File name: | GPU-Z.2.50.0.exe |
Full analysis: | https://app.any.run/tasks/3d79d1c2-d528-42f6-ae60-714942518821 |
Verdict: | Malicious activity |
Analysis date: | October 05, 2022, 01:53:40 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed |
MD5: | AAABF7F2971517A1C9E33927750BC961 |
SHA1: | 956BB62CC78790A278EF66F3A209F9B18DAA9A19 |
SHA256: | 49F87AE37C935C36535FB33C7920CF3536E63F9040F83C0E1FFC7DE3174B3636 |
SSDEEP: | 196608:pj+INk9rAkfBJCkJtWe954UeptOBr03KUpbL:pj+r9rA8fSS5fEAcn5L |
.exe | | | UPX compressed Win32 Executable (43.5) |
---|---|---|
.exe | | | Win32 EXE Yoda's Crypter (42.7) |
.exe | | | Win32 Executable (generic) (7.2) |
.exe | | | Generic Win/DOS Executable (3.2) |
.exe | | | DOS Executable Generic (3.2) |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 2022-Oct-01 08:58:02 |
Detected languages: |
|
CompanyName: | TechPowerUp (www.techpowerup.com) |
FileDescription: | GPU-Z - Video card Information Utility |
FileVersion: | 2.50.0.0 |
InternalName: | GPU-Z.exe |
LegalCopyright: | (c) 2007-2022 TechPowerUp (www.techpowerup.com) |
OriginalFilename: | GPU-Z.exe |
ProductName: | GPU-Z - Video card Information Utility |
ProductVersion: | 2.50.0.0 |
e_magic: | MZ |
---|---|
e_cblp: | 144 |
e_cp: | 3 |
e_crlc: | - |
e_cparhdr: | 4 |
e_minalloc: | - |
e_maxalloc: | 65535 |
e_ss: | - |
e_sp: | 184 |
e_csum: | - |
e_ip: | - |
e_cs: | - |
e_ovno: | - |
e_oemid: | - |
e_oeminfo: | - |
e_lfanew: | 304 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
NumberofSections: | 3 |
TimeDateStamp: | 2022-Oct-01 08:58:02 |
PointerToSymbolTable: | - |
NumberOfSymbols: | - |
SizeOfOptionalHeader: | 224 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
UPX0 | 4096 | 21880832 | 0 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | |
UPX1 | 21884928 | 7413760 | 7412736 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 7.99998 |
.rsrc | 29298688 | 86016 | 82432 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.14436 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 3.87773 | 1384 | UNKNOWN | UNKNOWN | RT_ICON |
2 | 5.02163 | 1128 | UNKNOWN | UNKNOWN | RT_ICON |
3 | 5.72775 | 2216 | UNKNOWN | UNKNOWN | RT_ICON |
4 | 4.8351 | 4264 | UNKNOWN | UNKNOWN | RT_ICON |
5 | 5.15311 | 3752 | UNKNOWN | UNKNOWN | RT_ICON |
6 | 4.83126 | 9640 | UNKNOWN | UNKNOWN | RT_ICON |
7 | 7.9552 | 21146 | UNKNOWN | UNKNOWN | RT_ICON |
8 | 2.10907 | 1696 | UNKNOWN | UNKNOWN | RT_ICON |
9 | 2.05908 | 1264 | UNKNOWN | UNKNOWN | RT_ICON |
10 | 1.56096 | 9640 | UNKNOWN | UNKNOWN | RT_ICON |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
IMM32.dll |
KERNEL32.DLL |
MSIMG32.dll |
NETAPI32.dll |
OLEACC.dll |
OLEAUT32.dll |
PSAPI.DLL |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1116 | "C:\Users\admin\AppData\Local\Temp\GPU-Z.2.50.0.exe" | C:\Users\admin\AppData\Local\Temp\GPU-Z.2.50.0.exe | — | Explorer.EXE | |||||||||||
User: admin Company: TechPowerUp (www.techpowerup.com) Integrity Level: MEDIUM Description: GPU-Z - Video card Information Utility Exit code: 3221226540 Version: 2.50.0.0 Modules
| |||||||||||||||
2344 | "C:\Users\admin\AppData\Local\Temp\GPU-Z.2.50.0.exe" | C:\Users\admin\AppData\Local\Temp\GPU-Z.2.50.0.exe | Explorer.EXE | ||||||||||||
User: admin Company: TechPowerUp (www.techpowerup.com) Integrity Level: HIGH Description: GPU-Z - Video card Information Utility Exit code: 0 Version: 2.50.0.0 Modules
| |||||||||||||||
1700 | "C:\Users\admin\AppData\Local\Temp\\gpuz_installer.exe" | C:\Users\admin\AppData\Local\Temp\gpuz_installer.exe | GPU-Z.2.50.0.exe | ||||||||||||
User: admin Company: TechPowerUp Integrity Level: HIGH Description: TechPowerUp GPU-Z Setup Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
3068 | "C:\Users\admin\AppData\Local\Temp\is-LUJ2D.tmp\gpuz_installer.tmp" /SL5="$3012E,721408,721408,C:\Users\admin\AppData\Local\Temp\gpuz_installer.exe" | C:\Users\admin\AppData\Local\Temp\is-LUJ2D.tmp\gpuz_installer.tmp | gpuz_installer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
2256 | "C:\Program Files\GPU-Z\GPU-Z.exe" | C:\Program Files\GPU-Z\GPU-Z.exe | gpuz_installer.tmp | ||||||||||||
User: admin Company: TechPowerUp (www.techpowerup.com) Integrity Level: HIGH Description: GPU-Z - Video card Information Utility Version: 2.50.0.0 Modules
|
(PID) Process: | (3068) gpuz_installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | Owner |
Value: FC0B000052AF2C585DD8D801 | |||
(PID) Process: | (3068) gpuz_installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | SessionHash |
Value: 496D1DCBF2E48EE430A0E1445A95B068BBD2CC55C119670116970E808685ABC1 | |||
(PID) Process: | (3068) gpuz_installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | Sequence |
Value: 1 | |||
(PID) Process: | (3068) gpuz_installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | RegFiles0000 |
Value: C:\Program Files\GPU-Z\GPU-Z.exe | |||
(PID) Process: | (3068) gpuz_installer.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | RegFilesHash |
Value: 3963519C81EC6DFE30DE9CABD1324A12DFD679DB667AB7D91599561989519459 | |||
(PID) Process: | (3068) gpuz_installer.tmp | Key: | HKEY_CURRENT_USER\Software\techPowerUp\GPU-Z |
Operation: | write | Name: | Install_Dir |
Value: C:\Program Files\GPU-Z | |||
(PID) Process: | (3068) gpuz_installer.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B0F211E-5846-4FB2-B0B9-4EB31546FDF9}}_is1 |
Operation: | write | Name: | Inno Setup: Setup Version |
Value: 6.0.2 (u) | |||
(PID) Process: | (3068) gpuz_installer.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B0F211E-5846-4FB2-B0B9-4EB31546FDF9}}_is1 |
Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files\GPU-Z | |||
(PID) Process: | (3068) gpuz_installer.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B0F211E-5846-4FB2-B0B9-4EB31546FDF9}}_is1 |
Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\GPU-Z\ | |||
(PID) Process: | (3068) gpuz_installer.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{8B0F211E-5846-4FB2-B0B9-4EB31546FDF9}}_is1 |
Operation: | write | Name: | Inno Setup: Icon Group |
Value: (Default) |
PID | Process | Filename | Type | |
---|---|---|---|---|
3068 | gpuz_installer.tmp | C:\Users\Public\Desktop\TechPowerUp GPU-Z.lnk | lnk | |
MD5:BABB256B8B5B7D8A3F26F841ED520BE6 | SHA256:DE4197A6602D44E6730A0BF05FBCFD58BBB7B67ECDCDC342B96F87A63A3E1793 | |||
3068 | gpuz_installer.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\TechPowerUp GPU-Z.lnk | lnk | |
MD5:A621700174FA4C970A062B79F3135670 | SHA256:6CF4F372D3FDB3D5938BCAB4FE00892550C0ECE47D60535F902A363927F11577 | |||
3068 | gpuz_installer.tmp | C:\Program Files\GPU-Z\unins000.dat | dat | |
MD5:71BC811E1F88533E3D9268E40052BD52 | SHA256:C3643B05EA64B5B1475E13371293242C739752D5EA9A1255252DAAABD5C506CC | |||
2256 | GPU-Z.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\07CEF2F654E3ED6050FFC9B6EB844250_3431D4C539FB2CFCB781821E9902850D | binary | |
MD5:ED2C459864E2AEDEE4ABA48F7563B7A3 | SHA256:94C0346CBB04FAAABB55D0B09493C4EAA1AE149D809FF86AC04D15BCB3E6D341 | |||
2256 | GPU-Z.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\572BF21E454637C9F000BE1AF9B1E1A9 | binary | |
MD5:C1D6B26863C2F74BA997C6025692A2BF | SHA256:CB281E7E582FA0C4B56AD5254AC8A13C9E3E71F153A583C23176431802673DC4 | |||
2344 | GPU-Z.2.50.0.exe | C:\Users\admin\AppData\Local\Temp\GPU-Z.exe | executable | |
MD5:AAABF7F2971517A1C9E33927750BC961 | SHA256:49F87AE37C935C36535FB33C7920CF3536E63F9040F83C0E1FFC7DE3174B3636 | |||
3068 | gpuz_installer.tmp | C:\Program Files\GPU-Z\is-C63R4.tmp | executable | |
MD5:AAABF7F2971517A1C9E33927750BC961 | SHA256:49F87AE37C935C36535FB33C7920CF3536E63F9040F83C0E1FFC7DE3174B3636 | |||
2256 | GPU-Z.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\03005CB84A266CEC058C632BB7746F6A | binary | |
MD5:33C6B2326344C0976E744F149E608D70 | SHA256:D8DCC0B8F3CDE109B375A6AB2CCC4132F351E4BDCA3F9217FCE26368AF7A854C | |||
3068 | gpuz_installer.tmp | C:\Program Files\GPU-Z\GPU-Z.exe | executable | |
MD5:AAABF7F2971517A1C9E33927750BC961 | SHA256:49F87AE37C935C36535FB33C7920CF3536E63F9040F83C0E1FFC7DE3174B3636 | |||
2256 | GPU-Z.exe | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\57C8EDB95DF3F0AD4EE2DC2B8CFD4157 | binary | |
MD5:4F4A702BA1AC27144112E531F251498B | SHA256:7DC8C8CC351985CBED60FEB0BCCD46FE80EC06227A6FF82CF7FE84EC6D423EC3 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2256 | GPU-Z.exe | GET | 200 | 172.64.155.188:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D | US | der | 2.18 Kb | whitelisted |
2256 | GPU-Z.exe | GET | 200 | 172.64.155.188:80 | http://crl.comodoca.com/AAACertificateServices.crl | US | der | 506 b | whitelisted |
2256 | GPU-Z.exe | GET | 200 | 104.18.32.68:80 | http://ocsp.sectigo.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRDC9IOTxN6GmyRjyTl2n4yTUczyAQUjYxexFStiuF36Zv5mwXhuAGNYeECEEe6PinQT32mTH9oWfJSNJ0%3D | US | der | 471 b | whitelisted |
2256 | GPU-Z.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?de3682e9c46324b8 | US | compressed | 4.70 Kb | whitelisted |
2256 | GPU-Z.exe | GET | 200 | 104.18.32.68:80 | http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D | US | der | 1.42 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2256 | GPU-Z.exe | 172.64.155.188:80 | ocsp.comodoca.com | CLOUDFLARENET | US | suspicious |
2256 | GPU-Z.exe | 104.18.32.68:80 | ocsp.comodoca.com | CLOUDFLARENET | — | suspicious |
2256 | GPU-Z.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
2256 | GPU-Z.exe | 138.199.40.8:443 | www.gpu-z.com | Datacamp Limited | US | unknown |
— | — | 192.168.100.2:53 | — | — | — | whitelisted |
— | — | 104.18.32.68:80 | ocsp.comodoca.com | CLOUDFLARENET | — | suspicious |
Domain | IP | Reputation |
---|---|---|
www.microsoft.com |
| whitelisted |
www.gpu-z.com |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.comodoca.com |
| whitelisted |
crl.comodoca.com |
| whitelisted |
ocsp.usertrust.com |
| whitelisted |
ocsp.sectigo.com |
| whitelisted |
Process | Message |
---|---|
GPU-Z.2.50.0.exe | in CXCrashHandler
|
GPU-Z.exe | in CXCrashHandler
|
GPU-Z.2.50.0.exe | in ~CXCrashHandler
|