| File name: | YURI.exe |
| Full analysis: | https://app.any.run/tasks/122fddce-f54f-4da0-bd41-64ec1ff773ac |
| Verdict: | Malicious activity |
| Analysis date: | March 07, 2024, 06:35:48 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 22FEA7DED6038E37EC78586B97F6D94D |
| SHA1: | A26A53807240168C13AAC609373BB72A396B10F0 |
| SHA256: | B5E20E364D461D402B4708E99F33AFBB3D1008B420226AD2744B5F953B0F567C |
| SSDEEP: | 24576:BlcUMjNCo/XqBMQw5VO81bvatIEZ2tAOJ:oomiaNbvan2tA+ |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2001:08:23 07:39:46+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 81920 |
| InitializedDataSize: | 32768 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x19052 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1384 | "C:\Users\admin\AppData\Local\Temp\YURI.exe" | C:\Users\admin\AppData\Local\Temp\YURI.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| 2472 | "C:\Users\admin\AppData\Local\Temp\~ef7194.tmp" 1384 "C:\Users\admin\AppData\Local\Temp\" | C:\Users\admin\AppData\Local\Temp\~ef7194.tmp | — | YURI.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1384 | YURI.exe | C:\Users\admin\AppData\Local\Temp\~eff58b\~df394b.tmp | executable | |
MD5:D89F6BB4D45A8554D4A9FD9BAEF39E26 | SHA256:A505A4CC38619D3C7B2B61466E26E9281273B3BAB939040300A28AF40F6D3961 | |||
| 1384 | YURI.exe | C:\Users\admin\AppData\Local\Temp\~ef7194.tmp | executable | |
MD5:F487118C900E9792DE1EA7CE6A47E25A | SHA256:1213608B452707E8EE29BD2FDC8C5BF7F06A0DE6C4C763E4E6E1BDD610D77ECB | |||
| 1384 | YURI.exe | C:\Users\admin\AppData\Local\Temp\~eff58b\SECDRV.SYS | executable | |
MD5:F376A1580204E47F37A721E1CBC5582A | SHA256:65D7E6D64C7BEA67772C0CDE8682E2B88EB2BA205DDE0CF1842B7361C39E58E1 | |||
| 1384 | YURI.exe | C:\Users\admin\AppData\Local\Temp\~eff58b\~dec584.tmp | executable | |
MD5:167ADE91BAE5E7F69D9D5BF5D3A7193E | SHA256:8E1D0AA245D843ABF6DC706A89497495D8A8EB22D6125EEEB24C84F0D8D62936 | |||
| 1384 | YURI.exe | C:\Users\admin\AppData\Local\Temp\~eff58b\DrvMgt.dll | executable | |
MD5:F067B3E660CEBED6AC554FE0C9D7D17D | SHA256:916B1767D80B932D5B05B24FD75294E27291FD9BCEB9EB6D057DF334F8679F6B | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |