| File name: | f1463e608272a17277311174668cc8a67bdffc60267613e6e853c98542ff9e6b.exe |
| Full analysis: | https://app.any.run/tasks/25fff109-50d4-4fdb-8e3f-e1894a70d697 |
| Verdict: | Malicious activity |
| Analysis date: | November 08, 2018, 17:58:30 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 99820592897D0FDE194B51086DB4F5FF |
| SHA1: | 8D7CDDA5D3D0BCA2A5D7B3CE5BABE48D99E9F113 |
| SHA256: | F1463E608272A17277311174668CC8A67BDFFC60267613E6E853C98542FF9E6B |
| SSDEEP: | 3072:YdRB9x3vpxWG56U4C9c6iPf3HylpJmmo8zx3vpSvOP:Yb/xfpV56Bwt3qexfp |
| .dll | | | Win32 Dynamic Link Library (generic) (38.3) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (26.2) |
| .exe | | | Win16/32 Executable Delphi generic (12) |
| .exe | | | Generic Win/DOS Executable (11.6) |
| .exe | | | DOS Executable Generic (11.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2015:05:18 02:33:09+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 7 |
| CodeSize: | 151552 |
| InitializedDataSize: | 12800 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1138 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 18-May-2015 00:33:09 |
| Detected languages: |
|
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000080 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 4 |
| Time date stamp: | 18-May-2015 00:33:09 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00024EE0 | 0x00025000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.87946 |
.jdata | 0x00026000 | 0x0000277C | 0x00002800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.61655 |
.zdata | 0x00029000 | 0x000002C0 | 0x00000400 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.148 |
.rcrs | 0x0002A000 | 0x0000059A | 0x00000600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 6.78319 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 7.18899 | 1280 | UNKNOWN | English - United States | RT_DIALOG |
cfgmgr32.dll |
cmutil.dll |
kernel32.dll |
modemui.dll |
untfs.dll |
user32.dll |
wtsapi32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1260 | "C:\Users\admin\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\JavaDeployReg.exe" | C:\Users\admin\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\JavaDeployReg.exe | — | f1463e608272a17277311174668cc8a67bdffc60267613e6e853c98542ff9e6b.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1264 | "C:\Windows\system32\cmd.exe" /c "C:\Users\admin\AppData\Local\Temp\updcca1f0fd.bat" | C:\Windows\system32\cmd.exe | — | f1463e608272a17277311174668cc8a67bdffc60267613e6e853c98542ff9e6b.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2508 | C:\Windows\system32\svchost.exe | C:\Windows\system32\svchost.exe | — | JavaDeployReg.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2788 | "C:\Users\admin\AppData\Local\Temp\f1463e608272a17277311174668cc8a67bdffc60267613e6e853c98542ff9e6b.exe" | C:\Users\admin\AppData\Local\Temp\f1463e608272a17277311174668cc8a67bdffc60267613e6e853c98542ff9e6b.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2976 | C:\Windows\system32\svchost.exe | C:\Windows\system32\svchost.exe | JavaDeployReg.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2976) svchost.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | WarnonBadCertRecving |
Value: 0 | |||
| (PID) Process: | (2976) svchost.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | JavaDeployReg.exe |
Value: C:\Users\admin\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\JavaDeployReg.exe | |||
| (PID) Process: | (2976) svchost.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Loabpy |
| Operation: | write | Name: | Kike |
Value: 6EDAB411CBDBDC335D397421FEDECB262391D00F88C7163B093691B9BBCF4020314B4EE4542B0A4642B0A0C41D02FBC0013D6DADC0A179B37DF4F161632028C76360CF4129F2C1232E839531B3426C1A28B83F76B1CBC56111302FC3A5BC689C771788ACBBCD18B0909764684910FCCF0B93A41F66CDCD32036295BBF2A8FA1575C4BD91F4E4152EA1172F2A4ADCE4030721E211B0AD7F19F12249536F13020620577ADE74A5F07B591F5ED4D8C5EB211EDDF1C85A9F3A1CA7978A26C29E20B2F0ECF0D06E6E646ADA9C9713502DC995797195C0ADFDCE7B97EC8D52F720B6F157DD08A12E44B843061A483A26821DA26EA9F361B430382893C2FC6BBA28AC39BBD12D3FE785B07895C96E1BE670FC37E9DA6C81C55B3AE2DC401C6A3F4AE6412DF9DD727AB2B61170C15C53E4BEDFB4D3AB0425024CEBB077334393890FCCE25DE02F737B7121A8C8E4115D7FCE1BB2C7406AAAE98A0AC7139F83C5BF443605A253B2D43E5DBBB09189C5A0C86DF77F9F5DA5B98E5F4D1742117D018455F198284A134F0BD59DCD445BE720EC24EE5871EDA38605D6F373342D27332675C76319553829DE42B3E2EA8D52D165F93FEC52236C4809EFED70DC1287428394CAB423F39E99C9FAFABEAE0BF4A4D94F1B2CD73486AC15BA346A7EEDF9B1EA32D1C0CAF540812F83F14CDCF2E35C9110EFE7F87AEAEC85DAED19C8FFCD9ABA652FF86FE448D1995C1236970075A294BAD10E4B33D0E0F5B27FD01326B6B2E2AA7DA038FF2D2A3B8C4C2B25A62B54ABD607261D520BFC3C6847DDFF8A65742AC4742E18C39145D245E1D0494E8A7D3962E564E91BC944562C9632B70E6657E7887BF8124A6B0211DA7B83447017C1EF1E37185AC795D028FFF3A0A796CBDFCEE0ACBEEF46BA70F770BC425DA08E08F51E5A16D0AA6906F89517CCE773F688577AF06E1F42D303222F958289BAEC4F9976E477B717C6444BAE0E282AD5D1890FD7A5FC6FCB5338B90AD82F2EFDB7AF35E204E380614C52EB52F2CE97B4DD6B7E647429684B09CBA322DEAAD4C2BDD6EDD150CD7E5F91DCB828A3AD5FE70BF35D031C51A9770E5ADA8CA357C81F06EDF5546B39E0F3C4C18C0D33ED86840F9FC71603E9F5E8500BD3F9241A9822EC690399769257B573CFF710004BADD11F33015C4C7BDDE37255251B9209C55E2A927E1203D97999CBF368C9136609DA23E580B904443F523AB59FCFCA06F3E15EE539F308EE768BA2CE9EE83CCC0B26E7CEB2B854D40E44D225E7597122EBB06AF052CA180306F7C382AA0C206D8A0629027CABE3018243D081FB043447EACBA822D98805BE9EC48F4EE69A2AEF4F14F3980A4479DEDEF542D6CDF7540487264DF44B0CB07016317A5C25F68744C5629B1EEE4A813D7AAF562AA760F700F0B927F974460C5B6D43988688B16E232822B48F0CB608666F0AF52AFF09677E2269EA334B63A057CF38259F78CE168238F94BC592CAADEE4A76A54426F8D032D451235F7A76EEC95D525AFC868DB7BB7896716645DD5E8B406607B661F1A304A2A7EFF883ADF61C3FA87D88847502FA134B8A12EDCA436B660C1A6AD983E439347AEFCC92DAF67AB5D909128D2C3F29272B605D240ED5041D7C7112961C7297DE363A2812AD92934458570363376B2D948A76A6E7BB264EF149FB89190FD12FF1A3019818A702A796307D60201B42A5301E4406F6D3F1F85D388ADF9422655B42E52F808E9EE67BFEB9B6BC667BF4A0C9C4DBB49D972388132B4B4CF8D100FFA6D4C7A601DE13CF7D7ABD22E9473AF476EB62931D8A12CD09E2228B60EA652B19522CFB695CF1BF0C9FAF3B193AE353B995EE530E94BB0BA441003DA5D022F34173BAC32FA605F2F6D87238A81784B743C42911240E1FFD2734CC3D25B851C43845CFA3723F32452D5B5305F0D5353013AC1DE03B8578B25D55FCE3618F17271E8A0939A091E410413A68131D6445E80124AF09E4991D1E680AAF24711F81A1B5D57165582875E65DB1BD2FDB8FD88B4D2459C0AFFDBB425AA5E294BB37A99B733B42C0995FE0ADA703ACABBCB972D5966F9A61E857F3C317DC2ABD74B946309801D3402C398133E12C77C6EBA1104A18FE9C354805F4132C925DF8A6015A6547284B3543D8062D0DA8097ADFCA77C3953CF1B668AA09029EB3B9C0645BAB561148E40E7615E81009EFAE694A47CA1C5BA3443EFDEE144449C6DB0222D9583A11F045C900B673FB8182332892B1AC615B419CFFAEF45FD7DA2763397A7654E816839AF5DF75BA156AA5E6E99D05F086E7A23941CD4C2CD73F0E1DD03EF3E7E4B354038BDD3B278320F838700E6B8A53DA6616B2DA5C568843FED9F06CB92954425C77919B577A536EAA9DE332FCB12245EE00000D280C571919E23D4E9EE19D669A0207D18C28C973602DCDFCC7629E98C81209790D213C416A21DDE0ADEF502DE5804F39258C1B724DE94FE426A5393C5CDAB5FF6DFFC481D5F4E3BFF8B242293D1C66AD464A8E | |||
| (PID) Process: | (2976) svchost.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2976) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\svchost_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (2976) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\svchost_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (2976) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\svchost_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (2976) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\svchost_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (2976) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\svchost_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (2976) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\svchost_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2788 | f1463e608272a17277311174668cc8a67bdffc60267613e6e853c98542ff9e6b.exe | C:\Users\admin\AppData\Local\Temp\updcca1f0fd.bat | text | |
MD5:— | SHA256:— | |||
| 2788 | f1463e608272a17277311174668cc8a67bdffc60267613e6e853c98542ff9e6b.exe | C:\Users\admin\AppData\Local\Adobe\AcroCef\DC\Acrobat\Cache\JavaDeployReg.exe | executable | |
MD5:— | SHA256:— | |||
| 2976 | svchost.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\prefs.js | text | |
MD5:— | SHA256:— | |||
| 2976 | svchost.exe | C:\Users\admin\Desktop\Google Chrome.lnk | lnk | |
MD5:— | SHA256:— | |||
| 2976 | svchost.exe | C:\Users\admin\AppData\Roaming\Microsoft\Internet Explorer\Quick Launch\User Pinned\TaskBar\Google Chrome.lnk | lnk | |
MD5:37BADF5B93F8B5F269B99A82FA4F8B08 | SHA256:3073939456F5D291426DFDEFDF6C302EAD6E74BB487FF9664E198EF2794D7760 | |||
Domain | IP | Reputation |
|---|---|---|
mealsanywhere.top |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1056 | svchost.exe | Potentially Bad Traffic | ET DNS Query to a *.top domain - Likely Hostile |