File name:

2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe

Full analysis: https://app.any.run/tasks/67151e58-80f5-45e9-bbcf-6e34b4e40ce7
Verdict: Malicious activity
Threats:

Gh0st RAT is a malware with advanced trojan functionality that enables attackers to establish full control over the victim’s system. The spying capabilities of Gh0st RAT made it a go-to tool for numerous criminal groups in high-profile attacks against government and corporate organizations. The most common vector of attack involving this malware begins with spam and phishing emails.

Analysis date: December 19, 2023, 03:55:14
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
remote
rat
gh0st
payload
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

503C74E8B5AF63947A82EBDDB67DDB98

SHA1:

B046A503F266F00A175C1812B42EF7B82F429400

SHA256:

FC3870B865F8077DD0DB4D5CCC7923504A5D9BFC632AF964C187B4D76014DBD9

SSDEEP:

3072:VV+8xcDLhWCJqDTP7dNttb25qFHSLSVF2cxCZ9:VV+8g/cb/ni5KES2cxK9

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe (PID: 2208)
      • yrzXQki.exe (PID: 1780)
    • GH0ST has been detected (SURICATA)

      • 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe (PID: 2208)
    • Gh0st has been detected

      • yrzXQki.exe (PID: 1780)
  • SUSPICIOUS

    • Reads the Internet Settings

      • 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe (PID: 2208)
    • Connects to unusual port

      • 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe (PID: 2208)
      • yrzXQki.exe (PID: 1780)
    • Reads the Windows owner or organization settings

      • yrzXQki.exe (PID: 1780)
    • Starts CMD.EXE for commands execution

      • yrzXQki.exe (PID: 1780)
  • INFO

    • Reads the computer name

      • 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe (PID: 2208)
      • yrzXQki.exe (PID: 1780)
    • Checks supported languages

      • 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe (PID: 2208)
      • yrzXQki.exe (PID: 1780)
    • Checks proxy server information

      • 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe (PID: 2208)
    • Reads the machine GUID from the registry

      • 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe (PID: 2208)
    • Creates files or folders in the user directory

      • 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe (PID: 2208)
      • yrzXQki.exe (PID: 1780)
    • Create files in a temporary directory

      • yrzXQki.exe (PID: 1780)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:02:04 10:12:21+01:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 25088
InitializedDataSize: 118272
UninitializedDataSize: 1024
EntryPoint: 0x34a8
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 4.6.0.0
ProductVersionNumber: 4.6.0.0
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Simplified)
CharacterSet: Windows, Chinese (Simplified)
Comments: 《街头篮球》完整安装程序,(上海)天游软件
CompanyName: T2CN
FileDescription: 《街头篮球》安装程序 By LingDi/T2CN
FileVersion: 4.6.0.0
LegalCopyright: T2CN
LegalTrademarks: T2CN
ProductName: 《街头篮球》安装程序
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
4
Malicious processes
2
Suspicious processes
0

Behavior graph

Click at the process to see the details
start #GH0ST 2023年12月新发布-财会人员薪资补贴调整新政策所需材料  解压密码123.exe #GH0ST yrzxqki.exe cmd.exe no specs 2023年12月新发布-财会人员薪资补贴调整新政策所需材料  解压密码123.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1780"C:\Users\admin\AppData\Roaming\fy2f3\yrzXQki.exe" C:\Users\admin\AppData\Roaming\fy2f3\yrzXQki.exe
2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe
User:
admin
Company:
Indigo Rose Corporation
Integrity Level:
HIGH
Description:
TrueUpdate Client
Exit code:
0
Version:
3.8.0.0
Modules
Images
c:\users\admin\appdata\roaming\fy2f3\yrzxqki.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
2044"C:\Users\admin\AppData\Local\Temp\2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe" C:\Users\admin\AppData\Local\Temp\2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exeexplorer.exe
User:
admin
Company:
T2CN
Integrity Level:
MEDIUM
Description:
《街头篮球》安装程序 By LingDi/T2CN
Exit code:
3221226540
Version:
4.6.0.0
Modules
Images
c:\users\admin\appdata\local\temp\2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe
c:\windows\system32\ntdll.dll
2128cmd /c echo.>c:\xxxx.iniC:\Windows\System32\cmd.exeyrzXQki.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
2208"C:\Users\admin\AppData\Local\Temp\2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe" C:\Users\admin\AppData\Local\Temp\2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe
explorer.exe
User:
admin
Company:
T2CN
Integrity Level:
HIGH
Description:
《街头篮球》安装程序 By LingDi/T2CN
Exit code:
0
Version:
4.6.0.0
Modules
Images
c:\users\admin\appdata\local\temp\2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
1 335
Read events
1 322
Write events
13
Delete events
0

Modification events

(PID) Process:(2208) 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2208) 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(2208) 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2208) 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2208) 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2208) 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2208) 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies
Operation:writeName:CachePrefix
Value:
Cookie:
(PID) Process:(2208) 2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History
Operation:writeName:CachePrefix
Value:
Visited:
(PID) Process:(1780) yrzXQki.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Policies\System
Operation:writeName:ConsentPromptBehaviorAdmin
Value:
0
Executable files
3
Suspicious files
5
Text files
10
Unknown types
0

Dropped files

PID
Process
Filename
Type
22082023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exeC:\Users\admin\AppData\Roaming\fy2f3\yrzXQki.datcompressed
MD5:41FA352A1BC005B543295EA9AAD538FD
SHA256:BDFACD62F6F03F65285B124DD50A1972E35D52AF87E785B89E721EFA52564165
1780yrzXQki.exeC:\Users\admin\AppData\Local\Temp\_ir_tu2_temp_0\IRIMG4.JPGimage
MD5:05A6B5E6F8F3C239A9669DCC693E9B83
SHA256:1BFA036A09BAD94FC4B9CE956C13628987F4E390A5F88D64A47F44941AA31692
22082023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exeC:\Users\admin\AppData\Roaming\fy2f3\edge.xmlbinary
MD5:3AE9CFE1F12645251373F646E090AD9D
SHA256:4A30B51F5D891E17CB9F2018C9DFDDE33F65513614AD726CE24E6AE1FAD8F47B
22082023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\4[1]image
MD5:59193AD9394825FA905D95493D3FCC9A
SHA256:712A70C0E19666B402B587D882628A450B3D98EB4357BDE6921E66E9EE506559
22082023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\2[1]compressed
MD5:E2D1D5C2818E9328308FE1989446337A
SHA256:B71B7D48CDC115B3F61625C1CA77AC2D7E52B8DB3613A8CC63B30D57A3437575
22082023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\3[1]binary
MD5:193F56567100B152AA7B13A1F71BEFC0
SHA256:094F256E0786437A0779BEA5B3CB305AFA84C7525A245860B17C03FC83EC0C70
22082023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\PO2HN1X2\ll-23[1]image
MD5:9930D5DF15F859D90EF78FC80FEC0D0A
SHA256:921BDB72CB3343A1B67CC56C90E5D661B47E21A761D502175D53D40405146CCD
22082023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\B6QGX7LP\1[1]executable
MD5:732F6B6B8BCF37B9B98CC60AE2804645
SHA256:6388DA2F60C59E23D7C5F06B73AD80FEEE170238099AD5D418EBBE01A102F194
22082023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exeC:\Users\admin\AppData\Roaming\fy2f3\yrzXQki.exeexecutable
MD5:39E37A8A51418848C8C275BE100AB540
SHA256:B1E55C6DDBA3A00B499AB3B85A0BFB1839EE42FEAFF91EE65A9275EE63DE6F75
1780yrzXQki.exeC:\Users\admin\AppData\Local\Temp\_ir_tu2_temp_0\IRIMG1.JPGimage
MD5:B039A043B4589C8626DC3E8F1FE25B9F
SHA256:4E2C3590FEE4A854907D59A64644EFE943C7B56206CCA717952A21B523C9CC30
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
8
DNS requests
1
Threats
7

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2208
2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe
GET
200
202.79.175.103:8000
http://202.79.175.103:8000/ll-23
unknown
image
75.6 Kb
unknown
2208
2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe
GET
200
202.79.175.103:8000
http://202.79.175.103:8000/1
unknown
executable
529 Kb
unknown
2208
2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe
GET
200
202.79.175.103:8000
http://202.79.175.103:8000/2
unknown
compressed
129 Kb
unknown
2208
2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe
GET
200
202.79.175.103:8000
http://202.79.175.103:8000/4
unknown
image
356 Kb
unknown
2208
2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe
GET
200
202.79.175.103:8000
http://202.79.175.103:8000/3
unknown
binary
78.5 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2208
2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe
202.79.175.103:8000
BGPNET Global ASN
SG
unknown
1780
yrzXQki.exe
202.79.175.103:7700
BGPNET Global ASN
SG
unknown

DNS requests

Domain
IP
Reputation
lquxkw.net
unknown

Threats

PID
Process
Class
Message
2208
2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
2208
2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe
A Network Trojan was detected
ET MALWARE JS/WSF Downloader Dec 08 2016 M7
2208
2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe
Potentially Bad Traffic
ET HUNTING SUSPICIOUS Dotted Quad Host MZ Response
2208
2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe
Misc activity
ET INFO EXE - Served Attached HTTP
2208
2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe
Potentially Bad Traffic
ET INFO Executable Retrieved With Minimal HTTP Headers - Potential Second Stage Download
2208
2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe
Misc activity
ET INFO EXE IsDebuggerPresent (Used in Malware Anti-Debugging)
2208
2023年12月新发布-财会人员薪资补贴调整新政策所需材料 解压密码123.exe
A Network Trojan was detected
PAYLOAD [ANY.RUN] Encrypted DLL Gh0stRat inside Jpeg
Process
Message
yrzXQki.exe
Thread running...
yrzXQki.exe
Thread running...
yrzXQki.exe
Thread running...
yrzXQki.exe
Thread running...
yrzXQki.exe
Thread running...
yrzXQki.exe
Thread running...
yrzXQki.exe
Thread running...
yrzXQki.exe
Thread running...
yrzXQki.exe
Thread running...
yrzXQki.exe
Thread running...