File name:

9bc1601c1c08994fae0fc78b340b7d50464023665b780f182987589a261c9484

Full analysis: https://app.any.run/tasks/55283f2b-8d98-40e2-a6ef-ccf3d03e0eb5
Verdict: Malicious activity
Threats:

BlackMoon also known as KrBanker is a trojan aimed at stealing payment credentials. It specializes in man-in-the-browser (MitB) attacks, web injection, and credential theft to compromise users' online banking accounts. It was first noticed in early 2014 attacking banks in South Korea and has impressively evolved since by adding a number of new infiltration techniques and information stealing methods.

Analysis date: September 15, 2024, 10:01:27
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
vmprotect
blackmoon
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

DD356F0167A278B96E39D78789314B52

SHA1:

D652DA4FA7E8DD82129F8339539DA2E84E4228D8

SHA256:

9BC1601C1C08994FAE0FC78B340B7D50464023665B780F182987589A261C9484

SSDEEP:

98304:knkdiF+curL0JnGZyUV+JxcuSoSK5MVtuBNV+b0EwwO1uxGKPbBXMCtG/5hgSepr:bVaVTdZYbc8gpZxH9VU

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • BLACKMOON has been detected (YARA)

      • OGAI.PKQ (PID: 6676)
  • SUSPICIOUS

    • Starts itself from another location

      • 9bc1601c1c08994fae0fc78b340b7d50464023665b780f182987589a261c9484.exe (PID: 7052)
    • Creates file in the systems drive root

      • 9bc1601c1c08994fae0fc78b340b7d50464023665b780f182987589a261c9484.exe (PID: 7052)
      • OGAI.PKQ (PID: 6676)
    • Mutex name with non-standard characters

      • 9bc1601c1c08994fae0fc78b340b7d50464023665b780f182987589a261c9484.exe (PID: 7052)
      • OGAI.PKQ (PID: 6676)
    • Executable content was dropped or overwritten

      • 9bc1601c1c08994fae0fc78b340b7d50464023665b780f182987589a261c9484.exe (PID: 7052)
    • Starts application with an unusual extension

      • 9bc1601c1c08994fae0fc78b340b7d50464023665b780f182987589a261c9484.exe (PID: 7052)
    • Starts CMD.EXE for commands execution

      • OGAI.PKQ (PID: 6676)
    • The process executes via Task Scheduler

      • rundll32.exe (PID: 6908)
      • default-browser-agent.exe (PID: 1776)
    • Uses WMIC.EXE to obtain data on the base board management (motherboard or system board)

      • OGAI.PKQ (PID: 6676)
    • Loads DLL from Mozilla Firefox

      • default-browser-agent.exe (PID: 1776)
  • INFO

    • Reads the computer name

      • 9bc1601c1c08994fae0fc78b340b7d50464023665b780f182987589a261c9484.exe (PID: 7052)
      • OGAI.PKQ (PID: 6676)
    • Checks supported languages

      • 9bc1601c1c08994fae0fc78b340b7d50464023665b780f182987589a261c9484.exe (PID: 7052)
      • OGAI.PKQ (PID: 6676)
      • default-browser-agent.exe (PID: 1776)
    • Reads the software policy settings

      • OGAI.PKQ (PID: 6676)
    • Reads the machine GUID from the registry

      • OGAI.PKQ (PID: 6676)
    • Application launched itself

      • firefox.exe (PID: 6140)
    • VMProtect protector has been detected

      • OGAI.PKQ (PID: 6676)
    • Reads security settings of Internet Explorer

      • WMIC.exe (PID: 3112)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:03:20 14:26:23+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 1134592
InitializedDataSize: 1036288
UninitializedDataSize: -
EntryPoint: 0x7d2a3d
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
134
Monitored processes
11
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 9bc1601c1c08994fae0fc78b340b7d50464023665b780f182987589a261c9484.exe THREAT ogai.pkq cmd.exe no specs conhost.exe no specs rundll32.exe no specs default-browser-agent.exe no specs wmic.exe no specs conhost.exe no specs firefox.exe no specs firefox.exe no specs 9bc1601c1c08994fae0fc78b340b7d50464023665b780f182987589a261c9484.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1776"C:\Program Files\Mozilla Firefox\default-browser-agent.exe" do-task "308046B0AF4A39CB"C:\Program Files\Mozilla Firefox\default-browser-agent.exesvchost.exe
User:
admin
Company:
Mozilla Foundation
Integrity Level:
MEDIUM
Exit code:
2147500037
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\default-browser-agent.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\ole32.dll
3112wmic BaseBoard get SerialNumberC:\Windows\SysWOW64\wbem\WMIC.exeOGAI.PKQ
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
WMI Commandline Utility
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\wbem\wmic.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
4920"C:\Users\admin\Desktop\9bc1601c1c08994fae0fc78b340b7d50464023665b780f182987589a261c9484.exe" C:\Users\admin\Desktop\9bc1601c1c08994fae0fc78b340b7d50464023665b780f182987589a261c9484.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\9bc1601c1c08994fae0fc78b340b7d50464023665b780f182987589a261c9484.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
4976cmd /c echo t>c:\windows\system32\administratortestpermissions13708C:\Windows\SysWOW64\cmd.exeOGAI.PKQ
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
6140"C:\Program Files\Mozilla Firefox\firefox.exe" --backgroundtask defaultagent do-task 308046B0AF4A39CBC:\Program Files\Mozilla Firefox\firefox.exedefault-browser-agent.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
3
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\msvcp140.dll
c:\program files\mozilla firefox\vcruntime140.dll
c:\program files\mozilla firefox\vcruntime140_1.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
6596\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeWMIC.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6676"C:\Users\admin\Desktop\OGAI.PKQ"C:\Users\admin\Desktop\OGAI.PKQ
9bc1601c1c08994fae0fc78b340b7d50464023665b780f182987589a261c9484.exe
User:
admin
Integrity Level:
HIGH
Modules
Images
c:\users\admin\desktop\ogai.pkq
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ws2_32.dll
6828\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
6848"C:\Program Files\Mozilla Firefox\firefox.exe" --backgroundtask defaultagent do-task 308046B0AF4A39CBC:\Program Files\Mozilla Firefox\firefox.exefirefox.exe
User:
admin
Company:
Mozilla Corporation
Integrity Level:
MEDIUM
Description:
Firefox
Exit code:
3
Version:
123.0
Modules
Images
c:\program files\mozilla firefox\firefox.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\program files\mozilla firefox\mozglue.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\bcrypt.dll
c:\windows\system32\msvcp140.dll
c:\windows\system32\vcruntime140.dll
6908"C:\WINDOWS\system32\rundll32.exe" C:\WINDOWS\system32\PcaSvc.dll,PcaPatchSdbTaskC:\Windows\System32\rundll32.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shcore.dll
c:\windows\system32\imagehlp.dll
Total events
4 353
Read events
4 352
Write events
1
Delete events
0

Modification events

(PID) Process:(6848) firefox.exeKey:HKEY_CURRENT_USER\SOFTWARE\Mozilla\Firefox\DllPrefetchExperiment
Operation:writeName:C:\Program Files\Mozilla Firefox\firefox.exe
Value:
0
Executable files
1
Suspicious files
2
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
6848firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Background Tasks Profiles\93u99co2.MozillaBackgroundTask-308046B0AF4A39CB-defaultagent\datareporting\glean\db\data.safe.tmpdbf
MD5:7D3D11283370585B060D50A12715851A
SHA256:86BFF840E1BEC67B7C91F97F4D37E3A638C5FDC7B56AAE210B01745F292347B9
70529bc1601c1c08994fae0fc78b340b7d50464023665b780f182987589a261c9484.exeC:\Users\admin\Desktop\OGAI.PKQexecutable
MD5:E3EDBD03E2B7673030F8A92E4D9BCB5E
SHA256:5A16FA749D3B670B5DC18C65AB53659F2DFC1B89019E3D1E6834E031A81BCD5D
6676OGAI.PKQC:\Users\admin\Desktop\soft.initext
MD5:A90908FA1E562F9C160F178C0219EFC4
SHA256:70D7EFF2F403E4AC8578A276B7F027B50E7A1E46925617EE99D6F1936EFBC174
6848firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Background Tasks Profiles\93u99co2.MozillaBackgroundTask-308046B0AF4A39CB-defaultagent\datareporting\glean\db\data.safe.binbinary
MD5:7D3D11283370585B060D50A12715851A
SHA256:86BFF840E1BEC67B7C91F97F4D37E3A638C5FDC7B56AAE210B01745F292347B9
4976cmd.exeC:\Windows\SysWOW64\administratortestpermissions13708text
MD5:5696FEB53A6AD364E3DA313D7BB865C2
SHA256:9E8B03EA3B48312F8E3A15BEC7AA85C96A362E2776AC6BC3DFD74A40022BCC8A
6848firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Background Tasks Profiles\93u99co2.MozillaBackgroundTask-308046B0AF4A39CB-defaultagent\prefs.jstext
MD5:02F3155A6015BD1510380002A6284F1D
SHA256:CAF48F75B26DE374BA93F0C06699C2CA60898CC3969BC37998FED00CDC5D0937
6848firefox.exeC:\Users\admin\AppData\Roaming\Mozilla\Firefox\Background Tasks Profiles\93u99co2.MozillaBackgroundTask-308046B0AF4A39CB-defaultagent\prefs-1.jstext
MD5:02F3155A6015BD1510380002A6284F1D
SHA256:CAF48F75B26DE374BA93F0C06699C2CA60898CC3969BC37998FED00CDC5D0937
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
19
DNS requests
6
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6880
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
2120
MoUsoCoreWorker.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
6428
RUXIMICS.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
HEAD
200
103.235.47.188:443
https://www.baidu.com/
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
6880
svchost.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6428
RUXIMICS.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6880
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
2120
MoUsoCoreWorker.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
6428
RUXIMICS.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
6676
OGAI.PKQ
103.235.46.96:443
www.baidu.com
Beijing Baidu Netcom Science and Technology Co., Ltd.
HK
whitelisted
2120
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
6880
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 4.231.128.59
  • 20.73.194.208
whitelisted
google.com
  • 142.250.186.78
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
www.baidu.com
  • 103.235.46.96
  • 103.235.47.188
whitelisted
admin.yemanb.com
unknown

Threats

No threats detected
No debug info