File name:

f1.exe

Full analysis: https://app.any.run/tasks/166d8e23-7675-44e5-84d0-bb49118f4f95
Verdict: Malicious activity
Analysis date: November 24, 2023, 13:48:41
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

F16C22B491E1BD20F677515C4F87E807

SHA1:

14C2AC75AD47058085AF5E99AD930BCE442AED79

SHA256:

FC4C193BDA7AEFE0460D5072AFAFDE40FEA9D2460E6635274B96340FB46D3223

SSDEEP:

98304:NShDv++xsuDZYVE9IRQJ+FgGzrz5OnaltQwS3fMUNhfWQoxdKz83Rdxvqe/5nexv:feypWIHlPZddAWssA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • f1.exe (PID: 2788)
  • SUSPICIOUS

    • The process drops C-runtime libraries

      • f1.exe (PID: 2788)
    • Loads Python modules

      • f1.exe (PID: 2404)
    • Application launched itself

      • f1.exe (PID: 2788)
    • Process drops legitimate windows executable

      • f1.exe (PID: 2788)
  • INFO

    • Checks supported languages

      • f1.exe (PID: 2788)
      • f1.exe (PID: 2404)
    • Reads the computer name

      • f1.exe (PID: 2788)
    • Create files in a temporary directory

      • f1.exe (PID: 2788)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2023:11:19 10:31:49+01:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.35
CodeSize: 171008
InitializedDataSize: 166912
UninitializedDataSize: -
EntryPoint: 0xc200
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 10.0.19041.1
ProductVersionNumber: 10.0.19041.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Resource Monitor
FileVersion: 10.0.19041.1 (WinBuild.160101.0800)
InternalName: resmon.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFileName: resmon.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.19041.1
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start f1.exe no specs f1.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2404"C:\Users\admin\AppData\Local\Temp\f1.exe" C:\Users\admin\AppData\Local\Temp\f1.exef1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Resource Monitor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\appdata\local\temp\f1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll
2788"C:\Users\admin\AppData\Local\Temp\f1.exe" C:\Users\admin\AppData\Local\Temp\f1.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Resource Monitor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\appdata\local\temp\f1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll
Total events
13
Read events
13
Write events
0
Delete events
0

Modification events

No data
Executable files
18
Suspicious files
2
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2788f1.exeC:\Users\admin\AppData\Local\Temp\_MEI27882\_ctypes.pydexecutable
MD5:1ADFE4D0F4D68C9C539489B89717984D
SHA256:64E8FD952CCF5B8ADCA80CE8C7BC6C96EC7DF381789256FE8D326F111F02E95C
2788f1.exeC:\Users\admin\AppData\Local\Temp\_MEI27882\VCRUNTIME140.dllexecutable
MD5:4585A96CC4EEF6AAFD5E27EA09147DC6
SHA256:A8F950B4357EC12CFCCDDC9094CCA56A3D5244B95E09EA6E9A746489F2D58736
2788f1.exeC:\Users\admin\AppData\Local\Temp\_MEI27882\_ssl.pydexecutable
MD5:2089768E25606262921E4424A590FF05
SHA256:3E6E9FC56E1A9FE5EDB39EE03E5D47FA0E3F6ADB17BE1F087DC6F891D3B0BBCA
2788f1.exeC:\Users\admin\AppData\Local\Temp\_MEI27882\_hashlib.pydexecutable
MD5:F10D896ED25751EAD72D8B03E404EA36
SHA256:3660B985CA47CA1BBA07DB01458B3153E4E692EE57A8B23CE22F1A5CA18707C3
2788f1.exeC:\Users\admin\AppData\Local\Temp\_MEI27882\_lzma.pydexecutable
MD5:3798175FD77EDED46A8AF6B03C5E5F6D
SHA256:3C9D5A9433B22538FC64141CD3784800C567C18E4379003329CF69A1D59B2A41
2788f1.exeC:\Users\admin\AppData\Local\Temp\_MEI27882\_decimal.pydexecutable
MD5:65B4AB77D6C6231C145D3E20E7073F51
SHA256:93EB9D1859EDCA1C29594491863BF3D72AF70B9A4240E0D9DD171F668F4F8614
2788f1.exeC:\Users\admin\AppData\Local\Temp\_MEI27882\_sqlite3.pydexecutable
MD5:EB6313B94292C827A5758EEA82D018D9
SHA256:6B41DFD7D6AC12AFE523D74A68F8BD984A75E438DCF2DAA23A1F934CA02E89DA
2788f1.exeC:\Users\admin\AppData\Local\Temp\_MEI27882\_queue.pydexecutable
MD5:DECDABACA104520549B0F66C136A9DC1
SHA256:9D4880F7D0129B1DE95BECD8EA8BBBF0C044D63E87764D18F9EC00D382E43F84
2788f1.exeC:\Users\admin\AppData\Local\Temp\_MEI27882\_socket.pydexecutable
MD5:BCC3E26A18D59D76FD6CF7CD64E9E14D
SHA256:4E19F29266A3D6C127E5E8DE01D2C9B68BC55075DD3D6AABE22CF0DE4B946A98
2788f1.exeC:\Users\admin\AppData\Local\Temp\_MEI27882\base_library.zipcompressed
MD5:2F6D57BCCF7F7735ACB884A980410F6A
SHA256:1B7D326BAD406E96A4C83B5A49714819467E3174ED0A74F81C9EBD96D1DD40B3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
324
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info