File name:

d6b9d4b8f1baca0b5282d11dde4269b6

Full analysis: https://app.any.run/tasks/808fd63e-aa5c-4bbd-bc87-6925e2447aeb
Verdict: Malicious activity
Analysis date: February 12, 2024, 18:15:58
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

D6B9D4B8F1BACA0B5282D11DDE4269B6

SHA1:

62AD656B07F5C3B53300231CD09A5491EC584EC1

SHA256:

E3C6A2246582DDE0A48812844DA162DB0E814F98988F8B44E76FCCA4CD8ED31B

SSDEEP:

98304:RumKe94qumSvEPrt2twfCt+ZaaoVBfG+8VhJLFMa+GC+sdZ9YYHAdUQH1xvR61ci:PCrHiocsEpKxsO9f

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • d6b9d4b8f1baca0b5282d11dde4269b6.exe (PID: 4052)
      • coregen.exe (PID: 3180)
      • coregen.exe (PID: 3684)
      • coregen.exe (PID: 1560)
      • coregen.exe (PID: 1644)
      • coregen.exe (PID: 2900)
      • coregen.exe (PID: 2244)
      • coregen.exe (PID: 3404)
      • coregen.exe (PID: 2728)
      • coregen.exe (PID: 1864)
      • coregen.exe (PID: 1892)
      • coregen.exe (PID: 2324)
      • coregen.exe (PID: 2992)
      • coregen.exe (PID: 2052)
      • coregen.exe (PID: 1404)
      • coregen.exe (PID: 1584)
  • SUSPICIOUS

    • Process drops legitimate windows executable

      • d6b9d4b8f1baca0b5282d11dde4269b6.exe (PID: 4052)
      • coregen.exe (PID: 3684)
      • coregen.exe (PID: 1560)
      • coregen.exe (PID: 3180)
      • coregen.exe (PID: 1644)
      • coregen.exe (PID: 2900)
      • coregen.exe (PID: 2244)
      • coregen.exe (PID: 2728)
      • coregen.exe (PID: 1404)
      • coregen.exe (PID: 1584)
      • coregen.exe (PID: 2052)
    • Starts a Microsoft application from unusual location

      • d6b9d4b8f1baca0b5282d11dde4269b6.exe (PID: 4052)
    • Executable content was dropped or overwritten

      • d6b9d4b8f1baca0b5282d11dde4269b6.exe (PID: 4052)
      • coregen.exe (PID: 3180)
      • coregen.exe (PID: 3684)
      • coregen.exe (PID: 1560)
      • coregen.exe (PID: 1644)
      • coregen.exe (PID: 2728)
      • coregen.exe (PID: 2244)
      • coregen.exe (PID: 3404)
      • coregen.exe (PID: 2900)
      • coregen.exe (PID: 1864)
      • coregen.exe (PID: 1892)
      • coregen.exe (PID: 2324)
      • coregen.exe (PID: 1584)
      • coregen.exe (PID: 2992)
      • coregen.exe (PID: 1404)
      • coregen.exe (PID: 2052)
    • Uses RUNDLL32.EXE to load library

      • install.exe (PID: 3464)
    • Reads the Internet Settings

      • install.exe (PID: 3464)
    • Reads security settings of Internet Explorer

      • install.exe (PID: 3464)
  • INFO

    • Reads Environment values

      • d6b9d4b8f1baca0b5282d11dde4269b6.exe (PID: 4052)
    • Reads the machine GUID from the registry

      • d6b9d4b8f1baca0b5282d11dde4269b6.exe (PID: 4052)
      • coregen.exe (PID: 1404)
      • install.exe (PID: 3464)
      • Silverlight.Configuration.exe (PID: 2480)
    • Reads the computer name

      • d6b9d4b8f1baca0b5282d11dde4269b6.exe (PID: 4052)
      • install.exe (PID: 3464)
      • Silverlight.Configuration.exe (PID: 2480)
    • Checks supported languages

      • d6b9d4b8f1baca0b5282d11dde4269b6.exe (PID: 4052)
      • install.exe (PID: 3464)
      • coregen.exe (PID: 1560)
      • coregen.exe (PID: 3684)
      • coregen.exe (PID: 2900)
      • coregen.exe (PID: 2728)
      • coregen.exe (PID: 1644)
      • coregen.exe (PID: 2244)
      • coregen.exe (PID: 3404)
      • coregen.exe (PID: 1864)
      • coregen.exe (PID: 1892)
      • coregen.exe (PID: 2324)
      • coregen.exe (PID: 1404)
      • coregen.exe (PID: 1584)
      • coregen.exe (PID: 2992)
      • coregen.exe (PID: 2052)
      • Silverlight.Configuration.exe (PID: 2480)
      • coregen.exe (PID: 3180)
    • Create files in a temporary directory

      • install.exe (PID: 3464)
    • Creates files in the program directory

      • coregen.exe (PID: 3684)
      • coregen.exe (PID: 1560)
      • coregen.exe (PID: 1644)
      • coregen.exe (PID: 2728)
      • coregen.exe (PID: 2900)
      • coregen.exe (PID: 3404)
      • coregen.exe (PID: 2244)
      • coregen.exe (PID: 1892)
      • coregen.exe (PID: 2324)
      • coregen.exe (PID: 1864)
      • coregen.exe (PID: 1404)
      • coregen.exe (PID: 2992)
      • coregen.exe (PID: 1584)
      • coregen.exe (PID: 2052)
      • coregen.exe (PID: 3180)
    • Creates files or folders in the user directory

      • Silverlight.Configuration.exe (PID: 2480)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2004:06:25 00:14:00+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, Removable run from swap, Net run from swap
PEType: PE32
LinkerVersion: 7.1
CodeSize: 30720
InitializedDataSize: 3072
UninitializedDataSize: -
EntryPoint: 0x5892
OSVersion: 5.2
ImageVersion: 5.2
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 5.1.20513.0
ProductVersionNumber: 5.5.31.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Self-Extracting Cabinet
FileVersion: 5.1.20513.0
InternalName: SFXCAB.EXE
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFileName: SFXCAB.EXE
ProductName: Microsoft® Windows® Operating System
ProductVersion: 5.5.0031.0
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
76
Monitored processes
20
Malicious processes
2
Suspicious processes
10

Behavior graph

Click at the process to see the details
start d6b9d4b8f1baca0b5282d11dde4269b6.exe install.exe no specs install.exe rundll32.exe no specs coregen.exe coregen.exe coregen.exe coregen.exe coregen.exe coregen.exe coregen.exe coregen.exe coregen.exe coregen.exe coregen.exe coregen.exe coregen.exe coregen.exe coregen.exe silverlight.configuration.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1404"C:\Program Files\Microsoft Silverlight\5.1.20513.0\coregen.exe" System.ServiceModel.dllC:\Program Files\Microsoft Silverlight\5.1.20513.0\coregen.exe
install.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
0
Version:
5.1.20513.0 built by: SL_V5_SVC
Modules
Images
c:\program files\microsoft silverlight\5.1.20513.0\coregen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft silverlight\5.1.20513.0\coreclr.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1560"C:\Program Files\Microsoft Silverlight\5.1.20513.0\coregen.exe" System.Core.dllC:\Program Files\Microsoft Silverlight\5.1.20513.0\coregen.exe
install.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
0
Version:
5.1.20513.0 built by: SL_V5_SVC
Modules
Images
c:\program files\microsoft silverlight\5.1.20513.0\coregen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft silverlight\5.1.20513.0\coreclr.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1584"C:\Program Files\Microsoft Silverlight\5.1.20513.0\coregen.exe" System.Windows.RuntimeHost.dllC:\Program Files\Microsoft Silverlight\5.1.20513.0\coregen.exe
install.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
0
Version:
5.1.20513.0 built by: SL_V5_SVC
Modules
Images
c:\program files\microsoft silverlight\5.1.20513.0\coregen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft silverlight\5.1.20513.0\coreclr.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1644"C:\Program Files\Microsoft Silverlight\5.1.20513.0\coregen.exe" System.Net.dllC:\Program Files\Microsoft Silverlight\5.1.20513.0\coregen.exe
install.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
0
Version:
5.1.20513.0 built by: SL_V5_SVC
Modules
Images
c:\program files\microsoft silverlight\5.1.20513.0\coregen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft silverlight\5.1.20513.0\coreclr.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1864"C:\Program Files\Microsoft Silverlight\5.1.20513.0\coregen.exe" Microsoft.Xna.Framework.Graphics.dllC:\Program Files\Microsoft Silverlight\5.1.20513.0\coregen.exe
install.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
0
Version:
5.1.20513.0 built by: SL_V5_SVC
Modules
Images
c:\program files\microsoft silverlight\5.1.20513.0\coregen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft silverlight\5.1.20513.0\coreclr.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
1892"C:\Program Files\Microsoft Silverlight\5.1.20513.0\coregen.exe" Microsoft.Xna.Framework.Graphics.Shaders.dllC:\Program Files\Microsoft Silverlight\5.1.20513.0\coregen.exe
install.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
0
Version:
5.1.20513.0 built by: SL_V5_SVC
Modules
Images
c:\program files\microsoft silverlight\5.1.20513.0\coregen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft silverlight\5.1.20513.0\coreclr.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2052"C:\Program Files\Microsoft Silverlight\5.1.20513.0\coregen.exe" System.Windows.Browser.dllC:\Program Files\Microsoft Silverlight\5.1.20513.0\coregen.exe
install.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
0
Version:
5.1.20513.0 built by: SL_V5_SVC
Modules
Images
c:\program files\microsoft silverlight\5.1.20513.0\coregen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft silverlight\5.1.20513.0\coreclr.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2244"C:\Program Files\Microsoft Silverlight\5.1.20513.0\coregen.exe" System.ServiceModel.Web.dllC:\Program Files\Microsoft Silverlight\5.1.20513.0\coregen.exe
install.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
0
Version:
5.1.20513.0 built by: SL_V5_SVC
Modules
Images
c:\program files\microsoft silverlight\5.1.20513.0\coregen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft silverlight\5.1.20513.0\coreclr.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2324"C:\Program Files\Microsoft Silverlight\5.1.20513.0\coregen.exe" System.Windows.dllC:\Program Files\Microsoft Silverlight\5.1.20513.0\coregen.exe
install.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft Common Language Runtime native compiler
Exit code:
0
Version:
5.1.20513.0 built by: SL_V5_SVC
Modules
Images
c:\program files\microsoft silverlight\5.1.20513.0\coregen.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\program files\microsoft silverlight\5.1.20513.0\coreclr.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
2480"C:\Program Files\Microsoft Silverlight\5.1.20513.0\silverlight.configuration.exe" -enableMUC:\Program Files\Microsoft Silverlight\5.1.20513.0\Silverlight.Configuration.exeinstall.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft® Silverlight Configuration Utility
Exit code:
2147943458
Version:
5.1.20513.0
Modules
Images
c:\program files\microsoft silverlight\5.1.20513.0\silverlight.configuration.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
Total events
2 261
Read events
2 240
Write events
21
Delete events
0

Modification events

(PID) Process:(3464) install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
116
(PID) Process:(3464) install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{BA08A66F-113B-4D58-9329-A1B37AF30F0E}
Operation:writeName:Dll
Value:
C:\Program Files\Microsoft Silverlight\xapauthenticodesip.dll
(PID) Process:(3464) install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllPutSignedDataMsg\{BA08A66F-113B-4D58-9329-A1B37AF30F0E}
Operation:writeName:FuncName
Value:
XAP_CryptSIPPutSignedDataMsg
(PID) Process:(3464) install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{BA08A66F-113B-4D58-9329-A1B37AF30F0E}
Operation:writeName:Dll
Value:
C:\Program Files\Microsoft Silverlight\xapauthenticodesip.dll
(PID) Process:(3464) install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllGetSignedDataMsg\{BA08A66F-113B-4D58-9329-A1B37AF30F0E}
Operation:writeName:FuncName
Value:
XAP_CryptSIPGetSignedDataMsg
(PID) Process:(3464) install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllRemoveSignedDataMsg\{BA08A66F-113B-4D58-9329-A1B37AF30F0E}
Operation:writeName:Dll
Value:
C:\Program Files\Microsoft Silverlight\xapauthenticodesip.dll
(PID) Process:(3464) install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllRemoveSignedDataMsg\{BA08A66F-113B-4D58-9329-A1B37AF30F0E}
Operation:writeName:FuncName
Value:
XAP_CryptSIPRemoveSignedDataMsg
(PID) Process:(3464) install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllCreateIndirectData\{BA08A66F-113B-4D58-9329-A1B37AF30F0E}
Operation:writeName:Dll
Value:
C:\Program Files\Microsoft Silverlight\xapauthenticodesip.dll
(PID) Process:(3464) install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllCreateIndirectData\{BA08A66F-113B-4D58-9329-A1B37AF30F0E}
Operation:writeName:FuncName
Value:
XAP_CryptSIPCreateIndirectData
(PID) Process:(3464) install.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\OID\EncodingType 0\CryptSIPDllVerifyIndirectData\{BA08A66F-113B-4D58-9329-A1B37AF30F0E}
Operation:writeName:Dll
Value:
C:\Program Files\Microsoft Silverlight\xapauthenticodesip.dll
Executable files
18
Suspicious files
2
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
4052d6b9d4b8f1baca0b5282d11dde4269b6.exeC:\12924f0b54c74474d364f0\silverlight.7z
MD5:
SHA256:
4052d6b9d4b8f1baca0b5282d11dde4269b6.exeC:\12924f0b54c74474d364f0\silverlightdev.msp
MD5:
SHA256:
3464install.exeC:\12924f0b54c74474d364f0\Silverlight.msp
MD5:
SHA256:
3684coregen.exeC:\Program Files\Microsoft Silverlight\5.1.20513.0\System.ni.dllexecutable
MD5:665C6C0EA9595D9167DEF0E9FDE758E1
SHA256:28FC311F2A6C96C69BF9E099A3D4640B81A489890A6C905D3E0466CB7BC3867D
4052d6b9d4b8f1baca0b5282d11dde4269b6.exeC:\12924f0b54c74474d364f0\silverlight.msiexecutable
MD5:561751AC20B90C8E8F4DB004C16F7959
SHA256:C5CDBEAB8A080FAFF40B882E601D4C8CD21DCC48DDC70C62E5725903E802E9EE
4052d6b9d4b8f1baca0b5282d11dde4269b6.exeC:\12924f0b54c74474d364f0\install.res.dllexecutable
MD5:9FCDEF5A03E25345051CB220980EC54A
SHA256:D86A90ADA94441886C9305EF2F8FA0F9B0CAD112521C85964F7C41769CF93C8E
1560coregen.exeC:\Program Files\Microsoft Silverlight\5.1.20513.0\System.Core.ni.dllexecutable
MD5:33390689FC00A7A41594774023EE024A
SHA256:1C195CEC9B04DB5376F737FDC83205A975889BBA7FF93FBE4C4A542C51993A14
1404coregen.exeC:\Program Files\Microsoft Silverlight\5.1.20513.0\System.ServiceModel.ni.dllexecutable
MD5:F735A9B060AC1453A4972F5E7C593DC7
SHA256:6B8408590605910725D4330438DEF8264C4FA69E59485316EE16271A139F0A6A
1644coregen.exeC:\Program Files\Microsoft Silverlight\5.1.20513.0\System.Net.ni.dllexecutable
MD5:37BC2FC098CD86BDB9EAAD8D81B11BC5
SHA256:B19AE75DC0784D1AD07CDE0E6CFED9F1EEA89485B6DF15280D413B0FC1BD73DC
1892coregen.exeC:\Program Files\Microsoft Silverlight\5.1.20513.0\Microsoft.Xna.Framework.Graphics.Shaders.ni.dllexecutable
MD5:1033B9ECD957032D40DE47AE243E568E
SHA256:75EDAFBF5A84E619478A8A6C1715EC06179E754F3D051CAB52BA5A8C11C1648E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info