| File name: | skype.exe |
| Full analysis: | https://app.any.run/tasks/742b1ad9-838c-4938-96cf-408360b1ca59 |
| Verdict: | Malicious activity |
| Analysis date: | October 07, 2024, 17:17:08 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (console) Intel 80386, for MS Windows |
| MD5: | D11743B11A65AB7CA9A61913151BAC40 |
| SHA1: | 42E182D0CD1D3BB2F055BE55ABE880C675BA9DAD |
| SHA256: | DB27FD09303A4B73F0635E779269C53938425B7F631345B5F2A96739F2185DF7 |
| SSDEEP: | 98304:UNxBUQD+XIYLPZNvQ/Hw0704B6LQ4mJWje3yuTf4ufYRD0fpVufyEHVP05P0x19U:8eWxjPCtlKcKqOLFdZ |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:08:08 12:29:54+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 128000 |
| InitializedDataSize: | 116736 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x781a |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows command line |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3212 | "C:\Users\admin\AppData\Local\Temp\skype.exe" | C:\Users\admin\AppData\Local\Temp\skype.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 4294967295 Modules
| |||||||||||||||
| 3556 | "C:\Users\admin\AppData\Local\Temp\skype.exe" | C:\Users\admin\AppData\Local\Temp\skype.exe | skype.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 4294967295 Modules
| |||||||||||||||
| 3848 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3212 | skype.exe | C:\Users\admin\AppData\Local\Temp\_MEI32122\api-ms-win-core-datetime-l1-1-0.dll | executable | |
MD5:CB978304B79EF53962408C611DFB20F5 | SHA256:90FAE0E7C3644A6754833C42B0AC39B6F23859F9A7CF4B6C8624820F59B9DAD3 | |||
| 3212 | skype.exe | C:\Users\admin\AppData\Local\Temp\_MEI32122\_lzma.pyd | executable | |
MD5:B7F979DBAC49A9908B1EF32602D345E0 | SHA256:141B4BDEFAE997AF2F8C31602B2864DD30D655B1C20385DD31A098BA596ACFE0 | |||
| 3212 | skype.exe | C:\Users\admin\AppData\Local\Temp\_MEI32122\_bz2.pyd | executable | |
MD5:754B62BE2DBAB2C25DC3DD65AAC9EBB2 | SHA256:15A8B8543A3A485321C310FC51531F2BAD14C8CB51B98C7B039A68FB34DE8DDA | |||
| 3212 | skype.exe | C:\Users\admin\AppData\Local\Temp\_MEI32122\_hashlib.pyd | executable | |
MD5:CC867B685F9D4AB258437D86663E2839 | SHA256:4504720C2DFD09770D53BA71C8BA64D128B51284F3942A5964390416DE481D2F | |||
| 3212 | skype.exe | C:\Users\admin\AppData\Local\Temp\_MEI32122\_queue.pyd | executable | |
MD5:CB9F4B92F130B564767359A8DAC8D05B | SHA256:297A96DC95709034C4B802E25F769105F9EB4866B70991208C4BD8315171CAF6 | |||
| 3212 | skype.exe | C:\Users\admin\AppData\Local\Temp\_MEI32122\_ssl.pyd | executable | |
MD5:2E2B2B0C18E5D897CA79A3BD70685233 | SHA256:98558E6F4FA2706F011B324721CEB884795549C1A863C8B46AF08F2B15CFDA5E | |||
| 3212 | skype.exe | C:\Users\admin\AppData\Local\Temp\_MEI32122\api-ms-win-core-errorhandling-l1-1-0.dll | executable | |
MD5:6D778E83F74A4C7FE4C077DC279F6867 | SHA256:A97DCCA76CDB12E985DFF71040815F28508C655AB2B073512E386DD63F4DA325 | |||
| 3212 | skype.exe | C:\Users\admin\AppData\Local\Temp\_MEI32122\api-ms-win-core-console-l1-1-0.dll | executable | |
MD5:502263C56F931DF8440D7FD2FA7B7C00 | SHA256:94A5DF1227818EDBFD0D5091C6A48F86B4117C38550343F780C604EEE1CD6231 | |||
| 3212 | skype.exe | C:\Users\admin\AppData\Local\Temp\_MEI32122\api-ms-win-core-file-l1-2-0.dll | executable | |
MD5:E2F648AE40D234A3892E1455B4DBBE05 | SHA256:C8C499B012D0D63B7AFC8B4CA42D6D996B2FCF2E8B5F94CACFBEC9E6F33E8A03 | |||
| 3212 | skype.exe | C:\Users\admin\AppData\Local\Temp\_MEI32122\api-ms-win-core-debug-l1-1-0.dll | executable | |
MD5:88FF191FD8648099592ED28EE6C442A5 | SHA256:C310CC91464C9431AB0902A561AF947FA5C973925FF70482D3DE017ED3F73B7D | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
2564 | svchost.exe | 239.255.255.250:3702 | — | — | — | whitelisted |
1060 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3556 | skype.exe | 192.168.40.3:80 | — | — | — | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |