| File name: | rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.exe |
| Full analysis: | https://app.any.run/tasks/892e0833-1265-49c0-a11f-d08034748ab9 |
| Verdict: | Malicious activity |
| Analysis date: | May 15, 2024, 18:26:37 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 4CB945C7742D8BE2E123129156A3238C |
| SHA1: | 8B38C383B02251B235CF8BABD7E9305433D8CB4A |
| SHA256: | 49661AF76B4F466A04ACDF6363841CF25E1FB485E732334FF76C20727F810FFF |
| SSDEEP: | 98304:Egy8j3xzcFwGr/7U2Qh71sMJa1mgC0RxgwJpzG2GDhctMDK8HzyY8dhyYUxPqTcI:+px/kf8pogqRF98RAp1pi |
| .exe | | | Win32 Executable Delphi generic (45.2) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (20.9) |
| .exe | | | Win32 Executable (generic) (14.3) |
| .exe | | | Win16/32 Executable Delphi generic (6.6) |
| .exe | | | Generic Win/DOS Executable (6.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2016:04:06 14:39:04+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 66560 |
| InitializedDataSize: | 49664 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x117dc |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.3.7.492 |
| ProductVersionNumber: | 1.3.7.492 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | AFMG Technologies GmbH |
| FileDescription: | AFMG EASERA SysTune v1.3.7 |
| FileVersion: | 1.3.7.492 |
| LegalCopyright: | © AFMG Technologies GmbH 2007-2014 |
| ProductName: | LevelOne |
| ProductVersion: | 1.3.7.492 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 748 | "C:\Users\admin\Desktop\rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.exe" /SPAWNWND=$1013A /NOTIFYWND=$3012C | C:\Users\admin\Desktop\rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.exe | rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | ||||||||||||
User: admin Company: AFMG Technologies GmbH Integrity Level: HIGH Description: AFMG EASERA SysTune v1.3.7 Exit code: 0 Version: 1.3.7.492 Modules
| |||||||||||||||
| 1064 | "C:\Users\admin\AppData\Local\Temp\is-8POH0.tmp\rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp" /SL5="$2013C,14957451,117248,C:\Users\admin\Desktop\rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.exe" /SPAWNWND=$1013A /NOTIFYWND=$3012C | C:\Users\admin\AppData\Local\Temp\is-8POH0.tmp\rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1764 | "C:\Program Files\AFMG\EASERA SysTune\EASERA SysTune.exe" | C:\Program Files\AFMG\EASERA SysTune\EASERA SysTune.exe | — | explorer.exe | |||||||||||
User: admin Company: AFMG Technologies GmbH Integrity Level: MEDIUM Description: EASERA SysTune Version: 1.3.7.492 Modules
| |||||||||||||||
| 4012 | "C:\Users\admin\Desktop\rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.exe" | C:\Users\admin\Desktop\rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.exe | — | explorer.exe | |||||||||||
User: admin Company: AFMG Technologies GmbH Integrity Level: MEDIUM Description: AFMG EASERA SysTune v1.3.7 Exit code: 0 Version: 1.3.7.492 Modules
| |||||||||||||||
| 4032 | "C:\Users\admin\AppData\Local\Temp\is-BC7SG.tmp\rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp" /SL5="$3012C,14957451,117248,C:\Users\admin\Desktop\rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.exe" | C:\Users\admin\AppData\Local\Temp\is-BC7SG.tmp\rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | — | rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| (PID) Process: | (1064) rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 28040000E27BCE73F5A6DA01 | |||
| (PID) Process: | (1064) rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: A0F76206B31E2BFC3BF43DE686229BA87BCB2F10AD9662740F168712379DC6FD | |||
| (PID) Process: | (1064) rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (1064) rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Program Files\AFMG\AFMG Licence Manager\AFMG Licence Manager.exe | |||
| (PID) Process: | (1064) rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFilesHash |
Value: A21402A2013303B2A41BE290E68BD5679FB1572F20535820AA538CB0BF7E0F3D | |||
| (PID) Process: | (1064) rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\AFMG\AFMG Licence Manager |
| Operation: | write | Name: | Program Path |
Value: C:\Program Files\AFMG\AFMG Licence Manager\ | |||
| (PID) Process: | (1064) rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\EASERA SysTune.Config\shell\open\command |
| Operation: | write | Name: | command |
Value: hex(7):34,21,6a,74,3f,31,24,32,40,40,2e,5d,4d,3d,53,4e,60,6a,4a,48,3e,57,58,4e,41,61,2e,7d,28,45,3f,2d,7e,30,37,36,49,30,78,5e,39,20,22,25,31,22,00,00 | |||
| (PID) Process: | (1064) rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\AFMG\EASERA SysTune |
| Operation: | write | Name: | Program Path |
Value: C:\Program Files\AFMG\EASERA SysTune\ | |||
| (PID) Process: | (1064) rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\AFMG\EASERA SysTune |
| Operation: | write | Name: | AppData Path |
Value: C:\ProgramData\AFMG\EASERA SysTune | |||
| (PID) Process: | (1064) rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\AFMG\EASERA SysTune |
| Operation: | write | Name: | UserData Path |
Value: C:\Users\Public\Documents\AFMG\EASERA SysTune | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4012 | rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.exe | C:\Users\admin\AppData\Local\Temp\is-BC7SG.tmp\rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | — | |
MD5:— | SHA256:— | |||
| 1064 | rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | C:\Program Files\AFMG\EASERA SysTune\is-7TB12.tmp | — | |
MD5:— | SHA256:— | |||
| 1064 | rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | C:\Program Files\AFMG\AFMG Licence Manager\is-IF48P.tmp | — | |
MD5:— | SHA256:— | |||
| 1064 | rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | C:\Program Files\AFMG\AFMG Licence Manager\is-SDB5H.tmp | — | |
MD5:— | SHA256:— | |||
| 1064 | rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | C:\Program Files\AFMG\AFMG Licence Manager\AFMG Licence Manager.XmlSerializers.dll | — | |
MD5:— | SHA256:— | |||
| 1064 | rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | C:\Program Files\AFMG\AFMG Licence Manager\AFMG.Licencing.Definitions.dll | — | |
MD5:— | SHA256:— | |||
| 1064 | rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | C:\Program Files\AFMG\EASERA SysTune\ADIV.url | — | |
MD5:— | SHA256:— | |||
| 1064 | rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | C:\Program Files\AFMG\EASERA SysTune\AFMGInfoSampler.exe | — | |
MD5:— | SHA256:— | |||
| 1064 | rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | C:\Program Files\AFMG\EASERA SysTune\is-J9RUM.tmp | — | |
MD5:— | SHA256:— | |||
| 1064 | rsload.net.EASERA.SysTune.Pro.v1.3.7.CE.tmp | C:\Program Files\AFMG\EASERA SysTune\Crp32dll.dll | — | |
MD5:— | SHA256:— | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |