| File name: | BLTools v2.7.1 [PRO].sfx.exe |
| Full analysis: | https://app.any.run/tasks/265a8b5a-0e20-47fe-ae60-bc0b032d5c77 |
| Verdict: | Malicious activity |
| Analysis date: | January 06, 2024, 19:24:41 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | BD5FD5AF41AFC879A18D665F64C9EB20 |
| SHA1: | 9D5E51DDD394D66336AC2C1ED60395414913DE91 |
| SHA256: | 2F693C27BDD5DE21D5997D5956DD3F9DA16CD2372AB6AF2B265B24E89F1BE581 |
| SSDEEP: | 98304:9fLIQ/9lT9eNYrIpsPG21IIZC4QiNhPEvhOQ5s/NdM0G3OoZzl/044WOZJE41paE:9tNYjVrJjA |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:09:28 12:37:13+02:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.33 |
| CodeSize: | 214528 |
| InitializedDataSize: | 263680 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x21d50 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 492 | "C:\Users\admin\AppData\Local\Temp\BLTools v2.7.1 [PRO].exe" | C:\Users\admin\AppData\Local\Temp\BLTools v2.7.1 [PRO].exe | BLTools v2.7.1 [PRO].sfx.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: BLTools Cookies Checker Exit code: 0 Version: 2.7.1.0 Modules
| |||||||||||||||
| 2044 | "C:\Users\admin\AppData\Local\Temp\BLTools v2.7.1 [PRO].sfx.exe" | C:\Users\admin\AppData\Local\Temp\BLTools v2.7.1 [PRO].sfx.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2044) BLTools v2.7.1 [PRO].sfx.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2044) BLTools v2.7.1 [PRO].sfx.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2044) BLTools v2.7.1 [PRO].sfx.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2044) BLTools v2.7.1 [PRO].sfx.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2044) BLTools v2.7.1 [PRO].sfx.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2044) BLTools v2.7.1 [PRO].sfx.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (492) BLTools v2.7.1 [PRO].exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
| Operation: | write | Name: | Name |
Value: Explorer.EXE | |||
| (PID) Process: | (492) BLTools v2.7.1 [PRO].exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2044 | BLTools v2.7.1 [PRO].sfx.exe | C:\Users\admin\AppData\Local\Temp\Licansia.txt | text | |
MD5:1B9CA37C074C7AA2BC897FE35A944213 | SHA256:9C0D36420DC061082831BB4D47DC9F25D8F129D65A3D3AD43A12D57C5E1C2088 | |||
| 2044 | BLTools v2.7.1 [PRO].sfx.exe | C:\Users\admin\AppData\Local\Temp\CookiesCreator.exe | executable | |
MD5:AEE127951627898FF120D3F4A3ADA964 | SHA256:A61FE2CF0E51860F3BFDE5B6159F926748F7D2D0B7B397831BF695F63CF99106 | |||
| 2044 | BLTools v2.7.1 [PRO].sfx.exe | C:\Users\admin\AppData\Local\Temp\License.dll | text | |
MD5:26A0D549D0987279798CB6421D2DDFA2 | SHA256:A329CE0D40E38A0126731C4F47D638995808B2AFED73EC3E430909B213B232ED | |||
| 2044 | BLTools v2.7.1 [PRO].sfx.exe | C:\Users\admin\AppData\Local\Temp\Ookii.Dialogs.Wpf.dll | executable | |
MD5:932EBB3F9E7113071C6A17818342B7CC | SHA256:285AA8225732DDBCF211B1158BD6CFF8BF3ACBEEAB69617F4BE85862B7105AB5 | |||
| 2044 | BLTools v2.7.1 [PRO].sfx.exe | C:\Users\admin\AppData\Local\Temp\Settings.ini | text | |
MD5:3F3FA29AD9B39126AB766F374AB3A0D9 | SHA256:C6B91487F72AB5315322F9FC3F6B750A848A568B4A8CAA30F499FF3ACF186814 | |||
| 2044 | BLTools v2.7.1 [PRO].sfx.exe | C:\Users\admin\AppData\Local\Temp\Extreme.Net.dll | executable | |
MD5:F79F0E3A0361CAC000E2D3553753CD68 | SHA256:8A6518AB7419FBEC3AC9875BAA3AFB410AD1398C7AA622A09CD9084EC6CADFCD | |||
| 2044 | BLTools v2.7.1 [PRO].sfx.exe | C:\Users\admin\AppData\Local\Temp\MaterialDesignThemes.Wpf.dll | executable | |
MD5:824CBF63999F954AA1747F79586A4D3C | SHA256:344E2CEE979E979932F504DC76BD75E97AE1FF46CAA3FE2795ADFE0A866347F7 | |||
| 2044 | BLTools v2.7.1 [PRO].sfx.exe | C:\Users\admin\AppData\Local\Temp\Microsoft.Xaml.Behaviors.dll | executable | |
MD5:95F46F34C099421D917D5FEADBB33EDB | SHA256:8E77A1DD5E2DF4D4AF801376CC3428B082EB49FCB6E647B933967FAE12AD9D5D | |||
| 492 | BLTools v2.7.1 [PRO].exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 | binary | |
MD5:2CB40532B2A3434600BF6C3C1B135321 | SHA256:D9B6922C70A204127525DD7810DF34FD3D2F44165874FD21BAB37024F7AB232A | |||
| 2044 | BLTools v2.7.1 [PRO].sfx.exe | C:\Users\admin\AppData\Local\Temp\MaterialDesignColors.dll | executable | |
MD5:5C108C4DA6D03F0FA2C3B4DC7890CB52 | SHA256:B5EC30C93B1D2B4631EE2B178750EC92E302E2E331090EC9783981B9572354F8 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
492 | BLTools v2.7.1 [PRO].exe | GET | 200 | 87.248.204.0:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?99583e6c0cf8fc9d | unknown | compressed | 65.2 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
492 | BLTools v2.7.1 [PRO].exe | 104.26.0.5:443 | keyauth.win | CLOUDFLARENET | US | unknown |
492 | BLTools v2.7.1 [PRO].exe | 87.248.204.0:80 | ctldl.windowsupdate.com | LLNW | US | unknown |
492 | BLTools v2.7.1 [PRO].exe | 104.26.4.15:443 | api.steaminventoryhelper.com | CLOUDFLARENET | US | unknown |
Domain | IP | Reputation |
|---|---|---|
keyauth.win |
| malicious |
ctldl.windowsupdate.com |
| whitelisted |
api.steaminventoryhelper.com |
| unknown |