| File name: | Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe |
| Full analysis: | https://app.any.run/tasks/4e6bc272-19f4-4774-b8b6-0dfa442f8d7a |
| Verdict: | Malicious activity |
| Analysis date: | February 16, 2024, 01:01:52 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, UPX compressed, Nullsoft Installer self-extracting archive |
| MD5: | D0DEB74BF4056BB7315BD06E7EAB8BC0 |
| SHA1: | 21C377E05A37C4A4DF47B7E76178AE0918889104 |
| SHA256: | 4ABAF0C84D387E8C185591203A58B12E4221E2FC2ED1B452DD87A89EBDE363F7 |
| SSDEEP: | 24576:KgJATTgdXjeMCqMn9cGuQIOR8SdiZbhcovBkp7SAfHc3ik3zKuL2V8QhJk2B8VXE:KgJoTEXjeMCqMn9cGuQIOR8SdiZbhco6 |
| .exe | | | UPX compressed Win32 Executable (39.3) |
|---|---|---|
| .exe | | | Win32 EXE Yoda's Crypter (38.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (9.5) |
| .exe | | | Win32 Executable (generic) (6.5) |
| .exe | | | Generic Win/DOS Executable (2.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2015:08:05 00:46:27+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 20480 |
| InitializedDataSize: | 12288 |
| UninitializedDataSize: | 225280 |
| EntryPoint: | 0x3c560 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| Comments: | Distribuido pela Tribo Gamer Brasil® |
| CompanyName: | Tribo Gamer Brasil® |
| CompanyWebsite: | http://www.tribogamer.com/ |
| FileDescription: | Bioshock 2 Remastered Tradução BR 1.00 |
| FileVersion: | 1 |
| LegalCopyright: | 2017 - Tribo Gamer Brasil® - Direitos Reservados |
| LegalTrademarks: | Bioshock 2 Remastered é uma marca da 2K Games. Nós apenas traduzimos o jogo. |
| ProductName: | Tradução do jogo: Bioshock 2 Remastered |
| ProductVersion: | 1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2036 | "C:\Users\admin\AppData\Local\Temp\Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe" | C:\Users\admin\AppData\Local\Temp\Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | explorer.exe | ||||||||||||
User: admin Company: Tribo Gamer Brasil® Integrity Level: HIGH Description: Bioshock 2 Remastered Tradução BR 1.00 Exit code: 1 Version: 1.00 Modules
| |||||||||||||||
| 3864 | "C:\Users\admin\AppData\Local\Temp\Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe" | C:\Users\admin\AppData\Local\Temp\Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | — | explorer.exe | |||||||||||
User: admin Company: Tribo Gamer Brasil® Integrity Level: MEDIUM Description: Bioshock 2 Remastered Tradução BR 1.00 Exit code: 3221226540 Version: 1.00 Modules
| |||||||||||||||
| (PID) Process: | (2036) Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2036) Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2036) Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2036) Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2036) Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2036) Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2036) Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (2036) Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry |
| Operation: | delete value | Name: | AddToFavoritesInitialSelection |
Value: | |||
| (PID) Process: | (2036) Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\LowRegistry |
| Operation: | delete value | Name: | AddToFeedsInitialSelection |
Value: | |||
| (PID) Process: | (2036) Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager |
| Operation: | write | Name: | PendingFileRenameOperations |
Value: \??\C:\Users\admin\AppData\Local\Temp\nsjF06D.tmp\tr_data\ | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2036 | Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | C:\Users\admin\AppData\Local\Temp\nsjF06D.tmp\desc.bmp | image | |
MD5:DA839F46D4E58124434E41479D4BF57B | SHA256:991D9949DE90E744EA6A7EEC3487E34A22DBD785267D16E64958A7B8AEDCCB00 | |||
| 2036 | Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | C:\Users\admin\AppData\Local\Temp\nsjF06D.tmp\System.dll | executable | |
MD5:6F5257C0B8C0EF4D440F4F4FCE85FB1B | SHA256:B7CCB923387CC346731471B20FC3DF1EAD13EC8C2E3147353C71BB0BD59BC8B1 | |||
| 2036 | Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | C:\Users\admin\AppData\Local\Temp\nsjF06D.tmp\nsDialogs.dll | executable | |
MD5:D9256D9ACAECABB20B7E9A1595ABFA36 | SHA256:D7B2C55977A541F8D075E48D4E0A82EEC79AD247B0ED168C19A8518131ACD19C | |||
| 2036 | Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | C:\Users\admin\AppData\Local\Temp\nsjF06D.tmp\scroll.html | html | |
MD5:D278D5E2500F0913B22386E3D58F91FC | SHA256:17F6DAB712193E81BD633FF21A440EE489F57F8C169DF9342CAF4B93F2D80B96 | |||
| 2036 | Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | C:\Users\admin\AppData\Local\Temp\~DF2BD12689E12D1756.TMP | binary | |
MD5:3222E59D1824622E932D40AE6A199206 | SHA256:CB9AD302A7C2E353E9E3561832714E9400B1CCE94323786FF02BCD30B3EF9383 | |||
| 2036 | Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | C:\Users\admin\AppData\Local\Temp\nsjF06D.tmp\tr_data\legal.html | html | |
MD5:B3626E3A94CB2D8C3FC3A253E1846173 | SHA256:81EF9AAB1BAC38764893718DF361C4600AA7EB893E60D8D66AC855200D02CED3 | |||
| 2036 | Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | C:\Users\admin\AppData\Local\Temp\nsjF06D.tmp\tr_files\scroll.html | html | |
MD5:FA5E9EB978E1ACD9CB8E6CBE2BA76510 | SHA256:1D55105E632396F76B046513F1805F8144B8D2DC2A0D75DD78B37CB771BE705C | |||
| 2036 | Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | C:\Users\admin\AppData\Local\Temp\nsjF06D.tmp\tg_logo.gif | image | |
MD5:C7D46A49E9967694F856B566CFCF5E1F | SHA256:99616D738D6718FDE19B8408310CF29383A12F315A8A86B521BB93EC5721FC92 | |||
| 2036 | Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | C:\Users\admin\AppData\Local\Temp\nsjF06D.tmp\tr_files\scroll.js | text | |
MD5:451ADB9F6BED8859CEE8FFE17A356DC6 | SHA256:83C74FE20D8CD134C900BC18231311A307FE9D40508BB0A4A3C008333F4755BB | |||
| 2036 | Tradutor BioShock 2 Remastered pt-BR Baixesoft.com.exe | C:\Users\admin\AppData\Local\Temp\nsjF06D.tmp\tr_files\scroll0.css | text | |
MD5:C4B2510AE8A1EF4FA79C026BDACF1BC4 | SHA256:532B40642E87183BA650D1F719D86385425CCCA5D46B21E1A206832E58B36FE9 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |