File name:

Advanced IP Scanner.exe

Full analysis: https://app.any.run/tasks/d45649fb-c568-4ec7-8e36-54d7340a6a29
Verdict: Malicious activity
Analysis date: March 26, 2018, 02:12:51
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

131B41F613BD929B1F69A0C1F34561AB

SHA1:

80EF8200FC50864A8C25FB65C5E856C6C6DD6A92

SHA256:

A2A80866B711A541E86BC4F5964E9EA7FEA8008E1A9DF0E9A13902DCAC734463

SSDEEP:

196608:+4YDTB8ePWhnL5nmkuOB2SSaX9+PQHqnayl0+Qg+DzEnS6+mzfxlXY9h3:mDeePInL5ntu4X9+PGOf+87XYh3

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application loaded dropped or rewritten executable

      • advanced_ip_scanner.exe (PID: 3984)
    • Application was dropped or rewritten from another process

      • advanced_ip_scanner.exe (PID: 3984)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Dropped object may contain Bitcoin addresses

      • Advanced IP Scanner.exe (PID: 3424)
    • Dropped object may contain URL's

      • Advanced IP Scanner.exe (PID: 3424)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:04:02 05:20:13+02:00
PEType: PE32
LinkerVersion: 6
CodeSize: 24576
InitializedDataSize: 164864
UninitializedDataSize: 1024
EntryPoint: 0x312a
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.5.3.4
ProductVersionNumber: 2.5.3.4
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Windows, Chinese (Simplified)
Comments: Advanced IP Scanner
CompanyName: 大眼仔~旭感情无限公司
FileDescription: Advanced IP Scanner 中文版
FileVersion: 2.5.3.4
LegalCopyright: 大眼仔~旭感情无限公司(Anan)国际
LegalTrademarks: 大眼仔~旭感情无限公司
OriginalFileName: Advanced IP Scanner
ProductName: Advanced IP Scanner
ProductVersion: 2.5.3.4
dayanzaime: D

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 02-Apr-2016 03:20:13
Detected languages:
  • Chinese - PRC
  • English - United States
Comments: Advanced IP Scanner
CompanyName: 大眼仔~旭感情无限公司
FileDescription: Advanced IP Scanner 中文版
FileVersion: 2.5.3.4
LegalCopyright: 大眼仔~旭感情无限公司(Anan)国际
LegalTrademarks: 大眼仔~旭感情无限公司
OriginalFilename: Advanced IP Scanner
ProductName: Advanced IP Scanner
ProductVersion: 2.5.3.4
大眼仔~旭: www.dayanzai.me

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000C8

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 02-Apr-2016 03:20:13
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00005E66
0x00006000
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.44066
.rdata
0x00007000
0x000012A2
0x00001400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.05833
.data
0x00009000
0x00025D18
0x00000600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.18773
.ndata
0x0002F000
0x00009000
0x00000000
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
.rsrc
0x00038000
0x000070A8
0x00007200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.17661

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.21417
958
UNKNOWN
English - United States
RT_MANIFEST
2
5.17514
4264
UNKNOWN
English - United States
RT_ICON
3
5.20588
3752
UNKNOWN
English - United States
RT_ICON
4
5.15339
2216
UNKNOWN
English - United States
RT_ICON
5
3.24845
1640
UNKNOWN
English - United States
RT_ICON
6
3.13989
1384
UNKNOWN
English - United States
RT_ICON
7
4.83201
1128
UNKNOWN
English - United States
RT_ICON
8
3.45677
744
UNKNOWN
English - United States
RT_ICON
9
3.16629
296
UNKNOWN
English - United States
RT_ICON
103
2.73226
132
UNKNOWN
English - United States
RT_GROUP_ICON

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.dll
SHELL32.dll
USER32.dll
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start advanced ip scanner.exe advanced_ip_scanner.exe no specs cmd.exe no specs ipconfig.exe no specs advanced ip scanner.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2468"C:\Windows\system32\cmd.exe" C:\Windows\system32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3180"C:\Users\admin\AppData\Local\Temp\Advanced IP Scanner.exe" C:\Users\admin\AppData\Local\Temp\Advanced IP Scanner.exeexplorer.exe
User:
admin
Company:
大眼仔~旭感情无限公司
Integrity Level:
MEDIUM
Description:
Advanced IP Scanner 中文版
Exit code:
3221226540
Version:
2.5.3.4
Modules
Images
c:\users\admin\appdata\local\temp\advanced ip scanner.exe
c:\systemroot\system32\ntdll.dll
3396ipconfigC:\Windows\system32\ipconfig.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
IP Configuration Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ipconfig.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dnsapi.dll
c:\windows\system32\ws2_32.dll
3424"C:\Users\admin\AppData\Local\Temp\Advanced IP Scanner.exe" C:\Users\admin\AppData\Local\Temp\Advanced IP Scanner.exe
explorer.exe
User:
admin
Company:
大眼仔~旭感情无限公司
Integrity Level:
HIGH
Description:
Advanced IP Scanner 中文版
Exit code:
0
Version:
2.5.3.4
Modules
Images
c:\users\admin\appdata\local\temp\advanced ip scanner.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3984"C:\Users\admin\AppData\Local\Temp\Advanced IP Scanner\advanced_ip_scanner.exe" C:\Users\admin\AppData\Local\Temp\Advanced IP Scanner\advanced_ip_scanner.exeAdvanced IP Scanner.exe
User:
admin
Company:
Famatech Corp.
Integrity Level:
HIGH
Description:
Advanced IP Scanner
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\advanced ip scanner\advanced_ip_scanner.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\uxtheme.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
436
Read events
354
Write events
82
Delete events
0

Modification events

(PID) Process:(3424) Advanced IP Scanner.exeKey:HKEY_CURRENT_USER\Software\famatech\advanced_ip_scanner
Operation:writeName:locale
Value:
zh_cn
(PID) Process:(3424) Advanced IP Scanner.exeKey:HKEY_CURRENT_USER\Software\famatech\advanced_ip_scanner\Settings
Operation:writeName:check_updates
Value:
false
(PID) Process:(3424) Advanced IP Scanner.exeKey:HKEY_CURRENT_USER\Software\famatech\advanced_ip_scanner\State\CheckUpdates
Operation:writeName:LastCheck
Value:
40004400610074006500540069006D0065002800000000000000100000000000000000000000000025008100FB000000C600AD00CC0001002900
(PID) Process:(3424) Advanced IP Scanner.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(3424) Advanced IP Scanner.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(3984) advanced_ip_scanner.exeKey:HKEY_CURRENT_USER\Software\famatech\advanced_ip_scanner\State\ScanTab\Headers\0
Operation:writeName:Sort
Value:
2
(PID) Process:(3984) advanced_ip_scanner.exeKey:HKEY_CURRENT_USER\Software\famatech\advanced_ip_scanner\State\ScanTab\Headers\0
Operation:writeName:Visible
Value:
true
(PID) Process:(3984) advanced_ip_scanner.exeKey:HKEY_CURRENT_USER\Software\famatech\advanced_ip_scanner\State\ScanTab\Headers\0
Operation:writeName:Width
Value:
70
(PID) Process:(3984) advanced_ip_scanner.exeKey:HKEY_CURRENT_USER\Software\famatech\advanced_ip_scanner\State\ScanTab\Headers\1
Operation:writeName:Sort
Value:
2
(PID) Process:(3984) advanced_ip_scanner.exeKey:HKEY_CURRENT_USER\Software\famatech\advanced_ip_scanner\State\ScanTab\Headers\1
Operation:writeName:Visible
Value:
true
Executable files
17
Suspicious files
1
Text files
3
Unknown types
2

Dropped files

PID
Process
Filename
Type
3424Advanced IP Scanner.exeC:\Users\admin\AppData\Local\Temp\Advanced IP Scanner\advanced_ip_scanner_zh_cn.qmqm
MD5:
SHA256:
3424Advanced IP Scanner.exeC:\Users\admin\AppData\Local\Temp\Advanced IP Scanner\Qt5Network.dllexecutable
MD5:9DCBC6F10C658DDA550A5641AB19246D
SHA256:2D473C73E4E8DCC9E2065B7A46D96A9DD79036D62D18605E90556592CDAAC86F
3424Advanced IP Scanner.exeC:\Users\admin\AppData\Local\Temp\Advanced IP Scanner\pcre.dllexecutable
MD5:0333D07C3AC70E887C85E15DCFA56268
SHA256:DDED142693B890A56FBDECE8339AF2A3DD990E7571AEC710CA263B2A71DC957D
3424Advanced IP Scanner.exeC:\Users\admin\AppData\Local\Temp\Advanced IP Scanner\Qt5PrintSupport.dllexecutable
MD5:6BF75E28163392B65DC225B08EB005A2
SHA256:C66889BD77AB9E68B6ED541D3EF7AB137D13C5E23C58B8A6F870B1EAF6F0695A
3424Advanced IP Scanner.exeC:\Users\admin\AppData\Local\Temp\Advanced IP Scanner\ssleay32.dllexecutable
MD5:73B95CE024AFD8C4607B80E737BA9B4E
SHA256:FC9FC83D14018B1AC3ACB8FE0C6B7B5C1C9BFFDFDB30CF5EB5677D63A9A12FFC
3424Advanced IP Scanner.exeC:\Users\admin\AppData\Local\Temp\Advanced IP Scanner\Qt5Xml.dllexecutable
MD5:6CBCE9AD1938697E8329A51416321AE3
SHA256:0AFA86316BE4D6BD2EC578CB59CC1486FA808098E2564E16481D72B7ABB7D51B
3424Advanced IP Scanner.exeC:\Users\admin\AppData\Local\Temp\Advanced IP Scanner\advanced_ip_scanner_zh_tw.qmqm
MD5:1A50F283BE03EDA2F82899D171EC5F53
SHA256:0C5E83875B402B9526FAE546563DE878D342285CFC1BFC2C772078E7F2B271B6
3424Advanced IP Scanner.exeC:\Users\admin\AppData\Local\Temp\Advanced IP Scanner\details_panel_zh_tw.tplhtml
MD5:1E41F2F1C303F750C96681515894C7B4
SHA256:350321BFDAD2FD43E09E94DC59F47888B21BECA6EDAE3D23A7C90B7E246611C0
3424Advanced IP Scanner.exeC:\Users\admin\AppData\Local\Temp\Advanced IP Scanner\mac_interval_tree.txttext
MD5:AC0FBACBACE78DCDC0019700855365B8
SHA256:86015062970FBE66508604DBB7BD66DE0598112FD04C78F52DF1D666B17325C2
3424Advanced IP Scanner.exeC:\Users\admin\AppData\Local\Temp\Advanced IP Scanner\advanced_ip_scanner_console.exeexecutable
MD5:C0FCB0A8D9B525A07FAAB5C28D4485E8
SHA256:5252F6350E8057C063BB64DF684C22E71BB0371DA74AB62A455081A9E92A3D3F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info