| File name: | admtools.exe |
| Full analysis: | https://app.any.run/tasks/d660ef93-aaf0-4830-8fa3-8c20a716bda4 |
| Verdict: | Malicious activity |
| Analysis date: | December 02, 2023, 21:23:58 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | revengerat |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| MD5: | 86CA40FFE87618AD86BD49E5A9B6DA69 |
| SHA1: | B7EFD2E35262116BB1F2EB5913881166BB270952 |
| SHA256: | 9BD3D486E541B5C7E9EEC713B6162FAF97B21C0CF61A56A996F838A6F4F0BE59 |
| SSDEEP: | 6144:1qE56sobcarkvl3MH1eP/pl4pCZTZxCN:sEgcarkvc1eP/QpCVZgN |
| .exe | | | Generic CIL Executable (.NET, Mono, etc.) (63.1) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (23.8) |
| .dll | | | Win32 Dynamic Link Library (generic) (5.6) |
| .exe | | | Win32 Executable (generic) (3.8) |
| .exe | | | Generic Win/DOS Executable (1.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:03:28 09:41:22+02:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 11 |
| CodeSize: | 522752 |
| InitializedDataSize: | 1024 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x8186e |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3060 | "C:\Users\admin\Desktop\admtools.exe" | C:\Users\admin\Desktop\admtools.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3060 | admtools.exe | 45.84.227.157:50 | pex.0x01.cf | Beget LLC | RU | unknown |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
pex.0x01.cf |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Misc activity | ET INFO DNS Query for Suspicious .cf Domain |
