| File name: | PennyBee.exe |
| Full analysis: | https://app.any.run/tasks/3eb9e5aa-e932-4167-be12-3c3739303717 |
| Verdict: | Malicious activity |
| Analysis date: | February 20, 2024, 03:35:20 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | CE82328636D917085664F07AE6767EF5 |
| SHA1: | 71DDC153477522370420C4AB0FD2479AA996C2DC |
| SHA256: | A304949D56D4664B807A02D60243122DD59804F1AE0BBD49AFD02B189CA1DDDC |
| SSDEEP: | 24576:gAI6AqbWn4JIpinBu6cawNouAufc6Udx2SR9U0J0oRgNgjDUztYXnVe72896LFtC:jI6AqbWn4JIpinBu6cawNLAufc6Udx2P |
| .exe | | | NSIS - Nullsoft Scriptable Install System (94.8) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (3.4) |
| .dll | | | Win32 Dynamic Link Library (generic) (0.7) |
| .exe | | | Win32 Executable (generic) (0.5) |
| .exe | | | Generic Win/DOS Executable (0.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2009:06:06 21:41:54+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 23552 |
| InitializedDataSize: | 119808 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x323c |
| OSVersion: | 4 |
| ImageVersion: | 6.1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.0.0.0 |
| ProductVersionNumber: | 3.0.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | ASCII |
| CompanyName: | lyricsgizm |
| FileDescription: | Main Installer |
| FileVersion: | 3.0.0.0 |
| LegalCopyright: | Copyright lyricsgizm |
| ProductName: | Installer |
| ProductVersion: | 3.0.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1780 | C:\ProgramData\lyricsgizm\lyricsgizm.exe | C:\ProgramData\lyricsgizm\lyricsgizm.exe | PennyBee.exe | ||||||||||||
User: admin Company: Video Song Gizmos Agent Integrity Level: HIGH Exit code: 0 Version: 1.1.0.12 Modules
| |||||||||||||||
| 1836 | "C:\Users\admin\Desktop\PennyBee.exe" | C:\Users\admin\Desktop\PennyBee.exe | explorer.exe | ||||||||||||
User: admin Company: lyricsgizm Integrity Level: HIGH Description: Main Installer Exit code: 0 Version: 3.0.0.0 Modules
| |||||||||||||||
| 2432 | C:\ProgramData\lyricsgizm\lyricsgizm.exe /task=4 /InstallOn=0 /closebr=0 /active=24 /update=24 /interval=2880 /pubId=1001 /affId=10010047 /appId=111 /uId={48256522-66D1-4197-8D11-28FBCF0BF061} /version=3.0.0.0 /Override=false /IEhome=0 /IEsearch=0 /FFhome=0 /FFsearch=0 /CHhome=0 /CHsearch=0 /FFaddon= /CHaddon= /AutoSP= /regAppName=lyricsgizm /curSID=S-1-5-21-1302019708-1500728564-335382590-1000 /logf=C:\Users\admin\AppData\Local\Temp\lyricsgizm_installer_{48256522-66D1-4197-8D11-28FBCF0BF061}_1708400145.txt /chPol=0 /mac=12A9866C77DE /tst=None | C:\ProgramData\lyricsgizm\lyricsgizm.exe | taskeng.exe | ||||||||||||
User: SYSTEM Company: Video Song Gizmos Agent Integrity Level: SYSTEM Exit code: 0 Version: 1.1.0.12 Modules
| |||||||||||||||
| 2568 | "C:\ProgramData\lyricsgizm\lyricsgizm.exe" /InstallOn=0 /closebr=0 /active=24 /update=24 /interval=2880 /pubId=1001 /affId=10010047 /appId=111 /uId={48256522-66D1-4197-8D11-28FBCF0BF061} /version=3.0.0.0 /Override=true /Firstime=1 /IEhome=0 /IEsearch=0 /FFhome=0 /FFsearch=0 /CHhome=0 /CHsearch=0 /FFaddon= /CHaddon= /AutoSP= /regAppName=lyricsgizm /curSID=S-1-5-21-1302019708-1500728564-335382590-1000 /logf=C:\Users\admin\AppData\Local\Temp\lyricsgizm_installer_{48256522-66D1-4197-8D11-28FBCF0BF061}_1708400171.txt /chPol=0 /mac=12A9866C77DE /tst=None | C:\ProgramData\lyricsgizm\lyricsgizm.exe | PennyBee.exe | ||||||||||||
User: admin Company: Video Song Gizmos Agent Integrity Level: HIGH Exit code: 0 Version: 1.1.0.12 Modules
| |||||||||||||||
| 2616 | C:\ProgramData\lyricsgizm\lyricsgizm.exe /task=4 /InstallOn=0 /closebr=0 /active=24 /update=24 /interval=2880 /pubId=1001 /affId=10010047 /appId=111 /uId={48256522-66D1-4197-8D11-28FBCF0BF061} /version=3.0.0.0 /Override=true /IEhome=0 /IEsearch=0 /FFhome=0 /FFsearch=0 /CHhome=0 /CHsearch=0 /FFaddon= /CHaddon= /AutoSP= /regAppName=lyricsgizm /curSID=S-1-5-21-1302019708-1500728564-335382590-1000 /logf=C:\Users\admin\AppData\Local\Temp\lyricsgizm_installer_{48256522-66D1-4197-8D11-28FBCF0BF061}_1708400171.txt /chPol=0 /mac=12A9866C77DE /tst=None | C:\ProgramData\lyricsgizm\lyricsgizm.exe | taskeng.exe | ||||||||||||
User: SYSTEM Company: Video Song Gizmos Agent Integrity Level: SYSTEM Exit code: 0 Version: 1.1.0.12 Modules
| |||||||||||||||
| 2772 | "C:\Users\admin\Desktop\PennyBee.exe" | C:\Users\admin\Desktop\PennyBee.exe | explorer.exe | ||||||||||||
User: admin Company: lyricsgizm Integrity Level: HIGH Description: Main Installer Exit code: 0 Version: 3.0.0.0 Modules
| |||||||||||||||
| 2892 | "C:\ProgramData\lyricsgizm\lyricsgizm.exe" /InstallOn=0 /closebr=0 /active=24 /update=24 /interval=2880 /pubId=1001 /affId=10010047 /appId=111 /uId={48256522-66D1-4197-8D11-28FBCF0BF061} /version=3.0.0.0 /Override=false /Firstime=1 /IEhome=0 /IEsearch=0 /FFhome=0 /FFsearch=0 /CHhome=0 /CHsearch=0 /FFaddon= /CHaddon= /AutoSP= /regAppName=lyricsgizm /curSID=S-1-5-21-1302019708-1500728564-335382590-1000 /logf=C:\Users\admin\AppData\Local\Temp\lyricsgizm_installer_{48256522-66D1-4197-8D11-28FBCF0BF061}_1708400145.txt /chPol=0 /mac=12A9866C77DE /tst=None | C:\ProgramData\lyricsgizm\lyricsgizm.exe | PennyBee.exe | ||||||||||||
User: admin Company: Video Song Gizmos Agent Integrity Level: HIGH Exit code: 0 Version: 1.1.0.12 Modules
| |||||||||||||||
| 3668 | "C:\Users\admin\Desktop\PennyBee.exe" | C:\Users\admin\Desktop\PennyBee.exe | — | explorer.exe | |||||||||||
User: admin Company: lyricsgizm Integrity Level: MEDIUM Description: Main Installer Exit code: 3221226540 Version: 3.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (1836) PennyBee.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (1836) PennyBee.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyServer |
Value: | |||
| (PID) Process: | (1836) PennyBee.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyOverride |
Value: | |||
| (PID) Process: | (1836) PennyBee.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | AutoConfigURL |
Value: | |||
| (PID) Process: | (1836) PennyBee.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | AutoDetect |
Value: | |||
| (PID) Process: | (1836) PennyBee.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005C010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1836) PennyBee.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1836) PennyBee.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1836) PennyBee.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1836) PennyBee.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1836 | PennyBee.exe | C:\Users\admin\AppData\Local\Temp\nsvEA3.tmp\System.dll | executable | |
MD5:00A0194C20EE912257DF53BFE258EE4A | SHA256:DC4DA2CCADB11099076926B02764B2B44AD8F97CD32337421A4CC21A3F5448F3 | |||
| 1836 | PennyBee.exe | C:\Users\admin\AppData\Local\Temp\lyricsgizm_installer_{48256522-66D1-4197-8D11-28FBCF0BF061}_1708400145.txt | text | |
MD5:691D519A1F09EDF16E685DAF5482D4D2 | SHA256:44A861F5315FEC45E70D2297A83C56D80913CED5288ECE0C8BF28FF737C3232F | |||
| 1836 | PennyBee.exe | C:\Users\admin\AppData\LocalLow\lyricsgizm\content\dgapi.js | text | |
MD5:4255E16EB6203B8841CA19C6E60601CC | SHA256:E5452CC27BF7A867BFD8FE6D88DC84E9C989EE54EECC66BA130CD93DDD942E2D | |||
| 1836 | PennyBee.exe | C:\Users\admin\AppData\Local\Temp\nsvEA3.tmp\StdUtils.dll | executable | |
MD5:21010DF9BC37DAFFCC0B5AE190381D85 | SHA256:0EBD62DE633FA108CF18139BE6778FA560680F9F8A755E41C6AB544AB8DB5C16 | |||
| 1836 | PennyBee.exe | C:\Users\admin\AppData\Local\Temp\nsvEA3.tmp\nsisos.dll | executable | |
MD5:69806691D649EF1C8703FD9E29231D44 | SHA256:BA79AB7F63F02ED5D5D46B82B11D97DAC5B7EF7E9B9A4DF926B43CEAC18483B6 | |||
| 1836 | PennyBee.exe | C:\Users\admin\AppData\Local\Temp\nsvEA3.tmp\InstallerUtils.dll | executable | |
MD5:9CFE9C3909B80653D530377226928B73 | SHA256:F84402D3905A2C104DF84827BA6C94F42D689CBBA7E251B46036030CAC94B25A | |||
| 1836 | PennyBee.exe | C:\ProgramData\lyricsgizm\lyricsgizmutil.dll | executable | |
MD5:46F39C128A247353360058ED6CB2A20D | SHA256:49E3CCAD13408316DFC8952C5211B58298DF5B6FDFCC3B5608AA0E97562536EB | |||
| 1836 | PennyBee.exe | C:\Users\admin\AppData\Local\Temp\nsvEA3.tmp\UserInfo.dll | executable | |
MD5:7579ADE7AE1747A31960A228CE02E666 | SHA256:564C80DEC62D76C53497C40094DB360FF8A36E0DC1BDA8383D0F9583138997F5 | |||
| 1836 | PennyBee.exe | C:\ProgramData\lyricsgizm\logo.ico | image | |
MD5:9B4521D6FBAED9652986A538ABFBDDD4 | SHA256:5F5EFF0B19B3AAA79001F7063FA9916D5700538878312CE90F3D1834FE4423B2 | |||
| 1836 | PennyBee.exe | C:\ProgramData\lyricsgizm\Uninstaller.exe | executable | |
MD5:E4679FC77490E4DD89634C91ECEBCE81 | SHA256:D3389D920F2268CA382A6924A85CB71D3DC8DB99F19AAC3777A1F59D47B10E7A | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
ws.xcodelib.net |
| unknown |
s.xcodelib.net |
| unknown |
Process | Message |
|---|---|
lyricsgizm.exe | 02/20/24 03:35:55 (6906) -~- ProccesId: 2892, ThreadId: 2408 -~- SendStats -~- ws.xcodelib.net/ytlyrics/bho/report.php?type=install&sch=4&affId=10010047&pubId=1001&appId=111&agver=1.1.0.12&fferr=scss&chrerr=scss&guid={48256522-66D1-4197-8D11-28FBCF0BF061}&override=false&affIdLast=none&os=6.1&manu=&ff=115.0.2 (x86 en-US)&ch=109.0.5414.120&ie=11.0.9600.19596&mac=12A9866C77DE&newagnt=0&sltm=0&wktm=26<m=20_02_03_35_55&tst=none&x=112
|
lyricsgizm.exe | 02/20/24 03:35:55 (6906) -~- ProccesId: 2892, ThreadId: 2408 -~- OnInitDialog -~- Starting agent process cmdline: "C:\ProgramData\lyricsgizm\lyricsgizm.exe" /InstallOn=0 /closebr=0 /active=24 /update=24 /interval=2880 /pubId=1001 /affId=10010047 /appId=111 /uId={48256522-66D1-4197-8D11-28FBCF0BF061} /version=3.0.0.0 /Override=false /Firstime=1 /IEhome=0 /IEsearch=0 /FFhome=0 /FFsearch=0 /CHhome=0 /CHsearch=0 /FFaddon= /CHaddon= /AutoSP= /regAppName=lyricsgizm /curSID=S-1-5-21-1302019708-1500728564-335382590-1000 /logf=C:\Users\admin\AppData\Local\Temp\lyricsgizm_installer_{48256522-66D1-4197-8D11-28FBCF0BF061}_1708400145.txt /chPol=0 /mac=12A9866C77DE /tst=None
|
lyricsgizm.exe | 02/20/24 03:35:55 (6906) -~- ProccesId: 2892, ThreadId: 2408 -~- OnInitDialog -~- First time running
|
lyricsgizm.exe | 02/20/24 03:35:55 (6906) -~- ProccesId: 2892, ThreadId: 2408 -~- FirstTimeStat -~- Install starting, sending stats
|
lyricsgizm.exe | 02/20/24 03:36:01 (13656) -~- ProccesId: 2892, ThreadId: 2408 -~- SendStats -~- Error 12007 encountered at: Error 0x2ee7 at Failed HttpSendRequest
|
lyricsgizm.exe | 02/20/24 03:36:01 (13656) -~- ProccesId: 2892, ThreadId: 2408 -~- UpdateRegistryFromArguments -~- Updating registry
|
lyricsgizm.exe | 02/20/24 03:36:01 (13656) -~- ProccesId: 2892, ThreadId: 2408 -~- StartWorkerTasks -~- Starting tasks
|
lyricsgizm.exe | 02/20/24 03:36:06 (17984) -~- ProccesId: 2892, ThreadId: 2408 -~- SendStats -~- ws.xcodelib.net/ytlyrics/bho/report.php?type=install_end&affId=10010047&pubId=1001&appId=111&agver=1.1.0.12&fferr=scss&chrerr=scss&guid={48256522-66D1-4197-8D11-28FBCF0BF061}&override=false&affIdLast=none&os=6.1&manu=&ff=115.0.2 (x86 en-US)&ch=109.0.5414.120&ie=11.0.9600.19596&mac=12A9866C77DE&newagnt=0&sltm=0&wktm=26<m=20_02_03_36_06&tst=none&x=112
|
lyricsgizm.exe | 02/20/24 03:36:06 (17984) -~- ProccesId: 2892, ThreadId: 2408 -~- EndInstallStat -~- Install finished, sending stats
|
lyricsgizm.exe | 02/20/24 03:36:06 (17984) -~- ProccesId: 2892, ThreadId: 2408 -~- SetTaskComment -~- Comment is: {"regs":{"ffErr":""}}
|