| File name: | HPSupportSolutionsFramework-12.19.53.13.exe |
| Full analysis: | https://app.any.run/tasks/bc8afb2d-1472-4551-b4b5-53e6e0d2b519 |
| Verdict: | Malicious activity |
| Threats: | Pikabot is a trojan malware with a focus on loader capabilities. Pikabot is also used for other activities, such as executing commands on the infected system. The earlier versions of the malware made use of extensive code obfuscation to evade detection. Upon infection, it collects system information and sends it to command-and-control servers. |
| Analysis date: | December 12, 2023, 06:14:26 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 7FD0D6FB4DA4A47B1FC6353C3484D756 |
| SHA1: | C9D4F8528FF7AD98059EDDA3306C9EBD99CA0EE9 |
| SHA256: | 0F6BF99EF4DAD41F159CBFD37BE395BFD4BED0AF0978F1851BADECB554F9918D |
| SSDEEP: | 98304:liTNTd4wpycvOSlX5JcBbRmhzZNKCl2x7P3SySgUcO5mxxlNY7bKfmm5PcX6qf0M:NgsyqKygjcRwC4P4 |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2007:07:22 04:33:09+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 74752 |
| InitializedDataSize: | 23040 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x11de6 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.2.0.715 |
| ProductVersionNumber: | 1.2.0.715 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Private build |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | - |
| CompanyName: | Oleg N. Scherbakov |
| FileDescription: | 7z Setup SFX |
| FileVersion: | 1, 2, 0, 715 |
| InternalName: | 7ZSfxNew |
| LegalCopyright: | Copyright © 2005-2007 Oleg N. Scherbakov |
| LegalTrademarks: | - |
| OriginalFileName: | 7ZSfxNew.exe |
| PrivateBuild: | July 14, 2007 |
| ProductName: | 7ZSfxNew |
| ProductVersion: | 1, 2, 0, 715 |
| SpecialBuild: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1996 | "C:\Users\admin\Desktop\HPSupportSolutionsFramework-12.19.53.13.exe" | C:\Users\admin\Desktop\HPSupportSolutionsFramework-12.19.53.13.exe | — | explorer.exe | |||||||||||
User: admin Company: Oleg N. Scherbakov Integrity Level: MEDIUM Description: 7z Setup SFX Exit code: 0 Version: 1, 2, 0, 715 Modules
| |||||||||||||||
| 2492 | C:\Windows\system32\MsiExec.exe -Embedding C1C02942AA031BFC460F273359E268BB C | C:\Windows\System32\msiexec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2528 | "C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\HPSupportSolutionsFramework.exe" | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\HPSupportSolutionsFramework.exe | — | HPSupportSolutionsFramework-12.19.53.13.exe | |||||||||||
User: admin Company: Hewlett-Packard Company Integrity Level: MEDIUM Description: HPSupportSolutionsFramework Exit code: 3221226540 Version: 12.19.53.13 Modules
| |||||||||||||||
| 3516 | rundll32.exe "C:\Users\admin\AppData\Local\Temp\MSI189A.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_2168984 16 FrameworkCSharpCA!FrameworkCSharpCA.CustomActions.CheckHPSARunning | C:\Windows\System32\rundll32.exe | msiexec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3612 | rundll32.exe "C:\Users\admin\AppData\Local\Temp\MSI17ED.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_2168812 6 FrameworkCSharpCA!FrameworkCSharpCA.CustomActions.CheckIfLatestHPSAInstalled | C:\Windows\System32\rundll32.exe | msiexec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3892 | "C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\HPSupportSolutionsFramework.exe" | C:\Users\admin\AppData\Local\Temp\7ZipSfx.000\HPSupportSolutionsFramework.exe | HPSupportSolutionsFramework-12.19.53.13.exe | ||||||||||||
User: admin Company: Hewlett-Packard Company Integrity Level: HIGH Description: HPSupportSolutionsFramework Exit code: 0 Version: 12.19.53.13 Modules
| |||||||||||||||
| 3996 | "C:\Windows\System32\msiexec.exe" /i "C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFramework.msi" /l*v "C:\Users\admin\AppData\Local\Temp\Framework_MSI_20231212-061439.txt" | C:\Windows\System32\msiexec.exe | — | HPSupportSolutionsFramework.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 4008 | rundll32.exe "C:\Users\admin\AppData\Local\Temp\MSI1721.tmp",zzzzInvokeManagedCustomActionOutOfProc SfxCA_2168671 1 FrameworkCSharpCA!FrameworkCSharpCA.CustomActions.CheckIfNewerVersionInstalled | C:\Windows\System32\rundll32.exe | msiexec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 4044 | C:\Windows\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (1996) HPSupportSolutionsFramework-12.19.53.13.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1996) HPSupportSolutionsFramework-12.19.53.13.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1996) HPSupportSolutionsFramework-12.19.53.13.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1996) HPSupportSolutionsFramework-12.19.53.13.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3892) HPSupportSolutionsFramework.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3892) HPSupportSolutionsFramework.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3892) HPSupportSolutionsFramework.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3892) HPSupportSolutionsFramework.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3892) HPSupportSolutionsFramework.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3996) msiexec.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3892 | HPSupportSolutionsFramework.exe | C:\Program Files (x86)\Hewlett-Packard\HP Support Solutions\HPSupportSolutionsFramework.msi | — | |
MD5:— | SHA256:— | |||
| 3612 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\MSI17ED.tmp-\FrameworkCSharpCA.dll | executable | |
MD5:A7E55325073077B9137CB403F0B0B443 | SHA256:088A0BC458EA41B84F5B754E40E134214EB5EB5BE65BD24854C8A29F660EAA99 | |||
| 3612 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\MSI17ED.tmp-\Microsoft.Deployment.WindowsInstaller.dll | executable | |
MD5:73527C4CCFE8C3D2F27FFB4B9D1ADFF2 | SHA256:2DD1998A04BF8AB20DABD3DA8D8CB9F4BE737700AE100260F6F378D667A1A714 | |||
| 3516 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\MSI189A.tmp-\Microsoft.Deployment.WindowsInstaller.dll | executable | |
MD5:73527C4CCFE8C3D2F27FFB4B9D1ADFF2 | SHA256:2DD1998A04BF8AB20DABD3DA8D8CB9F4BE737700AE100260F6F378D667A1A714 | |||
| 4008 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\MSI1721.tmp-\FrameworkCSharpCA.dll | executable | |
MD5:A7E55325073077B9137CB403F0B0B443 | SHA256:088A0BC458EA41B84F5B754E40E134214EB5EB5BE65BD24854C8A29F660EAA99 | |||
| 3516 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\MSI189A.tmp-\FrameworkCSharpCA.dll | executable | |
MD5:A7E55325073077B9137CB403F0B0B443 | SHA256:088A0BC458EA41B84F5B754E40E134214EB5EB5BE65BD24854C8A29F660EAA99 | |||
| 3612 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\MSI17ED.tmp-\CustomAction.config | xml | |
MD5:83BD5A4F4DE927097F45325C2A38D138 | SHA256:EBC7BCFDB1791915853158ADE06E01215328AFA158E7489D9BD92C620A50BF27 | |||
| 3996 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI1721.tmp | executable | |
MD5:BC7824F4E39D3057BC6790A42EED96FB | SHA256:6E17F4BF09B79827B8579D7EBF22BFD73F3751F877EDFD1DB65265E6541BEB69 | |||
| 3516 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\MSI189A.tmp-\CustomAction.config | xml | |
MD5:83BD5A4F4DE927097F45325C2A38D138 | SHA256:EBC7BCFDB1791915853158ADE06E01215328AFA158E7489D9BD92C620A50BF27 | |||
| 4008 | rundll32.exe | C:\Users\admin\AppData\Local\Temp\MSI1721.tmp-\Microsoft.Deployment.WindowsInstaller.dll | executable | |
MD5:73527C4CCFE8C3D2F27FFB4B9D1ADFF2 | SHA256:2DD1998A04BF8AB20DABD3DA8D8CB9F4BE737700AE100260F6F378D667A1A714 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |