File name:

f1.exe

Full analysis: https://app.any.run/tasks/166d8e23-7675-44e5-84d0-bb49118f4f95
Verdict: Malicious activity
Analysis date: November 24, 2023, 13:48:41
OS: Windows 7 Professional Service Pack 1 (build: 7601, 64 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32+ executable (GUI) x86-64, for MS Windows
MD5:

F16C22B491E1BD20F677515C4F87E807

SHA1:

14C2AC75AD47058085AF5E99AD930BCE442AED79

SHA256:

FC4C193BDA7AEFE0460D5072AFAFDE40FEA9D2460E6635274B96340FB46D3223

SSDEEP:

98304:NShDv++xsuDZYVE9IRQJ+FgGzrz5OnaltQwS3fMUNhfWQoxdKz83Rdxvqe/5nexv:feypWIHlPZddAWssA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • f1.exe (PID: 2788)
  • SUSPICIOUS

    • The process drops C-runtime libraries

      • f1.exe (PID: 2788)
    • Process drops legitimate windows executable

      • f1.exe (PID: 2788)
    • Application launched itself

      • f1.exe (PID: 2788)
    • Loads Python modules

      • f1.exe (PID: 2404)
  • INFO

    • Reads the computer name

      • f1.exe (PID: 2788)
    • Create files in a temporary directory

      • f1.exe (PID: 2788)
    • Checks supported languages

      • f1.exe (PID: 2788)
      • f1.exe (PID: 2404)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win64 Executable (generic) (87.3)
.exe | Generic Win/DOS Executable (6.3)
.exe | DOS Executable Generic (6.3)

EXIF

EXE

MachineType: AMD AMD64
TimeStamp: 2023:11:19 10:31:49+01:00
ImageFileCharacteristics: Executable, Large address aware
PEType: PE32+
LinkerVersion: 14.35
CodeSize: 171008
InitializedDataSize: 166912
UninitializedDataSize: -
EntryPoint: 0xc200
OSVersion: 5.2
ImageVersion: -
SubsystemVersion: 5.2
Subsystem: Windows GUI
FileVersionNumber: 10.0.19041.1
ProductVersionNumber: 10.0.19041.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Microsoft Corporation
FileDescription: Resource Monitor
FileVersion: 10.0.19041.1 (WinBuild.160101.0800)
InternalName: resmon.exe
LegalCopyright: © Microsoft Corporation. All rights reserved.
OriginalFileName: resmon.exe
ProductName: Microsoft® Windows® Operating System
ProductVersion: 10.0.19041.1
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
35
Monitored processes
2
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start f1.exe no specs f1.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2404"C:\Users\admin\AppData\Local\Temp\f1.exe" C:\Users\admin\AppData\Local\Temp\f1.exef1.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Resource Monitor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\appdata\local\temp\f1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll
2788"C:\Users\admin\AppData\Local\Temp\f1.exe" C:\Users\admin\AppData\Local\Temp\f1.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Resource Monitor
Exit code:
0
Version:
10.0.19041.1 (WinBuild.160101.0800)
Modules
Images
c:\users\admin\appdata\local\temp\f1.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\amd64_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.18837_none_fa3b1e3d17594757\comctl32.dll
Total events
13
Read events
13
Write events
0
Delete events
0

Modification events

No data
Executable files
18
Suspicious files
2
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2788f1.exeC:\Users\admin\AppData\Local\Temp\_MEI27882\VCRUNTIME140.dllexecutable
MD5:4585A96CC4EEF6AAFD5E27EA09147DC6
SHA256:A8F950B4357EC12CFCCDDC9094CCA56A3D5244B95E09EA6E9A746489F2D58736
2788f1.exeC:\Users\admin\AppData\Local\Temp\_MEI27882\_decimal.pydexecutable
MD5:65B4AB77D6C6231C145D3E20E7073F51
SHA256:93EB9D1859EDCA1C29594491863BF3D72AF70B9A4240E0D9DD171F668F4F8614
2788f1.exeC:\Users\admin\AppData\Local\Temp\_MEI27882\libffi-8.dllexecutable
MD5:08B000C3D990BC018FCB91A1E175E06E
SHA256:135C772B42BA6353757A4D076CE03DBF792456143B42D25A62066DA46144FECE
2788f1.exeC:\Users\admin\AppData\Local\Temp\_MEI27882\_queue.pydexecutable
MD5:DECDABACA104520549B0F66C136A9DC1
SHA256:9D4880F7D0129B1DE95BECD8EA8BBBF0C044D63E87764D18F9EC00D382E43F84
2788f1.exeC:\Users\admin\AppData\Local\Temp\_MEI27882\_sqlite3.pydexecutable
MD5:EB6313B94292C827A5758EEA82D018D9
SHA256:6B41DFD7D6AC12AFE523D74A68F8BD984A75E438DCF2DAA23A1F934CA02E89DA
2788f1.exeC:\Users\admin\AppData\Local\Temp\_MEI27882\_ssl.pydexecutable
MD5:2089768E25606262921E4424A590FF05
SHA256:3E6E9FC56E1A9FE5EDB39EE03E5D47FA0E3F6ADB17BE1F087DC6F891D3B0BBCA
2788f1.exeC:\Users\admin\AppData\Local\Temp\_MEI27882\libcrypto-1_1.dllexecutable
MD5:DFFCAB08F94E627DE159E5B27326D2FC
SHA256:135B115E77479EEDD908D7A782E004ECE6DD900BB1CA05CC1260D5DD6273EF15
2788f1.exeC:\Users\admin\AppData\Local\Temp\_MEI27882\_hashlib.pydexecutable
MD5:F10D896ED25751EAD72D8B03E404EA36
SHA256:3660B985CA47CA1BBA07DB01458B3153E4E692EE57A8B23CE22F1A5CA18707C3
2788f1.exeC:\Users\admin\AppData\Local\Temp\_MEI27882\blank.aesbinary
MD5:B24BDCA143A4CB78986753463298558D
SHA256:BB685D815D7615BCCACEB5C25379D49F415E2A4963F26BDC699FA320E71C24CB
2788f1.exeC:\Users\admin\AppData\Local\Temp\_MEI27882\libssl-1_1.dllexecutable
MD5:8E8A145E122A593AF7D6CDE06D2BB89F
SHA256:A6A14C1BECCBD4128763E78C3EC588F747640297FFB3CC5604A9728E8EF246B1
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
6
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
324
svchost.exe
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1956
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

No data

Threats

No threats detected
No debug info