File name:

PixelSee_id2874525id.exe

Full analysis: https://app.any.run/tasks/9a6cb419-b2b6-40b1-8700-14147c7eb8c8
Verdict: Malicious activity
Analysis date: December 23, 2023, 02:51:37
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

CC4805556AFBAD7A49B6D2D32770977E

SHA1:

0DC67AA9AABF25BC6920432FFD3F70FCFF532222

SHA256:

DC5FC727D8478BD4069E5FBC75044EF1166140AB5CBBE2CBB41520C66E0646A0

SSDEEP:

98304:Qs09dMO3/N0Kdbgnvr+DpGRoPct/uN7cZzb8m/3uji6eWYw9wNdlk8CyNShgyIfV:dfIxwn1

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Actions looks like stealing of personal data

      • PixelSee_id2874525id.exe (PID: 2208)
  • SUSPICIOUS

    • Reads Internet Explorer settings

      • PixelSee_id2874525id.exe (PID: 2208)
    • Reads Microsoft Outlook installation path

      • PixelSee_id2874525id.exe (PID: 2208)
    • Reads the Internet Settings

      • PixelSee_id2874525id.exe (PID: 2208)
      • lum_inst.tmp (PID: 2588)
      • luminati-m-controller.exe (PID: 984)
    • Reads the Windows owner or organization settings

      • lum_inst.tmp (PID: 2588)
    • Adds/modifies Windows certificates

      • luminati-m-controller.exe (PID: 984)
    • Reads settings of System Certificates

      • luminati-m-controller.exe (PID: 984)
    • Detected use of alternative data streams (AltDS)

      • luminati-m-controller.exe (PID: 984)
  • INFO

    • Checks supported languages

      • PixelSee_id2874525id.exe (PID: 2208)
      • lum_inst.exe (PID: 2560)
      • lum_inst.tmp (PID: 2588)
      • test_wpf.exe (PID: 1424)
      • luminati-m-controller.exe (PID: 984)
    • Reads the computer name

      • PixelSee_id2874525id.exe (PID: 2208)
      • lum_inst.tmp (PID: 2588)
      • test_wpf.exe (PID: 1424)
      • luminati-m-controller.exe (PID: 984)
    • Checks proxy server information

      • PixelSee_id2874525id.exe (PID: 2208)
      • luminati-m-controller.exe (PID: 984)
    • Reads the machine GUID from the registry

      • PixelSee_id2874525id.exe (PID: 2208)
      • luminati-m-controller.exe (PID: 984)
      • test_wpf.exe (PID: 1424)
    • Create files in a temporary directory

      • PixelSee_id2874525id.exe (PID: 2208)
      • lum_inst.exe (PID: 2560)
    • Process drops legitimate windows executable

      • PixelSee_id2874525id.exe (PID: 2208)
      • luminati-m-controller.exe (PID: 984)
    • The process drops C-runtime libraries

      • PixelSee_id2874525id.exe (PID: 2208)
      • luminati-m-controller.exe (PID: 984)
    • Creates files or folders in the user directory

      • PixelSee_id2874525id.exe (PID: 2208)
      • luminati-m-controller.exe (PID: 984)
    • Drops the executable file immediately after the start

      • lum_inst.tmp (PID: 2588)
      • lum_inst.exe (PID: 2560)
      • PixelSee_id2874525id.exe (PID: 2208)
      • luminati-m-controller.exe (PID: 984)
    • Creates files in the program directory

      • luminati-m-controller.exe (PID: 984)
    • Process checks computer location settings

      • luminati-m-controller.exe (PID: 984)
    • Reads Environment values

      • luminati-m-controller.exe (PID: 984)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (76.4)
.exe | Win32 Executable (generic) (12.4)
.exe | Generic Win/DOS Executable (5.5)
.exe | DOS Executable Generic (5.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:09:29 19:25:35+02:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 14.29
CodeSize: 2723328
InitializedDataSize: 2256896
UninitializedDataSize: -
EntryPoint: 0x263f3f
OSVersion: 6
ImageVersion: -
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 13.0.0.0
ProductVersionNumber: 13.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
Comments: PixelSee Player Installer
CompanyName: SIA Circle Solutions
FileDescription: PixelSee Player Installer
FileVersion: 13.0.0.0
InternalName: pixelsee
LegalCopyright: Copyright © 2022-2023 SIA Circle Solutions
OriginalFileName: pixelsee
PrivateBuild: -
ProductName: PixelSee
ProductVersion: 13.0.0.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
46
Monitored processes
6
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start pixelsee_id2874525id.exe lum_inst.exe no specs lum_inst.tmp no specs luminati-m-controller.exe test_wpf.exe no specs pixelsee_id2874525id.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
984"C:\Users\admin\PixelSee\Luminati-m\luminati-m-controller.exe" switch_onC:\Users\admin\PixelSee\Luminati-m\luminati-m-controller.exe
lum_inst.tmp
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\pixelsee\luminati-m\luminati-m-controller.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\pixelsee\luminati-m\lum_sdk32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\shlwapi.dll
1424C:\ProgramData\BrightData\b85f5ef603041f1fc4e7f943c177a0d440a01266\test_wpf.exeC:\ProgramData\BrightData\b85f5ef603041f1fc4e7f943c177a0d440a01266\test_wpf.exeluminati-m-controller.exe
User:
admin
Company:
BrightData Ltd. (certified)
Integrity Level:
HIGH
Description:
test_wpf
Exit code:
0
Version:
1.418.267
Modules
Images
c:\programdata\brightdata\b85f5ef603041f1fc4e7f943c177a0d440a01266\test_wpf.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
2184"C:\Users\admin\AppData\Local\Temp\PixelSee_id2874525id.exe" C:\Users\admin\AppData\Local\Temp\PixelSee_id2874525id.exeexplorer.exe
User:
admin
Company:
SIA Circle Solutions
Integrity Level:
MEDIUM
Description:
PixelSee Player Installer
Exit code:
3221226540
Version:
13.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\pixelsee_id2874525id.exe
c:\windows\system32\ntdll.dll
2208"C:\Users\admin\AppData\Local\Temp\PixelSee_id2874525id.exe" C:\Users\admin\AppData\Local\Temp\PixelSee_id2874525id.exe
explorer.exe
User:
admin
Company:
SIA Circle Solutions
Integrity Level:
HIGH
Description:
PixelSee Player Installer
Exit code:
0
Version:
13.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\pixelsee_id2874525id.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ws2_32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\crypt32.dll
c:\windows\system32\msasn1.dll
2560"C:\Users\admin\AppData\Local\Temp\luminati\lum_inst.exe" /verysilentC:\Users\admin\AppData\Local\Temp\luminati\lum_inst.exePixelSee_id2874525id.exe
User:
admin
Company:
luminati
Integrity Level:
HIGH
Description:
luminati Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\luminati\lum_inst.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\comctl32.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
2588"C:\Users\admin\AppData\Local\Temp\is-G0G26.tmp\lum_inst.tmp" /SL5="$30194,5623757,832512,C:\Users\admin\AppData\Local\Temp\luminati\lum_inst.exe" /verysilentC:\Users\admin\AppData\Local\Temp\is-G0G26.tmp\lum_inst.tmplum_inst.exe
User:
admin
Company:
luminati
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-g0g26.tmp\lum_inst.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mpr.dll
c:\windows\system32\comdlg32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
7 493
Read events
7 444
Write events
49
Delete events
0

Modification events

(PID) Process:(2208) PixelSee_id2874525id.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2208) PixelSee_id2874525id.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2208) PixelSee_id2874525id.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2208) PixelSee_id2874525id.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2208) PixelSee_id2874525id.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2208) PixelSee_id2874525id.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(2588) lum_inst.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2588) lum_inst.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2588) lum_inst.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2588) lum_inst.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
Executable files
461
Suspicious files
135
Text files
126
Unknown types
1

Dropped files

PID
Process
Filename
Type
2208PixelSee_id2874525id.exeC:\Users\admin\AppData\Local\Temp\pixelsee-installer-tmp\curl-ca-bundle.crttext
MD5:BE2B0736EA029FFF398559FA7DF4E646
SHA256:C05A79296D61E3B2A2EBAF5AF476839B976D69A5ACB6F581A667E60E681049A2
2208PixelSee_id2874525id.exeC:\Users\admin\AppData\Local\Temp\pixelsee-installer-tmp\archive.7zcompressed
MD5:8293B1708DC0954D07A1AEA81335CC7C
SHA256:29AA2E2F3B2571FB018B21A57DCBE246901E021385A66BDBF8F7DA8415F82854
2208PixelSee_id2874525id.exeC:\Users\admin\AppData\Local\Temp\pixelsee-installer-tmp\bundles\main-lum.txthtml
MD5:807213BC5ECF0A3C1537787E874E27C4
SHA256:4803D962C4237FF0803C3E8D4D32CAA6A5A14701008218604FE9C9694F2D9465
2208PixelSee_id2874525id.exeC:\Users\admin\AppData\Local\Temp\pixelsee-installer-tmp\bundles\bundle-opera.htmlhtml
MD5:A0FD3EC1D58F5805C3ECBD3628B21815
SHA256:0C94BD8D4EAB1C2B4CE4FC9A8BB3F8FD11524DC9F8C8B2FEBE5FBC132978B4DD
2208PixelSee_id2874525id.exeC:\Users\admin\AppData\Local\Temp\pixelsee-installer-tmp\bundles\bundle-soax.htmlhtml
MD5:7460B2A28D6D735E69E5207E999D5CA4
SHA256:ADFA61CFD83D977B6E81012AFB6B5D2A7EF37865C8C2EA5D42DB58CE3A36E40D
2208PixelSee_id2874525id.exeC:\Users\admin\AppData\Local\Temp\pixelsee-installer-tmp\bundles\bundle-operagx.htmlhtml
MD5:EED7C15EFB77B51A5AA260AB1D5751B9
SHA256:C6544472CB0B18803C75FCD25CA1CBECB5D47AD9B0AAA83939493D652DE7D724
2208PixelSee_id2874525id.exeC:\Users\admin\AppData\Local\Temp\pixelsee-installer-tmp\bundles\main-nobundles.htmlhtml
MD5:9533945443F29FE2F6781309739C138A
SHA256:8C1FCC4FD722F00C1A3504B522FAAFD92768D797707C7B97505B2AB784D842BA
2208PixelSee_id2874525id.exeC:\Users\admin\AppData\Local\Temp\pixelsee-installer-tmp\bundles\main.htmlhtml
MD5:03D5A5B5744FBBE79C5D478608D6CD09
SHA256:3EFD4C823B1485893363D46F497AD73DA36C8582AFE2692AA0484F4193481CE8
2208PixelSee_id2874525id.exeC:\Users\admin\AppData\Local\Temp\pixelsee-installer-tmp\preloader.htmlhtml
MD5:37A05031BEC9D3E093388407848AF66F
SHA256:CF38F4F8663028BEFF3A7650A9D426B4116891E8547029B66B8D2A13FAD63A48
2208PixelSee_id2874525id.exeC:\Users\admin\AppData\Local\Temp\pixelsee-installer-tmp\Montserrat-Regular.eotbinary
MD5:2DD0A1DE870AF34D48D43B7CAD82B8D9
SHA256:057BC6C47C47AACCDF31ADC48A6B401F6090A02C28E354099EFF80907DC2AF32
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
20
DNS requests
4
Threats
1

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:138
whitelisted
2208
PixelSee_id2874525id.exe
51.158.130.233:443
pixelsee.app
Online S.a.s.
FR
unknown
984
luminati-m-controller.exe
206.189.231.23:443
perr.lum-sdk.io
DIGITALOCEAN-ASN
US
unknown
984
luminati-m-controller.exe
3.228.177.90:443
AMAZON-AES
US
unknown
984
luminati-m-controller.exe
159.223.133.120:443
perr.lum-sdk.io
DIGITALOCEAN-ASN
US
unknown
984
luminati-m-controller.exe
51.158.130.233:443
pixelsee.app
Online S.a.s.
FR
unknown
984
luminati-m-controller.exe
192.81.214.145:443
perr.lum-sdk.io
DIGITALOCEAN-ASN
US
unknown

DNS requests

Domain
IP
Reputation
pixelsee.app
  • 51.158.130.233
unknown
perr.lum-sdk.io
  • 206.189.231.23
  • 159.223.133.120
  • 192.81.214.145
  • 161.35.48.195
unknown
perr.l-err.biz
  • 206.189.231.23
  • 192.81.214.145
  • 159.223.133.120
  • 161.35.48.195
unknown

Threats

PID
Process
Class
Message
1080
svchost.exe
Potentially Bad Traffic
ET INFO Observed DNS Query to .biz TLD
No debug info