File name:

P.bin

Full analysis: https://app.any.run/tasks/fd32d0e2-7c8e-4d09-a72c-c7ecce4900a5
Verdict: Malicious activity
Analysis date: December 02, 2023, 14:55:17
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (console) Intel 80386, for MS Windows
MD5:

0DF17827C044C6A105C84CC852FE23B5

SHA1:

AF7EB5EB81093B6B12C7A106F5AD4B156B57F063

SHA256:

EFDE11A2EBE53466B8B934F5ECCB91E3A224D74C83A78B5C9DE046D28E0B9801

SSDEEP:

3072:9FtgB/edUWM5MqvfcocSzMTW/eAuTiBtPV1+jOGuv:JgB+UlfcocS1DuTO3Llv

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Modifies files in the Chrome extension folder

      • P.bin.exe (PID: 1236)
    • Drops the executable file immediately after the start

      • P.bin.exe (PID: 1236)
    • Actions looks like stealing of personal data

      • P.bin.exe (PID: 1236)
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    • Checks supported languages

      • P.bin.exe (PID: 1236)
    • Reads the computer name

      • P.bin.exe (PID: 1236)
    • Reads the machine GUID from the registry

      • P.bin.exe (PID: 1236)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2023:12:02 15:54:45+01:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 11
CodeSize: 51712
InitializedDataSize: 59392
UninitializedDataSize: -
EntryPoint: 0x46a8
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows command line
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
38
Monitored processes
1
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start p.bin.exe

Process information

PID
CMD
Path
Indicators
Parent process
1236"C:\Users\admin\Desktop\P.bin.exe" C:\Users\admin\Desktop\P.bin.exe
explorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\desktop\p.bin.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\mpr.dll
c:\windows\system32\cryptsp.dll
Total events
68
Read events
68
Write events
0
Delete events
0

Modification events

No data
Executable files
8
Suspicious files
2 439
Text files
2
Unknown types
0

Dropped files

PID
Process
Filename
Type
1236P.bin.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\AccLR.cab
MD5:
SHA256:
1236P.bin.exeC:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\AccLR.cab
MD5:
SHA256:
1236P.bin.exeC:\MSOCache\All Users\{90140000-0015-0410-0000-0000000FF1CE}-C\AccLR.cab
MD5:
SHA256:
1236P.bin.exeC:\MSOCache\All Users\{90140000-0015-0411-0000-0000000FF1CE}-C\AccLR.cab
MD5:
SHA256:
1236P.bin.exeC:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\AccessMUI.xmlbinary
MD5:1BBE2F474735BF3C3B76CB85D1EFB421
SHA256:5E878A18C8E3F760EC60BD24F62B22C8C4DF629F19E9FF100EA7273688EEF1EB
1236P.bin.exeC:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\Setup.xmlbinary
MD5:56AB7EC46C579B3BC533A2E27D3D210B
SHA256:4468BAA200746A3763F5EC0593096F6670DAFA040E9F00265564DA4C83DFA01D
1236P.bin.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\Setup.xmlbinary
MD5:2FC234765F04FF9B454DAC3D44017287
SHA256:1804F5749D05A35A9163340E29AFF32A7586B0437D3F2437DB3F5723A45BE07F
1236P.bin.exeC:\MSOCache\All Users\{90140000-0015-040C-0000-0000000FF1CE}-C\AccessMUI.msibinary
MD5:6B16A7F2F77D4A0ABECDAD73DE637CB1
SHA256:CE34897A675B14F290960DAA3504775DD29FD8F569D2C8885533652114373124
1236P.bin.exeC:\MSOCache\All Users\{90140000-0015-0412-0000-0000000FF1CE}-C\AccLR.cab
MD5:
SHA256:
1236P.bin.exeC:\MSOCache\All Users\{90140000-0015-0407-0000-0000000FF1CE}-C\AccessMUI.xmlbinary
MD5:E520B22047A1B12F850D823AC826784B
SHA256:56EFD16E6B2E24634C7595EA1ED6D120DC1F7A1AA3F2BA7FAC9A354BCB00D5F1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
2
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
868
svchost.exe
23.35.228.137:80
AKAMAI-AS
DE
unknown
4
System
192.168.100.255:138
whitelisted
868
svchost.exe
184.30.20.134:80
armmf.adobe.com
AKAMAI-AS
DE
unknown
4
System
192.168.100.255:137
whitelisted

DNS requests

Domain
IP
Reputation
armmf.adobe.com
  • 184.30.20.134
whitelisted
dns.msftncsi.com
  • 131.107.255.255
shared

Threats

No threats detected
No debug info