File name: | 02469657_3 |
Full analysis: | https://app.any.run/tasks/0647c3a0-a978-4228-8cf1-ee482c2953a1 |
Verdict: | Malicious activity |
Analysis date: | April 08, 2021, 23:52:35 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 1E4D916BE5D3E531F3D32405D4183425 |
SHA1: | DD040D37717CF9066EC512FD1E31F4BF4E0E0792 |
SHA256: | 115A90E61AC5BA58A14CF26D71D4C4F4AA59281587AFFF2F86DAFEB8FDF996F1 |
SSDEEP: | 196608:tCSnuVYkuK3dj1HpyqJ2bDKHkcBqtKWi75/Mwiyk01YulN+ukqcTCPqg:cSuVduuWaSMNTewh1YuBBcmPT |
.exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
---|---|---|
.exe | | | Win64 Executable (generic) (37.3) |
.dll | | | Win32 Dynamic Link Library (generic) (8.8) |
.exe | | | Win32 Executable (generic) (6) |
.exe | | | Generic Win/DOS Executable (2.7) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2012:02:24 20:20:04+01:00 |
PEType: | PE32 |
LinkerVersion: | 10 |
CodeSize: | 29696 |
InitializedDataSize: | 489984 |
UninitializedDataSize: | 16896 |
EntryPoint: | 0x38af |
OSVersion: | 5 |
ImageVersion: | 6 |
SubsystemVersion: | 5 |
Subsystem: | Windows GUI |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 24-Feb-2012 19:20:04 |
Detected languages: |
|
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x0090 |
Pages in file: | 0x0003 |
Relocations: | 0x0000 |
Size of header: | 0x0004 |
Min extra paragraphs: | 0x0000 |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x00B8 |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0000 |
Overlay number: | 0x0000 |
OEM identifier: | 0x0000 |
OEM information: | 0x0000 |
Address of NE header: | 0x000000D0 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 6 |
Time date stamp: | 24-Feb-2012 19:20:04 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x0000728C | 0x00007400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.49971 |
.rdata | 0x00009000 | 0x00002B6E | 0x00002C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.49793 |
.data | 0x0000C000 | 0x00072B9C | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.80494 |
.ndata | 0x0007F000 | 0x00089000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x00108000 | 0x000015A8 | 0x00001600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.46221 |
.reloc | 0x0010A000 | 0x00000FD6 | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.0715 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 5.21266 | 726 | UNKNOWN | English - United States | RT_MANIFEST |
103 | 1.91924 | 20 | UNKNOWN | English - United States | RT_GROUP_ICON |
105 | 2.66174 | 256 | UNKNOWN | English - United States | RT_DIALOG |
106 | 2.88094 | 284 | UNKNOWN | English - United States | RT_DIALOG |
111 | 2.48825 | 96 | UNKNOWN | English - United States | RT_DIALOG |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
SHELL32.dll |
USER32.dll |
VERSION.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
3712 | "C:\Users\admin\AppData\Local\Temp\02469657_3.exe" | C:\Users\admin\AppData\Local\Temp\02469657_3.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
|
PID | Process | Filename | Type | |
---|---|---|---|---|
3712 | 02469657_3.exe | C:\ProgramData\NVIDIA\Updatus\ApplicationOntology\data\icons\american_truck_simulator.png | image | |
MD5:8D3ACC0280A00070DA3F9C571030D556 | SHA256:A5AD48685EF8BACC7D6DAD76C2290F528ABE7419368BCD0A34DD1AF91DDF0B75 | |||
3712 | 02469657_3.exe | C:\ProgramData\NVIDIA\Updatus\ApplicationOntology\data\icons\ashes_of_the_singularity.png | image | |
MD5:3F6F49E9DD63312952542A86AECBF28C | SHA256:2EFE72FF4FB8D59840740E316E7D7A49F4B70AE606484887A3BEDE4005ED134D | |||
3712 | 02469657_3.exe | C:\ProgramData\NVIDIA\Updatus\ApplicationOntology\data\icons\assassins_creed_iii.png | image | |
MD5:1BE5D1D7146057FE66FD3F45447AF8CF | SHA256:7AAE19D690CABE9B19F43DFE6951C6BE091E9EA0A2AE7D72040143AC457AC1BD | |||
3712 | 02469657_3.exe | C:\ProgramData\NVIDIA\Updatus\ApplicationOntology\data\icons\ark_survival_evolved.png | image | |
MD5:59A2D119CA805F5ECEA9D2837CE2B307 | SHA256:39AAFC7FA3BE7E5F8B122B9F552064709B1E1D68604C111B81BEF3C9CF5A28B8 | |||
3712 | 02469657_3.exe | C:\ProgramData\NVIDIA\Updatus\ApplicationOntology\data\icons\7_days_to_die.png | image | |
MD5:814CA8C187F731FAD8D4FFE431DB8428 | SHA256:E57C25F2947D2B2668C192B77889754031993822A7B957E5157326A3983FE0DA | |||
3712 | 02469657_3.exe | C:\ProgramData\NVIDIA\Updatus\ApplicationOntology\data\icons\alice_vr.png | image | |
MD5:25143EE5BD93F18C8A811DDFAA16110B | SHA256:F888D64F878224DE0E2A1532D1EFDB263859624A112CBFAA5F6E4FB9C411F4C5 | |||
3712 | 02469657_3.exe | C:\ProgramData\NVIDIA\Updatus\ApplicationOntology\data\icons\arma_2_operation_arrowhead.png | image | |
MD5:8E6509560F12AD5213A1366EAF50A076 | SHA256:6DFBE1E86745A09ADC875530C26CE6BF306C91914DBF5B130113CF5CD05789BB | |||
3712 | 02469657_3.exe | C:\ProgramData\NVIDIA\Updatus\ApplicationOntology\data\icons\aion.png | image | |
MD5:3F1CEC429F46FF0327535B8324F6EB49 | SHA256:7C3DDAE99D46F31A2866AD2A34F90DA47A3E30E96A0C8E5C27F3FEFB19166F58 | |||
3712 | 02469657_3.exe | C:\ProgramData\NVIDIA\Updatus\ApplicationOntology\data\icons\assassins_creed_iv.png | image | |
MD5:5F0178862C361319B53339DBAB473A0C | SHA256:45150FAA9D865F07DBABAB69E160D080866403F051B1385549D2884479D1E771 | |||
3712 | 02469657_3.exe | C:\ProgramData\NVIDIA\Updatus\ApplicationOntology\data\icons\ace_combat_assault_horizon.png | image | |
MD5:65F4DD3955CAA2A2CFC1B231042D53CE | SHA256:CB992E991CE8B897AA85925C70E5D5CDDABD9856B495D8F176669C9517ABB594 |