File name:

nn.exe

Full analysis: https://app.any.run/tasks/26a63548-6199-4cb3-b2e3-3ddb24ecdda6
Verdict: Malicious activity
Analysis date: May 23, 2024, 16:03:47
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows
MD5:

ABAFBC01746FF15824A4FB94D1B96FF9

SHA1:

E147CDA8D32BDAE9C2EEBBCCDDE4687E931B25E6

SHA256:

C086CBCFCC44F5D44B9900CA6B95B7F17EA3D3F117437E44ECDC68CC9EDDFA19

SSDEEP:

24576:rMhEMCaWKtOz0eGJEN5nvp65nh/7kNt+h28j4HdVVh:rMhEMCakt1N5nvp65nh/7kX+h28j4Hdt

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • nn.exe (PID: 3976)
  • SUSPICIOUS

    • Creates file in the systems drive root

      • nn.exe (PID: 3976)
    • Detected use of alternative data streams (AltDS)

      • nn.exe (PID: 3976)
    • Executable content was dropped or overwritten

      • nn.exe (PID: 3976)
  • INFO

    • Checks supported languages

      • nn.exe (PID: 3976)
    • Reads the machine GUID from the registry

      • nn.exe (PID: 3976)
    • Manual execution by a user

      • explorer.exe (PID: 4016)
      • notepad.exe (PID: 312)
    • Creates files or folders in the user directory

      • nn.exe (PID: 3976)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (64.6)
.dll | Win32 Dynamic Link Library (generic) (15.4)
.exe | Win32 Executable (generic) (10.5)
.exe | Generic Win/DOS Executable (4.6)
.exe | DOS Executable Generic (4.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:03:29 21:38:00+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.16
CodeSize: 628224
InitializedDataSize: 252928
UninitializedDataSize: -
EntryPoint: 0x51a06
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
41
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start nn.exe explorer.exe no specs notepad.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
312"C:\Windows\system32\NOTEPAD.EXE" C:\keyforunlock\Key.txtC:\Windows\System32\notepad.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3976"C:\nn.exe" C:\nn.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\nn.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\cryptsp.dll
4016"C:\Windows\explorer.exe" C:\Windows\explorer.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
40 802
Read events
40 796
Write events
6
Delete events
0

Modification events

(PID) Process:(3976) nn.exeKey:HKEY_CURRENT_USER\Software\dtrs
Operation:writeName:pkey
Value:
MIICIDANBgkqhkiG9w0BAQEFAAOCAg0AMIICCAKCAgEAmX5SxKXqNG8E/tQSoE/6npVcKHLl gnS8MSyaNDXqxd1uDtqg9VtHUhEubEwCRdROF3PcWRJpG88reBOP0PyP3JUk8YSYZE+6MaNr LPQRuMM2kwHT1tEnIYTCM4bxiN7jUn7YxBm1mLj2DK9lEZvs6w7hfTU6MlO1nFz7BPXVqT1N iLwyJylx/ryS33tj8g4nbDYqHpMxh5hq2tfmQF32yGYs9V3KAvPrvAWjI1MHHxcWJm/hJNeZ Xbndg5Pwc5mA4PjpiYfBJjyv1KTV53hyzFOX+tuPnAiCbK6l9fmCbOi0fspfwNQNi/Jyfqho SnPJIbf8zOBpnXoCCOO9PZeuEhnz4kH4wSrVpsoGecm+/CIrqxXUJuKoyvLZGKVF9sQG1jHw kSgjQa8QR7wRE6CaYY9jLLuvIPCI3tY1/+cOO3n6hxOH5T/wcyY/kDL36K31Zxzfcy21wtBH P6wC3NBfbiHIuo9VHDCN6gIz8gP3l9IHw98coM3ltMxaXSJ3W+tgaSweMcN0qaWTHM+xnXFO QjoBo2Zk/cfhoq84DmdR66wkWT1GlVpiHMQFYSMP7kKXiB/2ftDq4sB0AjZUtC2HG/WuiYH5 4SdPnmRELc7oR5M/g0qMdbXXeIusG5KiZqNyRL4hlbberBtfxhu2jFVim7RbUlNAjq/DkJdW 7uo8ElMCARE=
(PID) Process:(3976) nn.exeKey:HKEY_CURRENT_USER\Software\dtrs
Operation:writeName:id
Value:
JL8BP1U35O3422
(PID) Process:(312) notepad.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Notepad
Operation:writeName:iWindowPosX
Value:
76
(PID) Process:(312) notepad.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Notepad
Operation:writeName:iWindowPosY
Value:
196
(PID) Process:(312) notepad.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Notepad
Operation:writeName:iWindowPosDX
Value:
958
(PID) Process:(312) notepad.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Notepad
Operation:writeName:iWindowPosDY
Value:
494
Executable files
5
Suspicious files
3 087
Text files
7
Unknown types
14

Dropped files

PID
Process
Filename
Type
3976nn.exeC:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\AccessMUI.xmlbinary
MD5:CFCD208495D565EF66E7DFF9F98764DA
SHA256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
3976nn.exeC:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\branding.xmlbinary
MD5:CFCD208495D565EF66E7DFF9F98764DA
SHA256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
3976nn.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\branding.xmlbinary
MD5:CFCD208495D565EF66E7DFF9F98764DA
SHA256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
3976nn.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\Setup.xmlbinary
MD5:CFCD208495D565EF66E7DFF9F98764DA
SHA256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
3976nn.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\MVgwFJeWKGUNiP0-Mail[princeondarkhorse34@gmail.com]ID-[JL8BP1U35O3422].6yJ3Fzbinary
MD5:4E86FA1DBDE4C64678637F06FB0EF5EF
SHA256:BE61C18FAC67908B74161521249FD143B0E709D6B7CE64CFE0D66C137626B532
3976nn.exeC:\MSOCache\All Users\{90140000-0015-0410-0000-0000000FF1CE}-C\Io3HM8sVAcCxmWK-Mail[princeondarkhorse34@gmail.com]ID-[JL8BP1U35O3422].f9GDurbinary
MD5:8A6A509365C6204FA7562AD454C1F95F
SHA256:76FD85041B649E77D0F4C4611499363D04FA1BEE0B2348AADC320668EC2F566A
3976nn.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\PnuQyx9OVG7jp5B-Mail[princeondarkhorse34@gmail.com]ID-[JL8BP1U35O3422].A0Vczgbinary
MD5:941B7ACB57D1BFAFF0E9708B7412717F
SHA256:32EF1F95547BAB8C8260B76CC58F1949DC7B00B2DF65D498D651A7CC04E83B76
3976nn.exeC:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\W7mECINbQXdfr9u-Mail[princeondarkhorse34@gmail.com]ID-[JL8BP1U35O3422].wPAVtQbinary
MD5:E413A9EF6B9497FB351F538CA1BCA642
SHA256:FA75B15504E34F90C5D2CF19C6F0AB813A83F13A98FC663645A441874E16E811
3976nn.exeC:\MSOCache\All Users\{90140000-0015-0410-0000-0000000FF1CE}-C\branding.xmlbinary
MD5:CFCD208495D565EF66E7DFF9F98764DA
SHA256:5FECEB66FFC86F38D952786C6D696C79C2DBC239DD4E91B46729D73A27FB57E9
3976nn.exeC:\MSOCache\All Users\{90140000-0015-0410-0000-0000000FF1CE}-C\pm9gO1qvetxAPEf-Mail[princeondarkhorse34@gmail.com]ID-[JL8BP1U35O3422].aFU4cobinary
MD5:4338C34A9D4C744B7C4C4084E1A8188B
SHA256:C6E882EC47B74E338E4C840F001A0AAB662BA5D25C71327E7D466FC8CEC8EAC8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info