| download: | test.bat |
| Full analysis: | https://app.any.run/tasks/38f250cf-6904-4e02-b6e6-3b0fee839705 |
| Verdict: | Malicious activity |
| Analysis date: | August 25, 2020, 06:32:46 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | text/plain |
| File info: | ASCII text, with no line terminators |
| MD5: | 20DEE4B291847837312C4CA29DCBEA77 |
| SHA1: | B02E780B2DD146E4E6F81D68CE75D484288D6DDD |
| SHA256: | F5E3B5C22EE23557B33996639EE23119B7427DF29229F4BB39D1D29AB6FAD28E |
| SSDEEP: | 3:Q6AAGR9efHXV9dV/:Qk0ef3VLd |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 272 | "C:\Windows\System32\Defrag.exe" | C:\Windows\System32\Defrag.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corp. Integrity Level: MEDIUM Description: Disk Defragmenter Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 308 | "C:\Windows\System32\calc.exe" | C:\Windows\System32\calc.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Calculator Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 332 | /c echo "test.bat" | C:\Windows\System32\cmd.exe | — | forfiles.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 532 | "C:\Windows\System32\AdapterTroubleshooter.exe" | C:\Windows\System32\AdapterTroubleshooter.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Troubleshoot Display Adapter Exit code: 3221226540 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 544 | "C:\Windows\System32\bthudtask.exe" | C:\Windows\System32\bthudtask.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Bluetooth Uninstall Device Task Exit code: 3221226540 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 544 | "C:\Windows\System32\DeviceProperties.exe" | C:\Windows\System32\DeviceProperties.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Device Properties Exit code: 3221226540 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 580 | "C:\Windows\System32\cmdl32.exe" | C:\Windows\System32\cmdl32.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Connection Manager Auto-Download Exit code: 1 Version: 7.02.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 608 | "C:\Windows\System32\cttune.exe" | C:\Windows\System32\cttune.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: ClearType Tuner Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 620 | "C:\Windows\System32\audiodg.exe" | C:\Windows\System32\audiodg.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Audio Device Graph Isolation Exit code: 6 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 688 | /c echo "thdzwq4e.kdo" | C:\Windows\System32\cmd.exe | — | forfiles.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (3080) AdapterTroubleshooter.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
| Operation: | write | Name: | Name |
Value: AdapterTroubleshooter.exe | |||
| (PID) Process: | (2720) cmd.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2720) cmd.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2244) AtBroker.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows NT\CurrentVersion\Accessibility |
| Operation: | write | Name: | Configuration |
Value: | |||
| (PID) Process: | (3596) aitagent.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\AppCompatFlags\AIT |
| Operation: | write | Name: | LastReadEntryTime |
Value: 0C316296A97AD601 | |||
| (PID) Process: | (308) calc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Calc |
| Operation: | write | Name: | Window_Placement |
Value: 2C0000000000000001000000FFFFFFFFFFFFFFFFFFFFFFFFFFFFFFFF2C0000002C0000004C03000084020000 | |||
| (PID) Process: | (2700) cleanmgr.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\136\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2700) cleanmgr.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\136\52C64B7E |
| Operation: | write | Name: | @C:\Windows\System32\occache.dll,-1070 |
Value: Downloaded Program Files | |||
| (PID) Process: | (2700) cleanmgr.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\136\52C64B7E |
| Operation: | write | Name: | @C:\Windows\System32\occache.dll,-1071 |
Value: Downloaded Program Files are ActiveX controls and Java applets downloaded automatically from the Internet when you view certain pages. They are temporarily stored in the Downloaded Program Files folder on your hard disk. | |||
| (PID) Process: | (2700) cleanmgr.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\136\52C64B7E |
| Operation: | write | Name: | @C:\Windows\System32\occache.dll,-1072 |
Value: &View Files | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2216 | ntvdm.exe | C:\Users\admin\AppData\Local\Temp\scsC7A6.tmp | — | |
MD5:— | SHA256:— | |||
| 2216 | ntvdm.exe | C:\Users\admin\AppData\Local\Temp\scsC7B6.tmp | — | |
MD5:— | SHA256:— | |||
| 2700 | cleanmgr.exe | C:\Users\admin\AppData\Local\Temp\{6089EE43-4653-4E3F-84DD-0E26E2CC005A} | — | |
MD5:— | SHA256:— | |||
| 1436 | ntvdm.exe | C:\Users\admin\AppData\Local\Temp\scsF609.tmp | — | |
MD5:— | SHA256:— | |||
| 1436 | ntvdm.exe | C:\Users\admin\AppData\Local\Temp\scsF619.tmp | — | |
MD5:— | SHA256:— | |||
| 3708 | DeviceDisplayObjectProvider.exe | C:\Users\admin\AppData\Local\Microsoft\Device Metadata\dmrc.idx.0 | — | |
MD5:— | SHA256:— | |||
| 3708 | DeviceDisplayObjectProvider.exe | C:\Users\admin\AppData\Local\Microsoft\Device Metadata\OLDCACHE.000 | — | |
MD5:— | SHA256:— | |||
| 5600 | ntvdm.exe | C:\Users\admin\AppData\Local\Temp\scs26ED.tmp | — | |
MD5:— | SHA256:— | |||
| 1908 | DeviceDisplayObjectProvider.exe | C:\Users\admin\AppData\Local\Microsoft\Device Metadata\dmrc.idx.0 | — | |
MD5:— | SHA256:— | |||
| 1908 | DeviceDisplayObjectProvider.exe | C:\Users\admin\AppData\Local\Microsoft\Device Metadata\OLDCACHE.000 | — | |
MD5:— | SHA256:— | |||
Process | Message |
|---|---|
cleanmgr.exe | PID=2700 Failed to create. - CScavengeCleanup::Initialize(hr:0x800702e4) |
mmc.exe | ViewerExternalLogsPath = 'C:\ProgramData\Microsoft\Event Viewer\ExternalLogs': Microsoft.Windows.ManagementUI.CombinedControls.EventsNode
|
mmc.exe | ViewerViewsFolderPath = 'C:\ProgramData\Microsoft\Event Viewer\Views': Microsoft.Windows.ManagementUI.CombinedControls.EventsNode
|
mmc.exe | ViewerAdminViewsPath = 'C:\ProgramData\Microsoft\Event Viewer\Views\ApplicationViewsRootNode': Microsoft.Windows.ManagementUI.CombinedControls.EventsNode
|
mmc.exe | ViewerViewsFolderPath = 'C:\ProgramData\Microsoft\Event Viewer\Views': Microsoft.Windows.ManagementUI.CombinedControls.EvĜ |
mmc.exe | AddIcons: Microsoft.TaskScheduler.SnapIn.TaskSchedulerExtension
|
mmc.exe | ViewerExternalLogsPath = 'C:\ProgramData\Microsoft\Event Viewer\ExternalLogs': Microsoft.Windows.ManagementUI.CombinedControls.EventsNode
|
mmc.exe | ViewerConfigPath = 'C:\ProgramData\Microsoft\Event Viewer': Microsoft.Windows.ManagementUI.CombinedControls.EventsNode
|
mmc.exe | ViewerViewsFolderPath = 'C:\ProgramData\Microsoft\Event Viewer\Views': Microsoft.Windows.ManagementUI.CombinedControls.EventsNode
|
mmc.exe | ViewerAdminViewsPath = 'C:\ProgramData\Microsoft\Event Viewer\Views\ApplicationViewsRootNode': Microsoft.Windows.ManagementUI.CombinedControls.EventsNode
|