download:

Peer2Profit.exe

Full analysis: https://app.any.run/tasks/3bd0e5b3-62b5-46bd-aeab-9885ef5770b3
Verdict: Malicious activity
Analysis date: October 16, 2021, 15:30:54
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

7CA2E2275D97B9CDDC5E412A192AC515

SHA1:

A85D33450F8287259E717BCB6E206EAF67FB869D

SHA256:

9D3152DD306C71A455FD33963E3200228991A79FF9CEF30DA6E8AE9C5FDBCFC8

SSDEEP:

393216:QcG3VLZOTokEXS9QSFhg/vKIi5Jsv6tWKFdu9CSWByhdpNcX0Fn8vEd:ILZOJES9rhg/iKWMhdvcnvEd

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • reg.exe (PID: 4032)
    • Drops executable file immediately after starts

      • cscript.exe (PID: 2360)
    • Application was dropped or rewritten from another process

      • Peer2Profit.exe (PID: 3880)
      • Peer2Profit.exe (PID: 2172)
      • Peer2Profit.exe (PID: 3064)
      • Peer2Profit.exe (PID: 2276)
      • Peer2Profit.exe (PID: 3328)
    • Starts NET.EXE for service management

      • cmd.exe (PID: 3040)
  • SUSPICIOUS

    • Application launched itself

      • Peer2Profit.exe (PID: 3716)
      • Peer2Profit.exe (PID: 2172)
    • Checks supported languages

      • Peer2Profit.exe (PID: 3716)
      • Peer2Profit.exe (PID: 1796)
      • cscript.exe (PID: 2360)
      • cscript.exe (PID: 3524)
      • Peer2Profit.exe (PID: 2172)
      • Peer2Profit.exe (PID: 3328)
      • Peer2Profit.exe (PID: 3064)
      • cmd.exe (PID: 1756)
      • cmd.exe (PID: 3040)
    • Reads the computer name

      • Peer2Profit.exe (PID: 3716)
      • Peer2Profit.exe (PID: 1796)
      • cscript.exe (PID: 3524)
      • cscript.exe (PID: 2360)
      • Peer2Profit.exe (PID: 3064)
    • Creates a directory in Program Files

      • Peer2Profit.exe (PID: 1796)
    • Executable content was dropped or overwritten

      • Peer2Profit.exe (PID: 1796)
      • cscript.exe (PID: 2360)
    • Creates files in the user directory

      • Peer2Profit.exe (PID: 1796)
    • Creates files in the program directory

      • Peer2Profit.exe (PID: 1796)
    • Uses REG.EXE to modify Windows registry

      • Peer2Profit.exe (PID: 1796)
    • Uses NETSH.EXE for network configuration

      • Peer2Profit.exe (PID: 1796)
      • cmd.exe (PID: 1756)
    • Reads Environment values

      • netsh.exe (PID: 3504)
      • netsh.exe (PID: 3428)
      • netsh.exe (PID: 3988)
      • netsh.exe (PID: 3324)
      • netsh.exe (PID: 3516)
      • netsh.exe (PID: 2276)
      • netsh.exe (PID: 240)
    • Creates a software uninstall entry

      • Peer2Profit.exe (PID: 1796)
    • Drops a file with a compile date too recent

      • Peer2Profit.exe (PID: 1796)
      • cscript.exe (PID: 2360)
    • Executes scripts

      • Peer2Profit.exe (PID: 1796)
    • Starts CMD.EXE for commands execution

      • Peer2Profit.exe (PID: 3064)
    • Reads the time zone

      • Peer2Profit.exe (PID: 3064)
  • INFO

    • Checks supported languages

      • reg.exe (PID: 4032)
      • netsh.exe (PID: 3504)
      • netsh.exe (PID: 3428)
      • netsh.exe (PID: 3988)
      • netsh.exe (PID: 3516)
      • netsh.exe (PID: 3324)
      • netsh.exe (PID: 2276)
      • netsh.exe (PID: 240)
      • net.exe (PID: 2888)
      • net1.exe (PID: 1448)
    • Reads the computer name

      • netsh.exe (PID: 3504)
      • netsh.exe (PID: 3428)
      • netsh.exe (PID: 3988)
      • netsh.exe (PID: 3324)
      • netsh.exe (PID: 3516)
      • netsh.exe (PID: 2276)
      • netsh.exe (PID: 240)
    • Checks Windows Trust Settings

      • cscript.exe (PID: 3524)
      • cscript.exe (PID: 2360)
    • Manual execution by user

      • Peer2Profit.exe (PID: 3880)
      • Peer2Profit.exe (PID: 2172)
    • Reads settings of System Certificates

      • Peer2Profit.exe (PID: 3064)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:03:10 10:58:34+01:00
PEType: PE32
LinkerVersion: 14
CodeSize: 14909952
InitializedDataSize: 6652416
UninitializedDataSize: -
EntryPoint: 0xd996cf
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 3.2.2.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileVersion: 
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
72
Monitored processes
21
Malicious processes
2
Suspicious processes
4

Behavior graph

Click at the process to see the details
start peer2profit.exe no specs peer2profit.exe reg.exe netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs netsh.exe no specs cscript.exe no specs cscript.exe peer2profit.exe no specs peer2profit.exe no specs peer2profit.exe peer2profit.exe peer2profit.exe cmd.exe no specs netsh.exe no specs netsh.exe no specs cmd.exe no specs net.exe no specs net1.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
240netsh advfirewall firewall add rule name="Peer2Profit" dir=in action=allow program="C:\Program Files\Peer2Profit\Peer2Profit.exe" enable=yes C:\Windows\system32\netsh.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
1448C:\Windows\system32\net1 stop remoteaccess" /c netsh advfirewall firewall del rule name="Peer2Profit" & netsh advfirewall firewall add rule name="Peer2Profit" dir=in action=allow program="C:\Program Files\Peer2Profit\Peer2Profit.exe enable=yes C:\Windows\system32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
1756cmd.exe /c netsh advfirewall firewall del rule name="Peer2Profit" & netsh advfirewall firewall add rule name="Peer2Profit" dir=in action=allow program="C:\Program Files\Peer2Profit\Peer2Profit.exe" enable=yes C:\Windows\system32\cmd.exePeer2Profit.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1796"C:\Users\admin\AppData\Local\Temp\Peer2Profit.exe" --startserver PRODUCTION,{aa4b457f-d429-4d00-9f7f-5513e3f6f883},{27ca5d86-7d64-41d2-8cd6-48c3cb84bf25}C:\Users\admin\AppData\Local\Temp\Peer2Profit.exe
Peer2Profit.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\peer2profit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\imm32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2172"C:\Program Files\Peer2Profit\Peer2Profit.exe" C:\Program Files\Peer2Profit\Peer2Profit.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
0.18.0.0
Modules
Images
c:\program files\peer2profit\peer2profit.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\imm32.dll
2276"C:\Program Files\Peer2Profit\Peer2Profit.exe" C:\Program Files\Peer2Profit\Peer2Profit.exePeer2Profit.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Version:
0.18.0.0
Modules
Images
c:\windows\system32\ntdll.dll
c:\program files\peer2profit\peer2profit.exe
2276netsh advfirewall firewall del rule name="Peer2Profit" C:\Windows\system32\netsh.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Network Command Shell
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\netsh.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\credui.dll
c:\windows\system32\user32.dll
2360cscript //Nologo C:\Users\admin\AppData\Local\Temp\deferredrenameNJskNu.vbsC:\Windows\system32\cscript.exe
Peer2Profit.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft � Console Based Script Host
Exit code:
0
Version:
5.8.7600.16385
Modules
Images
c:\windows\system32\cscript.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2888net stop remoteaccess" /c netsh advfirewall firewall del rule name="Peer2Profit" & netsh advfirewall firewall add rule name="Peer2Profit" dir=in action=allow program="C:\Program Files\Peer2Profit\Peer2Profit.exe enable=yes C:\Windows\system32\net.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\net.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\netutils.dll
c:\windows\system32\browcli.dll
3040cmd.exe /c "net stop remoteaccess" /c netsh advfirewall firewall del rule name="Peer2Profit" & netsh advfirewall firewall add rule name="Peer2Profit" dir=in action=allow program="C:\Program Files\Peer2Profit\Peer2Profit.exe" enable=yes C:\Windows\system32\cmd.exePeer2Profit.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\cmd.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
7 338
Read events
6 988
Write events
350
Delete events
0

Modification events

(PID) Process:(3716) Peer2Profit.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Peer2Profit.exe
(PID) Process:(3716) Peer2Profit.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\171\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3716) Peer2Profit.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3716) Peer2Profit.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3716) Peer2Profit.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3716) Peer2Profit.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1796) Peer2Profit.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Peer2Profit.exe
(PID) Process:(4032) reg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:Peer2Profit
Value:
C:\Program Files\Peer2Profit\Peer2Profit.exe --minimized
(PID) Process:(3504) netsh.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\171\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3504) netsh.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\171\52C64B7E
Operation:writeName:@%SystemRoot%\system32\dhcpqec.dll,-100
Value:
DHCP Quarantine Enforcement Client
Executable files
4
Suspicious files
4
Text files
13
Unknown types
4

Dropped files

PID
Process
Filename
Type
1796Peer2Profit.exeC:\Program Files\Peer2Profit\installerResources\io.p2p.app\0.18content.txt
MD5:
SHA256:
1796Peer2Profit.exeC:\Program Files\Peer2Profit\installerResources\io.p2p.app\0.18scripts.txt
MD5:
SHA256:
1796Peer2Profit.exeC:\Users\admin\AppData\Local\Temp\Peer2Profit.wvPSCz
MD5:
SHA256:
1796Peer2Profit.exeC:\Users\admin\AppData\Local\Temp\Peer2Profit.ORgLfQ
MD5:
SHA256:
1796Peer2Profit.exeC:\Program Files\Peer2Profit\network.xml
MD5:
SHA256:
1796Peer2Profit.exeC:\Users\admin\Desktop\Peer2Profit.lnklnk
MD5:
SHA256:
1796Peer2Profit.exeC:\Program Files\Peer2Profit\Peer2Profit.exeexecutable
MD5:
SHA256:
1796Peer2Profit.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Peer2Profit\Peer2Profit.lnklnk
MD5:
SHA256:
3716Peer2Profit.exeC:\Users\admin\AppData\Local\Temp\deferredrenamebpthNZ.vbsbinary
MD5:
SHA256:
1796Peer2Profit.exeC:\Users\admin\AppData\Local\Temp\Peer2Profit.cJZhFIexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

Domain
IP
Reputation
api.peer2profit.com
  • 172.67.195.147
  • 104.21.52.52
suspicious

Threats

No threats detected
Process
Message
Peer2Profit.exe
check crushes enable. crush path: "C:/Users/admin/AppData/Local/Peer2Profit/cache/crushes"
Peer2Profit.exe
check crushes enable. crush path: "C:/Users/admin/AppData/Local/Peer2Profit/cache/crushes"
Peer2Profit.exe
QtSingleCoreApplication: listen on local socket complete: qtsingleapp-PeerPr-ef39-1
Peer2Profit.exe
QtSingleCoreApplication: closeSocket and lock file
Peer2Profit.exe
Windows set native arguments: "-c"
Peer2Profit.exe
check crushes enable. crush path: "C:/Users/admin/AppData/Local/Peer2Profit/cache/crushes"
Peer2Profit.exe
opt: children enable
Peer2Profit.exe
Set app icon
Peer2Profit.exe
QtSingleCoreApplication: listen on local socket complete: qtsingleapp-PeerPr-ef39-1
Peer2Profit.exe
opt: child