File name:

HashCheckSetup-v2.4.0.exe

Full analysis: https://app.any.run/tasks/b728f4b7-4282-48c2-82e2-7c06a1d38975
Verdict: Malicious activity
Analysis date: April 01, 2018, 21:43:21
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

33E953479B4136B1D52E62F3D4A507A4

SHA1:

926958F11B78F3BE9ED2FF4D209ABCB0B6E70C30

SHA256:

2D6067F00BBB93526D146D2228A46DC4851F0FA866E69250279C6B2F00B8F1B7

SSDEEP:

12288:xgYg4WuvKbzTFBOHlbD+XkqgIBD/MpmITfAC:3rWWQYfqdD/MpmITfAC

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application loaded dropped or rewritten executable

      • HashCheckSetup-v2.4.0.exe (PID: 3452)
      • svchost.exe (PID: 856)
      • regsvr32.exe (PID: 3744)
      • explorer.exe (PID: 1632)
  • SUSPICIOUS

    • Creates COM task schedule object

      • regsvr32.exe (PID: 3744)
    • Modifies the open verb of a shell class

      • regsvr32.exe (PID: 3744)
    • Creates a software uninstall entry

      • regsvr32.exe (PID: 3744)
    • Creates files in the Windows directory

      • regsvr32.exe (PID: 3744)
  • INFO

    • Loads rich edit control libraries

      • HashCheckSetup-v2.4.0.exe (PID: 3452)
    • Dropped object may contain URL's

      • HashCheckSetup-v2.4.0.exe (PID: 3452)
      • regsvr32.exe (PID: 3744)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:07:25 02:55:51+02:00
PEType: PE32
LinkerVersion: 6
CodeSize: 25088
InitializedDataSize: 141824
UninitializedDataSize: 2048
EntryPoint: 0x33b6
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2.4.0.55
ProductVersionNumber: 2.4.0.55
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: ASCII
Comments: Installer distributed from https://github.com/gurnec/HashCheck/releases
FileDescription: Installer (x86/x64) from https://github.com/gurnec/HashCheck/releases
FileVersion: 2.4.0.55
LegalCopyright: Copyright © 2008-2016 Kai Liu, Christopher Gurnee, Tim Schlueter, et al. All rights reserved.
ProductName: HashCheck Shell Extension
ProductVersion: 2.4.0.55

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 25-Jul-2016 00:55:51
Detected languages:
  • English - United States
Comments: Installer distributed from https://github.com/gurnec/HashCheck/releases
FileDescription: Installer (x86/x64) from https://github.com/gurnec/HashCheck/releases
FileVersion: 2.4.0.55
LegalCopyright: Copyright © 2008-2016 Kai Liu, Christopher Gurnee, Tim Schlueter, et al. All rights reserved.
ProductName: HashCheck Shell Extension
ProductVersion: 2.4.0.55

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000C8

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 25-Jul-2016 00:55:51
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x0000615D
0x00006200
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.45023
.rdata
0x00008000
0x000013A4
0x00001400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.163
.data
0x0000A000
0x00020338
0x00000600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
3.9824
.ndata
0x0002B000
0x00023000
0x00000000
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
.rsrc
0x0004E000
0x00008780
0x00008800
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.07947

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.30439
1127
UNKNOWN
English - United States
RT_MANIFEST
2
4.25158
4264
UNKNOWN
English - United States
RT_ICON
3
6.22673
3752
UNKNOWN
English - United States
RT_ICON
4
6.18296
2216
UNKNOWN
English - United States
RT_ICON
5
3.26592
1640
UNKNOWN
English - United States
RT_ICON
6
6.04889
1384
UNKNOWN
English - United States
RT_ICON
7
4.53186
1128
UNKNOWN
English - United States
RT_ICON
8
3.55118
744
UNKNOWN
English - United States
RT_ICON
9
3.52748
296
UNKNOWN
English - United States
RT_ICON
102
2.71813
180
UNKNOWN
English - United States
RT_DIALOG

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.dll
SHELL32.dll
USER32.dll
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
37
Monitored processes
5
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start hashchecksetup-v2.4.0.exe regsvr32.exe svchost.exe no specs explorer.exe no specs hashchecksetup-v2.4.0.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
124"C:\Users\admin\AppData\Local\Temp\HashCheckSetup-v2.4.0.exe" C:\Users\admin\AppData\Local\Temp\HashCheckSetup-v2.4.0.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Installer (x86/x64) from https://github.com/gurnec/HashCheck/releases
Exit code:
3221226540
Version:
2.4.0.55
Modules
Images
c:\users\admin\appdata\local\temp\hashchecksetup-v2.4.0.exe
c:\systemroot\system32\ntdll.dll
856C:\Windows\system32\svchost.exe -k netsvcsC:\Windows\System32\svchost.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Host Process for Windows Services
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\svchost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\ole32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1632C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\winanr.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
3452"C:\Users\admin\AppData\Local\Temp\HashCheckSetup-v2.4.0.exe" C:\Users\admin\AppData\Local\Temp\HashCheckSetup-v2.4.0.exe
explorer.exe
User:
admin
Integrity Level:
HIGH
Description:
Installer (x86/x64) from https://github.com/gurnec/HashCheck/releases
Exit code:
0
Version:
2.4.0.55
Modules
Images
c:\users\admin\appdata\local\temp\hashchecksetup-v2.4.0.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3744regsvr32 /i /n /s "C:\Users\admin\AppData\Local\Temp\nsd403A.tmp"C:\Windows\system32\regsvr32.exe
HashCheckSetup-v2.4.0.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
294
Read events
146
Write events
146
Delete events
2

Modification events

(PID) Process:(1632) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Operation:writeName:P:\Hfref\nqzva\NccQngn\Ybpny\Grzc\UnfuPurpxFrghc-i2.4.0.rkr
Value:
00000000000000000000000000000000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
(PID) Process:(1632) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Operation:writeName:HRZR_PGYFRFFVBA
Value:
000000000A0000001B000000247C0700020000000E000000633103007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E00650078006500000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF9049717500000000000000008CE43102D5746D750004000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF38840E007C840E00808B0E00BCE431022FB1687680B09B76FCF13102381E69761463697610180D00F0E431020000000070000000DEA5C579D0E43102BE6A697610180D00F0E4310200000000FCE631026F62697610180D00F0E4310200000400000000807C62697610180D0063003A005C00750073006500720073005C00610064006D0069006E005C0061007000700064006100740061005C0072006F0061006D0069006E0067005C006D006900630072006F0073006F00660074005C0069006E007400650072006E006500740020006500780070006C006F007200650072005C0071007500690063006B0020006C00610075006E0063001100000010470D0008470D002000700069006E006E00650064005C0008E60000C2A4C579B8E531028291697608E63102BCE5310227956976000000005CC51500E4E53102CD9469765CC5150090E63102D0C01500E194697600000000D0C0150090E63102ECE53102020000000E000000633103007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E00650078006500000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF9049717500000000000000008CE43102D5746D750004000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF38840E007C840E00808B0E00BCE431022FB1687680B09B76FCF13102381E69761463697610180D00F0E431020000000070000000DEA5C579D0E43102BE6A697610180D00F0E4310200000000FCE631026F62697610180D00F0E4310200000400000000807C62697610180D0063003A005C00750073006500720073005C00610064006D0069006E005C0061007000700064006100740061005C0072006F0061006D0069006E0067005C006D006900630072006F0073006F00660074005C0069006E007400650072006E006500740020006500780070006C006F007200650072005C0071007500690063006B0020006C00610075006E0063001100000010470D0008470D002000700069006E006E00650064005C0008E60000C2A4C579B8E531028291697608E63102BCE5310227956976000000005CC51500E4E53102CD9469765CC5150090E63102D0C01500E194697600000000D0C0150090E63102ECE53102020000000E000000633103007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E00650078006500000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF9049717500000000000000008CE43102D5746D750004000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF38840E007C840E00808B0E00BCE431022FB1687680B09B76FCF13102381E69761463697610180D00F0E431020000000070000000DEA5C579D0E43102BE6A697610180D00F0E4310200000000FCE631026F62697610180D00F0E4310200000400000000807C62697610180D0063003A005C00750073006500720073005C00610064006D0069006E005C0061007000700064006100740061005C0072006F0061006D0069006E0067005C006D006900630072006F0073006F00660074005C0069006E007400650072006E006500740020006500780070006C006F007200650072005C0071007500690063006B0020006C00610075006E0063001100000010470D0008470D002000700069006E006E00650064005C0008E60000C2A4C579B8E531028291697608E63102BCE5310227956976000000005CC51500E4E53102CD9469765CC5150090E63102D0C01500E194697600000000D0C0150090E63102ECE53102
(PID) Process:(1632) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Operation:writeName:P:\Hfref\nqzva\NccQngn\Ybpny\Grzc\UnfuPurpxFrghc-i2.4.0.rkr
Value:
000000000000000000000000B00F0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
(PID) Process:(1632) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Operation:writeName:HRZR_PGYFRFFVBA
Value:
000000000A0000001B000000D48B0700020000000E000000633103007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E00650078006500000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF9049717500000000000000008CE43102D5746D750004000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF38840E007C840E00808B0E00BCE431022FB1687680B09B76FCF13102381E69761463697610180D00F0E431020000000070000000DEA5C579D0E43102BE6A697610180D00F0E4310200000000FCE631026F62697610180D00F0E4310200000400000000807C62697610180D0063003A005C00750073006500720073005C00610064006D0069006E005C0061007000700064006100740061005C0072006F0061006D0069006E0067005C006D006900630072006F0073006F00660074005C0069006E007400650072006E006500740020006500780070006C006F007200650072005C0071007500690063006B0020006C00610075006E0063001100000010470D0008470D002000700069006E006E00650064005C0008E60000C2A4C579B8E531028291697608E63102BCE5310227956976000000005CC51500E4E53102CD9469765CC5150090E63102D0C01500E194697600000000D0C0150090E63102ECE53102020000000E000000633103007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E00650078006500000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF9049717500000000000000008CE43102D5746D750004000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF38840E007C840E00808B0E00BCE431022FB1687680B09B76FCF13102381E69761463697610180D00F0E431020000000070000000DEA5C579D0E43102BE6A697610180D00F0E4310200000000FCE631026F62697610180D00F0E4310200000400000000807C62697610180D0063003A005C00750073006500720073005C00610064006D0069006E005C0061007000700064006100740061005C0072006F0061006D0069006E0067005C006D006900630072006F0073006F00660074005C0069006E007400650072006E006500740020006500780070006C006F007200650072005C0071007500690063006B0020006C00610075006E0063001100000010470D0008470D002000700069006E006E00650064005C0008E60000C2A4C579B8E531028291697608E63102BCE5310227956976000000005CC51500E4E53102CD9469765CC5150090E63102D0C01500E194697600000000D0C0150090E63102ECE53102020000000E000000633103007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E00650078006500000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF9049717500000000000000008CE43102D5746D750004000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF38840E007C840E00808B0E00BCE431022FB1687680B09B76FCF13102381E69761463697610180D00F0E431020000000070000000DEA5C579D0E43102BE6A697610180D00F0E4310200000000FCE631026F62697610180D00F0E4310200000400000000807C62697610180D0063003A005C00750073006500720073005C00610064006D0069006E005C0061007000700064006100740061005C0072006F0061006D0069006E0067005C006D006900630072006F0073006F00660074005C0069006E007400650072006E006500740020006500780070006C006F007200650072005C0071007500690063006B0020006C00610075006E0063001100000010470D0008470D002000700069006E006E00650064005C0008E60000C2A4C579B8E531028291697608E63102BCE5310227956976000000005CC51500E4E53102CD9469765CC5150090E63102D0C01500E194697600000000D0C0150090E63102ECE53102
(PID) Process:(1632) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\8F\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(1632) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.rtf\OpenWithProgids
Operation:writeName:Word.RTF.8
Value:
(PID) Process:(1632) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Operation:writeName:{S38OS404-1Q43-42S2-9305-67QR0O28SP23}\rkcybere.rkr
Value:
00000000020000000E00000024460300000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF9069ECCD45C7D30100000000
(PID) Process:(1632) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Operation:writeName:HRZR_PGYFRFFVBA
Value:
000000000A0000001B00000095A00700020000000E000000244603007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E00650078006500000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF9049717500000000000000008CE43102D5746D750004000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF38840E007C840E00808B0E00BCE431022FB1687680B09B76FCF13102381E69761463697610180D00F0E431020000000070000000DEA5C579D0E43102BE6A697610180D00F0E4310200000000FCE631026F62697610180D00F0E4310200000400000000807C62697610180D0063003A005C00750073006500720073005C00610064006D0069006E005C0061007000700064006100740061005C0072006F0061006D0069006E0067005C006D006900630072006F0073006F00660074005C0069006E007400650072006E006500740020006500780070006C006F007200650072005C0071007500690063006B0020006C00610075006E0063001100000010470D0008470D002000700069006E006E00650064005C0008E60000C2A4C579B8E531028291697608E63102BCE5310227956976000000005CC51500E4E53102CD9469765CC5150090E63102D0C01500E194697600000000D0C0150090E63102ECE53102020000000E000000244603007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E00650078006500000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF9049717500000000000000008CE43102D5746D750004000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF38840E007C840E00808B0E00BCE431022FB1687680B09B76FCF13102381E69761463697610180D00F0E431020000000070000000DEA5C579D0E43102BE6A697610180D00F0E4310200000000FCE631026F62697610180D00F0E4310200000400000000807C62697610180D0063003A005C00750073006500720073005C00610064006D0069006E005C0061007000700064006100740061005C0072006F0061006D0069006E0067005C006D006900630072006F0073006F00660074005C0069006E007400650072006E006500740020006500780070006C006F007200650072005C0071007500690063006B0020006C00610075006E0063001100000010470D0008470D002000700069006E006E00650064005C0008E60000C2A4C579B8E531028291697608E63102BCE5310227956976000000005CC51500E4E53102CD9469765CC5150090E63102D0C01500E194697600000000D0C0150090E63102ECE53102020000000E000000244603007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E00650078006500000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF9049717500000000000000008CE43102D5746D750004000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF38840E007C840E00808B0E00BCE431022FB1687680B09B76FCF13102381E69761463697610180D00F0E431020000000070000000DEA5C579D0E43102BE6A697610180D00F0E4310200000000FCE631026F62697610180D00F0E4310200000400000000807C62697610180D0063003A005C00750073006500720073005C00610064006D0069006E005C0061007000700064006100740061005C0072006F0061006D0069006E0067005C006D006900630072006F0073006F00660074005C0069006E007400650072006E006500740020006500780070006C006F007200650072005C0071007500690063006B0020006C00610075006E0063001100000010470D0008470D002000700069006E006E00650064005C0008E60000C2A4C579B8E531028291697608E63102BCE5310227956976000000005CC51500E4E53102CD9469765CC5150090E63102D0C01500E194697600000000D0C0150090E63102ECE53102
(PID) Process:(1632) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Operation:writeName:P:\Hfref\nqzva\NccQngn\Ybpny\Grzc\UnfuPurpxFrghc-i2.4.0.rkr
Value:
000000000000000001000000B00F0000000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BF000080BFFFFFFFFF000000000000000000000000
(PID) Process:(1632) explorer.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\UserAssist\{CEBFF5CD-ACE2-4F4F-9178-9926F41749EA}\Count
Operation:writeName:HRZR_PGYFRFFVBA
Value:
000000000A0000001C00000095A00700020000000E000000244603007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E00650078006500000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF9049717500000000000000008CE43102D5746D750004000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF38840E007C840E00808B0E00BCE431022FB1687680B09B76FCF13102381E69761463697610180D00F0E431020000000070000000DEA5C579D0E43102BE6A697610180D00F0E4310200000000FCE631026F62697610180D00F0E4310200000400000000807C62697610180D0063003A005C00750073006500720073005C00610064006D0069006E005C0061007000700064006100740061005C0072006F0061006D0069006E0067005C006D006900630072006F0073006F00660074005C0069006E007400650072006E006500740020006500780070006C006F007200650072005C0071007500690063006B0020006C00610075006E0063001100000010470D0008470D002000700069006E006E00650064005C0008E60000C2A4C579B8E531028291697608E63102BCE5310227956976000000005CC51500E4E53102CD9469765CC5150090E63102D0C01500E194697600000000D0C0150090E63102ECE53102020000000E000000244603007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E00650078006500000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF9049717500000000000000008CE43102D5746D750004000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF38840E007C840E00808B0E00BCE431022FB1687680B09B76FCF13102381E69761463697610180D00F0E431020000000070000000DEA5C579D0E43102BE6A697610180D00F0E4310200000000FCE631026F62697610180D00F0E4310200000400000000807C62697610180D0063003A005C00750073006500720073005C00610064006D0069006E005C0061007000700064006100740061005C0072006F0061006D0069006E0067005C006D006900630072006F0073006F00660074005C0069006E007400650072006E006500740020006500780070006C006F007200650072005C0071007500690063006B0020006C00610075006E0063001100000010470D0008470D002000700069006E006E00650064005C0008E60000C2A4C579B8E531028291697608E63102BCE5310227956976000000005CC51500E4E53102CD9469765CC5150090E63102D0C01500E194697600000000D0C0150090E63102ECE53102020000000E000000244603007B00460033003800420046003400300034002D0031004400340033002D0034003200460032002D0039003300300035002D003600370044004500300042003200380046004300320033007D005C006500780070006C006F007200650072002E00650078006500000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF9049717500000000000000008CE43102D5746D750004000000000000F0E43102FFFFFFFF888B0E00FFFFFFFF38840E007C840E00808B0E00BCE431022FB1687680B09B76FCF13102381E69761463697610180D00F0E431020000000070000000DEA5C579D0E43102BE6A697610180D00F0E4310200000000FCE631026F62697610180D00F0E4310200000400000000807C62697610180D0063003A005C00750073006500720073005C00610064006D0069006E005C0061007000700064006100740061005C0072006F0061006D0069006E0067005C006D006900630072006F0073006F00660074005C0069006E007400650072006E006500740020006500780070006C006F007200650072005C0071007500690063006B0020006C00610075006E0063001100000010470D0008470D002000700069006E006E00650064005C0008E60000C2A4C579B8E531028291697608E63102BCE5310227956976000000005CC51500E4E53102CD9469765CC5150090E63102D0C01500E194697600000000D0C0150090E63102ECE53102
Executable files
5
Suspicious files
0
Text files
2
Unknown types
1

Dropped files

PID
Process
Filename
Type
3452HashCheckSetup-v2.4.0.exeC:\Users\admin\AppData\Local\Temp\nsuD113.tmp
MD5:
SHA256:
856svchost.exeC:\Windows\appcompat\programs\RecentFileCache.bcftxt
MD5:
SHA256:
3452HashCheckSetup-v2.4.0.exeC:\Users\admin\AppData\Local\Temp\nskD124.tmp\nsDialogs.dllexecutable
MD5:0D45588070CF728359055F776AF16EC4
SHA256:067C77D51DF034B4A614F83803140FBF4CD2F8684B88EA8C8ACDF163EDAD085A
3452HashCheckSetup-v2.4.0.exeC:\Users\admin\AppData\Local\Temp\nskD124.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
3744regsvr32.exeC:\Windows\system32\ShellExt\HashCheck.dllexecutable
MD5:3CEEA8D9317097EBD1E5779346D1F3A1
SHA256:52619BFF776EDBBF660AE0DEB19F3E695C1A3256B39E98D841767B804C361035
3452HashCheckSetup-v2.4.0.exeC:\Users\admin\AppData\Local\Temp\nskD124.tmp\LangDLL.dllexecutable
MD5:0C44F21D4AFC81CC99FAC7CC35E4503A
SHA256:8DC2BE6679497994E3DDC97BC7BC1CE2B3C17EF3528B03DED6696EF198A11D10
3452HashCheckSetup-v2.4.0.exeC:\Users\admin\AppData\Local\Temp\nskD124.tmp\System.dllexecutable
MD5:A4DD044BCD94E9B3370CCF095B31F896
SHA256:2E226715419A5882E2E14278940EE8EF0AA648A3EF7AF5B3DC252674111962BC
3452HashCheckSetup-v2.4.0.exeC:\Users\admin\AppData\Local\Temp\nsd403A.tmpexecutable
MD5:3CEEA8D9317097EBD1E5779346D1F3A1
SHA256:52619BFF776EDBBF660AE0DEB19F3E695C1A3256B39E98D841767B804C361035
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info