| File name: | Odbcconf.exe.bat |
| Full analysis: | https://app.any.run/tasks/b68e1f22-2d2e-4aa9-8eab-b70b15d22ec3 |
| Verdict: | Malicious activity |
| Analysis date: | March 24, 2020, 05:54:29 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with CRLF line terminators |
| MD5: | 6DF5E3181CCD4DD1E6CEDEFFFC1C82E1 |
| SHA1: | 4C6C18889EDD13B38E1558CD6D3A24A936FBF77F |
| SHA256: | F0DF76756D4B1895EAB3B7D12A8633EE6BB45C8015F3D52DFDC35D22707C9F18 |
| SSDEEP: | 12:YYyDY8tdXkLfHcYn5GkJuYn/DfPJxfPDSOfOVw2PJphQlS:TfLfHcw5luw7fPvfPDSOfoPAS |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 392 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe /logfile= /LogToConsole=false /U AllTheThingsx86.dll | C:\Windows\Microsoft.NET\Framework\v4.0.30319\InstallUtil.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: .NET Framework installation utility Exit code: 4294967295 Version: 4.7.3062.0 built by: NET472REL1 Modules
| |||||||||||||||
| 576 | regsvr32.exe /s AllTheThingsx86.dll | C:\Windows\system32\regsvr32.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft(C) Register Server Exit code: 3 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 848 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\regsvcs.exe AllTheThingsx86.dll | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft .NET Services Installation Utility Exit code: 1 Version: 4.7.3062.0 built by: NET472REL1 Modules
| |||||||||||||||
| 916 | regsvr32.exe /s /u AllTheThingsx86.dll | C:\Windows\system32\regsvr32.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft(C) Register Server Exit code: 3 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1008 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\regsvcs.exe AllTheThingsx86.dll | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegSvcs.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft .NET Services Installation Utility Exit code: 1 Version: 4.7.3062.0 built by: NET472REL1 Modules
| |||||||||||||||
| 1140 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\regasm.exe /U AllTheThingsx86.dll | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft .NET Assembly Registration Utility Exit code: 100 Version: 4.7.3062.0 built by: NET472REL1 Modules
| |||||||||||||||
| 2056 | regsvr32.exe /s /u AllTheThingsx86.dll | C:\Windows\system32\regsvr32.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft(C) Register Server Exit code: 3 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2076 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\regasm.exe /U AllTheThingsx86.dll | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft .NET Assembly Registration Utility Exit code: 100 Version: 4.7.3062.0 built by: NET472REL1 Modules
| |||||||||||||||
| 2380 | C:\Windows\Microsoft.NET\Framework\v4.0.30319\regasm.exe /U AllTheThingsx86.dll | C:\Windows\Microsoft.NET\Framework\v4.0.30319\RegAsm.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft .NET Assembly Registration Utility Exit code: 100 Version: 4.7.3062.0 built by: NET472REL1 Modules
| |||||||||||||||
| 2464 | rundll32 AllTheThingsx86.dll,EntryPoint | C:\Windows\system32\rundll32.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||