File name: | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe |
Full analysis: | https://app.any.run/tasks/1a677c30-18a7-46ab-b76d-e3bed41345e5 |
Verdict: | Malicious activity |
Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
Analysis date: | January 11, 2019, 13:37:06 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 0821F015F5F520D8055BCDDB4A3661A3 |
SHA1: | AE6C900D333D9E4149CA3A29BF2E51F9777A7E75 |
SHA256: | 3109E82CB8EA8BAF58F3C92D82F357D6A1317BD4F238E14576B90D54AEC65160 |
SSDEEP: | 24576:z7aEgfUnUPWl/O6/KBeu2nJG0GrXaIWsmbacj0hXojh30scGEdIRpPppMxs0mUC9:z7ngf3Wj/M5iuGTbtmehFcVdI/PMeL3 |
.exe | | | Inno Setup installer (81.5) |
---|---|---|
.exe | | | Win32 Executable Delphi generic (10.5) |
.exe | | | Win32 Executable (generic) (3.3) |
.exe | | | Win16/32 Executable Delphi generic (1.5) |
.exe | | | Generic Win/DOS Executable (1.4) |
ProductVersion: | 3.1.8 |
---|---|
ProductName: | Conokigo |
LegalCopyright: | |
FileVersion: | 4.6.1.6 |
FileDescription: | Conokigo Setup |
CompanyName: | Galiboc |
Comments: | This installation was built with Inno Setup. |
CharacterSet: | Unicode |
LanguageCode: | Neutral |
FileSubtype: | - |
ObjectFileType: | Executable application |
FileOS: | Win32 |
FileFlags: | (none) |
FileFlagsMask: | 0x003f |
ProductVersionNumber: | 0.0.0.0 |
FileVersionNumber: | 0.0.0.0 |
Subsystem: | Windows GUI |
SubsystemVersion: | 4 |
ImageVersion: | 6 |
OSVersion: | 1 |
EntryPoint: | 0xaa98 |
UninitializedDataSize: | - |
InitializedDataSize: | 134144 |
CodeSize: | 41472 |
LinkerVersion: | 2.25 |
PEType: | PE32 |
TimeStamp: | 1992:06:20 00:22:17+02:00 |
MachineType: | Intel 386 or later, and compatibles |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 19-Jun-1992 22:22:17 |
Detected languages: |
|
Comments: | This installation was built with Inno Setup. |
CompanyName: | Galiboc |
FileDescription: | Conokigo Setup |
FileVersion: | 4.6.1.6 |
LegalCopyright: | - |
ProductName: | Conokigo |
ProductVersion: | 3.1.8 |
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x0050 |
Pages in file: | 0x0002 |
Relocations: | 0x0000 |
Size of header: | 0x0004 |
Min extra paragraphs: | 0x000F |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x00B8 |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0000 |
Overlay number: | 0x001A |
OEM identifier: | 0x0000 |
OEM information: | 0x0000 |
Address of NE header: | 0x00000100 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 8 |
Time date stamp: | 19-Jun-1992 22:22:17 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
CODE | 0x00001000 | 0x0000A1D0 | 0x0000A200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.6321 |
DATA | 0x0000C000 | 0x00000250 | 0x00000400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.74012 |
BSS | 0x0000D000 | 0x00000E94 | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.idata | 0x0000E000 | 0x0000097C | 0x00000A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.48608 |
.tls | 0x0000F000 | 0x00000008 | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rdata | 0x00010000 | 0x00000018 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED | 0.190489 |
.reloc | 0x00011000 | 0x0000091C | 0x00000000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED | 0 |
.rsrc | 0x00012000 | 0x0001FBC0 | 0x0001FC00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED | 7.40802 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 5.13965 | 1580 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 6.9708 | 2440 | Latin 1 / Western European | UNKNOWN | RT_ICON |
3 | 6.13571 | 9640 | Latin 1 / Western European | UNKNOWN | RT_ICON |
4 | 6.5761 | 16936 | Latin 1 / Western European | UNKNOWN | RT_ICON |
5 | 6.53412 | 38056 | Latin 1 / Western European | UNKNOWN | RT_ICON |
6 | 7.9787 | 55134 | Latin 1 / Western European | UNKNOWN | RT_ICON |
4089 | 3.21823 | 754 | Latin 1 / Western European | UNKNOWN | RT_STRING |
4090 | 3.31515 | 780 | Latin 1 / Western European | UNKNOWN | RT_STRING |
4091 | 3.25024 | 718 | Latin 1 / Western European | UNKNOWN | RT_STRING |
4093 | 2.86149 | 104 | Latin 1 / Western European | UNKNOWN | RT_STRING |
advapi32.dll |
comctl32.dll |
kernel32.dll |
oleaut32.dll |
user32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
3012 | "C:\Users\admin\AppData\Local\Temp\0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe" | C:\Users\admin\AppData\Local\Temp\0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | — | explorer.exe | |||||||||||
User: admin Company: Galiboc Integrity Level: MEDIUM Description: Conokigo Setup Exit code: 0 Version: 4.6.1.6 Modules
| |||||||||||||||
2108 | "C:\Users\admin\AppData\Local\Temp\0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe" /RSF /ppn:YyhwYgxaFRAiP211FM5W /mnl | C:\Users\admin\AppData\Local\Temp\0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | ||||||||||||
User: admin Company: Galiboc Integrity Level: HIGH Description: Conokigo Setup Exit code: 4294967295 Version: 4.6.1.6 Modules
| |||||||||||||||
2676 | /d /c TIMEOUT 1 & cmd /d /c copy /B /Y "C:\Users\admin\AppData\Local\Temp\D56220250089361.dat"+"C:\Users\admin\AppData\Local\Temp\D56220250089362.dat" "C:\Users\admin\AppData\Local\Temp\in616D0122\37432309_stp\avast_free_antivirus_setup_online.exe" & cmd /d /c del "C:\Users\admin\AppData\Local\Temp\D56220250089361.dat" & cmd /d /c del "C:\Users\admin\AppData\Local\Temp\D56220250089362.dat" | C:\Windows\system32\cmd.exe | — | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
3152 | TIMEOUT 1 | C:\Windows\system32\timeout.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: timeout - pauses command processing Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3708 | cmd /d /c copy /B /Y "C:\Users\admin\AppData\Local\Temp\D56220250089361.dat"+"C:\Users\admin\AppData\Local\Temp\D56220250089362.dat" "C:\Users\admin\AppData\Local\Temp\in616D0122\37432309_stp\avast_free_antivirus_setup_online.exe" | C:\Windows\system32\cmd.exe | cmd.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
4068 | cmd /d /c del "C:\Users\admin\AppData\Local\Temp\D56220250089361.dat" | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
2376 | cmd /d /c del "C:\Users\admin\AppData\Local\Temp\D56220250089362.dat" | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
2944 | "C:\Users\admin\AppData\Local\Temp\in616D0122\OperaSetup.exe" --silent --otd="utm.medium:pb,utm.source:ais,utm.campaign:Model-10-16_CRT_nc_Y,utm.id:VKNYFxT4CR4R%2BghrEf59bBL8CB0HuVheHPgMGxj6DRsQ%2Bw8ZFvgEGxL%2BGkVHrFlYHIVMT1OrflhOvU9PU%2BxfWEL5DhcT%2BQkYFP8JGBD5%2Fk4AAAAhyjwq" --allusers=0 | C:\Users\admin\AppData\Local\Temp\in616D0122\OperaSetup.exe | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: HIGH Description: Opera Installer Exit code: 0 Version: 57.0.3098.91 Modules
| |||||||||||||||
3472 | "C:\Users\admin\AppData\Local\Temp\in616D0122\37432309_stp\avast_free_antivirus_setup_online.exe" /silent /psh:gRS7b8FP6mbETesTxEmeFMdL62XSDrsmyU/vY81N7mPFTOxhw0/nY8dJ+T2SG7ogyTyJE6cp+TGGHuxgyU/uZ8RK72LFSuz+RwAAAPR931I= | C:\Users\admin\AppData\Local\Temp\in616D0122\37432309_stp\avast_free_antivirus_setup_online.exe | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | ||||||||||||
User: admin Company: AVAST Software Integrity Level: HIGH Description: Avast Antivirus Installer Version: 17.1.3394.0 Modules
| |||||||||||||||
3032 | C:\Users\admin\AppData\Local\Temp\in616D0122\OperaSetup.exe --type=crashpad-handler /prefetch:7 --monitor-self-annotation=ptype=crashpad-handler "--database=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\Crash Reports" "--crash-count-file=C:\Users\admin\AppData\Roaming\Opera Software\Opera Stable\crash_count.txt" --url=https://crashstats-collector.opera.com/collector/submit --annotation=channel=Stable --annotation=plat=Win32 --annotation=prod=OperaDesktop --annotation=ver=57.0.3098.91 --initial-client-data=0xd8,0xe0,0xe4,0xdc,0xe8,0x6e58d5e0,0x6e58d5f0,0x6e58d5fc | C:\Users\admin\AppData\Local\Temp\in616D0122\OperaSetup.exe | OperaSetup.exe | ||||||||||||
User: admin Company: Opera Software Integrity Level: HIGH Description: Opera Installer Exit code: 0 Version: 57.0.3098.91 Modules
|
(PID) Process: | (3012) 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
(PID) Process: | (3012) 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 1 | |||
(PID) Process: | (2108) 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\5F\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (2108) 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
(PID) Process: | (2108) 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 1 | |||
(PID) Process: | (2108) 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\0037 - Super Mario 64 DS (U)(Trashman)_0934887824_RASAPI32 |
Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
(PID) Process: | (2108) 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\0037 - Super Mario 64 DS (U)(Trashman)_0934887824_RASAPI32 |
Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
(PID) Process: | (2108) 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\0037 - Super Mario 64 DS (U)(Trashman)_0934887824_RASAPI32 |
Operation: | write | Name: | FileTracingMask |
Value: 4294901760 | |||
(PID) Process: | (2108) 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\0037 - Super Mario 64 DS (U)(Trashman)_0934887824_RASAPI32 |
Operation: | write | Name: | ConsoleTracingMask |
Value: 4294901760 | |||
(PID) Process: | (2108) 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\0037 - Super Mario 64 DS (U)(Trashman)_0934887824_RASAPI32 |
Operation: | write | Name: | MaxFileSize |
Value: 1048576 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3012 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | C:\Users\admin\AppData\Local\Temp\0020EEE8.log | — | |
MD5:— | SHA256:— | |||
3012 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | C:\Users\admin\AppData\Local\Temp\inH215831254144\css\main.css | text | |
MD5:E746780AAF6A28F0EA4B8E6B0B8EB860 | SHA256:912FC396C3BB2ED56B4970721A12A3A343E6A8729DA2476FA7FA6C80213C6526 | |||
3012 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | C:\Users\admin\AppData\Local\Temp\inH215831254144\css\sdk-ui\browse.css | text | |
MD5:6009D6E864F60AEA980A9DF94C1F7E1C | SHA256:5EF48A8C8C3771B4F233314D50DD3B5AFDCD99DD4B74A9745C8FE7B22207056D | |||
3012 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | C:\Users\admin\AppData\Local\Temp\inH215831254144\css\sdk-ui\button.css | text | |
MD5:37E1FF96E084EC201F0D95FEEF4D5E94 | SHA256:8E806F5B94FC294E918503C8053EF1284E4F4B1E02C7DA4F4635E33EC33E0534 | |||
3012 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | C:\Users\admin\AppData\Local\Temp\inH215831254144\css\sdk-ui\images\progress-bg.png | image | |
MD5:E9F12F92A9EEB8EBE911080721446687 | SHA256:C1CF449536BC2778E27348E45F0F53D04C284109199FB7A9AF7A61016B91F8BC | |||
3012 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | C:\Users\admin\AppData\Local\Temp\inH215831254144\form.bmp.Mask | binary | |
MD5:D2FC989F9C2043CD32332EC0FAD69C70 | SHA256:27DD029405CBFB0C3BF8BAC517BE5DB9AA83E981B1DC2BD5C5D6C549FA514101 | |||
3012 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | C:\Users\admin\AppData\Local\Temp\inH215831254144\images\Pause_Button.png | image | |
MD5:84B37CB510F50C8FEA812EB308D3F03F | SHA256:7BF800336671204DE36B7D1F6CEFFDFF830040F51D21BC44F220F68D72CF492B | |||
3012 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | C:\Users\admin\AppData\Local\Temp\inH215831254144\css\ie6_main.css | text | |
MD5:18DCA6FB20A466C0B3D11758F43862ED | SHA256:05A3AE723FC901EEDD0DAA61224C8C255DC10E655BF00385E6D4BF1F54C889F7 | |||
3012 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | C:\Users\admin\AppData\Local\Temp\inH215831254144\images\Icon_Generic .png | image | |
MD5:FB83D70D885933C3726F9C2864A261DD | SHA256:ED0C0A6D4A60264F36CECA4972500E36AE6BA4F860E147AFE895AE48502FD851 | |||
3012 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | C:\Users\admin\AppData\Local\Temp\inH215831254144\images\Icon_Generic.png | image | |
MD5:A35AEB077FFA7FFB4382C639743D29CC | SHA256:DCCFB478E6097086D886B5A01D120BF511B381982B0975E0C65EAB3846E4234D |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | POST | 200 | 52.214.73.247:80 | http://rp.funtownsoftware.com/ | IE | — | — | malicious |
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | POST | 200 | 52.214.73.247:80 | http://rp.funtownsoftware.com/ | IE | — | — | malicious |
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | POST | 200 | 52.214.73.247:80 | http://rp.funtownsoftware.com/ | IE | — | — | malicious |
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | POST | 200 | 52.214.73.247:80 | http://rp.funtownsoftware.com/ | IE | — | — | malicious |
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | GET | 200 | 146.185.27.53:80 | http://img.funtownsoftware.com/img/Tavasat/15Feb17/v2/EN.png | GB | image | 43.9 Kb | malicious |
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | POST | 200 | 52.214.73.247:80 | http://rp.funtownsoftware.com/ | IE | — | — | malicious |
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | POST | 200 | 52.214.73.247:80 | http://rp.funtownsoftware.com/ | IE | — | — | malicious |
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | POST | 200 | 52.210.70.79:80 | http://os.funtownsoftware.com/Norassie/ | IE | binary | 799 Kb | malicious |
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | POST | 200 | 52.214.73.247:80 | http://rp.funtownsoftware.com/ | IE | — | — | malicious |
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | GET | 200 | 146.185.27.53:80 | http://img.funtownsoftware.com/img/Rowabobeso/icon2.png | GB | image | 422 b | malicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3472 | avast_free_antivirus_setup_online.exe | 77.234.45.54:80 | v7event.stats.avast.com | AVAST Software s.r.o. | DE | unknown |
3472 | avast_free_antivirus_setup_online.exe | 216.58.206.14:80 | www.google-analytics.com | Google Inc. | US | whitelisted |
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | 52.214.73.247:80 | rp.funtownsoftware.com | Amazon.com, Inc. | IE | malicious |
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | 146.185.27.53:80 | img.funtownsoftware.com | UK-2 Limited | GB | malicious |
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | 104.18.58.127:443 | romsmania.cc | Cloudflare Inc | US | shared |
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | 199.201.110.78:80 | cdnus.funtownsoftware.com | Namecheap, Inc. | US | malicious |
2944 | OperaSetup.exe | 185.26.182.95:443 | autoupdate.geo.opera.com | Opera Software AS | — | unknown |
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | 52.210.70.79:80 | os.funtownsoftware.com | Amazon.com, Inc. | IE | malicious |
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | 104.18.52.125:443 | romsmania.com | Cloudflare Inc | US | shared |
2944 | OperaSetup.exe | 82.145.217.121:443 | desktop-netinstaller-sub.osp.opera.software | Opera Software AS | — | suspicious |
Domain | IP | Reputation |
---|---|---|
rp.funtownsoftware.com |
| malicious |
info.funtownsoftware.com |
| malicious |
os.funtownsoftware.com |
| malicious |
romsmania.com |
| suspicious |
romsmania.cc |
| malicious |
img.funtownsoftware.com |
| malicious |
cdneu.funtownsoftware.com |
| malicious |
cdnus.funtownsoftware.com |
| malicious |
www.google-analytics.com |
| whitelisted |
v7event.stats.avast.com |
| whitelisted |
PID | Process | Class | Message |
---|---|---|---|
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | Misc activity | ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M2 |
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | Misc activity | ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M1 |
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | Misc activity | ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M4 |
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | Misc activity | ADWARE [PTsecurity] PUP.Optional.InstallCore Artifact M3 |
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | A Network Trojan was detected | SC TROJAN_DOWNLOADER Possible threat - .exe downloading with HEAD option |
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
2108 | 0037 - Super Mario 64 DS (U)(Trashman)_0934887824.exe | Misc activity | ET INFO EXE IsDebuggerPresent (Used in Malware Anti-Debugging) |
2152 | AvEmUpdate.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
Process | Message |
---|---|
instup.exe | [2019-01-11 13:37:53.353] [error ] [settings ] [ 2256: 2276] Failed to get program directory
Exception: Unable to retrieve path of the program directory!
Code: 0x00000002 (2)
|
assistant_installer.exe | [0111/133903.871:INFO:assistant_installer_main.cc(150)] Running assistant installer with command line "C:\Users\admin\AppData\Local\Temp\opera autoupdate\CProgram FilesOpera\installing\extra_apps_dir/assistant\assistant_installer.exe" --installfolder="C:\Program Files\Opera\assistant" --copyonly=0 --allusers=0
|
assistant_installer.exe | [0111/133903.933:INFO:assistant_installer.cc(229)] Setting up the registry
|
assistant_installer.exe | [0111/133904.542:INFO:assistant_installer.cc(281)] Creating scheduled task
|
assistant_installer.exe | [0111/133904.667:INFO:assistant_installer_main.cc(150)] Running assistant installer with command line "C:\Program Files\Opera\assistant\assistant_installer.exe" --installfolder="C:\Program Files\Opera\assistant" --run-assistant --allusers=0
|
assistant_installer.exe | [0111/133904.667:INFO:assistant_installer.cc(144)] Performing PostElevation Install Tasks
|
assistant_installer.exe | [0111/133904.667:INFO:assistant_installer.cc(192)] Running Assistant
|
browser_assistant.exe | [0111/133911.699:INFO:browser_installation_event_reporter.cc(135)] Installed browsers:
|
browser_assistant.exe | [0111/133911.714:INFO:browser_installation_event_reporter.cc(137)] Chrome
|
browser_assistant.exe | [0111/133911.714:INFO:browser_installation_event_reporter.cc(137)] Firefox
|