File name:

P.bin

Full analysis: https://app.any.run/tasks/fd32d0e2-7c8e-4d09-a72c-c7ecce4900a5
Verdict: Malicious activity
Analysis date: December 02, 2023, 14:55:17
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows
MD5:

0DF17827C044C6A105C84CC852FE23B5

SHA1:

AF7EB5EB81093B6B12C7A106F5AD4B156B57F063

SHA256:

EFDE11A2EBE53466B8B934F5ECCB91E3A224D74C83A78B5C9DE046D28E0B9801

SSDEEP:

3072:9FtgB/edUWM5MqvfcocSzMTW/eAuTiBtPV1+jOGuv:JgB+UlfcocS1DuTO3Llv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • P.bin.exe (PID: 1236)
    • Modifies files in the Chrome extension folder

      • P.bin.exe (PID: 1236)
    • Actions looks like stealing of personal data

      • P.bin.exe (PID: 1236)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Reads the machine GUID from the registry

      • P.bin.exe (PID: 1236)
    • Checks supported languages

      • P.bin.exe (PID: 1236)
    • Reads the computer name

      • P.bin.exe (PID: 1236)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:12:02 15:54:45+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 51712
InitializedDataSize: 59392
UninitializedDataSize: -
EntryPoint: 0x46a8
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start p.bin.exe

Process information

PID
CMD
Path
Indicators
Parent process
1236"C:\Users\admin\Desktop\P.bin.exe" C:\Users\admin\Desktop\P.bin.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\p.bin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\mpr.dll
c:\windows\system32\cryptsp.dll
Total events
68
Read events
68
Write events
0
Delete events
0

Modification events

No data
Executable files
8
Suspicious files
2 439
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
1236P.bin.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\AccLR.cab
MD5:
SHA256:
1236P.bin.exeC:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\AccLR.cab
MD5:
SHA256:
1236P.bin.exeC:\MSOCache\All Users\{90140000-0015-0410-0000-0000000FF1CE}-C\AccLR.cab
MD5:
SHA256:
1236P.bin.exeC:\MSOCache\All Users\{90140000-0015-0411-0000-0000000FF1CE}-C\AccLR.cab
MD5:
SHA256:
1236P.bin.exeC:\MSOCache\All Users\{90140000-0015-0410-0000-0000000FF1CE}-C\AccessMUI.xmlbinary
MD5:0BDBE70810565EDDC24542C92E74C794
SHA256:1DF363E4A477698DF56773E6CDC281D1391435260CA516791F92FB8B4CF72AAC
1236P.bin.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\branding.xmlbinary
MD5:35AA16879163E6DA8114F9850F7EE4B7
SHA256:A072C0A41BA521907046E7B922E4F902D05F411789F0FAA343AE2790E547D4EA
1236P.bin.exeC:\MSOCache\All Users\{90140000-0015-0410-0000-0000000FF1CE}-C\branding.xmlbinary
MD5:4184042BC30D8A993CA41222205F7E25
SHA256:D59EE62E3E194671B47025F1B4A6ABEC3A70733ED25C32D3987723BF87CE4B79
1236P.bin.exeC:\MSOCache\All Users\{90140000-0015-0410-0000-0000000FF1CE}-C\AccessMUI.msibinary
MD5:2169F39484453F331CA2A1BDF3BF6F8C
SHA256:410597AB510E893E20462A118B0A49CFD26E1B5A72AEA385409A8CA1E99C4309
1236P.bin.exeC:\MSOCache\All Users\{90140000-0015-0412-0000-0000000FF1CE}-C\AccLR.cab
MD5:
SHA256:
1236P.bin.exeC:\MSOCache\All Users\{90140000-0015-0411-0000-0000000FF1CE}-C\AccessMUI.xmlbinary
MD5:2F0969DCC311A89F91C6963E6EBE65FD
SHA256:912C2307CEB187B40C9EE4ED4524E5DAF3887A7D75D0406212857B291C3A52F0
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
868
svchost.exe
23.35.228.137:80
AKAMAI-AS
DE
unknown
4
System
192.168.100.255:138
whitelisted
868
svchost.exe
184.30.20.134:80
armmf.adobe.com
AKAMAI-AS
DE
unknown
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
armmf.adobe.com
  • 184.30.20.134
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info