File name:

netrekinstall.exe

Full analysis: https://app.any.run/tasks/5b3f3528-5f02-4f37-a9cb-c25d358602e6
Verdict: Malicious activity
Analysis date: March 10, 2024, 10:02:09
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

E53C3E2BBEC22BAF273C01D70AF09FEA

SHA1:

44F2A54B745EB2BFC60062D3BE8087829B3D392A

SHA256:

A0D34AB3B10F1E104969250DC5A341DA8647F1D748F4AB1A904DF22B43C8C1F8

SSDEEP:

98304:czv2pI9KShOKtxYKDjK5zb6HiXKKQeJX6ku/hOFXNKf2I0YZUirgHsD4i7p9w/EK:gzzFZbl/5uWAEGHLH

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • netrekinstall.exe (PID: 3660)
  • SUSPICIOUS

    • Start notepad (likely ransomware note)

      • netrekinstall.exe (PID: 3660)
    • Creates a software uninstall entry

      • netrekinstall.exe (PID: 3660)
    • Executable content was dropped or overwritten

      • netrekinstall.exe (PID: 3660)
    • Reads the Internet Settings

      • netrek.exe (PID: 1836)
  • INFO

    • Checks supported languages

      • netrekinstall.exe (PID: 3660)
      • netrek.exe (PID: 3212)
      • netrek.exe (PID: 1836)
      • netrek.exe (PID: 2208)
    • Reads the computer name

      • netrekinstall.exe (PID: 3660)
      • netrek.exe (PID: 3212)
      • netrek.exe (PID: 1836)
      • netrek.exe (PID: 2208)
    • Creates files in the program directory

      • netrek.exe (PID: 3212)
      • netrekinstall.exe (PID: 3660)
    • Manual execution by a user

      • netrek.exe (PID: 2208)
      • netrek.exe (PID: 1836)
    • Application launched itself

      • msedge.exe (PID: 2100)
      • msedge.exe (PID: 968)
      • msedge.exe (PID: 2256)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (33)
.exe | Win32 Executable MS Visual C++ (generic) (23.9)
.exe | Win64 Executable (generic) (21.2)
.scr | Windows screen saver (10)
.dll | Win32 Dynamic Link Library (generic) (5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2004:12:17 09:01:41+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 90112
InitializedDataSize: 45056
UninitializedDataSize: -
EntryPoint: 0x12ded
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.0.0.24
ProductVersionNumber: 2.0.0.24
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: -
CompanyName: -
FileDescription: -
FileVersion: 2, 0, 0, 24
InternalName: -
LegalCopyright: -
LegalTrademarks: -
OriginalFileName: -
PrivateBuild: -
ProductName: Netrek XP 2010 v1.0 Install Program
ProductVersion: 2, 0, 0, 24
SpecialBuild: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
72
Monitored processes
30
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start netrekinstall.exe notepad.exe no specs netrek.exe netrek.exe netrek.exe msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs msedge.exe no specs netrekinstall.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
392"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=2960 --field-trial-handle=1280,i,2759296458159529946,1611548967009235498,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
844"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=1556 --field-trial-handle=1280,i,2759296458159529946,1611548967009235498,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
864"C:\Windows\system32\NOTEPAD.EXE" C:\PROGRA~1\Netrek\controls.txtC:\Windows\System32\notepad.exenetrekinstall.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
884"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4032 --field-trial-handle=1280,i,2759296458159529946,1611548967009235498,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
968"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://www.netrek.org/C:\Program Files\Microsoft\Edge\Application\msedge.exenetrek.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1112"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1264 --field-trial-handle=1280,i,2759296458159529946,1611548967009235498,131072 /prefetch:2C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1172"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --mojo-platform-channel-handle=2320 --field-trial-handle=1280,i,2759296458159529946,1611548967009235498,131072 /prefetch:1C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1236"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1536 --field-trial-handle=1280,i,2759296458159529946,1611548967009235498,131072 /prefetch:3C:\Program Files\Microsoft\Edge\Application\msedge.exe
msedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1352"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1592 --field-trial-handle=1280,i,2759296458159529946,1611548967009235498,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1604"C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3444 --field-trial-handle=1280,i,2759296458159529946,1611548967009235498,131072 /prefetch:8C:\Program Files\Microsoft\Edge\Application\msedge.exemsedge.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
LOW
Description:
Microsoft Edge
Exit code:
0
Version:
109.0.1518.115
Modules
Images
c:\program files\microsoft\edge\application\msedge.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft\edge\application\109.0.1518.115\msedge_elf.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
5 272
Read events
5 225
Write events
43
Delete events
4

Modification events

(PID) Process:(3660) netrekinstall.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Netrek XP 2010 v1.0
Operation:writeName:DisplayName
Value:
Netrek XP 2010 v1.0
(PID) Process:(3660) netrekinstall.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Netrek XP 2010 v1.0
Operation:writeName:UninstallString
Value:
C:\Program Files\Netrek\Uninstall.exe
(PID) Process:(2256) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:failed_count
Value:
0
(PID) Process:(2256) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
2
(PID) Process:(2256) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
(PID) Process:(2256) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty
Operation:writeName:StatusCodes
Value:
01000000
(PID) Process:(2256) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon
Operation:writeName:state
Value:
1
(PID) Process:(2256) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}
Operation:writeName:dr
Value:
1
(PID) Process:(2256) msedge.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Edge\StabilityMetrics
Operation:writeName:user_experience_metrics.stability.exited_cleanly
Value:
0
(PID) Process:(2256) msedge.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault
Operation:writeName:S-1-5-21-1302019708-1500728564-335382590-1000
Value:
0A93C6D2E1712F00
Executable files
22
Suspicious files
177
Text files
199
Unknown types
17

Dropped files

PID
Process
Filename
Type
3660netrekinstall.exeC:\Program Files\Netrek\Uninstall.$Aexecutable
MD5:1F34142BC16A800721F6024B24132253
SHA256:EE05CF9C82C495242B6D68A9545E3F2E113E55360FE5893AA9042DF9C858C419
3660netrekinstall.exeC:\Program Files\Netrek\SDL_mixer.dllexecutable
MD5:CC3CD2330BA1FCB32662F3509E25E38C
SHA256:FCE8D4E1667717A51BF0FFED9EEFAAF5B55A7FA29011A49F8790DA9D8FAE62C3
3660netrekinstall.exeC:\Program Files\Netrek\SDL.$Aexecutable
MD5:755242AA2DAA6AD888E94B21DCAF0449
SHA256:0A48932C999FF1279C7BFA9E1117F49BF0F52CEE4077EDAF5858D28C7AF93D84
3660netrekinstall.exeC:\Program Files\Netrek\SDL_mixer.$Aexecutable
MD5:CC3CD2330BA1FCB32662F3509E25E38C
SHA256:FCE8D4E1667717A51BF0FFED9EEFAAF5B55A7FA29011A49F8790DA9D8FAE62C3
3660netrekinstall.exeC:\Program Files\Netrek\zlib1.$Aexecutable
MD5:80E41408F6D641DC1C0F5353A0CC8125
SHA256:B09537250201236472CCD3CAFF5C0C12A5FAD262E1E951350E9E5ED2A81D9DDE
3660netrekinstall.exeC:\Program Files\Netrek\bitmaps\misclib\beepliteplayerm.bmpbinary
MD5:B341F4BE3ACF8058DC9744F77891E0B4
SHA256:25B35F3830D6D2A9385B2219BF2601C12EB6EEAC55496FDA160BB6939F9DC32D
3660netrekinstall.exeC:\Program Files\Netrek\bitmaps\misclib\cloak.$Aimage
MD5:06C972B472F78D0D954D801BCEACC9D2
SHA256:38BC060D1AB8DF9C6236829F0390BBFF6EED24A2403234BAA3B54C08E43A734C
3660netrekinstall.exeC:\Program Files\Netrek\bitmaps\misclib\beepliteplayerm.$Abinary
MD5:B341F4BE3ACF8058DC9744F77891E0B4
SHA256:25B35F3830D6D2A9385B2219BF2601C12EB6EEAC55496FDA160BB6939F9DC32D
3660netrekinstall.exeC:\Program Files\Netrek\bitmaps\misclib\color\clock.bmpimage
MD5:990DA740E4BA6525D5C0343F4F3D8CEF
SHA256:5FFA68438A2147E397C8E10DE65DD36C007434416BC3E2F1719F45E4BD940B41
3660netrekinstall.exeC:\Program Files\Netrek\bitmaps\misclib\clock.$Aimage
MD5:975A0D8E7B3F2EE8399AC5417B9D72F5
SHA256:A409D0719D547C4A1FBAC78CF5E2CF19E4AB6ABEBB110CD8DB37929AB4DBEE16
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
3
TCP/UDP connections
22
DNS requests
32
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1236
msedge.exe
GET
302
63.170.91.10:80
http://www.netrek.org/
unknown
html
287 b
unknown
1236
msedge.exe
GET
302
63.170.91.10:80
http://www.netrek.org/
unknown
html
287 b
unknown
1236
msedge.exe
GET
302
63.170.91.10:80
http://www.netrek.org/
unknown
html
287 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
unknown
3212
netrek.exe
224.0.0.1:3521
unknown
1836
netrek.exe
224.0.0.1:3521
unknown
2208
netrek.exe
224.0.0.1:3521
unknown
1236
msedge.exe
204.79.197.239:443
edge.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
2256
msedge.exe
239.255.255.250:1900
unknown
1236
msedge.exe
13.107.42.16:443
config.edge.skype.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
whitelisted
1236
msedge.exe
63.170.91.10:80
www.netrek.org
REAL-TIME
US
unknown
1236
msedge.exe
63.170.91.10:443
www.netrek.org
REAL-TIME
US
unknown

DNS requests

Domain
IP
Reputation
metaserver.us.netrek.org
unknown
metaserver2.us.netrek.org
unknown
metaserver3.us.netrek.org
unknown
metaserver.servegame.org
unknown
www.netrek.org
  • 63.170.91.10
unknown
edge.microsoft.com
  • 204.79.197.239
whitelisted
config.edge.skype.com
  • 13.107.42.16
whitelisted
www.bing.com
  • 2.23.209.177
whitelisted
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com
  • 152.199.21.175
whitelisted

Threats

PID
Process
Class
Message
1080
svchost.exe
Potentially Bad Traffic
ET INFO DYNAMIC_DNS Query to a *.servegame .org Domain
No debug info