File name:

registry.exe

Full analysis: https://app.any.run/tasks/c4c6bf95-960c-4d2b-a058-0f1454f27a25
Verdict: Malicious activity
Analysis date: January 19, 2024, 13:59:45
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

3FCE5F36000D0EF363C92A90E17C99A6

SHA1:

44434C8D9DBF1D8CB14923C413D4F72ECF78ECD7

SHA256:

9DE53A4A78BD5D79C244C063297377442E0F20DBD6A76DEF0550AC4A9A85498A

SSDEEP:

96:r1rkyEwY7CG1mLbW+BKw4SieplPdYKIPfZYgY/ewqUaHC:hXEwkCG1mLbW+LRY5fZY9f

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Modifies files in the Chrome extension folder

      • registry.exe (PID: 128)
    • Create files in the Startup directory

      • registry.exe (PID: 128)
    • Steals credentials from Web Browsers

      • registry.exe (PID: 128)
    • Drops the executable file immediately after the start

      • registry.exe (PID: 128)
    • Actions looks like stealing of personal data

      • registry.exe (PID: 128)
  • SUSPICIOUS

    • Reads browser cookies

      • registry.exe (PID: 128)
  • INFO

    • Reads the computer name

      • registry.exe (PID: 128)
    • Checks supported languages

      • registry.exe (PID: 128)
    • Reads the machine GUID from the registry

      • registry.exe (PID: 128)
    • Creates files or folders in the user directory

      • registry.exe (PID: 128)
    • Create files in a temporary directory

      • registry.exe (PID: 128)
    • Creates files in the program directory

      • registry.exe (PID: 128)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (82.9)
.dll | Win32 Dynamic Link Library (generic) (7.4)
.exe | Win32 Executable (generic) (5.1)
.exe | Generic Win/DOS Executable (2.2)
.exe | DOS Executable Generic (2.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:01:09 15:46:28+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 4096
InitializedDataSize: 512
UninitializedDataSize: -
EntryPoint: 0x2f0e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start registry.exe

Process information

PID
CMD
Path
Indicators
Parent process
128"C:\Users\admin\AppData\Local\Temp\registry.exe" C:\Users\admin\AppData\Local\Temp\registry.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\registry.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
52
Read events
52
Write events
0
Delete events
0

Modification events

No data
Executable files
10
Suspicious files
1 811
Text files
2
Unknown types
1

Dropped files

PID
Process
Filename
Type
128registry.exeC:\Users\admin\AppData\Local\IconCache.db.FuckOff
MD5:
SHA256:
128registry.exeC:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\progressbar_blue_active_200.png.FuckOffbinary
MD5:67B3C99D5E5E93F7B49B8AABA73E78ED
SHA256:D947FE12571209ECB0C733CBFC610A6250C69EA8A113A7EBB31344FF4B57E90B
128registry.exeC:\Users\admin\ntuser.ini.FuckOffbinary
MD5:3B5662A5D3E8B120E6DA617B6FE17A96
SHA256:4D42A94CF8F8AE75EE9791A7BD9B5872C7E63CA26E7205B604418EF2ACFFD4A0
128registry.exeC:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\progressbar_blue_active_125.png.FuckOffbinary
MD5:1E18D24DC5846FA36F79D8245F5ABDCA
SHA256:D6E2B642472D17E2591307C082B9E4B8EDD1C82C0AD5371C036D007BF6E28F2C
128registry.exeC:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\progressbar_blue_active_100.png.FuckOffbinary
MD5:38454694866F1F215A3A910251E72C97
SHA256:F58CD3E06531C30F728C6F06F3663C862E9F6D836E5FC2BB7E22B8541E313BED
128registry.exeC:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\progressbar_blue_active_150.png.FuckOffbinary
MD5:FEF999AE9B4102D249E4DEB7961341C7
SHA256:704FC0F6E27DF57ED50CB058600046A421124767BEDE3F4F9CF774132608B746
128registry.exeC:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\progressbar_pole_null_100.png.FuckOffbinary
MD5:90FEB0C9B31C304073C60DBA9901C0D2
SHA256:2CE8E622EEE04A172CDC606E630D6CA3695F34969C2F7A139925F5295732A43F
128registry.exeC:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\gccheck_small.exe.FuckOffbinary
MD5:925A8F579FC8A7FB68E231DC874E5F34
SHA256:B286506AD513081F550487802698CFA7399EBD0454E2DC71FAD04D67FE0220A3
128registry.exeC:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\info_icon_100.png.FuckOffbinary
MD5:C3040A5B7A1087BD12D43DDC6519F775
SHA256:EC243872F01A9814EC394419ACDE361304383798FED947B5646532A854BC6581
128registry.exeC:\Users\admin\AppData\Local\GDIPFONTCACHEV1.DAT.FuckOffbinary
MD5:0AE6FF0D32691B845C93E33DEB0EB745
SHA256:8A86A4D71F4FC38BE1A92274FE01D1935E715A82506F24CDC80CCA1CC2D89C67
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info