File name:

ChimeraInstaller.exe

Full analysis: https://app.any.run/tasks/0966ea86-0e85-4d46-b1c2-5cc1a6acc092
Verdict: Malicious activity
Analysis date: December 11, 2023, 15:52:06
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed
MD5:

34CCA09CCC351EE6E292AC9F6674BC9E

SHA1:

BC3C97EF7325D0F5A9C0972C2319429D4C11F543

SHA256:

CCC8EA653C0F5EF241D4F47AD757918C98F530B2072E234180E4A30A0D85A065

SSDEEP:

196608:bnoBjn6NrW719ck+i+fy9ikn7ZxUekUf5Jw9UmSbz/5/U9+4kfZ:Et6NK7Oy9iHJC5J/bz/5/M+4kZ

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Chimera.exe (PID: 3176)
      • ChimeraInstaller.exe (PID: 2292)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • ChimeraInstaller.exe (PID: 2292)
    • Reads settings of System Certificates

      • Chimera.exe (PID: 3176)
    • Reads the BIOS version

      • Chimera.exe (PID: 3176)
    • Reads the Internet Settings

      • Chimera.exe (PID: 3176)
    • Detected use of alternative data streams (AltDS)

      • Chimera.exe (PID: 3176)
    • Runs PING.EXE to delay simulation

      • cmd.exe (PID: 240)
  • INFO

    • Creates files or folders in the user directory

      • ChimeraInstaller.exe (PID: 2292)
      • Chimera.exe (PID: 3176)
    • Checks supported languages

      • ChimeraInstaller.exe (PID: 2292)
      • Chimera.exe (PID: 3176)
    • Reads the computer name

      • ChimeraInstaller.exe (PID: 2292)
      • Chimera.exe (PID: 3176)
    • Reads the machine GUID from the registry

      • ChimeraInstaller.exe (PID: 2292)
    • Process checks are UAC notifies on

      • Chimera.exe (PID: 3176)
    • Creates files in the program directory

      • ChimeraInstaller.exe (PID: 2292)
      • Chimera.exe (PID: 3176)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | UPX compressed Win32 Executable (76)
.exe | Win32 Executable (generic) (12.6)
.exe | Generic Win/DOS Executable (5.6)
.exe | DOS Executable Generic (5.6)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:03:26 15:01:01+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14
CodeSize: 7864320
InitializedDataSize: 86016
UninitializedDataSize: 20398080
EntryPoint: 0x1af3be0
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 6.55.1457.0
ProductVersionNumber: 6.55.1457.0
FileFlagsMask: 0x0017
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Euroserver Sro.
FileDescription: Chimera mobile tool installer
InternalName: chimeraInstaller
LegalCopyright: Copyright (C) 2016 Euroserver Sro.
OriginalFileName: ChimeraInstaller.exe
ProductName: Chimera Installer
FileVersion: 6, 55, 1457, 0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
45
Monitored processes
5
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start chimerainstaller.exe cmd.exe no specs chimera.exe ping.exe no specs chimerainstaller.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
240cmd.exe /C ping 127.0.0.1 -n 2 -w 3000 > Nul & rd /s /q C:\Program Files\Chimera\DriversC:\Windows\System32\cmd.exeChimeraInstaller.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
3
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2292"C:\Users\admin\AppData\Local\Temp\ChimeraInstaller.exe" C:\Users\admin\AppData\Local\Temp\ChimeraInstaller.exe
explorer.exe
User:
admin
Company:
Euroserver Sro.
Integrity Level:
HIGH
Description:
Chimera mobile tool installer
Exit code:
0
Version:
6, 55, 1457, 0
Modules
Images
c:\users\admin\appdata\local\temp\chimerainstaller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
2464"C:\Users\admin\AppData\Local\Temp\ChimeraInstaller.exe" C:\Users\admin\AppData\Local\Temp\ChimeraInstaller.exeexplorer.exe
User:
admin
Company:
Euroserver Sro.
Integrity Level:
MEDIUM
Description:
Chimera mobile tool installer
Exit code:
3221226540
Version:
6, 55, 1457, 0
Modules
Images
c:\users\admin\appdata\local\temp\chimerainstaller.exe
c:\windows\system32\ntdll.dll
2716ping 127.0.0.1 -n 2 -w 3000 C:\Windows\System32\PING.EXEcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ping.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\iphlpapi.dll
c:\windows\system32\nsi.dll
3176"C:\Program Files\Chimera\Chimera.exe" showchangelogC:\Program Files\Chimera\Chimera.exe
ChimeraInstaller.exe
User:
admin
Company:
Griff Gate Ltd.
Integrity Level:
HIGH
Description:
ChimeraTool mobile service software
Exit code:
0
Version:
37, 67, 1048, 0
Modules
Images
c:\program files\chimera\chimera.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\setupapi.dll
c:\windows\system32\cfgmgr32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
Total events
2 248
Read events
2 246
Write events
2
Delete events
0

Modification events

(PID) Process:(2292) ChimeraInstaller.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
Explorer.EXE
(PID) Process:(3176) Chimera.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication
Operation:writeName:Name
Value:
ChimeraInstaller.exe
Executable files
4
Suspicious files
481
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
2292ChimeraInstaller.exeC:\Users\admin\AppData\Local\ChimeraInstaller\cache\qmlcache\9779a7429fce2510e47ce1a9b32b01bfc446a599.jsc.Ya2292binary
MD5:D54FF5C7548719A6A6C27887E2C9AC0D
SHA256:BB5BD68D79D63AA896E63492DCED9DDA6BEC6E3FFA20CC6CF0494654AFB2F4B7
2292ChimeraInstaller.exeC:\Users\admin\AppData\Local\ChimeraInstaller\cache\qmlcache\170ac466fb099e5966c88f98dc00006766876aac.qmlcbinary
MD5:1512791F9E73EC2B4B10400473D52744
SHA256:77B012A49A6B1AC2AC8931AA97B59CA6E227B63B85268F4B60A259CE10C659B2
2292ChimeraInstaller.exeC:\Users\admin\AppData\Local\ChimeraInstaller\cache\qmlcache\c45e0a706eb6ccbb094e556ff56d02266ca8f60c.qmlcbinary
MD5:D329A015C3D08D1B2F58B4CF9E03E35A
SHA256:FCE2A69EDA2DA1FA9EC740DD0F256D884A7FB05145C86E7D3EC76DB62DE0B176
2292ChimeraInstaller.exeC:\Users\admin\AppData\Local\ChimeraInstaller\cache\qmlcache\60275f5f6e33c334fc27395521c9281b31d7c5ab.qmlcbinary
MD5:23E104189383168335A59B1B7977B86B
SHA256:02850E7D904B9610E78F3B13349868DA27CECDAFB338A632702DE517DCDD4155
2292ChimeraInstaller.exeC:\Users\admin\AppData\Local\ChimeraInstaller\cache\qmlcache\4cc811ad3a00e44dac571a176d367310c763fbb5.qmlcbinary
MD5:215C053F7057C1D4A0CFF7769D8B82A3
SHA256:A43D3D42282979414AC9BDF27A91D745EF8DD310F68664137AB56A87DBDD1D35
2292ChimeraInstaller.exeC:\Users\admin\AppData\Local\ChimeraInstaller\cache\qmlcache\9779a7429fce2510e47ce1a9b32b01bfc446a599.jscbinary
MD5:D54FF5C7548719A6A6C27887E2C9AC0D
SHA256:BB5BD68D79D63AA896E63492DCED9DDA6BEC6E3FFA20CC6CF0494654AFB2F4B7
2292ChimeraInstaller.exeC:\Users\admin\AppData\Local\ChimeraInstaller\cache\qmlcache\60275f5f6e33c334fc27395521c9281b31d7c5ab.qmlc.cr2292binary
MD5:23E104189383168335A59B1B7977B86B
SHA256:02850E7D904B9610E78F3B13349868DA27CECDAFB338A632702DE517DCDD4155
2292ChimeraInstaller.exeC:\Users\admin\AppData\Local\ChimeraInstaller\cache\qmlcache\619572f4c59c16656b0e91e66eead08b0e301f06.jscbinary
MD5:850B4391D84AC1E95C44A45E9F458A03
SHA256:A4530E9DEE2CB7DFA4FA22321624FC798BD7F377020232F38E3CE3A6F6E01B1F
2292ChimeraInstaller.exeC:\Users\admin\AppData\Local\ChimeraInstaller\cache\qmlcache\9764a0cf7398d05f1f046dc0c358adf765f28657.jsc.Nl2292binary
MD5:96678B8BD1C4DDF39AD6F67980621EAB
SHA256:441C9DA67C9316D0F850C1AE534AA9BE152B9AFCE3BB9FC8180BDD84B55904C9
2292ChimeraInstaller.exeC:\Users\admin\AppData\Local\ChimeraInstaller\cache\qmlcache\e4ef80837691d5be54fee0047ddf51951a963467.jscbinary
MD5:E3F5DDF4C0D9BC5BC5F52D31C6D3B3E7
SHA256:B80567D9C44534F1C8D469EF7DA280B2B61B6A281729423280FB237F48B6C1DA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
10
DNS requests
3
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2292
ChimeraInstaller.exe
104.20.77.245:443
chimeratool.com
CLOUDFLARENET
shared
2292
ChimeraInstaller.exe
104.20.78.245:443
chimeratool.com
CLOUDFLARENET
shared
2292
ChimeraInstaller.exe
104.18.14.248:443
data.chimeratool.com
CLOUDFLARENET
unknown

DNS requests

Domain
IP
Reputation
chimeratool.com
  • 104.20.78.245
  • 104.20.77.245
whitelisted
data.chimeratool.com
  • 104.18.14.248
  • 104.18.15.248
unknown

Threats

No threats detected
Process
Message
ChimeraInstaller.exe
QWindowsEGLStaticContext::doTest: Failed to load and resolve libEGL functions
ChimeraInstaller.exe
Failed to load libEGL (The specified module could not be found.)