File 3b1e4b18ed054552_mmgbmoih.exe

Size 69.0KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 90688b25d934184191c2ddb885e05e02
SHA1 d68fcfb7d2becac8989fec8963451ab777b4489b
SHA256 3b1e4b18ed0545528b2b3588204e8c865eead548e8acc8f04801ee9a0bac6d06
SHA512
c1c26216ebae8bbb356fe8c81ca0354d3f0ead8d4f56cb9b6ff4fdad1a7853f4fd7b8a266c944c7222956abbc46d16dcf35a8698f78194f6d48f6f40b3440ae5
CRC32 20EA4EBF
ssdeep None
Yara
  • screenshot - Take screenshot
  • win_mutex - Create or check mutex
  • win_registry - Affect system registries
  • win_files_operation - Affect private profile

Score

This file is very suspicious, with a score of 9.9 out of 10!

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Autosubmit

Parent_Task_ID:6149063

Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE March 25, 2025, 6:53 p.m. March 25, 2025, 7:03 p.m. 578 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log


        

Cuckoo Log


        

Signatures

Yara rules detected for file (4 events)
description Take screenshot rule screenshot
description Create or check mutex rule win_mutex
description Affect system registries rule win_registry
description Affect private profile rule win_files_operation
The executable contains unknown PE section names indicative of a packer (could be a false positive) (2 events)
section .fldo
section .l1
Creates executable files on the filesystem (50 out of 1544 events)
file C:\Windows\System32\Hkpgll32.exe
file C:\Windows\System32\Kbdqfnkg.dll
file C:\Windows\System32\Chpgleeh.exe
file C:\Windows\System32\Pjgiihal.dll
file C:\Windows\System32\Noendjlf.exe
file C:\Windows\System32\Qdpnpphc.exe
file C:\Windows\System32\Nbkphhla.dll
file C:\Windows\System32\Dbmembhk.dll
file C:\Windows\System32\Ocijgp32.dll
file C:\Windows\System32\Bjlpigmk.dll
file C:\Windows\System32\Kmajdh32.dll
file C:\Windows\System32\Qpjbihbb.exe
file C:\Windows\System32\Ckdldb32.exe
file C:\Windows\System32\Njdenl32.exe
file C:\Windows\System32\Fgbcbbbc.dll
file C:\Windows\System32\Kacjkg32.dll
file C:\Windows\System32\Ncjoef32.dll
file C:\Windows\System32\Bgffcjol.exe
file C:\Windows\System32\Ohmnekgo.exe
file C:\Windows\System32\Oenganfh.dll
file C:\Windows\System32\Pfgnaiml.dll
file C:\Windows\System32\Nqomeili.exe
file C:\Windows\System32\Njkdohkh.exe
file C:\Windows\System32\Loeolnca.dll
file C:\Windows\System32\Fmdmlbcf.dll
file C:\Windows\System32\Bcqmnfil.dll
file C:\Windows\System32\Nakanh32.exe
file C:\Windows\System32\Pndfmh32.exe
file C:\Windows\System32\Ipnchbfl.dll
file C:\Windows\System32\Hckkghji.exe
file C:\Windows\System32\Edpmclqc.exe
file C:\Windows\System32\Keficg32.exe
file C:\Windows\System32\Fjdlal32.dll
file C:\Windows\System32\Ddpcma32.exe
file C:\Windows\System32\Fcnpjqce.dll
file C:\Windows\System32\Iecfml32.dll
file C:\Windows\System32\Mfgjaddk.dll
file C:\Windows\System32\Opcjjq32.dll
file C:\Windows\System32\Cllmkjfi.dll
file C:\Windows\System32\Calhfqhc.exe
file C:\Windows\System32\Pffkjfkb.dll
file C:\Windows\System32\Oalcmj32.dll
file C:\Windows\System32\Ejadmkce.dll
file C:\Windows\System32\Clglio32.exe
file C:\Windows\System32\Flmdgo32.dll
file C:\Windows\System32\Hbmbil32.exe
file C:\Windows\System32\Kiepna32.exe
file C:\Windows\System32\Qdmhqg32.dll
file C:\Windows\System32\Midmdb32.exe
file C:\Windows\System32\Onpcfe32.exe
The binary likely contains encrypted or compressed data indicative of a packer (2 events)
section {u'size_of_data': u'0x00007f6c', u'virtual_address': u'0x00001000', u'entropy': 6.985526741742674, u'name': u'.rsrc', u'virtual_size': u'0x00007f6c'} entropy 6.98552674174 description A section with a high entropy has been found
entropy 0.475676621559 description Overall entropy of this PE file is high
Installs itself for autorun at Windows startup (50 out of 772 events)
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
File has been identified by 13 AntiVirus engine on IRMA as malicious (13 events)
G Data Antivirus (Windows) Virus: Dropped:Backdoor.Padodor.BJ (Engine A), Win32.Trojan.PSE.11RRK8R (Engine B)
Avast Core Security (Linux) Win32:TrojanX-gen [Trj]
C4S ClamAV (Linux) Win.Trojan.Crypted-30
Trellix (Linux) Trojan-FVOJ
WithSecure (Linux) Trojan.TR/Crypt.ZPACK.Gen2
eScan Antivirus (Linux) Dropped:Backdoor.Padodor.BJ(DB)
ESET Security (Windows) a variant of Win32/Padodor.NAX trojan
Sophos Anti-Virus (Linux) Troj/Agent-BGRP
DrWeb Antivirus (Linux) BackDoor.HangUp.43791
ClamAV (Linux) Win.Trojan.Crypted-30
Bitdefender Antivirus (Linux) Dropped:Backdoor.Padodor.BJ
Kaspersky Standard (Windows) Trojan-Proxy.Win32.Qukart.gen
Emsisoft Commandline Scanner (Windows) Dropped:Backdoor.Padodor.BJ (B)
Screenshots
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.