| File name: | SecuriteInfo.com.Adware.Downware.20566.24802.22853 |
| Full analysis: | https://app.any.run/tasks/0a70ac84-38cb-463d-9b34-fcf084ed100e |
| Verdict: | Malicious activity |
| Analysis date: | August 07, 2024, 18:38:07 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 10A0E8DBF074B007D6B96BA09C32FCDB |
| SHA1: | 17E3B3E10D60C014201385A2FD5910FC931FE627 |
| SHA256: | 23AE69131A9A46EF53E67106ECB998F43B41914AA07F858F7AC74F9A7498DE22 |
| SSDEEP: | 98304:IHZ2Rp5VP5N5UvcVDbary/Utdf+yWt4mf9h9ackkdm0XDPYYa1ChUVxNpuK3lX0q:ImlKQyvWWtl6jUL6gkNt6AQp9kj+ |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:05:26 17:55:44+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 6307840 |
| InitializedDataSize: | 303104 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x58c12f |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Satisfy Salty Tools |
| FileDescription: | 7-zip Satisfy Salty Tools |
| FileVersion: | 1.0.0.0 |
| LegalCopyright: | Copyright 2002-2022 Satisfy Salty Tools |
| ProductName: | 7-zip Satisfy Salty Tools |
| ProductVersion: | 1.0.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 6444 | "C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.Adware.Downware.20566.24802.22853.exe" | C:\Users\admin\AppData\Local\Temp\SecuriteInfo.com.Adware.Downware.20566.24802.22853.exe | explorer.exe | ||||||||||||
User: admin Company: Satisfy Salty Tools Integrity Level: MEDIUM Description: 7-zip Satisfy Salty Tools Version: 1.0.0.0 Modules
| |||||||||||||||
| 6568 | "C:\Users\admin\AppData\Local\Temp\Setup.exe" | C:\Users\admin\AppData\Local\Temp\setup.exe | SecuriteInfo.com.Adware.Downware.20566.24802.22853.exe | ||||||||||||
User: admin Company: Nullsoft, Inc. Integrity Level: HIGH Description: Winamp Installer Version: 5.6.6.3507 Modules
| |||||||||||||||
| (PID) Process: | (6444) SecuriteInfo.com.Adware.Downware.20566.24802.22853.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (6444) SecuriteInfo.com.Adware.Downware.20566.24802.22853.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (6444) SecuriteInfo.com.Adware.Downware.20566.24802.22853.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (6444) SecuriteInfo.com.Adware.Downware.20566.24802.22853.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6444 | SecuriteInfo.com.Adware.Downware.20566.24802.22853.exe | C:\Users\admin\AppData\Local\Temp\setup.exe | executable | |
MD5:76954D7DBF005D6DB5E38D64F25A8C20 | SHA256:E9E2EB114941F9F9157B4FB139E5588665FB89B709DF82D4A8346AE66CCF03E1 | |||
| 6568 | setup.exe | C:\Users\admin\AppData\Local\Temp\nso5FE0.tmp\modern-header.bmp | image | |
MD5:827358320DD8861C44EAC1E220047C29 | SHA256:88E8A05BE9CFB8DAEC31872C8322B7313B66CEAA45C361F8EFEDA53809F46910 | |||
| 6568 | setup.exe | C:\Users\admin\AppData\Local\Temp\nso5FE0.tmp\modern-wizard.bmp | image | |
MD5:2D63E33FA1CF672338A22C88FA45E6A0 | SHA256:7AE875CFCB6E3B1F4A06460FBDA99D8014DC4674EE256B0B79EC656777C7E292 | |||
| 6568 | setup.exe | C:\Users\admin\AppData\Local\Temp\nso5FE0.tmp\nsDialogs.dll | executable | |
MD5:4CCC4A742D4423F2F0ED744FD9C81F63 | SHA256:416133DD86C0DFF6B0FCAF1F46DFE97FDC85B37F90EFFB2D369164A8F7E13AE6 | |||
| 6568 | setup.exe | C:\Users\admin\AppData\Local\Temp\nso5FE0.tmp\System.dll | executable | |
MD5:BF712F32249029466FA86756F5546950 | SHA256:7851CB12FA4131F1FEE5DE390D650EF65CAC561279F1CFE70AD16CC9780210AF | |||
| 6568 | setup.exe | C:\Users\admin\AppData\Local\Temp\nso5FE0.tmp\LangDLL.dll | executable | |
MD5:A1CD3F159EF78D9ACE162F067B544FD9 | SHA256:47B9E251C9C90F43E3524965AECC07BD53C8E09C5B9F9862B44C306667E2B0B6 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5336 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | whitelisted |
3812 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
6872 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
6920 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3188 | RUXIMICS.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
3888 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2120 | MoUsoCoreWorker.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
876 | svchost.exe | 20.73.194.208:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
876 | svchost.exe | 4.231.128.59:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5336 | SearchApp.exe | 95.100.146.26:443 | www.bing.com | Akamai International B.V. | CZ | unknown |
5336 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
3812 | svchost.exe | 20.190.159.23:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
Domain | IP | Reputation |
|---|---|---|
google.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
login.live.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
th.bing.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |