File name:

AC22_K_Up7_V1.1.exe

Full analysis: https://app.any.run/tasks/c56c6290-088f-49c7-8308-bbd5fcce14eb
Verdict: Malicious activity
Analysis date: March 13, 2024, 17:46:30
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, PECompact2 compressed
MD5:

26184480E6E7DB6E2E87956A891A466D

SHA1:

45ECEE492A00FF838B0839CE5E0743638A02102B

SHA256:

D716C9742749CB48E5F761F7BEF98D97C02BC7BF3C865C673076C23F98E03A86

SSDEEP:

49152:D7Ac9KrOwCzpn3UOF0IXtBFUi8amQxn4hFJiOtlWjx+1TsOGUJDJ0GQqspQCplwg:DEfHCzxWIXjxLx4hqmGq7Jd0GQDexw

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • AC22_K_Up7_V1.1.exe (PID: 2852)
      • AC22_K_Up7_V1.1.exe (PID: 3684)
      • AC22_K_Up7_V1.1.exe (PID: 3680)
      • AC22_K_Up7_V1.1.exe (PID: 2516)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • AC22_K_Up7_V1.1.exe (PID: 3684)
      • AC22_K_Up7_V1.1.exe (PID: 2852)
      • AC22_K_Up7_V1.1.exe (PID: 3680)
      • AC22_K_Up7_V1.1.exe (PID: 2516)
  • INFO

    • Checks supported languages

      • AC22_K_Up7_V1.1.exe (PID: 2852)
      • AC22_K_Up7_V1.1.exe (PID: 3684)
      • AC22_K_Up7_V1.1.exe (PID: 3680)
      • AC22_K_Up7_V1.1.exe (PID: 2516)
      • mode.com (PID: 908)
      • MEP-ENERGY.exe (PID: 2104)
    • Reads the computer name

      • AC22_K_Up7_V1.1.exe (PID: 2852)
      • AC22_K_Up7_V1.1.exe (PID: 3684)
      • AC22_K_Up7_V1.1.exe (PID: 3680)
      • AC22_K_Up7_V1.1.exe (PID: 2516)
    • Create files in a temporary directory

      • AC22_K_Up7_V1.1.exe (PID: 2852)
      • AC22_K_Up7_V1.1.exe (PID: 3684)
      • AC22_K_Up7_V1.1.exe (PID: 3680)
      • AC22_K_Up7_V1.1.exe (PID: 2516)
    • Manual execution by a user

      • AC22_K_Up7_V1.1.exe (PID: 2672)
      • AC22_K_Up7_V1.1.exe (PID: 3684)
      • AC22_K_Up7_V1.1.exe (PID: 1844)
      • AC22_K_Up7_V1.1.exe (PID: 3680)
      • AC22_K_Up7_V1.1.exe (PID: 2516)
      • MEP-ENERGY.exe (PID: 2104)
      • cmd.exe (PID: 3380)
      • rundll32.exe (PID: 2124)
      • rundll32.exe (PID: 3228)
      • notepad.exe (PID: 3708)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 EXE PECompact compressed (v2.x) (51)
.exe | Win32 EXE PECompact compressed (generic) (35.9)
.dll | Win32 Dynamic Link Library (generic) (5.6)
.exe | Win32 Executable (generic) (3.8)
.exe | Generic Win/DOS Executable (1.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2007:11:14 16:27:56+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 954368
InitializedDataSize: 675840
UninitializedDataSize: -
EntryPoint: 0x1000
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x003f
FileFlags: Private build, Special build
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: -
AtedwithMultimediaBuilder: -
Ion49813: -
TName: -
SpecialBuild: 1.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
93
Monitored processes
39
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start ac22_k_up7_v1.1.exe ac22_k_up7_v1.1.exe no specs ac22_k_up7_v1.1.exe ac22_k_up7_v1.1.exe no specs ac22_k_up7_v1.1.exe ac22_k_up7_v1.1.exe mep-energy.exe no specs cmd.exe no specs mode.com no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs find.exe no specs notepad.exe no specs rundll32.exe no specs rundll32.exe no specs ac22_k_up7_v1.1.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
908mode con cols=50 lines=30C:\Windows\System32\mode.comcmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
DOS Device MODE Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\mode.com
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ulib.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1388FIND /C /I "par10s34-in-f8.1e100.net" C:\Windows\system32\drivers\etc\hostsC:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (grep) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1844"C:\Users\admin\Desktop\Archicad 22\AC22_K_Up7_V1.1.exe" C:\Users\admin\Desktop\Archicad 22\AC22_K_Up7_V1.1.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\archicad 22\ac22_k_up7_v1.1.exe
c:\windows\system32\ntdll.dll
1880FIND /C /I "gs-com.cloudapp.net" C:\Windows\system32\drivers\etc\hostsC:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (grep) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2104"C:\Users\admin\AppData\Local\Temp\MMBPlayer\MEP-ENERGY.exe" C:\Users\admin\AppData\Local\Temp\MMBPlayer\MEP-ENERGY.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\mmbplayer\mep-energy.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2124"C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\AppData\Local\Temp\MMBPlayer\GSLicenseManager.dllC:\Windows\System32\rundll32.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
2316FIND /C /I "usagelogger.graphisoft.com" C:\Windows\system32\drivers\etc\hostsC:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (grep) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2500FIND /C /I "par10s22-in-f232.1e100.net" C:\Windows\system32\drivers\etc\hostsC:\Windows\System32\find.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Find String (grep) Utility
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\find.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ulib.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2516"C:\Users\admin\Desktop\Archicad 22\AC22_K_Up7_V1.1.exe" C:\Users\admin\Desktop\Archicad 22\AC22_K_Up7_V1.1.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\desktop\archicad 22\ac22_k_up7_v1.1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
2672"C:\Users\admin\Desktop\Archicad22\AC22_K_Up7_V1.1.exe" C:\Users\admin\Desktop\Archicad22\AC22_K_Up7_V1.1.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\desktop\archicad22\ac22_k_up7_v1.1.exe
c:\windows\system32\ntdll.dll
Total events
6 954
Read events
6 930
Write events
24
Delete events
0

Modification events

(PID) Process:(2852) AC22_K_Up7_V1.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
Operation:writeName:Name
Value:
AC22_K_Up7_V1.1.exe
(PID) Process:(2852) AC22_K_Up7_V1.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
Operation:writeName:ID
Value:
(PID) Process:(2852) AC22_K_Up7_V1.1.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\DirectSound\Speaker Configuration
Operation:writeName:Speaker Configuration
Value:
4
(PID) Process:(3684) AC22_K_Up7_V1.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
Operation:writeName:Name
Value:
AC22_K_Up7_V1.1.exe
(PID) Process:(3684) AC22_K_Up7_V1.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
Operation:writeName:ID
Value:
(PID) Process:(3684) AC22_K_Up7_V1.1.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\DirectSound\Speaker Configuration
Operation:writeName:Speaker Configuration
Value:
4
(PID) Process:(3680) AC22_K_Up7_V1.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
Operation:writeName:Name
Value:
AC22_K_Up7_V1.1.exe
(PID) Process:(3680) AC22_K_Up7_V1.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
Operation:writeName:ID
Value:
(PID) Process:(3680) AC22_K_Up7_V1.1.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\MediaResources\DirectSound\Speaker Configuration
Operation:writeName:Speaker Configuration
Value:
4
(PID) Process:(2516) AC22_K_Up7_V1.1.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectDraw\MostRecentApplication
Operation:writeName:Name
Value:
AC22_K_Up7_V1.1.exe
Executable files
12
Suspicious files
5
Text files
4
Unknown types
3

Dropped files

PID
Process
Filename
Type
3684AC22_K_Up7_V1.1.exeC:\Users\admin\AppData\Local\Temp\MMBPlayer\GSLicenseBase.dllexecutable
MD5:E9D614FFB5ED355F334743E4109AC2D0
SHA256:939812D76ABB4B4E3E1003E105317A0C1EC03408FECDB1490BC65A2CB26ADD63
3684AC22_K_Up7_V1.1.exeC:\Users\admin\AppData\Local\Temp\MMBPlayer\MEP-ENERGY.exeexecutable
MD5:B11B70541836FEB508001B8BE468A0D1
SHA256:D62884B252A5AE3ABE0A1EE3A27649CC0E952F388FD5EB343B8EB8C151E46AD5
3680AC22_K_Up7_V1.1.exeC:\Users\admin\AppData\Local\Temp\MMBPlayer\GSLicenseManager.dllexecutable
MD5:C76B13A38515F6A8C90794BA21BDCD71
SHA256:460AEBE2A4F7D6726553B10C273EFDFC2370DCC366821B6B0BFEF6DC1765EA70
2852AC22_K_Up7_V1.1.exeC:\Users\admin\AppData\Local\Temp\MMBPlayer\MEP-ENERGY.exeexecutable
MD5:B11B70541836FEB508001B8BE468A0D1
SHA256:D62884B252A5AE3ABE0A1EE3A27649CC0E952F388FD5EB343B8EB8C151E46AD5
2852AC22_K_Up7_V1.1.exeC:\Users\admin\AppData\Local\Temp\MMBPlayer\ODBA.INIbinary
MD5:CC9980126690359D99B7176D5AF26F7A
SHA256:9B2105857B6CC6D3EFC75E27C2AE2A14E7DB22B1D7537A221770CD96D2E022CA
2852AC22_K_Up7_V1.1.exeC:\Users\admin\AppData\Local\Temp\MMBPlayer\GSLicenseManager.dllexecutable
MD5:C76B13A38515F6A8C90794BA21BDCD71
SHA256:460AEBE2A4F7D6726553B10C273EFDFC2370DCC366821B6B0BFEF6DC1765EA70
2852AC22_K_Up7_V1.1.exeC:\Users\admin\AppData\Local\Temp\MMBPlayer\script.battext
MD5:1C907C10F8920F3B041050D8DAF44CE0
SHA256:48290436C76390B2F87FE90A657B7890B0E30240707179F8D27A6BB3A5F3AE92
2852AC22_K_Up7_V1.1.exeC:\Users\admin\AppData\Local\Temp\MMBPlayer\_mct_xm_Hello Sid-Riders!.tmpbinary
MD5:B7CAA9846606025B99D5ADD789E0855D
SHA256:83CFB29A6209DC760E7ABE14FAC1DE41DD5F70F0745890E0658CE08A58E74E14
2852AC22_K_Up7_V1.1.exeC:\Users\admin\AppData\Local\Temp\MMBPlayer\GSLicenseBase.dllexecutable
MD5:E9D614FFB5ED355F334743E4109AC2D0
SHA256:939812D76ABB4B4E3E1003E105317A0C1EC03408FECDB1490BC65A2CB26ADD63
3684AC22_K_Up7_V1.1.exeC:\Users\admin\AppData\Local\Temp\MMBPlayer\_mct_xm_Hello Sid-Riders!.tmpxm
MD5:B7CAA9846606025B99D5ADD789E0855D
SHA256:83CFB29A6209DC760E7ABE14FAC1DE41DD5F70F0745890E0658CE08A58E74E14
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info