File name:

ComboFix.exe

Full analysis: https://app.any.run/tasks/72ea4c04-b38a-4b14-b19e-b8be16a0947e
Verdict: Malicious activity
Analysis date: October 02, 2024, 19:12:00
OS: Windows 10 Professional (build: 19045, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, RAR self-extracting archive
MD5:

E867B695E79AE16E1839E277920B703D

SHA1:

135763B72132FFBD4D86D60CC2DC8A98BF6A5B9F

SHA256:

F3C2E8A565CB22F482FBF2B32D376868F175FD4D282194E483D728306C8AA7C3

SSDEEP:

98304:+YN2wc2t4yH6PqTXpOb1DcV/3+Gs8w6aon05fDaJNIuo90rOdsrH9hkmvumP7rOR:+VYe

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    • Drops a system driver (possible attempt to evade defenses)

      • ComboFix.exe (PID: 884)
    • Process drops legitimate windows executable

      • gsar.cfexe (PID: 6628)
    • Starts application with an unusual extension

      • nircmd.com (PID: 3712)
      • ComboFix.exe (PID: 884)
      • nircmd.com (PID: 3852)
      • cmd.execf (PID: 5548)
    • Executable content was dropped or overwritten

      • ComboFix.exe (PID: 884)
      • gsar.cfexe (PID: 6628)
  • INFO

    • NirSoft software is detected

      • nircmd.com (PID: 2032)
      • nircmd.com (PID: 1404)
      • nircmd.com (PID: 3712)
      • nircmd.com (PID: 3852)
      • nircmd.com (PID: 6432)
    • Changes the display of characters in the console

      • cmd.execf (PID: 5548)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | WinRAR Self Extracting archive (88.2)
.exe | UPX compressed Win32 Executable (4.6)
.exe | Win32 EXE Yoda's Crypter (4.5)
.dll | Win32 Dynamic Link Library (generic) (1.1)
.exe | Win32 Executable (generic) (0.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2008:09:10 14:36:32+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 5
CodeSize: 49152
InitializedDataSize: 8192
UninitializedDataSize: 94208
EntryPoint: 0x23060
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
160
Monitored processes
27
Malicious processes
1
Suspicious processes
1

Behavior graph

Click at the process to see the details
start combofix.exe nircmd.com no specs infdefaultinstall.exe no specs runonce.exe no specs hidec.exe no specs nircmd.com no specs swreg.exe no specs conhost.exe no specs swreg.exe no specs conhost.exe no specs grpconv.exe no specs nircmd.com no specs gsar.cfexe conhost.exe no specs nircmd.com no specs cmd.execf no specs conhost.exe no specs find.exe no specs find.exe no specs find.exe no specs swreg.exe no specs grep.cfexe no specs swreg.exe no specs swreg.exe no specs chcp.com no specs nircmd.com no specs combofix.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
13232788R22FWJFW\swreg.exe import 32788R22FWJFW\EXE.regC:\32788R22FWJFW\swreg.exehidec.exe
User:
admin
Company:
SteelWerX
Integrity Level:
HIGH
Description:
Freeware implementation of REG.EXE
Exit code:
1
Version:
3.0.0.0
Modules
Images
c:\32788r22fwjfw\swreg.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
492SWREG acl "hklm\software\microsoft\windows nt\currentversion\windows" /RO:F /RA:F /QC:\32788R22FWJFW\swreg.execmd.execf
User:
admin
Company:
SteelWerX
Integrity Level:
HIGH
Description:
Freeware implementation of REG.EXE
Exit code:
0
Version:
3.0.0.0
Modules
Images
c:\32788r22fwjfw\swreg.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
696"C:\WINDOWS\system32\runonce.exe" -rC:\Windows\SysWOW64\runonce.exeInfDefaultInstall.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Run Once Wrapper
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\runonce.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\advapi32.dll
c:\windows\syswow64\msvcrt.dll
884"C:\Users\admin\AppData\Local\Temp\ComboFix.exe" C:\Users\admin\AppData\Local\Temp\ComboFix.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\combofix.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
1404"C:\32788R22FWJFW\nircmd.com" exec hide 32788R22FWJFW\SWREG.exe acl "hklm\software\microsoft\windows nt\currentversion\windows" /de:f /qC:\32788R22FWJFW\nircmd.comComboFix.exe
User:
admin
Company:
NirSoft
Integrity Level:
HIGH
Description:
NirCmd
Exit code:
0
Version:
2.10
Modules
Images
c:\32788r22fwjfw\nircmd.com
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2032"C:\32788R22FWJFW\nircmd.com" shexec install 32788R22FWJFW\nircmd.infC:\32788R22FWJFW\nircmd.comComboFix.exe
User:
admin
Company:
NirSoft
Integrity Level:
HIGH
Description:
NirCmd
Exit code:
0
Version:
2.10
Modules
Images
c:\32788r22fwjfw\nircmd.com
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\advapi32.dll
2056\??\C:\WINDOWS\system32\conhost.exe 0xffffffff -ForceV1C:\Windows\System32\conhost.exeswreg.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Console Window Host
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\windows\system32\conhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcp_win.dll
c:\windows\system32\ucrtbase.dll
c:\windows\system32\shcore.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\combase.dll
c:\windows\system32\rpcrt4.dll
2816"C:\WINDOWS\system32\Find.exe" "Windows XP" OsVerC:\Windows\SysWOW64\find.execmd.execf
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Find String (grep) Utility
Exit code:
1
Version:
10.0.19041.3636 (WinBuild.160101.0800)
Modules
Images
c:\windows\syswow64\find.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\msvcrt.dll
c:\windows\syswow64\ulib.dll
3148GREP.cfexe -sq "currentversion.* 6.0" OsVer00 C:\32788R22FWJFW\grep.cfexecmd.execf
User:
admin
Integrity Level:
HIGH
Exit code:
1
Modules
Images
c:\32788r22fwjfw\grep.cfexe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\msvcrt.dll
3528"C:\32788R22FWJFW\hidec.exe" 32788R22FWJFW\swreg.exe import 32788R22FWJFW\EXE.regC:\32788R22FWJFW\hidec.exeComboFix.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\32788r22fwjfw\hidec.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
Total events
1 638
Read events
1 616
Write events
16
Delete events
6

Modification events

(PID) Process:(2032) nircmd.comKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.inf\OpenWithProgids
Operation:writeName:inffile
Value:
(PID) Process:(2032) nircmd.comKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\WINDOWS\System32\InfDefaultInstall.exe.FriendlyAppName
Value:
INF Default Install
(PID) Process:(2032) nircmd.comKey:HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\MuiCache
Operation:writeName:C:\WINDOWS\System32\InfDefaultInstall.exe.ApplicationCompany
Value:
Microsoft Corporation
(PID) Process:(6948) InfDefaultInstall.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\cscript.exe
Operation:delete keyName:(default)
Value:
(PID) Process:(6948) InfDefaultInstall.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\rundll32.exe
Operation:delete keyName:(default)
Value:
(PID) Process:(6948) InfDefaultInstall.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Image File Execution Options\wscript.exe
Operation:delete keyName:(default)
Value:
(PID) Process:(6948) InfDefaultInstall.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
Operation:writeName:DisableRegistryTools
Value:
0
(PID) Process:(6948) InfDefaultInstall.exeKey:HKEY_CURRENT_USER\SOFTWARE\Policies\Microsoft\Windows\System
Operation:writeName:DisableCMD
Value:
0
(PID) Process:(6948) InfDefaultInstall.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce
Operation:writeName:GrpConv
Value:
grpconv -o
(PID) Process:(696) runonce.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\RunOnce
Operation:delete valueName:GrpConv
Value:
grpconv -o
Executable files
34
Suspicious files
3
Text files
70
Unknown types
1

Dropped files

PID
Process
Filename
Type
884ComboFix.exeC:\32788R22FWJFW\clsid.dattext
MD5:C608104C02E2D6048DB7174313CAEF30
SHA256:A6629655CF98AAC641A0871EB2372288AA149FEBF0C415B038B5D0232DCBECA5
884ComboFix.exeC:\32788R22FWJFW\appinit.badtext
MD5:503550F607ACC5F4D79CE82EA98C3F19
SHA256:C696873928F3BC755E8AFB89E90B9C7F22114D911A3AD4A8DE1A8194E7A395DF
884ComboFix.exeC:\32788R22FWJFW\Assoc.cmdtext
MD5:839E1B5C7B8AEE30B824E3B2B490CD14
SHA256:9D3A57069D583A1FECEAC5FAA25371C2C80840CB1DCD4F18BE1862D201F7286B
884ComboFix.exeC:\32788R22FWJFW\023v.dattext
MD5:AC22AC1EB4A61AD32D6019032FC0ACE9
SHA256:DDA470461F24189AF50C5D59B662B0EA227B6B36DE171C8AC4E89B29D5F944AD
884ComboFix.exeC:\32788R22FWJFW\badclsidtext
MD5:16E0E620A1D1248C9A73F82C945C833E
SHA256:07734715AD6E63F13ADDA5346702E6C9662565EDFC0C69D859CDCB79727ACEAC
884ComboFix.exeC:\32788R22FWJFW\Boot.battext
MD5:21FC54519806330B8D4826654F5CC7EA
SHA256:C420F7585EB1DEF827E07923B23A7FF9C077A58A9EB033F694194D19F1B1FCC5
884ComboFix.exeC:\32788R22FWJFW\Combo-Fix.sysexecutable
MD5:79C42F486A1186BF71BCC9C345C20AB3
SHA256:B8F1148C771A46EA77735A1B86E60A138BD130EC90AC23CEFC9DDC0815237077
884ComboFix.exeC:\32788R22FWJFW\BootSectpgc
MD5:5BC47BF1A60289ABD3F193A51208E2A1
SHA256:030CC797AAAE6C4200C16BEA3F4FA35E06E4235EDC3D8C93BD92CDFD0242B633
884ComboFix.exeC:\32788R22FWJFW\catchme.cfexeexecutable
MD5:288BBDD4968670DADC17173374F96DF1
SHA256:8DB95138E5CEA3B393E7EC05FF8D46B34AF190F216F220AA5E94CA6B9299B1F2
884ComboFix.exeC:\32788R22FWJFW\023.dattext
MD5:DFDE2D69E304EFB45FF7132782F5F265
SHA256:214DFC36A4408F89C8A26C2E2930A61A35AE3202D6FCBC38825374601EEC6063
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
56
DNS requests
16
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2120
MoUsoCoreWorker.exe
GET
200
23.35.229.160:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
1076
backgroundTaskHost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D
unknown
whitelisted
1252
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
1252
SIHClient.exe
GET
200
88.221.169.152:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
2064
svchost.exe
GET
200
192.229.221.95:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
4
System
192.168.100.255:137
whitelisted
2120
MoUsoCoreWorker.exe
23.35.229.160:80
www.microsoft.com
AKAMAI-AS
DE
whitelisted
4
System
192.168.100.255:138
whitelisted
3888
svchost.exe
239.255.255.250:1900
whitelisted
4324
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
3260
svchost.exe
40.113.103.199:443
client.wns.windows.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
2064
svchost.exe
40.126.31.71:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted
2064
svchost.exe
192.229.221.95:80
ocsp.digicert.com
EDGECAST
US
whitelisted
2776
svchost.exe
184.28.89.167:443
go.microsoft.com
AKAMAI-AS
US
whitelisted

DNS requests

Domain
IP
Reputation
settings-win.data.microsoft.com
  • 40.127.240.158
  • 51.104.136.2
whitelisted
google.com
  • 142.250.184.238
whitelisted
www.microsoft.com
  • 23.35.229.160
  • 88.221.169.152
whitelisted
client.wns.windows.com
  • 40.113.103.199
whitelisted
login.live.com
  • 40.126.31.71
  • 20.190.159.73
  • 20.190.159.75
  • 20.190.159.64
  • 20.190.159.23
  • 40.126.31.67
  • 20.190.159.4
  • 20.190.159.68
whitelisted
ocsp.digicert.com
  • 192.229.221.95
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
slscr.update.microsoft.com
  • 20.114.59.183
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 20.242.39.171
whitelisted
arc.msn.com
  • 20.223.35.26
whitelisted

Threats

No threats detected
No debug info