| File name: | GPU-Z.2.50.0.exe |
| Full analysis: | https://app.any.run/tasks/3d79d1c2-d528-42f6-ae60-714942518821 |
| Verdict: | Malicious activity |
| Analysis date: | October 05, 2022, 01:53:40 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
| MD5: | AAABF7F2971517A1C9E33927750BC961 |
| SHA1: | 956BB62CC78790A278EF66F3A209F9B18DAA9A19 |
| SHA256: | 49F87AE37C935C36535FB33C7920CF3536E63F9040F83C0E1FFC7DE3174B3636 |
| SSDEEP: | 196608:pj+INk9rAkfBJCkJtWe954UeptOBr03KUpbL:pj+r9rA8fSS5fEAcn5L |
| .exe | | | UPX compressed Win32 Executable (43.5) |
|---|---|---|
| .exe | | | Win32 EXE Yoda's Crypter (42.7) |
| .exe | | | Win32 Executable (generic) (7.2) |
| .exe | | | Generic Win/DOS Executable (3.2) |
| .exe | | | DOS Executable Generic (3.2) |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 2022-Oct-01 08:58:02 |
| Detected languages: |
|
| CompanyName: | TechPowerUp (www.techpowerup.com) |
| FileDescription: | GPU-Z - Video card Information Utility |
| FileVersion: | 2.50.0.0 |
| InternalName: | GPU-Z.exe |
| LegalCopyright: | (c) 2007-2022 TechPowerUp (www.techpowerup.com) |
| OriginalFilename: | GPU-Z.exe |
| ProductName: | GPU-Z - Video card Information Utility |
| ProductVersion: | 2.50.0.0 |
| e_magic: | MZ |
|---|---|
| e_cblp: | 144 |
| e_cp: | 3 |
| e_crlc: | - |
| e_cparhdr: | 4 |
| e_minalloc: | - |
| e_maxalloc: | 65535 |
| e_ss: | - |
| e_sp: | 184 |
| e_csum: | - |
| e_ip: | - |
| e_cs: | - |
| e_ovno: | - |
| e_oemid: | - |
| e_oeminfo: | - |
| e_lfanew: | 304 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| NumberofSections: | 3 |
| TimeDateStamp: | 2022-Oct-01 08:58:02 |
| PointerToSymbolTable: | - |
| NumberOfSymbols: | - |
| SizeOfOptionalHeader: | 224 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
UPX0 | 4096 | 21880832 | 0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | |
UPX1 | 21884928 | 7413760 | 7412736 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.99998 |
.rsrc | 29298688 | 86016 | 82432 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.14436 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 3.87773 | 1384 | UNKNOWN | UNKNOWN | RT_ICON |
2 | 5.02163 | 1128 | UNKNOWN | UNKNOWN | RT_ICON |
3 | 5.72775 | 2216 | UNKNOWN | UNKNOWN | RT_ICON |
4 | 4.8351 | 4264 | UNKNOWN | UNKNOWN | RT_ICON |
5 | 5.15311 | 3752 | UNKNOWN | UNKNOWN | RT_ICON |
6 | 4.83126 | 9640 | UNKNOWN | UNKNOWN | RT_ICON |
7 | 7.9552 | 21146 | UNKNOWN | UNKNOWN | RT_ICON |
8 | 2.10907 | 1696 | UNKNOWN | UNKNOWN | RT_ICON |
9 | 2.05908 | 1264 | UNKNOWN | UNKNOWN | RT_ICON |
10 | 1.56096 | 9640 | UNKNOWN | UNKNOWN | RT_ICON |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
IMM32.dll |
KERNEL32.DLL |
MSIMG32.dll |
NETAPI32.dll |
OLEACC.dll |
OLEAUT32.dll |
PSAPI.DLL |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1116 | "C:\Users\admin\AppData\Local\Temp\GPU-Z.2.50.0.exe" | C:\Users\admin\AppData\Local\Temp\GPU-Z.2.50.0.exe | — | Explorer.EXE | |||||||||||
User: admin Company: TechPowerUp (www.techpowerup.com) Integrity Level: MEDIUM Description: GPU-Z - Video card Information Utility Exit code: 3221226540 Version: 2.50.0.0 Modules
| |||||||||||||||
| 1700 | "C:\Users\admin\AppData\Local\Temp\\gpuz_installer.exe" | C:\Users\admin\AppData\Local\Temp\gpuz_installer.exe | GPU-Z.2.50.0.exe | ||||||||||||
User: admin Company: TechPowerUp Integrity Level: HIGH Description: TechPowerUp GPU-Z Setup Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2256 | "C:\Program Files\GPU-Z\GPU-Z.exe" | C:\Program Files\GPU-Z\GPU-Z.exe | gpuz_installer.tmp | ||||||||||||
User: admin Company: TechPowerUp (www.techpowerup.com) Integrity Level: HIGH Description: GPU-Z - Video card Information Utility Exit code: 0 Version: 2.50.0.0 Modules
| |||||||||||||||
| 2344 | "C:\Users\admin\AppData\Local\Temp\GPU-Z.2.50.0.exe" | C:\Users\admin\AppData\Local\Temp\GPU-Z.2.50.0.exe | Explorer.EXE | ||||||||||||
User: admin Company: TechPowerUp (www.techpowerup.com) Integrity Level: HIGH Description: GPU-Z - Video card Information Utility Exit code: 0 Version: 2.50.0.0 Modules
| |||||||||||||||
| 3068 | "C:\Users\admin\AppData\Local\Temp\is-LUJ2D.tmp\gpuz_installer.tmp" /SL5="$3012E,721408,721408,C:\Users\admin\AppData\Local\Temp\gpuz_installer.exe" | C:\Users\admin\AppData\Local\Temp\is-LUJ2D.tmp\gpuz_installer.tmp | gpuz_installer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| (PID) Process: | (3068) gpuz_installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: FC0B000052AF2C585DD8D801 | |||
| (PID) Process: | (3068) gpuz_installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: 496D1DCBF2E48EE430A0E1445A95B068BBD2CC55C119670116970E808685ABC1 | |||
| (PID) Process: | (3068) gpuz_installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (3068) gpuz_installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Program Files\GPU-Z\GPU-Z.exe | |||
| (PID) Process: | (3068) gpuz_installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFilesHash |
Value: 3963519C81EC6DFE30DE9CABD1324A12DFD679DB667AB7D91599561989519459 | |||
| (PID) Process: | (3068) gpuz_installer.tmp | Key: | HKEY_CURRENT_USER\Software\techPowerUp\GPU-Z |
| Operation: | write | Name: | Install_Dir |
Value: C:\Program Files\GPU-Z | |||
| (PID) Process: | (3068) gpuz_installer.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B0F211E-5846-4FB2-B0B9-4EB31546FDF9}}_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 6.0.2 (u) | |||
| (PID) Process: | (3068) gpuz_installer.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B0F211E-5846-4FB2-B0B9-4EB31546FDF9}}_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files\GPU-Z | |||
| (PID) Process: | (3068) gpuz_installer.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B0F211E-5846-4FB2-B0B9-4EB31546FDF9}}_is1 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\GPU-Z\ | |||
| (PID) Process: | (3068) gpuz_installer.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B0F211E-5846-4FB2-B0B9-4EB31546FDF9}}_is1 |
| Operation: | write | Name: | Inno Setup: Icon Group |
Value: (Default) | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2256 | GPU-Z.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\03005CB84A266CEC058C632BB7746F6A | binary | |
MD5:— | SHA256:— | |||
| 2344 | GPU-Z.2.50.0.exe | C:\Users\admin\AppData\Local\Temp\GPU-Z.exe | executable | |
MD5:— | SHA256:— | |||
| 3068 | gpuz_installer.tmp | C:\Users\Public\Desktop\TechPowerUp GPU-Z.lnk | lnk | |
MD5:— | SHA256:— | |||
| 3068 | gpuz_installer.tmp | C:\Program Files\GPU-Z\GPU-Z.exe | executable | |
MD5:— | SHA256:— | |||
| 3068 | gpuz_installer.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechPowerUp GPU-Z.lnk | lnk | |
MD5:— | SHA256:— | |||
| 3068 | gpuz_installer.tmp | C:\Program Files\GPU-Z\unins000.dat | dat | |
MD5:— | SHA256:— | |||
| 3068 | gpuz_installer.tmp | C:\Program Files\GPU-Z\is-C63R4.tmp | executable | |
MD5:— | SHA256:— | |||
| 2256 | GPU-Z.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\78RFYB7Z\version_v2[1].json | binary | |
MD5:— | SHA256:— | |||
| 2256 | GPU-Z.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\03005CB84A266CEC058C632BB7746F6A | der | |
MD5:— | SHA256:— | |||
| 2344 | GPU-Z.2.50.0.exe | C:\Users\admin\AppData\Local\Temp\gpuz_installer.exe | executable | |
MD5:DB0FE2FC8B640F81BE6103EFABB69FC1 | SHA256:6CDFAC9A6FD83D7A0B652BD8D5A971A753704302E697C3129DCAA5F2DE465A44 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2256 | GPU-Z.exe | GET | 200 | 172.64.155.188:80 | http://crl.comodoca.com/AAACertificateServices.crl | US | der | 506 b | whitelisted |
2256 | GPU-Z.exe | GET | 200 | 104.18.32.68:80 | http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEEe6PinQT32mTH9oWfJSNJ0%3D | US | der | 471 b | whitelisted |
2256 | GPU-Z.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?de3682e9c46324b8 | US | compressed | 4.70 Kb | whitelisted |
2256 | GPU-Z.exe | GET | 200 | 104.18.32.68:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D | US | der | 1.42 Kb | whitelisted |
2256 | GPU-Z.exe | GET | 200 | 172.64.155.188:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D | US | der | 2.18 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 192.168.100.2:53 | — | — | — | whitelisted |
2256 | GPU-Z.exe | 138.199.40.8:443 | www.gpu-z.com | Datacamp Limited | US | unknown |
2256 | GPU-Z.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
2256 | GPU-Z.exe | 172.64.155.188:80 | ocsp.comodoca.com | CLOUDFLARENET | US | suspicious |
— | — | 104.18.32.68:80 | ocsp.comodoca.com | CLOUDFLARENET | — | suspicious |
2256 | GPU-Z.exe | 104.18.32.68:80 | ocsp.comodoca.com | CLOUDFLARENET | — | suspicious |
Domain | IP | Reputation |
|---|---|---|
www.microsoft.com |
| whitelisted |
www.gpu-z.com |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.comodoca.com |
| whitelisted |
crl.comodoca.com |
| whitelisted |
ocsp.usertrust.com |
| whitelisted |
ocsp.sectigo.com |
| whitelisted |
Process | Message |
|---|---|
GPU-Z.2.50.0.exe | in CXCrashHandler
|
GPU-Z.exe | in CXCrashHandler
|
GPU-Z.2.50.0.exe | in ~CXCrashHandler
|