| File name: | injector.exe |
| Full analysis: | https://app.any.run/tasks/590ab5b7-64a5-4ea0-abd8-6fcd8b849eb8 |
| Verdict: | Malicious activity |
| Analysis date: | October 26, 2023, 11:39:40 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 448064E48D4D61F213FB8889D672EE46 |
| SHA1: | CDEE079DBA3325980192938B05AB661801612F24 |
| SHA256: | CB936C01E3BF684DC3E48EBDDAA711ABB3E6C2175975715D6B09F6D76F13C405 |
| SSDEEP: | 384:U6q/rquCaNc3jMk3FHsFeH7xWst15Buv:UWuCAvqB70st15BG |
| .dll | | | Win32 Dynamic Link Library (generic) (43.5) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (29.8) |
| .exe | | | Generic Win/DOS Executable (13.2) |
| .exe | | | DOS Executable Generic (13.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:10:26 13:27:56+02:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 11 |
| CodeSize: | 13312 |
| InitializedDataSize: | 20992 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x154c |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 576 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2328 | C:\Users\admin\Desktop\injector.exe | C:\Users\admin\Desktop\injector.exe | runas.exe | ||||||||||||
User: Administrator Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2752 | "C:\Windows\System32\runas.exe" /user:administrator C:\Users\admin\Desktop\injector.exe | C:\Windows\System32\runas.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Run As Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2328) injector.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | userini |
Value: C:\Windows\system32\userini.exe | |||
| (PID) Process: | (2328) injector.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run |
| Operation: | write | Name: | userini |
Value: C:\Windows\system32\userini.exe | |||
| (PID) Process: | (2328) injector.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | userini |
Value: C:\Windows\system32\userini.exe | |||
| (PID) Process: | (2328) injector.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\Run |
| Operation: | write | Name: | userini |
Value: C:\Windows\system32\userini.exe | |||
| (PID) Process: | (2328) injector.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | delete value | Name: | ProxyBypass |
Value: 0 | |||
| (PID) Process: | (2328) injector.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | delete value | Name: | IntranetName |
Value: 0 | |||
| (PID) Process: | (2328) injector.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2328) injector.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2328) injector.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2328) injector.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2328 | injector.exe | C:\Windows\system32\userini.exe | executable | |
MD5:448064E48D4D61F213FB8889D672EE46 | SHA256:CB936C01E3BF684DC3E48EBDDAA711ABB3E6C2175975715D6B09F6D76F13C405 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2328 | injector.exe | GET | — | 18.158.249.75:80 | http://32a2-2a01-e34-ec67-99e0-2911-f69e-8593-8211.ngrok-free.app/page.php | unknown | — | — | unknown |
2328 | injector.exe | GET | 200 | 18.158.249.75:80 | http://32a2-2a01-e34-ec67-99e0-2911-f69e-8593-8211.ngrok-free.app/page.php | unknown | text | 70.8 Kb | unknown |
2328 | injector.exe | GET | 200 | 18.158.249.75:80 | http://32a2-2a01-e34-ec67-99e0-2911-f69e-8593-8211.ngrok-free.app/page.php | unknown | text | 70.7 Kb | unknown |
2328 | injector.exe | GET | 200 | 18.158.249.75:80 | http://32a2-2a01-e34-ec67-99e0-2911-f69e-8593-8211.ngrok-free.app/page.php | unknown | text | 70.6 Kb | unknown |
2328 | injector.exe | GET | 200 | 18.158.249.75:80 | http://32a2-2a01-e34-ec67-99e0-2911-f69e-8593-8211.ngrok-free.app/page.php | unknown | text | 70.7 Kb | unknown |
2328 | injector.exe | GET | 200 | 18.158.249.75:80 | http://32a2-2a01-e34-ec67-99e0-2911-f69e-8593-8211.ngrok-free.app/page.php | unknown | text | 70.8 Kb | unknown |
2328 | injector.exe | GET | 200 | 18.158.249.75:80 | http://32a2-2a01-e34-ec67-99e0-2911-f69e-8593-8211.ngrok-free.app/page.php | unknown | text | 70.8 Kb | unknown |
2328 | injector.exe | GET | 200 | 18.158.249.75:80 | http://32a2-2a01-e34-ec67-99e0-2911-f69e-8593-8211.ngrok-free.app/page.php | unknown | text | 70.4 Kb | unknown |
2328 | injector.exe | GET | 200 | 18.158.249.75:80 | http://32a2-2a01-e34-ec67-99e0-2911-f69e-8593-8211.ngrok-free.app/page.php | unknown | text | 70.5 Kb | unknown |
2328 | injector.exe | GET | 200 | 18.158.249.75:80 | http://32a2-2a01-e34-ec67-99e0-2911-f69e-8593-8211.ngrok-free.app/page.php | unknown | text | 70.7 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2328 | injector.exe | 18.158.249.75:80 | 32a2-2a01-e34-ec67-99e0-2911-f69e-8593-8211.ngrok-free.app | AMAZON-02 | DE | unknown |
2328 | injector.exe | 98.136.96.92:25 | mx-aol.mail.gm0.yahoodns.net | YAHOO-NE1 | US | unknown |
2328 | injector.exe | 80.12.26.32:25 | smtp-in.orange.fr | Orange | FR | unknown |
2328 | injector.exe | 104.47.58.161:25 | hotmail-com.olc.protection.outlook.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
2328 | injector.exe | 67.219.246.209:25 | cluster4.us.messagelabs.com | AMAZON-AES | US | unknown |
2328 | injector.exe | 67.195.204.82:25 | mx-rogers.mail.am0.yahoodns.net | YAHOO-BF1 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
32a2-2a01-e34-ec67-99e0-2911-f69e-8593-8211.ngrok-free.app |
| unknown |
aol.com |
| unknown |
mx-aol.mail.gm0.yahoodns.net |
| unknown |
orange.fr |
| unknown |
smtp-in.orange.fr |
| unknown |
hotmail.com |
| unknown |
hotmail-com.olc.protection.outlook.com |
| shared |
ford.com |
| unknown |
cluster4.us.messagelabs.com |
| unknown |
rogers.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
2328 | injector.exe | Generic Protocol Command Decode | SURICATA SMTP no server welcome message |
2328 | injector.exe | Generic Protocol Command Decode | SURICATA SMTP no server welcome message |
2328 | injector.exe | Generic Protocol Command Decode | SURICATA SMTP no server welcome message |
2328 | injector.exe | Generic Protocol Command Decode | SURICATA SMTP no server welcome message |
2328 | injector.exe | Generic Protocol Command Decode | SURICATA SMTP data command rejected |
2328 | injector.exe | Generic Protocol Command Decode | SURICATA SMTP data command rejected |
2328 | injector.exe | Generic Protocol Command Decode | SURICATA SMTP no server welcome message |
2328 | injector.exe | Generic Protocol Command Decode | SURICATA SMTP no server welcome message |
2328 | injector.exe | Generic Protocol Command Decode | SURICATA SMTP no server welcome message |
2328 | injector.exe | Generic Protocol Command Decode | SURICATA SMTP no server welcome message |