File name:

CENA.exe

Full analysis: https://app.any.run/tasks/f51d3087-590b-4999-a640-e55d2c02dac8
Verdict: Malicious activity
Analysis date: October 15, 2024, 08:32:21
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
autoit
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

BA4F46E2CE7C45FA7BFEECED8FD44162

SHA1:

4C15B91909514BB53DD95FB30DE9405D5B8ECA55

SHA256:

9AA3F41D8029B8469E94ECB81BDAC8843150225CB40E9309518C08AD6F368882

SSDEEP:

49152:mypBqwrT5pWicSSOhiFLaWLwV2A07JN+iuYvKr9xUQp4JghhGdBigLHkrJ1/9R9+:hpBqA/OJN+Q4RczUujvKCJuws41l0GDN

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Executes application which crashes

      • CENA.exe (PID: 1396)
  • INFO

    • Checks supported languages

      • CENA.exe (PID: 1396)
    • Reads mouse settings

      • CENA.exe (PID: 1396)
    • Create files in a temporary directory

      • CENA.exe (PID: 1396)
    • The process uses AutoIt

      • CENA.exe (PID: 1396)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | AutoIt3 compiled script executable (92.2)
.exe | Win64 Executable (generic) (4.9)
.dll | Win32 Dynamic Link Library (generic) (1.1)
.exe | Win32 Executable (generic) (0.8)
.exe | Generic Win/DOS Executable (0.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:03:07 16:08:39+00:00
ImageFileCharacteristics: No relocs, Executable, Large address aware, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 524800
InitializedDataSize: 120320
UninitializedDataSize: -
EntryPoint: 0x16310
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 3.3.6.0
ProductVersionNumber: 3.3.6.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (British)
CharacterSet: Unicode
FileDescription: -
FileVersion: 3, 3, 6, 0
CompiledScript: AutoIt v3 Script: 3, 3, 6, 0
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
132
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start THREAT cena.exe svchost.exe no specs werfault.exe

Process information

PID
CMD
Path
Indicators
Parent process
1396"C:\Users\admin\AppData\Local\Temp\CENA.exe" C:\Users\admin\AppData\Local\Temp\CENA.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221225477
Version:
3, 3, 6, 0
Modules
Images
c:\users\admin\appdata\local\temp\cena.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\psapi.dll
5084"C:\Users\admin\AppData\Local\Temp\CENA.exe" C:\Windows\SysWOW64\svchost.exeCENA.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Host Process for Windows Services
Version:
10.0.19041.1 (WinBuild.160101.0800)
6836C:\WINDOWS\SysWOW64\WerFault.exe -u -p 1396 -s 764C:\Windows\SysWOW64\WerFault.exe
CENA.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Problem Reporting
Exit code:
0
Version:
10.0.19041.3996 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\werfault.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\combase.dll
Total events
3 129
Read events
3 129
Write events
0
Delete events
0

Modification events

No data
Executable files
0
Suspicious files
7
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
6836WerFault.exeC:\ProgramData\Microsoft\Windows\WER\ReportArchive\AppCrash_CENA.exe_f256e3f81c196448ae4af54cbfb573a21a871d0_832d91a1_c2dcbb25-67a4-4a4a-8369-e8686e8ffd84\Report.wer
MD5:
SHA256:
6836WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERCC04.tmp.WERInternalMetadata.xmlxml
MD5:0D64229CFF9240DE99E940719DA1B483
SHA256:19E2AC14BA178F72D43799E3AA589458726A9FC3305DA7956267F9764BF88D20
6836WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERCA5D.tmp.dmpbinary
MD5:79533C9C02B4A91F356E5566285BBE81
SHA256:285BC9068002FCE37747E65079DAE8AE4731B96E842109B2C265E94057CF37A7
6836WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\21253908F3CB05D51B1C2DA8B681A785binary
MD5:D05D282EC3C6B89A296334A3ECF5E3A0
SHA256:FDA8F4E23D86E13137F7063807E3362303D176CE7348E7774542B971B80DDEB5
1396CENA.exeC:\Users\admin\AppData\Local\Temp\murkybinary
MD5:683EBE515BD1BC0BB538A52815BAB212
SHA256:6AF43F3F82DA63ECDFB185420819A670407E503DA78EB81E4D26BD4460162C38
6836WerFault.exeC:\ProgramData\Microsoft\Windows\WER\Temp\WERCC73.tmp.xmlxml
MD5:75C3A4ED6CF2559745203C941EF243E3
SHA256:B33494FF9E71C1B3EB3B5CCD514161921A9A65530B25F586D8EB1BFBC5BD30E1
6836WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\37C951188967C8EB88D99893D9D191FEder
MD5:F0CF5B1794ECA7CD73F9C020DAAB8EF2
SHA256:2AF00EDCE7EF3266897E52DC81E8DE3B7A079028C0F1F96EAFF9E38AD342F617
6836WerFault.exeC:\Users\admin\AppData\Local\CrashDumps\CENA.exe.1396.dmpbinary
MD5:809BC8E36855195AECFB2C2C1597C3D7
SHA256:81AD4BAA9A2630A9649A5EA1C9C1F51FB9A1B6C1FD55740AEE1A9606AEF2B6CD
6836WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\37C951188967C8EB88D99893D9D191FEbinary
MD5:1236BEF7B1C0C05C9A589B839E9F5DC3
SHA256:88ADD16A3E096E5618D270B5D9B89C521F6AAA1497EEBFA3C9B1DC14D22C7651
6836WerFault.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\21253908F3CB05D51B1C2DA8B681A785der
MD5:1B7FD5177461034E4086724C5845E927
SHA256:065AF18C229898A1C2A8D989911ADCD9B1E2AB14B1953EBF8EAF34AE37EA1627
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
11
TCP/UDP connections
62
DNS requests
25
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5588
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
US
binary
471 b
whitelisted
7532
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
NL
binary
407 b
whitelisted
5852
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
US
binary
471 b
whitelisted
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
973 b
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
2.16.164.106:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
1.01 Kb
whitelisted
5488
MoUsoCoreWorker.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
973 b
whitelisted
GET
200
2.16.164.106:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
1.01 Kb
whitelisted
6836
WerFault.exe
GET
200
2.16.164.106:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
NL
binary
1.01 Kb
whitelisted
6836
WerFault.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
NL
binary
973 b
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
US
binary
313 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6944
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4360
SearchApp.exe
2.23.209.141:443
www.bing.com
Akamai International B.V.
GB
whitelisted
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5488
MoUsoCoreWorker.exe
2.16.164.106:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
2.16.164.106:80
crl.microsoft.com
Akamai International B.V.
NL
whitelisted
5488
MoUsoCoreWorker.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
4020
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 51.124.78.146
whitelisted
www.bing.com
  • 2.23.209.141
  • 2.23.209.149
  • 2.23.209.147
  • 2.23.209.140
  • 2.23.209.135
  • 2.23.209.136
  • 2.23.209.133
  • 2.23.209.143
  • 2.23.209.144
  • 2.23.209.166
  • 2.23.209.164
  • 2.23.209.163
  • 2.23.209.161
  • 2.23.209.169
  • 2.23.209.159
  • 2.23.209.160
  • 2.23.209.167
  • 2.23.209.168
  • 2.23.209.142
  • 2.23.209.192
  • 2.23.209.130
whitelisted
crl.microsoft.com
  • 2.16.164.106
  • 2.16.164.49
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
google.com
  • 216.58.206.46
whitelisted
login.live.com
  • 40.126.32.74
  • 40.126.32.134
  • 20.190.160.17
  • 40.126.32.72
  • 40.126.32.68
  • 40.126.32.140
  • 40.126.32.76
  • 20.190.160.14
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
th.bing.com
  • 2.23.209.168
  • 2.23.209.166
  • 2.23.209.164
  • 2.23.209.163
  • 2.23.209.161
  • 2.23.209.169
  • 2.23.209.159
  • 2.23.209.160
  • 2.23.209.167
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted

Threats

No threats detected
No debug info