File name:

Q-Dir.exe

Full analysis: https://app.any.run/tasks/a32617ce-17ac-4842-b6d6-63924f19a7ef
Verdict: Malicious activity
Analysis date: October 26, 2023, 16:12:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

A8CC0A67869C905F06C1FCD5690BF9FD

SHA1:

81549DF4EE8380279DB43EDB702460BCA3FCEDB8

SHA256:

A1FC9DF1B846B44D66F5C31BDBC89F7A6728376DD90FE93E3668C402EF226E46

SSDEEP:

49152:53+ieZ9ugt7P/ISPpHSzmh0GVLvgYv3SocMrM7q9W8:5LeZ9Nt7P/Ia0G1IwiXGhJ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • Q-Dir.exe (PID: 3408)
  • SUSPICIOUS

    • Application launched itself

      • Q-Dir.exe (PID: 1884)
    • Reads the Internet Settings

      • Q-Dir.exe (PID: 1884)
  • INFO

    • Reads the computer name

      • Q-Dir.exe (PID: 1884)
      • Q-Dir.exe (PID: 3408)
    • Checks supported languages

      • Q-Dir.exe (PID: 1884)
      • Q-Dir.exe (PID: 3408)
    • Reads the machine GUID from the registry

      • Q-Dir.exe (PID: 1884)
      • Q-Dir.exe (PID: 3408)
    • Creates files or folders in the user directory

      • Q-Dir.exe (PID: 1884)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (36.8)
.exe | Win32 Executable MS Visual C++ (generic) (26.6)
.exe | Win64 Executable (generic) (23.6)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:10:21 08:07:53+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 692224
InitializedDataSize: 643072
UninitializedDataSize: -
EntryPoint: 0x9c602
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 11.4.3.0
ProductVersionNumber: 11.4.3.0
FileFlagsMask: 0x003f
FileFlags: Private build, Special build
FileOS: Win32
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Company: Nenad Hrg (SoftwareOK.de)
CompanyName: Nenad Hrg (SoftwareOK.com)
Comments: Q-Dir - the alternative Quad File Explorer for Windows
FileDescription: Q-Dir
FileInfo: Q-Dir
InternalName: Q-Dir
LegalCopyright: Copyright © Nenad Hrg (SoftwareOK.com) 2006-2023
OriginalFileName: Q-Dir.exe
ProductName: Q-Dir SoftwareOK.com
LegalTrademarks: -
ProductVersion: 11,4,3,0
FileVersion: 11,4,3,0
PrivateBuild: -
SpecialBuild: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
2
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start q-dir.exe no specs q-dir.exe

Process information

PID
CMD
Path
Indicators
Parent process
1884"C:\Users\admin\AppData\Local\Temp\Q-Dir.exe" C:\Users\admin\AppData\Local\Temp\Q-Dir.exeexplorer.exe
User:
admin
Company:
Nenad Hrg (SoftwareOK.com)
Integrity Level:
MEDIUM
Description:
Q-Dir
Exit code:
65278
Version:
11,4,3,0
Modules
Images
c:\users\admin\appdata\local\temp\q-dir.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\winspool.drv
3408"C:\Users\admin\AppData\Local\Temp\Q-Dir.exe" C:\Users\admin\AppData\Roaming\Q-Dir\start2.qdrC:\Users\admin\AppData\Local\Temp\Q-Dir.exe
Q-Dir.exe
User:
admin
Company:
Nenad Hrg (SoftwareOK.com)
Integrity Level:
HIGH
Description:
Q-Dir
Exit code:
0
Version:
11,4,3,0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\q-dir.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winspool.drv
Total events
10 357
Read events
10 208
Write events
147
Delete events
2

Modification events

(PID) Process:(1884) Q-Dir.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Explorer.EXE
(PID) Process:(1884) Q-Dir.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
(PID) Process:(1884) Q-Dir.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:MRUListEx
Value:
01000000000000000200000007000000060000000C0000000B0000000D0000000A0000000900000008000000030000000500000004000000FFFFFFFF
(PID) Process:(1884) Q-Dir.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\0\0
Operation:writeName:MRUListEx
Value:
0000000001000000FFFFFFFF
(PID) Process:(1884) Q-Dir.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU
Operation:writeName:NodeSlots
Value:
0202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202
(PID) Process:(1884) Q-Dir.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\200\Shell
Operation:writeName:SniffedFolderType
Value:
Generic
(PID) Process:(1884) Q-Dir.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\200\Shell
Operation:writeName:SniffedFolderType
Value:
Pictures
(PID) Process:(1884) Q-Dir.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1884) Q-Dir.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\34\Shell
Operation:writeName:SniffedFolderType
Value:
Generic
(PID) Process:(1884) Q-Dir.exeKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0
Operation:writeName:MRUListEx
Value:
000000000200000001000000040000000500000003000000FFFFFFFF
Executable files
0
Suspicious files
0
Text files
3
Unknown types
0

Dropped files

PID
Process
Filename
Type
1884Q-Dir.exeC:\Users\admin\AppData\Roaming\Q-Dir\Q-Dir.initext
MD5:49D5033312FBAB32316EFAB74A512E4F
SHA256:3E3C5E7C73358B34B6C055DF755B4E1E8790DB5FA8EE32240DAFEC660B4EA87F
3408Q-Dir.exeC:\Windows\Q-Dir.initext
MD5:692B277A30C37B84849DD8D3DBC88A0F
SHA256:727CB6E93977A1F03C0B8DFD80DC7BBF576411B1DF50FAD6E2BBDD71A4F78993
1884Q-Dir.exeC:\Users\admin\AppData\Roaming\Q-Dir\start2.qdrtext
MD5:94AF38DE00CDD03B1D685A2CD47F1915
SHA256:73BC6540F2FADAA727057265B564391F0F5DE9D2282C4C1306B396A8DA23A1A8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2656
svchost.exe
239.255.255.250:1900
whitelisted
1088
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info