| download: | INSTALL.EXE |
| Full analysis: | https://app.any.run/tasks/943f24c9-9773-45bc-9e6d-c5763921647e |
| Verdict: | Malicious activity |
| Analysis date: | January 06, 2020, 21:53:38 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 530A43E24D6D2AF4011EA3A14F84ECBB |
| SHA1: | 21F082D3DF5A3C3E6D8AF78E80C8BAF6541D209B |
| SHA256: | 1551B67CED3C2353D44ED63B06515BB4B0D76443984B347469005A773DC42C94 |
| SSDEEP: | 6144:BjAKmEGlZyjQmTB7v9MXzLjtBzmMm0CqCUCpeexq37IWV+5cSciVRGNSkN1HReAU:nVkojZTBv9YKMWp+UWwqpmmSkvHRdI |
| .exe | | | Win32 Executable MS Visual C++ (generic) (46.3) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (41) |
| .exe | | | Win32 Executable (generic) (6.6) |
| .exe | | | Generic Win/DOS Executable (2.9) |
| .exe | | | DOS Executable Generic (2.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2016:11:30 11:32:01+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 7.1 |
| CodeSize: | 88064 |
| InitializedDataSize: | 123904 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x160b6 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 22.0.2.0 |
| ProductVersionNumber: | 22.0.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Unknown (0) |
| ObjectFileType: | Unknown |
| FileSubtype: | - |
| LanguageCode: | French |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | PC SOFT |
| FileDescription: | WDAutoEx.EXE (Executable auto-extractible) - Win32 |
| FileVersion: | 22.0.2.0 |
| LegalCopyright: | Copyright © PC SOFT 1993-2016 |
| OriginalFileName: | WDAutoEx.EXE |
| Comments: | EB Francais |
| Plateforme: | Win32 UNICODE |
| FileDescriptionUS: | WDAutoEx.EXE (Self-extractible archive) - Win32 |
| ProductName: | WINDEV |
| ProductVersion: | 22.0 (22.0.2.0) VI xxxxxxxxxxxx |
| VersionVI: | xxxxxxxxxxxx |
| Version: | 22.0.2.0 |
| Checksum: | xx |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 30-Nov-2016 10:32:01 |
| Detected languages: |
|
| Debug artifacts: |
|
| CompanyName: | PC SOFT |
| FileDescription: | WDAutoEx.EXE (Executable auto-extractible) - Win32 |
| FileVersion: | 22.0.2.0 |
| LegalCopyright: | Copyright © PC SOFT 1993-2016 |
| OriginalFilename: | WDAutoEx.EXE |
| Comments: | EB Francais |
| Plateforme: | Win32 UNICODE |
| FileDescriptionUS: | WDAutoEx.EXE (Self-extractible archive) - Win32 |
| ProductName: | WINDEV |
| ProductVersion: | 22.0 (22.0.2.0) VI xxxxxxxxxxxx |
| VersionVI: | xxxxxxxxxxxx |
| Version: | 22.0.2.0 |
| Checksum: | xx |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000100 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 4 |
| Time date stamp: | 30-Nov-2016 10:32:01 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x0001564A | 0x00015800 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.60646 |
.rdata | 0x00017000 | 0x0000754F | 0x00007600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.26909 |
.data | 0x0001F000 | 0x00000530 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.40583 |
.rsrc | 0x00020000 | 0x00016A98 | 0x00016C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.06173 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 4.99496 | 487 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 5.04282 | 9640 | Latin 1 / Western European | French - France | RT_ICON |
3 | 5.14795 | 4264 | Latin 1 / Western European | French - France | RT_ICON |
4 | 4.89085 | 1128 | Latin 1 / Western European | French - France | RT_ICON |
20 | 2.87334 | 202 | Latin 1 / Western European | French - France | RT_STRING |
21 | 2.45463 | 108 | Latin 1 / Western European | French - France | RT_STRING |
102 | 4.56671 | 289 | Latin 1 / Western European | French - France | INFOWDZ |
103 | 4.794 | 550 | Latin 1 / Western European | French - France | INFOWDZ |
104 | 3.44531 | 664 | Latin 1 / Western European | French - France | RT_DIALOG |
105 | 2.65982 | 62 | Latin 1 / Western European | French - France | RT_GROUP_ICON |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
MPR.dll |
MSVCRT.dll |
SHELL32.dll |
USER32.dll |
ole32.dll |
Title | Ordinal | Address |
|---|---|---|
CommandeComposante | 1 | 0x000071EC |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1324 | "C:\Users\admin\AppData\Local\Temp\WD_A727.tmp\INSTALL.EXE" | C:\Users\admin\AppData\Local\Temp\WD_A727.tmp\INSTALL.EXE | INSTALL.EXE | ||||||||||||
User: admin Company: PC SOFT Integrity Level: MEDIUM Description: PreInstall.exe (Pré-Installateur) - Win32 Exit code: 0 Version: 23.0.4.0 Modules
| |||||||||||||||
| 1936 | "C:\Users\admin\AppData\Local\Temp\WDAD51.tmp\WDSetup.EXE" /IDIPC=4215d0af0a7d4c968968e0f4fb931746:13546 /NOCHKADMIN /REP="C:\Users\admin\AppData\Local\Temp\WDAD51.tmp\" /PID_PARENT=1324 /VERSION_PARENT=23 /COMPOSITE=0 /WXF="C:\Users\admin\AppData\Local\Temp\WDAD51.tmp\INST.WXF" "C:\Users\admin\AppData\Local\Temp\WD_A727.tmp\INSTALL.EXE" | C:\Users\admin\AppData\Local\Temp\WDAD51.tmp\WDSetup.EXE | WDSetup.EXE | ||||||||||||
User: admin Company: PC SOFT Integrity Level: HIGH Description: Outil d'installation Exit code: 0 Version: 23.0.23.0 Modules
| |||||||||||||||
| 2600 | "C:\Users\admin\AppData\Local\Temp\INSTALL.EXE" | C:\Users\admin\AppData\Local\Temp\INSTALL.EXE | explorer.exe | ||||||||||||
User: admin Company: PC SOFT Integrity Level: MEDIUM Description: WDAutoEx.EXE (Executable auto-extractible) - Win32 Exit code: 0 Version: 22.0.2.0 Modules
| |||||||||||||||
| 3456 | "C:\Program Files\UNI-Associations\UNI-Associations.exe" | C:\Program Files\UNI-Associations\UNI-Associations.exe | WDSetup.EXE | ||||||||||||
User: admin Company: Spordle Inc Integrity Level: MEDIUM Description: Logiciel UNI-Association Exit code: 0 Version: 1.220720F Modules
| |||||||||||||||
| 3924 | "C:\Users\admin\AppData\Local\Temp\WDAD51.tmp\WDSetup.EXE" /REP="C:\Users\admin\AppData\Local\Temp\WDAD51.tmp\" /PID_PARENT=1324 /VERSION_PARENT=23 /COMPOSITE=0 /WXF="C:\Users\admin\AppData\Local\Temp\WDAD51.tmp\INST.WXF" "C:\Users\admin\AppData\Local\Temp\WD_A727.tmp\INSTALL.EXE" | C:\Users\admin\AppData\Local\Temp\WDAD51.tmp\WDSetup.EXE | — | INSTALL.EXE | |||||||||||
User: admin Company: PC SOFT Integrity Level: MEDIUM Description: Outil d'installation Exit code: 0 Version: 23.0.23.0 Modules
| |||||||||||||||
| (PID) Process: | (2600) INSTALL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2600) INSTALL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (1324) INSTALL.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\INSTALL_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (1324) INSTALL.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\INSTALL_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (1324) INSTALL.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\INSTALL_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (1324) INSTALL.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\INSTALL_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (1324) INSTALL.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\INSTALL_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (1324) INSTALL.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\INSTALL_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
| (PID) Process: | (1324) INSTALL.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\INSTALL_RASMANCS |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (1324) INSTALL.EXE | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\INSTALL_RASMANCS |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2600 | INSTALL.EXE | C:\Users\admin\AppData\Local\Temp\WD_A727.tmp\INSTALL.EXE | executable | |
MD5:689938DDC1B696F274155EB3E17CE660 | SHA256:02875DF0CD65DE335056F7AEFEBE2D9145F83B31F2E5FD54701CFE56CBE1FB8F | |||
| 1324 | INSTALL.EXE | C:\Users\admin\AppData\Local\Temp\WDAD51.tmp\WDMetabase.dll | executable | |
MD5:— | SHA256:— | |||
| 1324 | INSTALL.EXE | C:\Users\admin\AppData\Local\Temp\WDAD51.tmp\wd230hf.dll | executable | |
MD5:1AC565716B20517870E2A67BED6C916E | SHA256:16A8AB2B38E90104ABB62FA5F8182204D38E1AE1C59D564957C99FB8EA6CA703 | |||
| 1324 | INSTALL.EXE | C:\Users\admin\AppData\Local\Temp\WDAD51.tmp\wd230mat.dll | executable | |
MD5:03A366021002A5720CB91678380BD643 | SHA256:32D9DA12D6E02B58DB34AD757592FC2DEA5B4A7BEB56D3A18433B8D54CB3D87F | |||
| 1324 | INSTALL.EXE | C:\Users\admin\AppData\Local\Temp\WDAD51.tmp\INST.WXF | txt | |
MD5:— | SHA256:— | |||
| 1324 | INSTALL.EXE | C:\Users\admin\AppData\Local\Temp\WDAD51.tmp\wd230mdl.dll | executable | |
MD5:538B7A635295AF4FC7D5B90A38277359 | SHA256:3A84351C858B34D1A620E2B28E44F517414692324CCD36F5FC06A2626BCE2821 | |||
| 1324 | INSTALL.EXE | C:\Users\admin\AppData\Local\Temp\WDAD51.tmp\INSTALL.ZIP | compressed | |
MD5:— | SHA256:— | |||
| 1324 | INSTALL.EXE | C:\Users\admin\AppData\Local\Temp\WDAD51.tmp\wd230pnt.dll | executable | |
MD5:6EA7D4879F0DC890CA31CA76DF2F1EB0 | SHA256:9B48E14240DAC988CFA8E3B06DB12915B09AE5573714C6B75CFC3A25787715E9 | |||
| 1324 | INSTALL.EXE | C:\Users\admin\AppData\Local\Temp\WDAD51.tmp\wd230xml.dll | executable | |
MD5:AFD5347F17529C2D01F442AB6C635CF4 | SHA256:CB9884C308A5B30AC42310320B8C28BCF2E71EE9E03B914823A1C2AFE8F3A961 | |||
| 1324 | INSTALL.EXE | C:\Users\admin\AppData\Local\Temp\WDAD51.tmp\wd230trs.dll | executable | |
MD5:BA08AFFF6DBF3F5372832C63C798F2E1 | SHA256:CD5CFEC49AA70A669CA62D38B8A888D91494FACCF976FB325205EF306C9C5D3D | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1936 | WDSetup.EXE | GET | 200 | 184.107.166.26:80 | http://update.publicationsports.com/associations/INSTALL/__WDINST.ZIP | CA | compressed | 71.1 Mb | unknown |
1324 | INSTALL.EXE | GET | 200 | 184.107.166.26:80 | http://update.publicationsports.com/associations/INSTALL/INSTALL.ZIP | CA | compressed | 24.6 Mb | unknown |
1936 | WDSetup.EXE | GET | 200 | 184.107.166.26:80 | http://update.publicationsports.com/associations/INSTALL/_FRAMEWORK.ZIP | CA | compressed | 19.2 Mb | unknown |
3456 | UNI-Associations.exe | GET | 200 | 184.107.166.26:80 | http://update.publicationsports.com/associations/INSTALL/WDUPDATE.NET | CA | text | 670 b | unknown |
1936 | WDSetup.EXE | GET | 200 | 184.107.166.26:80 | http://update.publicationsports.com/associations/INSTALL/_UPDATE.ZIP | CA | compressed | 4.91 Mb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1324 | INSTALL.EXE | 184.107.166.26:80 | update.publicationsports.com | iWeb Technologies Inc. | CA | unknown |
3456 | UNI-Associations.exe | 184.107.166.26:80 | update.publicationsports.com | iWeb Technologies Inc. | CA | unknown |
3456 | UNI-Associations.exe | 174.142.75.172:3306 | uni.publicationsports.com | iWeb Technologies Inc. | CA | unknown |
3456 | UNI-Associations.exe | 192.175.107.237:3306 | — | iWeb Technologies Inc. | CA | unknown |
1936 | WDSetup.EXE | 184.107.166.26:80 | update.publicationsports.com | iWeb Technologies Inc. | CA | unknown |
Domain | IP | Reputation |
|---|---|---|
update.publicationsports.com |
| unknown |
uni.publicationsports.com |
| unknown |