File 75cc00067e0ccf7c_mddnda32.exe

Size 56.0KB
Type PE32 executable (GUI) Intel 80386, for MS Windows
MD5 ee83d912a7d5b1025764fa353d1c75d6
SHA1 3601956aa25faaad7daabc4d48f0e97312530f53
SHA256 75cc00067e0ccf7c5882324a7bfa71c593049cb1479db314e94d5af4f1b8a97e
SHA512
25a59cb84c0f313b975b4919dc374eace9b63c0759baecce6491082398503ab0103652efa78a59d1c359353998727db566debae38d2c8bb8c7f3da640d6d54d4
CRC32 FB4EFB5D
ssdeep None
Yara
  • win_mutex - Create or check mutex
  • win_registry - Affect system registries
  • win_files_operation - Affect private profile

Score

This file is very suspicious, with a score of 10.0 out of 10!

Please notice: The scoring system is currently still in development and should be considered an alpha feature.


Autosubmit

Parent_Task_ID:7316631

Feedback

Expecting different results? Send us this analysis and we will inspect it. Click here

Information on Execution

Analysis
Category Started Completed Duration Routing Logs
FILE Jan. 18, 2026, 11:42 a.m. Jan. 18, 2026, 11:47 a.m. 341 seconds internet Show Analyzer Log
Show Cuckoo Log

Analyzer Log


        

Cuckoo Log


        

Signatures

Yara rules detected for file (3 events)
description Create or check mutex rule win_mutex
description Affect system registries rule win_registry
description Affect private profile rule win_files_operation
The executable contains unknown PE section names indicative of a packer (could be a false positive) (2 events)
section .gfcd
section .l1
One or more processes crashed (1 event)
Time & API Arguments Status Return Repeated

__exception__

stacktrace:
RtlInitializeExceptionChain+0x63 RtlAllocateActivationContextStack-0xa5 ntdll+0x39f72 @ 0x77e59f72
RtlInitializeExceptionChain+0x36 RtlAllocateActivationContextStack-0xd2 ntdll+0x39f45 @ 0x77e59f45

exception.instruction_r: 31 08 90 90 90 40 90 90 90 90 90 90 90 90 90 90
exception.symbol: dkeobc32+0x31027
exception.instruction: xor dword ptr [eax], ecx
exception.module: Dkeobc32.exe
exception.exception_code: 0xc0000005
exception.offset: 200743
exception.address: 0x431027
registers.esp: 1638252
registers.edi: 0
registers.eax: 4395005
registers.ebp: 1638292
registers.edx: 4395010
registers.ebx: 4231516
registers.esi: 0
registers.ecx: 1511795429
1 0 0
Creates executable files on the filesystem (50 out of 804 events)
file C:\Windows\System32\Enpdbq32.dll
file C:\Windows\System32\Mecmhdnf.dll
file C:\Windows\System32\Lmigbpbb.exe
file C:\Windows\System32\Jheelc32.dll
file C:\Windows\System32\Aaodcl32.dll
file C:\Windows\System32\Ihacngng.dll
file C:\Windows\System32\Cpbodlaq.dll
file C:\Windows\System32\Imkencjm.dll
file C:\Windows\System32\Mihbqn32.dll
file C:\Windows\System32\Jfcbom32.exe
file C:\Windows\System32\Hnlmhm32.dll
file C:\Windows\System32\Pqlpjhkp.dll
file C:\Windows\System32\Lkhmcpdh.exe
file C:\Windows\System32\Hafllplm.dll
file C:\Windows\System32\Mgkjmg32.exe
file C:\Windows\System32\Akbeqf32.exe
file C:\Windows\System32\Ajdmoe32.dll
file C:\Windows\System32\Jdnfen32.dll
file C:\Windows\System32\Eomkno32.dll
file C:\Windows\System32\Nhfaakai.exe
file C:\Windows\System32\Bdeciach.dll
file C:\Windows\System32\Kgkaamff.exe
file C:\Windows\System32\Fjlpgd32.exe
file C:\Windows\System32\Loeopfhm.exe
file C:\Windows\System32\Bkbnia32.exe
file C:\Windows\System32\Cjaeieai.exe
file C:\Windows\System32\Imnaaa32.exe
file C:\Windows\System32\Dklclgia.exe
file C:\Windows\System32\Copdmd32.dll
file C:\Windows\System32\Micjgipe.exe
file C:\Windows\System32\Anlolh32.exe
file C:\Windows\System32\Lkjnicmp.dll
file C:\Windows\System32\Feaokp32.dll
file C:\Windows\System32\Gcdoci32.exe
file C:\Windows\System32\Fbmjpn32.exe
file C:\Windows\System32\Inhgld32.dll
file C:\Windows\System32\Imjhfajn.exe
file C:\Windows\System32\Eijkopjo.dll
file C:\Windows\System32\Mplakh32.exe
file C:\Windows\System32\Eflomdie.exe
file C:\Windows\System32\Gqddel32.exe
file C:\Windows\System32\Pineei32.exe
file C:\Windows\System32\Qmcndonn.exe
file C:\Windows\System32\Bmngegpe.exe
file C:\Windows\System32\Ofbmjm32.dll
file C:\Windows\System32\Qboafahk.dll
file C:\Windows\System32\Keoolocb.dll
file C:\Windows\System32\Hehfno32.dll
file C:\Windows\System32\Gjfimf32.exe
file C:\Windows\System32\Ngjmilhg.exe
The binary likely contains encrypted or compressed data indicative of a packer (2 events)
section {u'size_of_data': u'0x0000815c', u'virtual_address': u'0x00001000', u'entropy': 7.189635776972097, u'name': u'.text', u'virtual_size': u'0x0000815c'} entropy 7.18963577697 description A section with a high entropy has been found
entropy 0.598972652293 description Overall entropy of this PE file is high
Installs itself for autorun at Windows startup (50 out of 402 events)
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
reg_key HKEY_LOCAL_MACHINE\SOFTWARE\Wow6432Node\Microsoft\Windows\CurrentVersion\ShellServiceObjectDelayLoad\Web Event Logger reg_value {79FEACFF-FFCE-815E-A900-316290B5B738}
File has been identified by 13 AntiVirus engine on IRMA as malicious (13 events)
G Data Antivirus (Windows) Virus: Generic.Dacic.1.Backdoor.Hangup.A.4917A72A (Engine A), Win32.Trojan.PSE.11RRK8R (Engine B)
Avast Core Security (Linux) Win32:Qukart-AO [Trj]
C4S ClamAV (Linux) Win.Dropper.Berbew-9106192-0
Trellix (Linux) Generic Malware.bj trojan
WithSecure (Linux) Trojan.TR/Crypt.XDR.Gen
eScan Antivirus (Linux) Generic.Dacic.1.Backdoor.Hangup.A.4917A72A(DB)
ESET Security (Windows) a variant of Win32/Padodor.NAX trojan
Sophos Anti-Virus (Linux) Troj/Agent-BGRP
DrWeb Antivirus (Linux) BackDoor.HangUp.43784
ClamAV (Linux) Win.Dropper.Berbew-9106192-0
Bitdefender Antivirus (Linux) Generic.Dacic.1.Backdoor.Hangup.A.4917A72A
Kaspersky Standard (Windows) Trojan-Proxy.Win32.Qukart.vjh
Emsisoft Commandline Scanner (Windows) Generic.Dacic.1.Backdoor.Hangup.A.4917A72A (B)
Screenshots
Name Response Post-Analysis Lookup
No hosts contacted.
IP Address Status Action VT Location
No hosts contacted.
Cuckoo

We're processing your submission... This could take a few seconds.