File name: | Plants vs Zombies main.pak Patcherer.exe |
Full analysis: | https://app.any.run/tasks/81af8a3c-e495-43ff-8b5b-e922037e1ffd |
Verdict: | Malicious activity |
Analysis date: | November 23, 2023, 01:18:19 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, RAR self-extracting archive |
MD5: | 657DC36A147ED82180F35BCDBA675643 |
SHA1: | 749B0A637DC66E2A0E70E211EE43C16055F4063D |
SHA256: | 4A65B0E6984EEB5028002F744785DDC64F55FE98A9CA5E5DD32CC544BF1A1574 |
SSDEEP: | 49152:ppmPNrHbLXKBijhg+dHTjlPElvD6P+1mozKMZ8pxFlyB6k1pQbgBJ9oh+aIJncXZ:pY9KstgiT58D6mIouMKpblyB62yMJGhb |
.exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
---|---|---|
.exe | | | Win64 Executable (generic) (37.3) |
.dll | | | Win32 Dynamic Link Library (generic) (8.8) |
.exe | | | Win32 Executable (generic) (6) |
.exe | | | Generic Win/DOS Executable (2.7) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2009:12:12 11:11:36+01:00 |
ImageFileCharacteristics: | No relocs, Executable, 32-bit |
PEType: | PE32 |
LinkerVersion: | 9 |
CodeSize: | 67584 |
InitializedDataSize: | 37376 |
UninitializedDataSize: | - |
EntryPoint: | 0xa7cb |
OSVersion: | 5 |
ImageVersion: | - |
SubsystemVersion: | 4 |
Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
3020 | "C:\Windows\System32\NOTEPAD.EXE" C:\Users\admin\Desktop\PVZ\Patcher.bat | C:\Windows\System32\notepad.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3404 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\Desktop\PVZ\Patcher.bat" " | C:\Windows\System32\cmd.exe | — | Plants vs Zombies main.pak Patcherer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
3444 | quickbms patchmain.exe main.pak . | C:\Users\admin\Desktop\PVZ\quickbms.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 4294967295 Modules
| |||||||||||||||
3460 | "C:\Users\admin\Desktop\Plants vs Zombies main.pak Patcherer.exe" | C:\Users\admin\Desktop\Plants vs Zombies main.pak Patcherer.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
3488 | PATCH.exe | C:\Users\admin\Desktop\PVZ\PATCH.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
|
(PID) Process: | (3460) Plants vs Zombies main.pak Patcherer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
(PID) Process: | (3460) Plants vs Zombies main.pak Patcherer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
Operation: | write | Name: | SavedLegacySettings |
Value: 4600000059010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (3460) Plants vs Zombies main.pak Patcherer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (3460) Plants vs Zombies main.pak Patcherer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (3460) Plants vs Zombies main.pak Patcherer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (3460) Plants vs Zombies main.pak Patcherer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (3460) Plants vs Zombies main.pak Patcherer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
(PID) Process: | (3460) Plants vs Zombies main.pak Patcherer.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
Operation: | write | Name: | CachePrefix |
Value: Visited: |
PID | Process | Filename | Type | |
---|---|---|---|---|
3460 | Plants vs Zombies main.pak Patcherer.exe | C:\Users\admin\Desktop\PVZ\quickbms.exe | executable | |
MD5:B6F8E7509107F5E4D4AB37A33C861F67 | SHA256:F54B1ABE028E339766B50DBC7E8990C3DAFE83E2DF7F4D25303D43B8F942B328 | |||
3460 | Plants vs Zombies main.pak Patcherer.exe | C:\Users\admin\Desktop\PVZ\Patcher.bat | text | |
MD5:D46B9AAA1F980A0FD00A218EA901A242 | SHA256:7600974A335E7B6AF9100B7CD229754BFCEC9C3F19F959559E31F633E63081FF | |||
3460 | Plants vs Zombies main.pak Patcherer.exe | C:\Users\admin\Desktop\PVZ\PATCH.exe | executable | |
MD5:694770374EF672C697E23DA747F5A925 | SHA256:A1E8679C9D01443E85AD95AB1578619D9624A4AC2FE7981FC705E9249AB8EE15 | |||
3460 | Plants vs Zombies main.pak Patcherer.exe | C:\Users\admin\Desktop\PVZ\src\bcl\bcltest.c | text | |
MD5:0A3C6D6EC0BEDEE4A502351D116FD4B6 | SHA256:180139D828E2C08CB5C07753B57A1B9F26C4ED195FB2906F7C91B4B2E6656AE1 | |||
3460 | Plants vs Zombies main.pak Patcherer.exe | C:\Users\admin\Desktop\PVZ\patchmain.exe | text | |
MD5:E0F55B71E82C97F2634B00A4C7A117C8 | SHA256:1545885C31E354359375608B30FC35AB94A86EC138FE974422DCC3A7961618BA | |||
3460 | Plants vs Zombies main.pak Patcherer.exe | C:\Users\admin\Desktop\PVZ\src\bcl\huffman.h | text | |
MD5:9B810309D5A549F0678AC57C648D561D | SHA256:48F32686F177C1AA0D12AAEDE5762A8680B59F2F38C4588AFA5317387131E881 | |||
3460 | Plants vs Zombies main.pak Patcherer.exe | C:\Users\admin\Desktop\PVZ\PopCap_Logo.jpg | image | |
MD5:153E5E26CE390F1C67F295D41588BDF7 | SHA256:2F8A5F2CD13AB79280B7335001642547F5DCA39FCFBB90E2EFCBF1ABF2394ACF | |||
3460 | Plants vs Zombies main.pak Patcherer.exe | C:\Users\admin\Desktop\PVZ\src\bcl\huffman.c | text | |
MD5:D056F0A3D00F635134817B9610F1259A | SHA256:CEE0511995A3221244CF1FA1ED200B98C0D6E7A9BB0B5E6A9009175CE0FF5592 | |||
3460 | Plants vs Zombies main.pak Patcherer.exe | C:\Users\admin\Desktop\PVZ\src\bcl\Makefile | text | |
MD5:49C1943DB59DEB19EB8F06B1C8A9C9ED | SHA256:DD5C7DC1AA68901C41A0591848EBCE06B99EFBB84207B0E245A17096D0D70E8E | |||
3460 | Plants vs Zombies main.pak Patcherer.exe | C:\Users\admin\Desktop\PVZ\src\bcl\rice.h | text | |
MD5:561E7C4236DE5A3AAB36108A051F9EBF | SHA256:6142094A182EB3F1446CF467E89E34B63372578C0147DE9CFB680E90C7215156 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |