| File name: | ВАСЯ диагност 1.1.exe |
| Full analysis: | https://app.any.run/tasks/818bea28-33b4-48eb-8e61-eb81c7cc57b2 |
| Verdict: | Malicious activity |
| Analysis date: | August 12, 2022, 16:13:36 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 84EB8B45ADF54CD9F364C347421FCE75 |
| SHA1: | 84075EFFD993E3450BDB898ADC6943DFBDC87599 |
| SHA256: | 03A3EDB161597BDA64D7A734AF85F936D8961A7DB151CC14C9D72A482281593C |
| SSDEEP: | 196608:QUHkek8H+/rRhBy9K88FR9O/fuFyj1R4Yqdt:9Hkekj/VhAy9O/fuchRqdt |
| .exe | | | InstallShield setup (36.8) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (26.6) |
| .exe | | | Win64 Executable (generic) (23.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (5.6) |
| .exe | | | Win32 Executable (generic) (3.8) |
| ProductVersion: | 1.1.0 |
|---|---|
| ProductName: | ВАСЯ диагност |
| OriginalFileName: | vd_1.1.0_setup.exe |
| LegalCopyright: | Copyright (C) Car2diag |
| InternalName: | vd_1.1.0_setup |
| FileVersion: | 1.1.0 |
| FileDescription: | Эта база данных содержит все необходимое для установки ВАСЯ диагност. |
| CompanyName: | Car2diag |
| CharacterSet: | Unicode |
| LanguageCode: | Russian |
| FileSubtype: | - |
| ObjectFileType: | Dynamic link library |
| FileOS: | Win32 |
| FileFlags: | Debug |
| FileFlagsMask: | 0x003f |
| ProductVersionNumber: | 1.1.0.0 |
| FileVersionNumber: | 1.1.0.0 |
| Subsystem: | Windows GUI |
| SubsystemVersion: | 5 |
| ImageVersion: | - |
| OSVersion: | 5 |
| EntryPoint: | 0x993d9 |
| UninitializedDataSize: | - |
| InitializedDataSize: | 382464 |
| CodeSize: | 812544 |
| LinkerVersion: | 9 |
| PEType: | PE32 |
| TimeStamp: | 2011:08:16 11:35:51+02:00 |
| MachineType: | Intel 386 or later, and compatibles |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 16-Aug-2011 09:35:51 |
| Detected languages: |
|
| Debug artifacts: |
|
| CompanyName: | Car2diag |
| FileDescription: | Эта база данных содержит все необходимое для установки ВАСЯ диагност. |
| FileVersion: | 1.1.0 |
| InternalName: | vd_1.1.0_setup |
| LegalCopyright: | Copyright (C) Car2diag |
| OriginalFileName: | vd_1.1.0_setup.exe |
| ProductName: | ВАСЯ диагност |
| ProductVersion: | 1.1.0 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000F8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 16-Aug-2011 09:35:51 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x000C653E | 0x000C6600 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.62726 |
.rdata | 0x000C8000 | 0x00030CB2 | 0x00030E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.4147 |
.data | 0x000F9000 | 0x00008EC4 | 0x00002E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.22785 |
.rsrc | 0x00102000 | 0x000163BC | 0x00016400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.53486 |
.reloc | 0x00119000 | 0x00013574 | 0x00013600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 5.12346 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.22953 | 845 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 3.08438 | 744 | Latin 1 / Western European | Russian - Russia | RT_ICON |
3 | 3.20315 | 488 | Latin 1 / Western European | Russian - Russia | RT_ICON |
4 | 3.08623 | 296 | Latin 1 / Western European | Russian - Russia | RT_ICON |
5 | 5.59298 | 3752 | Latin 1 / Western European | Russian - Russia | RT_ICON |
6 | 6.02092 | 2216 | Latin 1 / Western European | Russian - Russia | RT_ICON |
7 | 6.00379 | 1736 | Latin 1 / Western European | Russian - Russia | RT_ICON |
8 | 4.59129 | 1384 | Latin 1 / Western European | Russian - Russia | RT_ICON |
9 | 3.96518 | 1114 | Latin 1 / Western European | Russian - Russia | RT_STRING |
10 | 4.22341 | 2032 | Latin 1 / Western European | Russian - Russia | RT_STRING |
ADVAPI32.dll |
COMCTL32.dll |
COMDLG32.dll |
GDI32.dll |
KERNEL32.dll |
MSIMG32.dll |
NETAPI32.dll |
OLEAUT32.dll |
SHELL32.dll |
SHLWAPI.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 740 | C:\Windows\system32\MsiExec.exe -Embedding D98538F8FC31A4F55327D05649460571 C | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 900 | C:\Windows\system32\MsiExec.exe -Embedding A00FE99FDBDC0E8C345EC303F489A425 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1976 | "C:\Users\admin\AppData\Local\Temp\ВАСЯ диагност 1.1.exe" | C:\Users\admin\AppData\Local\Temp\ВАСЯ диагност 1.1.exe | Explorer.EXE | ||||||||||||
User: admin Company: Car2diag Integrity Level: MEDIUM Description: Эта база данных содержит все необходимое для установки ВАСЯ диагност. Exit code: 0 Version: 1.1.0 Modules
| |||||||||||||||
| 3052 | "C:\Program Files\ВАСЯ диагност\1.1.0\Driver\CDM20814_Setup.exe" | C:\Program Files\ВАСЯ диагност\1.1.0\Driver\CDM20814_Setup.exe | — | MsiExec.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 3148 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3404 | "C:\Users\admin\AppData\Local\Temp\ВАСЯ диагност 1.1.exe" /i "C:\Users\admin\AppData\Roaming\Car2diag\ВАСЯ диагност\install\5359E47\ВАСЯ.msi" EXECUTEACTION="INSTALL" SECONDSEQUENCE="1" CLIENTPROCESSID="4012" ADDLOCAL="MainFeature" ACTION="INSTALL" CLIENTUILEVEL="0" INSTALLLEVEL="1000" PRIMARYFOLDER="APPDIR" ROOTDRIVE="C:\" AI_SETUPEXEPATH="C:\Users\admin\AppData\Local\Temp\ВАСЯ диагност 1.1.exe" SETUPEXEDIR="C:\Users\admin\AppData\Local\Temp\" TARGETDIR="C:\" APPDIR="C:\Program Files\ВАСЯ диагност\1.1.0\" SHORTCUTDIR="C:\ProgramData\Microsoft\Windows\Start Menu\Programs\ВАСЯ диагност 1.1.0\" | C:\Users\admin\AppData\Local\Temp\ВАСЯ диагност 1.1.exe | ВАСЯ диагност 1.1.exe | ||||||||||||
User: admin Company: Car2diag Integrity Level: HIGH Description: Эта база данных содержит все необходимое для установки ВАСЯ диагност. Exit code: 0 Version: 1.1.0 Modules
| |||||||||||||||
| 3848 | "C:\Program Files\ВАСЯ диагност\1.1.0\Driver\CDM20814_Setup.exe" | C:\Program Files\ВАСЯ диагност\1.1.0\Driver\CDM20814_Setup.exe | MsiExec.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 2 Modules
| |||||||||||||||
| 4012 | /i "C:\Users\admin\AppData\Roaming\Car2diag\ВАСЯ диагност\install\5359E47\ВАСЯ.msi" AI_SETUPEXEPATH="C:\Users\admin\AppData\Local\Temp\ВАСЯ диагност 1.1.exe" SETUPEXEDIR="C:\Users\admin\AppData\Local\Temp\" | C:\Users\admin\AppData\Local\Temp\ВАСЯ диагност 1.1.exe | ВАСЯ диагност 1.1.exe | ||||||||||||
User: admin Company: Car2diag Integrity Level: MEDIUM Description: Эта база данных содержит все необходимое для установки ВАСЯ диагност. Exit code: 0 Version: 1.1.0 Modules
| |||||||||||||||
| (PID) Process: | (4012) ВАСЯ диагност 1.1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (4012) ВАСЯ диагност 1.1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (4012) ВАСЯ диагност 1.1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (4012) ВАСЯ диагност 1.1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3148) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 4C0C0000D65C2E9B66AED801 | |||
| (PID) Process: | (3148) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: 2F547943331CFE1FA6A05D410996D72D067BDA827861EE19E61289965C5EAC1D | |||
| (PID) Process: | (3148) msiexec.exe | Key: | HKEY_USERS\S-1-5-21-1302019708-1500728564-335382590-1000\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (3148) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\InProgress |
| Operation: | write | Name: | (default) |
Value: C:\Windows\Installer\e829a.ipi | |||
| (PID) Process: | (3148) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Folders |
| Operation: | write | Name: | C:\Config.Msi\ |
Value: | |||
| (PID) Process: | (3148) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Installer\Rollback\Scripts |
| Operation: | write | Name: | C:\Config.Msi\e829b.rbs |
Value: 30977647 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1976 | ВАСЯ диагност 1.1.exe | C:\Users\admin\AppData\Roaming\Car2diag\ВАСЯ диагност\install\5359E47\LCode.exe | executable | |
MD5:8739BF76E229F3C5729EF682790C08B4 | SHA256:AF3E275B652DF036D4C12DC243097E93EF333E8F4DCDAB734CFB697136D6FADD | |||
| 1976 | ВАСЯ диагност 1.1.exe | C:\Users\admin\AppData\Roaming\Car2diag\ВАСЯ диагност\install\5359E47\Driver\CDM20814_Setup.exe | executable | |
MD5:080C9F252D15D67540C7F82173D5A135 | SHA256:35F4B0FB91145D56BDED0E71A2EAF8D713C3676971F79BC3A7201333D951DFB7 | |||
| 1976 | ВАСЯ диагност 1.1.exe | C:\Users\admin\AppData\Roaming\Car2diag\ВАСЯ диагност\install\5359E47\Labels\LabelVer.txt | text | |
MD5:1848E47B498F59C8ED4CFC4F1DAF454A | SHA256:B4AA1DCA3E768E547FF8E20D6E803E86855F0CF1A3AD16DB734E619FAF155FE1 | |||
| 1976 | ВАСЯ диагност 1.1.exe | C:\Users\admin\AppData\Roaming\Car2diag\ВАСЯ диагност\install\5359E47\Debug\ReadMe.txt | text | |
MD5:4A329D42AB14E1FD61014B5FB050C485 | SHA256:9B32937F7CE4E53FE1FAC78293CE4FA34FEFE3AD698F663A6A764699C363FD80 | |||
| 1976 | ВАСЯ диагност 1.1.exe | C:\Users\admin\AppData\Roaming\Car2diag\ВАСЯ диагност\install\5359E47\vd.exe.manifest | xml | |
MD5:26A7C7C71924B6EBE2201FF0A4E0E821 | SHA256:3C3A3AC34E4EA4600C607C0CF28FE63054C38A34B8D5EC599A5321D2077BF873 | |||
| 1976 | ВАСЯ диагност 1.1.exe | C:\Users\admin\AppData\Roaming\Car2diag\ВАСЯ диагност\install\5359E47\AutoScan.txt | text | |
MD5:212F36431702AD0C3FFFC33F50B2B8F1 | SHA256:1DACA662E49C44FC72E78E1986CE18A3EF03D6BD36C59165A19D04F862F93F97 | |||
| 1976 | ВАСЯ диагност 1.1.exe | C:\Users\admin\AppData\Roaming\Car2diag\ВАСЯ диагност\install\5359E47\LCode.ini | text | |
MD5:91A94C7D3811C24D42E5C6E6893B28CC | SHA256:08A18FAFC251B88A90BB106F60C5FA7C69CFD0EC00ABA094579FAD533341F2B7 | |||
| 1976 | ВАСЯ диагност 1.1.exe | C:\Users\admin\AppData\Roaming\Car2diag\ВАСЯ диагност\install\5359E47\Driver\ftd2xx.h | text | |
MD5:30C72676B95D747E80C54F096DD231BB | SHA256:90432B8FB114EF0AD4519588172C60D9ABFA477E4A68ABDE05A37E9052A6C338 | |||
| 1976 | ВАСЯ диагност 1.1.exe | C:\Users\admin\AppData\Roaming\Car2diag\ВАСЯ диагност\install\5359E47\Driver\amd64\ftd2xx64.dll | executable | |
MD5:04E2D6F40D388DD2324CF574A604B842 | SHA256:27005B9ECBC9863A5BA9174BDB0A449B5868814FA1D21B2760C29345168D95FA | |||
| 1976 | ВАСЯ диагност 1.1.exe | C:\Users\admin\AppData\Roaming\Car2diag\ВАСЯ диагност\install\5359E47\VCScope.exe | executable | |
MD5:AD9FA79452329C6EE94174E06A97CE41 | SHA256:CF7D21EAAB97895A1D8D2B7C46E6CBF129467DB7DACF0969A6C92BD07E86A3A6 | |||