| File name: | cw1.exe |
| Full analysis: | https://app.any.run/tasks/d84974d4-6c8d-49ea-a15f-6b9a86fdd4cd |
| Verdict: | Malicious activity |
| Analysis date: | March 07, 2024, 17:21:21 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (console) Intel 80386, for MS Windows |
| MD5: | 51D3A136BBC6A5C90A400D238EA4210C |
| SHA1: | 630CD304036F52C9CCD93454174117F7BBE8A639 |
| SHA256: | E96F8EAEF7A46A8B6F96252378071C2A2F3B8D281A4BF01B85E4484DE10407EC |
| SSDEEP: | 192:OHl/OTIc3RahVhkR+aI9b5h/BN+S0A4V7E5pz6dVrMYY:cFhfkMf9b/PkA4V7XM |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:09:04 18:11:12+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.28 |
| CodeSize: | 5632 |
| InitializedDataSize: | 6144 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x15f1 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows command line |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | C:\Windows\system32\DllHost.exe /Processid:{BA126F01-2166-11D1-B1D0-00805FC1270E} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 980 | "C:\Windows\system32\ipconfig.exe" /all | C:\Windows\System32\ipconfig.exe | — | sdiagnhost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: IP Configuration Utility Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1772 | "C:\Windows\system32\makecab.exe" /f NetworkConfiguration.ddf | C:\Windows\System32\makecab.exe | — | sdiagnhost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft® Cabinet Maker Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2148 | -skip TRUE -path C:\Windows\diagnostics\system\networking -af C:\Users\admin\AppData\Local\Temp\NDF211B.tmp -ep NetworkDiagnosticsConnectivity | C:\Windows\System32\msdt.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Diagnostics Troubleshooting Wizard Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2160 | "C:\Users\admin\AppData\Local\Temp\cw1.exe" | C:\Users\admin\AppData\Local\Temp\cw1.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 1 Modules
| |||||||||||||||
| 2332 | cmd.exe /C ping 1.1.1.1 -n 1 -w 3000 > Nul & Del /f /q "C:\Users\admin\AppData\Local\Temp\cw1.exe" | C:\Windows\System32\cmd.exe | — | cw1.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2804 | "C:\Windows\system32\ROUTE.EXE" print | C:\Windows\System32\ROUTE.EXE | — | sdiagnhost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: TCP/IP Route Command Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2960 | C:\Windows\System32\rundll32.exe shell32.dll,SHCreateLocalServerRunDll {995C996E-D918-4a8c-A302-45719A6F4EA7} -Embedding | C:\Windows\System32\rundll32.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3212 | ping 1.1.1.1 -n 1 -w 3000 | C:\Windows\System32\PING.EXE | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: TCP/IP Ping Command Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3308 | C:\Windows\System32\sdiagnhost.exe -Embedding | C:\Windows\System32\sdiagnhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Scripted Diagnostics Native Host Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2160) cw1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2160) cw1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2160) cw1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2160) cw1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2160) cw1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2160) cw1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyServer |
Value: | |||
| (PID) Process: | (2160) cw1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyOverride |
Value: | |||
| (PID) Process: | (2160) cw1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | AutoConfigURL |
Value: | |||
| (PID) Process: | (2160) cw1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | AutoDetect |
Value: | |||
| (PID) Process: | (2160) cw1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005C010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2148 | msdt.exe | C:\Users\admin\AppData\Local\Temp\SDIAG_4b951ef9-22ef-4dc6-9d75-d9dba2c752db\DiagPackage.diagpkg | xml | |
MD5:C9FB87FA3460FAE6D5D599236CFD77E2 | SHA256:CDE728C08A4E50A02FCFF35C90EE2B3B33AB24C8B858F180B6A67BFA94DEF35F | |||
| 2148 | msdt.exe | C:\Users\admin\AppData\Local\Temp\SDIAG_4b951ef9-22ef-4dc6-9d75-d9dba2c752db\HTInteractiveRes.ps1 | text | |
MD5:C25ED2111C6EE9299E6D9BF51012F2F5 | SHA256:8E326EE0475208D4C943D885035058FAD7146BBA02B66305F7C9F31F6A57E81B | |||
| 2148 | msdt.exe | C:\Users\admin\AppData\Local\Temp\SDIAG_4b951ef9-22ef-4dc6-9d75-d9dba2c752db\en-US\LocalizationData.psd1 | text | |
MD5:DFC212122EADE84D83607BA672A06114 | SHA256:CEC7595C6607862FB8B633468272C2118253EC77B47901AACE7CD94F4F6C1F0B | |||
| 2148 | msdt.exe | C:\Users\admin\AppData\Local\Temp\SDIAG_4b951ef9-22ef-4dc6-9d75-d9dba2c752db\en-US\DiagPackage.dll.mui | executable | |
MD5:5D7936806E6855E2ECC2B095316D45D8 | SHA256:71A4559F9FD122914A95998E8685BE638B8F81E581987708497E8F8A7A2F4DCB | |||
| 2148 | msdt.exe | C:\Users\admin\AppData\Local\Temp\SDIAG_4b951ef9-22ef-4dc6-9d75-d9dba2c752db\result\8889D4F3-3057-4408-AA98-06257AFADE3E.Diagnose.0.etl | binary | |
MD5:FC465BC14190C9C93B99C7A7A799B4C2 | SHA256:5FDD4BB07766C6376B23730A1E085EE400560D5B4394243BA01F56FB19BBA1A0 | |||
| 3308 | sdiagnhost.exe | C:\Users\admin\AppData\Local\Temp\8889D4F3-3057-4408-AA98-06257AFADE3E.Diagnose.0.etl | etl | |
MD5:FC465BC14190C9C93B99C7A7A799B4C2 | SHA256:5FDD4BB07766C6376B23730A1E085EE400560D5B4394243BA01F56FB19BBA1A0 | |||
| 2148 | msdt.exe | C:\Users\admin\AppData\Local\Temp\SDIAG_4b951ef9-22ef-4dc6-9d75-d9dba2c752db\UtilityFunctions.ps1 | text | |
MD5:2F7C3DB0C268CF1CF506FE6E8AECB8A0 | SHA256:886A625F71E0C35E5722423ED3AA0F5BFF8D120356578AB81A64DE2AB73D47F3 | |||
| 3308 | sdiagnhost.exe | C:\Users\admin\AppData\Local\Temp\tmp27C2.tmp\route.print.txt | text | |
MD5:D6BAB7F03D228D75D5CD49BC0C892C8C | SHA256:C1BA19C19145DC9B4AB22569596C73EF911F05AEE04AF6E23ADD784BCC92438F | |||
| 2148 | msdt.exe | C:\Users\admin\AppData\Local\Temp\SDIAG_4b951ef9-22ef-4dc6-9d75-d9dba2c752db\result\results.xsl | xml | |
MD5:310E1DA2344BA6CA96666FB639840EA9 | SHA256:67401342192BABC27E62D4C1E0940409CC3F2BD28F77399E71D245EAE8D3F63C | |||
| 3308 | sdiagnhost.exe | C:\Users\admin\AppData\Local\Temp\tmp27C2.tmp\NetworkConfiguration.ddf | text | |
MD5:00848049D4218C485D9E9D7A54AA3B5F | SHA256:FFEAFBB8E7163FD7EC9ABC029076796C73CD7B4EDDAEEDA9BA394C547419769E | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2160 | cw1.exe | 49.13.77.253:80 | ssl-6582datamanager.hellotherehi.local | Hetzner Online GmbH | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
ssl-6582datamanager.hellotherehi.local |
| unknown |