File name:

HWID Changer By Neos07.exe

Full analysis: https://app.any.run/tasks/28b3528c-2024-45ba-8e28-85efce68538b
Verdict: Malicious activity
Analysis date: March 18, 2024, 13:35:36
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

26C1BFD41A14611D05D135411F01A37C

SHA1:

289EF909E127C37F2B62D7506918E784BD9F8604

SHA256:

A9DBF5243ADFCDEB226AB66ACD0F8AEA7D74DB8B874F07DA830B04EEF0EADD83

SSDEEP:

6144:WNNNNWNNNNNNNNNHBPDpU4G+6D9ZNNNNWNNNNNNNNNHBPDV28:hJmSJY8

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • HWID Changer By Neos07.exe (PID: 2908)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • HWID Changer By Neos07.exe (PID: 2908)
    • Starts CMD.EXE for commands execution

      • HWID Changer By Neos07.exe (PID: 2908)
    • Reads the Internet Settings

      • HWID Changer By Neos07.exe (PID: 2908)
    • Reads security settings of Internet Explorer

      • HWID Changer By Neos07.exe (PID: 2908)
  • INFO

    • Checks supported languages

      • Volumeid.exe (PID: 1656)
      • HWID Changer By Neos07.exe (PID: 2908)
    • Reads the computer name

      • HWID Changer By Neos07.exe (PID: 2908)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (45.1)
.exe | Win32 Executable MS Visual C++ (generic) (19.2)
.exe | Win64 Executable (generic) (17)
.scr | Windows screen saver (8)
.dll | Win32 Dynamic Link Library (generic) (4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2015:08:24 15:14:33+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 544256
InitializedDataSize: 375808
UninitializedDataSize: -
EntryPoint: 0x86c1e
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
CompanyName: Neos07
FileDescription: HWID Changer By Neos07
FileVersion: 1.0.0.0
InternalName: HWID Changer By Neos07.exe
LegalCopyright: Copyright © 2015 Neos07
OriginalFileName: HWID Changer By Neos07.exe
ProductName: HWID Changer By Neos07
ProductVersion: 1.0.0.0
AssemblyVersion: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start hwid changer by neos07.exe cmd.exe no specs volumeid.exe no specs hwid changer by neos07.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
848"C:\Windows\System32\cmd.exe" /c Volumeid.exe C: 7B8E-69C9C:\Windows\System32\cmd.exeHWID Changer By Neos07.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1656Volumeid.exe C: 7B8E-69C9C:\Users\admin\Desktop\Volumeid.execmd.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\volumeid.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\comdlg32.dll
1696"C:\Users\admin\Desktop\HWID Changer By Neos07.exe" C:\Users\admin\Desktop\HWID Changer By Neos07.exeexplorer.exe
User:
admin
Company:
Neos07
Integrity Level:
MEDIUM
Description:
HWID Changer By Neos07
Exit code:
3221226540
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\hwid changer by neos07.exe
c:\windows\system32\ntdll.dll
2908"C:\Users\admin\Desktop\HWID Changer By Neos07.exe" C:\Users\admin\Desktop\HWID Changer By Neos07.exe
explorer.exe
User:
admin
Company:
Neos07
Integrity Level:
HIGH
Description:
HWID Changer By Neos07
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\desktop\hwid changer by neos07.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
1 213
Read events
1 204
Write events
9
Delete events
0

Modification events

(PID) Process:(2908) HWID Changer By Neos07.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2908) HWID Changer By Neos07.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2908) HWID Changer By Neos07.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2908) HWID Changer By Neos07.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(1656) Volumeid.exeKey:HKEY_CURRENT_USER\Software\Sysinternals\VolumeID
Operation:writeName:EulaAccepted
Value:
1
Executable files
1
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1656Volumeid.exe\Device\HarddiskVolume2
MD5:
SHA256:
2908HWID Changer By Neos07.exeC:\Users\admin\Desktop\Volumeid.exeexecutable
MD5:0D1E78E6077BECDA50298DFB8D0AD439
SHA256:24BC7372DF998EEB36789174D6FB80CBCFCB52AC2FA1B9BD29F7B592A1B2AEBA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info