| File name: | file |
| Full analysis: | https://app.any.run/tasks/37b5061f-d4c0-4802-a6b9-d587e027104e |
| Verdict: | Malicious activity |
| Analysis date: | December 02, 2023, 09:10:51 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 6F5BAD34630757F92632E3691314AB90 |
| SHA1: | 66215D8C4B00C7498D62BFCC9E805F075FBE2F89 |
| SHA256: | 9C8842F212BAE9485736D671DFC506632E80D0F11DF8BF926AAED73FF48B32FF |
| SSDEEP: | 98304:QGiMhc9jyX0C0kSyA4SpshtXF2jIyXRl1oNypRagKxq98yjs34EOhpREkDJm2cxr:AyMeAGgMvwQ |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:07:02 04:09:37+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 25600 |
| InitializedDataSize: | 117760 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x3382 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 796 | "C:\Users\admin\AppData\Local\Temp\file.exe" | C:\Users\admin\AppData\Local\Temp\file.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 3028 | "C:\Users\admin\AppData\Local\Temp\file.exe" | C:\Users\admin\AppData\Local\Temp\file.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (3028) file.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3028) file.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3028) file.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3028) file.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 46000000C1000000010000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3028) file.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\SESSION MANAGER |
| Operation: | write | Name: | PendingFileRenameOperations |
Value: \??\C:\Users\admin\AppData\Local\Temp\nsq2E2F.tmp\Checker.dll | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3028 | file.exe | C:\Windows\servicing\Editions\CabInfo.dll | executable | |
MD5:7AC6E52C84F30D4A3B2F5FC8C40FDBE7 | SHA256:713A73F42AF9F45DDDFE99597E7B6186AA6CBCBA8A9214AC953EF54B8FF13F83 | |||
| 3028 | file.exe | C:\Program Files (x86)\ClocX\ClocX.exe | executable | |
MD5:2943A5A31664A8183E993D480B8709BC | SHA256:282397F5EFC6B5A517881350736901620649C3CF0A692423CF77B9093F933E8B | |||
| 3028 | file.exe | C:\Users\admin\AppData\Local\Temp\nsq2E2F.tmp\Zip.dll | executable | |
MD5:B803FA39A384FA59FC48FAF6EC082843 | SHA256:8EA882CBB8843B0020957488A030F86D1AAEE82D3908350899261853C97F6733 | |||
| 3028 | file.exe | C:\Users\admin\AppData\Local\Temp\nsg2E40.tmp | binary | |
MD5:615C251B298303A6315577A9EDCF29E7 | SHA256:BCEB71407AE4EADB38DDB7E7ED0096507F9BD292261B38DC3E159953AEE6C2B5 | |||
| 3028 | file.exe | C:\Program Files (x86)\ClocX\Lang\Bosanski.lng | binary | |
MD5:4DAD1A9BFCB103D54B06909ABB097536 | SHA256:79DBBB2DE47A367B70646DCCB4AF1DFCD56A9ADCD4959D82612CF6889B1D8CF7 | |||
| 3028 | file.exe | C:\Program Files (x86)\ClocX\BackupAlarms.bat | text | |
MD5:C8BF8F5A39C3CD41974F240DE82A0E75 | SHA256:CC51C20EF9133B8B13F5DDC0464679B81677413CF34A5B70785ABFEF857367B5 | |||
| 3028 | file.exe | C:\Program Files (x86)\ClocX\Lang\Czech.lng | binary | |
MD5:A1A459AEBED25C19F29A65E4BA95649C | SHA256:A3BFBCEF85E8317089B62B98265B052949F3B11D0B404526B51AA489C14E5649 | |||
| 3028 | file.exe | C:\Users\admin\AppData\Local\Temp\nsq2E2F.tmp\Checker.dll | executable | |
MD5:84C45156C6048B6764BD12ABE86E6497 | SHA256:4ACF888EEA6DB480C9724F1DDB587AF5680CAD6F654983097E3806FFE0FB130F | |||
| 3028 | file.exe | C:\Program Files (x86)\ClocX\Lang\Arabic.lng | binary | |
MD5:B0277FB1E01F2C417AC128A7E683B81B | SHA256:6F8806A904F7ADED9C217C8A7FA5F38F13CE0BB5F5A21E0CCB74612C9C9B3EB5 | |||
| 3028 | file.exe | C:\Program Files (x86)\ClocX\Lang\French.lng | binary | |
MD5:7767FBCDA3DB9B77F1E8FEB02172AE34 | SHA256:4FFE5D4BF560C15DB2777F0BC31652D7C733DC3CAD3B4E052B10BBD6AF65A0EC | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1956 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
324 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3028 | file.exe | 192.186.7.211:2001 | — | FEDERAL-ONLINE-GROUP-LLC | US | unknown |
3028 | file.exe | 38.6.193.13:8889 | — | — | — | unknown |
Domain | IP | Reputation |
|---|---|---|
dns.msftncsi.com |
| shared |