analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

01_extracted.exe

Full analysis: https://app.any.run/tasks/b7972f61-0c51-40e1-8e87-1ff3723720ac
Verdict: Malicious activity
Analysis date: July 18, 2019, 13:34:04
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows
MD5:

D21A922998BA32E029FE7E2A30D77C3E

SHA1:

97D4AF593BD3615F8DB060A508EED0A1F5372F3E

SHA256:

BFCF10F7555AD13ABBAADEBEC7E965154384B4C83518A5D5E9DE26E9A1678151

SSDEEP:

6144:z7iKwcu/j60jfiOp3w5oyRGackA5zGT38xXr2fnvOFQwd0+2JITo2EoMD+ubhrTU:SKwcSjbfLAWyR3Czy38en2+NJYoz9Rz/

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Writes to a start menu file

      • 01_extracted.exe (PID: 3528)
  • SUSPICIOUS

    • Starts Internet Explorer

      • vbc.exe (PID: 3112)
    • Creates files in the user directory

      • 01_extracted.exe (PID: 3528)
    • Executes scripts

      • 01_extracted.exe (PID: 3528)
    • Executable content was dropped or overwritten

      • 01_extracted.exe (PID: 3528)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Generic CIL Executable (.NET, Mono, etc.) (82.9)
.dll | Win32 Dynamic Link Library (generic) (7.4)
.exe | Win32 Executable (generic) (5.1)
.exe | Generic Win/DOS Executable (2.2)
.exe | DOS Executable Generic (2.2)

EXIF

EXE

ProductName: eeb5a548-0086-406f-bdef-bcbb5a033b93
AssemblyVersion: 0.0.0.0
ProductVersion: 1.0.0.0
OriginalFileName: bdb0aa10-3b74-41dd-b306-85ca5d96dd8c.exe
LegalCopyright: 6e0bb32d-0322-45d8-b00b-72feffb8bf12
InternalName: mHXKzbypfWYQLdQMm.exe
FileVersion: 1.0.0.0
FileDescription: 46d841bd-6f9a-46b8-ba00-9457d6bb273
CharacterSet: Unicode
LanguageCode: Neutral
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x003f
ProductVersionNumber: 0.0.0.0
FileVersionNumber: 0.0.0.0
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0x5d5ae
UninitializedDataSize: -
InitializedDataSize: 2560
CodeSize: 374272
LinkerVersion: 8
PEType: PE32
TimeStamp: 2019:03:13 12:51:20+01:00
MachineType: Intel 386 or later, and compatibles
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
3
Malicious processes
0
Suspicious processes
1

Behavior graph

Click at the process to see the details
start 01_extracted.exe vbc.exe no specs iexplore.exe

Process information

PID
CMD
Path
Indicators
Parent process
3528"C:\Users\admin\AppData\Local\Temp\01_extracted.exe" C:\Users\admin\AppData\Local\Temp\01_extracted.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
46d841bd-6f9a-46b8-ba00-9457d6bb273
Version:
1.0.0.0
3112"C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe"C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exe01_extracted.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Visual Basic Command Line Compiler
Version:
8.0.50727.5420
3600 C:\Windows\Microsoft.NET\Framework\v2.0.50727\vbc.exeC:\Program Files\Internet Explorer\iexplore.exe
vbc.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Internet Explorer
Version:
8.00.7600.16385 (win7_rtm.090713-1255)
Total events
10
Read events
10
Write events
0
Delete events
0

Modification events

No data
Executable files
1
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
352801_extracted.exeC:\Users\admin\AppData\Roaming\filename.exeexecutable
MD5:D21A922998BA32E029FE7E2A30D77C3E
SHA256:BFCF10F7555AD13ABBAADEBEC7E965154384B4C83518A5D5E9DE26E9A1678151
352801_extracted.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\startupname.urltext
MD5:F94AFCE955E293AB9851AA4795C576B8
SHA256:A43840F84DC9DE86FE05F0C7546B4ADA45F2A0A572C82B78EC683F32926F50A9
3600iexplore.exeC:\Users\admin\AppData\Local\Temp\admin.bmpimage
MD5:343FA15C150A516B20CC9F787CFD530E
SHA256:D632E9DBACDCD8F6B86BA011ED6B23F961D104869654CAA764216EA57A916524
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
11
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3600
iexplore.exe
67.214.175.69:1011
manuel3.publicvm.com
Colostore.com
US
malicious

DNS requests

Domain
IP
Reputation
manuel3.publicvm.com
  • 67.214.175.69
malicious

Threats

No threats detected
No debug info