File name:

processhacker-3.0.3477-setup.exe

Full analysis: https://app.any.run/tasks/7066ebe6-d364-4ca4-b501-5443a87f87df
Verdict: Malicious activity
Analysis date: October 23, 2020, 20:58:27
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

76FE9E01C6A3FF99A933761C98608AD9

SHA1:

D84322B560938E3C8D6E00E06921D12739B78D55

SHA256:

A7E190E9638E8402B3CB7E65F5B2156AACCC63A509DD1F328D5083940919B0A1

SSDEEP:

49152:nUX80JS/bqKBlysEzG1eK+A/ZfAjZPZ0Zd4hWy2qctMjxBQUcldTc7D6RGdXIf9+:nUXt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • ProcessHacker.exe (PID: 4004)
    • Loads dropped or rewritten executable

      • ProcessHacker.exe (PID: 4004)
    • Changes settings of System certificates

      • ProcessHacker.exe (PID: 4004)
  • SUSPICIOUS

    • Application launched itself

      • processhacker-3.0.3477-setup.exe (PID: 2656)
    • Executable content was dropped or overwritten

      • processhacker-3.0.3477-setup.exe (PID: 2924)
    • Creates files in the program directory

      • processhacker-3.0.3477-setup.exe (PID: 2924)
    • Creates a software uninstall entry

      • processhacker-3.0.3477-setup.exe (PID: 2924)
    • Adds / modifies Windows certificates

      • ProcessHacker.exe (PID: 4004)
  • INFO

    • Reads settings of System Certificates

      • ProcessHacker.exe (PID: 4004)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2037:12:16 01:24:23+01:00
PEType: PE32
LinkerVersion: 14.27
CodeSize: 171520
InitializedDataSize: 8640512
UninitializedDataSize: -
EntryPoint: 0x13f10
OSVersion: 6.1
ImageVersion: -
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 3.0.8004.3477
ProductVersionNumber: 3.0.8004.3477
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (Australian)
CharacterSet: Unicode
CompanyName: Process Hacker
FileDescription: Process Hacker - Setup
FileVersion: 3.0.8004.3477
InternalName: processhacker-setup.exe
LegalCopyright: Licensed under the GNU GPL, v3. Copyright (C) 2017
OriginalFileName: processhacker-setup.exe
ProductName: Process Hacker
ProductVersion: 3.0.8004.3477

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 16-Dec-2037 00:24:23
Detected languages:
  • English - Australia
  • English - United States
Debug artifacts:
  • CustomSetupTool.pdb
CompanyName: Process Hacker
FileDescription: Process Hacker - Setup
FileVersion: 3.0.8004.3477
InternalName: processhacker-setup.exe
LegalCopyright: Licensed under the GNU GPL, v3. Copyright (C) 2017
OriginalFilename: processhacker-setup.exe
ProductName: Process Hacker
ProductVersion: 3.0.8004.3477

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x00000108

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 6
Time date stamp: 16-Dec-2037 00:24:23
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00029C7D
0x00029E00
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.65036
.rdata
0x0002B000
0x00026DA4
0x00026E00
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
6.4343
.data
0x00052000
0x00002268
0x00001000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
2.15213
.didat
0x00055000
0x000000A8
0x00000200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
1.49479
.rsrc
0x00056000
0x00812038
0x00812200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
6.08258
.reloc
0x00869000
0x000021C8
0x00002200
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ
6.64501

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.19222
2841
UNKNOWN
English - United States
RT_MANIFEST
2
3.80858
744
UNKNOWN
English - Australia
RT_ICON
3
3.29425
488
UNKNOWN
English - Australia
RT_ICON
4
3.1653
296
UNKNOWN
English - Australia
RT_ICON
5
5.5254
3752
UNKNOWN
English - Australia
RT_ICON
6
6.002
2216
UNKNOWN
English - Australia
RT_ICON
7
5.2012
1736
UNKNOWN
English - Australia
RT_ICON
8
2.89511
1384
UNKNOWN
English - Australia
RT_ICON
9
7.94638
67507
UNKNOWN
English - Australia
RT_ICON
10
5.27113
9640
UNKNOWN
English - Australia
RT_ICON

Imports

COMCTL32.dll (delay-loaded)
COMDLG32.dll
KERNEL32.dll
ntdll.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
40
Monitored processes
3
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start drop and start processhacker-3.0.3477-setup.exe no specs processhacker-3.0.3477-setup.exe processhacker.exe

Process information

PID
CMD
Path
Indicators
Parent process
2656"C:\Users\admin\AppData\Local\Temp\processhacker-3.0.3477-setup.exe" C:\Users\admin\AppData\Local\Temp\processhacker-3.0.3477-setup.exeexplorer.exe
User:
admin
Company:
Process Hacker
Integrity Level:
MEDIUM
Description:
Process Hacker - Setup
Exit code:
0
Version:
3.0.8004.3477
Modules
Images
c:\users\admin\appdata\local\temp\processhacker-3.0.3477-setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
2924"C:\Users\admin\AppData\Local\Temp\processhacker-3.0.3477-setup.exe" "C:\Users\admin\AppData\Local\Temp\processhacker-3.0.3477-setup.exe" C:\Users\admin\AppData\Local\Temp\processhacker-3.0.3477-setup.exe
processhacker-3.0.3477-setup.exe
User:
admin
Company:
Process Hacker
Integrity Level:
HIGH
Description:
Process Hacker - Setup
Exit code:
0
Version:
3.0.8004.3477
Modules
Images
c:\users\admin\appdata\local\temp\processhacker-3.0.3477-setup.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
4004"C:\Program Files\Process Hacker\ProcessHacker.exe" C:\Program Files\Process Hacker\ProcessHacker.exe
processhacker-3.0.3477-setup.exe
User:
admin
Company:
Process Hacker
Integrity Level:
HIGH
Description:
Process Hacker
Exit code:
0
Version:
3.0.8004.3477
Modules
Images
c:\program files\process hacker\processhacker.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
852
Read events
822
Write events
30
Delete events
0

Modification events

(PID) Process:(2656) processhacker-3.0.3477-setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2656) processhacker-3.0.3477-setup.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2924) processhacker-3.0.3477-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ProcessHacker
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Process Hacker\processhacker.exe,0
(PID) Process:(2924) processhacker-3.0.3477-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ProcessHacker
Operation:writeName:DisplayName
Value:
Process Hacker
(PID) Process:(2924) processhacker-3.0.3477-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ProcessHacker
Operation:writeName:DisplayVersion
Value:
3.x
(PID) Process:(2924) processhacker-3.0.3477-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ProcessHacker
Operation:writeName:HelpLink
Value:
https://processhacker.sourceforge.io/
(PID) Process:(2924) processhacker-3.0.3477-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ProcessHacker
Operation:writeName:InstallLocation
Value:
C:\Program Files\Process Hacker\
(PID) Process:(2924) processhacker-3.0.3477-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ProcessHacker
Operation:writeName:Publisher
Value:
Process Hacker
(PID) Process:(2924) processhacker-3.0.3477-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ProcessHacker
Operation:writeName:UninstallString
Value:
"C:\Program Files\Process Hacker\\processhacker-setup.exe" -uninstall
(PID) Process:(2924) processhacker-3.0.3477-setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\ProcessHacker
Operation:writeName:NoModify
Value:
1
Executable files
15
Suspicious files
1
Text files
5
Unknown types
3

Dropped files

PID
Process
Filename
Type
2924processhacker-3.0.3477-setup.exeC:\Users\Public\Desktop\Process Hacker.lnklnk
MD5:
SHA256:
2924processhacker-3.0.3477-setup.exeC:\Program Files\Process Hacker\processhacker-setup.exeexecutable
MD5:
SHA256:
2924processhacker-3.0.3477-setup.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\Process Hacker.lnklnk
MD5:
SHA256:
2924processhacker-3.0.3477-setup.exeC:\ProgramData\Microsoft\Windows\Start Menu\Programs\PE Viewer.lnklnk
MD5:
SHA256:
2924processhacker-3.0.3477-setup.exeC:\Program Files\Process Hacker\README.txttext
MD5:7F666192140C92A8602585972AD40D4B
SHA256:8141740E4F31D3252530287B715AD80703D665E53CB0C437025754C6ACAA9F38
2924processhacker-3.0.3477-setup.exeC:\Program Files\Process Hacker\COPYRIGHT.txttext
MD5:39B07060A5C6199730219E29C747C061
SHA256:319CD301CF40BE03C00CD086560D4E810E0F6D0DBFDC2D28D6AF3522C027CF49
2924processhacker-3.0.3477-setup.exeC:\Program Files\Process Hacker\ProcessHacker.sigbinary
MD5:
SHA256:
2924processhacker-3.0.3477-setup.exeC:\Program Files\Process Hacker\plugins\DotNetTools.dllexecutable
MD5:
SHA256:
2924processhacker-3.0.3477-setup.exeC:\Program Files\Process Hacker\plugins\HardwareDevices.dllexecutable
MD5:
SHA256:
2924processhacker-3.0.3477-setup.exeC:\Program Files\Process Hacker\plugins\ExtendedServices.dllexecutable
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4004
ProcessHacker.exe
162.243.25.33:443
wj32.org
Digital Ocean, Inc.
US
suspicious

DNS requests

Domain
IP
Reputation
wj32.org
  • 162.243.25.33
whitelisted

Threats

No threats detected
No debug info