File name: | 1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0 |
Full analysis: | https://app.any.run/tasks/f641fcbb-b53e-4abe-9e55-ac472aae252a |
Verdict: | Malicious activity |
Analysis date: | December 06, 2022, 03:09:50 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 519BE4854BF61C1199C50974B74FF3F5 |
SHA1: | 7AE6AB717D2E44FB02F493FBD2ED1DE9FC5D7050 |
SHA256: | 1C749421CFF2C00B4D18E08EEACFB970A3D2FE4636B324BEC711A172C0A487B0 |
SSDEEP: | 12288:pljDkWrnvA1/hEcya1p07k2GNehSQ2okRDVbaehj/CD:pVDjrvwlyaBJsYxouDcehrCD |
.exe | | | Inno Setup installer (71.1) |
---|---|---|
.exe | | | Win32 Executable Delphi generic (9.1) |
.scr | | | Windows screen saver (8.4) |
.dll | | | Win32 Dynamic Link Library (generic) (4.2) |
.exe | | | Win32 Executable (generic) (2.9) |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 1992-Jun-19 22:22:17 |
Detected languages: |
|
Comments: | ´Ë°²×°³ÌÐòÓÉ Inno Setup ¹¹½¨¡£ |
CompanyName: | 深圳航天信息有限公司 |
FileDescription: | MonitorFPKPVer.exe |
FileVersion: | 1.0.21.1230 |
LegalCopyright: | 2018 深圳航信 |
ProductName: | MonitorFPKPVer |
ProductVersion: | 1.0.21.1230 |
e_magic: | MZ |
---|---|
e_cblp: | 80 |
e_cp: | 2 |
e_crlc: | - |
e_cparhdr: | 4 |
e_minalloc: | 15 |
e_maxalloc: | 65535 |
e_ss: | - |
e_sp: | 184 |
e_csum: | - |
e_ip: | - |
e_cs: | - |
e_ovno: | 26 |
e_oemid: | - |
e_oeminfo: | - |
e_lfanew: | 256 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
NumberofSections: | 8 |
TimeDateStamp: | 1992-Jun-19 22:22:17 |
PointerToSymbolTable: | - |
NumberOfSymbols: | - |
SizeOfOptionalHeader: | 224 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
CODE | 4096 | 41828 | 41984 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.70808 |
DATA | 49152 | 592 | 1024 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.75232 |
BSS | 53248 | 3720 | 0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | |
.idata | 57344 | 2380 | 2560 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.42897 |
.tls | 61440 | 8 | 0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | |
.rdata | 65536 | 24 | 512 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED | 0.190489 |
.reloc | 69632 | 2244 | 0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED | |
.rsrc | 73728 | 9555 | 9728 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED | 4.99151 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 3.25755 | 296 | UNKNOWN | Dutch - Netherlands | RT_ICON |
2 | 3.47151 | 1384 | UNKNOWN | Dutch - Netherlands | RT_ICON |
3 | 3.91708 | 744 | UNKNOWN | Dutch - Netherlands | RT_ICON |
4 | 3.91366 | 2216 | UNKNOWN | Dutch - Netherlands | RT_ICON |
4089 | 5.50613 | 322 | UNKNOWN | UNKNOWN | RT_STRING |
4090 | 5.62693 | 278 | UNKNOWN | UNKNOWN | RT_STRING |
4091 | 5.87174 | 254 | UNKNOWN | UNKNOWN | RT_STRING |
4093 | 2.86149 | 104 | UNKNOWN | UNKNOWN | RT_STRING |
4094 | 3.20731 | 180 | UNKNOWN | UNKNOWN | RT_STRING |
4095 | 3.04592 | 174 | UNKNOWN | UNKNOWN | RT_STRING |
advapi32.dll |
advapi32.dll (#2) |
comctl32.dll |
kernel32.dll |
kernel32.dll (#2) |
oleaut32.dll |
user32.dll |
user32.dll (#2) |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
1580 | "C:\Users\admin\AppData\Local\Temp\1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.exe" | C:\Users\admin\AppData\Local\Temp\1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.exe | — | Explorer.EXE |
User: admin Company: 深圳航天信息有限公司 Integrity Level: MEDIUM Description: MonitorFPKPVer.exe Exit code: 3221226540 Version: 1.0.21.1230 | ||||
2988 | "C:\Users\admin\AppData\Local\Temp\1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.exe" | C:\Users\admin\AppData\Local\Temp\1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.exe | Explorer.EXE | |
User: admin Company: 深圳航天信息有限公司 Integrity Level: HIGH Description: MonitorFPKPVer.exe Exit code: 0 Version: 1.0.21.1230 | ||||
3204 | "C:\Users\admin\AppData\Local\Temp\is-676AO.tmp\1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.tmp" /SL5="$60198,258993,56832,C:\Users\admin\AppData\Local\Temp\1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.exe" | C:\Users\admin\AppData\Local\Temp\is-676AO.tmp\1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.tmp | 1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.exe | |
User: admin Integrity Level: HIGH Description: °²×°/жÔØ Exit code: 0 Version: 51.52.0.0 | ||||
3200 | "C:\MonitorFPKPVer\Run\MonitorFPKPVer.exe" Wait | C:\MonitorFPKPVer\Run\MonitorFPKPVer.exe | 1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.tmp | |
User: admin Integrity Level: HIGH Description: MonitorFPKPVer Version: 1.0.21.1230 |
(PID) Process: | (3204) 1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | Owner |
Value: 840C000012C1C2382009D901 | |||
(PID) Process: | (3204) 1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | SessionHash |
Value: FBC4213FBA97769CD959B08D92CCA80DE0E462E39F40736F28FB3CC14E094716 | |||
(PID) Process: | (3204) 1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | Sequence |
Value: 1 | |||
(PID) Process: | (3204) 1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | RegFiles0000 |
Value: C:\MonitorFPKPVer\Run\MonitorFPKPVer.exe | |||
(PID) Process: | (3204) 1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | RegFilesHash |
Value: 30D7D57A3ABBC5CED12BC4C93415754910E30AF648A74D11635A48855799C0B5 | |||
(PID) Process: | (3204) 1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | delete value | Name: | RegFilesHash |
Value: 30D7D57A3ABBC5CED12BC4C93415754910E30AF648A74D11635A48855799C0B5 | |||
(PID) Process: | (3204) 1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | delete value | Name: | RegFiles0000 |
Value: C:\MonitorFPKPVer\Run\MonitorFPKPVer.exe | |||
(PID) Process: | (3204) 1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | delete value | Name: | Sequence |
Value: 1 | |||
(PID) Process: | (3204) 1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | delete value | Name: | SessionHash |
Value: FBC4213FBA97769CD959B08D92CCA80DE0E462E39F40736F28FB3CC14E094716 | |||
(PID) Process: | (3204) 1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | delete value | Name: | Owner |
Value: 840C000012C1C2382009D901 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3204 | 1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.tmp | C:\MonitorFPKPVer\Run\Interop.TaskScheduler.dll | executable | |
MD5:22D17D02CA0C5BD9ECA14C2F9B216C47 | SHA256:2ABD39E50FE45774F9CA687006A0BE6C7C5FA66E04E5E41B561869A002C2C0D1 | |||
3204 | 1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.tmp | C:\Users\admin\AppData\Local\Temp\is-2RUHU.tmp\IsTaskEx.dll | executable | |
MD5:C42DC406FE541F9801F1F27ECB9864A8 | SHA256:5A7ECE17CA1F0AB3266F5CE01EDAA76A093744C7F507DEDFB8AA6AC1F714FDDA | |||
3200 | MonitorFPKPVer.exe | C:\MonitorFPKPVer\Run\MonitorFpkpVer\Log2022-12-06.log | text | |
MD5:20956E4FDFF2276E99CF18CD48AAEDBB | SHA256:3A9618D57D7850E6D84B75F3DC75254FDE403A15D33B6814722869A27F7576E2 | |||
3204 | 1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.tmp | C:\MonitorFPKPVer\Run\MonitorFPKPVer.exe | executable | |
MD5:DD0CCA1A7B55EC57A999F51845064941 | SHA256:3D3574E5190D9C2ECCFB8258D0478936D4F4B1ABEF48D2D787C90EFAFAC82F48 | |||
3204 | 1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.tmp | C:\MonitorFPKPVer\Run\is-0UDLL.tmp | executable | |
MD5:22D17D02CA0C5BD9ECA14C2F9B216C47 | SHA256:2ABD39E50FE45774F9CA687006A0BE6C7C5FA66E04E5E41B561869A002C2C0D1 | |||
3204 | 1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.tmp | C:\MonitorFPKPVer\Run\is-L73BM.tmp | executable | |
MD5:7E1B749EB09C62748DF22EB61756EF7D | SHA256:767F30AC2372F1C350307BE7D4900CA3A85EAD4065B9A68234045C9BAF775D89 | |||
3204 | 1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.tmp | C:\MonitorFPKPVer\Run\Interop.IWshRuntimeLibrary.dll | executable | |
MD5:7E1B749EB09C62748DF22EB61756EF7D | SHA256:767F30AC2372F1C350307BE7D4900CA3A85EAD4065B9A68234045C9BAF775D89 | |||
3204 | 1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.tmp | C:\MonitorFPKPVer\Run\is-3JVR4.tmp | executable | |
MD5:DD0CCA1A7B55EC57A999F51845064941 | SHA256:3D3574E5190D9C2ECCFB8258D0478936D4F4B1ABEF48D2D787C90EFAFAC82F48 | |||
3204 | 1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.tmp | C:\MonitorFPKPVer\Run\ICSharpCode.SharpZipLib.dll | executable | |
MD5:70ECB43C490ED5B16DAFAFF662BF7653 | SHA256:B4CBA17E1123333356BF7E80A20E3ADFFD8EC335C14DA1A249D1B10F3D7CFD0B | |||
3204 | 1c749421cff2c00b4d18e08eeacfb970a3d2fe4636b324bec711a172c0a487b0.tmp | C:\MonitorFPKPVer\Run\is-TUMNB.tmp | executable | |
MD5:70ECB43C490ED5B16DAFAFF662BF7653 | SHA256:B4CBA17E1123333356BF7E80A20E3ADFFD8EC335C14DA1A249D1B10F3D7CFD0B |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3200 | MonitorFPKPVer.exe | GET | — | 119.147.23.75:80 | http://update.szhtxx.com.cn/Upgrade/UpgradeApp/MonitorFPKP/updateVerEx.ini | CN | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3200 | MonitorFPKPVer.exe | 119.147.23.75:80 | update.szhtxx.com.cn | Chinanet | CN | unknown |
Domain | IP | Reputation |
---|---|---|
update.szhtxx.com.cn |
| unknown |