File name:

Combo Editor by xRisky 1.0.exe

Full analysis: https://app.any.run/tasks/68f73a81-330e-4465-980d-6dd7fdea4be3
Verdict: Malicious activity
Analysis date: February 07, 2024, 00:16:55
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386 (stripped to external PDB), for MS Windows
MD5:

F3CCFDC1F0E498AE2F6CCB4B67781708

SHA1:

EC14A0925B58756CA57ACF8127A7F9CABF6673C2

SHA256:

E11A59AF6B650A2DAF5ED7384BCC9EA291EA340EABE72EC18ADA5B2B0291D040

SSDEEP:

98304:0eiPKI83uUhTmgYSxwjVjDTZzTUaHp1nSkGU5pSyY7mT171bTMAGf2N478q/rYIE:0eigTDxgZz7PnSHqu

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Combo Editor by xRisky 1.0.exe (PID: 1588)
      • svhost.exe (PID: 2736)
    • Create files in the Startup directory

      • svhost.exe (PID: 2736)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • Combo Editor by xRisky 1.0.exe (PID: 1588)
    • The process creates files with name similar to system file names

      • Combo Editor by xRisky 1.0.exe (PID: 1588)
    • The executable file from the user directory is run by the CMD process

      • Combo Editor by xRisky.exe (PID: 2448)
      • svhost.exe (PID: 2736)
    • Executable content was dropped or overwritten

      • Combo Editor by xRisky 1.0.exe (PID: 1588)
      • svhost.exe (PID: 2736)
  • INFO

    • Reads the computer name

      • wmpnscfg.exe (PID: 1264)
      • svhost.exe (PID: 2736)
    • Checks supported languages

      • wmpnscfg.exe (PID: 1264)
      • Combo Editor by xRisky 1.0.exe (PID: 1588)
      • svhost.exe (PID: 2736)
      • Combo Editor by xRisky.exe (PID: 2448)
    • Create files in a temporary directory

      • Combo Editor by xRisky 1.0.exe (PID: 1588)
    • Reads the machine GUID from the registry

      • svhost.exe (PID: 2736)
    • Creates files or folders in the user directory

      • svhost.exe (PID: 2736)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (61.6)
.dll | Win32 Dynamic Link Library (generic) (14.6)
.exe | Win32 Executable (generic) (10)
.exe | Win16/32 Executable Delphi generic (4.6)
.exe | Generic Win/DOS Executable (4.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 0000:00:00 00:00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, No debug
PEType: PE32
LinkerVersion: 6
CodeSize: 2048
InitializedDataSize: 3426816
UninitializedDataSize: -
EntryPoint: 0x14b5
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 1.0.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Unknown (0)
ObjectFileType: Unknown
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: -
FileTitle: Combo Tools by xRisky.exe
FileDescription: Combo Tools by xRisky
FileVersion: 1,0,0,0
LegalCopyright: Copyright © 2018
LegalTrademark: -
ProductName: Combo Tools by xRisky
ProductVersion: 1,0,0,0
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
6
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start combo editor by xrisky 1.0.exe cmd.exe no specs svhost.exe cmd.exe no specs combo editor by xrisky.exe no specs wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1264"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
1588"C:\Users\admin\AppData\Local\Temp\Combo Editor by xRisky 1.0.exe" C:\Users\admin\AppData\Local\Temp\Combo Editor by xRisky 1.0.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Combo Tools by xRisky
Exit code:
0
Version:
1,0,0,0
Modules
Images
c:\users\admin\appdata\local\temp\combo editor by xrisky 1.0.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\apphelp.dll
1604cmd /c start "" "C:\Users\admin\AppData\Local\Temp\svhost.exe"C:\Windows\System32\cmd.exeCombo Editor by xRisky 1.0.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2448"C:\Users\admin\AppData\Local\Temp\Combo Editor by xRisky.exe" C:\Users\admin\AppData\Local\Temp\Combo Editor by xRisky.execmd.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Combo Tools by xRisky
Exit code:
4294967295
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\combo editor by xrisky.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2736"C:\Users\admin\AppData\Local\Temp\svhost.exe" C:\Users\admin\AppData\Local\Temp\svhost.exe
cmd.exe
User:
admin
Integrity Level:
MEDIUM
Description:
cmd updater
Exit code:
0
Version:
1.0.0.0
Modules
Images
c:\users\admin\appdata\local\temp\svhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3564cmd /c start "" "C:\Users\admin\AppData\Local\Temp\Combo Editor by xRisky.exe"C:\Windows\System32\cmd.exeCombo Editor by xRisky 1.0.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
139
Read events
139
Write events
0
Delete events
0

Modification events

No data
Executable files
3
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

PID
Process
Filename
Type
1588Combo Editor by xRisky 1.0.exeC:\Users\admin\AppData\Local\Temp\Combo Editor by xRisky.exeexecutable
MD5:C094249EFE9A74C2B2D8DD6F751DA502
SHA256:CFB6F1970D72A68F758FA867AD90AFD4C32F12BE2EFB751D658E60AEE37F51FC
2736svhost.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\Chrome updater.exeexecutable
MD5:29309826CB7313EF7ECA6C1B482A6686
SHA256:5A383939299B75D1A0E35267ED4BCB9EB62BD2420A5B8BDE9BBF60CB3982A72A
1588Combo Editor by xRisky 1.0.exeC:\Users\admin\AppData\Local\Temp\svhost.exeexecutable
MD5:29309826CB7313EF7ECA6C1B482A6686
SHA256:5A383939299B75D1A0E35267ED4BCB9EB62BD2420A5B8BDE9BBF60CB3982A72A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
Process
Message
svhost.exe
RunBotKiller: Access is denied
svhost.exe
RunBotKiller: Access is denied
svhost.exe
RunBotKiller: Access is denied
svhost.exe
RunBotKiller: Access is denied
svhost.exe
RunBotKiller: Access is denied
svhost.exe
RunBotKiller: Access is denied
svhost.exe
RunBotKiller: Access is denied
svhost.exe
RunBotKiller: Access is denied
svhost.exe
RunBotKiller: Access is denied
svhost.exe
RunBotKiller: Access is denied