| File name: | SportZone_1.5.1.exe |
| Full analysis: | https://app.any.run/tasks/a8668d8b-aa83-4c44-94f7-b3546e231a59 |
| Verdict: | Malicious activity |
| Analysis date: | October 05, 2019, 18:17:49 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 946C86867655B804D510A1F42A623988 |
| SHA1: | 4D1187E5E11C051AB08060B02FC3BF6F9054C586 |
| SHA256: | 49AD0D1C94A41CB234CEBE97A8660CFFF82E562171A2D61DDF1C29D1CAC60794 |
| SSDEEP: | 6144:Maaw+iHiiAoDuTBQtLEqj4fS+JR9W6aHthlSfz3GgKMkmZ58Z:MaawYiAoDuTCLEwuJJvWjHcfz3GZmZs |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2016:08:30 21:51:23+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 66048 |
| InitializedDataSize: | 66560 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1622 |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 30-Aug-2016 19:51:23 |
| Detected languages: |
|
| Debug artifacts: |
|
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000E0 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 30-Aug-2016 19:51:23 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00010087 | 0x00010200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.66007 |
.rdata | 0x00012000 | 0x0000573A | 0x00005800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.6728 |
.data | 0x00018000 | 0x00003940 | 0x00000E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.71842 |
.rsrc | 0x0001C000 | 0x000085F8 | 0x00008600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.41534 |
.reloc | 0x00025000 | 0x0000167C | 0x00001800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 3.91103 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 4.79597 | 346 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 3.70864 | 2216 | Latin 1 / Western European | English - United States | RT_ICON |
3 | 2.42353 | 1384 | Latin 1 / Western European | English - United States | RT_ICON |
4 | 7.9382 | 10937 | Latin 1 / Western European | English - United States | RT_ICON |
5 | 4.70082 | 9640 | Latin 1 / Western European | English - United States | RT_ICON |
6 | 5.2161 | 4264 | Latin 1 / Western European | English - United States | RT_ICON |
7 | 5.37436 | 1128 | Latin 1 / Western European | English - United States | RT_ICON |
100 | 2.71858 | 104 | Latin 1 / Western European | English - United States | RT_GROUP_ICON |
KERNEL32.dll |
SHELL32.dll |
SHLWAPI.dll |
USER32.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1360 | "C:\Program Files\SportZone\SportZone.exe" | C:\Program Files\SportZone\SportZone.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2248 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2404 | "C:\Users\admin\AppData\Local\Temp\AIRE183.tmp\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe" -runtime C:\Users\admin\AppData\Local\Temp\AIRE183.tmp -withRuntime -url C:\Users\admin\AppData\Local\Temp\AIR4C77.tmp\SportZone | C:\Users\admin\AppData\Local\Temp\AIRE183.tmp\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe | Adobe AIR Installer.exe | ||||||||||||
User: admin Company: Adobe Integrity Level: MEDIUM Description: Adobe AIR Application Installer Exit code: 0 Version: 32.0.0.125 Modules
| |||||||||||||||
| 2428 | "C:\Users\admin\AppData\Local\Temp\AIR4C77.tmp\Install SportZone.exe" | C:\Users\admin\AppData\Local\Temp\AIR4C77.tmp\Install SportZone.exe | SportZone_1.5.1.exe | ||||||||||||
User: admin Company: Adobe Systems Inc. Integrity Level: MEDIUM Description: Adobe Bootstrapping Utility Exit code: 0 Version: 23.0.0.257 Modules
| |||||||||||||||
| 2448 | "C:\Users\admin\AppData\Local\Temp\AIRE183.tmp\Adobe AIR Installer.exe" -x1 "C:\Users\admin\AppData\Local\Temp\AIR4C77.tmp\SportZone" | C:\Users\admin\AppData\Local\Temp\AIRE183.tmp\Adobe AIR Installer.exe | — | AIRRuntimeInstaller.exe | |||||||||||
User: admin Company: Adobe Integrity Level: MEDIUM Description: Adobe AIR Installer Exit code: 0 Version: 32.0.0.125 Modules
| |||||||||||||||
| 2624 | "C:\Program Files\SportZone\SportZone.exe" | C:\Program Files\SportZone\SportZone.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2940 | "C:\Users\admin\AppData\Local\Temp\SportZone_1.5.1.exe" | C:\Users\admin\AppData\Local\Temp\SportZone_1.5.1.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3148 | "C:\Users\admin\AppData\Local\Temp\AIRRuntimeInstaller.exe" -x1 "C:\Users\admin\AppData\Local\Temp\AIR4C77.tmp\SportZone" | C:\Users\admin\AppData\Local\Temp\AIRRuntimeInstaller.exe | Install SportZone.exe | ||||||||||||
User: admin Company: Adobe Integrity Level: MEDIUM Description: Adobe AIR Installer Exit code: 0 Version: 32.0.0.125 Modules
| |||||||||||||||
| 3164 | "C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe" -updatecheck | C:\Program Files\Common Files\Adobe AIR\Versions\1.0\Resources\Adobe AIR Updater.exe | SportZone.exe | ||||||||||||
User: admin Company: Adobe Integrity Level: MEDIUM Description: Adobe AIR Installer Exit code: 0 Version: 32.0.0.125 Modules
| |||||||||||||||
| 3392 | "C:\Users\admin\AppData\Local\Temp\AIRE183.tmp\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe" -stdio \\.\pipe\AIR_2404_0 -runtime C:\Users\admin\AppData\Local\Temp\AIRE183.tmp -silent -logToStdout -withRuntime -url -location "C:\Program Files" -desktopShortcut -programMenu C:\Users\admin\AppData\Local\Temp\AIR4C77.tmp\SportZone | C:\Users\admin\AppData\Local\Temp\AIRE183.tmp\Adobe AIR\Versions\1.0\Adobe AIR Application Installer.exe | Adobe AIR Application Installer.exe | ||||||||||||
User: admin Company: Adobe Integrity Level: HIGH Description: Adobe AIR Application Installer Exit code: 0 Version: 32.0.0.125 Modules
| |||||||||||||||
| (PID) Process: | (2940) SportZone_1.5.1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2940) SportZone_1.5.1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2428) Install SportZone.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Install SportZone_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (2428) Install SportZone.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Install SportZone_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (2428) Install SportZone.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Install SportZone_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (2428) Install SportZone.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Install SportZone_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: 4294901760 | |||
| (PID) Process: | (2428) Install SportZone.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Install SportZone_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (2428) Install SportZone.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Install SportZone_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
| (PID) Process: | (2428) Install SportZone.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Install SportZone_RASMANCS |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (2428) Install SportZone.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Install SportZone_RASMANCS |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2940 | SportZone_1.5.1.exe | C:\Users\admin\AppData\Local\Temp\AIR4C77.tmp\.launch | text | |
MD5:410AA7C4ADE1DAB2E8D3E6E0D9BFBE7F | SHA256:5BF92A7A179DDC88C834781CC3B4767423B2FA5409D76D268301E60835E602EE | |||
| 2428 | Install SportZone.exe | C:\Users\admin\AppData\Local\Adobe\AIR\logs\Install.log | text | |
MD5:— | SHA256:— | |||
| 2428 | Install SportZone.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\EF87FE2FBAF08DA89A8C148EF56C40E0 | binary | |
MD5:— | SHA256:— | |||
| 2940 | SportZone_1.5.1.exe | C:\Users\admin\AppData\Local\Temp\AIR4C77.tmp\SportZone\icons\icon_16.png | image | |
MD5:8111AE0F83EA20460109DC59739E2AC2 | SHA256:CED8CFC8344BB52F76F4FE5B08D0E2569F2CE9591E6756A9E05FC56302173216 | |||
| 2940 | SportZone_1.5.1.exe | C:\Users\admin\AppData\Local\Temp\AIR4C77.tmp\SportZone\icons\icon_128.png | image | |
MD5:942E611B22AA0290663DB9AA065C26A5 | SHA256:2135FF309A45ECE5848E8327289A602A8A76DC93D4FAFF1C3A62556D010949E9 | |||
| 2940 | SportZone_1.5.1.exe | C:\Users\admin\AppData\Local\Temp\AIR4C77.tmp\SportZone\META-INF\signatures.xml | text | |
MD5:EB0132020272BE7F688740ADCCCC753B | SHA256:410A482CA0C284E800CDE5D694E52362747DD1E807CA52959E62918EBBCF7FFC | |||
| 2940 | SportZone_1.5.1.exe | C:\Users\admin\AppData\Local\Temp\AIR4C77.tmp\SportZone\META-INF\AIR\hash | binary | |
MD5:49D7A9D707F89D3B118E89CFE4DC9AC7 | SHA256:E1C83BC40F8DA70DADE73C4725ED0C7C37B2ACE406B96E97255E31987787D411 | |||
| 2940 | SportZone_1.5.1.exe | C:\Users\admin\AppData\Local\Temp\AIR4C77.tmp\SportZone\icons\icon_32.png | image | |
MD5:4DD258D2B4ECB7CE46BBD1309A6B8558 | SHA256:8B9D7C41FB0B148C5CFC50124A70E52701F3A30B60B05C893A039A3D51F1CAC9 | |||
| 2428 | Install SportZone.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\9C07FA4C8533A07B5EDE782A6F5AFA6A | binary | |
MD5:— | SHA256:— | |||
| 2940 | SportZone_1.5.1.exe | C:\Users\admin\AppData\Local\Temp\AIR4C77.tmp\SportZone\XSportZonePlayer.swf | binary | |
MD5:38F02438BF907AEE1A69F9C83994F365 | SHA256:A4508AB27D4635FA0BE8AD28FD653E99651834BABEA65593144007416EAA2EEE | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2428 | Install SportZone.exe | GET | 301 | 92.122.255.51:80 | http://airdownload.adobe.com/air/3/nai/windows6.1/x86/installer | unknown | — | — | whitelisted |
2428 | Install SportZone.exe | GET | 301 | 92.122.255.51:80 | http://airdownload.adobe.com/air/3/nai/windows6.1/x86/installer.p7 | unknown | — | — | whitelisted |
2404 | Adobe AIR Application Installer.exe | GET | 200 | 93.184.220.29:80 | http://ts-crl.ws.symantec.com/tss-ca-g2.crl | US | der | 477 b | whitelisted |
2428 | Install SportZone.exe | GET | 200 | 23.45.74.146:80 | http://crl.adobe.com/cds.crl | NL | der | 637 b | whitelisted |
2428 | Install SportZone.exe | GET | 200 | 23.45.74.146:80 | http://crl.adobe.com/prodSvce.crl | NL | der | 425 b | whitelisted |
2404 | Adobe AIR Application Installer.exe | GET | 200 | 93.184.220.29:80 | http://crl.thawte.com/ThawteTimestampingCA.crl | US | der | 341 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2624 | SportZone.exe | 95.211.209.47:1935 | — | LeaseWeb Netherlands B.V. | NL | unknown |
2428 | Install SportZone.exe | 92.122.255.51:80 | airdownload.adobe.com | GTT Communications Inc. | — | suspicious |
2624 | SportZone.exe | 185.49.69.55:1935 | — | Leaseweb Deutschland GmbH | DE | unknown |
3164 | Adobe AIR Updater.exe | 92.122.255.51:443 | airdownload.adobe.com | GTT Communications Inc. | — | suspicious |
1360 | SportZone.exe | 93.189.62.10:1935 | — | Melbikomas UAB | DE | unknown |
1360 | SportZone.exe | 91.192.80.210:1935 | — | Melbikomas UAB | RU | unknown |
2624 | SportZone.exe | 93.189.57.254:1935 | — | Melbikomas UAB | NL | unknown |
2404 | Adobe AIR Application Installer.exe | 93.184.220.29:80 | crl.thawte.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2428 | Install SportZone.exe | 92.122.255.51:443 | airdownload.adobe.com | GTT Communications Inc. | — | suspicious |
2428 | Install SportZone.exe | 23.45.74.146:80 | crl.adobe.com | Akamai Technologies, Inc. | NL | unknown |
Domain | IP | Reputation |
|---|---|---|
airdownload.adobe.com |
| whitelisted |
crl.adobe.com |
| whitelisted |
crl.thawte.com |
| whitelisted |
ts-crl.ws.symantec.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2404 | Adobe AIR Application Installer.exe | Potential Corporate Privacy Violation | ET POLICY Outdated Flash Version M1 |