File name:

Ransom;Win32.Genasom.DV.exe

Full analysis: https://app.any.run/tasks/611ca9b4-c1e0-4110-a95e-3055dd3c4eaa
Verdict: Malicious activity
Analysis date: July 19, 2024, 23:15:39
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

4E0F3D3DBD17F31AF89F854E939A6F43

SHA1:

71252434CB96F2E2B0B4727F67AB2E52C92B0744

SHA256:

A955183B97C96A8B847F8488B06841ED1773A5E9811F49B876D1D99C5F2F1F0E

SSDEEP:

96:S/Bz4kd7GaAiifqerCd9NhKUqaRHhnTDd83fO2/y3tXGtW:Sl4I7GaViCeCXNhKUqaRpTDGly9XGt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Ransom;Win32.Genasom.DV.exe (PID: 7604)
      • Ransom;Win32.Genasom.DV.exe (PID: 236)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • Ransom;Win32.Genasom.DV.exe (PID: 7604)
    • Reads the date of Windows installation

      • Ransom;Win32.Genasom.DV.exe (PID: 7604)
    • Application launched itself

      • Ransom;Win32.Genasom.DV.exe (PID: 7604)
    • Starts itself from another location

      • Ransom;Win32.Genasom.DV.exe (PID: 236)
    • The process executes via Task Scheduler

      • PLUGScheduler.exe (PID: 2720)
    • Executable content was dropped or overwritten

      • Ransom;Win32.Genasom.DV.exe (PID: 236)
  • INFO

    • Reads the computer name

      • Ransom;Win32.Genasom.DV.exe (PID: 7604)
      • sys3.exe (PID: 2436)
    • Checks supported languages

      • Ransom;Win32.Genasom.DV.exe (PID: 7604)
      • Ransom;Win32.Genasom.DV.exe (PID: 236)
      • sys3.exe (PID: 2436)
      • PLUGScheduler.exe (PID: 2720)
    • Create files in a temporary directory

      • Ransom;Win32.Genasom.DV.exe (PID: 236)
    • Process checks computer location settings

      • Ransom;Win32.Genasom.DV.exe (PID: 7604)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2011:05:23 10:56:07+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 7.1
CodeSize: 3072
InitializedDataSize: 6144
UninitializedDataSize: -
EntryPoint: 0x1671
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
243
Monitored processes
6
Malicious processes
0
Suspicious processes
2

Behavior graph

Click at the process to see the details
start ransom;win32.genasom.dv.exe no specs ransom;win32.genasom.dv.exe sys3.exe no specs plugscheduler.exe no specs ruximics.exe no specs ruximics.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
236"C:\Users\admin\Desktop\Ransom;Win32.Genasom.DV.exe" C:\Users\admin\Desktop\Ransom;Win32.Genasom.DV.exe
Ransom;Win32.Genasom.DV.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\ransom;win32.genasom.dv.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2436C:\Users\admin\AppData\Local\Temp\\sys3.exeC:\Users\admin\AppData\Local\Temp\sys3.exeRansom;Win32.Genasom.DV.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\sys3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2720"C:\Program Files\RUXIM\PLUGscheduler.exe"C:\Program Files\RUXIM\PLUGScheduler.exesvchost.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows Update LifeCycle Component Scheduler
Exit code:
0
Version:
10.0.19041.3623 (WinBuild.160101.0800)
Modules
Images
c:\program files\ruxim\plugscheduler.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
4668%ProgramFiles%\RUXIM\RUXIMICS.EXE /onlyloadcampaignsC:\Program Files\RUXIM\RUXIMICS.exePLUGScheduler.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Reusable UX Interaction Manager
Exit code:
0
Version:
10.0.19041.3623 (WinBuild.160101.0800)
5744%ProgramFiles%\RUXIM\RUXIMICS.EXE /nonetworkC:\Program Files\RUXIM\RUXIMICS.exePLUGScheduler.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Reusable UX Interaction Manager
Exit code:
0
Version:
10.0.19041.3623 (WinBuild.160101.0800)
7604"C:\Users\admin\Desktop\Ransom;Win32.Genasom.DV.exe" C:\Users\admin\Desktop\Ransom;Win32.Genasom.DV.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1073807364
Modules
Images
c:\users\admin\desktop\ransom;win32.genasom.dv.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
636
Read events
628
Write events
8
Delete events
0

Modification events

(PID) Process:(7604) Ransom;Win32.Genasom.DV.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(7604) Ransom;Win32.Genasom.DV.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(7604) Ransom;Win32.Genasom.DV.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(7604) Ransom;Win32.Genasom.DV.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
1
Suspicious files
45
Text files
1
Unknown types
36

Dropped files

PID
Process
Filename
Type
236Ransom;Win32.Genasom.DV.exe\Device\Harddisk0\DR0
MD5:
SHA256:
2720PLUGScheduler.exeC:\ProgramData\PLUG\Logs\RUXIMLog.027.etletl
MD5:868E79A00A8204448B2FFC4F4D5C08EA
SHA256:148FE324431CB4C826BCF0436147D946AC389A877732612CF40629048B8517DC
2720PLUGScheduler.exeC:\ProgramData\PLUG\Logs\RUXIMLog.028.etletl
MD5:2F36C598EBFF5B5CDD898C9691D6BCCB
SHA256:8900C5931ED8E0D1B68082B45CF2F4E8C1025D36825508E0804C916D781B9F50
236Ransom;Win32.Genasom.DV.exeC:\Users\admin\AppData\Local\Temp\sys3.exeexecutable
MD5:4E0F3D3DBD17F31AF89F854E939A6F43
SHA256:A955183B97C96A8B847F8488B06841ED1773A5E9811F49B876D1D99C5F2F1F0E
236Ransom;Win32.Genasom.DV.exeC:\Users\admin\AppData\Local\Temp\systm.txttext
MD5:FE0AB4E6D77F55CD9C870627C852E6DE
SHA256:E4D70F9C9A12A66EC5EAE3942593A7725B810137821AECAC938E41E7686519A6
2720PLUGScheduler.exeC:\ProgramData\PLUG\Logs\RUXIMLog.030.etletl
MD5:673727AF7C6805E869C9F8BE1E468F4A
SHA256:6B16B7DE97F397BCEC36EB3F18C7B64CD3DB6D2974DDF319A251CE27B80D837B
2720PLUGScheduler.exeC:\ProgramData\PLUG\Logs\RUXIMLog.029.etletl
MD5:079890A8EC8D5CB6523FCEC2209780AA
SHA256:0E12D2D76DD738CE196BED522E35F75E2CC91294F78CDDCBE8CE7787AAA70049
2720PLUGScheduler.exeC:\ProgramData\PLUG\Logs\RUXIMLog.026.etletl
MD5:44A0E917AD0C126931B1BCD959285A9A
SHA256:DDFBE47E7DFD6D8B7517F2F6FF9808ECF3C0A25F588A9F96D04F4E2B4A578573
2720PLUGScheduler.exeC:\ProgramData\PLUG\Logs\RUXIMLog.024.etletl
MD5:C8834D365FAE073DEDE1F1620454CE71
SHA256:C6DD793EEE1D5551CA507A3C5BFFECA82DD3E29C63C2C6DD218A7D4BFB37046B
2720PLUGScheduler.exeC:\ProgramData\PLUG\Logs\RUXIMLog.021.etletl
MD5:FED961067F664B5381B65A534B7AB728
SHA256:652F31A8284AE812D1D9D24192BC800976BF74C240591C6AC443A28C4709FB7C
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
29
DNS requests
15
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4716
svchost.exe
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
5620
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4.209.32.67:443
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
52.161.91.37:443
activation-v2.sls.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
US
unknown
4032
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
20.190.159.4:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2760
svchost.exe
40.113.110.67:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
239.255.255.250:3702
whitelisted

DNS requests

Domain
IP
Reputation
login.live.com
  • 20.190.159.4
  • 40.126.31.71
  • 20.190.159.75
  • 20.190.159.23
  • 20.190.159.73
  • 20.190.159.64
  • 40.126.31.69
  • 20.190.159.2
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
  • 51.124.78.146
whitelisted
activation-v2.sls.microsoft.com
  • 52.161.91.37
whitelisted
google.com
  • 142.250.186.142
whitelisted
officeclient.microsoft.com
  • 52.109.32.97
whitelisted
ecs.office.com
  • 52.113.194.132
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
www.bing.com
  • 2.23.209.133
  • 2.23.209.140
  • 2.23.209.149
  • 2.23.209.187
  • 2.23.209.130
  • 2.23.209.179
  • 2.23.209.182
whitelisted
r.bing.com
  • 2.23.209.133
  • 2.23.209.149
  • 2.23.209.140
  • 2.23.209.182
  • 2.23.209.187
  • 2.23.209.130
  • 2.23.209.179
whitelisted
self.events.data.microsoft.com
  • 20.189.173.3
whitelisted

Threats

No threats detected
No debug info