File name: | 02322404_2 |
Full analysis: | https://app.any.run/tasks/70cad71d-444f-4b05-bb6e-04c55dfb15a7 |
Verdict: | Malicious activity |
Analysis date: | November 30, 2020, 04:45:49 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive, LHa self-extracting archive |
MD5: | EF9D9E06C4202794A51863708D1AA184 |
SHA1: | 53B84C75E863909A1BBC6C0955A8D82B48A676CC |
SHA256: | 237A9165DC8C39B5FD66E113DD837A9FCD55366F54C38232A77480AFE04FD134 |
SSDEEP: | 196608:tuA8nShxOZNsR2BYCkGuwUymRFVotTDpR6K/Bh:kAK3oRCYYEPo99Bh |
.exe | | | Win32 Executable (generic) (52.9) |
---|---|---|
.exe | | | Generic Win/DOS Executable (23.5) |
.exe | | | DOS Executable Generic (23.5) |
ProductVersion: | 2.20.0.1 |
---|---|
ProductName: | WinSFX32 for Win32 |
OriginalFileName: | LZHSFX32.EXE |
LegalCopyright: | (C)Micco 1997-2010 All rights reserved. |
InternalName: | LZHSFX32 |
FileVersion: | 2.20.0.1 |
FileDescription: | WinSFX32 Self Extractor for Win32 |
CompanyName: | - |
CharacterSet: | Windows, Japan (Shift - JIS X-0208) |
LanguageCode: | Japanese |
FileSubtype: | - |
ObjectFileType: | Executable application |
FileOS: | Windows NT 32-bit |
FileFlags: | (none) |
FileFlagsMask: | 0x001f |
ProductVersionNumber: | 2.20.0.1 |
FileVersionNumber: | 2.20.0.1 |
Subsystem: | Windows GUI |
SubsystemVersion: | 4 |
ImageVersion: | 4 |
OSVersion: | 4 |
EntryPoint: | 0x5490 |
UninitializedDataSize: | - |
InitializedDataSize: | 11264 |
CodeSize: | 18432 |
LinkerVersion: | 5.2 |
PEType: | PE32 |
TimeStamp: | 2010:05:29 17:21:27+02:00 |
MachineType: | Intel 386 or later, and compatibles |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 29-May-2010 15:21:27 |
Detected languages: |
|
CompanyName: | - |
FileDescription: | WinSFX32 Self Extractor for Win32 |
FileVersion: | 2.20.0.1 |
InternalName: | LZHSFX32 |
LegalCopyright: | (C)Micco 1997-2010 All rights reserved. |
OriginalFilename: | LZHSFX32.EXE |
ProductName: | WinSFX32 for Win32 |
ProductVersion: | 2.20.0.1 |
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x00CF |
Pages in file: | 0x0003 |
Relocations: | 0x0000 |
Size of header: | 0x0020 |
Min extra paragraphs: | 0x0000 |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x025C |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0026 |
Overlay number: | 0x0000 |
OEM identifier: | 0x484C |
OEM information: | 0x2741 |
Address of NE header: | 0x000004D0 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 7 |
Time date stamp: | 29-May-2010 15:21:27 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x000047A4 | 0x00004800 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.55049 |
.rdata | 0x00006000 | 0x000000B5 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.02228 |
.data | 0x00007000 | 0x0000056C | 0x00000600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.2551 |
.idata | 0x00008000 | 0x00000BB8 | 0x00000C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.09582 |
.CRT | 0x00009000 | 0x00000008 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x0000A000 | 0x00000FB8 | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.20964 |
.reloc | 0x0000B000 | 0x000005E4 | 0x00000600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.02822 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 5.00561 | 963 | UNKNOWN | Japanese - Japan | RT_MANIFEST |
2 | 2.17002 | 296 | UNKNOWN | Japanese - Japan | RT_ICON |
GETDIRDIALOG | 3.19794 | 414 | UNKNOWN | Japanese - Japan | RT_DIALOG |
SFXDIALOG | 2.79624 | 234 | UNKNOWN | Japanese - Japan | RT_DIALOG |
IDI_ICON1 | 2.37086 | 34 | UNKNOWN | Japanese - Japan | RT_GROUP_ICON |
ADVAPI32.dll |
CRTDLL.dll |
GDI32.dll |
KERNEL32.dll |
SHELL32.dll |
USER32.dll |
comdlg32.dll |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
2784 | "C:\Users\admin\AppData\Local\Temp\02322404_2.exe" | C:\Users\admin\AppData\Local\Temp\02322404_2.exe | explorer.exe | |
User: admin Integrity Level: MEDIUM Description: WinSFX32 Self Extractor for Win32 Exit code: 0 Version: 2.20.0.1 | ||||
1340 | "C:\Users\admin\AppData\Local\Temp\cswnd\cwns\csw\csw.exe" | C:\Users\admin\AppData\Local\Temp\cswnd\cwns\csw\csw.exe | — | 02322404_2.exe |
User: admin Company: Fuji Xerox Co., Ltd. Integrity Level: MEDIUM Description: Driver Installation Tool Exit code: 3221226540 Version: 6.14.00.3 | ||||
572 | "C:\Users\admin\AppData\Local\Temp\cswnd\cwns\csw\csw.exe" | C:\Users\admin\AppData\Local\Temp\cswnd\cwns\csw\csw.exe | 02322404_2.exe | |
User: admin Company: Fuji Xerox Co., Ltd. Integrity Level: HIGH Description: Driver Installation Tool Version: 6.14.00.3 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2784 | 02322404_2.exe | C:\Users\admin\AppData\Local\Temp\cswnd\ART_EX\x64\fxdrkkdm.dl_ | compressed | |
MD5:8D561488289580E75B9B56CAB43DEEAD | SHA256:3B775ED117D335E7A668F7E6558A42A7E2A3768EBA93A37A6585F7045FE252FB | |||
2784 | 02322404_2.exe | C:\Users\admin\AppData\Local\Temp\cswnd\ART_EX\x64\fxdrkji.tb_ | compressed | |
MD5:56D8F0D43A8DEC8C62111B7532CB691A | SHA256:A6EAD84053AAC300AA3E3489070A6A134339E4C6623F90E99D9790ECFBADDBFA | |||
2784 | 02322404_2.exe | C:\Users\admin\AppData\Local\Temp\cswnd\ART_EX\x64\fxlzfcs2.fx_ | compressed | |
MD5:C016C6B15F43B506A88A56A312831E42 | SHA256:BE1AC1060F95A76B5A981A7A1F035632679087C7491976A5190429BDB2F6EE0F | |||
2784 | 02322404_2.exe | C:\Users\admin\AppData\Local\Temp\cswnd\ART_EX\x64\fxdrkjf.ch_ | compressed | |
MD5:0874F70DEEC56EF8776D420643C5A236 | SHA256:47E7D5BDD3758AB9ACCEC5191CED5420782AB46A262CCBC568BF73B1B771ADCC | |||
2784 | 02322404_2.exe | C:\Users\admin\AppData\Local\Temp\cswnd\ART_EX\x64\fxdrkj.cd_ | compressed | |
MD5:47E0FA373DBF0847C32DD13DF22557DC | SHA256:BBD626383D291024B987F3F8C33E3DAD113DFECF097B0C1F5263408053A60523 | |||
2784 | 02322404_2.exe | C:\Users\admin\AppData\Local\Temp\cswnd\ART_EX\x64\fxdrkji.cat | cat | |
MD5:A4B75FD44D3FC41A25268B7BFEFD2D62 | SHA256:E2D8C68F8E7AA12F71F88F5C23F68B3D53FACF3209F388BC85FD3381C93DE3E8 | |||
2784 | 02322404_2.exe | C:\Users\admin\AppData\Local\Temp\cswnd\ART_EX\x64\fxdrkj.xr_ | compressed | |
MD5:B73A848FEC4D8394632B892FC323F3B9 | SHA256:6FCA565414B2B9EA86323A9CF8F766A5EC4ACA3026727EF2ED501EFC159B8757 | |||
2784 | 02322404_2.exe | C:\Users\admin\AppData\Local\Temp\cswnd\ART_EX\x64\fxdrkjir.xr_ | compressed | |
MD5:95B2F4285421D1B403FA809D2863B4D5 | SHA256:D30776FB2AF69EF5312003879FB5C78583A93DE7690396BBEADCD8209F3C4E49 | |||
2784 | 02322404_2.exe | C:\Users\admin\AppData\Local\Temp\cswnd\ART_EX\x64\fxdrkjiv.dl_ | compressed | |
MD5:656FE66FB70B8ACDDFC4B86D8CD871B9 | SHA256:BC2A2E1262F449D540D9475DB945CD7F4DD8FC85EC57F799ECBF9123E4E3B0F9 | |||
2784 | 02322404_2.exe | C:\Users\admin\AppData\Local\Temp\cswnd\ART_EX\x64\fxdrkjdm.dl_ | compressed | |
MD5:D389E1B9BF1DCCACC766FEB405D32DEC | SHA256:3539633B33CF8D5564C94627B175CBA3DCA915B6D0044389D3DC6463A499269E |