| File name: | AcronisShellExtension_All.exe |
| Full analysis: | https://app.any.run/tasks/668e2347-6d6d-4170-820a-308c9d04e60e |
| Verdict: | Malicious activity |
| Analysis date: | December 12, 2023, 17:14:18 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | EB18AA2F87D83DA8FDA437F26B0FB174 |
| SHA1: | 5800D5FEA17CB191CDE20A5486C6C2138A812112 |
| SHA256: | 2F31CDDC558121CE3FC304F81ED65AEEC90D7C04535FF0A29C221A06B6333EB5 |
| SSDEEP: | 196608:HdZmJo9scI3vYBe6JxH8aDw95jD1uagDNkOGBZ56GcKV/368nofLa:H3miOABe6rhIuagqTTcKZ33Qa |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2011:04:28 13:38:36+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 87040 |
| InitializedDataSize: | 254464 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x15cbf |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.4.1.2100 |
| ProductVersionNumber: | 1.4.1.2100 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Private build |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| CompanyName: | Sergei Strelec |
| FileDescription: | ProgramPE |
| FileVersion: | 1.4.1.2100 |
| InternalName: | 7ZSfxMod |
| LegalCopyright: | Copyright © 2005-2010 Oleg N. Scherbakov |
| OriginalFileName: | 7ZSfxMod_x86.exe |
| PrivateBuild: | April 28, 2011 |
| ProductName: | 7-Zip SFX |
| ProductVersion: | 1.4.1.2100 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1116 | C:\Windows\system32\cmd.exe /c 32.cmd | C:\Windows\System32\cmd.exe | — | hidcon.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2132 | "C:\Users\admin\AppData\Local\Temp\AcronisShell\hidcon.exe" 32.cmd | C:\Users\admin\AppData\Local\Temp\AcronisShell\hidcon.exe | — | AcronisShellExtension_All.exe | |||||||||||
User: admin Company: Andrew Grechkin Integrity Level: MEDIUM Description: Execute hidden console Exit code: 0 Version: 1, 1, 4, 0 Modules
| |||||||||||||||
| 2464 | "C:\Users\admin\AppData\Local\Temp\AcronisShellExtension_All.exe" | C:\Users\admin\AppData\Local\Temp\AcronisShellExtension_All.exe | — | explorer.exe | |||||||||||
User: admin Company: Sergei Strelec Integrity Level: MEDIUM Description: ProgramPE Exit code: 0 Version: 1.4.1.2100 Modules
| |||||||||||||||
| (PID) Process: | (2464) AcronisShellExtension_All.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2464) AcronisShellExtension_All.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2464) AcronisShellExtension_All.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2464) AcronisShellExtension_All.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2464 | AcronisShellExtension_All.exe | C:\Users\admin\AppData\Local\Temp\AcronisShell\32.cmd | text | |
MD5:68522BDAFC248C8E7F1ECB7929071045 | SHA256:56B9356F4DA58D1ECEBF9E3E6B864CE642B1EBB530871E4CB6D8C86E6BC1C40D | |||
| 2464 | AcronisShellExtension_All.exe | C:\Users\admin\AppData\Local\Temp\AcronisShell\AcronisShellExtension\archive3_adapter.dll | executable | |
MD5:B38DC832B4758BF8F571B78340ECAFD0 | SHA256:D912EC5970B6D35953C8791D6E37D032D855206A53F5117FE5EFEFF72210052E | |||
| 2464 | AcronisShellExtension_All.exe | C:\Users\admin\AppData\Local\Temp\AcronisShell\hidcon.exe | executable | |
MD5:7D45129EBFEEC0D8CDC90DE24C2D914D | SHA256:693485F0A3FE5A2CCBF875625CDC8ECE2988442AC70C60F2E130D01559E7A891 | |||
| 2464 | AcronisShellExtension_All.exe | C:\Users\admin\AppData\Local\Temp\AcronisShell\AcronisShellExtension\archive3.dll | executable | |
MD5:F242027B019C8040B592AD30776E6878 | SHA256:CFC16D5F03661927620887CE80029CB89A9184845D109D873418EDE5BB6A04CD | |||
| 2464 | AcronisShellExtension_All.exe | C:\Users\admin\AppData\Local\Temp\AcronisShell\AcronisShellExtension\astor_client.dll | executable | |
MD5:8558E8CE6F3052199F31B793548471CB | SHA256:332FC7747308166428D2B660A16F729C896ABD433BBB47D17057DF98DF08E318 | |||
| 2464 | AcronisShellExtension_All.exe | C:\Users\admin\AppData\Local\Temp\AcronisShell\AcronisShellExtension\icu38.dll | executable | |
MD5:F50155C5E48274DEB52C5BEFBD7A72F0 | SHA256:A70488D66ED9C3146C50BCD7547D0D595EFBE1800CE66DC3BD29B8736F858012 | |||
| 2464 | AcronisShellExtension_All.exe | C:\Users\admin\AppData\Local\Temp\AcronisShell\64.cmd | text | |
MD5:95CBC8FBB7575B0DD56B96671D9DAEED | SHA256:8700A08C398D9AF08C19801FA24C28545A3C4664A6EE763AFAAB6959BA641AB0 | |||
| 2464 | AcronisShellExtension_All.exe | C:\Users\admin\AppData\Local\Temp\AcronisShell\64r.reg | text | |
MD5:41C1FB79DFF8078494FED71B1850453C | SHA256:EDF283C2548E7F7998575AE3FF82696850AEE5FB73D6971B972D59372CFB6083 | |||
| 2464 | AcronisShellExtension_All.exe | C:\Users\admin\AppData\Local\Temp\AcronisShell\32r.reg | text | |
MD5:A31A7AFE1C25320AD740CF3B7B6BFB46 | SHA256:E5B092F4183A9A49166BF1F3447698920F5C445BEBAB227D045DB136E90FD36D | |||
| 2464 | AcronisShellExtension_All.exe | C:\Users\admin\AppData\Local\Temp\AcronisShell\AcronisShellExtension\icudt38.dll | executable | |
MD5:A7A8139EF4C0DF2E6A797CECD097B60F | SHA256:B320843A62FBBD2DA49D0FEAE8FA13A0BC2C31B12D49F0A1BC5DD465A2128597 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |