File name:

bifit_signer_8.23.exe

Full analysis: https://app.any.run/tasks/7500bd69-4fcb-4af1-a6ce-6c2648231149
Verdict: Malicious activity
Analysis date: July 18, 2023, 11:07:24
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

5904318F8419E708C9E6238963B6A88A

SHA1:

7B8DB59AF938A92FECE34AEEC1CE6FAD3CE75D6E

SHA256:

FF08F85313A23735CDEE6E70AC52D4371726A003FCF58C2BAFE62DA67B9664DE

SSDEEP:

196608:yhyE9AHKQwSEATalF9JSofA4QCFIAH/l5:yhyNHK+a3LfAhcIA/l5

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • bifit_signer_8.23.exe (PID: 3288)
      • BSHControlPanel.exe (PID: 2380)
    • Application was dropped or rewritten from another process

      • BSHControlPanel.exe (PID: 2380)
      • BIFITSignerHost.exe (PID: 3208)
      • BIFITSignerHost.exe (PID: 3652)
    • Actions looks like stealing of personal data

      • bifit_signer_8.23.exe (PID: 3288)
  • SUSPICIOUS

    • Starts application with an unusual extension

      • bifit_signer_8.23.exe (PID: 3288)
    • The process creates files with name similar to system file names

      • bifit_signer_8.23.exe (PID: 3288)
    • Uses WMIC.EXE

      • ns5DCF.tmp (PID: 4048)
    • Executable content was dropped or overwritten

      • bifit_signer_8.23.exe (PID: 3288)
    • Reads the Internet Settings

      • bifit_signer_8.23.exe (PID: 3288)
      • BSHControlPanel.exe (PID: 2380)
      • WMIC.exe (PID: 2388)
    • Application launched itself

      • BIFITSignerHost.exe (PID: 3208)
    • Searches for installed software

      • BSHControlPanel.exe (PID: 2380)
  • INFO

    • Reads the computer name

      • bifit_signer_8.23.exe (PID: 3288)
      • BIFITSignerHost.exe (PID: 3208)
      • BIFITSignerHost.exe (PID: 3652)
      • BSHControlPanel.exe (PID: 2380)
    • The process checks LSA protection

      • bifit_signer_8.23.exe (PID: 3288)
      • WMIC.exe (PID: 2388)
      • BIFITSignerHost.exe (PID: 3652)
      • BIFITSignerHost.exe (PID: 3208)
      • BSHControlPanel.exe (PID: 2380)
    • Checks supported languages

      • bifit_signer_8.23.exe (PID: 3288)
      • ns5CE3.tmp (PID: 3604)
      • ns5DCF.tmp (PID: 4048)
      • BSHControlPanel.exe (PID: 2380)
      • BIFITSignerHost.exe (PID: 3652)
      • BIFITSignerHost.exe (PID: 3208)
    • Creates files or folders in the user directory

      • bifit_signer_8.23.exe (PID: 3288)
      • BIFITSignerHost.exe (PID: 3208)
      • BSHControlPanel.exe (PID: 2380)
    • Create files in a temporary directory

      • WMIC.exe (PID: 2388)
      • bifit_signer_8.23.exe (PID: 3288)
    • Checks proxy server information

      • bifit_signer_8.23.exe (PID: 3288)
      • BSHControlPanel.exe (PID: 2380)
    • Reads the machine GUID from the registry

      • BSHControlPanel.exe (PID: 2380)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

ProductVersion: 8.23
ProductName: BIFIT Signer
LegalCopyright: © 2015-2023 "AO БИФИТ"
FileVersion: 8.23
FileDescription: BIFIT Signer 8.23
CompanyName: BIFIT
CharacterSet: Windows, Cyrillic
LanguageCode: Russian
FileSubtype: -
ObjectFileType: Executable application
FileOS: Win32
FileFlags: (none)
FileFlagsMask: 0x0000
ProductVersionNumber: 0.8.23.0
FileVersionNumber: 0.8.23.0
Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: 6
OSVersion: 4
EntryPoint: 0x35d8
UninitializedDataSize: 16384
InitializedDataSize: 428544
CodeSize: 26112
LinkerVersion: 6
PEType: PE32
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
TimeStamp: 2020:08:01 02:52:49+00:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 01-Aug-2020 02:52:49
Detected languages:
  • English - United States
  • Russian - Russia
CompanyName: BIFIT
FileDescription: BIFIT Signer 8.23
FileVersion: 8.23
LegalCopyright: © 2015-2023 "AO БИФИТ"
ProductName: BIFIT Signer
ProductVersion: 8.23

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000D8

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 01-Aug-2020 02:52:49
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00006572
0x00006600
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.45248
.rdata
0x00008000
0x00001398
0x00001400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.13672
.data
0x0000A000
0x00066378
0x00000600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
4.09411
.ndata
0x00071000
0x001C8000
0x00000000
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
.rsrc
0x00239000
0x00009770
0x00009800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.28572

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.28833
1251
UNKNOWN
English - United States
RT_MANIFEST
2
5.15373
9640
UNKNOWN
English - United States
RT_ICON
3
5.46476
4264
UNKNOWN
English - United States
RT_ICON
4
5.63167
2440
UNKNOWN
English - United States
RT_ICON
5
5.85283
1128
UNKNOWN
English - United States
RT_ICON
102
2.71813
180
UNKNOWN
English - United States
RT_DIALOG
103
2.79808
76
UNKNOWN
English - United States
RT_GROUP_ICON
105
2.73893
514
UNKNOWN
English - United States
RT_DIALOG
106
2.91148
248
UNKNOWN
English - United States
RT_DIALOG
107
2.52183
160
UNKNOWN
English - United States
RT_DIALOG

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.dll
SHELL32.dll
USER32.dll
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
8
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
drop and start start bifit_signer_8.23.exe ns5ce3.tmp no specs ping.exe no specs ns5dcf.tmp no specs wmic.exe no specs bshcontrolpanel.exe no specs bifitsignerhost.exe no specs bifitsignerhost.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2380"C:\Users\admin\AppData\Local\BIFIT\BIFIT Signer Host\BSHControlPanel.exe" --silentC:\Users\admin\AppData\Local\BIFIT\BIFIT Signer Host\BSHControlPanel.exebifit_signer_8.23.exe
User:
admin
Company:
BIFIT
Integrity Level:
MEDIUM
Description:
BIFIT Signer
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\bifit\bifit signer host\bshcontrolpanel.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\dbghelp.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
2388C:\Windows\system32\wbem\wmic /record:'C:\Users\admin\AppData\Local\Temp\nsk5DCE.tmp' path Win32_PingStatus where "Address='signer.bifit.com' and StatusCode=0 and ProtocolAddress='127.0.0.1'"C:\Windows\System32\wbem\WMIC.exens5DCF.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
WMI Commandline Utility
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\wbem\wmic.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\user32.dll
c:\windows\system32\ole32.dll
3208"C:\Users\admin\AppData\Local\BIFIT\BIFIT Signer Host\BIFITSignerHost.exe"C:\Users\admin\AppData\Local\BIFIT\BIFIT Signer Host\BIFITSignerHost.exeBSHControlPanel.exe
User:
admin
Company:
BIFIT
Integrity Level:
MEDIUM
Description:
BIFIT Signer
Exit code:
0
Version:
2.8.23.5
Modules
Images
c:\users\admin\appdata\local\bifit\bifit signer host\bifitsignerhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\usp10.dll
3288"C:\Users\admin\AppData\Local\Temp\bifit_signer_8.23.exe" C:\Users\admin\AppData\Local\Temp\bifit_signer_8.23.exe
explorer.exe
User:
admin
Company:
BIFIT
Integrity Level:
MEDIUM
Description:
BIFIT Signer 8.23
Exit code:
0
Version:
8.23
Modules
Images
c:\users\admin\appdata\local\temp\bifit_signer_8.23.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sechost.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\shell32.dll
3604"C:\Users\admin\AppData\Local\Temp\nsvEC17.tmp\ns5CE3.tmp" ping -n 1 signer.bifit.comC:\Users\admin\AppData\Local\Temp\nsvEC17.tmp\ns5CE3.tmpbifit_signer_8.23.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsvec17.tmp\ns5ce3.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3652"C:\Users\admin\AppData\Local\BIFIT\BIFIT Signer Host\BIFITSignerHost.exe"C:\Users\admin\AppData\Local\BIFIT\BIFIT Signer Host\BIFITSignerHost.exeBIFITSignerHost.exe
User:
admin
Company:
BIFIT
Integrity Level:
MEDIUM
Description:
BIFIT Signer
Exit code:
0
Version:
2.8.23.5
Modules
Images
c:\users\admin\appdata\local\bifit\bifit signer host\bifitsignerhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\shell32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
4020ping -n 1 signer.bifit.comC:\Windows\System32\PING.EXEns5CE3.tmp
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
TCP/IP Ping Command
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ping.exe
c:\windows\system32\kernel32.dll
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\nsi.dll
c:\windows\system32\winnsi.dll
4048"C:\Users\admin\AppData\Local\Temp\nsvEC17.tmp\ns5DCF.tmp" C:\Windows\system32\wbem\wmic /record:'C:\Users\admin\AppData\Local\Temp\nsk5DCE.tmp' path Win32_PingStatus where "Address='signer.bifit.com' and StatusCode=0 and ProtocolAddress='127.0.0.1'"C:\Users\admin\AppData\Local\Temp\nsvEC17.tmp\ns5DCF.tmpbifit_signer_8.23.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
0
Modules
Images
c:\windows\system32\ntdll.dll
c:\windows\system32\kernelbase.dll
c:\users\admin\appdata\local\temp\nsvec17.tmp\ns5dcf.tmp
c:\windows\system32\kernel32.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
Total events
1 556
Read events
1 556
Write events
0
Delete events
0

Modification events

No data
Executable files
18
Suspicious files
3
Text files
18
Unknown types
0

Dropped files

PID
Process
Filename
Type
3288bifit_signer_8.23.exeC:\Users\admin\AppData\Local\BIFIT\BIFIT Signer Host\rtpkcs11ecp.dllexecutable
MD5:E50094D9F7F183874E20C42E57510C36
SHA256:32BDBBEB462FF55254C98980C9283FE95644FB7D0C2A9B1450427AFA9780D7B9
3288bifit_signer_8.23.exeC:\Users\admin\AppData\Local\BIFIT\BIFIT Signer Host\favicon.icoimage
MD5:3A98A05B470DA34BE9B6F1E449001CA7
SHA256:E03E426424706684AC62485B544D576E2A13168B8E794BB94567E333A391774F
3288bifit_signer_8.23.exeC:\Users\admin\AppData\Local\Temp\nsvEC17.tmp\LangDLL.dllexecutable
MD5:AB1DB56369412FE8476FEFFFD11E4CC0
SHA256:6F14C8F01F50A30743DAC68C5AC813451463DFB427EB4E35FCDFE2410E1A913B
3288bifit_signer_8.23.exeC:\Users\admin\AppData\Local\Temp\nsvEC17.tmp\nsDialogs.dllexecutable
MD5:466179E1C8EE8A1FF5E4427DBB6C4A01
SHA256:1E40211AF65923C2F4FD02CE021458A7745D28E2F383835E3015E96575632172
3288bifit_signer_8.23.exeC:\Users\admin\AppData\Local\BIFIT\BIFIT Signer Host\BIFITSigner.dllexecutable
MD5:0628E4D54116D2A54C9725CD7B70A4FE
SHA256:5DD7D7AEFF7E1C33DCC8D1D9A9DAA9D32DC889F2770D668F9244AE232C0980DA
3288bifit_signer_8.23.exeC:\Users\admin\AppData\Local\BIFIT\BIFIT Signer Host\jckt2.txttext
MD5:88BF92AE0F3E849D149FF73897E276E9
SHA256:ABD975DC8C845A4589F0AD717BAB2E1D4D1BB1E61F8E5D0DC6768B07BF2EEDA1
3288bifit_signer_8.23.exeC:\Users\admin\AppData\Local\BIFIT\BIFIT Signer Host\NOTICE.txttext
MD5:1308906409E296D07DD1278EDFFFE2FE
SHA256:B30CDC8D570840AE49FA504C3FB62D999F7FEF528480D795E258B2B283DB5A58
3288bifit_signer_8.23.exeC:\Users\admin\AppData\Local\BIFIT\BIFIT Signer Host\fix_domain.battext
MD5:07D557DB2F41EBC39E4C99130F92777C
SHA256:D19C02C4BE2ED65786409E17A42FA9622A561759CFB3F94D5D3A6ED9A0121F0F
3288bifit_signer_8.23.exeC:\Users\admin\AppData\Local\Temp\nsvEC17.tmp\System.dllexecutable
MD5:0D7AD4F45DC6F5AA87F606D0331C6901
SHA256:3EB38AE99653A7DBC724132EE240F6E5C4AF4BFE7C01D31D23FAF373F9F2EACA
3288bifit_signer_8.23.exeC:\Users\admin\AppData\Local\BIFIT\BIFIT Signer Host\nd.dllexecutable
MD5:A994DDE8FF051D8B0DAE8A023116FB7C
SHA256:C00053E6CA3A9A7C1B09451181661774BBCFF70F86FC869FCA5B3856B94BF241
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
1
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
2640
svchost.exe
239.255.255.250:1900
whitelisted

DNS requests

Domain
IP
Reputation
signer.bifit.com
  • 127.0.0.1
unknown

Threats

No threats detected
No debug info