File name:

windows_10_cmake_Release_graphviz-install-12.1.0-win64.exe

Full analysis: https://app.any.run/tasks/6ec678a8-3bab-4946-b248-4061851cd101
Verdict: Malicious activity
Analysis date: August 25, 2024, 20:20:31
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

9564050473AE87264B1D4D3378A82F5D

SHA1:

91E47CFC3AF8062200414F65D38767032C55975B

SHA256:

D37482360888F70FAF14B4E9D100F4EAAA42AAD716B8142F282EA0C218FFA5B7

SSDEEP:

98304:sI8n4O4Ilto1l8QycJHQ9LjNT6NirvTABuwWEuW8+tP4+FnK+D/DizqOhvJxCIGf:FDs1hABe2f6ON

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • windows_10_cmake_Release_graphviz-install-12.1.0-win64.exe (PID: 6784)
    • Executable content was dropped or overwritten

      • windows_10_cmake_Release_graphviz-install-12.1.0-win64.exe (PID: 6784)
    • The process creates files with name similar to system file names

      • windows_10_cmake_Release_graphviz-install-12.1.0-win64.exe (PID: 6784)
    • Creates a software uninstall entry

      • windows_10_cmake_Release_graphviz-install-12.1.0-win64.exe (PID: 6784)
    • Drops the executable file immediately after the start

      • windows_10_cmake_Release_graphviz-install-12.1.0-win64.exe (PID: 6784)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • windows_10_cmake_Release_graphviz-install-12.1.0-win64.exe (PID: 6784)
    • The process drops C-runtime libraries

      • windows_10_cmake_Release_graphviz-install-12.1.0-win64.exe (PID: 6784)
  • INFO

    • Creates files in the program directory

      • windows_10_cmake_Release_graphviz-install-12.1.0-win64.exe (PID: 6784)
    • Reads the computer name

      • windows_10_cmake_Release_graphviz-install-12.1.0-win64.exe (PID: 6784)
    • Checks supported languages

      • windows_10_cmake_Release_graphviz-install-12.1.0-win64.exe (PID: 6784)
    • Create files in a temporary directory

      • windows_10_cmake_Release_graphviz-install-12.1.0-win64.exe (PID: 6784)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2020:08:01 02:53:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 25088
InitializedDataSize: 262144
UninitializedDataSize: 8192
EntryPoint: 0x3312
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
166
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start windows_10_cmake_release_graphviz-install-12.1.0-win64.exe windows_10_cmake_release_graphviz-install-12.1.0-win64.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
6736"C:\Users\admin\AppData\Local\Temp\windows_10_cmake_Release_graphviz-install-12.1.0-win64.exe" C:\Users\admin\AppData\Local\Temp\windows_10_cmake_Release_graphviz-install-12.1.0-win64.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\windows_10_cmake_release_graphviz-install-12.1.0-win64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
6784"C:\Users\admin\AppData\Local\Temp\windows_10_cmake_Release_graphviz-install-12.1.0-win64.exe" C:\Users\admin\AppData\Local\Temp\windows_10_cmake_Release_graphviz-install-12.1.0-win64.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\windows_10_cmake_release_graphviz-install-12.1.0-win64.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
Total events
3 268
Read events
3 253
Write events
15
Delete events
0

Modification events

(PID) Process:(6784) windows_10_cmake_Release_graphviz-install-12.1.0-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Graphviz
Operation:writeName:DisplayName
Value:
Graphviz
(PID) Process:(6784) windows_10_cmake_Release_graphviz-install-12.1.0-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Graphviz
Operation:writeName:DisplayVersion
Value:
12.1.0
(PID) Process:(6784) windows_10_cmake_Release_graphviz-install-12.1.0-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Graphviz
Operation:writeName:Publisher
Value:
Graphviz
(PID) Process:(6784) windows_10_cmake_Release_graphviz-install-12.1.0-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Graphviz
Operation:writeName:UninstallString
Value:
"C:\Program Files\Graphviz\Uninstall.exe"
(PID) Process:(6784) windows_10_cmake_Release_graphviz-install-12.1.0-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Graphviz
Operation:writeName:NoRepair
Value:
1
(PID) Process:(6784) windows_10_cmake_Release_graphviz-install-12.1.0-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Graphviz
Operation:writeName:NoModify
Value:
1
(PID) Process:(6784) windows_10_cmake_Release_graphviz-install-12.1.0-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Graphviz
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Graphviz\Uninstall.exe
(PID) Process:(6784) windows_10_cmake_Release_graphviz-install-12.1.0-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Graphviz
Operation:writeName:HelpLink
Value:
https://www.graphviz.org
(PID) Process:(6784) windows_10_cmake_Release_graphviz-install-12.1.0-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Graphviz
Operation:writeName:URLInfoAbout
Value:
https://www.graphviz.org
(PID) Process:(6784) windows_10_cmake_Release_graphviz-install-12.1.0-win64.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\Graphviz
Operation:writeName:StartMenu
Value:
Graphviz
Executable files
99
Suspicious files
16
Text files
131
Unknown types
1

Dropped files

PID
Process
Filename
Type
6784windows_10_cmake_Release_graphviz-install-12.1.0-win64.exeC:\Users\admin\AppData\Local\Temp\nsiE25F.tmp\modern-header.bmpimage
MD5:940C56737BF9BB69CE7A31C623D4E87A
SHA256:766A893FE962AEFD27C574CB05F25CF895D3FC70A00DB5A6FA73D573F571AEFC
6784windows_10_cmake_Release_graphviz-install-12.1.0-win64.exeC:\Users\admin\AppData\Local\Temp\nsiE25F.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
6784windows_10_cmake_Release_graphviz-install-12.1.0-win64.exeC:\Users\admin\AppData\Local\Temp\nsiE25F.tmp\UserInfo.dllexecutable
MD5:ACBDA33DD5700C122E2FE48E3D4351FD
SHA256:943B33829F9013E4D361482A5C8981BA20A7155C78691DBE02A8F8CD2A02EFA0
6784windows_10_cmake_Release_graphviz-install-12.1.0-win64.exeC:\Users\admin\AppData\Local\Temp\nsiE25F.tmp\StartMenu.dllexecutable
MD5:26836307758E048D1CE0AFE754D6A972
SHA256:A6919F5F3B53A9C8C015413BABE7A9872491A2583E49BB3C261E60785C3C3534
6784windows_10_cmake_Release_graphviz-install-12.1.0-win64.exeC:\Users\admin\AppData\Local\Temp\nsiE25F.tmp\InstallOptions.dllexecutable
MD5:5F35212D7E90EE622B10BE39B09BD270
SHA256:31944B93E44301974D9C6F810D2DA792E34A53DCACD619A08CB0385AC59E513D
6784windows_10_cmake_Release_graphviz-install-12.1.0-win64.exeC:\Users\admin\AppData\Local\Temp\nsiE25F.tmp\ioSpecial.iniini
MD5:E2D5070BC28DB1AC745613689FF86067
SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0
6784windows_10_cmake_Release_graphviz-install-12.1.0-win64.exeC:\Users\admin\AppData\Local\Temp\nsiE25F.tmp\NSIS.InstallOptions.initext
MD5:7DB6AE6FB6E11CE14465C21470CC5080
SHA256:F9E0B0FCD3CF9DFABEE7F9A7542E3831D22F49312584088516402A420F19AE84
6784windows_10_cmake_Release_graphviz-install-12.1.0-win64.exeC:\Program Files\Graphviz\bin\cairo-2.dllexecutable
MD5:475EFBFFA3B35C5ED1BCEBDEF32BA5DF
SHA256:2A2738F1A4AC92F59367EDFDD34AE67005AD7BE9ECAF1BF734C3160BCA25D9C7
6784windows_10_cmake_Release_graphviz-install-12.1.0-win64.exeC:\Program Files\Graphviz\bin\bz2.dllexecutable
MD5:DC3AEE8E0253B90330235EE20EFC8961
SHA256:85E3BE4D6BCBD3685B1A5362100CE8F907E9FE9DC92D6FA53703A8DA9ACA5CFF
6784windows_10_cmake_Release_graphviz-install-12.1.0-win64.exeC:\Program Files\Graphviz\bin\brotlidec.dllexecutable
MD5:F49F531C764127326902958AAD152A55
SHA256:F8C378E342B59279ECA07CE22BB94A4D9B0ED924181640CEAC918989CD40A5B2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
74
DNS requests
59
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2224
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
6176
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6176
SIHClient.exe
GET
200
184.30.21.171:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5336
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2720
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
2904
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2720
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3260
svchost.exe
40.113.110.67:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2120
MoUsoCoreWorker.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2224
svchost.exe
40.126.32.140:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
unknown
2224
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
6176
SIHClient.exe
40.127.169.103:443
slscr.update.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 20.73.194.208
  • 51.104.136.2
  • 4.231.128.59
whitelisted
google.com
  • 142.250.185.206
whitelisted
client.wns.windows.com
  • 40.113.110.67
whitelisted
login.live.com
  • 40.126.32.140
  • 40.126.32.76
  • 20.190.160.20
  • 40.126.32.68
  • 20.190.160.14
  • 40.126.32.133
  • 20.190.160.22
  • 40.126.32.72
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
slscr.update.microsoft.com
  • 40.127.169.103
whitelisted
www.microsoft.com
  • 184.30.21.171
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.3.187.198
whitelisted
www.bing.com
  • 2.23.209.133
  • 2.23.209.176
  • 2.23.209.182
  • 2.23.209.140
  • 2.23.209.189
  • 2.23.209.187
  • 2.23.209.179
  • 2.23.209.149
  • 2.23.209.185
  • 2.23.209.130
whitelisted
th.bing.com
  • 2.23.209.182
  • 2.23.209.179
  • 2.23.209.187
  • 2.23.209.140
  • 2.23.209.185
  • 2.23.209.130
  • 2.23.209.149
  • 2.23.209.176
  • 2.23.209.189
  • 2.23.209.133
whitelisted

Threats

No threats detected
No debug info