| File name: | nn.exe |
| Full analysis: | https://app.any.run/tasks/26a63548-6199-4cb3-b2e3-3ddb24ecdda6 |
| Verdict: | Malicious activity |
| Analysis date: | May 23, 2024, 16:03:47 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (console) Intel 80386, for MS Windows |
| MD5: | ABAFBC01746FF15824A4FB94D1B96FF9 |
| SHA1: | E147CDA8D32BDAE9C2EEBBCCDDE4687E931B25E6 |
| SHA256: | C086CBCFCC44F5D44B9900CA6B95B7F17EA3D3F117437E44ECDC68CC9EDDFA19 |
| SSDEEP: | 24576:rMhEMCaWKtOz0eGJEN5nvp65nh/7kNt+h28j4HdVVh:rMhEMCakt1N5nvp65nh/7kX+h28j4Hdt |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:03:29 21:38:00+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.16 |
| CodeSize: | 628224 |
| InitializedDataSize: | 252928 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x51a06 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows command line |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 312 | "C:\Windows\system32\NOTEPAD.EXE" C:\keyforunlock\Key.txt | C:\Windows\System32\notepad.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3976 | "C:\nn.exe" | C:\nn.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
| 4016 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3976) nn.exe | Key: | HKEY_CURRENT_USER\Software\dtrs |
| Operation: | write | Name: | pkey |
Value: MIICIDANBgkqhkiG9w0BAQEFAAOCAg0AMIICCAKCAgEAmX5SxKXqNG8E/tQSoE/6npVcKHLl
gnS8MSyaNDXqxd1uDtqg9VtHUhEubEwCRdROF3PcWRJpG88reBOP0PyP3JUk8YSYZE+6MaNr
LPQRuMM2kwHT1tEnIYTCM4bxiN7jUn7YxBm1mLj2DK9lEZvs6w7hfTU6MlO1nFz7BPXVqT1N
iLwyJylx/ryS33tj8g4nbDYqHpMxh5hq2tfmQF32yGYs9V3KAvPrvAWjI1MHHxcWJm/hJNeZ
Xbndg5Pwc5mA4PjpiYfBJjyv1KTV53hyzFOX+tuPnAiCbK6l9fmCbOi0fspfwNQNi/Jyfqho
SnPJIbf8zOBpnXoCCOO9PZeuEhnz4kH4wSrVpsoGecm+/CIrqxXUJuKoyvLZGKVF9sQG1jHw
kSgjQa8QR7wRE6CaYY9jLLuvIPCI3tY1/+cOO3n6hxOH5T/wcyY/kDL36K31Zxzfcy21wtBH
P6wC3NBfbiHIuo9VHDCN6gIz8gP3l9IHw98coM3ltMxaXSJ3W+tgaSweMcN0qaWTHM+xnXFO
QjoBo2Zk/cfhoq84DmdR66wkWT1GlVpiHMQFYSMP7kKXiB/2ftDq4sB0AjZUtC2HG/WuiYH5
4SdPnmRELc7oR5M/g0qMdbXXeIusG5KiZqNyRL4hlbberBtfxhu2jFVim7RbUlNAjq/DkJdW
7uo8ElMCARE=
| |||
| (PID) Process: | (3976) nn.exe | Key: | HKEY_CURRENT_USER\Software\dtrs |
| Operation: | write | Name: | id |
Value: JL8BP1U35O3422 | |||
| (PID) Process: | (312) notepad.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Notepad |
| Operation: | write | Name: | iWindowPosX |
Value: 76 | |||
| (PID) Process: | (312) notepad.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Notepad |
| Operation: | write | Name: | iWindowPosY |
Value: 196 | |||
| (PID) Process: | (312) notepad.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Notepad |
| Operation: | write | Name: | iWindowPosDX |
Value: 958 | |||
| (PID) Process: | (312) notepad.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Notepad |
| Operation: | write | Name: | iWindowPosDY |
Value: 494 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3976 | nn.exe | C:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\AccessMUI.xml | binary | |
MD5:CFCD208495D565EF66E7DFF9F98764DA | SHA256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9 | |||
| 3976 | nn.exe | C:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\branding.xml | binary | |
MD5:CFCD208495D565EF66E7DFF9F98764DA | SHA256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9 | |||
| 3976 | nn.exe | C:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\branding.xml | binary | |
MD5:CFCD208495D565EF66E7DFF9F98764DA | SHA256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9 | |||
| 3976 | nn.exe | C:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\Setup.xml | binary | |
MD5:CFCD208495D565EF66E7DFF9F98764DA | SHA256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9 | |||
| 3976 | nn.exe | C:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\MVgwFJeWKGUNiP0-Mail[princeondarkhorse34@gmail.com]ID-[JL8BP1U35O3422].6yJ3Fz | binary | |
MD5:4E86FA1DBDE4C64678637F06FB0EF5EF | SHA256:BE61C18FAC67908B74161521249FD143B0E709D6B7CE64CFE0D66C137626B532 | |||
| 3976 | nn.exe | C:\MSOCache\All Users\{90140000-0015-0410-0000-0000000FF1CE}-C\Io3HM8sVAcCxmWK-Mail[princeondarkhorse34@gmail.com]ID-[JL8BP1U35O3422].f9GDur | binary | |
MD5:8A6A509365C6204FA7562AD454C1F95F | SHA256:76FD85041B649E77D0F4C4611499363D04FA1BEE0B2348AADC320668EC2F566A | |||
| 3976 | nn.exe | C:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\PnuQyx9OVG7jp5B-Mail[princeondarkhorse34@gmail.com]ID-[JL8BP1U35O3422].A0Vczg | binary | |
MD5:941B7ACB57D1BFAFF0E9708B7412717F | SHA256:32EF1F95547BAB8C8260B76CC58F1949DC7B00B2DF65D498D651A7CC04E83B76 | |||
| 3976 | nn.exe | C:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\W7mECINbQXdfr9u-Mail[princeondarkhorse34@gmail.com]ID-[JL8BP1U35O3422].wPAVtQ | binary | |
MD5:E413A9EF6B9497FB351F538CA1BCA642 | SHA256:FA75B15504E34F90C5D2CF19C6F0AB813A83F13A98FC663645A441874E16E811 | |||
| 3976 | nn.exe | C:\MSOCache\All Users\{90140000-0015-0410-0000-0000000FF1CE}-C\branding.xml | binary | |
MD5:CFCD208495D565EF66E7DFF9F98764DA | SHA256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9 | |||
| 3976 | nn.exe | C:\MSOCache\All Users\{90140000-0015-0410-0000-0000000FF1CE}-C\pm9gO1qvetxAPEf-Mail[princeondarkhorse34@gmail.com]ID-[JL8BP1U35O3422].aFU4co | binary | |
MD5:4338C34A9D4C744B7C4C4084E1A8188B | SHA256:C6E882EC47B74E338E4C840F001A0AAB662BA5D25C71327E7D466FC8CEC8EAC8 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |