| File name: | Eraser 6.2.0.2993.exe |
| Full analysis: | https://app.any.run/tasks/b4b16264-ca9f-44c9-b38b-0bf1c9215ccb |
| Verdict: | Malicious activity |
| Analysis date: | August 21, 2023, 12:42:20 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | CCC33A97215D0F681F0A93E9C2CBEA21 |
| SHA1: | 4264B1E46B1F4D0E98659C8167994197A87F6A11 |
| SHA256: | 062CCB4E9E6F90D3E5B0DF23A4C85C65690A1B527A70015C914E17468FC74BBC |
| SSDEEP: | 196608:4LP77AnQvG91X+fOqHi2z6/o7W7D8Jsj/7dPV7MgsKXLB6:4L/UH2fnz6Q7W7oO//AgsKXLw |
| .exe | | | Win64 Executable (generic) (64.6) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) |
| .exe | | | Win32 Executable (generic) (10.5) |
| .exe | | | Generic Win/DOS Executable (4.6) |
| .exe | | | DOS Executable Generic (4.6) |
| ProductVersion: | 6.2.0.2993 |
|---|---|
| OriginalFileName: | Eraser Setup Bootstrapper |
| LegalCopyright: | Copyright © 2008-2021 The Eraser Project |
| InternalName: | Eraser Setup Bootstrapper |
| FileVersion: | 6.2.0.2993 |
| FileDescription: | Eraser Setup Bootstrapper |
| CompanyName: | The Eraser Project |
| Comments: | Eraser Setup Bootstrapper |
| CharacterSet: | Unicode |
| LanguageCode: | English (U.S.) |
| FileSubtype: | - |
| ObjectFileType: | Executable application |
| FileOS: | Win32 |
| FileFlags: | (none) |
| FileFlagsMask: | 0x0017 |
| ProductVersionNumber: | 6.2.0.2993 |
| FileVersionNumber: | 6.2.0.2993 |
| Subsystem: | Windows GUI |
| SubsystemVersion: | 6 |
| ImageVersion: | - |
| OSVersion: | 6 |
| EntryPoint: | 0xcf70 |
| UninitializedDataSize: | - |
| InitializedDataSize: | 8646144 |
| CodeSize: | 99840 |
| LinkerVersion: | 14.29 |
| PEType: | PE32 |
| ImageFileCharacteristics: | Executable, 32-bit |
| TimeStamp: | 2021:09:25 17:24:52+00:00 |
| MachineType: | Intel 386 or later, and compatibles |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 25-Sep-2021 17:24:52 |
| Detected languages: |
|
| Comments: | Eraser Setup Bootstrapper |
| CompanyName: | The Eraser Project |
| FileDescription: | Eraser Setup Bootstrapper |
| FileVersion: | 6.2.0.2993 |
| InternalName: | Eraser Setup Bootstrapper |
| LegalCopyright: | Copyright © 2008-2021 The Eraser Project |
| OriginalFilename: | Eraser Setup Bootstrapper |
| ProductVersion: | 6.2.0.2993 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000110 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 25-Sep-2021 17:24:52 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x0001857B | 0x00018600 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.61442 |
.rdata | 0x0001A000 | 0x0000ABF6 | 0x0000AC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.60032 |
.data | 0x00025000 | 0x000039C0 | 0x00000C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.39904 |
.rsrc | 0x00029000 | 0x00831F0C | 0x00832000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.99983 |
.reloc | 0x0085B000 | 0x00001500 | 0x00001600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.49289 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.11909 | 608 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 4.4813 | 2216 | Latin 1 / Western European | English - United States | RT_ICON |
3 | 2.28449 | 1384 | Latin 1 / Western European | English - United States | RT_ICON |
4 | 7.97982 | 34269 | Latin 1 / Western European | English - United States | RT_ICON |
5 | 5.13976 | 9640 | Latin 1 / Western European | English - United States | RT_ICON |
6 | 5.09265 | 4264 | Latin 1 / Western European | English - United States | RT_ICON |
7 | 5.11893 | 1128 | Latin 1 / Western European | English - United States | RT_ICON |
100 | 2.71858 | 104 | Latin 1 / Western European | English - United States | RT_GROUP_ICON |
101 | 7.99998 | 8534259 | Latin 1 / Western European | Process Default Language | RT_RCDATA |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
SHELL32.dll |
USER32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 996 | "C:\Users\admin\Desktop\Eraser 6.2.0.2993.exe" | C:\Users\admin\Desktop\Eraser 6.2.0.2993.exe | — | explorer.exe | |||||||||||
User: admin Company: The Eraser Project Integrity Level: MEDIUM Description: Eraser Setup Bootstrapper Exit code: 3221226540 Version: 6.2.0.2993 Modules
| |||||||||||||||
| 1024 | C:\Windows\Explorer.EXE | C:\Windows\explorer.exe | — | — | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1608 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1880 | "C:\Program Files\Eraser\Eraser.exe" | C:\Program Files\Eraser\Eraser.exe | explorer.exe | ||||||||||||
User: admin Company: The Eraser Project Integrity Level: HIGH Description: Eraser Exit code: 3762504530 Version: 6.2.0.2993 Modules
| |||||||||||||||
| 1908 | msiexec.exe /i "C:\Users\admin\AppData\Local\Temp\eraserInstallBootstrapper\Eraser (x86).msi" | C:\Windows\System32\msiexec.exe | Eraser 6.2.0.2993.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2068 | "C:\Users\admin\Desktop\Eraser 6.2.0.2993.exe" | C:\Users\admin\Desktop\Eraser 6.2.0.2993.exe | explorer.exe | ||||||||||||
User: admin Company: The Eraser Project Integrity Level: HIGH Description: Eraser Setup Bootstrapper Exit code: 0 Version: 6.2.0.2993 Modules
| |||||||||||||||
| 2724 | "C:\Program Files\Eraser\Eraser.exe" | C:\Program Files\Eraser\Eraser.exe | explorer.exe | ||||||||||||
User: admin Company: The Eraser Project Integrity Level: HIGH Description: Eraser Exit code: 3762504530 Version: 6.2.0.2993 | |||||||||||||||
| 2936 | "C:\Program Files\Eraser\Eraser.exe" | C:\Program Files\Eraser\Eraser.exe | msiexec.exe | ||||||||||||
User: admin Company: The Eraser Project Integrity Level: HIGH Description: Eraser Exit code: 0 Version: 6.2.0.2993 Modules
| |||||||||||||||
| 2940 | C:\Windows\system32\MsiExec.exe -Embedding 241522C138F157AD5FBAA0635C3C247B C | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2948 | "C:\Program Files\Eraser\Eraser.exe" | C:\Program Files\Eraser\Eraser.exe | — | explorer.exe | |||||||||||
User: admin Company: The Eraser Project Integrity Level: MEDIUM Description: Eraser Exit code: 3221226540 Version: 6.2.0.2993 Modules
| |||||||||||||||
| (PID) Process: | (1024) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Action Center\Checks\{C8E6F269-B90A-4053-A3BE-499AFCEC98C4}.check.0 |
| Operation: | write | Name: | CheckSetting |
Value: 01000000D08C9DDF0115D1118C7A00C04FC297EB01000000F6D6788197A75D498472ACE88906AC8D0000000002000000000010660000000100002000000075B0D7E28E2E17B576E141128F731FE5320CCA30C35292A435B65D5E91F3150B000000000E80000000020000200000000C791686155A322F498D360901A0BC88A787D4ADF186758AE2D9BB16BE317ECD30000000E07A76BA5A881A8B5FF9F7A7FE5833EB2B96D7A240E8CDC394ED7C494DEC5BF8E13DB07B279185F24F9C8B497FA4E70A400000008D71222A7DB9FE2EAB90303DA35140A5A9A6780343B0FFB0C4B233499C2F0735FA041306AFACB24F5B397960A2D4CBA893F7FF12508B7C84A5AE9013C2C0A092 | |||
| (PID) Process: | (1024) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\StartPage\NewShortcuts |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (1024) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count |
| Operation: | write | Name: | HRZR_PGYFRFFVBA |
Value: 0000000091010000D9020000533B61013F0000004A0000008E0F0D004D006900630072006F0073006F00660074002E0049006E007400650072006E00650074004500780070006C006F007200650072002E00440065006600610075006C007400000028003E004000A4E75102B8E651020000000000000000000000000000080274E45102000008026CE25102000000000000D26CFFFFFFFF705911750000000000000000A4E251027C900D75000400000000000008E35102FFFFFFFF38EA7000FFFFFFFF080A7400D80E740030EA7000D4E25102F7AF3D7680D0707614F05102081D3E76E4613E766820700008E351020000000071000000BBF2CB00E8E25102A1693E766820700008E351020000000014E551023F613E766820700008E3510200000400000000800400000026E4510298E351025DA5147726E45102D26E147779A51477D6794D7526E4510210E65102000100006400610072E3510226E451026F0061006D0069006E0067005C006D006900630072006F0073006F0066007400CCE351023400000080E35102DE70310033003300350033003800310030003000F8E551025A000000A0E351021DA71477D6610E02D4E351025A00000010E651025C00000011000000104F7000084F7000F8E55102C4E3510220E40000D7F3CB00D0E351025E903E7620E45102D4E3510203943E760000000064561802FCE35102A9933E7664561802A8E45102D8511802BD933E7600000000D8511802A8E4510204E45102010000007F000000130B63004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E0043006F006E00740072006F006C00500061006E0065006C000000000001000000514F1D7621D9E2138202000088D9FE010000000000000000000000002CE33A02C0E33A0298E53A02136822762575C567FEFFFFFF514F1D7662001B74880005008202000001000000000000000000000088D9FE018CFF1A748800050001000000FFFFFFFFFFFFFFFFE0C31D7691C41D764E00000000000000000000000000000064E33A02A8C01A74B8E73A021368227625FEC567BCD9FE014EC41D76FE501D760000000088F41A7488000500C11000000000000000000000E454F70001000000FFFFFFFFC11000000C00000088F41A748800050030281D0020E43A02EA531D76D054F7002051F7000000000020E43A0224CE1D76088000007D2F1D7650441A740880000088000500FCFFFFFF0D000000780CFD011100000048512100405121000C00000030C4E71378E43A02C0E40000F3DFE21374E43A025E903376C0E43A0264570000DFDFE21388E43A02929B337668570B024C060000A0E43A02D8520B02ACE43A02110000004851210040512100A0E43A02F8520B0210E5000007DFE213C0E43A025E90337610E53A02C4E43A02039433760000000064570B02ECE43A02A993337664570B0298E53A02D8520B02BD93337600000000D8520B0298E53A02F4E43A02010000007F000000130B63004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E0043006F006E00740072006F006C00500061006E0065006C000000000001000000514F1D7621D9E2138202000088D9FE010000000000000000000000002CE33A02C0E33A0298E53A02136822762575C567FEFFFFFF514F1D7662001B74880005008202000001000000000000000000000088D9FE018CFF1A748800050001000000FFFFFFFFFFFFFFFFE0C31D7691C41D764E00000000000000000000000000000064E33A02A8C01A74B8E73A021368227625FEC567BCD9FE014EC41D76FE501D760000000088F41A7488000500C11000000000000000000000E454F70001000000FFFFFFFFC11000000C00000088F41A748800050030281D0020E43A02EA531D76D054F7002051F7000000000020E43A0224CE1D76088000007D2F1D7650441A740880000088000500FCFFFFFF0D000000780CFD011100000048512100405121000C00000030C4E71378E43A02C0E40000F3DFE21374E43A025E903376C0E43A0264570000DFDFE21388E43A02929B337668570B024C060000A0E43A02D8520B02ACE43A02110000004851210040512100A0E43A02F8520B0210E5000007DFE213C0E43A025E90337610E53A02C4E43A02039433760000000064570B02ECE43A02A993337664570B0298E53A02D8520B02BD93337600000000D8520B0298E53A02F4E43A02 | |||
| (PID) Process: | (1024) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count |
| Operation: | write | Name: | P:\Hfref\nqzva\Qrfxgbc\Renfre 6.2.0.2993.rkr |
Value: 00000000000000000100000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000 | |||
| (PID) Process: | (1024) explorer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count |
| Operation: | write | Name: | HRZR_PGYFRFFVBA |
Value: 0000000091010000DA020000533B61013F0000004A0000008E0F0D004D006900630072006F0073006F00660074002E0049006E007400650072006E00650074004500780070006C006F007200650072002E00440065006600610075006C007400000028003E004000A4E75102B8E651020000000000000000000000000000080274E45102000008026CE25102000000000000D26CFFFFFFFF705911750000000000000000A4E251027C900D75000400000000000008E35102FFFFFFFF38EA7000FFFFFFFF080A7400D80E740030EA7000D4E25102F7AF3D7680D0707614F05102081D3E76E4613E766820700008E351020000000071000000BBF2CB00E8E25102A1693E766820700008E351020000000014E551023F613E766820700008E3510200000400000000800400000026E4510298E351025DA5147726E45102D26E147779A51477D6794D7526E4510210E65102000100006400610072E3510226E451026F0061006D0069006E0067005C006D006900630072006F0073006F0066007400CCE351023400000080E35102DE70310033003300350033003800310030003000F8E551025A000000A0E351021DA71477D6610E02D4E351025A00000010E651025C00000011000000104F7000084F7000F8E55102C4E3510220E40000D7F3CB00D0E351025E903E7620E45102D4E3510203943E760000000064561802FCE35102A9933E7664561802A8E45102D8511802BD933E7600000000D8511802A8E4510204E45102010000007F000000130B63004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E0043006F006E00740072006F006C00500061006E0065006C000000000001000000514F1D7621D9E2138202000088D9FE010000000000000000000000002CE33A02C0E33A0298E53A02136822762575C567FEFFFFFF514F1D7662001B74880005008202000001000000000000000000000088D9FE018CFF1A748800050001000000FFFFFFFFFFFFFFFFE0C31D7691C41D764E00000000000000000000000000000064E33A02A8C01A74B8E73A021368227625FEC567BCD9FE014EC41D76FE501D760000000088F41A7488000500C11000000000000000000000E454F70001000000FFFFFFFFC11000000C00000088F41A748800050030281D0020E43A02EA531D76D054F7002051F7000000000020E43A0224CE1D76088000007D2F1D7650441A740880000088000500FCFFFFFF0D000000780CFD011100000048512100405121000C00000030C4E71378E43A02C0E40000F3DFE21374E43A025E903376C0E43A0264570000DFDFE21388E43A02929B337668570B024C060000A0E43A02D8520B02ACE43A02110000004851210040512100A0E43A02F8520B0210E5000007DFE213C0E43A025E90337610E53A02C4E43A02039433760000000064570B02ECE43A02A993337664570B0298E53A02D8520B02BD93337600000000D8520B0298E53A02F4E43A02010000007F000000130B63004D006900630072006F0073006F00660074002E00570069006E0064006F00770073002E0043006F006E00740072006F006C00500061006E0065006C000000000001000000514F1D7621D9E2138202000088D9FE010000000000000000000000002CE33A02C0E33A0298E53A02136822762575C567FEFFFFFF514F1D7662001B74880005008202000001000000000000000000000088D9FE018CFF1A748800050001000000FFFFFFFFFFFFFFFFE0C31D7691C41D764E00000000000000000000000000000064E33A02A8C01A74B8E73A021368227625FEC567BCD9FE014EC41D76FE501D760000000088F41A7488000500C11000000000000000000000E454F70001000000FFFFFFFFC11000000C00000088F41A748800050030281D0020E43A02EA531D76D054F7002051F7000000000020E43A0224CE1D76088000007D2F1D7650441A740880000088000500FCFFFFFF0D000000780CFD011100000048512100405121000C00000030C4E71378E43A02C0E40000F3DFE21374E43A025E903376C0E43A0264570000DFDFE21388E43A02929B337668570B024C060000A0E43A02D8520B02ACE43A02110000004851210040512100A0E43A02F8520B0210E5000007DFE213C0E43A025E90337610E53A02C4E43A02039433760000000064570B02ECE43A02A993337664570B0298E53A02D8520B02BD93337600000000D8520B0298E53A02F4E43A02 | |||
| (PID) Process: | (1908) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\178\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1908) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1 |
| Operation: | write | Name: | Blob |
Value: 7A000000010000000C000000300A06082B06010505070309190000000100000010000000CB9DD0FCEAAA492F75CE292C21BBFBDD53000000010000007E000000307C301F06092B06010401A032010130123010060A2B0601040182373C0101030200C0301F06092B06010401A032010230123010060A2B0601040182373C0101030200C0301B060567810C010130123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C00B000000010000003000000047006C006F00620061006C005300690067006E00200052006F006F00740020004300410020002D0020005200360000006200000001000000200000002CABEAFE37D06CA22ABA7391C0033D25982952C453647349763A3AB5AD6CCF69140000000100000014000000AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A01D0000000100000010000000521F5C98970D19A8E515EF6EEB6D48EF7F000000010000000C000000300A06082B060105050703097E00000001000000080000000000042BEB77D5010300000001000000140000008094640EB5A7A1CA119C1FDDD59F810263A7FBD10F0000000100000030000000EA09C51D4C3A334CE4ACD2BC08C6A9BE352E334F45C4FCCFCAB63EDB9F82DC87D4BD2ED2FADAE11163FB954809984FF1090000000100000056000000305406082B0601050507030206082B06010505070303060A2B0601040182370A030C060A2B0601040182370A030406082B0601050507030406082B0601050507030906082B0601050507030106082B06010505070308200000000100000087050000308205833082036BA003020102020E45E6BB038333C3856548E6FF4551300D06092A864886F70D01010C0500304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523631133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E301E170D3134313231303030303030305A170D3334313231303030303030305A304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523631133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E30820222300D06092A864886F70D01010105000382020F003082020A02820201009507E873CA66F9EC14CA7B3CF70D08F1B4450B2C82B448C6EB5B3CAE83B841923314A46F7FE92ACCC6B0886BC5B689D1C6B2FF14CE511421EC4ADD1B5AC6D687EE4D3A1506ED64660B9280CA44DE73944EF3A7897F4F786308C812506D42662F4DB979284D521A8A1A80B719810E7EC48ABC644C211C4368D73D3C8AC5B266D5909AB73106C5BEE26D3206A61EF9B9EBAAA3B8BFBE826350D0F01889DFE40F79F5EAA21F2AD2702E7BE7BC93BB6D53E2487C8C100738FF66B277617EE0EA8C3CAAB4A4F6F3954A12076DFD8CB289CFD0A06177C85874B0D4233AF75D3ACAA2DB9D09DE5D442D90F181CD5792FA7EBC50046334DF6B9318BE6B36B239E4AC2436B7F0EFB61C135793B6DEB2F8E285B773A2B835AA45F2E09D36A16F548AF172566E2E88C55142441594EEA3C538969B4E4E5A0B47F30636497730BC7137E5A6EC210875FCE661163F77D5D99197840A6CD4024D74C014EDFD39FB83F25E14A104B00BE9FEEE8FE16E0BB208B36166096AB1063A659659C0F035FDC9DA288D1A118770810AA89A751D9E3A8605009EDB80D625F9DC059E27594C76395BEAF9A5A1D8830FD1FFDF3011F985CF3348F5CA6D64142C7A584FD34B0849C595641A630E793DF5B38CCA58AD9C4245796E0E87195C54B165B6BF8C9BDC13E90D6FB82EDC676EC98B11B584148A0019708379919791D41A27BF371E3207D814633C284CAF0203010001A3633061300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E04160414AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A0301F0603551D23041830168014AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A0300D06092A864886F70D01010C050003820201008325EDE8D1FD9552CD9EC004A09169E65CD084DEDCADA24FE84778D66598A95BA83C877C028AD16EB71673E65FC05498D574BEC1CDE21191AD23183DDDE1724496B4955EC07B8E99781643135657B3A2B33BB577DC4072ACA3EB9B353EB10821A1E7C443377932BEB5E79C2C4CBC4329998E30D3AC21E0E31DFAD80733765400222AB94D202E7068DAE553FC835CD39DF2FF440C4466F2D2E3BD46001A6D02BA255D8DA13151DD54461C4DDB9996EF1A1C045CA615EF78E079FE5DDB3EAA4C55FD9A15A96FE1A6FBDF7030E9C3EE4246EDC2930589FA7D637B3FD071817C00E898AE0E7834C325FBAF0A9F206BDD3B138F128CE2411A487A73A07769C7B65C7F82C81EFE581B282BA86CAD5E6DC005D27BB7EB80FE2537FE029B68AC425DC3EEF5CCDCF05075D236699CE67B04DF6E0669B6DE0A09485987EB7B14607A64AA6943EF91C74CEC18DD6CEF532D8C99E15EF2723ECF54C8BD67ECA40F4C45FFD3B93023074C8F10BF8696D9995AB499571CA4CCBB158953BA2C050FE4C49E19B11834D54C9DBAEDF71FAF24950478A803BBEE81E5DA5F7C8B4AA1907425A7B33E4BC82C56BDC7C8EF38E25C92F079F79C84BA742D6101207E7ED1F24F07595F8B2D4352EB460C94E1F566477977D5545B1FAD2437CB455A4EA04448C8D8B099C5158409F6D64949C065B8E61A716EA0A8F182E8453E6CD602D70A6783055AC9A410 | |||
| (PID) Process: | (1908) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\8094640EB5A7A1CA119C1FDDD59F810263A7FBD1 |
| Operation: | write | Name: | Blob |
Value: 0400000001000000100000004FDD07E4D42264391E0C3742EAD1C6AE090000000100000056000000305406082B0601050507030206082B06010505070303060A2B0601040182370A030C060A2B0601040182370A030406082B0601050507030406082B0601050507030906082B0601050507030106082B060105050703080F0000000100000030000000EA09C51D4C3A334CE4ACD2BC08C6A9BE352E334F45C4FCCFCAB63EDB9F82DC87D4BD2ED2FADAE11163FB954809984FF10300000001000000140000008094640EB5A7A1CA119C1FDDD59F810263A7FBD17E00000001000000080000000000042BEB77D5017F000000010000000C000000300A06082B060105050703091D0000000100000010000000521F5C98970D19A8E515EF6EEB6D48EF140000000100000014000000AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A06200000001000000200000002CABEAFE37D06CA22ABA7391C0033D25982952C453647349763A3AB5AD6CCF690B000000010000003000000047006C006F00620061006C005300690067006E00200052006F006F00740020004300410020002D00200052003600000053000000010000007E000000307C301F06092B06010401A032010130123010060A2B0601040182373C0101030200C0301F06092B06010401A032010230123010060A2B0601040182373C0101030200C0301B060567810C010130123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C0190000000100000010000000CB9DD0FCEAAA492F75CE292C21BBFBDD7A000000010000000C000000300A06082B06010505070309200000000100000087050000308205833082036BA003020102020E45E6BB038333C3856548E6FF4551300D06092A864886F70D01010C0500304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523631133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E301E170D3134313231303030303030305A170D3334313231303030303030305A304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523631133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E30820222300D06092A864886F70D01010105000382020F003082020A02820201009507E873CA66F9EC14CA7B3CF70D08F1B4450B2C82B448C6EB5B3CAE83B841923314A46F7FE92ACCC6B0886BC5B689D1C6B2FF14CE511421EC4ADD1B5AC6D687EE4D3A1506ED64660B9280CA44DE73944EF3A7897F4F786308C812506D42662F4DB979284D521A8A1A80B719810E7EC48ABC644C211C4368D73D3C8AC5B266D5909AB73106C5BEE26D3206A61EF9B9EBAAA3B8BFBE826350D0F01889DFE40F79F5EAA21F2AD2702E7BE7BC93BB6D53E2487C8C100738FF66B277617EE0EA8C3CAAB4A4F6F3954A12076DFD8CB289CFD0A06177C85874B0D4233AF75D3ACAA2DB9D09DE5D442D90F181CD5792FA7EBC50046334DF6B9318BE6B36B239E4AC2436B7F0EFB61C135793B6DEB2F8E285B773A2B835AA45F2E09D36A16F548AF172566E2E88C55142441594EEA3C538969B4E4E5A0B47F30636497730BC7137E5A6EC210875FCE661163F77D5D99197840A6CD4024D74C014EDFD39FB83F25E14A104B00BE9FEEE8FE16E0BB208B36166096AB1063A659659C0F035FDC9DA288D1A118770810AA89A751D9E3A8605009EDB80D625F9DC059E27594C76395BEAF9A5A1D8830FD1FFDF3011F985CF3348F5CA6D64142C7A584FD34B0849C595641A630E793DF5B38CCA58AD9C4245796E0E87195C54B165B6BF8C9BDC13E90D6FB82EDC676EC98B11B584148A0019708379919791D41A27BF371E3207D814633C284CAF0203010001A3633061300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E04160414AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A0301F0603551D23041830168014AE6C05A39313E2A2E7E2D71CD6C7F07FC86753A0300D06092A864886F70D01010C050003820201008325EDE8D1FD9552CD9EC004A09169E65CD084DEDCADA24FE84778D66598A95BA83C877C028AD16EB71673E65FC05498D574BEC1CDE21191AD23183DDDE1724496B4955EC07B8E99781643135657B3A2B33BB577DC4072ACA3EB9B353EB10821A1E7C443377932BEB5E79C2C4CBC4329998E30D3AC21E0E31DFAD80733765400222AB94D202E7068DAE553FC835CD39DF2FF440C4466F2D2E3BD46001A6D02BA255D8DA13151DD54461C4DDB9996EF1A1C045CA615EF78E079FE5DDB3EAA4C55FD9A15A96FE1A6FBDF7030E9C3EE4246EDC2930589FA7D637B3FD071817C00E898AE0E7834C325FBAF0A9F206BDD3B138F128CE2411A487A73A07769C7B65C7F82C81EFE581B282BA86CAD5E6DC005D27BB7EB80FE2537FE029B68AC425DC3EEF5CCDCF05075D236699CE67B04DF6E0669B6DE0A09485987EB7B14607A64AA6943EF91C74CEC18DD6CEF532D8C99E15EF2723ECF54C8BD67ECA40F4C45FFD3B93023074C8F10BF8696D9995AB499571CA4CCBB158953BA2C050FE4C49E19B11834D54C9DBAEDF71FAF24950478A803BBEE81E5DA5F7C8B4AA1907425A7B33E4BC82C56BDC7C8EF38E25C92F079F79C84BA742D6101207E7ED1F24F07595F8B2D4352EB460C94E1F566477977D5545B1FAD2437CB455A4EA04448C8D8B099C5158409F6D64949C065B8E61A716EA0A8F182E8453E6CD602D70A6783055AC9A410 | |||
| (PID) Process: | (1908) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD |
| Operation: | write | Name: | Blob |
Value: 530000000100000040000000303E301F06092B06010401A032010130123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C0190000000100000010000000D0FD3C9C380D7B65E26B9A3FEDD39B8F0B000000010000003000000047006C006F00620061006C005300690067006E00200052006F006F00740020004300410020002D002000520033000000620000000100000020000000CBB522D7B7F127AD6A0113865BDF1CD4102E7D0759AF635A7CF4720DC963C53B1400000001000000140000008FF04B7FA82E4524AE4D50FA639A8BDEE2DD1BBC1D000000010000001000000001728E1ECF7A9D86FB3CEC8948ABA953030000000100000014000000D69B561148F01C77C54578C10926DF5B856976AD0F00000001000000200000005229BA15B31B0C6F4CCA89C2985177974327D1B689A3B935A0BD975532AF22AB090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703082000000001000000630300003082035F30820247A003020102020B04000000000121585308A2300D06092A864886F70D01010B0500304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523331133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E301E170D3039303331383130303030305A170D3239303331383130303030305A304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523331133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E30820122300D06092A864886F70D01010105000382010F003082010A0282010100CC2576907906782216F5C083B684CA289EFD057611C5AD8872FC460243C7B28A9D045F24CB2E4BE1608246E152AB0C8147706CDD64D1EBF52CA30F823D0C2BAE97D7B614861079BB3B1380778C08E149D26A622F1F5EFA9668DF892795389F06D73EC9CB26590D73DEB0C8E9260E8315C6EF5B8BD20460CA49A628F6693BF6CBC82891E59D8A615737AC7414DC74E03AEE722F2E9CFBD0BBBFF53D00E10633E8822BAE53A63A16738CDD410E203AC0B4A7A1E9B24F902E3260E957CBB904926868E538266075B29F77FF9114EFAE2049FCAD401548D1023161195EB897EFAD77B7649A7ABF5FC113EF9B62FB0D6CE0546916A903DA6EE983937176C6698582170203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604148FF04B7FA82E4524AE4D50FA639A8BDEE2DD1BBC300D06092A864886F70D01010B050003820101004B40DBC050AAFEC80CEFF796544549BB96000941ACB3138686280733CA6BE674B9BA002DAEA40AD3F5F1F10F8ABF73674A83C7447B78E0AF6E6C6F03298E333945C38EE4B9576CAAFC1296EC53C62DE4246CB99463FBDC536867563E83B8CF3521C3C968FECEDAC253AACC908AE9F05D468C95DD7A58281A2F1DDECD0037418FED446DD75328977EF367041E15D78A96B4D3DE4C27A44C1B737376F41799C21F7A0EE32D08AD0A1C2CFF3CAB550E0F917E36EBC35749BEE12E2D7C608BC3415113239DCEF7326B9401A899E72C331F3A3B25D28640CE3B2C8678C9612F14BAEEDB556FDF84EE05094DBD28D872CED36250651EEB92978331D9B3B5CA47583F5F | |||
| (PID) Process: | (1908) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\AuthRoot\Certificates\D69B561148F01C77C54578C10926DF5B856976AD |
| Operation: | write | Name: | Blob |
Value: 040000000100000010000000C5DFB849CA051355EE2DBA1AC33EB028090000000100000054000000305206082B0601050507030206082B06010505070303060A2B0601040182370A030406082B0601050507030406082B0601050507030606082B0601050507030706082B0601050507030106082B060105050703080F00000001000000200000005229BA15B31B0C6F4CCA89C2985177974327D1B689A3B935A0BD975532AF22AB030000000100000014000000D69B561148F01C77C54578C10926DF5B856976AD1D000000010000001000000001728E1ECF7A9D86FB3CEC8948ABA9531400000001000000140000008FF04B7FA82E4524AE4D50FA639A8BDEE2DD1BBC620000000100000020000000CBB522D7B7F127AD6A0113865BDF1CD4102E7D0759AF635A7CF4720DC963C53B0B000000010000003000000047006C006F00620061006C005300690067006E00200052006F006F00740020004300410020002D002000520033000000190000000100000010000000D0FD3C9C380D7B65E26B9A3FEDD39B8F530000000100000040000000303E301F06092B06010401A032010130123010060A2B0601040182373C0101030200C0301B060567810C010330123010060A2B0601040182373C0101030200C02000000001000000630300003082035F30820247A003020102020B04000000000121585308A2300D06092A864886F70D01010B0500304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523331133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E301E170D3039303331383130303030305A170D3239303331383130303030305A304C3120301E060355040B1317476C6F62616C5369676E20526F6F74204341202D20523331133011060355040A130A476C6F62616C5369676E311330110603550403130A476C6F62616C5369676E30820122300D06092A864886F70D01010105000382010F003082010A0282010100CC2576907906782216F5C083B684CA289EFD057611C5AD8872FC460243C7B28A9D045F24CB2E4BE1608246E152AB0C8147706CDD64D1EBF52CA30F823D0C2BAE97D7B614861079BB3B1380778C08E149D26A622F1F5EFA9668DF892795389F06D73EC9CB26590D73DEB0C8E9260E8315C6EF5B8BD20460CA49A628F6693BF6CBC82891E59D8A615737AC7414DC74E03AEE722F2E9CFBD0BBBFF53D00E10633E8822BAE53A63A16738CDD410E203AC0B4A7A1E9B24F902E3260E957CBB904926868E538266075B29F77FF9114EFAE2049FCAD401548D1023161195EB897EFAD77B7649A7ABF5FC113EF9B62FB0D6CE0546916A903DA6EE983937176C6698582170203010001A3423040300E0603551D0F0101FF040403020106300F0603551D130101FF040530030101FF301D0603551D0E041604148FF04B7FA82E4524AE4D50FA639A8BDEE2DD1BBC300D06092A864886F70D01010B050003820101004B40DBC050AAFEC80CEFF796544549BB96000941ACB3138686280733CA6BE674B9BA002DAEA40AD3F5F1F10F8ABF73674A83C7447B78E0AF6E6C6F03298E333945C38EE4B9576CAAFC1296EC53C62DE4246CB99463FBDC536867563E83B8CF3521C3C968FECEDAC253AACC908AE9F05D468C95DD7A58281A2F1DDECD0037418FED446DD75328977EF367041E15D78A96B4D3DE4C27A44C1B737376F41799C21F7A0EE32D08AD0A1C2CFF3CAB550E0F917E36EBC35749BEE12E2D7C608BC3415113239DCEF7326B9401A899E72C331F3A3B25D28640CE3B2C8678C9612F14BAEEDB556FDF84EE05094DBD28D872CED36250651EEB92978331D9B3B5CA47583F5F | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2068 | Eraser 6.2.0.2993.exe | C:\Users\admin\AppData\Local\Temp\eraserInstallBootstrapper\Eraser (x64).msi | — | |
MD5:— | SHA256:— | |||
| 2068 | Eraser 6.2.0.2993.exe | C:\Users\admin\AppData\Local\Temp\eraserInstallBootstrapper\Eraser (x86).msi | — | |
MD5:— | SHA256:— | |||
| 3580 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 3580 | msiexec.exe | C:\Windows\Installer\1057c6.msi | — | |
MD5:— | SHA256:— | |||
| 3580 | msiexec.exe | C:\System Volume Information\SPP\snapshot-2 | binary | |
MD5:1F05BE24FC92934A16FB89755475C1D7 | SHA256:C28E0CEA0165DBBB9D61E035717F0000354D1F4079CEA35C6CDFCA9F2A9D0A2A | |||
| 3580 | msiexec.exe | C:\System Volume Information\SPP\OnlineMetadataCache\{7a0d2c3c-d02c-4220-9a32-c5601161e215}_OnDiskSnapshotProp | binary | |
MD5:1F05BE24FC92934A16FB89755475C1D7 | SHA256:C28E0CEA0165DBBB9D61E035717F0000354D1F4079CEA35C6CDFCA9F2A9D0A2A | |||
| 3580 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\~DFAD2D855329EAA8F3.TMP | gmc | |
MD5:20BC287FDC530926E8A145A1146586DA | SHA256:A85E56EAC1F647E71A7C9BAC6939F65EC02E3A054C9E99E33536E900C18D3161 | |||
| 3580 | msiexec.exe | C:\Windows\Installer\MSI5D25.tmp | binary | |
MD5:B83382A2EAA77A5EAF6512163D19660D | SHA256:B55DBFCFD8CB8C47A3BC691E754E31109F95159F85AE2447DCD5B9F01B6628DA | |||
| 3580 | msiexec.exe | C:\Windows\Installer\1057c7.ipi | binary | |
MD5:9B6302EE24A0AA292EA7B986F249A35B | SHA256:9F58CFC781C1A7654421B24993D9865BFE555247622ADE5C0AA224B6919C61BB | |||
| 3580 | msiexec.exe | C:\Program Files\Eraser\alglibnet2.dll | executable | |
MD5:1DE2CB8A20E4F2B1823063AF30544ECB | SHA256:C2961B7AFBE82F7FF0C7CA94BB11F96FBA6DAECD954DA839B89DF568BEAC1E77 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 104.208.16.93:443 | watson.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | suspicious |
Domain | IP | Reputation |
|---|---|---|
watson.microsoft.com |
| whitelisted |
dns.msftncsi.com |
| shared |