File name: | Acunetix Premium Activation Tool.exe |
Full analysis: | https://app.any.run/tasks/aca3843e-6ca6-452b-a762-0f7e9c9263c9 |
Verdict: | Malicious activity |
Analysis date: | October 30, 2023, 05:51:29 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32+ executable (GUI) x86-64, for MS Windows |
MD5: | BB612315F3A8DF67C64B933FAD04ED2C |
SHA1: | 62FF97C94602DE37C1046A5A129EE2C955852084 |
SHA256: | 4C9C43F2EECE93A8996CB614D59E161B4824FF929555FAA3B05142DB49E0A3A3 |
SSDEEP: | 98304:iQR79rMVOV0HTnW1Et5+zu9c/kU/v/EAMsg1W9y/AnUfD4JnMEUvI3v5V5wCqwMt:XqH6n38OctbBoQIZck08Jp9Vfex |
.exe | | | Generic Win/DOS Executable (50) |
---|---|---|
.exe | | | DOS Executable Generic (49.9) |
MachineType: | AMD AMD64 |
---|---|
TimeStamp: | 2023:10:29 18:00:56+01:00 |
ImageFileCharacteristics: | Executable, Large address aware |
PEType: | PE32+ |
LinkerVersion: | 14.16 |
CodeSize: | 734208 |
InitializedDataSize: | 9509888 |
UninitializedDataSize: | - |
EntryPoint: | 0xfea058 |
OSVersion: | 5.2 |
ImageVersion: | - |
SubsystemVersion: | 5.2 |
Subsystem: | Windows GUI |
FileVersionNumber: | 23.9.23102.153 |
ProductVersionNumber: | 23.9.23102.153 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Unknown |
FileSubtype: | - |
LanguageCode: | English (British) |
CharacterSet: | Unicode |
Comments: | www.Dr-FarFar.com |
CompanyName: | Dr.FarFar | www.Dr-FarFar.com |
FileDescription: | Acunetix Premium Activation Tool (ViP) |
FileVersion: | 23.9.231020153 |
InternalName: | Acunetix Premium Activation Tool.exe |
LegalCopyright: | Copyright © Dr.FarFar |
LegalTrademarks: | www.Dr-FarFar.com |
OriginalFileName: | Acunetix Premium Activation Tool.exe |
ProductName: | Acunetix Premium Activation Tool (ViP) |
ProductVersion: | 23.9.231020153 |
AssemblyVersion: | 23.9.231020153 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
244 | C:\Windows\system32\net1 stop "Acunetix Database" | C:\Windows\System32\net1.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
284 | net stop Acunetix | C:\Windows\System32\net.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
712 | C:\Windows\system32\cmd.exe /C net start "Acunetix Database" | C:\Windows\System32\cmd.exe | — | Acunetix Premium Activation Tool.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
1584 | net start Acunetix | C:\Windows\System32\net.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1644 | net stop "Acunetix Database" | C:\Windows\System32\net.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
1824 | C:\Windows\system32\cmd.exe /C net stop Acunetix | C:\Windows\System32\cmd.exe | — | Acunetix Premium Activation Tool.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
2128 | "C:\Users\admin\AppData\Local\Temp\Acunetix Premium Activation Tool.exe" | C:\Users\admin\AppData\Local\Temp\Acunetix Premium Activation Tool.exe | explorer.exe | ||||||||||||
User: admin Company: Dr.FarFar | www.Dr-FarFar.com Integrity Level: HIGH Description: Acunetix Premium Activation Tool (ViP) Exit code: 0 Version: 23.9.231020153 Modules
| |||||||||||||||
2160 | C:\Windows\system32\net1 stop Acunetix | C:\Windows\System32\net1.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
2160 | C:\Windows\system32\net1 start Acunetix | C:\Windows\System32\net1.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
2464 | C:\Windows\system32\cmd.exe /C net stop "Acunetix Database" | C:\Windows\System32\cmd.exe | — | Acunetix Premium Activation Tool.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 2 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
|
PID | Process | Filename | Type | |
---|---|---|---|---|
2128 | Acunetix Premium Activation Tool.exe | C:\Users\admin\AppData\Local\Temp\autCCA2.tmp | image | |
MD5:04EF95DECF3B30DDC2BF049451D545D6 | SHA256:FE8C6DA36EC29C411567E775CC1C75A4FA832F7ED9AB0522AB227A5027B89FBA | |||
2128 | Acunetix Premium Activation Tool.exe | C:\Users\admin\AppData\Local\Temp\autF740.tmp | binary | |
MD5:671249B261777F9088F253755032F14B | SHA256:E5011A4047A78E831C722EDDB457BC6B87B7EB0C2035699069EE0C0476A4E636 | |||
2128 | Acunetix Premium Activation Tool.exe | C:\Users\admin\AppData\Local\Temp\autF72F.tmp | binary | |
MD5:081FBCDD9C513495381C2C338581A5FD | SHA256:E878736860D7D2956FBEC4FB73ADA9F02DF85D904A67751A7304938E27CEB918 | |||
2128 | Acunetix Premium Activation Tool.exe | C:\Windows\system32\drivers\etc\hosts | text | |
MD5:55A51E982C31EED6B268CF59726DBBCE | SHA256:DF21AFD6FADFA147E2E7C3A0AFFCBB1D01B8F1F146503A82FC8E379CCCEA968A | |||
2128 | Acunetix Premium Activation Tool.exe | C:\Users\admin\AppData\Local\Temp\autF71F.tmp | binary | |
MD5:F57011712B73FA6490F4C5DD91A5554F | SHA256:2FAE4C200D455166F1C1322B9EDCEC741F99D388D67AFA3FC5329A6E6C423D00 | |||
2128 | Acunetix Premium Activation Tool.exe | C:\Users\admin\AppData\Local\Temp\autF49D.tmp | executable | |
MD5:55AC1B23AEFEFE768CCEFE58264B07A9 | SHA256:EA812DC5CD875C0DD4D52E8E7C53F8D5CF372A982DED00BBFA6CC1C2605864C9 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
324 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
1956 | svchost.exe | 239.255.255.250:1900 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
Domain | IP | Reputation |
---|---|---|
teredo.ipv6.microsoft.com |
| unknown |