| File name: | Patch.exe |
| Full analysis: | https://app.any.run/tasks/34b51b7e-3b2c-49c6-a1bb-31fd53356009 |
| Verdict: | Malicious activity |
| Analysis date: | February 10, 2024, 14:18:16 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | E434437BBCFA95A0E809F2AB2D8D4B05 |
| SHA1: | 304774B335B987979157C9C69B17CAF6AC9DE059 |
| SHA256: | 05732B23340450E6E58FFE3964B0C7581987B8FBE69999E2E772918BABAB38F6 |
| SSDEEP: | 49152:hGLy0IzO9w0PdKaNjlU1O985ypQb1YdirUu8NuzxzmlkZPDku2HB6zCIrA6hPQRO:hH0iOW0PQaJlU15KWVcszSmQ/SxoRKQg |
| .dll | | | Win32 Dynamic Link Library (generic) (38.3) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (26.2) |
| .exe | | | Win16/32 Executable Delphi generic (12) |
| .exe | | | Generic Win/DOS Executable (11.6) |
| .exe | | | DOS Executable Generic (11.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:11:08 18:33:43+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 897024 |
| InitializedDataSize: | 45056 |
| UninitializedDataSize: | 1572864 |
| EntryPoint: | 0x25b380 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.4.0.1 |
| ProductVersionNumber: | 2.4.0.1 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | RadiXX11 |
| FileDescription: | Icecream Apps Patch |
| FileVersion: | 2.4.0.1 |
| InternalName: | Patch.exe |
| LegalCopyright: | © RadiXX11 |
| LegalTrademarks: | - |
| OriginalFileName: | Patch.exe |
| ProductName: | Icecream Apps Patch |
| ProductVersion: | 2.4.0.0 |
| Comments: | By RadiXX11 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3668 | "C:\Users\admin\AppData\Local\Temp\Patch.exe" | C:\Users\admin\AppData\Local\Temp\Patch.exe | — | explorer.exe | |||||||||||
User: admin Company: RadiXX11 Integrity Level: MEDIUM Description: Icecream Apps Patch Exit code: 3221226540 Version: 2.4.0.1 Modules
| |||||||||||||||
| 3772 | "C:\Users\admin\AppData\Local\Temp\Patch.exe" | C:\Users\admin\AppData\Local\Temp\Patch.exe | explorer.exe | ||||||||||||
User: admin Company: RadiXX11 Integrity Level: HIGH Description: Icecream Apps Patch Exit code: 0 Version: 2.4.0.1 Modules
| |||||||||||||||
| (PID) Process: | (3772) Patch.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |