| File name: | Gui.ps1 |
| Full analysis: | https://app.any.run/tasks/7cccad2c-e23f-41fa-951d-1cda79b986f5 |
| Verdict: | Malicious activity |
| Analysis date: | July 16, 2024, 11:05:21 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Indicators: | |
| MIME: | text/x-c++ |
| File info: | C++ source, ASCII text, with very long lines (5761) |
| MD5: | 8763A2E08937D135E3ABDBF4579DDA27 |
| SHA1: | 26DB49E76D3DD9578DB93474A752709F09A6C7CB |
| SHA256: | B421AD0C8320CE128EE394FDE02106E8510B543F28DFA83342822F2B699C5633 |
| SSDEEP: | 384:pmF2OOogMBFnRskeBhjofFx1Vc3pknh70nq/GQ4dWGLJ8xF6LGi+mjoy+vN/w6Y:4F2ro6kSufFdku35FAGiKvO5 |
| .xaml | | | Microsoft Extensible Application Markup Language (100) |
|---|
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 552 | "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:1208 CREDAT:144385 /prefetch:2 | C:\Program Files (x86)\Internet Explorer\iexplore.exe | — | iexplore.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 1208 | "C:\Program Files\Internet Explorer\IEXPLORE.EXE" C:\Users\admin\AppData\Local\Temp\Gui.ps1.xaml | C:\Program Files\Internet Explorer\iexplore.exe | — | PresentationHost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 1376 | "C:\Windows\System32\PresentationHost.exe" C:\Users\admin\AppData\Local\Temp\Gui.ps1.xaml | C:\Windows\System32\PresentationHost.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Presentation Foundation Host Exit code: 0 Version: 4.0.41210.0 built by: Main Modules
| |||||||||||||||
| 2072 | C:\Windows\SysWOW64\PresentationHost.exe -Embedding | C:\Windows\SysWOW64\PresentationHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Presentation Foundation Host Exit code: 4294967295 Version: 4.0.41210.0 built by: Main Modules
| |||||||||||||||
| 2096 | "C:\Program Files (x86)\Internet Explorer\IEXPLORE.EXE" SCODEF:1208 CREDAT:333057 /prefetch:2 | C:\Program Files (x86)\Internet Explorer\iexplore.exe | — | iexplore.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2376 | C:\Windows\SysWOW64\PresentationHost.exe -Embedding | C:\Windows\SysWOW64\PresentationHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Presentation Foundation Host Version: 4.0.41210.0 built by: Main Modules
| |||||||||||||||
| (PID) Process: | (1376) PresentationHost.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1376) PresentationHost.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1376) PresentationHost.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1376) PresentationHost.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1208) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPDaysSinceLastAutoMigration |
Value: 6 | |||
| (PID) Process: | (1208) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchLowDateTime |
Value: 278260064 | |||
| (PID) Process: | (1208) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\TabbedBrowsing |
| Operation: | write | Name: | NTPLastLaunchHighDateTime |
Value: 31119216 | |||
| (PID) Process: | (1208) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateLowDateTime |
Value: 578575064 | |||
| (PID) Process: | (1208) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\UrlBlockManager |
| Operation: | write | Name: | NextCheckForUpdateHighDateTime |
Value: 31119216 | |||
| (PID) Process: | (1208) iexplore.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
360 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
www.bing.com |
| whitelisted |
api.bing.com |
| whitelisted |