| download: | /shift/download/shift%20-%20recipes_mkr3j.exe |
| Full analysis: | https://app.any.run/tasks/3bdd34ea-ee22-4abc-af24-5a34b9418ce0 |
| Verdict: | Malicious activity |
| Analysis date: | March 01, 2024, 22:51:59 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 3309BC3CE827067F87C95514729547E7 |
| SHA1: | E16C50DC34F71238C885D72EB247A283DA010BD8 |
| SHA256: | 53C620082F8E9AC1C0D3EC4DEF4546BC47410BD3D4FC812F0EA4445E11452F2A |
| SSDEEP: | 98304:C+cD4dnHwICNdt3uMEBitlGX8XsQpZX5vEVpyQn6hHzwOeNO4SPvsm6Puq/GpBjJ:kaB |
| .exe | | | Inno Setup installer (67.7) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (25.6) |
| .exe | | | Win32 Executable (generic) (2.7) |
| .exe | | | Win16/32 Executable Delphi generic (1.2) |
| .exe | | | Generic Win/DOS Executable (1.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:02:15 14:54:16+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741888 |
| InitializedDataSize: | 421888 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6.1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 118.9.0.0 |
| ProductVersionNumber: | 118.9.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Shift |
| FileDescription: | Shift Setup |
| FileVersion: | 118.9.0 |
| LegalCopyright: | Copyright Shift. All rights reserved. |
| OriginalFileName: | |
| ProductName: | Shift |
| ProductVersion: | 118.9.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3240 | "C:\Users\admin\AppData\Local\Temp\3bdd34ea-ee22-4abc-af24-5a34b9418ce0.exe" | C:\Users\admin\AppData\Local\Temp\3bdd34ea-ee22-4abc-af24-5a34b9418ce0.exe | explorer.exe | ||||||||||||
User: admin Company: Shift Integrity Level: MEDIUM Description: Shift Setup Exit code: 0 Version: 118.9.0 Modules
| |||||||||||||||
| 3672 | "C:\Users\admin\AppData\Local\Temp\is-OJ0F7.tmp\3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp" /SL5="$E0170,1390925,1164800,C:\Users\admin\AppData\Local\Temp\3bdd34ea-ee22-4abc-af24-5a34b9418ce0.exe" | C:\Users\admin\AppData\Local\Temp\is-OJ0F7.tmp\3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp | 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.exe | ||||||||||||
User: admin Company: Shift Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| (PID) Process: | (3672) 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 580E000054C234192B6CDA01 | |||
| (PID) Process: | (3672) 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: 8BF1CD131C5DD8B9F467E7F41159D2A2222827A5BC3E7359A4F2DFCD89F62294 | |||
| (PID) Process: | (3672) 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (3672) 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3672 | 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp | C:\Users\admin\AppData\Local\Temp\is-SK14K.tmp\shift.png | image | |
MD5:0423D0589E58341B5B64C6099F4123B7 | SHA256:A1D2C48437058F24A5EA85C323469473AC4430198770794522A32C28783AADB7 | |||
| 3240 | 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.exe | C:\Users\admin\AppData\Local\Temp\is-OJ0F7.tmp\3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp | executable | |
MD5:8D02EE65163DDEF78FFD93584DD69B7F | SHA256:478F6536B636E432AC2E908335F54E2D5904D07F5F7F78821CA52063130286EE | |||
| 3672 | 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp | C:\Users\admin\AppData\Local\Temp\is-SK14K.tmp\shift.bmp | image | |
MD5:6FD867F79E4C82E47C570F09646E9E2E | SHA256:334779A03F50163C87618856BEF8D8493806CC4B086E460E3189791DB6323796 | |||
| 3672 | 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp | C:\Users\admin\AppData\Local\Temp\is-SK14K.tmp\min-pressed.bmp | image | |
MD5:CC62DDE39B9CAA24626A3A0EB93C70FA | SHA256:8D25A76A6552A927407CB0D7BA1E61E8644D76420C2690F8CB3DB90F75ECC1E7 | |||
| 3672 | 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp | C:\Users\admin\AppData\Local\Temp\is-SK14K.tmp\min-rest.bmp | image | |
MD5:C32BFC11F1A32BAB6A1ED327C8A89E0E | SHA256:24BEE6D5DA65DC8A65EB639E3C189F257BC4B231940BD078BBEA23BA985EABB5 | |||
| 3672 | 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp | C:\Users\admin\AppData\Local\Temp\is-SK14K.tmp\min-10-dark.png | image | |
MD5:14CA04108E5AC6A1B8C7A2B689382E44 | SHA256:9CB22401A923DFECAFC5F51DACEF5CBAE440B53B9932217C6BC4626F04920929 | |||
| 3672 | 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp | C:\Users\admin\AppData\Local\Temp\is-SK14K.tmp\min-hover.bmp | image | |
MD5:E08B0A658E4A166C5461C542BE2B0D2F | SHA256:6F696C0C59CEDD0456270BCC868B6B3D7CBCA43911390904014F532CD7B131D5 | |||
| 3672 | 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp | C:\Users\admin\AppData\Local\Temp\is-SK14K.tmp\Win32Library.dll | executable | |
MD5:D82B30898C428A7DBEE81CECEA520F68 | SHA256:92AF9D054E3B5DC9F472FF9534060D1C70E2AC77F768AE9E5029E29FCD606198 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3672 | 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp | 52.34.167.222:443 | updates.shiftapis.com | AMAZON-02 | US | unknown |
3672 | 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp | 49.13.77.253:443 | update.shiftapis.com | Hetzner Online GmbH | DE | unknown |
3672 | 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp | 35.190.25.25:443 | api.mixpanel.com | GOOGLE | US | whitelisted |
3672 | 3bdd34ea-ee22-4abc-af24-5a34b9418ce0.tmp | 104.22.77.241:443 | downloads.tryshift.com | CLOUDFLARENET | — | unknown |
Domain | IP | Reputation |
|---|---|---|
updates.shiftapis.com |
| unknown |
update.shiftapis.com |
| unknown |
api.mixpanel.com |
| whitelisted |
downloads.tryshift.com |
| unknown |