| File name: | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe |
| Full analysis: | https://app.any.run/tasks/67151e58-80f5-45e9-bbcf-6e34b4e40ce7 |
| Verdict: | Malicious activity |
| Threats: | Gh0st RAT is a malware with advanced trojan functionality that enables attackers to establish full control over the victim’s system. The spying capabilities of Gh0st RAT made it a go-to tool for numerous criminal groups in high-profile attacks against government and corporate organizations. The most common vector of attack involving this malware begins with spam and phishing emails. |
| Analysis date: | December 19, 2023, 03:55:14 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 503C74E8B5AF63947A82EBDDB67DDB98 |
| SHA1: | B046A503F266F00A175C1812B42EF7B82F429400 |
| SHA256: | FC3870B865F8077DD0DB4D5CCC7923504A5D9BFC632AF964C187B4D76014DBD9 |
| SSDEEP: | 3072:VV+8xcDLhWCJqDTP7dNttb25qFHSLSVF2cxCZ9:VV+8g/cb/ni5KES2cxK9 |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:02:04 10:12:21+01:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 25088 |
| InitializedDataSize: | 118272 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x34a8 |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 4.6.0.0 |
| ProductVersionNumber: | 4.6.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | Windows, Chinese (Simplified) |
| Comments: | 《街头篮球》完整安装程序,(上海)天游软件 |
| CompanyName: | T2CN |
| FileDescription: | 《街头篮球》安装程序 By LingDi/T2CN |
| FileVersion: | 4.6.0.0 |
| LegalCopyright: | T2CN |
| LegalTrademarks: | T2CN |
| ProductName: | 《街头篮球》安装程序 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1780 | "C:\Users\admin\AppData\Roaming\fy2f3\yrzXQki.exe" | C:\Users\admin\AppData\Roaming\fy2f3\yrzXQki.exe | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | ||||||||||||
User: admin Company: Indigo Rose Corporation Integrity Level: HIGH Description: TrueUpdate Client Exit code: 0 Version: 3.8.0.0 Modules
| |||||||||||||||
| 2044 | "C:\Users\admin\AppData\Local\Temp\2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe" | C:\Users\admin\AppData\Local\Temp\2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | — | explorer.exe | |||||||||||
User: admin Company: T2CN Integrity Level: MEDIUM Description: 《街头篮球》安装程序 By LingDi/T2CN Exit code: 3221226540 Version: 4.6.0.0 Modules
| |||||||||||||||
| 2128 | cmd /c echo.>c:\xxxx.ini | C:\Windows\System32\cmd.exe | — | yrzXQki.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2208 | "C:\Users\admin\AppData\Local\Temp\2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe" | C:\Users\admin\AppData\Local\Temp\2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | explorer.exe | ||||||||||||
User: admin Company: T2CN Integrity Level: HIGH Description: 《街头篮球》安装程序 By LingDi/T2CN Exit code: 0 Version: 4.6.0.0 Modules
| |||||||||||||||
| (PID) Process: | (2208) 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2208) 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2208) 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2208) 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2208) 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2208) 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2208) 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2208) 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (1780) yrzXQki.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System |
| Operation: | write | Name: | ConsentPromptBehaviorAdmin |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2208 | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | C:\Users\admin\AppData\Roaming\fy2f3\yrzXQki.dat | compressed | |
MD5:41FA352A1BC005B543295EA9AAD538FD | SHA256:BDFACD62F6F03F65285B124DD50A1972E35D52AF87E785B89E721EFA52564165 | |||
| 1780 | yrzXQki.exe | C:\Users\admin\AppData\Local\Temp\_ir_tu2_temp_0\IRIMG4.JPG | image | |
MD5:05A6B5E6F8F3C239A9669DCC693E9B83 | SHA256:1BFA036A09BAD94FC4B9CE956C13628987F4E390A5F88D64A47F44941AA31692 | |||
| 2208 | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | C:\Users\admin\AppData\Roaming\fy2f3\edge.xml | binary | |
MD5:3AE9CFE1F12645251373F646E090AD9D | SHA256:4A30B51F5D891E17CB9F2018C9DFDDE33F65513614AD726CE24E6AE1FAD8F47B | |||
| 2208 | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\4[1] | image | |
MD5:59193AD9394825FA905D95493D3FCC9A | SHA256:712A70C0E19666B402B587D882628A450B3D98EB4357BDE6921E66E9EE506559 | |||
| 2208 | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\2[1] | compressed | |
MD5:E2D1D5C2818E9328308FE1989446337A | SHA256:B71B7D48CDC115B3F61625C1CA77AC2D7E52B8DB3613A8CC63B30D57A3437575 | |||
| 2208 | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\3[1] | binary | |
MD5:193F56567100B152AA7B13A1F71BEFC0 | SHA256:094F256E0786437A0779BEA5B3CB305AFA84C7525A245860B17C03FC83EC0C70 | |||
| 2208 | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\ll-23[1] | image | |
MD5:9930D5DF15F859D90EF78FC80FEC0D0A | SHA256:921BDB72CB3343A1B67CC56C90E5D661B47E21A761D502175D53D40405146CCD | |||
| 2208 | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\1[1] | executable | |
MD5:732F6B6B8BCF37B9B98CC60AE2804645 | SHA256:6388DA2F60C59E23D7C5F06B73AD80FEEE170238099AD5D418EBBE01A102F194 | |||
| 2208 | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | C:\Users\admin\AppData\Roaming\fy2f3\yrzXQki.exe | executable | |
MD5:39E37A8A51418848C8C275BE100AB540 | SHA256:B1E55C6DDBA3A00B499AB3B85A0BFB1839EE42FEAFF91EE65A9275EE63DE6F75 | |||
| 1780 | yrzXQki.exe | C:\Users\admin\AppData\Local\Temp\_ir_tu2_temp_0\IRIMG1.JPG | image | |
MD5:B039A043B4589C8626DC3E8F1FE25B9F | SHA256:4E2C3590FEE4A854907D59A64644EFE943C7B56206CCA717952A21B523C9CC30 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2208 | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | GET | 200 | 202.79.175.103:8000 | http://202.79.175.103:8000/ll-23 | unknown | image | 75.6 Kb | unknown |
2208 | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | GET | 200 | 202.79.175.103:8000 | http://202.79.175.103:8000/1 | unknown | executable | 529 Kb | unknown |
2208 | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | GET | 200 | 202.79.175.103:8000 | http://202.79.175.103:8000/2 | unknown | compressed | 129 Kb | unknown |
2208 | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | GET | 200 | 202.79.175.103:8000 | http://202.79.175.103:8000/4 | unknown | image | 356 Kb | unknown |
2208 | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | GET | 200 | 202.79.175.103:8000 | http://202.79.175.103:8000/3 | unknown | binary | 78.5 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2208 | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | 202.79.175.103:8000 | — | BGPNET Global ASN | SG | unknown |
1780 | yrzXQki.exe | 202.79.175.103:7700 | — | BGPNET Global ASN | SG | unknown |
Domain | IP | Reputation |
|---|---|---|
lquxkw.net |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
2208 | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2208 | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | A Network Trojan was detected | ET MALWARE JS/WSF Downloader Dec 08 2016 M7 |
2208 | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | Potentially Bad Traffic | ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response |
2208 | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | Misc activity | ET INFO EXE - Served Attached HTTP |
2208 | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | Potentially Bad Traffic | ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download |
2208 | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | Misc activity | ET INFO EXE IsDebuggerPresent (Used in Malware Anti-Debugging) |
2208 | 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe | A Network Trojan was detected | PAYLOAD [ANY.RUN] Encrypted DLL Gh0stRat inside Jpeg |
Process | Message |
|---|---|
yrzXQki.exe | Thread running...
|
yrzXQki.exe | Thread running...
|
yrzXQki.exe | Thread running...
|
yrzXQki.exe | Thread running...
|
yrzXQki.exe | Thread running...
|
yrzXQki.exe | Thread running...
|
yrzXQki.exe | Thread running...
|
yrzXQki.exe | Thread running...
|
yrzXQki.exe | Thread running...
|
yrzXQki.exe | Thread running...
|