| File name: | Anti_DDoS_Guardian_setup_5.0.exe |
| Full analysis: | https://app.any.run/tasks/4a89552a-2e24-4552-a9e5-942752ba95da |
| Verdict: | Malicious activity |
| Analysis date: | October 28, 2019, 22:38:27 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 3429C25534E6C3ABFD59DABC6E9D4B05 |
| SHA1: | 9E4D12D10C9883305C26C2FC798BE7E547189509 |
| SHA256: | 05A3F632AD885030E939C99ED18D43F47FC46B36AEA24DECE5B78763A933BDBA |
| SSDEEP: | 49152:ic/wA+AUomLGFkqA8Gu6fLbl/6jB8rdIJYzQ9jj8rY5QelqnLSKhj0:lUXLGFbARu6fflSGdTE8qlqLxj |
| .exe | | | Win32 Executable Delphi generic (45.2) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (20.9) |
| .exe | | | Win32 Executable (generic) (14.3) |
| .exe | | | Win16/32 Executable Delphi generic (6.6) |
| .exe | | | Generic Win/DOS Executable (6.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2016:04:06 16:39:04+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 66560 |
| InitializedDataSize: | 53760 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x117dc |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 5.0.0.0 |
| ProductVersionNumber: | 5.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | BeeThink Software Research and Development Center, Hundred M |
| FileDescription: | Anti DDoS Guardian Setup |
| FileVersion: | 5.0.0.0 |
| LegalCopyright: | |
| ProductName: | Anti DDoS Guardian |
| ProductVersion: | 5.0.0.0 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 06-Apr-2016 14:39:04 |
| Detected languages: |
|
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | BeeThink Software Research and Development Center, Hundred M |
| FileDescription: | Anti DDoS Guardian Setup |
| FileVersion: | 5.0.0.0 |
| LegalCopyright: | - |
| ProductName: | Anti DDoS Guardian |
| ProductVersion: | 5.0.0.0 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0050 |
| Pages in file: | 0x0002 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x000F |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x001A |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000100 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 8 |
| Time date stamp: | 06-Apr-2016 14:39:04 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x0000F244 | 0x0000F400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.37521 |
.itext | 0x00011000 | 0x00000F64 | 0x00001000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.7322 |
.data | 0x00012000 | 0x00000C88 | 0x00000E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.29672 |
.bss | 0x00013000 | 0x000056BC | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.idata | 0x00019000 | 0x00000E04 | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.59781 |
.tls | 0x0001A000 | 0x00000008 | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rdata | 0x0001B000 | 0x00000018 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.204488 |
.rsrc | 0x0001C000 | 0x0000B200 | 0x0000B200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.14506 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.13965 | 1580 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 3.47151 | 1384 | UNKNOWN | Dutch - Netherlands | RT_ICON |
3 | 3.91708 | 744 | UNKNOWN | Dutch - Netherlands | RT_ICON |
4 | 3.91366 | 2216 | UNKNOWN | Dutch - Netherlands | RT_ICON |
4091 | 2.56031 | 104 | UNKNOWN | UNKNOWN | RT_STRING |
4092 | 3.25287 | 212 | UNKNOWN | UNKNOWN | RT_STRING |
4093 | 3.26919 | 164 | UNKNOWN | UNKNOWN | RT_STRING |
4094 | 3.33268 | 684 | UNKNOWN | UNKNOWN | RT_STRING |
4095 | 3.34579 | 844 | UNKNOWN | UNKNOWN | RT_STRING |
4096 | 3.28057 | 660 | UNKNOWN | UNKNOWN | RT_STRING |
advapi32.dll |
comctl32.dll |
kernel32.dll |
oleaut32.dll |
user32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 792 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 10 Global\{007442b3-0ed3-5537-cf9e-530bd61e875f} Global\{0dccc5af-4827-50c1-2d4f-d377df3a081f} C:\Windows\System32\DriverStore\Temp\{5006b729-b729-5006-09f2-b531415fdc27}\NBlocker.inf C:\Windows\System32\DriverStore\Temp\{5006b729-b729-5006-09f2-b531415fdc27}\nblocker.cat | C:\Windows\system32\rundll32.exe | — | DrvInst.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 940 | "C:\Program Files\Anti DDoS Guardian 5.0\install.exe" a | C:\Program Files\Anti DDoS Guardian 5.0\install.exe | Anti_DDoS_Guardian_setup_5.0.tmp | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1516 | "C:\Program Files\Anti DDoS Guardian 5.0\AntiDDoS.exe" | C:\Program Files\Anti DDoS Guardian 5.0\AntiDDoS.exe | — | Anti_DDoS_Guardian_setup_5.0.tmp | |||||||||||
User: admin Company: BeeThink SoftWare, Inc. Integrity Level: HIGH Description: BeeThink Network Security Tool Exit code: 0 Version: 3, 4, 0, 0 Modules
| |||||||||||||||
| 1896 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2080 | "C:\Program Files\Anti DDoS Guardian 5.0\StopBruteForceService.exe" | C:\Program Files\Anti DDoS Guardian 5.0\StopBruteForceService.exe | — | services.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Exit code: 0 Modules
| |||||||||||||||
| 2116 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{0ad41047-0c5a-3e11-9d91-5a7e5b508168}\NBlocker.inf" "0" "6e6e619ff" "000004D0" "WinSta0\Default" "000002F0" "208" "C:\Program Files\Anti DDoS Guardian 5.0" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2200 | "C:\Users\admin\AppData\Local\Temp\is-PCUJS.tmp\Anti_DDoS_Guardian_setup_5.0.tmp" /SL5="$5012A,2222701,121344,C:\Users\admin\AppData\Local\Temp\Anti_DDoS_Guardian_setup_5.0.exe" /SPAWNWND=$40126 /NOTIFYWND=$4012C | C:\Users\admin\AppData\Local\Temp\is-PCUJS.tmp\Anti_DDoS_Guardian_setup_5.0.tmp | Anti_DDoS_Guardian_setup_5.0.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2240 | "C:\Users\admin\AppData\Local\Temp\is-O0MU2.tmp\Anti_DDoS_Guardian_setup_5.0.tmp" /SL5="$4012C,2222701,121344,C:\Users\admin\AppData\Local\Temp\Anti_DDoS_Guardian_setup_5.0.exe" | C:\Users\admin\AppData\Local\Temp\is-O0MU2.tmp\Anti_DDoS_Guardian_setup_5.0.tmp | — | Anti_DDoS_Guardian_setup_5.0.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2452 | "C:\Program Files\Anti DDoS Guardian 5.0\MiniIPBlocker.exe" | C:\Program Files\Anti DDoS Guardian 5.0\MiniIPBlocker.exe | — | Anti_DDoS_Guardian_setup_5.0.tmp | |||||||||||
User: admin Company: BeeThink SoftWare, Inc. Integrity Level: HIGH Description: Mini IP Blocker Exit code: 0 Version: 1, 0, 0, 1 Modules
| |||||||||||||||
| 2496 | "C:\Program Files\Internet Explorer\iexplore.exe" -nohome | C:\Program Files\Internet Explorer\iexplore.exe | Anti_DDoS_Guardian_setup_5.0.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 1 Version: 8.00.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2200) Anti_DDoS_Guardian_setup_5.0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 98080000964A7D75E08DD501 | |||
| (PID) Process: | (2200) Anti_DDoS_Guardian_setup_5.0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: F80F5A44825BFCE76F8909A7E1A97C18190F2C6B5A1D81C5D3A568FDA5099B37 | |||
| (PID) Process: | (2200) Anti_DDoS_Guardian_setup_5.0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (2200) Anti_DDoS_Guardian_setup_5.0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Program Files\Anti DDoS Guardian 5.0\7zdec.dll | |||
| (PID) Process: | (2200) Anti_DDoS_Guardian_setup_5.0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFilesHash |
Value: EE853E1BE1803C1BDFB1BCA64D5DBE159B49778000261888F553A579C7F35217 | |||
| (PID) Process: | (3412) certutil.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\BDF616ECB5155A54010DD77163D5CFA568740F39 |
| Operation: | write | Name: | Blob |
Value: 030000000100000014000000BDF616ECB5155A54010DD77163D5CFA568740F3920000000010000002E0500003082052A30820412A0030201020210167EAE8B86CE85E0E7E72FA1A0C288E1300D06092A864886F70D0101050500304A310B300906035504061302555331153013060355040A130C5468617774652C20496E632E312430220603550403131B54686177746520436F6465205369676E696E67204341202D204732301E170D3134303831383030303030305A170D3136303831373233353935395A3081B3310B300906035504061302434E310F300D060355040813065368616E7869310E300C06035504071405586927616E313A3038060355040A14314265655468696E6B20536F66747761726520526573656172636820616E6420446576656C6F706D656E742043656E746572310B3009060355040B14024954313A3038060355040314314265655468696E6B20536F66747761726520526573656172636820616E6420446576656C6F706D656E742043656E74657230820122300D06092A864886F70D01010105000382010F003082010A02820101008BE13661D50231D974D8C6A114AE494CAEBD4BBE4C8DEF38B1345172F5AC5092851A2C03C05161A7662F27781D5A54A2E3C80F2DE32FBCD40E698A74AA5BA8F2E43A4D5B3AF23C37D25CFC6EFD0A60AD1D87F61AA1A6090B0D842323A091118A307ED91935333C9B41F4D7584D282ED233CE1B0368247F8C033F7D0FB9D6D1B2FDB5FA8B93D2C9C623CF425EB4BF1BF321B7CB05B1A7F87BCA9917A06F15D53280590C2FD9AE5844A4EABAEC2AC98EBF038D49BF78F127DEDAFBEA03AD8FF92F629A429B42D6D5E454B65132724F9A5B7D6B2C76659DE259A88AC73E7C2877268CDC63DD890DE1704B0A731099D0CC146FD9ED9C01672389C55428F5B75427230203010001A38201A03082019C30090603551D1304023000301F0603551D23041830168014D40D653F7ABD34C6FE47E74C0DC0BDF2DE15AB71301D0603551D0E04160414C7F961FD4B0CA61308846E85F09612601C282A47302B0603551D1F042430223020A01EA01C861A687474703A2F2F74682E73796D63622E636F6D2F74682E63726C300E0603551D0F0101FF040403020780301F0603551D250418301606082B06010505070303060A2B06010401823702011630660603551D20045F305D305B060B6086480186F84501073002304C302306082B06010505070201161768747470733A2F2F642E73796D63622E636F6D2F637073302506082B060105050702023019161768747470733A2F2F642E73796D63622E636F6D2F727061301D0603551D0404163014300E300C060A2B06010401823702011603020780305706082B06010505070101044B3049301F06082B060105050730018613687474703A2F2F74682E73796D63642E636F6D302606082B06010505073002861A687474703A2F2F74682E73796D63622E636F6D2F74682E637274301106096086480186F8420101040403020410300D06092A864886F70D010105050003820101009FD799109F865167250F58628124D88463C0EB253455AEF899A8C25F4937074F18DBC2133446DECDCCFDAB1E03D79AD6D44545F7BD40EE7EE824FECED3AB8FF8AAF8A19AB885D66C3E34C7BBE6AD3844517890FD1B9D49C2E9320591CC2B2FB45E8108A468E3D9059B4AD05E07CD5E1309D6371FF9B37EB6977E901BE9886F34B8655BB52B4A312E2ADF6EA4E59AB1FDDA5395911F5E70E26FB011433FD2584A939F15F35959CFA9498E950D94622ED129A9E38FD3923CE82725D09F715AF0BF3883D5006666F025A69812D160648578222640C2468843EBA84F431997F6714F392393F3DE2FD2FFAD6CD66A59D42794094212C9AAA64D12E4E5EC88F631762A | |||
| (PID) Process: | (3412) certutil.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2200) Anti_DDoS_Guardian_setup_5.0.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | Anti DDoS |
Value: C:\Program Files\Anti DDoS Guardian 5.0\AntiDDoS.exe | |||
| (PID) Process: | (2200) Anti_DDoS_Guardian_setup_5.0.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | MINI IP Blocker |
Value: C:\Program Files\Anti DDoS Guardian 5.0\MiniIPBlocker.exe | |||
| (PID) Process: | (2200) Anti_DDoS_Guardian_setup_5.0.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Anti DDoS Guardian_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 5.5.9 (u) | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2200 | Anti_DDoS_Guardian_setup_5.0.tmp | C:\Program Files\Anti DDoS Guardian 5.0\is-EIL14.tmp | — | |
MD5:— | SHA256:— | |||
| 2200 | Anti_DDoS_Guardian_setup_5.0.tmp | C:\Program Files\Anti DDoS Guardian 5.0\is-3SDIB.tmp | — | |
MD5:— | SHA256:— | |||
| 2200 | Anti_DDoS_Guardian_setup_5.0.tmp | C:\Program Files\Anti DDoS Guardian 5.0\is-OEM3K.tmp | — | |
MD5:— | SHA256:— | |||
| 2200 | Anti_DDoS_Guardian_setup_5.0.tmp | C:\Program Files\Anti DDoS Guardian 5.0\is-EKE29.tmp | — | |
MD5:— | SHA256:— | |||
| 2200 | Anti_DDoS_Guardian_setup_5.0.tmp | C:\Program Files\Anti DDoS Guardian 5.0\is-3LG4Q.tmp | — | |
MD5:— | SHA256:— | |||
| 2200 | Anti_DDoS_Guardian_setup_5.0.tmp | C:\Program Files\Anti DDoS Guardian 5.0\is-J1LVO.tmp | — | |
MD5:— | SHA256:— | |||
| 2200 | Anti_DDoS_Guardian_setup_5.0.tmp | C:\Program Files\Anti DDoS Guardian 5.0\is-CN4DM.tmp | — | |
MD5:— | SHA256:— | |||
| 2200 | Anti_DDoS_Guardian_setup_5.0.tmp | C:\Program Files\Anti DDoS Guardian 5.0\is-PCANJ.tmp | — | |
MD5:— | SHA256:— | |||
| 2200 | Anti_DDoS_Guardian_setup_5.0.tmp | C:\Program Files\Anti DDoS Guardian 5.0\is-SK8UE.tmp | — | |
MD5:— | SHA256:— | |||
| 2200 | Anti_DDoS_Guardian_setup_5.0.tmp | C:\Program Files\Anti DDoS Guardian 5.0\is-8F1AU.tmp | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2588 | iexplore.exe | GET | — | 104.31.69.232:80 | http://www.beethink.com/css/bootstrap.min.css | US | — | — | suspicious |
2588 | iexplore.exe | GET | — | 104.31.69.232:80 | http://www.beethink.com/css/small-business.css | US | — | — | suspicious |
2588 | iexplore.exe | GET | — | 104.31.69.232:80 | http://www.beethink.com/css/heroic-features.css | US | — | — | suspicious |
2588 | iexplore.exe | GET | 200 | 104.31.69.232:80 | http://www.beethink.com/BeeGuardian/StopBruteForce/images/RDP_Tcp_Properties.jpg | US | image | 37.9 Kb | suspicious |
2588 | iexplore.exe | GET | 404 | 104.31.69.232:80 | http://www.beethink.com/favicon.ico | US | html | 2.12 Kb | suspicious |
2588 | iexplore.exe | GET | 200 | 104.31.69.232:80 | http://www.beethink.com/BeeGuardian/StopBruteForce/images/rdp_host_config.jpg | US | image | 37.7 Kb | suspicious |
2588 | iexplore.exe | GET | 200 | 104.31.69.232:80 | http://www.beethink.com/Support_rdp_protection.htm | US | html | 2.11 Kb | suspicious |
2588 | iexplore.exe | GET | 200 | 104.31.69.232:80 | http://www.beethink.com/css/small-business.css | US | text | 335 b | suspicious |
2588 | iexplore.exe | GET | 200 | 104.31.69.232:80 | http://www.beethink.com/css/heroic-features.css | US | text | 309 b | suspicious |
2588 | iexplore.exe | GET | 200 | 104.31.69.232:80 | http://www.beethink.com/js/jquery.js | US | text | 32.4 Kb | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2496 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
2588 | iexplore.exe | 104.31.69.232:80 | www.beethink.com | Cloudflare Inc | US | shared |
2588 | iexplore.exe | 23.111.8.154:443 | oss.maxcdn.com | netDNA | US | unknown |
Domain | IP | Reputation |
|---|---|---|
www.beethink.com |
| suspicious |
www.bing.com |
| whitelisted |
oss.maxcdn.com |
| whitelisted |