| File name: | HidHide_1.5.212_x64.exe |
| Full analysis: | https://app.any.run/tasks/4ad45c39-c581-47cc-8d16-0cba25fb2b57 |
| Verdict: | Malicious activity |
| Analysis date: | March 05, 2024, 15:25:05 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | BDBA9D05FC40BCAE71D344802C6CC2F7 |
| SHA1: | 9757F9ABB56E1ACF24128046910441BCF903CEAD |
| SHA256: | 2093D5422C2C009911098E2B03101A349FAE2BE834A7F972BA3EF40C781EDE38 |
| SSDEEP: | 98304:loLfIHceJw1fOHuwjNYGy+6YBBm9we6+hyxk8Ud+EhQvkcFJmELMQ8VHp8b3iAog:lSGjo7RHO0e |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:01:23 16:35:17+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.38 |
| CodeSize: | 2716672 |
| InitializedDataSize: | 1122816 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x20c1a0 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.5.212.0 |
| ProductVersionNumber: | 1.5.212.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Debug |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Nefarius Software Solutions e.U. |
| FileDescription: | HidHide Installer |
| FileVersion: | 1.5.212 |
| InternalName: | HidHide_1.5.212_x64 |
| LegalCopyright: | Copyright (C) 2024 Nefarius Software Solutions e.U. |
| OriginalFileName: | HidHide_1.5.212_x64.exe |
| ProductName: | HidHide |
| ProductVersion: | 1.5.212 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2160 | "C:\Users\admin\AppData\Local\Temp\HidHide_1.5.212_x64.exe" | C:\Users\admin\AppData\Local\Temp\HidHide_1.5.212_x64.exe | explorer.exe | ||||||||||||
User: admin Company: Nefarius Software Solutions e.U. Integrity Level: MEDIUM Description: HidHide Installer Exit code: 3758096389 Version: 1.5.212 Modules
| |||||||||||||||
| (PID) Process: | (2160) HidHide_1.5.212_x64.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2160) HidHide_1.5.212_x64.exe | Key: | HKEY_CURRENT_USER\Software\AiTemp |
| Operation: | delete value | Name: | C__Users_admin_AppData_Local_Temp_HidHide_1.5.212_x64.exe |
Value: | |||
| (PID) Process: | (2160) HidHide_1.5.212_x64.exe | Key: | HKEY_CURRENT_USER\Software\AiTemp |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (2160) HidHide_1.5.212_x64.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce |
| Operation: | delete value | Name: | C__Users_admin_AppData_Local_Temp_HidHide_1.5.212_x64.exe |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2160 | HidHide_1.5.212_x64.exe | C:\ProgramData\Nefarius Software Solutions\HidHide 1.5.212\install\holder0.aiph | — | |
MD5:— | SHA256:— | |||
| 2160 | HidHide_1.5.212_x64.exe | C:\ProgramData\Nefarius Software Solutions\HidHide 1.5.212\install\FD6A45B\HidHide.msi | executable | |
MD5:8B51A36E4DD2AB392B360572833C9751 | SHA256:EF367FAD8E300D87E0D440228C6DD328E5E8EF7D9B14EB96C6D8BE520C610E79 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |