File name:

1.71_kazaalite171.exe

Full analysis: https://app.any.run/tasks/89b15bb6-32f2-48c4-934d-3742fd977727
Verdict: Malicious activity
Analysis date: August 01, 2024, 01:59:19
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
installer
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

ACFF763F4AF0821F90B283E1494A424B

SHA1:

963B1E0C0505F38ADE95E1A75E717761432F955D

SHA256:

F480A74A85858E767788917AC6690AC6B48E9DB4314907A3914CE04051D2DF7B

SSDEEP:

49152:FthbBxbPxCtLeCrCy/9mfZQJ5HjsFtcFzlL3qGDMA0snI38CwuRluuC+tXcvmhFE:F7NxbPctjuimfZQfDsFtbGDMAfn9CI+G

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • 1.71_kazaalite171.exe (PID: 3592)
  • SUSPICIOUS

    • Searches for installed software

      • 1.71_kazaalite171.exe (PID: 3592)
    • Creates a software uninstall entry

      • 1.71_kazaalite171.exe (PID: 3592)
    • Executable content was dropped or overwritten

      • 1.71_kazaalite171.exe (PID: 3592)
    • Reads the Internet Settings

      • Kazaa.exe (PID: 3504)
    • Reads security settings of Internet Explorer

      • Kazaa.exe (PID: 3504)
    • Reads Microsoft Outlook installation path

      • Kazaa.exe (PID: 3504)
    • Reads Internet Explorer settings

      • Kazaa.exe (PID: 3504)
  • INFO

    • Checks supported languages

      • 1.71_kazaalite171.exe (PID: 3592)
      • Kazaa.exe (PID: 3504)
      • wmpnscfg.exe (PID: 3392)
    • Creates files in the program directory

      • 1.71_kazaalite171.exe (PID: 3592)
    • Reads the computer name

      • 1.71_kazaalite171.exe (PID: 3592)
      • Kazaa.exe (PID: 3504)
      • wmpnscfg.exe (PID: 3392)
    • Create files in a temporary directory

      • 1.71_kazaalite171.exe (PID: 3592)
      • Kazaa.exe (PID: 3504)
    • Manual execution by a user

      • Kazaa.exe (PID: 3504)
      • wmpnscfg.exe (PID: 3392)
    • Reads the machine GUID from the registry

      • Kazaa.exe (PID: 3504)
    • Checks proxy server information

      • Kazaa.exe (PID: 3504)
    • Creates files or folders in the user directory

      • Kazaa.exe (PID: 3504)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Wise Installer executable (96.9)
.dll | Win32 Dynamic Link Library (generic) (1.3)
.exe | Win32 Executable (generic) (0.9)
.exe | Generic Win/DOS Executable (0.4)
.exe | DOS Executable Generic (0.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2000:04:25 14:37:12+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit, Removable run from swap
PEType: PE32
LinkerVersion: 6
CodeSize: 8704
InitializedDataSize: 5632
UninitializedDataSize: -
EntryPoint: 0x21af
OSVersion: 4
ImageVersion: 4
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.7.1.0
ProductVersionNumber: 1.7.1.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows 16-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
CompanyName: KaZaA Lite
FileDescription: KaZaA Lite 1.7.1 Installation
FileVersion: 1.7.1
LegalCopyright: KaZaA
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
44
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start 1.71_kazaalite171.exe kazaa.exe no specs wmpnscfg.exe no specs 1.71_kazaalite171.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2460"C:\Users\admin\Downloads\1.71_kazaalite171.exe" C:\Users\admin\Downloads\1.71_kazaalite171.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\downloads\1.71_kazaalite171.exe
c:\windows\system32\ntdll.dll
3392"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3504"C:\Program Files\KaZaA Lite\Kazaa.exe" C:\Program Files\KaZaA Lite\Kazaa.exeexplorer.exe
User:
admin
Company:
Sharman Networks
Integrity Level:
MEDIUM
Description:
KaZaA Lite
Exit code:
0
Version:
1, 7, 0, 0
Modules
Images
c:\program files\kazaa lite\kazaa.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
3592"C:\Users\admin\Downloads\1.71_kazaalite171.exe" C:\Users\admin\Downloads\1.71_kazaalite171.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\downloads\1.71_kazaalite171.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
Total events
2 708
Read events
2 482
Write events
211
Delete events
15

Modification events

(PID) Process:(3592) 1.71_kazaalite171.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KaZaA Lite 1.7.1
Operation:writeName:DisplayName
Value:
KaZaA Lite 1.7.1
(PID) Process:(3592) 1.71_kazaalite171.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\KaZaA Lite 1.7.1
Operation:writeName:UninstallString
Value:
C:\PROGRA~1\KAZAAL~1\UNWISE.EXE C:\PROGRA~1\KAZAAL~1\INSTALL.LOG
(PID) Process:(3592) 1.71_kazaalite171.exeKey:HKEY_CURRENT_USER\Software\Kazaa
Operation:writeName:LimitBitrate
Value:
0
(PID) Process:(3592) 1.71_kazaalite171.exeKey:HKEY_CURRENT_USER\Software\Kazaa\Advanced
Operation:writeName:MaxSearchResult
Value:
200
(PID) Process:(3592) 1.71_kazaalite171.exeKey:HKEY_CURRENT_USER\Software\Kazaa\InstantMessaging
Operation:writeName:IgnoreAll
Value:
0
(PID) Process:(3592) 1.71_kazaalite171.exeKey:HKEY_CURRENT_USER\Software\Kazaa\InstantMessaging
Operation:writeName:IgnoredUsers
Value:
(PID) Process:(3592) 1.71_kazaalite171.exeKey:HKEY_CURRENT_USER\Software\Kazaa\LocalContent
Operation:writeName:DisableSharing
Value:
0
(PID) Process:(3592) 1.71_kazaalite171.exeKey:HKEY_CURRENT_USER\Software\Kazaa\LocalContent
Operation:writeName:DownloadDir
Value:
C:\PROGRA~1\KAZAAL~1\My Shared Folder
(PID) Process:(3592) 1.71_kazaalite171.exeKey:HKEY_CURRENT_USER\Software\Kazaa\ResultsFilter
Operation:writeName:firewall_filter
Value:
1
(PID) Process:(3592) 1.71_kazaalite171.exeKey:HKEY_CURRENT_USER\Software\Kazaa\Settings
Operation:writeName:HideBonzi
Value:
1
Executable files
14
Suspicious files
11
Text files
9
Unknown types
0

Dropped files

PID
Process
Filename
Type
35921.71_kazaalite171.exeC:\Program Files\KaZaA Lite\UNWISE.EXEexecutable
MD5:3A938ED2427DF10E571041069E6980CB
SHA256:4751A3547F3B482BB4A2440D4E91E3DCBA9B4B0F5B1BB50416A32FB47AE75C5E
35921.71_kazaalite171.exeC:\Users\admin\AppData\Local\Temp\GLF2B54.tmptext
MD5:576D1820159378842C17B451052DA7FC
SHA256:FFF750622735AEDD296CEDA8E8FCC4F1B226F1E98CE3B9A657312466B4BA4A1A
35921.71_kazaalite171.exeC:\Users\admin\AppData\Local\Temp\~GLH0000.TMPexecutable
MD5:B9B41E50D612E00BF3A49A6405B89D74
SHA256:50E7A30E1825FAB93B94B698C2C6D2CC1787B094C6CEE53EEED5C497F77443C9
35921.71_kazaalite171.exeC:\Program Files\KaZaA Lite\~GLH0002.TMPexecutable
MD5:3A938ED2427DF10E571041069E6980CB
SHA256:4751A3547F3B482BB4A2440D4E91E3DCBA9B4B0F5B1BB50416A32FB47AE75C5E
35921.71_kazaalite171.exeC:\Program Files\KaZaA Lite\shared.icoimage
MD5:032EB59A6561AA3387E984F6370789F6
SHA256:64FADF36879FB6B95029CDE1365426739CBAA018FAADFCD06C699B300BC172E7
35921.71_kazaalite171.exeC:\Program Files\KaZaA Lite\kazaahelp.chmchm
MD5:025FA0186C16915169FA73EE152624D9
SHA256:77B07FFD22F12B6244DB6B91DA599672505EC53C53E5D2A5E9475939EF759394
35921.71_kazaalite171.exeC:\Program Files\KaZaA Lite\~GLH0004.TMPimage
MD5:032EB59A6561AA3387E984F6370789F6
SHA256:64FADF36879FB6B95029CDE1365426739CBAA018FAADFCD06C699B300BC172E7
35921.71_kazaalite171.exeC:\Program Files\KaZaA Lite\~GLH0005.TMPexecutable
MD5:65FD7EA79F626F7B57F4D6CED6339F32
SHA256:DF94491BA2793DA99A2431591F317C67150D22E2530A9D34D5F427AD854FCCF4
35921.71_kazaalite171.exeC:\Program Files\KaZaA Lite\cd_clint.dllexecutable
MD5:65FD7EA79F626F7B57F4D6CED6339F32
SHA256:DF94491BA2793DA99A2431591F317C67150D22E2530A9D34D5F427AD854FCCF4
35921.71_kazaalite171.exeC:\Users\admin\AppData\Local\Temp\GLK1F78.tmpexecutable
MD5:3DF61E5730883B2D338ADDD7ACBE4BC4
SHA256:2EFE9A54C8EB878711D9B6CD18F276838645AFF52FE69D8A864376CB258EC616
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
4
TCP/UDP connections
12
DNS requests
10
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1372
svchost.exe
GET
304
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33
unknown
whitelisted
1060
svchost.exe
GET
304
199.232.214.172:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?5445ebff82c5850f
unknown
whitelisted
1372
svchost.exe
GET
200
2.16.241.12:80
http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl
unknown
whitelisted
1372
svchost.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
whitelisted
239.255.255.250:3702
whitelisted
4
System
192.168.100.255:138
whitelisted
1372
svchost.exe
51.124.78.146:443
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1060
svchost.exe
224.0.0.252:5355
whitelisted
1372
svchost.exe
40.127.240.158:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
1372
svchost.exe
199.232.214.172:80
ctldl.windowsupdate.com
FASTLY
US
unknown
1372
svchost.exe
2.16.241.12:80
crl.microsoft.com
Akamai International B.V.
DE
unknown
1372
svchost.exe
95.101.149.131:80
www.microsoft.com
Akamai International B.V.
NL
unknown

DNS requests

Domain
IP
Reputation
google.com
  • 172.217.16.142
whitelisted
settings-win.data.microsoft.com
  • 40.127.240.158
whitelisted
ctldl.windowsupdate.com
  • 199.232.214.172
  • 199.232.210.172
whitelisted
crl.microsoft.com
  • 2.16.241.12
  • 2.16.241.19
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
update.kazaa.com
unknown
desktop.kazaa.com
unknown

Threats

No threats detected
No debug info