File name:

Magnus Night V3_14361638.exe

Full analysis: https://app.any.run/tasks/4e8b6809-3809-41c0-8d66-9325f3982d40
Verdict: Malicious activity
Analysis date: February 05, 2024, 14:37:26
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

93D16508432C3FF3512EB9DE584F48E6

SHA1:

6ED9FD4D190AFC6C5154730D85CF883FD3AD4D2E

SHA256:

BE5357F63B036DA79D198978CBC5B652EA02B1CCFCB1538352442CDC7F4D5549

SSDEEP:

98304:F7GowcdPyJC8JRlobIlEQBYIXwUOZkj0o14vZGcwhnVx/mp9814L/fKBUe3VBOUu:R/JiB

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Magnus Night V3_14361638.exe (PID: 2628)
      • setup14361638.exe (PID: 3044)
    • Actions looks like stealing of personal data

      • setup14361638.exe (PID: 3044)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • setup14361638.exe (PID: 3044)
      • Magnus Night V3_14361638.exe (PID: 2628)
    • Process drops legitimate windows executable

      • setup14361638.exe (PID: 3044)
    • Reads the Internet Settings

      • Magnus Night V3_14361638.exe (PID: 2628)
      • setup14361638.exe (PID: 3044)
      • setup14361638.exe (PID: 3560)
    • Checks Windows Trust Settings

      • Magnus Night V3_14361638.exe (PID: 2628)
      • setup14361638.exe (PID: 3044)
    • The process creates files with name similar to system file names

      • setup14361638.exe (PID: 3044)
    • The process drops C-runtime libraries

      • setup14361638.exe (PID: 3044)
    • Reads security settings of Internet Explorer

      • setup14361638.exe (PID: 3044)
      • Magnus Night V3_14361638.exe (PID: 2628)
    • Reads the Windows owner or organization settings

      • setup14361638.exe (PID: 3044)
    • Reads settings of System Certificates

      • setup14361638.exe (PID: 3044)
      • Magnus Night V3_14361638.exe (PID: 2628)
    • Adds/modifies Windows certificates

      • setup14361638.exe (PID: 3044)
    • Searches for installed software

      • setup14361638.exe (PID: 3044)
  • INFO

    • Checks proxy server information

      • Magnus Night V3_14361638.exe (PID: 2628)
    • Checks supported languages

      • setup14361638.exe (PID: 3044)
      • Magnus Night V3_14361638.exe (PID: 2628)
      • setup14361638.exe (PID: 3560)
    • Reads the computer name

      • Magnus Night V3_14361638.exe (PID: 2628)
      • setup14361638.exe (PID: 3044)
      • setup14361638.exe (PID: 3560)
    • Reads the machine GUID from the registry

      • Magnus Night V3_14361638.exe (PID: 2628)
      • setup14361638.exe (PID: 3044)
      • setup14361638.exe (PID: 3560)
    • Creates files or folders in the user directory

      • Magnus Night V3_14361638.exe (PID: 2628)
      • setup14361638.exe (PID: 3044)
    • Create files in a temporary directory

      • setup14361638.exe (PID: 3044)
      • setup14361638.exe (PID: 3560)
    • Reads product name

      • setup14361638.exe (PID: 3044)
    • Reads Environment values

      • setup14361638.exe (PID: 3044)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:11:21 20:16:16+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.22
CodeSize: 4345344
InitializedDataSize: 5646336
UninitializedDataSize: -
EntryPoint: 0x39649e
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Unknown (0)
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
FileDescription: Download Manager
FileVersion: 1
InternalName: Download Manager
LegalCopyright: Download Manager
OriginalFileName: Download Manager
ProductName: Download Manager
ProductVersion: 1
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start magnus night v3_14361638.exe setup14361638.exe setup14361638.exe no specs magnus night v3_14361638.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
268"C:\Users\admin\AppData\Local\Temp\Magnus Night V3_14361638.exe" C:\Users\admin\AppData\Local\Temp\Magnus Night V3_14361638.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Download Manager
Exit code:
3221226540
Version:
1
Modules
Images
c:\users\admin\appdata\local\temp\magnus night v3_14361638.exe
c:\windows\system32\ntdll.dll
2628"C:\Users\admin\AppData\Local\Temp\Magnus Night V3_14361638.exe" C:\Users\admin\AppData\Local\Temp\Magnus Night V3_14361638.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Download Manager
Exit code:
0
Version:
1
Modules
Images
c:\users\admin\appdata\local\temp\magnus night v3_14361638.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3044C:\Users\admin\AppData\Local\setup14361638.exe hhwnd=1966522 hreturntoinstaller hextras=id:--nWOHRC:\Users\admin\AppData\Local\setup14361638.exe
Magnus Night V3_14361638.exe
User:
admin
Company:
DT001
Integrity Level:
HIGH
Description:
Software Installation
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\setup14361638.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3560C:\Users\admin\AppData\Local\setup14361638.exe hreadyC:\Users\admin\AppData\Local\setup14361638.exeMagnus Night V3_14361638.exe
User:
admin
Company:
DT001
Integrity Level:
HIGH
Description:
Software Installation
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\setup14361638.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
Total events
10 339
Read events
10 239
Write events
100
Delete events
0

Modification events

(PID) Process:(2628) Magnus Night V3_14361638.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2628) Magnus Night V3_14361638.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2628) Magnus Night V3_14361638.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2628) Magnus Night V3_14361638.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2628) Magnus Night V3_14361638.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2628) Magnus Night V3_14361638.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2628) Magnus Night V3_14361638.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2628) Magnus Night V3_14361638.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2628) Magnus Night V3_14361638.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2628) Magnus Night V3_14361638.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
0300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB6200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
Executable files
23
Suspicious files
7
Text files
15
Unknown types
0

Dropped files

PID
Process
Filename
Type
2628Magnus Night V3_14361638.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\CAF4703619713E3F18D8A9D5D88D6288_45E3C223BCF135987E4038FB6B0DBA13binary
MD5:12F6767311F4BBCE2ACC65829F8D6C5B
SHA256:C343D01DA08242E3C1E74E86AF815CB4C983D1D614767385393D0F9F7BFADA65
2628Magnus Night V3_14361638.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\3465EF07B9A6512425B2408FA7DBF4E5_F38ABF5BFFF4E687C6F66BAEAE5ADE1Cbinary
MD5:BBBF2BFB4F9EA9CED83E378ADBC9AB17
SHA256:4CD8D599033EAB686882DEAB96AFB3321655B13B9660E4C1EF4F2E339CA4C65F
3044setup14361638.exeC:\Users\admin\AppData\Local\Temp\ec05d89197b949eb6957b79472e8723d\GenericSetup.dllexecutable
MD5:08112F27DCD8F1D779231A7A3E944CB1
SHA256:11C6A8470A3F2B2BE9B8CAFE5F9A0AFCE7303BFD02AB783A0F0EE09A184649FA
3044setup14361638.exeC:\Users\admin\AppData\Local\Temp\ec05d89197b949eb6957b79472e8723d\GenericSetup.LastScreen.dllexecutable
MD5:6E001F8D0EE4F09A6673A9E8168836B6
SHA256:6A30F9C604C4012D1D2E1BA075213C378AFB1BFCB94276DE7995ED7BBF492859
2628Magnus Night V3_14361638.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:D51291C4D2F235CBE761E52733ED342D
SHA256:0575D436BDF3ECF78BE6DAE6A40A38E0E45A580819A65865C8DA6B2A476BE968
2628Magnus Night V3_14361638.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\24BD96D5497F70B3F510A6B53CD43F3E_3A89246FB90C5EE6620004F1AE0EB0EAbinary
MD5:D022364E647540F82682ADBC0BE0A7DD
SHA256:B9A18D9FD953A2F69B1E7D3F47B4A73E26B8A14A8C56BD9AC12712B331FE84F5
3044setup14361638.exeC:\Users\admin\AppData\Local\Temp\ec05d89197b949eb6957b79472e8723d\H2OServices.dllexecutable
MD5:6DF226BDA27D26CE4523B80DBF57A9EA
SHA256:17D737175D50EEE97AC1C77DB415FE25CC3C7A3871B65B93CC3FAD63808A9ABC
2628Magnus Night V3_14361638.exeC:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\3465EF07B9A6512425B2408FA7DBF4E5_F38ABF5BFFF4E687C6F66BAEAE5ADE1Cbinary
MD5:1527EE6E3896E93FEF52D88E6C414848
SHA256:D8FD9FEA9418DFD2DDA27EF5607FD6AF34F6D061A8807C9A8B99931CFF93092C
3044setup14361638.exeC:\Users\admin\AppData\Local\Temp\ec05d89197b949eb6957b79472e8723d\ServiceHide.dllexecutable
MD5:72990C7E32EE6C811EA3D2EA64523234
SHA256:E77E0B4F2762F76A3EAAADF5A3138A35EC06ECE80EDC4B3396DE7A601F8DA1B3
2628Magnus Night V3_14361638.exeC:\Users\admin\AppData\Local\setup14361638.exeexecutable
MD5:29D3A70CEC060614E1691E64162A6C1E
SHA256:CC70B093A19610E9752794D757AEC9EF07CA862EA9267EC6F9CC92B2AA882C72
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
14
DNS requests
8
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
GET
200
172.217.23.99:80
http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D
unknown
binary
1.41 Kb
unknown
GET
304
23.53.42.16:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?08dd7118ff501167
unknown
unknown
GET
200
172.217.23.99:80
http://ocsp.pki.goog/s/gts1d4/tE2rewqz3dw/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSMBFDqU0NJQdZdEGU3bkhj0FoRrQQUJeIYDrJXkZQq5dRdhpCD3lOzuJICECdevec1BTW3CTOOyMl566o%3D
unknown
binary
471 b
unknown
GET
200
172.217.23.99:80
http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIAjrICMzZli2TN25s%3D
unknown
binary
724 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
2628
Magnus Night V3_14361638.exe
35.190.60.70:443
www.dlsft.com
GOOGLE
US
whitelisted
2628
Magnus Night V3_14361638.exe
23.53.42.16:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2628
Magnus Night V3_14361638.exe
172.217.23.99:80
ocsp.pki.goog
GOOGLE
US
whitelisted
3044
setup14361638.exe
104.17.8.52:443
flow.lavasoft.com
CLOUDFLARENET
shared
3044
setup14361638.exe
104.18.68.73:443
sos.adaware.com
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
www.dlsft.com
  • 35.190.60.70
unknown
ctldl.windowsupdate.com
  • 23.53.42.16
  • 23.53.41.243
  • 23.53.42.49
  • 23.53.42.40
  • 23.53.42.25
  • 23.53.42.26
whitelisted
ocsp.pki.goog
  • 172.217.23.99
whitelisted
www.google.com
  • 142.250.181.228
whitelisted
flow.lavasoft.com
  • 104.17.8.52
  • 104.17.9.52
whitelisted
sos.adaware.com
  • 104.18.68.73
  • 104.18.67.73
whitelisted
dlsft.com
  • 35.190.60.70
unknown

Threats

Found threats are available for the paid subscriptions
4 ETPRO signatures available at the full report
Process
Message
setup14361638.exe
Error: File not found - sciterwrapper:console.tis
setup14361638.exe
setup14361638.exe
file:resources/tis/TranslateOfferTemplate.tis(82) : warning :'async' does not contain any 'await'
setup14361638.exe
at sciter:init-script.tis
setup14361638.exe