| File name: | 13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.exe |
| Full analysis: | https://app.any.run/tasks/24eccde2-7312-4dc4-95fb-9f096d39cb85 |
| Verdict: | Malicious activity |
| Analysis date: | March 04, 2024, 02:29:30 |
| OS: | Windows 10 Professional (build: 19044, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 3D716D8C6114533BBE1FDA6938B84092 |
| SHA1: | C918F6FC8ECA08C330C5434D46344AC63D31A3E7 |
| SHA256: | 13902861132376C808E304074E537F22435976567BD3E48B959363108AB79389 |
| SSDEEP: | 98304:G+cD4dnHh0N1nb0ZwL0egN9P8YW+HyeY4E9w11TwjyxviGZfeTw4ug4Dr1j1ZfUE:WR8tdT |
| .exe | | | Inno Setup installer (53.5) |
|---|---|---|
| .exe | | | InstallShield setup (21) |
| .exe | | | Win32 EXE PECompact compressed (generic) (20.2) |
| .exe | | | Win32 Executable (generic) (2.1) |
| .exe | | | Win16/32 Executable Delphi generic (1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:02:15 14:54:16+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741888 |
| InitializedDataSize: | 89600 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.1 |
| ProductVersionNumber: | 1.0.0.1 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | PGWARE LLC |
| FileDescription: | Throttle Setup |
| FileVersion: | 1.0.0.1 |
| LegalCopyright: | Copyright © 2001-2022 PGWARE LLC |
| OriginalFileName: | |
| ProductName: | Throttle |
| ProductVersion: | 1.0.0.1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1816 | "C:\Users\admin\AppData\Local\Temp\is-ARVI9.tmp\rk_setup.exe" -c: 3033 -lang: 1 -tpi: PGWARE_THROTTLE | C:\Users\admin\AppData\Local\Temp\is-ARVI9.tmp\rk_setup.exe | 13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.tmp | ||||||||||||
User: admin Company: TMRG Integrity Level: HIGH Description: RelevantKnowledge Setup Setup Exit code: 0 Version: 1.1.0 Modules
| |||||||||||||||
| 2168 | "C:\Users\admin\AppData\Local\Temp\is-BQOJR.tmp\rk_setup.tmp" /SL5="$80158,2145894,832512,C:\Users\admin\AppData\Local\Temp\is-ARVI9.tmp\rk_setup.exe" -c: 3033 -lang: 1 -tpi: PGWARE_THROTTLE | C:\Users\admin\AppData\Local\Temp\is-BQOJR.tmp\rk_setup.tmp | rk_setup.exe | ||||||||||||
User: admin Company: TMRG Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2664 | "C:\Users\admin\AppData\Local\Temp\13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.exe" /SPAWNWND=$90272 /NOTIFYWND=$11004C | C:\Users\admin\AppData\Local\Temp\13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.exe | 13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.tmp | ||||||||||||
User: admin Company: PGWARE LLC Integrity Level: HIGH Description: Throttle Setup Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 2696 | "C:\Users\admin\AppData\Local\Temp\is-K87LT.tmp\13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.tmp" /SL5="$11004C,4523637,832512,C:\Users\admin\AppData\Local\Temp\13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.exe" | C:\Users\admin\AppData\Local\Temp\is-K87LT.tmp\13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.tmp | — | 13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.exe | |||||||||||
User: admin Company: PGWARE LLC Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 5456 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | svchost.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
| 6056 | "C:\Users\admin\AppData\Local\Temp\13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.exe" | C:\Users\admin\AppData\Local\Temp\13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.exe | explorer.exe | ||||||||||||
User: admin Company: PGWARE LLC Integrity Level: MEDIUM Description: Throttle Setup Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 6660 | "C:\Users\admin\AppData\Local\Temp\is-OB6UM.tmp\13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.tmp" /SL5="$8013C,4523637,832512,C:\Users\admin\AppData\Local\Temp\13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.exe" /SPAWNWND=$90272 /NOTIFYWND=$11004C | C:\Users\admin\AppData\Local\Temp\is-OB6UM.tmp\13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.tmp | 13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.exe | ||||||||||||
User: admin Company: PGWARE LLC Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| (PID) Process: | (6660) 13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 041A0000D13EBCD9DB6DDA01 | |||
| (PID) Process: | (6660) 13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: 7A7B65A6DFF8C983C739831ABFE3935134A43A32547A372AFD45CAADB1DC5428 | |||
| (PID) Process: | (6660) 13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (6660) 13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (6660) 13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (6660) 13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (6660) 13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2168) rk_setup.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001 |
| Operation: | write | Name: | Owner |
Value: 78080000EDF269DCDB6DDA01 | |||
| (PID) Process: | (2168) rk_setup.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001 |
| Operation: | write | Name: | SessionHash |
Value: DDB13A88161E5DC477AA583A75EB6744AD8225CE75E5E9A01F27C44DE8D749AD | |||
| (PID) Process: | (2168) rk_setup.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0001 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6660 | 13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.tmp | C:\Users\admin\AppData\Local\Temp\is-ARVI9.tmp\rk_setup.exe | executable | |
MD5:6A38C053466EAB3656074F81DDC00D77 | SHA256:3979455D612A9398808B80B0B6867194A1147D84987DDBAEE707A5F01610213A | |||
| 6056 | 13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.exe | C:\Users\admin\AppData\Local\Temp\is-K87LT.tmp\13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.tmp | executable | |
MD5:034372FA86E28E4DCF1A1D44A9CFCECD | SHA256:F399902F50EECA069DCBCB9F528BA159BCA0EC6072B1216D53BAA6062A38810C | |||
| 1816 | rk_setup.exe | C:\Users\admin\AppData\Local\Temp\is-BQOJR.tmp\rk_setup.tmp | executable | |
MD5:63B305BAA9994EA2A53AD5BD640F3494 | SHA256:A2BDFFBE67FAE5656019BB2ECC2EF708599BF0F10E75FEB64060EBB6553A5352 | |||
| 2664 | 13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.exe | C:\Users\admin\AppData\Local\Temp\is-OB6UM.tmp\13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.tmp | executable | |
MD5:034372FA86E28E4DCF1A1D44A9CFCECD | SHA256:F399902F50EECA069DCBCB9F528BA159BCA0EC6072B1216D53BAA6062A38810C | |||
| 6660 | 13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.tmp | C:\Users\admin\AppData\Local\Temp\is-ARVI9.tmp\idp.dll | executable | |
MD5:55C310C0319260D798757557AB3BF636 | SHA256:54E7E0AD32A22B775131A6288F083ED3286A9A436941377FC20F85DD9AD983ED | |||
| 2168 | rk_setup.tmp | C:\Users\admin\AppData\Local\Temp\is-EKEO6.tmp\CallbackAdapter.dll | executable | |
MD5:94FA1BDAEB995239E459ACA68B5FCD39 | SHA256:F6A85D1DBD81D7796386CA058086147898782A156662EDE5C57377F5CFD1F5F7 | |||
| 6660 | 13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.tmp | C:\Users\admin\AppData\Local\Temp\is-ARVI9.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
| 6660 | 13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.tmp | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\75CA58072B9926F763A91F0CC2798706_056B48C93C4964C2E64C0A8958238656 | binary | |
MD5:6BEC29ED7A3B8082CFCC15D8046D4017 | SHA256:F0C6DC54FC3196B5CE7E9B3CF54B10F81B227E5DE31D458EE53EBCF9C72FD42F | |||
| 2168 | rk_setup.tmp | C:\Users\admin\AppData\Local\Temp\is-EKEO6.tmp\curl-ca-bundle.crt | binary | |
MD5:D8771605855EF563748A3D599854B8DF | SHA256:9FA396BA8B6FDB0A1D5350408A1814CB7658BC08B34F70423939709FAD8480FB | |||
| 2168 | rk_setup.tmp | C:\Users\admin\AppData\Local\Temp\is-EKEO6.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
6660 | 13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.tmp | GET | 200 | 18.66.142.79:80 | http://ocsp.rootca1.amazontrust.com/MFQwUjBQME4wTDAJBgUrDgMCGgUABBRPWaOUU8%2B5VZ5%2Fa9jFTaU9pkK3FAQUhBjMhTTsvAyUlC4IWZzHshBOCggCEwdzEkpLy9ROx7U76vGUhC06D6E%3D | unknown | binary | 1.37 Kb | unknown |
5928 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | binary | 471 b | unknown |
6748 | svchost.exe | GET | 200 | 23.53.41.88:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | binary | 1.01 Kb | unknown |
2052 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D | unknown | binary | 471 b | unknown |
2464 | svchost.exe | GET | 200 | 104.115.228.157:80 | http://x1.c.lencr.org/ | unknown | binary | 717 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3848 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
6748 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
6896 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
5928 | svchost.exe | 40.126.32.72:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
6660 | 13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.tmp | 13.32.121.51:443 | dpd.securestudies.com | AMAZON-02 | US | unknown |
6660 | 13902861132376c808e304074e537f22435976567bd3e48b959363108ab79389.tmp | 18.66.142.79:80 | ocsp.rootca1.amazontrust.com | AMAZON-02 | US | unknown |
5928 | svchost.exe | 192.229.221.95:80 | — | EDGECAST | US | whitelisted |
6748 | svchost.exe | 23.53.41.88:80 | crl.microsoft.com | Akamai International B.V. | DE | unknown |
2168 | rk_setup.tmp | 13.32.121.51:443 | dpd.securestudies.com | AMAZON-02 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
dpd.securestudies.com |
| whitelisted |
ocsp.rootca1.amazontrust.com |
| shared |
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |