File name: | Tftpd64-4.64-setup.exe |
Full analysis: | https://app.any.run/tasks/e6dfceab-fe9e-4354-9cc1-19862ec66520 |
Verdict: | Malicious activity |
Analysis date: | February 09, 2024, 08:50:45 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
MD5: | 044CC568B52CE2E65EB82D3D3B7FFA2F |
SHA1: | E53DF45B9994F7D02B48B0E002D5E06F00535BC6 |
SHA256: | 525A2EB43F2A4C702213723541335DC0391B42A01177E1FAF5873E0CB7540CE0 |
SSDEEP: | 12288:slKyxovP4Jw+ULNC0IVfG5IAeKPOFwTM84qpcy+qtv2tSoTqLQby4q:sMyavP4Jhg7IWWFA4qphN28o+LQe4q |
.exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
---|---|---|
.exe | | | Win64 Executable (generic) (37.3) |
.dll | | | Win32 Dynamic Link Library (generic) (8.8) |
.exe | | | Win32 Executable (generic) (6) |
.exe | | | Generic Win/DOS Executable (2.7) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2016:04:02 05:20:13+02:00 |
ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
PEType: | PE32 |
LinkerVersion: | 6 |
CodeSize: | 24576 |
InitializedDataSize: | 164864 |
UninitializedDataSize: | 1024 |
EntryPoint: | 0x312a |
OSVersion: | 4 |
ImageVersion: | 6 |
SubsystemVersion: | 4 |
Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2328 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3240 | "C:\Users\admin\AppData\Local\Temp\Tftpd64-4.64-setup.exe" | C:\Users\admin\AppData\Local\Temp\Tftpd64-4.64-setup.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
3784 | "C:\Users\admin\AppData\Local\Temp\Tftpd64-4.64-setup.exe" | C:\Users\admin\AppData\Local\Temp\Tftpd64-4.64-setup.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
|
(PID) Process: | (3784) Tftpd64-4.64-setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Tftpd64 |
Operation: | write | Name: | Install_Dir |
Value: C:\Program Files\Tftpd64 | |||
(PID) Process: | (3784) Tftpd64-4.64-setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Tftpd64 |
Operation: | write | Name: | DisplayName |
Value: Tftpd64 Standalone Edition (remove only) | |||
(PID) Process: | (3784) Tftpd64-4.64-setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Tftpd64 |
Operation: | write | Name: | UninstallString |
Value: "C:\Program Files\Tftpd64\uninstall.exe" | |||
(PID) Process: | (3784) Tftpd64-4.64-setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Tftpd64 |
Operation: | write | Name: | NoModify |
Value: 1 | |||
(PID) Process: | (3784) Tftpd64-4.64-setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Tftpd64 |
Operation: | write | Name: | NoRepair |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3784 | Tftpd64-4.64-setup.exe | C:\Program Files\Tftpd64\EUPL-EN.pdf | ||
MD5:254B5DDBC15269E72BA3A0508681A70C | SHA256:CD5D9E2A925D8DAA92D083FD8C1CEA48DF1BCFFFD857F4F93E2148FDDC5001EC | |||
3784 | Tftpd64-4.64-setup.exe | C:\Program Files\Tftpd64\tftpd32.chm | binary | |
MD5:DE0095E371874836FB50CD3400D7B204 | SHA256:810A0F52703D051B30D5ECD219C72B0599964DE34D1C1912367271C87D4725BF | |||
3784 | Tftpd64-4.64-setup.exe | C:\Program Files\Tftpd64\tftpd32.ini | text | |
MD5:C973075D00B0BF2D5C4CB18155AD92FB | SHA256:0C00CBDAE4E3F2F430CA803E2E08BB3CBBA4E83CF9024DBB64DA212B8034E60D | |||
3784 | Tftpd64-4.64-setup.exe | C:\Program Files\Tftpd64\uninstall.exe | executable | |
MD5:078DAF9669EF12A368F1AED5A21B1CD1 | SHA256:0A91E2FAB1DE979C8BD0816C5A709DEB7BDB80A198C9163D58A5CE377607FB9D | |||
3784 | Tftpd64-4.64-setup.exe | C:\Program Files\Tftpd64\tftpd64.exe | executable | |
MD5:3C1E3215ACC69F06F044802ED4695333 | SHA256:34DE53B43C32E3ED5231A57683103ACAD1AEBEEF08309CF8E770C27ACC90E4E7 | |||
3784 | Tftpd64-4.64-setup.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tftpd64\Tftpd64.lnk | binary | |
MD5:F076957ABD540CDCF3C9FF020CC1D09E | SHA256:1E29898E6B9062EA8F51E089F7364FF25832D015D724AABA975728CF50BC1EEA | |||
3784 | Tftpd64-4.64-setup.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tftpd64\Uninstall.lnk | binary | |
MD5:8C96466F2DA3B63C2487449111F730C7 | SHA256:E7E762DC928A4F3460435DD4FC412D115B9134E87EA039318010C84B2ECB7305 | |||
3784 | Tftpd64-4.64-setup.exe | C:\Users\admin\Desktop\Tftpd64.lnk | binary | |
MD5:C39B83BB07D039F187AC2A390468D1ED | SHA256:0F98240775B6351376E2A7CEB9C751863C3446D113636AA07BA871C391E6FADA | |||
3784 | Tftpd64-4.64-setup.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Tftpd64\Tftpd64 Settings.lnk | binary | |
MD5:5C7C0CDC80AA7148B3EB30A97A264EE5 | SHA256:A3EE76A20E01D65FF61DA63FEED1797C2EADEA9B77D76A8EDF307754BD6DC6B8 |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |