli\botocore\data\codedeploy\2014-10-06\endpoint-rule-set-1.json | text | |
MD5:7663D58ED8D107FD428A44B08E7A8380 | SHA256:C9403FFD439EC8DDD6366C4A3D5A6A165DB249A95F77733FA69A04FFCD9A4A15 | |||
| 2780 | Embedit.exe | C:\users\admin\appdata\local\temp\.mysterium-docs\awscli\botocore\data\config\2014-11-12\endpoint-rule-set-1.json | text | |
MD5:8C4AFB7EAADA7B8828D4FF936D2FD90A | SHA256:754447927B5F8F777C3D9DDF4C1D03E4C836C5A8517BF689A1A8ED10A13CCA41 | |||
| 2780 | Embedit.exe | C:\users\admin\appdata\local\temp\.mysterium-docs\awscli\botocore\data\opsworkscm\2016-11-01\endpoint-rule-set-1.json | text | |
MD5:5ABB632A177D8A679E77BEA9677729AE | SHA256:A816DBB4247DA1C68D81C32286088D6D0D36B3FA1F8ED10DE45E99FB6F96F048 | |||
| 2780 | Embedit.exe | C:\users\admin\appdata\local\temp\.mysterium-docs\awscli\botocore\data\opsworks\2013-02-18\waiters-2.json | binary | |
MD5:5618701317F62106DE766B0FA72B4311 | SHA256:D9CAE616E01D166D67D605DFADB04783FC3E6F469A08FB41897C47CE9D4DF8B2 | |||
| 2780 | Embedit.exe | C:\users\admin\appdata\local\temp\.mysterium-docs\awscli\botocore\data\opsworkscm\2016-11-01\waiters-2.json | binary | |
MD5:75CC59D984AA23B67BF978F819FAEB5C | SHA256:9D39C5B5E983EC7E1827DF4FAA650B5CD7D978D6F5F13D6CC62B505C39ED276A | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1956 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
324 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |