File name: | Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe |
Full analysis: | https://app.any.run/tasks/4e6bc272-19f4-4774-b8b6-0dfa442f8d7a |
Verdict: | Malicious activity |
Analysis date: | February 16, 2024, 01:01:52 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, Nullsoft Installer self-extracting archive |
MD5: | D0DEB74BF4056BB7315BD06E7EAB8BC0 |
SHA1: | 21C377E05A37C4A4DF47B7E76178AE0918889104 |
SHA256: | 4ABAF0C84D387E8C185591203A58B12E4221E2FC2ED1B452DD87A89EBDE363F7 |
SSDEEP: | 24576:KgJATTgdXjeMCqMn9cGuQIOR8SdiZbhcovBkp7SAfHc3ik3zKuL2V8QhJk2B8VXE:KgJoTEXjeMCqMn9cGuQIOR8SdiZbhco6 |
.exe | | | UPX compressed Win32 Executable (39.3) |
---|---|---|
.exe | | | Win32 EXE Yoda's Crypter (38.6) |
.dll | | | Win32 Dynamic Link Library (generic) (9.5) |
.exe | | | Win32 Executable (generic) (6.5) |
.exe | | | Generic Win/DOS Executable (2.9) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2015:08:05 00:46:27+00:00 |
ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
PEType: | PE32 |
LinkerVersion: | 6 |
CodeSize: | 20480 |
InitializedDataSize: | 12288 |
UninitializedDataSize: | 225280 |
EntryPoint: | 0x3c560 |
OSVersion: | 4 |
ImageVersion: | 6 |
SubsystemVersion: | 4 |
Subsystem: | Windows GUI |
FileVersionNumber: | 1.0.0.0 |
ProductVersionNumber: | 1.0.0.0 |
FileFlagsMask: | 0x0000 |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | English (U.S.) |
CharacterSet: | Windows, Latin1 |
Comments: | Distribuido pela Tribo Gamer Brasil® |
CompanyName: | Tribo Gamer Brasil® |
CompanyWebsite: | http://www.tribogamer.com/ |
FileDescription: | Bioshock 2 Remastered Tradução BR 1.00 |
FileVersion: | 1 |
LegalCopyright: | 2017 - Tribo Gamer Brasil® - Direitos Reservados |
LegalTrademarks: | Bioshock 2 Remastered é uma marca da 2K Games. Nós apenas traduzimos o jogo. |
ProductName: | Tradução do jogo: Bioshock 2 Remastered |
ProductVersion: | 1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2036 | "C:\Users\admin\AppData\Local\Temp\Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe" | C:\Users\admin\AppData\Local\Temp\Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | explorer.exe | ||||||||||||
User: admin Company: Tribo Gamer Brasil® Integrity Level: HIGH Description: Bioshock 2 Remastered Tradução BR 1.00 Exit code: 1 Version: 1.00 Modules
| |||||||||||||||
3864 | "C:\Users\admin\AppData\Local\Temp\Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe" | C:\Users\admin\AppData\Local\Temp\Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | — | explorer.exe | |||||||||||
User: admin Company: Tribo Gamer Brasil® Integrity Level: MEDIUM Description: Bioshock 2 Remastered Tradução BR 1.00 Exit code: 3221226540 Version: 1.00 Modules
|
(PID) Process: | (2036) Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (2036) Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (2036) Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (2036) Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (2036) Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
Operation: | write | Name: | CachePrefix |
Value: | |||
(PID) Process: | (2036) Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
(PID) Process: | (2036) Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
(PID) Process: | (2036) Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry |
Operation: | delete value | Name: | AddToFavoritesInitialSelection |
Value: | |||
(PID) Process: | (2036) Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry |
Operation: | delete value | Name: | AddToFeedsInitialSelection |
Value: | |||
(PID) Process: | (2036) Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager |
Operation: | write | Name: | PendingFileRenameOperations |
Value: \??\C:\Users\admin\AppData\Local\Temp\nsjF06D.tmp\tr_data\ |
PID | Process | Filename | Type | |
---|---|---|---|---|
2036 | Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | C:\Users\admin\AppData\Local\Temp\nsjF06D.tmp\tr_files\scroll.dflt.js | text | |
MD5:46903025390C7274E546DDCF50526CFA | SHA256:FB295CF92B819F9E7D95B62495AEB15E12CD3291ADD18093C946184127411984 | |||
2036 | Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | C:\Users\admin\AppData\Local\Temp\nsjF06D.tmp\newadvsplash.dll | executable | |
MD5:7EE14DFF57FB6E6C644B318D16768F4C | SHA256:53377D0710F551182EDBAB4150935425948535D11B92BF08A1C2DCF989723BD7 | |||
2036 | Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | C:\Users\admin\AppData\Local\Temp\nsjF06D.tmp\tr_files\scroll.js | text | |
MD5:451ADB9F6BED8859CEE8FFE17A356DC6 | SHA256:83C74FE20D8CD134C900BC18231311A307FE9D40508BB0A4A3C008333F4755BB | |||
2036 | Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | C:\Users\admin\AppData\Local\Temp\nsjF06D.tmp\tr_files\scroll.html | html | |
MD5:FA5E9EB978E1ACD9CB8E6CBE2BA76510 | SHA256:1D55105E632396F76B046513F1805F8144B8D2DC2A0D75DD78B37CB771BE705C | |||
2036 | Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | C:\Users\admin\AppData\Local\Temp\nsjF06D.tmp\scroll.html | html | |
MD5:D278D5E2500F0913B22386E3D58F91FC | SHA256:17F6DAB712193E81BD633FF21A440EE489F57F8C169DF9342CAF4B93F2D80B96 | |||
2036 | Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | C:\Users\admin\AppData\Local\Temp\nsjF06D.tmp\System.dll | executable | |
MD5:6F5257C0B8C0EF4D440F4F4FCE85FB1B | SHA256:B7CCB923387CC346731471B20FC3DF1EAD13EC8C2E3147353C71BB0BD59BC8B1 | |||
2036 | Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | C:\Users\admin\AppData\Local\Temp\nsjF06D.tmp\tr_files\scroll.tpl0.js | text | |
MD5:39133E190F144254AC4A3BA40D8863A6 | SHA256:D61DF469C5484D3C20AD027E741321DD1921285142CC8ACF73CF363D7798E310 | |||
2036 | Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | C:\Users\admin\AppData\Local\Temp\nsjF06D.tmp\desc.bmp | image | |
MD5:DA839F46D4E58124434E41479D4BF57B | SHA256:991D9949DE90E744EA6A7EEC3487E34A22DBD785267D16E64958A7B8AEDCCB00 | |||
2036 | Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | C:\Users\admin\AppData\Local\Temp\nsjF06D.tmp\nsDialogs.dll | executable | |
MD5:D9256D9ACAECABB20B7E9A1595ABFA36 | SHA256:D7B2C55977A541F8D075E48D4E0A82EEC79AD247B0ED168C19A8518131ACD19C | |||
2036 | Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | C:\Users\admin\AppData\Local\Temp\nsjF06D.tmp\modern-header.bmp | image | |
MD5:475D20DD189CB549A7164AF5A2C85A2B | SHA256:712A6CA00F0D0C287DFDA1F15A56640CC857C6EC6844ADB3862CE72B805B98B2 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |