File name: | 7tsp GUI v0.6(2019).exe |
Full analysis: | https://app.any.run/tasks/81498521-075d-426f-bd15-2a561da1d25d |
Verdict: | Malicious activity |
Analysis date: | April 30, 2024, 21:06:59 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
MD5: | 0FC4B5592E3B58F1FC87D5EF81DE981A |
SHA1: | F9408F54BE6540CCAF7CE0B9DBB80B81AFD83CA8 |
SHA256: | 090C9E214599150F6ED241171BB2107E04D13BFA5E74927B094B139EAE280B65 |
SSDEEP: | 98304:0kJXjsBN1FOVttlTfMO5bkjUBoUpQbo3r95HwTClvBAOMpWaQ0dy4ybVWT1rk/lv:0o31yYVBFX |
.exe | | | UPX compressed Win32 Executable (39.3) |
---|---|---|
.exe | | | Win32 EXE Yoda's Crypter (38.6) |
.dll | | | Win32 Dynamic Link Library (generic) (9.5) |
.exe | | | Win32 Executable (generic) (6.5) |
.exe | | | Generic Win/DOS Executable (2.9) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2010:03:07 16:08:39+00:00 |
ImageFileCharacteristics: | No relocs, Executable, Large address aware, 32-bit |
PEType: | PE32 |
LinkerVersion: | 9 |
CodeSize: | 270336 |
InitializedDataSize: | 151552 |
UninitializedDataSize: | 602112 |
EntryPoint: | 0xd5bc0 |
OSVersion: | 5 |
ImageVersion: | - |
SubsystemVersion: | 5 |
Subsystem: | Windows GUI |
FileVersionNumber: | 0.6.2.0 |
ProductVersionNumber: | 3.3.6.0 |
FileFlagsMask: | 0x0000 |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Unknown |
FileSubtype: | - |
LanguageCode: | English (U.S.) |
CharacterSet: | Unicode |
FileVersion: | 0.6.2.0 |
Comments: | Se7en Theme Source Patcher v0.6.2019 Patches your Windows Se7en System Files with new Icons and Bitmaps |
FileDescription: | Se7en Theme Source Patcher |
LegalCopyright: | XPtsp Team -Program Written By Fixit- |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
112 | TAKEOWN /F "C:\Windows\system32\imageres.dll" /a | C:\Windows\System32\takeown.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Takes ownership of a file Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
116 | "C:\ProgramData\local\temp\7tsp\Programs\reshacker.exe""" -extract "C:\Windows\system32\shell32.dll", "C:\ProgramData\local\temp\7tsp\Extra\shell32\633.bmp", BITMAP,633, | C:\ProgramData\local\temp\7tsp\programs\ResHacker.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: HIGH Description: Resource viewer, decompiler & recompiler. Exit code: 0 Version: 3.6.0.92 Modules
| |||||||||||||||
116 | icacls "C:\Windows\system32\imageres.dll" /grant *S-1-5-32-544:F | C:\Windows\System32\icacls.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
304 | "C:\ProgramData\local\temp\7tsp\Programs\reshacker.exe""" -extract "C:\Windows\explorer.exe", "C:\ProgramData\local\temp\7tsp\temp\orb.bmp", BITMAP,6801, | C:\ProgramData\local\temp\7tsp\programs\ResHacker.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: HIGH Description: Resource viewer, decompiler & recompiler. Exit code: 0 Version: 3.6.0.92 Modules
| |||||||||||||||
304 | "C:\ProgramData\local\temp\7tsp\programs\bru.exe""" "C:\ProgramData\local\temp\7tsp\imageres.dll.bru | C:\ProgramData\local\temp\7tsp\programs\bru.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
748 | "C:\ProgramData\local\temp\7tsp\Programs\reshacker.exe""" -extract "C:\Windows\system32\imageres.dll", "C:\ProgramData\local\temp\7tsp\Extra\logon\5033.jpg", IMAGE,5033, | C:\ProgramData\local\temp\7tsp\programs\ResHacker.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: HIGH Description: Resource viewer, decompiler & recompiler. Exit code: 0 Version: 3.6.0.92 Modules
| |||||||||||||||
764 | C:\Windows\system32\cmd.exe /c icacls "C:\Windows\system32\imageres.dll" /setowner *S-1-5-80-956008885-3418522649-1831038044-1853292631-2271478464 | C:\Windows\System32\cmd.exe | — | 7tsp GUI v0.6(2019).exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
856 | "C:\ProgramData\local\temp\7tsp\programs\bru.exe""" "C:\ProgramData\local\temp\7tsp\shell32.dll.bru | C:\ProgramData\local\temp\7tsp\programs\bru.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
864 | C:\Windows\system32\cmd.exe /c icacls "C:\Windows\system32\imageres.dll" /grant *S-1-5-32-544:F | C:\Windows\System32\cmd.exe | — | 7tsp GUI v0.6(2019).exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
948 | C:\Windows\system32\cmd.exe /c ""C:\ProgramData\local\temp\7tsp\Programs\reshacker.exe""" -extract "C:\ProgramData\local\temp\7tsp\resources\shell32.dll.res", "C:\ProgramData\local\temp\7tsp\recompile\recompile.rc ,,," | C:\Windows\System32\cmd.exe | — | 7tsp GUI v0.6(2019).exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
|
(PID) Process: | (4068) 7tsp GUI v0.6(2019).exe | Key: | HKEY_CURRENT_USER\Software\Fixit Tools\7tsp |
Operation: | write | Name: | Agreement |
Value: (2019)Yes | |||
(PID) Process: | (4068) 7tsp GUI v0.6(2019).exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\FirstFolder |
Operation: | delete value | Name: | MRUList |
Value: | |||
(PID) Process: | (4068) 7tsp GUI v0.6(2019).exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\FirstFolder |
Operation: | write | Name: | 0 |
Value: 43003A005C00550073006500720073005C00610064006D0069006E005C0041007000700044006100740061005C004C006F00630061006C005C00540065006D0070005C00370074007300700020004700550049002000760030002E0036002800320030003100390029002E00650078006500000043003A005C00550073006500720073005C00610064006D0069006E005C004400650073006B0074006F0070000000 | |||
(PID) Process: | (4068) 7tsp GUI v0.6(2019).exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\FirstFolder |
Operation: | write | Name: | MRUListEx |
Value: 00000000FFFFFFFF | |||
(PID) Process: | (4068) 7tsp GUI v0.6(2019).exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
Operation: | write | Name: | NodeSlots |
Value: 0202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202 | |||
(PID) Process: | (4068) 7tsp GUI v0.6(2019).exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
Operation: | write | Name: | MRUListEx |
Value: 01000000070000000200000006000000000000000B0000000C0000000D0000000A0000000900000008000000030000000500000004000000FFFFFFFF | |||
(PID) Process: | (4068) 7tsp GUI v0.6(2019).exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (4068) 7tsp GUI v0.6(2019).exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU |
Operation: | write | Name: | 4 |
Value: 370074007300700020004700550049002000760030002E0036002800320030003100390029002E0065007800650000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000006E0100009C000000EE0300007C020000000000000000000000000000000000000100000000000000 | |||
(PID) Process: | (4068) 7tsp GUI v0.6(2019).exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU |
Operation: | delete value | Name: | 4 |
Value: 7tsp GUI v0.6(2019).exe | |||
(PID) Process: | (4068) 7tsp GUI v0.6(2019).exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU |
Operation: | write | Name: | 4 |
Value: 370074007300700020004700550049002000760030002E0036002800320030003100390029002E006500780065000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000006B010000730000009703000044020000000000000000000000000000000000006E0100009C000000EE0300007C020000000000000000000000000000000000000100000000000000 |
PID | Process | Filename | Type | |
---|---|---|---|---|
4068 | 7tsp GUI v0.6(2019).exe | C:\ProgramData\local\temp\7tsp\Programs\logos.bmp | image | |
MD5:D04E046BA533CE644FE6B97CD492FDB5 | SHA256:6D9C1A14BDBF29D835F297CBAF39CF94FC4725CCDFE8878E3548D194E2E46648 | |||
4068 | 7tsp GUI v0.6(2019).exe | C:\ProgramData\local\temp\7tsp\Programs\logo.bmp | image | |
MD5:E0EF4516C9ECA05CCF55E3F6413B18FD | SHA256:FDE61D0757522A87E9D11A64A6FD08569BD7977E94ED9E9502F52843217B6D50 | |||
4068 | 7tsp GUI v0.6(2019).exe | C:\Users\admin\AppData\Local\Temp\aut5621.tmp | binary | |
MD5:50A46D26B330BCD5D0BAC4E14554953B | SHA256:0D7193BDB42674D17C242D8504DB31A2C5B6864BD1D372016E8CDC9EAA62D9E4 | |||
4068 | 7tsp GUI v0.6(2019).exe | C:\ProgramData\local\temp\7tsp\programs\lang.ini | text | |
MD5:DD3D7C4A542DBD24F254093762300901 | SHA256:38B48270CC628E4B60DDB354EE115E6C465740D0B93AA6FCAECC60D5C67D9B72 | |||
4068 | 7tsp GUI v0.6(2019).exe | C:\ProgramData\local\temp\ReadMe.txt | text | |
MD5:907DB78291FB358F7D8B4CE73D33F8F1 | SHA256:4C01C8609EFEFF5B359AA5355266C933EDB3F50DCA1CBF532C4D9096253581C9 | |||
4068 | 7tsp GUI v0.6(2019).exe | C:\Users\admin\AppData\Local\Temp\aut569F.tmp | binary | |
MD5:0C4F0907658D48D9356D01C14282B1A0 | SHA256:15B3DE395AD0E35EED04C239703C5CF1187FD016FD2B021A47A43AC85FD49D50 | |||
4068 | 7tsp GUI v0.6(2019).exe | C:\ProgramData\local\temp\7tsp\programs\bru.exe | executable | |
MD5:6D93FA10C1C8C9DE200CF63F89A9092A | SHA256:163F17B8F6DB680DE43A71DCCA00101F9935AAF09B1E75DBF756DA16B9C80536 | |||
4068 | 7tsp GUI v0.6(2019).exe | C:\ProgramData\local\temp\7tsp\programs\logon.bmp | image | |
MD5:46924FE2203EEDB58D745612F23758F6 | SHA256:35820E9395F57D10B75ADB672552C0F487A60D90F6856A91CD0A472983D613EB | |||
4068 | 7tsp GUI v0.6(2019).exe | C:\ProgramData\local\temp\7tsp\programs\7za.dll | executable | |
MD5:251C8B50C9D79D1628769AEFDD571330 | SHA256:6816DB7F35F078B29A585F179C298ED2538916368EC714F3E3C279240515BACA | |||
4068 | 7tsp GUI v0.6(2019).exe | C:\Users\admin\AppData\Local\Temp\aut868D.tmp | binary | |
MD5:EE15D23DEA27B37C972E58AFE27DC201 | SHA256:4536C7F61CD9A26411D159E91DFF12B43AC72AEBA9F6C252AF49F0E682D12E19 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
1816 | sipnotify.exe | HEAD | — | 184.25.191.235:80 | http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133589885519530000 | unknown | — | — | — |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1472 | svchost.exe | 239.255.255.250:3702 | — | — | — | unknown |
1120 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1816 | sipnotify.exe | 184.25.191.235:80 | query.prod.cms.rt.microsoft.com | AKAMAI-AS | US | unknown |
Domain | IP | Reputation |
---|---|---|
query.prod.cms.rt.microsoft.com |
| unknown |