File name: | 4621984fa691bd80870e3e3f15cc83121a5862cef4abf2989844d858b2c64b0f.exe |
Full analysis: | https://app.any.run/tasks/d5858056-41b0-4f71-a81b-ad39b10b0f5b |
Verdict: | Malicious activity |
Threats: | A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection. |
Analysis date: | September 29, 2020, 17:06:06 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 2B8191C867A85313C85AAF7DE35FD9EA |
SHA1: | 856B7A2B8C4B6AFAC6F604FC5397F0B2E0D6915E |
SHA256: | 4621984FA691BD80870E3E3F15CC83121A5862CEF4ABF2989844D858B2C64B0F |
SSDEEP: | 24576:DRQvMp+/QlYqSS3A6PzFxXPn4h6AjDptp:DmMpYYAS3zFxXIX |
.exe | | | Win32 Executable (generic) (52.9) |
---|---|---|
.exe | | | Generic Win/DOS Executable (23.5) |
.exe | | | DOS Executable Generic (23.5) |
SpecialBuild: | - |
---|---|
ProductVersion: | 07.02.00.01 |
ProductName: | ExentCtl Module |
PrivateBuild: | Free Ride Games.exe 1, 0, 0, 19 |
OriginalFileName: | ExentCtl.ocx |
OLESelfRegister: | - |
LegalTrademarks: | - |
LegalCopyright: | Copyright © 1996-2007 Exent Technologies Ltd. All rights reserved. |
InternalName: | ExentCtl |
FileVersion: | 07.02.00.01 |
FileDescription: | ExentCtl Module |
CompanyName: | Exent Technologies Ltd. |
Comments: | Release. |
CharacterSet: | Unicode |
LanguageCode: | English (U.S.) |
FileSubtype: | - |
ObjectFileType: | Dynamic link library |
FileOS: | Win32 |
FileFlags: | (none) |
FileFlagsMask: | 0x003f |
ProductVersionNumber: | 7.2.0.1 |
FileVersionNumber: | 7.2.0.1 |
Subsystem: | Windows GUI |
SubsystemVersion: | 4 |
ImageVersion: | - |
OSVersion: | 4 |
EntryPoint: | 0x92b6 |
UninitializedDataSize: | - |
InitializedDataSize: | 950272 |
CodeSize: | 69632 |
LinkerVersion: | 6 |
PEType: | PE32 |
TimeStamp: | 2008:08:20 15:51:24+02:00 |
MachineType: | Intel 386 or later, and compatibles |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 20-Aug-2008 13:51:24 |
Detected languages: |
|
Comments: | Release. |
CompanyName: | Exent Technologies Ltd. |
FileDescription: | ExentCtl Module |
FileVersion: | 07.02.00.01 |
InternalName: | ExentCtl |
LegalCopyright: | Copyright © 1996-2007 Exent Technologies Ltd. All rights reserved. |
LegalTrademarks: | - |
OLESelfRegister: | - |
OriginalFilename: | ExentCtl.ocx |
PrivateBuild: | Free Ride Games.exe 1, 0, 0, 19 |
VVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVVV: | - |
ProductName: | ExentCtl Module |
ProductVersion: | 07.02.00.01 |
SpecialBuild: | - |
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x0090 |
Pages in file: | 0x0003 |
Relocations: | 0x0000 |
Size of header: | 0x0004 |
Min extra paragraphs: | 0x0000 |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x00B8 |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0000 |
Overlay number: | 0x0000 |
OEM identifier: | 0x0000 |
OEM information: | 0x0000 |
Address of NE header: | 0x000000E8 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 4 |
Time date stamp: | 20-Aug-2008 13:51:24 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x00010802 | 0x00011000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.53759 |
.rdata | 0x00012000 | 0x000024C5 | 0x00003000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.17393 |
.data | 0x00015000 | 0x00004BC8 | 0x00004000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.30338 |
.rsrc | 0x0001A000 | 0x000E05C4 | 0x000E1000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.71732 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 3.42035 | 1196 | Latin 1 / Western European | English - United States | RT_VERSION |
1000 | 2.16096 | 20 | Latin 1 / Western European | Hebrew - Israel | RT_GROUP_ICON |
1100 | 2.55327 | 66 | Latin 1 / Western European | Hebrew - Israel | RT_DIALOG |
2000 | 7.74106 | 904488 | Latin 1 / Western European | English - United States | SETUP |
2002 | 4.98616 | 196 | Latin 1 / Western European | English - United States | GENERALSETTINGS |
COMCTL32.dll |
KERNEL32.dll |
SHELL32.dll |
USER32.dll |
VERSION.dll |
ole32.dll |
Title | Ordinal | Address |
---|---|---|
??0IExentCtlInstaller@@QAE@ABV0@@Z | 1 | 0x00001F33 |
??0IExentCtlInstaller@@QAE@XZ | 2 | 0x00001F2A |
??4IExentCtlInstaller@@QAEAAV0@ABV0@@Z | 3 | 0x00001F3E |
??_7IExentCtlInstaller@@6B@ | 4 | 0x0001225C |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
3304 | "C:\Users\admin\AppData\Local\Temp\4621984fa691bd80870e3e3f15cc83121a5862cef4abf2989844d858b2c64b0f.exe" | C:\Users\admin\AppData\Local\Temp\4621984fa691bd80870e3e3f15cc83121a5862cef4abf2989844d858b2c64b0f.exe | explorer.exe | ||||||||||||
User: admin Company: Exent Technologies Ltd. Integrity Level: MEDIUM Description: ExentCtl Module Exit code: 18 Version: 07.02.00.01 Modules
| |||||||||||||||
1840 | "C:\Users\admin\AppData\Local\Temp\SDM143\Free Ride Games.exe" "u 'http://www.freeridegames.com/do/SDMC?action=config&type=NO_TB&contentId=%d' p '143' c '748750' l 'Installer'" | C:\Users\admin\AppData\Local\Temp\SDM143\Free Ride Games.exe | 4621984fa691bd80870e3e3f15cc83121a5862cef4abf2989844d858b2c64b0f.exe | ||||||||||||
User: admin Company: Exent Technologies Ltd. Integrity Level: MEDIUM Description: FreeRide Games Application Version: 1, 0, 0, 19 Modules
| |||||||||||||||
2120 | cmd /c ""C:\Users\admin\AppData\Local\Temp\_uninsep.bat" " | C:\Windows\system32\cmd.exe | — | 4621984fa691bd80870e3e3f15cc83121a5862cef4abf2989844d858b2c64b0f.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
824 | read | C:\Users\admin\AppData\Local\Temp\SDM143\cmhelper.exe | — | Free Ride Games.exe | |||||||||||
User: admin Company: Exent Technologies Ltd. Integrity Level: LOW Description: cmhelper Exit code: 0 Version: 1, 0, 0, 10 Modules
| |||||||||||||||
1764 | write | C:\Users\admin\AppData\Local\Temp\SDM143\cmhelper.exe | — | Free Ride Games.exe | |||||||||||
User: admin Company: Exent Technologies Ltd. Integrity Level: LOW Description: cmhelper Exit code: 0 Version: 1, 0, 0, 10 Modules
| |||||||||||||||
3716 | write | C:\Users\admin\AppData\Local\Temp\SDM143\cmhelper.exe | — | Free Ride Games.exe | |||||||||||
User: admin Company: Exent Technologies Ltd. Integrity Level: LOW Description: cmhelper Exit code: 0 Version: 1, 0, 0, 10 Modules
| |||||||||||||||
2860 | write | C:\Users\admin\AppData\Local\Temp\SDM143\cmhelper.exe | — | Free Ride Games.exe | |||||||||||
User: admin Company: Exent Technologies Ltd. Integrity Level: LOW Description: cmhelper Exit code: 0 Version: 1, 0, 0, 10 Modules
| |||||||||||||||
2332 | "C:\Users\admin\AppData\Local\Temp\SDM143\FreeRideGames.exe" /s | C:\Users\admin\AppData\Local\Temp\SDM143\FreeRideGames.exe | Free Ride Games.exe | ||||||||||||
User: admin Company: Exent Technologies Ltd. Integrity Level: HIGH Description: Free Ride Games Version: 07.04.77.06 Modules
| |||||||||||||||
3976 | "C:\Users\admin\AppData\Local\Temp\pft4890.tmp\Setup.exe" -s | C:\Users\admin\AppData\Local\Temp\pft4890.tmp\Setup.exe | FreeRideGames.exe | ||||||||||||
User: admin Company: InstallShield Software Corporation Integrity Level: HIGH Description: InstallShield (R) Setup Launcher Version: 6, 31, 100, 1190 Modules
| |||||||||||||||
3948 | "C:\Program Files\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe" -RegServer | C:\Program Files\Common Files\InstallShield\Engine\6\Intel 32\IKernel.exe | — | Setup.exe | |||||||||||
User: admin Company: InstallShield Software Corporation Integrity Level: HIGH Description: InstallShield (R) Setup Engine Exit code: 3221225547 Version: 6, 31, 100, 1221 Modules
|
(PID) Process: | (3304) 4621984fa691bd80870e3e3f15cc83121a5862cef4abf2989844d858b2c64b0f.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
(PID) Process: | (3304) 4621984fa691bd80870e3e3f15cc83121a5862cef4abf2989844d858b2c64b0f.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 1 | |||
(PID) Process: | (1840) Free Ride Games.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
(PID) Process: | (1840) Free Ride Games.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
Operation: | write | Name: | SavedLegacySettings |
Value: 46000000A5000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
(PID) Process: | (1840) Free Ride Games.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
(PID) Process: | (1840) Free Ride Games.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 1 | |||
(PID) Process: | (1840) Free Ride Games.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
Operation: | write | Name: | CachePrefix |
Value: | |||
(PID) Process: | (1840) Free Ride Games.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
(PID) Process: | (1840) Free Ride Games.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
(PID) Process: | (824) cmhelper.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\LowCache\Content |
Operation: | write | Name: | CachePrefix |
Value: |
PID | Process | Filename | Type | |
---|---|---|---|---|
3304 | 4621984fa691bd80870e3e3f15cc83121a5862cef4abf2989844d858b2c64b0f.exe | C:\Users\admin\AppData\Local\Temp\SDM143\003BA5A7 | — | |
MD5:— | SHA256:— | |||
1840 | Free Ride Games.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Q4SEPDNP.txt | — | |
MD5:— | SHA256:— | |||
1840 | Free Ride Games.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\CATU4YF4.txt | — | |
MD5:— | SHA256:— | |||
1840 | Free Ride Games.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\UGD4YI15.txt | — | |
MD5:— | SHA256:— | |||
1840 | Free Ride Games.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-shm | — | |
MD5:— | SHA256:— | |||
1840 | Free Ride Games.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\JE5SM6CO.txt | — | |
MD5:— | SHA256:— | |||
1764 | cmhelper.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\YATGOCAY.txt | — | |
MD5:— | SHA256:— | |||
1840 | Free Ride Games.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite-wal | — | |
MD5:— | SHA256:— | |||
1840 | Free Ride Games.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\SUIDQIX7.txt | — | |
MD5:— | SHA256:— | |||
3716 | cmhelper.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Cookies\Low\H7FA5LN0.txt | — | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
1840 | Free Ride Games.exe | HEAD | 200 | 104.16.41.24:80 | http://dts1.freeridegames.com/FRG_site/downloads/EXEtender_Default.exe | US | — | — | suspicious |
2852 | IKernel.exe | POST | 200 | 104.16.41.24:80 | http://www.freeridegames.com/opTools/clientTracking.jsp?track=playerinstallationstart&muid=30300030ADD1ADD2ADD33647C4BA99FF4C411000AB3B2966C268C771588316DD00067EDB&ver=117733126 | US | — | — | suspicious |
1840 | Free Ride Games.exe | GET | 302 | 104.16.40.24:80 | http://www.freeridegames.com/do/SDMC?action=config&type=NO_TB&contentId=748750 | US | — | — | suspicious |
2852 | IKernel.exe | POST | — | 104.16.41.24:80 | http://www.freeridegames.com/opTools/clientTracking.jsp?trackEvent=clientInstallationFinished&ver=117733126&muid=30300030ADD1ADD2ADD33647C4BA99FF4C411000AB3B2966C268C771588316DD00067EDB | US | — | — | suspicious |
1840 | Free Ride Games.exe | GET | 206 | 104.16.41.24:80 | http://dts1.freeridegames.com/FRG_site/downloads/EXEtender_Default.exe | US | binary | 2.45 Mb | suspicious |
1840 | Free Ride Games.exe | GET | 206 | 104.16.41.24:80 | http://dts1.freeridegames.com/FRG_site/downloads/EXEtender_Default.exe | US | flc | 2.45 Mb | suspicious |
1840 | Free Ride Games.exe | GET | 200 | 104.16.40.24:80 | http://www.freeridegames.com/do/SDM?action=config&contentId=748750&type=NO_TB | US | xml | 1.93 Kb | suspicious |
1840 | Free Ride Games.exe | POST | 200 | 104.16.40.24:80 | http://www.freeridegames.com/opTools/clientTracking.jsp?trackEvent=SDM_DownloadFinished&sdmVersion=01.51.00.52&muid=30300030DE44205241533647C4BA99FF00000800AB3B2966C268C771588316DD00067EDB | US | xml | 1.93 Kb | suspicious |
1840 | Free Ride Games.exe | GET | 206 | 104.16.41.24:80 | http://dts1.freeridegames.com/FRG_site/downloads/EXEtender_Default.exe | US | executable | 2.45 Mb | suspicious |
1840 | Free Ride Games.exe | POST | 200 | 104.16.40.24:80 | http://www.freeridegames.com/opTools/clientTracking.jsp?trackEvent=SDM_DownloadStart&sdmVersion=01.51.00.52&fileName=http://dts1.freeridegames.com/FRG_site/downloads/EXEtender_Default.exe&muid=30300030DE44205241533647C4BA99FF00000800AB3B2966C268C771588316DD00067EDB | US | xml | 1.93 Kb | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
1840 | Free Ride Games.exe | 104.16.41.24:80 | www.freeridegames.com | Cloudflare Inc | US | shared |
1840 | Free Ride Games.exe | 104.16.124.74:80 | img.exent.com | Cloudflare Inc | US | shared |
1840 | Free Ride Games.exe | 104.16.123.74:80 | img.exent.com | Cloudflare Inc | US | shared |
2852 | IKernel.exe | 104.16.41.24:80 | www.freeridegames.com | Cloudflare Inc | US | shared |
1840 | Free Ride Games.exe | 104.16.40.24:80 | www.freeridegames.com | Cloudflare Inc | US | shared |
Domain | IP | Reputation |
---|---|---|
www.freeridegames.com |
| suspicious |
dns.msftncsi.com |
| shared |
img.exent.com |
| suspicious |
dts1.freeridegames.com |
| suspicious |
PID | Process | Class | Message |
---|---|---|---|
— | — | A Network Trojan was detected | ET POLICY FreeRide Games Some AVs report as TrojWare.Win32.Trojan.Agent.Gen |
— | — | A Network Trojan was detected | ET POLICY FreeRide Games Some AVs report as TrojWare.Win32.Trojan.Agent.Gen |
— | — | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
Process | Message |
---|---|
4621984fa691bd80870e3e3f15cc83121a5862cef4abf2989844d858b2c64b0f.exe | Selfdestruct !!! |
Free Ride Games.exe |
******SDM CommandLine: "u 'http://www.freeridegames.com/do/SDMC?action=config&type=NO_TB&contentId=%d' p '143' c '748750' l 'Installer'" |
Free Ride Games.exe | ******External Result: 32 |
Free Ride Games.exe |
******EXTERNAL: SDM_GetOSBitType |
Free Ride Games.exe | ******Func Result: LoadPage: res://C:\Users\admin\AppData\Local\Temp\SDM143\resourceDll.dll/HTML/index.html |
Free Ride Games.exe |
******SDM FetchConfigurationXML: OK |
Free Ride Games.exe | ******Func Result: CS: Failed |
Free Ride Games.exe | ******Func Result: SyncCookies: Failed to sync www.freeridegames.com using CSNamesEx, CS error = 4 |
Free Ride Games.exe | IsInstallPlayerRequired - OCX |
Free Ride Games.exe | ******Request Status: OK |