File name:

6e79997d9111751211864b4e468e390f

Full analysis: https://app.any.run/tasks/722a7e7d-9d3f-4e42-badc-287674ca0912
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: November 23, 2023, 19:17:02
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Tags:
socks5systemz
loader
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

6E79997D9111751211864B4E468E390F

SHA1:

F1CC1D2CB7CA96C79F96A514C9F2549ABADB262D

SHA256:

A04BC4D06EA0530391A2C7D1B381A9B6D23AF6965E345AE99290755C80C1D751

SSDEEP:

98304:lAZJrufNILXqMW7Y6IGD1SukGXdJ32iW6e4K9EcHCjXDr14PTbZm/v5naxPrC7Zh:wcT/We0w

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Uses Task Scheduler to run other applications

      • 6e79997d9111751211864b4e468e390f.tmp (PID: 2748)
    • Drops the executable file immediately after the start

      • AVILine.exe (PID: 2576)
      • 6e79997d9111751211864b4e468e390f.tmp (PID: 2748)
      • 6e79997d9111751211864b4e468e390f.exe (PID: 2336)
      • 6e79997d9111751211864b4e468e390f.exe (PID: 848)
    • SOCKS5SYSTEMZ has been detected (YARA)

      • AVILine.exe (PID: 1492)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • 6e79997d9111751211864b4e468e390f.tmp (PID: 2748)
    • Reads the Windows owner or organization settings

      • 6e79997d9111751211864b4e468e390f.tmp (PID: 2748)
  • INFO

    • Checks supported languages

      • 6e79997d9111751211864b4e468e390f.exe (PID: 2336)
      • 6e79997d9111751211864b4e468e390f.tmp (PID: 2748)
      • AVILine.exe (PID: 2576)
      • 6e79997d9111751211864b4e468e390f.tmp (PID: 2700)
      • AVILine.exe (PID: 1492)
      • 6e79997d9111751211864b4e468e390f.exe (PID: 848)
    • Create files in a temporary directory

      • 6e79997d9111751211864b4e468e390f.tmp (PID: 2748)
      • 6e79997d9111751211864b4e468e390f.exe (PID: 2336)
      • AVILine.exe (PID: 2576)
      • 6e79997d9111751211864b4e468e390f.exe (PID: 848)
    • Reads the computer name

      • 6e79997d9111751211864b4e468e390f.tmp (PID: 2748)
      • AVILine.exe (PID: 2576)
      • 6e79997d9111751211864b4e468e390f.tmp (PID: 2700)
    • Creates files in the program directory

      • 6e79997d9111751211864b4e468e390f.tmp (PID: 2748)
      • AVILine.exe (PID: 2576)
      • AVILine.exe (PID: 1492)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:11:23 20:08:07+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 37888
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0x9b24
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: AVILine Setup
FileVersion:
LegalCopyright:
ProductName: AVILine
ProductVersion:
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
9
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
start 6e79997d9111751211864b4e468e390f.exe no specs 6e79997d9111751211864b4e468e390f.tmp no specs 6e79997d9111751211864b4e468e390f.exe 6e79997d9111751211864b4e468e390f.tmp no specs schtasks.exe no specs aviline.exe no specs net.exe no specs #SOCKS5SYSTEMZ aviline.exe no specs net1.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
668C:\Windows\system32\net1 helpmsg 23C:\Windows\SysWOW64\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\syswow64\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
848"C:\Users\admin\AppData\Local\Temp\6e79997d9111751211864b4e468e390f.exe" /SPAWNWND=$1D01AA /NOTIFYWND=$1801C8 C:\Users\admin\AppData\Local\Temp\6e79997d9111751211864b4e468e390f.exe
6e79997d9111751211864b4e468e390f.tmp
User:
admin
Company:
Integrity Level:
HIGH
Description:
AVILine Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\6e79997d9111751211864b4e468e390f.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
1392"C:\Windows\system32\net.exe" helpmsg 23C:\Windows\SysWOW64\net.exe6e79997d9111751211864b4e468e390f.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\net.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
1492"C:\Program Files (x86)\Common Files\AVILine\AVILine.exe" -sC:\Program Files (x86)\Common Files\AVILine\AVILine.exe
6e79997d9111751211864b4e468e390f.tmp
User:
admin
Integrity Level:
HIGH
Description:
AVILine
Exit code:
0
Version:
3.4.6.3
Modules
Images
c:\program files (x86)\common files\aviline\aviline.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2204"C:\Windows\system32\schtasks.exe" /QueryC:\Windows\SysWOW64\schtasks.exe6e79997d9111751211864b4e468e390f.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\syswow64\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2336"C:\Users\admin\AppData\Local\Temp\6e79997d9111751211864b4e468e390f.exe" C:\Users\admin\AppData\Local\Temp\6e79997d9111751211864b4e468e390f.exeexplorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
AVILine Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\6e79997d9111751211864b4e468e390f.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2576"C:\Program Files (x86)\Common Files\AVILine\AVILine.exe" -iC:\Program Files (x86)\Common Files\AVILine\AVILine.exe6e79997d9111751211864b4e468e390f.tmp
User:
admin
Integrity Level:
HIGH
Description:
AVILine
Exit code:
0
Version:
3.4.6.3
Modules
Images
c:\program files (x86)\common files\aviline\aviline.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2700"C:\Users\admin\AppData\Local\Temp\is-VEMLT.tmp\6e79997d9111751211864b4e468e390f.tmp" /SL5="$1801C8,2631586,54272,C:\Users\admin\AppData\Local\Temp\6e79997d9111751211864b4e468e390f.exe" C:\Users\admin\AppData\Local\Temp\is-VEMLT.tmp\6e79997d9111751211864b4e468e390f.tmp6e79997d9111751211864b4e468e390f.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.51.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-vemlt.tmp\6e79997d9111751211864b4e468e390f.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
2748"C:\Users\admin\AppData\Local\Temp\is-PK34G.tmp\6e79997d9111751211864b4e468e390f.tmp" /SL5="$160032,2631586,54272,C:\Users\admin\AppData\Local\Temp\6e79997d9111751211864b4e468e390f.exe" /SPAWNWND=$1D01AA /NOTIFYWND=$1801C8 C:\Users\admin\AppData\Local\Temp\is-PK34G.tmp\6e79997d9111751211864b4e468e390f.tmp6e79997d9111751211864b4e468e390f.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.51.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-pk34g.tmp\6e79997d9111751211864b4e468e390f.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\system32\kernel32.dll
c:\windows\syswow64\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\syswow64\kernelbase.dll
Total events
1 674
Read events
1 674
Write events
0
Delete events
0

Modification events

No data
Executable files
26
Suspicious files
8
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
8486e79997d9111751211864b4e468e390f.exeC:\Users\admin\AppData\Local\Temp\is-PK34G.tmp\6e79997d9111751211864b4e468e390f.tmpexecutable
MD5:F507CE43EA08D1721816AD4B0E090F50
SHA256:D2218BDE27D66F28E3CAF15E899653A9357EBDC7ADF9A763B687F6C03C93E5E1
27486e79997d9111751211864b4e468e390f.tmpC:\Users\admin\AppData\Local\Temp\is-7UF83.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
27486e79997d9111751211864b4e468e390f.tmpC:\Users\admin\AppData\Local\Temp\is-7UF83.tmp\_isetup\_iscrypt.dllexecutable
MD5:A69559718AB506675E907FE49DEB71E9
SHA256:2F6294F9AA09F59A574B5DCD33BE54E16B39377984F3D5658CDA44950FA0F8FC
27486e79997d9111751211864b4e468e390f.tmpC:\Users\admin\AppData\Local\Temp\is-7UF83.tmp\_isetup\_RegDLL.tmpexecutable
MD5:0EE914C6F0BB93996C75941E1AD629C6
SHA256:4DC09BAC0613590F1FAC8771D18AF5BE25A1E1CB8FDBF4031AA364F3057E74A2
23366e79997d9111751211864b4e468e390f.exeC:\Users\admin\AppData\Local\Temp\is-VEMLT.tmp\6e79997d9111751211864b4e468e390f.tmpexecutable
MD5:F507CE43EA08D1721816AD4B0E090F50
SHA256:D2218BDE27D66F28E3CAF15E899653A9357EBDC7ADF9A763B687F6C03C93E5E1
27486e79997d9111751211864b4e468e390f.tmpC:\Program Files (x86)\Common Files\AVILine\is-06GNP.tmptext
MD5:C94B4A9A92647DF47962F849C42D91FB
SHA256:6B08A4921A930BFFBF0EA84D8D6F8257D7BD4D6948678E0A455C363DFBEBBB16
27486e79997d9111751211864b4e468e390f.tmpC:\Program Files (x86)\Common Files\AVILine\opus1.dllexecutable
MD5:1B7FB1C58EE3B29763C9F0356A2F5DFC
SHA256:FA70A865EB72E962562E526A061797FDC184C0BA970D68D07E803B2D21911FC2
27486e79997d9111751211864b4e468e390f.tmpC:\Program Files (x86)\Common Files\AVILine\is-7EO3H.tmpexecutable
MD5:1B7FB1C58EE3B29763C9F0356A2F5DFC
SHA256:FA70A865EB72E962562E526A061797FDC184C0BA970D68D07E803B2D21911FC2
27486e79997d9111751211864b4e468e390f.tmpC:\Users\admin\AppData\Local\Temp\is-7UF83.tmp\_isetup\_setup64.tmpexecutable
MD5:4FF75F505FDDCC6A9AE62216446205D9
SHA256:A4C86FC4836AC728D7BD96E7915090FD59521A9E74F1D06EF8E5A47C8695FD81
27486e79997d9111751211864b4e468e390f.tmpC:\Program Files (x86)\Common Files\AVILine\flac.dllexecutable
MD5:F3226E7F495C3BD8D93D71D970DD72FA
SHA256:FCFDACEDD3EBDE5C29B8D86C8C9BE3394E38EA523CD69885578463C49C319A52
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted
324
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info