File name:

www.skype.com

Full analysis: https://app.any.run/tasks/332cbc28-0f39-4d1c-8d4f-d4ce68f7d206
Verdict: Malicious activity
Analysis date: November 07, 2023, 16:03:38
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

46A8C7B210C5CC7BF5EC34259CD091F2

SHA1:

6B36E78C0FE8C044D7A149B809E5DFD2F960F1B5

SHA256:

E034451DCAEA3BEFE27948E9C32974E4D916E5BA04B2DB45DE51FB2317132059

SSDEEP:

49152:S2Cdc56+LZYM0gDy1E5n7K1YseGch27YqPeporY9f7avHnJqSsdNfMtDIoX+zAi/:Si6s9D15oeK7YF7d0HJfsdStDJGbJQq2

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • www.skype.com.exe (PID: 2928)
      • sbin.exe (PID: 3468)
    • Unusual connection from system programs

      • rundll32.exe (PID: 3528)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • www.skype.com.exe (PID: 2928)
      • sbin.exe (PID: 3468)
      • cmd.exe (PID: 3464)
    • Reads the Internet Settings

      • sbin.exe (PID: 3468)
    • Application launched itself

      • cmd.exe (PID: 3464)
    • Uses TIMEOUT.EXE to delay execution

      • cmd.exe (PID: 3576)
    • Uses REG/REGEDIT.EXE to modify registry

      • cmd.exe (PID: 3276)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 3688)
    • Connects to unusual port

      • rundll32.exe (PID: 3528)
  • INFO

    • Checks supported languages

      • wmpnscfg.exe (PID: 3448)
      • www.skype.com.exe (PID: 2928)
      • sbin.exe (PID: 3468)
      • wmpnscfg.exe (PID: 3908)
    • Reads the machine GUID from the registry

      • wmpnscfg.exe (PID: 3448)
      • wmpnscfg.exe (PID: 3908)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3448)
      • sbin.exe (PID: 3468)
      • wmpnscfg.exe (PID: 3908)
    • Create files in a temporary directory

      • www.skype.com.exe (PID: 2928)
      • rundll32.exe (PID: 3528)
    • The executable file from the user directory is run by the CMD process

      • sbin.exe (PID: 3468)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3908)
    • Creates files or folders in the user directory

      • sbin.exe (PID: 3468)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2008:04:13 20:32:45+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 7.1
CodeSize: 39424
InitializedDataSize: 1046016
UninitializedDataSize: -
EntryPoint: 0x645c
OSVersion: 5.1
ImageVersion: 5.1
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.4.4.6
ProductVersionNumber: 1.4.4.6
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Lazesoft
FileDescription: Lazesoft Winnet config Application
FileVersion: 1, 4, 4, 6
InternalName: winnetconfiig
LegalCopyright: Copyright (C) 2021
OriginalFileName: winnetconfiig.exe
ProductName: Lazesoft Winnetmp configs Applicationts
ProductVersion: 1, 4, 4, 6
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
51
Monitored processes
14
Malicious processes
4
Suspicious processes
1

Behavior graph

Click at the process to see the details
start www.skype.com.exe no specs cmd.exe no specs notepad.exe no specs sbin.exe no specs cmd.exe no specs cmd.exe no specs timeout.exe no specs cmd.exe no specs reg.exe no specs rundll32.exe cmd.exe no specs taskkill.exe no specs wmpnscfg.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2928"C:\Users\admin\AppData\Local\Temp\www.skype.com.exe" C:\Users\admin\AppData\Local\Temp\www.skype.com.exeexplorer.exe
User:
admin
Company:
Lazesoft
Integrity Level:
MEDIUM
Description:
Lazesoft Winnet config Application
Exit code:
0
Version:
1, 4, 4, 6
Modules
Images
c:\users\admin\appdata\local\temp\www.skype.com.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2932cmd /c NoTepad&&sbin.exeC:\Windows\System32\cmd.exewww.skype.com.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3276cmd /c reg.exe import cfg.iniC:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3424timeout 1C:\Windows\System32\timeout.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
timeout - pauses command processing
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\timeout.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\ws2_32.dll
3448"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3464"C:\Windows\System32\cmd.exe" /c cd C:\Users\admin\AppData\Roaming\YourNotes&&cmd /c timeout 1&&cmd /c reg.exe import cfg.iniC:\Windows\System32\cmd.exesbin.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3468sbin.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\sbin.execmd.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
1
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\ixp000.tmp\sbin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvbvm60.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
3508NoTepadC:\Windows\System32\notepad.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Notepad
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\notepad.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
3528"C:\Windows\SysWOW64\rundll32.exe" /sta {CCB947DB-0C9E-4497-AB87-DD60CB9C2B83}C:\Windows\System32\rundll32.exe
sbin.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows host process (Rundll32)
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\rundll32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imagehlp.dll
3576cmd /c timeout 1C:\Windows\System32\cmd.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
3 916
Read events
3 902
Write events
8
Delete events
6

Modification events

(PID) Process:(3448) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{8A8545E0-4BFB-4832-905D-D0EDBE311F21}\{CE7EA37A-9EEF-4BB3-9F0E-1AF391F5C737}
Operation:delete keyName:(default)
Value:
(PID) Process:(3448) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{8A8545E0-4BFB-4832-905D-D0EDBE311F21}
Operation:delete keyName:(default)
Value:
(PID) Process:(3448) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{84898FAF-7BBC-4CA6-9771-9DECC7061280}
Operation:delete keyName:(default)
Value:
(PID) Process:(3468) sbin.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3468) sbin.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3468) sbin.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3468) sbin.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3908) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{410AB6A5-5D5E-4BAF-AF8A-849B4BFF6563}\{A84BA541-4FF5-4056-ABC7-19A5878D7F51}
Operation:delete keyName:(default)
Value:
(PID) Process:(3908) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{410AB6A5-5D5E-4BAF-AF8A-849B4BFF6563}
Operation:delete keyName:(default)
Value:
(PID) Process:(3908) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{C1078A5C-0CC5-48B6-9C97-AF386C4DB845}
Operation:delete keyName:(default)
Value:
Executable files
4
Suspicious files
0
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
2928www.skype.com.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\ny.png
MD5:
SHA256:
2928www.skype.com.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\g1.ocxexecutable
MD5:3C8FAD6D759D7D42FCD9E4358F45E8A0
SHA256:CA6A999B5A0DDDFBCFDA2588410C800A700D7F1D6E7C0F96FD2E52F98F467989
3468sbin.exeC:\Users\admin\AppData\Roaming\YourNotes\cfg.initext
MD5:8129F259BFFD7CC11DDC025889437DFA
SHA256:271E8B639702ED445ED79829C9E2C85D968134397DC5F3E91AF5A174278F37D8
2928www.skype.com.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\g2.ocxexecutable
MD5:2BC07C8BB180683161BC3A79FDC9A535
SHA256:4D743D188278601233B47CA7D93ADF5E50F8BAD8046960E0A8929B5617A79ACE
2928www.skype.com.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\cfg.initext
MD5:43971A7010A4EE2B20BB9FAA3ACBDE74
SHA256:BF1AA2AA4B8D3B3CD58A5E8FDD6CE087B89D2409E16AFDAF2FD7F182290B2483
2928www.skype.com.exeC:\Users\admin\AppData\Local\Temp\IXP000.TMP\sbin.exeexecutable
MD5:D10694A3BB1D5D0CCD111F8791A2A25E
SHA256:F2A2C1E630F406A2403F6428E91CAA2E82DEDF66250D3B676B5F7469C69631D8
3468sbin.exeC:\Users\admin\AppData\Roaming\YourNotes\MadeForNotebook.dllexecutable
MD5:E6EAEDECCB9882CED3E6DFFE27053E89
SHA256:B93A9DDE24F0B00CBA1AC19339B05A6CBC05B96DBC19C4582F161E026482E0F4
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
30
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
3528
rundll32.exe
76.8.53.136:1212
roodstarslook.com
D102-PHL-1
US
unknown

DNS requests

Domain
IP
Reputation
roodstarslook.com
  • 76.8.53.136
unknown

Threats

No threats detected
No debug info