| File name: | 514.1589_byond.exe |
| Full analysis: | https://app.any.run/tasks/f332c958-c1d4-416f-9af2-5235e68a4108 |
| Verdict: | Malicious activity |
| Analysis date: | March 05, 2024, 16:23:12 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 63B53B30CE9E3783724A1EF8B4249CBC |
| SHA1: | BA48C8213AFF8AF19EA7CFF1BD1EF120C9DB2872 |
| SHA256: | 0C05D274ED4DB7F1B110F0A7AC2CB79E813298B4542CCBEF60747AAE133EA1D0 |
| SSDEEP: | 98304:gnQx98dlMqwUxdF4thzaVQd/+yQp9DhMttPhphldMxUNyI2mGtwEfOehMoijZecI:N3Je+gp4PO9heWLnIMpPEKvqTa |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2016:12:11 21:50:45+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 24576 |
| InitializedDataSize: | 118784 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x32bf |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 5.0.514.1589 |
| ProductVersionNumber: | 5.0.514.1589 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | ASCII |
| CompanyName: | BYOND Software |
| FileDescription: | BYOND Installer |
| FileVersion: | 5.0.514.1589 |
| LegalCopyright: | © 2022 BYOND Software |
| ProductName: | BYOND Installer |
| ProductVersion: | 5.0.514.1589 (5.0 Public) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 880 | "C:\Program Files\BYOND\bin\byond.exe" | C:\Program Files\BYOND\bin\byond.exe | 514.1589_byond.exe | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: BYOND Exit code: 0 Version: 5.0.514.1589 Modules
| |||||||||||||||
| 956 | C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801} | C:\Windows\System32\dllhost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1336 | regsvr32 /s /c "C:\Program Files\BYOND\bin\byondstub.dll" | C:\Windows\System32\regsvr32.exe | — | 514.1589_byond.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1776 | "C:\Users\admin\AppData\Local\Temp\514.1589_byond.exe" /UAC:12019C /NCRC | C:\Users\admin\AppData\Local\Temp\514.1589_byond.exe | 514.1589_byond.exe | ||||||||||||
User: admin Company: BYOND Software Integrity Level: HIGH Description: BYOND Installer Exit code: 1223 Version: 5.0.514.1589 Modules
| |||||||||||||||
| 2120 | "C:\Program Files\BYOND\directx\DXSETUP.exe" /silent | C:\Program Files\BYOND\directx\DXSETUP.exe | ns5AC0.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft DirectX Setup Exit code: 0 Version: 4.9.0.0904 Modules
| |||||||||||||||
| 2648 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3864 | "C:\Users\admin\AppData\Local\Temp\514.1589_byond.exe" | C:\Users\admin\AppData\Local\Temp\514.1589_byond.exe | explorer.exe | ||||||||||||
User: admin Company: BYOND Software Integrity Level: MEDIUM Description: BYOND Installer Exit code: 1223 Version: 5.0.514.1589 Modules
| |||||||||||||||
| 4060 | "C:\Users\admin\AppData\Local\Temp\nswF89A.tmp\ns5AC0.tmp" "C:\Program Files\BYOND\directx\DXSETUP.exe" /silent | C:\Users\admin\AppData\Local\Temp\nswF89A.tmp\ns5AC0.tmp | — | 514.1589_byond.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2120) DXSETUP.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectX |
| Operation: | write | Name: | command |
Value: 0 | |||
| (PID) Process: | (2120) DXSETUP.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\DirectX |
| Operation: | write | Name: | DXSetup |
Value: 0 | |||
| (PID) Process: | (2120) DXSETUP.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 40000000000000001127E681196FDA0148080000A80F0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2120) DXSETUP.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 40000000000000006B89E881196FDA0148080000A80F0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2120) DXSETUP.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 75 | |||
| (PID) Process: | (2120) DXSETUP.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 400000000000000087D7F681196FDA0148080000A80F0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2120) DXSETUP.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 400000000000000095FEFD81196FDA0148080000780F0000E8030000010000000000000000000000682653967C4416459CACE4356478BB850000000000000000 | |||
| (PID) Process: | (2648) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000A3250582196FDA01580A0000B8080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2648) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000A3250582196FDA01580A0000F4080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2648) VSSVC.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000A3250582196FDA01580A0000500B0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1776 | 514.1589_byond.exe | C:\Users\admin\AppData\Local\Temp\nswF89A.tmp\modern-wizard.bmp | image | |
MD5:A3FC51B1BD19974E46DB7B52F90FF5BC | SHA256:67A4B5579F6E751159BAD822DA105858B68F4080E5F430B79EE1B9BD4AC05040 | |||
| 1776 | 514.1589_byond.exe | C:\Users\admin\AppData\Local\Temp\spltmp.bmp | image | |
MD5:E0F5E79C3FCDB02DBD645E70AE9F0661 | SHA256:CC8A70AC324F641536677BFCA9D7BF0699E5741BF0661D770C9C0640526372FB | |||
| 1776 | 514.1589_byond.exe | C:\Users\admin\AppData\Local\Temp\nswF89A.tmp\modern-header.bmp | image | |
MD5:044093109EBEF3C866A65A435010BAAB | SHA256:26B00AA88EDFB27DFD208394B81AF4E909D28EF5219A31380C3FBDEDDEF0E112 | |||
| 1776 | 514.1589_byond.exe | C:\Users\admin\AppData\Local\Temp\nswF89A.tmp\ioSpecial.ini | text | |
MD5:E2D5070BC28DB1AC745613689FF86067 | SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0 | |||
| 1776 | 514.1589_byond.exe | C:\Users\admin\AppData\Local\Temp\nswF89A.tmp\advsplash.dll | executable | |
MD5:15D8EEE287329E2030C34C6BB3E62C87 | SHA256:9BF33690090655E91389469BEB5DBDD45942192F2E2486C9FA82FA6D74A0F88B | |||
| 1776 | 514.1589_byond.exe | C:\Users\admin\AppData\Local\Temp\nswF89A.tmp\nsProcessBYOND.dll | executable | |
MD5:7B6CBDE5DA4391FE1B59B5E66E1A8507 | SHA256:A54E0DF29E251120CEB49D05E9977950F5B25B873E6222672EEECB100BCBB4A2 | |||
| 1776 | 514.1589_byond.exe | C:\Users\admin\AppData\Local\Temp\nswF89A.tmp\UAC.dll | executable | |
MD5:4814167AA1C7EC892E84907094646FAA | SHA256:32DD7269ABF5A0E5DB888E307D9DF313E87CEF4F1B597965A9D8E00934658822 | |||
| 1776 | 514.1589_byond.exe | C:\Users\admin\AppData\Local\Temp\nswF89A.tmp\System.dll | executable | |
MD5:3F176D1EE13B0D7D6BD92E1C7A0B9BAE | SHA256:FA4AB1D6F79FD677433A31ADA7806373A789D34328DA46CCB0449BBF347BD73E | |||
| 1776 | 514.1589_byond.exe | C:\Users\admin\AppData\Local\Temp\nswF89A.tmp\UserInfo.dll | executable | |
MD5:C22C9D7B6937B8960FBA4C8A145076B2 | SHA256:510E466A715933499FB9D5A1753B483826B2BF89161B9D466DD2AD7E52EDE2FC | |||
| 1776 | 514.1589_byond.exe | C:\Program Files\12345.tmp | binary | |
MD5:93B885ADFE0DA089CDF634904FD59F71 | SHA256:6E340B9CFFB37A989CA544E6BB780A2C78901D3FB33738768511A30617AFA01D | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
880 | byond.exe | GET | — | 172.67.180.70:80 | http://www.byond.com/HubPorts | unknown | — | — | unknown |
880 | byond.exe | GET | — | 172.67.180.70:80 | http://www.byond.com/rsc/hubcache.js?1709640000 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
880 | byond.exe | 172.67.180.70:80 | www.byond.com | CLOUDFLARENET | US | unknown |
Domain | IP | Reputation |
|---|---|---|
www.byond.com |
| unknown |
Process | Message |
|---|---|
DXSETUP.exe | DLL_PROCESS_ATTACH |
DXSETUP.exe | DLL_PROCESS_ATTACH |
DXSETUP.exe | DLL_PROCESS_DETACH |
DXSETUP.exe | DLL_PROCESS_DETACH |