File name:

file

Full analysis: https://app.any.run/tasks/13d44071-1347-499c-9f0f-294ff4e09038
Verdict: Malicious activity
Analysis date: November 15, 2024, 10:15:23
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, 10 sections
MD5:

61A258D01CA778D303B44CBBF41BECC1

SHA1:

E2AB78BCEB60663DA12BD4CE6D827F1533D309BE

SHA256:

EB16B633187AE498FB15AD453E1A4194317A8EDA531956DA27F2425289F50D1D

SSDEEP:

98304:2bUNc1qGW+Q6fmnPmddSFlvSCY2UYRQ5JV0Gf2LQW3gziIbNlooFJC6tY+yb4uht:bA79To4W

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Starts NET.EXE for service management

      • file.tmp (PID: 3128)
      • net.exe (PID: 5748)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • file.exe (PID: 4792)
      • file.tmp (PID: 3128)
      • shineencoder.exe (PID: 6676)
    • Reads the Windows owner or organization settings

      • file.tmp (PID: 3128)
    • Process drops legitimate windows executable

      • file.tmp (PID: 3128)
    • The process drops C-runtime libraries

      • file.tmp (PID: 3128)
    • Reads security settings of Internet Explorer

      • shineencoder.exe (PID: 6676)
    • Starts POWERSHELL.EXE for commands execution

      • shineencoder.exe (PID: 6676)
  • INFO

    • Create files in a temporary directory

      • file.tmp (PID: 3128)
      • file.exe (PID: 4792)
    • Checks supported languages

      • file.exe (PID: 4792)
      • file.tmp (PID: 3128)
      • shineencoder.exe (PID: 6676)
    • Creates files or folders in the user directory

      • file.tmp (PID: 3128)
    • Creates a software uninstall entry

      • file.tmp (PID: 3128)
    • Reads the computer name

      • file.tmp (PID: 3128)
      • shineencoder.exe (PID: 6676)
    • Creates files in the program directory

      • shineencoder.exe (PID: 6676)
    • The process uses the downloaded file

      • shineencoder.exe (PID: 6676)
    • Process checks computer location settings

      • shineencoder.exe (PID: 6676)
    • Changes the registry key values via Powershell

      • shineencoder.exe (PID: 6676)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (51.8)
.exe | InstallShield setup (20.3)
.exe | Win32 EXE PECompact compressed (generic) (19.6)
.dll | Win32 Dynamic Link Library (generic) (3.1)
.exe | Win32 Executable (generic) (2.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2019:04:27 08:22:11+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 682496
InitializedDataSize: 37888
UninitializedDataSize: -
EntryPoint: 0xa7ed0
OSVersion: 6
ImageVersion: 6
SubsystemVersion: 6
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName:
FileDescription: Shine Encoder Setup
FileVersion:
LegalCopyright:
OriginalFileName:
ProductName: Shine Encoder
ProductVersion:
No data.
screenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
141
Monitored processes
8
Malicious processes
2
Suspicious processes
1

Behavior graph

Click at the process to see the details
start file.exe file.tmp net.exe no specs shineencoder.exe conhost.exe no specs net1.exe no specs powershell.exe no specs conhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
3128"C:\Users\admin\AppData\Local\Temp\is-T54JG.tmp\file.tmp" /SL5="$5028C,5587251,721408,C:\Users\admin\AppData\Local\Temp\file.exe" C:\Users\admin\AppData\Local\Temp\is-T54JG.tmp\file.tmp
file.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Version:
51.1052.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-t54jg.tmp\file.tmp
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\comdlg32.dll
3828\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exepowershell.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
3844"C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe" -c Set-ItemProperty -Path "HKCU:\Software\Microsoft\Windows\CurrentVersion\Run" -Name "dEshenc47" -Value "C:\ProgramData\EShineEncoder\EShineEncoder.exe"C:\Windows\SysWOW64\WindowsPowerShell\v1.0\powershell.exeshineencoder.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows PowerShell
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\windowspowershell\v1.0\powershell.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
4792"C:\Users\admin\AppData\Local\Temp\file.exe" C:\Users\admin\AppData\Local\Temp\file.exe
explorer.exe
User:
admin
Company:
Integrity Level:
MEDIUM
Description:
Shine Encoder Setup
Version:
Modules
Images
c:\users\admin\appdata\local\temp\file.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
5748"C:\WINDOWS\system32\net.exe" pause shine-encoder_11151C:\Windows\SysWOW64\net.exefile.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Net Command
Exit code:
2
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\net.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
5944C:\WINDOWS\system32\net1 pause shine-encoder_11151C:\Windows\SysWOW64\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Net Command
Exit code:
2
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\net1.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\sechost.dll
6676"C:\Users\admin\AppData\Local\Shine Encoder 3.5.6\shineencoder.exe" -iC:\Users\admin\AppData\Local\Shine Encoder 3.5.6\shineencoder.exe
file.tmp
User:
admin
Integrity Level:
MEDIUM
Version:
16.0.199.1
Modules
Images
c:\users\admin\appdata\local\shine encoder 3.5.6\shineencoder.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6688\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
Total events
4 654
Read events
4 640
Write events
14
Delete events
0

Modification events

(PID) Process:(3128) file.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Shine Encoder_is1
Operation:writeName:Inno Setup: Setup Version
Value:
6.0.2 (u)
(PID) Process:(3128) file.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Shine Encoder_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Users\admin\AppData\Local\Shine Encoder 3.5.6
(PID) Process:(3128) file.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Shine Encoder_is1
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Local\Shine Encoder 3.5.6\
(PID) Process:(3128) file.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Shine Encoder_is1
Operation:writeName:Inno Setup: Icon Group
Value:
(Default)
(PID) Process:(3128) file.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Shine Encoder_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(3128) file.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Shine Encoder_is1
Operation:writeName:Inno Setup: Language
Value:
en
(PID) Process:(3128) file.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Shine Encoder_is1
Operation:writeName:DisplayName
Value:
Shine Encoder 3.5.6
(PID) Process:(3128) file.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Shine Encoder_is1
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Local\Shine Encoder 3.5.6\uninstall\unins000.exe"
(PID) Process:(3128) file.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Shine Encoder_is1
Operation:writeName:QuietUninstallString
Value:
"C:\Users\admin\AppData\Local\Shine Encoder 3.5.6\uninstall\unins000.exe" /SILENT
(PID) Process:(3128) file.tmpKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Shine Encoder_is1
Operation:writeName:NoModify
Value:
1
Executable files
19
Suspicious files
33
Text files
4
Unknown types
0

Dropped files

PID
Process
Filename
Type
3128file.tmpC:\Users\admin\AppData\Local\Temp\is-LDNQP.tmp\_isetup\_setup64.tmpexecutable
MD5:E4211D6D009757C078A9FAC7FF4F03D4
SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95
3128file.tmpC:\Users\admin\AppData\Local\Shine Encoder 3.5.6\is-2C9CC.tmpexecutable
MD5:86F1895AE8C5E8B17D99ECE768A70732
SHA256:8094AF5EE310714CAEBCCAEEE7769FFB08048503BA478B879EDFEF5F1A24FEFE
3128file.tmpC:\Users\admin\AppData\Local\Shine Encoder 3.5.6\msvcr71.dllexecutable
MD5:86F1895AE8C5E8B17D99ECE768A70732
SHA256:8094AF5EE310714CAEBCCAEEE7769FFB08048503BA478B879EDFEF5F1A24FEFE
3128file.tmpC:\Users\admin\AppData\Local\Shine Encoder 3.5.6\is-SG3R3.tmpexecutable
MD5:6330B1294C40518F7C6363F97338A0A9
SHA256:4D100667AD119AD52D1172173C97EB9EC30B7C378070DFD2D07A2A04767B4D86
3128file.tmpC:\Users\admin\AppData\Local\Shine Encoder 3.5.6\is-8J81S.tmpexecutable
MD5:43F2BC6828B177477C2F98B8973460E8
SHA256:3B578B15AD0D0747E8A3D958A0E7BF1FF6D5C335B8894FF7A020604DA008D79D
3128file.tmpC:\Users\admin\AppData\Local\Shine Encoder 3.5.6\CH375DLL.dllexecutable
MD5:43F2BC6828B177477C2F98B8973460E8
SHA256:3B578B15AD0D0747E8A3D958A0E7BF1FF6D5C335B8894FF7A020604DA008D79D
3128file.tmpC:\Users\admin\AppData\Local\Shine Encoder 3.5.6\Library\is-OL1MC.tmpbinary
MD5:619CA288DE840F0BEC52218DB7F2036C
SHA256:C2A6D78B635CA45E316D10936EF7507B1643F4674BAA08B79FE22285EADC3966
3128file.tmpC:\Users\admin\AppData\Local\Shine Encoder 3.5.6\cairogfx.dllexecutable
MD5:6330B1294C40518F7C6363F97338A0A9
SHA256:4D100667AD119AD52D1172173C97EB9EC30B7C378070DFD2D07A2A04767B4D86
3128file.tmpC:\Users\admin\AppData\Local\Shine Encoder 3.5.6\Library\is-801PI.tmpbinary
MD5:7D692438B7E70DE932BC386A3D44D319
SHA256:05CB2D622DDEED62E052B8BBDB19DBE99B83F44F4447408601823B518D330586
3128file.tmpC:\Users\admin\AppData\Local\Shine Encoder 3.5.6\is-5O4M3.tmpexecutable
MD5:21CF2233F94BF81E22737E2CAE984FD1
SHA256:FCB2DC122AD93E88AA07B99DB1292CF5B8F04F7F5125C7A9AD98E8790E0F7366
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
39
DNS requests
20
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
6944
svchost.exe
GET
200
23.48.23.156:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
6944
svchost.exe
GET
200
23.52.120.96:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1880
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
4360
SearchApp.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D
unknown
whitelisted
6380
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
7120
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
6380
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
6944
svchost.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
5488
MoUsoCoreWorker.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
7048
RUXIMICS.exe
20.73.194.208:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
4
System
192.168.100.255:138
whitelisted
6944
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
6944
svchost.exe
23.48.23.156:80
crl.microsoft.com
Akamai International B.V.
DE
whitelisted
6944
svchost.exe
23.52.120.96:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
5488
MoUsoCoreWorker.exe
4.231.128.59:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4360
SearchApp.exe
2.16.110.179:443
www.bing.com
Akamai International B.V.
DE
whitelisted

DNS requests

Domain
IP
Reputation
google.com
  • 142.250.185.142
whitelisted
settings-win.data.microsoft.com
  • 51.104.136.2
  • 4.231.128.59
  • 20.73.194.208
whitelisted
crl.microsoft.com
  • 23.48.23.156
  • 23.48.23.143
whitelisted
www.microsoft.com
  • 23.52.120.96
  • 88.221.169.152
whitelisted
www.bing.com
  • 2.16.110.179
  • 2.16.110.130
  • 2.16.110.131
  • 2.16.110.170
  • 2.16.110.168
  • 2.16.110.171
  • 2.16.110.177
  • 2.16.110.146
  • 2.16.110.200
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
login.live.com
  • 40.126.32.138
  • 40.126.32.140
  • 40.126.32.68
  • 40.126.32.136
  • 20.190.160.17
  • 40.126.32.72
  • 40.126.32.133
  • 40.126.32.74
whitelisted
th.bing.com
  • 2.16.110.170
  • 2.16.110.203
  • 2.16.110.168
  • 2.16.110.179
  • 2.16.110.171
  • 2.16.110.152
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
slscr.update.microsoft.com
  • 4.245.163.56
whitelisted

Threats

No threats detected
No debug info