| File name: | spywareguardsetup.exe |
| Full analysis: | https://app.any.run/tasks/49058fe1-26cd-41d6-b59c-0cc948897300 |
| Verdict: | Malicious activity |
| Analysis date: | February 24, 2024, 16:56:57 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, InnoSetup self-extracting archive |
| MD5: | 14CE452049D0FC3F34B4B9CE56DCEE60 |
| SHA1: | E2432FA050EDFA7F19B88C00F25C723F3940CFF2 |
| SHA256: | 173AA92938B5B1BFC6C888F8FF435BDAC068B7F295C93887D41515A99E01CE24 |
| SSDEEP: | 98304:4GQSPCl52tnMuDPY6sBVMBnFUg8NMZqiePQ+8ypkv8h6872cHd7wjWXmD4B8zbkY:po81bN |
| .exe | | | Inno Setup installer (82.8) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (10.7) |
| .exe | | | Win32 Executable (generic) (3.4) |
| .exe | | | Generic Win/DOS Executable (1.5) |
| .exe | | | DOS Executable Generic (1.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:19 22:22:17+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 46592 |
| InitializedDataSize: | 16384 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xbed8 |
| OSVersion: | 1 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 240 | "C:\Program Files\SpywareGuard\sgliveupdate.exe" | C:\Program Files\SpywareGuard\sgliveupdate.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: SpywareGuard LiveUpdate Exit code: 3221226540 Version: 2.02.0001 Modules
| |||||||||||||||
| 1624 | "C:\Program Files\SpywareGuard\sgmain.exe" | C:\Program Files\SpywareGuard\sgmain.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: SpywareGuard Exit code: 0 Version: 2.02.0001 Modules
| |||||||||||||||
| 1824 | "C:\Program Files\SpywareGuard\sgliveupdate.exe" | C:\Program Files\SpywareGuard\sgliveupdate.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: SpywareGuard LiveUpdate Exit code: 0 Version: 2.02.0001 Modules
| |||||||||||||||
| 2208 | "C:\Program Files\SpywareGuard\sgliveupdate.exe" | C:\Program Files\SpywareGuard\sgliveupdate.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: SpywareGuard LiveUpdate Exit code: 3221226540 Version: 2.02.0001 Modules
| |||||||||||||||
| 2340 | "C:\Program Files\SpywareGuard\sgbhp.exe" | C:\Program Files\SpywareGuard\sgbhp.exe | — | sgmain.exe | |||||||||||
User: admin Integrity Level: HIGH Description: SG Browser Hijacking Protection Exit code: 0 Version: 2.02.0001 Modules
| |||||||||||||||
| 2472 | "C:\Users\admin\AppData\Local\Temp\spywareguardsetup.exe" | C:\Users\admin\AppData\Local\Temp\spywareguardsetup.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 2576 | "C:\Program Files\SpywareGuard\sgmain.exe" | C:\Program Files\SpywareGuard\sgmain.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: SpywareGuard Exit code: 0 Version: 2.02.0001 Modules
| |||||||||||||||
| 2624 | "C:\Program Files\SpywareGuard\sgmain.exe" | C:\Program Files\SpywareGuard\sgmain.exe | — | INSF741.tmp | |||||||||||
User: admin Integrity Level: HIGH Description: SpywareGuard Exit code: 0 Version: 2.02.0001 Modules
| |||||||||||||||
| 2668 | "C:\Program Files\SpywareGuard\sgmain.exe" | C:\Program Files\SpywareGuard\sgmain.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: SpywareGuard Exit code: 0 Version: 2.02.0001 Modules
| |||||||||||||||
| 2744 | "C:\Program Files\SpywareGuard\sgliveupdate.exe" | C:\Program Files\SpywareGuard\sgliveupdate.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: SpywareGuard LiveUpdate Exit code: 0 Version: 2.02.0001 Modules
| |||||||||||||||
| (PID) Process: | (3216) INSF741.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs |
| Operation: | write | Name: | C:\Windows\system32\MSINET.OCX |
Value: 1 | |||
| (PID) Process: | (3216) INSF741.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs |
| Operation: | write | Name: | C:\Windows\system32\RICHTX32.OCX |
Value: 1 | |||
| (PID) Process: | (3216) INSF741.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs |
| Operation: | write | Name: | C:\Windows\system32\stdole2.tlb |
Value: 2 | |||
| (PID) Process: | (3216) INSF741.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs |
| Operation: | write | Name: | C:\Windows\system32\msvbvm60.dll |
Value: 2 | |||
| (PID) Process: | (3216) INSF741.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs |
| Operation: | write | Name: | C:\Windows\system32\oleaut32.dll |
Value: 2 | |||
| (PID) Process: | (3216) INSF741.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs |
| Operation: | write | Name: | C:\Windows\system32\olepro32.dll |
Value: 2 | |||
| (PID) Process: | (3216) INSF741.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs |
| Operation: | write | Name: | C:\Windows\system32\asycfilt.dll |
Value: 2 | |||
| (PID) Process: | (3216) INSF741.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs |
| Operation: | write | Name: | C:\Windows\system32\comcat.dll |
Value: 2 | |||
| (PID) Process: | (3216) INSF741.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved |
| Operation: | write | Name: | {81559C35-8464-49F7-BB0E-07A383BEF910} |
Value: | |||
| (PID) Process: | (3216) INSF741.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer\ShellExecuteHooks |
| Operation: | write | Name: | {81559C35-8464-49F7-BB0E-07A383BEF910} |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3708 | spywareguardsetup.exe | C:\Users\admin\AppData\Local\Temp\INSF741.tmp | executable | |
MD5:99FA571A302C7E8ED49D149C1C700623 | SHA256:D2E9C5966937BEADBA64D89D3CE31212C61A85118D9662ADB98FDEAC1AD6EB44 | |||
| 3216 | INSF741.tmp | C:\Users\admin\AppData\Local\Temp\is-G425L.tmp\_isbunzp.dll | executable | |
MD5:59A7E0FA5404DB5E9F1F18E2A2F69797 | SHA256:5BCC823BA75C9BF6A8E01101EB5CEE690FD3DCB2D635432AD4E26BF76024954C | |||
| 3216 | INSF741.tmp | C:\Program Files\SpywareGuard\sgmain.exe | executable | |
MD5:61C028ABA5E49573A6332F4A7C744E87 | SHA256:69CCD902F1A62237F98DF5134483DA51DBB459EFDA94D6130790BA478A2AA467 | |||
| 3216 | INSF741.tmp | C:\Program Files\SpywareGuard\is-K8AFN.tmp | text | |
MD5:40EE7B133696D747B5806953E16134E6 | SHA256:017142478E3AC208E027FCA7AEFD963577A564F8BFF46793A05F6340B796A31D | |||
| 3216 | INSF741.tmp | C:\Program Files\SpywareGuard\def2.dtb | ini | |
MD5:6B9EC873774E555612CAC3F29445515C | SHA256:75680E802CF43407BCE6D9E76FCF8947BE6279931B7433F793F320F451FB9BC3 | |||
| 3216 | INSF741.tmp | C:\Program Files\SpywareGuard\is-7G64R.tmp | ini | |
MD5:6B9EC873774E555612CAC3F29445515C | SHA256:75680E802CF43407BCE6D9E76FCF8947BE6279931B7433F793F320F451FB9BC3 | |||
| 3216 | INSF741.tmp | C:\Program Files\SpywareGuard\is-IMQDD.tmp | ini | |
MD5:19BC9BBA7A71C34C3A618FCF53BF9ECB | SHA256:56BC809CF27E088194BC0F41ACD339F29D65E5B5E5D0061BBABDEB75D2C48DF1 | |||
| 3216 | INSF741.tmp | C:\Program Files\SpywareGuard\def1.dtb | ini | |
MD5:1513962462F96DB20758841581B3E30B | SHA256:F00AAFA57F6F3474EA2328FDF187BAE8895456DB5956B77E8F9BAAF12CD31024 | |||
| 3216 | INSF741.tmp | C:\Program Files\SpywareGuard\dlbdata1.dtb | ini | |
MD5:19BC9BBA7A71C34C3A618FCF53BF9ECB | SHA256:56BC809CF27E088194BC0F41ACD339F29D65E5B5E5D0061BBABDEB75D2C48DF1 | |||
| 3216 | INSF741.tmp | C:\Program Files\SpywareGuard\dlbdata2.dtb | ini | |
MD5:F3F70B68D9F96AE7617C72A10E915683 | SHA256:11C1EB4E2D6984C652ADB643909EF97A4737949AFC54919F265296A8CA0FD610 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1824 | sgliveupdate.exe | GET | 301 | 67.225.152.77:80 | http://www.javacoolsoftware.com/spywareguardversion.txt | unknown | html | 257 b | unknown |
1824 | sgliveupdate.exe | GET | 200 | 67.225.152.78:80 | http://www.brightfort.com/spywareguardversion.txt | unknown | text | 504 b | unknown |
1824 | sgliveupdate.exe | GET | 301 | 67.225.152.77:80 | http://www.javacoolsoftware.com/spywareguard/def1.dtb | unknown | html | 255 b | unknown |
1824 | sgliveupdate.exe | GET | 206 | 67.225.152.78:80 | http://www.brightfort.com/spywareguard/def1.dtb | unknown | text | 16.1 Kb | unknown |
1824 | sgliveupdate.exe | GET | 301 | 67.225.152.77:80 | http://www.javacoolsoftware.com/spywareguard/def2.dtb | unknown | html | 255 b | unknown |
1824 | sgliveupdate.exe | GET | 206 | 67.225.152.78:80 | http://www.brightfort.com/spywareguard/def2.dtb | unknown | text | 9.96 Kb | unknown |
1824 | sgliveupdate.exe | GET | 301 | 67.225.152.77:80 | http://www.javacoolsoftware.com/spywareguard/dlbdata1.dtb | unknown | html | 259 b | unknown |
1824 | sgliveupdate.exe | GET | 206 | 67.225.152.78:80 | http://www.brightfort.com/spywareguard/dlbdata1.dtb | unknown | text | 9.10 Kb | unknown |
1824 | sgliveupdate.exe | GET | 301 | 67.225.152.77:80 | http://www.javacoolsoftware.com/spywareguard/dlbdata2.dtb | unknown | html | 259 b | unknown |
1824 | sgliveupdate.exe | GET | 206 | 67.225.152.78:80 | http://www.brightfort.com/spywareguard/dlbdata2.dtb | unknown | text | 9.58 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1824 | sgliveupdate.exe | 67.225.152.77:80 | www.javacoolsoftware.com | LIQUIDWEB | US | unknown |
1824 | sgliveupdate.exe | 67.225.152.78:80 | www.brightfort.com | LIQUIDWEB | US | unknown |
2744 | sgliveupdate.exe | 67.225.152.77:80 | www.javacoolsoftware.com | LIQUIDWEB | US | unknown |
2744 | sgliveupdate.exe | 67.225.152.78:80 | www.brightfort.com | LIQUIDWEB | US | unknown |
Domain | IP | Reputation |
|---|---|---|
www.javacoolsoftware.com |
| unknown |
www.brightfort.com |
| unknown |