File name: | b8818709bff2361fbdf4c601b38c73a0974e7a776102213fd316a2ba13206d22 |
Full analysis: | https://app.any.run/tasks/d37ebafa-7eca-479e-8244-70298f03ae27 |
Verdict: | Malicious activity |
Analysis date: | December 13, 2024, 21:09:28 |
OS: | Windows 10 Professional (build: 19045, 64 bit) |
Tags: | |
Indicators: | |
MIME: | application/vnd.microsoft.portable-executable |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, 5 sections |
MD5: | 3055C324DE3EE493D6A43942043682CE |
SHA1: | 5890D2202BAFE6A51A6843A8265C5345986896E2 |
SHA256: | B8818709BFF2361FBDF4C601B38C73A0974E7A776102213FD316A2BA13206D22 |
SSDEEP: | 49152:PxnZ/qvgNlriBXFEeG+r3NlWFhWP4xDSuPBv51qVkvY/qILTkg5jL:pntAgN8VvWlx2u5Ep5f |
.exe | | | Win64 Executable (generic) (64.6) |
---|---|---|
.dll | | | Win32 Dynamic Link Library (generic) (15.4) |
.exe | | | Win32 Executable (generic) (10.5) |
.exe | | | Generic Win/DOS Executable (4.6) |
.exe | | | DOS Executable Generic (4.6) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2024:07:23 03:00:13+00:00 |
ImageFileCharacteristics: | Executable, 32-bit |
PEType: | PE32 |
LinkerVersion: | 9 |
CodeSize: | 997888 |
InitializedDataSize: | 249344 |
UninitializedDataSize: | - |
EntryPoint: | 0xce979 |
OSVersion: | 5 |
ImageVersion: | - |
SubsystemVersion: | 5 |
Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1876 | "C:\Users\admin\Desktop\b8818709bff2361fbdf4c601b38c73a0974e7a776102213fd316a2ba13206d22.exe" | C:\Users\admin\Desktop\b8818709bff2361fbdf4c601b38c73a0974e7a776102213fd316a2ba13206d22.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
4128 | "C:\Users\admin\Desktop\b8818709bff2361fbdf4c601b38c73a0974e7a776102213fd316a2ba13206d22.exe" | C:\Users\admin\Desktop\b8818709bff2361fbdf4c601b38c73a0974e7a776102213fd316a2ba13206d22.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
|
(PID) Process: | (4128) b8818709bff2361fbdf4c601b38c73a0974e7a776102213fd316a2ba13206d22.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
Operation: | write | Name: | CachePrefix |
Value: | |||
(PID) Process: | (4128) b8818709bff2361fbdf4c601b38c73a0974e7a776102213fd316a2ba13206d22.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
(PID) Process: | (4128) b8818709bff2361fbdf4c601b38c73a0974e7a776102213fd316a2ba13206d22.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
Operation: | write | Name: | CachePrefix |
Value: Visited: |
PID | Process | Filename | Type | |
---|---|---|---|---|
4128 | b8818709bff2361fbdf4c601b38c73a0974e7a776102213fd316a2ba13206d22.exe | C:\Users\admin\Desktop\EasyLog.log | text | |
MD5:AF9102491E5344DD29DC6F095F96C0DA | SHA256:B895F96781CA7E21A29DE988564D1132472E39543615205582D6185A5514C0B5 | |||
4128 | b8818709bff2361fbdf4c601b38c73a0974e7a776102213fd316a2ba13206d22.exe | C:\Program Files\Common Files\System\symsrv.dll | executable | |
MD5:7574CF2C64F35161AB1292E2F532AABF | SHA256:DE055A89DE246E629A8694BDE18AF2B1605E4B9B493C7E4AEF669DD67ACF5085 | |||
4128 | b8818709bff2361fbdf4c601b38c73a0974e7a776102213fd316a2ba13206d22.exe | C:\Program Files\Common Files\System\symsrv.dll.000 | text | |
MD5:1130C911BF5DB4B8F7CF9B6F4B457623 | SHA256:EBA08CC8182F379392A97F542B350EA0DBBE5E4009472F35AF20E3D857EAFDF1 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
4712 | MoUsoCoreWorker.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4128 | b8818709bff2361fbdf4c601b38c73a0974e7a776102213fd316a2ba13206d22.exe | GET | 403 | 72.14.178.174:80 | http://www.aieov.com/logo.gif | unknown | — | — | malicious |
2632 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
4128 | b8818709bff2361fbdf4c601b38c73a0974e7a776102213fd316a2ba13206d22.exe | GET | 403 | 72.14.178.174:80 | http://www.aieov.com/logo.gif | unknown | — | — | malicious |
4712 | MoUsoCoreWorker.exe | GET | 200 | 23.32.238.107:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
4128 | b8818709bff2361fbdf4c601b38c73a0974e7a776102213fd316a2ba13206d22.exe | GET | 403 | 72.14.178.174:80 | http://www.aieov.com/logo.gif | unknown | — | — | malicious |
4128 | b8818709bff2361fbdf4c601b38c73a0974e7a776102213fd316a2ba13206d22.exe | GET | 403 | 72.14.178.174:80 | http://www.aieov.com/logo.gif | unknown | — | — | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 192.168.100.255:137 | — | — | — | whitelisted |
2632 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4712 | MoUsoCoreWorker.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 104.126.37.178:443 | www.bing.com | Akamai International B.V. | DE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4712 | MoUsoCoreWorker.exe | 23.32.238.107:80 | crl.microsoft.com | Akamai International B.V. | DE | whitelisted |
4128 | b8818709bff2361fbdf4c601b38c73a0974e7a776102213fd316a2ba13206d22.exe | 72.14.178.174:80 | www.aieov.com | Linode, LLC | US | malicious |
4712 | MoUsoCoreWorker.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
2632 | svchost.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
Domain | IP | Reputation |
---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
google.com |
| whitelisted |
5isohu.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.aieov.com |
| malicious |
www.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
Process | Message |
---|---|
b8818709bff2361fbdf4c601b38c73a0974e7a776102213fd316a2ba13206d22.exe | [1296]-21:09:38:767 ParseCmdLine param=
|
b8818709bff2361fbdf4c601b38c73a0974e7a776102213fd316a2ba13206d22.exe | [1296]-21:09:38:767 CTools::loadIni configPath=C:\Users\admin\Desktop\InitConfigure.ini
|