File name:

PSemuX-7z2201-x64.exe_931005.exe

Full analysis: https://app.any.run/tasks/a684b431-97e4-44a3-a1a1-60f968b8126a
Verdict: Malicious activity
Analysis date: September 10, 2024, 11:09:37
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

29D75CBD37E14F0EB50947520665A89B

SHA1:

A7F430821DB451A833D2B623F8043E9D82DF9DF4

SHA256:

C599D5ADB4C86F3491630618231C52A834D5ED31CE7DDB2C2A12D231BBA955ED

SSDEEP:

49152:NyWQW1ex4ShDaM4hhnFYDENYq0n8a4SzFphdFt1oHWJgvcVz3s:NyRxPH26qG8a1zFDTVg

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Searches for installed software

      • PSemuX-7z2201-x64.exe_931005.exe (PID: 7144)
      • PSemuX-7z2201-x64.exe_931005.exe (PID: 5712)
    • Reads security settings of Internet Explorer

      • PSemuX-7z2201-x64.exe_931005.exe (PID: 7144)
      • PSemuX-7z2201-x64.exe_931005.exe (PID: 5712)
    • Application launched itself

      • PSemuX-7z2201-x64.exe_931005.exe (PID: 7144)
    • Executable content was dropped or overwritten

      • PSemuX-7z2201-x64.exe_931005.exe (PID: 5712)
      • SniffoUtil.exe (PID: 5128)
    • Drops 7-zip archiver for unpacking

      • PSemuX-7z2201-x64.exe_931005.exe (PID: 5712)
      • SniffoUtil.exe (PID: 5128)
    • Creates/Modifies COM task schedule object

      • SniffoUtil.exe (PID: 5128)
    • Creates a software uninstall entry

      • SniffoUtil.exe (PID: 5128)
  • INFO

    • Checks supported languages

      • PSemuX-7z2201-x64.exe_931005.exe (PID: 7144)
      • PSemuX-7z2201-x64.exe_931005.exe (PID: 5712)
      • SniffoUtil.exe (PID: 5128)
    • Reads the computer name

      • PSemuX-7z2201-x64.exe_931005.exe (PID: 7144)
      • PSemuX-7z2201-x64.exe_931005.exe (PID: 5712)
      • SniffoUtil.exe (PID: 5128)
    • The process uses the downloaded file

      • PSemuX-7z2201-x64.exe_931005.exe (PID: 7144)
      • PSemuX-7z2201-x64.exe_931005.exe (PID: 5712)
    • Process checks computer location settings

      • PSemuX-7z2201-x64.exe_931005.exe (PID: 7144)
      • PSemuX-7z2201-x64.exe_931005.exe (PID: 5712)
    • Creates files in the program directory

      • PSemuX-7z2201-x64.exe_931005.exe (PID: 5712)
      • SniffoUtil.exe (PID: 5128)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (78.5)
.exe | Win32 Executable (generic) (11.3)
.exe | Generic Win/DOS Executable (5)
.exe | DOS Executable Generic (5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2024:09:06 13:34:09+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 10012672
InitializedDataSize: 501760
UninitializedDataSize: -
EntryPoint: 0x9142ca
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Sniff Natural World Solutions
LegalCopyright: Sniff Natural World Solutions 2023
FileDescription: Sniff Util
FileVersion: 1.0.0.0
ProductVersion: 1.0.0.0
OriginalFileName: SniffNatural.exe
ProductName: SniffUtil
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
125
Monitored processes
3
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start psemux-7z2201-x64.exe_931005.exe no specs psemux-7z2201-x64.exe_931005.exe sniffoutil.exe

Process information

PID
CMD
Path
Indicators
Parent process
5128"C:\Program Files (x86)\SniffNaturaldpiUtil\SniffoUtil.exe" C:\Program Files (x86)\SniffNaturaldpiUtil\SniffoUtil.exe
PSemuX-7z2201-x64.exe_931005.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7-Zip Installer
Exit code:
0
Version:
24.07
Modules
Images
c:\program files (x86)\sniffnaturaldpiutil\sniffoutil.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\ole32.dll
5712"C:\Users\admin\AppData\Local\Temp\PSemuX-7z2201-x64.exe_931005.exe" /uirestC:\Users\admin\AppData\Local\Temp\PSemuX-7z2201-x64.exe_931005.exe
PSemuX-7z2201-x64.exe_931005.exe
User:
admin
Company:
Sniff Natural World Solutions
Integrity Level:
HIGH
Description:
Sniff Util
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\psemux-7z2201-x64.exe_931005.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7144"C:\Users\admin\AppData\Local\Temp\PSemuX-7z2201-x64.exe_931005.exe" C:\Users\admin\AppData\Local\Temp\PSemuX-7z2201-x64.exe_931005.exeexplorer.exe
User:
admin
Company:
Sniff Natural World Solutions
Integrity Level:
MEDIUM
Description:
Sniff Util
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\psemux-7z2201-x64.exe_931005.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
1 347
Read events
1 328
Write events
19
Delete events
0

Modification events

(PID) Process:(5128) SniffoUtil.exeKey:HKEY_CURRENT_USER\SOFTWARE\7-Zip
Operation:writeName:Path32
Value:
C:\Program Files (x86)\7-Zip\
(PID) Process:(5128) SniffoUtil.exeKey:HKEY_CURRENT_USER\SOFTWARE\7-Zip
Operation:writeName:Path
Value:
C:\Program Files (x86)\7-Zip\
(PID) Process:(5128) SniffoUtil.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\7-Zip
Operation:writeName:Path32
Value:
C:\Program Files (x86)\7-Zip\
(PID) Process:(5128) SniffoUtil.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\7-Zip
Operation:writeName:Path
Value:
C:\Program Files (x86)\7-Zip\
(PID) Process:(5128) SniffoUtil.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{23170F69-40C1-278A-1000-000100020000}\InprocServer32
Operation:writeName:ThreadingModel
Value:
Apartment
(PID) Process:(5128) SniffoUtil.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved
Operation:writeName:{23170F69-40C1-278A-1000-000100020000}
Value:
7-Zip Shell Extension
(PID) Process:(5128) SniffoUtil.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\7zFM.exe
Operation:writeName:Path
Value:
C:\Program Files (x86)\7-Zip\
(PID) Process:(5128) SniffoUtil.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\7-Zip
Operation:writeName:DisplayName
Value:
7-Zip 24.07
(PID) Process:(5128) SniffoUtil.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\7-Zip
Operation:writeName:DisplayVersion
Value:
24.07
(PID) Process:(5128) SniffoUtil.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\7-Zip
Operation:writeName:DisplayIcon
Value:
C:\Program Files (x86)\7-Zip\7zFM.exe
Executable files
9
Suspicious files
3
Text files
97
Unknown types
0

Dropped files

PID
Process
Filename
Type
5128SniffoUtil.exeC:\Program Files (x86)\7-Zip\History.txttext
MD5:553A02739D516379833451440076F884
SHA256:83B1AE6D3486C2653766A28806AC110C9A0AFDE17020CA6AA0B7550A2F10E147
5128SniffoUtil.exeC:\Program Files (x86)\7-Zip\descript.iontext
MD5:EB7E322BDC62614E49DED60E0FB23845
SHA256:1DA513F5A4E8018B9AE143884EB3EAF72454B606FD51F2401B7CFD9BE4DBBF4F
5128SniffoUtil.exeC:\Program Files (x86)\7-Zip\Lang\bn.txttext
MD5:771C8B73A374CB30DF4DF682D9C40EDF
SHA256:3F55B2EC5033C39C159593C6F5ECE667B92F32938B38FCAF58B4B2A98176C1FC
5128SniffoUtil.exeC:\Program Files (x86)\7-Zip\Lang\an.txttext
MD5:F16218139E027338A16C3199091D0600
SHA256:3AB9F7AACD38C4CDE814F86BC37EEC2B9DF8D0DDDB95FC1D09A5F5BCB11F0EEB
5128SniffoUtil.exeC:\Program Files (x86)\7-Zip\7-zip.chmbinary
MD5:B79894FBEE3C882C3EFC71FF3D4A21BB
SHA256:2D55CA494A8B6DCC739D84BDD112F5C50D612F8ABF409C9FB5F2B5C2C84C37A0
5128SniffoUtil.exeC:\Program Files (x86)\7-Zip\Lang\az.txttext
MD5:3C297FBE9B1ED5582BEABFC112B55523
SHA256:055EC86AED86ABBDBD52D8E99FEC6E868D073A6DF92C60225ADD16676994C314
5128SniffoUtil.exeC:\Program Files (x86)\7-Zip\Lang\be.txttext
MD5:B1DD654E9D8C8C1B001F7B3A15D7B5D3
SHA256:32071222AF04465A3D98BB30E253579AA4BECEAEB6B21AC7C15B25F46620BF30
5128SniffoUtil.exeC:\Program Files (x86)\7-Zip\Lang\ast.txttext
MD5:1CF6411FF9154A34AFB512901BA3EE02
SHA256:F5F2174DAF36E65790C7F0E9A4496B12E14816DAD2EE5B1D48A52307076BE35F
5128SniffoUtil.exeC:\Program Files (x86)\7-Zip\Lang\ba.txttext
MD5:387FF78CF5F524FC44640F3025746145
SHA256:8A85C3FCB5F81157490971EE4F5E6B9E4F80BE69A802EBED04E6724CE859713F
5128SniffoUtil.exeC:\Program Files (x86)\7-Zip\Lang\de.txttext
MD5:1E30A705DA680AAECEAEC26DCF2981DE
SHA256:895F76BFA4B1165E4C5A11BDAB70A774E7D05D4BBDAEC0230F29DCC85D5D3563
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
14
DNS requests
9
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
5796
svchost.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
8
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
5796
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6412
RUXIMICS.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2120
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:138
whitelisted
5712
PSemuX-7z2201-x64.exe_931005.exe
104.21.90.216:443
bestappinstaller.com
CLOUDFLARENET
unknown
5796
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
5796
svchost.exe
184.30.21.171:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
3260
svchost.exe
40.115.3.253:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
8
svchost.exe
40.126.32.136:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 51.104.136.2
  • 40.127.240.158
whitelisted
google.com
  • 172.217.23.110
whitelisted
bestappinstaller.com
  • 104.21.90.216
  • 172.67.161.110
unknown
www.microsoft.com
  • 184.30.21.171
whitelisted
client.wns.windows.com
  • 40.115.3.253
whitelisted
login.live.com
  • 40.126.32.136
  • 40.126.32.74
  • 40.126.32.140
  • 40.126.32.72
  • 40.126.32.68
  • 40.126.32.76
  • 40.126.32.134
  • 20.190.160.14
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted

Threats

No threats detected
No debug info