| File name: | ranware.exe |
| Full analysis: | https://app.any.run/tasks/82e2f939-25c2-4edd-9881-4cfd2f0b2364 |
| Verdict: | Malicious activity |
| Analysis date: | April 17, 2024, 13:56:19 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (console) Intel 80386, for MS Windows |
| MD5: | 3D7F6269576D5233773B6CAB30D1FA9C |
| SHA1: | 8D4B1F76262E10E59A98FC21FA820BD25079F384 |
| SHA256: | C6489FE8CA0C356C470A864950849721E765F8DC76C8249FBAB39D961791ABE6 |
| SSDEEP: | 3072:IYCreVL9mJTVo+Lrkioba9fK8siSiY+yzV1DcCGHN8wxBM/s3fXEx/oitCGHg/I:IZaLSo8rkioW9y83SiY+yvDceCUg/I |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:04:09 20:01:33+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.39 |
| CodeSize: | 134144 |
| InitializedDataSize: | 56832 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x816b |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows command line |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 324 | "C:\Users\admin\AppData\Local\Temp\ranware.exe" | C:\Users\admin\AppData\Local\Temp\ranware.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 324 | ranware.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\progressbar_blue_active_200.png | binary | |
MD5:C00E8876653CDD4EEC651860E544E7B3 | SHA256:E5A638D5C49F3F1D794062EE82C0B7BB122AA4AFD400217392D7274DC158AE72 | |||
| 324 | ranware.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\info_icon_100.png | binary | |
MD5:C00E8876653CDD4EEC651860E544E7B3 | SHA256:E5A638D5C49F3F1D794062EE82C0B7BB122AA4AFD400217392D7274DC158AE72 | |||
| 324 | ranware.exe | C:\Users\admin\.oracle_jre_usage\90737d32e3abaa4.timestamp | binary | |
MD5:D737E14CE5BE94484F9B09728A2E91BB | SHA256:23801204DD925781C2CF7E97DFF4388CD453457B77D95A6351DF94A9225EC0BC | |||
| 324 | ranware.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\progressbar_blue_active_125.png | binary | |
MD5:C00E8876653CDD4EEC651860E544E7B3 | SHA256:E5A638D5C49F3F1D794062EE82C0B7BB122AA4AFD400217392D7274DC158AE72 | |||
| 324 | ranware.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\close_200.png | binary | |
MD5:C00E8876653CDD4EEC651860E544E7B3 | SHA256:E5A638D5C49F3F1D794062EE82C0B7BB122AA4AFD400217392D7274DC158AE72 | |||
| 324 | ranware.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\gccheck_small.exe | binary | |
MD5:B652452CC9ACBBB480A0E4434A616F39 | SHA256:2145205D7B133DB9C87D4E292CB5D4ECBD662AE8997BA6CD73D40608908BB333 | |||
| 324 | ranware.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\progressbar_pole_null_200.png | binary | |
MD5:C00E8876653CDD4EEC651860E544E7B3 | SHA256:E5A638D5C49F3F1D794062EE82C0B7BB122AA4AFD400217392D7274DC158AE72 | |||
| 324 | ranware.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\gray_button_200.png | binary | |
MD5:C00E8876653CDD4EEC651860E544E7B3 | SHA256:E5A638D5C49F3F1D794062EE82C0B7BB122AA4AFD400217392D7274DC158AE72 | |||
| 324 | ranware.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\progressbar_darkgray_base_100.png | binary | |
MD5:C00E8876653CDD4EEC651860E544E7B3 | SHA256:E5A638D5C49F3F1D794062EE82C0B7BB122AA4AFD400217392D7274DC158AE72 | |||
| 324 | ranware.exe | C:\Users\admin\AppData\Local\Adobe\A0A2C719-B8B1-4DC7-B33B-C50E709F20B0\progressbar_darkgray_base_200.png | binary | |
MD5:C00E8876653CDD4EEC651860E544E7B3 | SHA256:E5A638D5C49F3F1D794062EE82C0B7BB122AA4AFD400217392D7274DC158AE72 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |