File name:

Taskbarify_1.exe

Full analysis: https://app.any.run/tasks/9f44be8e-1639-40fe-b191-9a3cc3f9d556
Verdict: Malicious activity
Analysis date: November 07, 2023, 13:59:50
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

9289BC29D56AC3BE7D98EFABC012FFCE

SHA1:

ECE623E4EA7F26003B79DD3053ACBE95B1AA47BE

SHA256:

C19B732C171F027718BEC6672905ED06B82692D2AD5E0BDBCA43A533394BBE2C

SSDEEP:

98304:w+cD4dneGogekvnZMmQLGuD7FVOYlkoXIkSo6m8UztcHZ8ZEjPiPh4Wof5RvtHlH:vgjPmqFep

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Taskbarify_1.exe (PID: 3372)
      • Taskbarify_1.tmp (PID: 3540)
  • SUSPICIOUS

    • Checks Windows Trust Settings

      • Taskbarify.exe (PID: 2424)
    • Reads settings of System Certificates

      • Taskbarify.exe (PID: 2424)
      • Taskbarify_1.tmp (PID: 3540)
    • Reads security settings of Internet Explorer

      • Taskbarify.exe (PID: 2424)
    • Reads Microsoft Outlook installation path

      • Taskbarify.exe (PID: 2424)
    • Reads the Internet Settings

      • Taskbarify.exe (PID: 2424)
    • Reads Internet Explorer settings

      • Taskbarify.exe (PID: 2424)
    • Reads the Windows owner or organization settings

      • Taskbarify_1.tmp (PID: 3540)
    • Process drops legitimate windows executable

      • Taskbarify_1.tmp (PID: 3540)
  • INFO

    • Reads the computer name

      • wmpnscfg.exe (PID: 3416)
      • Taskbarify.exe (PID: 2424)
      • wmpnscfg.exe (PID: 3984)
      • Taskbarify_1.tmp (PID: 3540)
    • Checks supported languages

      • wmpnscfg.exe (PID: 3416)
      • Taskbarify_1.exe (PID: 3372)
      • Taskbarify_1.tmp (PID: 3540)
      • Taskbarify.exe (PID: 2424)
      • wmpnscfg.exe (PID: 3984)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3416)
      • Taskbarify.exe (PID: 2424)
      • wmpnscfg.exe (PID: 3984)
      • Taskbarify_1.tmp (PID: 3540)
    • Create files in a temporary directory

      • Taskbarify_1.exe (PID: 3372)
      • Taskbarify_1.tmp (PID: 3540)
    • Creates files or folders in the user directory

      • Taskbarify.exe (PID: 2424)
      • Taskbarify_1.tmp (PID: 3540)
    • Reads Environment values

      • Taskbarify.exe (PID: 2424)
    • Reads product name

      • Taskbarify.exe (PID: 2424)
    • Reads the time zone

      • Taskbarify.exe (PID: 2424)
    • Checks proxy server information

      • Taskbarify.exe (PID: 2424)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3984)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (67.7)
.exe | Win32 EXE PECompact compressed (generic) (25.6)
.exe | Win32 Executable (generic) (2.7)
.exe | Win16/32 Executable Delphi generic (1.2)
.exe | Generic Win/DOS Executable (1.2)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2022:04:14 18:10:23+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 741888
InitializedDataSize: 318976
UninitializedDataSize: -
EntryPoint: 0xb5eec
OSVersion: 6.1
ImageVersion: 6
SubsystemVersion: 6.1
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.1
ProductVersionNumber: 1.0.0.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Taskbarify
FileDescription: Taskbarify Setup
FileVersion: 1.0.0.1
LegalCopyright: Copyright © 2022 Taskbarify
OriginalFileName:
ProductName: Taskbarify
ProductVersion: 1.0.0.1
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
39
Monitored processes
5
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start taskbarify_1.exe no specs taskbarify_1.tmp taskbarify.exe wmpnscfg.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2424"C:\Users\admin\AppData\Local\Programs\Taskbarify\Taskbarify.exe"C:\Users\admin\AppData\Local\Programs\Taskbarify\Taskbarify.exe
Taskbarify_1.tmp
User:
admin
Integrity Level:
MEDIUM
Description:
Taskbarify
Exit code:
0
Version:
1.0.0.1
Modules
Images
c:\users\admin\appdata\local\programs\taskbarify\taskbarify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3372"C:\Users\admin\AppData\Local\Temp\Taskbarify_1.exe" C:\Users\admin\AppData\Local\Temp\Taskbarify_1.exeexplorer.exe
User:
admin
Company:
Taskbarify
Integrity Level:
MEDIUM
Description:
Taskbarify Setup
Exit code:
0
Version:
1.0.0.1
Modules
Images
c:\users\admin\appdata\local\temp\taskbarify_1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3416"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3540"C:\Users\admin\AppData\Local\Temp\is-66P3I.tmp\Taskbarify_1.tmp" /SL5="$70134,3469488,1061888,C:\Users\admin\AppData\Local\Temp\Taskbarify_1.exe" C:\Users\admin\AppData\Local\Temp\is-66P3I.tmp\Taskbarify_1.tmp
Taskbarify_1.exe
User:
admin
Company:
Taskbarify
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-66p3i.tmp\taskbarify_1.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3984"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
Total events
8 184
Read events
8 138
Write events
34
Delete events
12

Modification events

(PID) Process:(3416) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{EB7214B6-6828-4EF0-AF7B-DAA324CC6E41}\{6798FEA9-3D6D-4B3E-8ED0-3D99CB14B3FC}
Operation:delete keyName:(default)
Value:
(PID) Process:(3416) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{EB7214B6-6828-4EF0-AF7B-DAA324CC6E41}
Operation:delete keyName:(default)
Value:
(PID) Process:(3416) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{60B040B4-8ACA-4273-85DB-6095E6E5845C}
Operation:delete keyName:(default)
Value:
(PID) Process:(3540) Taskbarify_1.tmpKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2424) Taskbarify.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3540) Taskbarify_1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFilesHash
Value:
F27BFBEA33CD2ACBAF69D006FF11FDAFE6271E61C45C125582CBEC91562D37F4
(PID) Process:(3540) Taskbarify_1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:RegFiles0000
Value:
C:\Users\admin\AppData\Local\Programs\Taskbarify\Taskbarify.exe
(PID) Process:(3540) Taskbarify_1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Sequence
Value:
1
(PID) Process:(3540) Taskbarify_1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:SessionHash
Value:
0FEA191A17C4C6D558B6DB05B3F8CC5B9479D9F67E009BF0190733BE1A306894
(PID) Process:(3540) Taskbarify_1.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:delete valueName:Owner
Value:
D40D0000726239B48211DA01
Executable files
19
Suspicious files
3
Text files
6
Unknown types
0

Dropped files

PID
Process
Filename
Type
3540Taskbarify_1.tmpC:\Users\admin\AppData\Local\Programs\Taskbarify\is-6PF2S.tmpxml
MD5:3E8F51C2B6FD8149C32819EADEC0CA72
SHA256:0E7ACBB755E5161D596D65BC357EC09EE0F82017D15F65504E4EEC47DAC927BD
3540Taskbarify_1.tmpC:\Users\admin\AppData\Local\Programs\Taskbarify\AsyncBridge.Net35.dllexecutable
MD5:35CBDBE6987B9951D3467DDA2F318F3C
SHA256:E4915F18FD6713EE84F27A06ED1F6F555CDBEBE1522792CF4B4961664550CF83
3540Taskbarify_1.tmpC:\Users\admin\AppData\Local\Programs\Taskbarify\is-HU924.tmpexecutable
MD5:23058EBEAB7A610991AAAC3E706C8F97
SHA256:851ABB309525ABFB608293472B4F643FBB4589E46EF374E52298315E01A35A30
3540Taskbarify_1.tmpC:\Users\admin\AppData\Local\Programs\Taskbarify\sdk.dllexecutable
MD5:3A31709EEF32705B1B4B00614A6E3DB5
SHA256:2A3BBEA7AE9505B4F82323E679049EA1D225A4DF42F17EAAC4434698D6450DED
3540Taskbarify_1.tmpC:\Users\admin\AppData\Local\Programs\Taskbarify\is-KV2VU.tmpexecutable
MD5:304E0F414C764D7A5C2647D721646E13
SHA256:86CB999EF8B3D20CB81B69FF03580CC6F3D2CA6CC699AB0810FAB8CAC0E7397E
3540Taskbarify_1.tmpC:\Users\admin\AppData\Local\Programs\Taskbarify\Countly.dllexecutable
MD5:304E0F414C764D7A5C2647D721646E13
SHA256:86CB999EF8B3D20CB81B69FF03580CC6F3D2CA6CC699AB0810FAB8CAC0E7397E
3540Taskbarify_1.tmpC:\Users\admin\AppData\Local\Programs\Taskbarify\is-G0OQL.tmpexecutable
MD5:C1A31AB7394444FD8AA2E8FE3C7C5094
SHA256:64B7231EDA298844697D38DD3539BD97FE995D88AE0C5E0C09D63A908F7336C4
3540Taskbarify_1.tmpC:\Users\admin\AppData\Local\Programs\Taskbarify\Taskbarify.exe.configxml
MD5:3E8F51C2B6FD8149C32819EADEC0CA72
SHA256:0E7ACBB755E5161D596D65BC357EC09EE0F82017D15F65504E4EEC47DAC927BD
3540Taskbarify_1.tmpC:\Users\admin\AppData\Local\Programs\Taskbarify\is-1PV6B.tmpexecutable
MD5:35CBDBE6987B9951D3467DDA2F318F3C
SHA256:E4915F18FD6713EE84F27A06ED1F6F555CDBEBE1522792CF4B4961664550CF83
3540Taskbarify_1.tmpC:\Users\admin\AppData\Local\Programs\Taskbarify\SharpRaven.dllexecutable
MD5:C1A31AB7394444FD8AA2E8FE3C7C5094
SHA256:64B7231EDA298844697D38DD3539BD97FE995D88AE0C5E0C09D63A908F7336C4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
19
DNS requests
14
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3540
Taskbarify_1.tmp
188.114.96.3:443
stats.taskbarify.com
CLOUDFLARENET
NL
unknown
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3540
Taskbarify_1.tmp
188.114.97.3:443
stats.taskbarify.com
CLOUDFLARENET
NL
unknown
2424
Taskbarify.exe
188.114.96.3:443
stats.taskbarify.com
CLOUDFLARENET
NL
unknown
2424
Taskbarify.exe
46.4.68.50:5001
quickhelping.net
unknown
2424
Taskbarify.exe
178.63.14.102:5001
fastweakpong.net
unknown
2424
Taskbarify.exe
104.16.124.96:443
www.cloudflare.com
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
stats.taskbarify.com
  • 188.114.96.3
  • 188.114.97.3
unknown
track.taskbarify.com
  • 188.114.97.3
  • 188.114.96.3
unknown
quickhelping.net
  • 46.4.68.50
  • 116.202.83.221
  • 188.40.23.171
  • 88.99.115.32
  • 46.4.68.51
  • 188.40.60.220
  • 148.251.184.150
  • 136.243.130.37
  • 148.251.184.159
  • 46.4.105.181
  • 148.251.184.167
  • 148.251.184.143
  • 144.76.137.185
  • 148.251.184.186
  • 176.9.20.82
  • 116.202.83.222
unknown
fastweakpong.net
  • 178.63.14.102
  • 176.9.41.56
  • 213.133.98.140
  • 88.99.242.212
  • 116.202.237.235
  • 138.201.83.67
  • 157.90.208.43
  • 195.201.84.182
  • 188.40.126.181
  • 159.69.138.94
  • 188.40.63.34
  • 46.4.79.62
  • 88.198.62.169
  • 46.4.122.239
  • 116.202.232.105
  • 88.99.115.184
unknown
www.cloudflare.com
  • 104.16.124.96
  • 104.16.123.96
whitelisted
google-search10.site
  • 109.248.133.132
unknown
www.dhl.de
  • 104.102.55.145
  • 2.23.79.223
whitelisted
authentication-prod.ar.indazn.com
  • 18.196.130.234
  • 3.65.222.0
unknown
update.taskbarify.com
  • 188.114.96.3
  • 188.114.97.3
unknown
vac.vap.expedia.com
  • 23.201.241.91
unknown

Threats

No threats detected
No debug info