File name:

mirc.exe

Full analysis: https://app.any.run/tasks/87d2a284-1c5e-4d5d-8001-d632121fdb9c
Verdict: Malicious activity
Analysis date: November 12, 2023, 16:34:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
notmalicious
falsepositive
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

4D410F62F53A8C2E585D426182BF6632

SHA1:

2D335135F0BB7AFADE369FF8313A91FDBB9EA30A

SHA256:

ABBC18A652C412BB81B4162D107CD076BBC170A07CE9909F6EFE5C09DEC88CC5

SSDEEP:

98304:VOupp75459h5cOZ1KjzNjHlMp0moVJhJaqXkVCI1kmNfja3QTNj5/t6T3/DkUIcg:NQ0yW03qA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Reads the Internet Settings

      • mirc.exe (PID: 2912)
  • INFO

    • Reads the computer name

      • mirc.exe (PID: 2912)
    • Checks supported languages

      • mirc.exe (PID: 2912)
    • Checks proxy server information

      • mirc.exe (PID: 2912)
    • Reads the machine GUID from the registry

      • mirc.exe (PID: 2912)
    • Creates files or folders in the user directory

      • mirc.exe (PID: 2912)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (46.3)
.exe | Win64 Executable (generic) (41)
.exe | Win32 Executable (generic) (6.6)
.exe | Generic Win/DOS Executable (2.9)
.exe | DOS Executable Generic (2.9)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:08:26 15:08:09+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 4870656
InitializedDataSize: 1907712
UninitializedDataSize: -
EntryPoint: 0xb21ab6
OSVersion: 5
ImageVersion: -
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 7.75.0.0
ProductVersionNumber: 7.75.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: mIRC Co. Ltd.
FileDescription: mIRC
FileVersion: 7.75.0.0
InternalName: mirc
LegalCopyright: Copyright © 1995-2023 mIRC Co. Ltd.
LegalTrademarks: mIRC® is a Registered Trademark of mIRC Co. Ltd.
OriginalFileName: mirc.exe
ProductName: mIRC
ProductVersion: 7.75
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
36
Monitored processes
1
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start mirc.exe

Process information

PID
CMD
Path
Indicators
Parent process
2912"C:\Users\admin\AppData\Local\Temp\mirc.exe" C:\Users\admin\AppData\Local\Temp\mirc.exe
explorer.exe
User:
admin
Company:
mIRC Co. Ltd.
Integrity Level:
MEDIUM
Description:
mIRC
Exit code:
0
Version:
7.75.0.0
Modules
Images
c:\users\admin\appdata\local\temp\mirc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
726
Read events
722
Write events
4
Delete events
0

Modification events

(PID) Process:(2912) mirc.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2912) mirc.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2912) mirc.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2912) mirc.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000059010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
Executable files
6
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2912mirc.exeC:\Users\admin\AppData\Roaming\mIRC\mirc8873276.tm_text
MD5:F8E78AA998EA0666B20CD3FD38C88C80
SHA256:13443EFC3A5716C04D12CF701CCEA609C735FCFE0D56768867AAC4DBAD6BEE0C
2912mirc.exeC:\Users\admin\AppData\Roaming\mIRC\mirc6458991.tm_text
MD5:A9D85944B17420B9F0FE3D6A9C8BB22B
SHA256:707E75EF0F63546B6D210D8BB80DDEB89C281DED458D037F6AA3FEBFA791A08F
2912mirc.exeC:\Users\admin\AppData\Roaming\mIRC\mirc7227119.tm_text
MD5:9B9DDA0C66B426E965A17F97C59FE742
SHA256:0B2C12C8216C1651D2B790AC289B89003AD17EDDB0FD91EF5D83645746DAC996
2912mirc.exeC:\Users\admin\AppData\Roaming\mIRC\mirc.initext
MD5:A9D85944B17420B9F0FE3D6A9C8BB22B
SHA256:707E75EF0F63546B6D210D8BB80DDEB89C281DED458D037F6AA3FEBFA791A08F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
6
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2912
mirc.exe
POST
200
50.28.52.187:80
http://www.mirc.com/regabout.html
unknown
html
697 b
unknown
2912
mirc.exe
POST
200
50.28.52.187:80
http://www.mirc.com/update.html
unknown
html
87 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
2912
mirc.exe
50.28.52.187:80
www.mirc.com
LIQUIDWEB
US
unknown

DNS requests

Domain
IP
Reputation
www.mirc.com
  • 50.28.52.187
malicious
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info