| File name: | aqua_energizer.exe |
| Full analysis: | https://app.any.run/tasks/c19b8554-c6ed-4956-af04-64dbcd0f4516 |
| Verdict: | No threats detected |
| Analysis date: | February 07, 2020, 01:49:16 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | E1F25DCF28EB1F3E0068B3661C3F457A |
| SHA1: | 46F39D28C907F4C10EC84C07518EF5F56D7B4992 |
| SHA256: | 3AC66F108F6E8756CEAEFBB849B00EE0FAFB80D9429977E1464C86457E671E07 |
| SSDEEP: | 12288:ELZjMPEhzcCG4HWgun73DbwPmbUn9w4r6qlzJe+wk0o:lMWgunTDEPmE/7s1k0o |
| .exe | | | Win32 Executable Microsoft Visual Basic 6 (63.9) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (24.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (5.1) |
| .exe | | | Win32 Executable (generic) (3.5) |
| .exe | | | Generic Win/DOS Executable (1.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2002:04:19 08:32:37+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 196608 |
| InitializedDataSize: | 77824 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x12c0 |
| OSVersion: | 4 |
| ImageVersion: | 1 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.1591 |
| ProductVersionNumber: | 1.0.0.1591 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| Comments: | - |
| CompanyName: | - |
| FileDescription: | - |
| LegalCopyright: | - |
| LegalTrademarks: | - |
| ProductName: | Aqua Energizer |
| FileVersion: | 1.00.1591 |
| ProductVersion: | 1.00.1591 |
| InternalName: | Player |
| OriginalFileName: | Player.exe |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1748 | "C:\Users\admin\AppData\Local\Temp\aqua_energizer.exe" | C:\Users\admin\AppData\Local\Temp\aqua_energizer.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Version: 1.00.1591 Modules
| |||||||||||||||
| 2756 | inflate C:\Users\admin\AppData\Local\Temp\3CV9Z33\LAUNCH.EXE$ | C:\Users\admin\AppData\Local\Temp\3CV9Z33\inflate.exe | aqua_energizer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3432 | inflate C:\Users\admin\AppData\Local\Temp\3CV9Z33\aqua.swf$ | C:\Users\admin\AppData\Local\Temp\3CV9Z33\inflate.exe | — | aqua_energizer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (1748) aqua_energizer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (1748) aqua_energizer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1748 | aqua_energizer.exe | C:\Users\admin\AppData\Local\Temp\3CV9Z33\LAUNCH.EXE$ | — | |
MD5:— | SHA256:— | |||
| 1748 | aqua_energizer.exe | C:\Users\admin\AppData\Local\Temp\3CV9Z33\aqua.swf$ | — | |
MD5:— | SHA256:— | |||
| 1748 | aqua_energizer.exe | C:\Users\admin\AppData\Local\Temp\3CV9Z33\aqua_energizer.ico | — | |
MD5:— | SHA256:— | |||
| 1748 | aqua_energizer.exe | C:\Users\admin\AppData\Local\Temp\~DFDFF81CA08F01F472.TMP | — | |
MD5:— | SHA256:— | |||
| 1748 | aqua_energizer.exe | C:\Users\admin\AppData\Local\Temp\3CV9Z33\INFLATE.EXE | executable | |
MD5:96E7ED62F6AA33E0ACDC2974B8B8C890 | SHA256:37E0DC741C67B383BC0FB9DF7F3D59118C567B545E253CBD24B082D3D9E19331 | |||
| 1748 | aqua_energizer.exe | C:\Users\admin\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sol | sol | |
MD5:64A3B550FCAB63CE591EE0FA43672347 | SHA256:872FF17A2D3C880C9F8558BF42ADBD0DC9463714144512CF982CC787365372B9 | |||
| 3432 | inflate.exe | C:\Users\admin\AppData\Local\Temp\3CV9Z33\aqua.swf | swf | |
MD5:71AAB962761ED38F91835F745E9BCFF7 | SHA256:B9F3FFFE6C665EF57E4B4527AE4D47CCB9AD607B78FB1B69C2A01BEDA7986C6C | |||
| 1748 | aqua_energizer.exe | C:\Users\admin\AppData\Local\Temp\3CV9Z33\block.sdf | binary | |
MD5:6BD5015B8AA3ED542CE54679C8871A1F | SHA256:99018BF249AD46F44E16589697232779EF52375360E0D38DF57871F88CBB92F9 | |||
| 2756 | inflate.exe | C:\Users\admin\AppData\Local\Temp\3CV9Z33\LAUNCH.EXE | executable | |
MD5:732C98ED25BFBEEC8E214DF0D6100C2B | SHA256:5F78F7AD5055A2D9AE5AD5177C2F3219EDE076C6D07054AB0A05050300BC1769 | |||
| 1748 | aqua_energizer.exe | C:\Users\admin\AppData\Roaming\Macromedia\Flash Player\macromedia.com\support\flashplayer\sys\settings.sxx | sol | |
MD5:8D8E33F5F89585553109A40A90CB7FCC | SHA256:4428C7D57355E006AB1EFCBB20DB15EAA3BEA740213F664F2835499285B88411 | |||