File name:

webex.exe

Full analysis: https://app.any.run/tasks/5f90f9f4-f231-4f90-a572-73c70196227f
Verdict: Malicious activity
Analysis date: February 13, 2024, 06:33:56
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

20F5880EF93933DB5ECCE852D7D39FBA

SHA1:

00AA3D80262B7CA0E5673A27A0257AA9355262DA

SHA256:

ADA51EEA0A49428FBACBF60669FE14EB69B89264F613AB2CC0FC6452FA8701D5

SSDEEP:

12288:8FzmqBpnlUXAU50IzmnZnznVzRnVzh0ejf:8FzmqBplYAZymRr9b

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • webex.exe (PID: 4052)
  • SUSPICIOUS

    • Reads the Internet Settings

      • webex.exe (PID: 4052)
    • Reads settings of System Certificates

      • webex.exe (PID: 4052)
    • Reads security settings of Internet Explorer

      • webex.exe (PID: 4052)
    • Checks Windows Trust Settings

      • webex.exe (PID: 4052)
  • INFO

    • Checks supported languages

      • webex.exe (PID: 4052)
    • Checks proxy server information

      • webex.exe (PID: 4052)
    • Reads the machine GUID from the registry

      • webex.exe (PID: 4052)
    • Create files in a temporary directory

      • webex.exe (PID: 4052)
    • Reads the computer name

      • webex.exe (PID: 4052)
    • Reads the software policy settings

      • webex.exe (PID: 4052)
    • Creates files or folders in the user directory

      • webex.exe (PID: 4052)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:06:13 09:01:06+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.28
CodeSize: 188416
InitializedDataSize: 297984
UninitializedDataSize: -
EntryPoint: 0x171a0
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 10043.6.2023.613
ProductVersionNumber: 10043.6.2023.613
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Dynamic link library
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Cisco Webex LLC
FileDescription: Cisco Webex Meeting
FileVersion: 10043,6,2023,0613
InternalName: Webex
LegalCopyright: © 2023 Cisco and/or its affiliates. All rights reserved.
OriginalFileName: Webex.exe
ProductName: Cisco Webex Meeting
ProductVersion: 10043,6,2023,0613
GPCVersion: 3
UrlProtocolVersion: 1
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start webex.exe

Process information

PID
CMD
Path
Indicators
Parent process
4052"C:\Users\admin\AppData\Local\Temp\webex.exe" C:\Users\admin\AppData\Local\Temp\webex.exe
explorer.exe
User:
admin
Company:
Cisco Webex LLC
Integrity Level:
MEDIUM
Description:
Cisco Webex Meeting
Exit code:
0
Version:
10043,6,2023,0613
Modules
Images
c:\users\admin\appdata\local\temp\webex.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
3 871
Read events
3 831
Write events
34
Delete events
6

Modification events

(PID) Process:(4052) webex.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(4052) webex.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyServer
Value:
(PID) Process:(4052) webex.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:ProxyOverride
Value:
(PID) Process:(4052) webex.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoConfigURL
Value:
(PID) Process:(4052) webex.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:delete valueName:AutoDetect
Value:
(PID) Process:(4052) webex.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005C010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(4052) webex.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(4052) webex.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(4052) webex.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(4052) webex.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
0
Suspicious files
1
Text files
1
Unknown types
2

Dropped files

PID
Process
Filename
Type
4052webex.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\6CFED4E1A8866BE87BE17622BFB4D726_FBADB8F7FD7B56EE191ACF24A8989D94binary
MD5:B04442527401C14030D9EC981F489E36
SHA256:A4F17C210ABC97828B2661F3CA2D1979334C071BA741A34598AC5870DFA85A09
4052webex.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157binary
MD5:F22F6130FEC58504680F5DD741CD7C80
SHA256:FE4E75277F94EAC3207F38AA94313BBA1ED991250B0F42B875B928A30CA9D313
4052webex.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\1TWS7Z9P.txttext
MD5:C63E4565D54B4FB9F02D3488A6DB45A4
SHA256:94DF0CC9E4DABD7EA0F68ECF4D429194FE6B134849119FEC02E7179F458412CA
4052webex.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\6CFED4E1A8866BE87BE17622BFB4D726_FBADB8F7FD7B56EE191ACF24A8989D94binary
MD5:A4B9A2A1C80C86F718E6B4A36F2A5AEE
SHA256:FB851ABC4C8EA069A39A27516D604688BAE5BAA28F13B1F05168E6566EBD9312
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
8
DNS requests
4
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
4052
webex.exe
GET
304
23.62.98.64:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?f34bf006e77033a5
NL
unknown
4052
webex.exe
GET
200
192.35.177.23:80
http://commercial.ocsp.identrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTQfEOioPd4%2FtCA3%2FhgDklRXB0FwgQU7UQZwNPwBovupHu%2BQucmVMiONnYCEEABbvsKIFz66%2BGPcdc6u3g%3D
US
binary
1.63 Kb
unknown
1080
svchost.exe
GET
200
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?a414549a770d7263
GB
compressed
65.2 Kb
unknown
1080
svchost.exe
GET
304
93.184.221.240:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c503292d7802e201
GB
compressed
65.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4052
webex.exe
173.243.0.154:443
empower.webex.com
13445
US
unknown
4052
webex.exe
23.62.98.64:80
ctldl.windowsupdate.com
Akamai International B.V.
NL
whitelisted
4052
webex.exe
192.35.177.23:80
commercial.ocsp.identrust.com
SLC-IDENT-AS
US
unknown
1080
svchost.exe
93.184.221.240:80
ctldl.windowsupdate.com
EDGECAST
GB
whitelisted

DNS requests

Domain
IP
Reputation
empower.webex.com
  • 173.243.0.154
unknown
ctldl.windowsupdate.com
  • 23.62.98.64
  • 23.62.98.8
  • 93.184.221.240
whitelisted
commercial.ocsp.identrust.com
  • 192.35.177.23
whitelisted

Threats

No threats detected
No debug info