File name: | PSO2_Tweaker_Installerv6b.exe |
Full analysis: | https://app.any.run/tasks/d6ecdc58-6b93-4ff9-97ad-ae88bb89b3f4 |
Verdict: | Malicious activity |
Analysis date: | May 30, 2020, 14:15:12 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, InstallShield self-extracting archive |
MD5: | 1A17FD77EAEB41FD8120A266DFCE2861 |
SHA1: | 9A58B6E0B9C0658D0C472068F93F30B48412A0D8 |
SHA256: | 40485D5D70D43432835570A37AE8934073470285870175765E0BF48813557279 |
SSDEEP: | 98304:va4qzo4DByjl4sTqb9dgBgtC7UEVskv4HhlFUPHV9uRYEUdyjQx/G3:S31yjCsub9PteiXXUPHO+fxe3 |
.exe | | | Win32 Executable MS Visual C++ (generic) (41) |
---|---|---|
.exe | | | Win64 Executable (generic) (36.3) |
.dll | | | Win32 Dynamic Link Library (generic) (8.6) |
.exe | | | Win32 Executable (generic) (5.9) |
.exe | | | Win16/32 Executable Delphi generic (2.7) |
Subsystem: | Windows GUI |
---|---|
SubsystemVersion: | 4 |
ImageVersion: | - |
OSVersion: | 4 |
EntryPoint: | 0x1000 |
UninitializedDataSize: | - |
InitializedDataSize: | 259072 |
CodeSize: | 201728 |
LinkerVersion: | 2.5 |
PEType: | PE32 |
TimeStamp: | 2016:09:04 00:28:04+02:00 |
MachineType: | Intel 386 or later, and compatibles |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 03-Sep-2016 22:28:04 |
Detected languages: |
|
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x0090 |
Pages in file: | 0x0003 |
Relocations: | 0x0000 |
Size of header: | 0x0004 |
Min extra paragraphs: | 0x0000 |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x00B8 |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0000 |
Overlay number: | 0x0000 |
OEM identifier: | 0x0000 |
OEM information: | 0x0000 |
Address of NE header: | 0x00000080 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 5 |
Time date stamp: | 03-Sep-2016 22:28:04 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.code | 0x00001000 | 0x00008C0B | 0x00008E00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.48422 |
.text | 0x0000A000 | 0x0002842C | 0x00028600 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.55935 |
.rdata | 0x00033000 | 0x000054AC | 0x00005600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.67857 |
.data | 0x00039000 | 0x00033384 | 0x00032000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.97815 |
.rsrc | 0x0006D000 | 0x00006840 | 0x00006A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.84101 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 4.8674 | 874 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 4.30941 | 744 | UNKNOWN | English - United States | RT_ICON |
3 | 4.03304 | 296 | UNKNOWN | English - United States | RT_ICON |
4 | 6.4265 | 3752 | UNKNOWN | English - United States | RT_ICON |
5 | 6.64193 | 2216 | UNKNOWN | English - United States | RT_ICON |
6 | 5.61672 | 1384 | UNKNOWN | English - United States | RT_ICON |
7 | 5.11499 | 9640 | UNKNOWN | English - United States | RT_ICON |
8 | 5.62416 | 4264 | UNKNOWN | English - United States | RT_ICON |
9 | 6.05238 | 1128 | UNKNOWN | English - United States | RT_ICON |
ADVAPI32.DLL |
COMCTL32.DLL |
GDI32.DLL |
IMAGEHLP.DLL |
KERNEL32.dll |
MSVCRT.dll |
OLE32.DLL |
SETUPAPI.DLL |
SHELL32.DLL |
USER32.DLL |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
372 | "C:\Users\admin\AppData\Local\Temp\PSO2_Tweaker_Installerv6b.exe" | C:\Users\admin\AppData\Local\Temp\PSO2_Tweaker_Installerv6b.exe | — | explorer.exe |
User: admin Integrity Level: MEDIUM Exit code: 3221226540 | ||||
2776 | "C:\Users\admin\AppData\Local\Temp\PSO2_Tweaker_Installerv6b.exe" | C:\Users\admin\AppData\Local\Temp\PSO2_Tweaker_Installerv6b.exe | explorer.exe | |
User: admin Integrity Level: HIGH Exit code: 0 | ||||
3924 | "C:\PSO2 Tweaker\PSO2 Tweaker.exe" | C:\PSO2 Tweaker\PSO2 Tweaker.exe | — | PSO2_Tweaker_Installerv6b.exe |
User: admin Company: Arks-Layer Integrity Level: HIGH Description: PSO2 Tweaker Exit code: 3221225547 Version: 6.0.0.0 | ||||
1620 | "C:\PSO2 Tweaker\PSO2 Tweaker.exe" | C:\PSO2 Tweaker\PSO2 Tweaker.exe | — | PSO2 Tweaker.exe |
User: admin Company: Arks-Layer Integrity Level: HIGH Description: PSO2 Tweaker Exit code: 0 Version: 6.0.0.0 |
PID | Process | Filename | Type | |
---|---|---|---|---|
2776 | PSO2_Tweaker_Installerv6b.exe | C:\USERS\PUBLIC\DESKTOP\PSO2 Tweaker.lnk | lnk | |
MD5:F432D6558B216D9BEC1DD6FADCEDD1E0 | SHA256:6EC96B6BCDFCC3FA67E1F93B52264CB9DC4749AC3623802D56A8EDA1B1645BCC | |||
2776 | PSO2_Tweaker_Installerv6b.exe | C:\Users\admin\AppData\Local\Temp\IF{FAA17EFA-F1F9-418B-8421-9FB7CC890CD3}\languages.dat | text | |
MD5:2F9A77BEB8B287749ED4C95A9A3E0FF5 | SHA256:0447F76CC9B5C503FE8CD78729C6E0466E4E0313305A45414A53EA25CCB745BA | |||
2776 | PSO2_Tweaker_Installerv6b.exe | C:\PSO2 Tweaker\PSO2 Tweaker.exe | executable | |
MD5:4AA51DB5F02156F661F09C2A15057946 | SHA256:8368F28B1A6B84BE5B701E453287F4BBB08A6C5C8117524411C65FBE4B292A7F | |||
2776 | PSO2_Tweaker_Installerv6b.exe | C:\Users\admin\AppData\Local\Temp\IF{FAA17EFA-F1F9-418B-8421-9FB7CC890CD3}\Startmenu.dat | text | |
MD5:2841842E21C8C92C22C94F116CA058A3 | SHA256:E471552C53731579C1C1F48DBDDE69B7E7F908065715A6202854A60F8C170A22 | |||
2776 | PSO2_Tweaker_Installerv6b.exe | C:\Users\admin\AppData\Local\Temp\IF{FAA17EFA-F1F9-418B-8421-9FB7CC890CD3}\Desktop.dat | text | |
MD5:2841842E21C8C92C22C94F116CA058A3 | SHA256:E471552C53731579C1C1F48DBDDE69B7E7F908065715A6202854A60F8C170A22 | |||
2776 | PSO2_Tweaker_Installerv6b.exe | C:\Users\admin\AppData\Local\Temp\IF{FAA17EFA-F1F9-418B-8421-9FB7CC890CD3}\Image_Left.jpg | image | |
MD5:761C46EFA8DAD58359DD2E51EA4814FB | SHA256:B6B9395861F8146C5F1EB98D2BED5493290CBA27CCC6BB7FA0AA0B07BEA61E46 | |||
2776 | PSO2_Tweaker_Installerv6b.exe | C:\Users\admin\AppData\Local\Temp\IF{FAA17EFA-F1F9-418B-8421-9FB7CC890CD3}\Setup.cab | compressed | |
MD5:A9D11FC449C0CEA0F0CC2120D8A77D17 | SHA256:FBDAB6E55A9778563C95838AC55049F5819417EE8D303C5A78A6B2AC32ACAD23 | |||
2776 | PSO2_Tweaker_Installerv6b.exe | C:\Users\admin\AppData\Local\Temp\IF{FAA17EFA-F1F9-418B-8421-9FB7CC890CD3}\isps.dat | image | |
MD5:8F27F6E28C6DFB578DF734F939A019D8 | SHA256:2D05B7EAF0148E732245519FF29A288DC41AD8B5F84D1B42200F518D1232ADA4 | |||
3924 | PSO2 Tweaker.exe | C:\PSO2 Tweaker\logfile.txt | — | |
MD5:— | SHA256:— | |||
1620 | PSO2 Tweaker.exe | C:\PSO2 Tweaker\logfile.txt | — | |
MD5:— | SHA256:— |