| File name: | hlsw32.exe |
| Full analysis: | https://app.any.run/tasks/bb9ff016-a231-4420-9c83-ac42f21dd697 |
| Verdict: | Malicious activity |
| Analysis date: | April 15, 2019, 18:44:25 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 152BC6AE10DB218CBAC08D41F344AD33 |
| SHA1: | D08C6C5AA39D9EBFB1A7A6F69360AD98340ABAAD |
| SHA256: | 1B09BF8646BC17A31D0EC5CC7B5F41B08705C04B1257A500FB7242864ED4269B |
| SSDEEP: | 98304:zDfed53zjlaa8wZqeEhXQ/BvLPGEsJqNUGHek0x5Hb6lD+fL:zCfb1xBjoqNU28b3 |
| .exe | | | Wise Installer executable (91.7) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (5.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (1.2) |
| .exe | | | Win32 Executable (generic) (0.8) |
| .exe | | | Generic Win/DOS Executable (0.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2001:10:25 21:47:11+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 8704 |
| InitializedDataSize: | 5632 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x21af |
| OSVersion: | 4 |
| ImageVersion: | 4 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 12.4455.0.0 |
| ProductVersionNumber: | 12.4455.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows 16-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Aladdin Knowledge Systems |
| FileDescription: | Hardlock Server Installation |
| FileVersion: | 12/2003 |
| LegalCopyright: | Aladdin Knowledge Systems Ltd. © 2003. |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1000 | "C:\Users\admin\AppData\Local\Temp\hlsw32.exe" | C:\Users\admin\AppData\Local\Temp\hlsw32.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1812 | "C:\Users\admin\AppData\Local\Temp\hldrv32.exe" /s | C:\Users\admin\AppData\Local\Temp\hldrv32.exe | hlsw32.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2696 | C:\Windows\system32\HLS32SVC.EXE | C:\Windows\system32\HLS32SVC.EXE | — | services.exe | |||||||||||
User: SYSTEM Company: Aladdin Knowledge Systems Ltd. Integrity Level: SYSTEM Description: HL-Server Service for Windows NT/2k/XP Exit code: 0 Version: 4.60 Modules
| |||||||||||||||
| 3324 | "C:\Users\admin\AppData\Local\Temp\hlsw32.exe" | C:\Users\admin\AppData\Local\Temp\hlsw32.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| (PID) Process: | (1000) hlsw32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hardlock Server |
| Operation: | write | Name: | DisplayName |
Value: Hardlock Server | |||
| (PID) Process: | (1000) hlsw32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hardlock Server |
| Operation: | write | Name: | UninstallString |
Value: C:\PROGRA~1\HL-SER~1\UNWISE.EXE C:\PROGRA~1\HL-SER~1\INSTALL.LOG | |||
| (PID) Process: | (1000) hlsw32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\HLSINST |
| Operation: | write | Name: | HLS32 |
Value: 1 | |||
| (PID) Process: | (1000) hlsw32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (1000) hlsw32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (1812) hldrv32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hardlock Device Driver |
| Operation: | write | Name: | DisplayName |
Value: Hardlock Device Driver | |||
| (PID) Process: | (1812) hldrv32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Hardlock Device Driver |
| Operation: | write | Name: | UninstallString |
Value: C:\Windows\System32\UNWISE.EXE C:\Windows\System32\HLDRV.LOG | |||
| (PID) Process: | (1812) hldrv32.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\HaspCheck |
| Operation: | delete key | Name: | |
Value: | |||
| (PID) Process: | (1812) hldrv32.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\VirtualDeviceDrivers |
| Operation: | write | Name: | VDD |
Value: HLVDD.DLL | |||
| (PID) Process: | (1812) hldrv32.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\hardlock\Parameters |
| Operation: | write | Name: | IoPortAddress0 |
Value: 888 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1000 | hlsw32.exe | C:\Users\admin\AppData\Local\Temp\~GLH0000.TMP | — | |
MD5:— | SHA256:— | |||
| 1000 | hlsw32.exe | C:\Program Files\HL-Server\~GLH0001.TMP | — | |
MD5:— | SHA256:— | |||
| 1000 | hlsw32.exe | C:\Windows\system32\~GLH0002.TMP | — | |
MD5:— | SHA256:— | |||
| 1000 | hlsw32.exe | C:\Program Files\HL-Server\~GLH0003.TMP | — | |
MD5:— | SHA256:— | |||
| 1000 | hlsw32.exe | C:\Program Files\HL-Server\~GLH0004.TMP | — | |
MD5:— | SHA256:— | |||
| 1000 | hlsw32.exe | C:\Program Files\HL-Server\~GLH0005.TMP | — | |
MD5:— | SHA256:— | |||
| 1000 | hlsw32.exe | C:\Program Files\HL-Server\temp.000 | — | |
MD5:— | SHA256:— | |||
| 1000 | hlsw32.exe | C:\PROGRA~1\HL-SER~1\~GLH0006.TMP | — | |
MD5:— | SHA256:— | |||
| 1000 | hlsw32.exe | C:\Program Files\HL-Server\~GLH0007.TMP | — | |
MD5:— | SHA256:— | |||
| 1000 | hlsw32.exe | C:\PROGRA~1\HL-SER~1\~GLH0008.TMP | — | |
MD5:— | SHA256:— | |||