| File name: | Setup_FileViewPro_2016.exe |
| Full analysis: | https://app.any.run/tasks/4309aa87-e2bf-4c3d-b8c5-615ae32b0d59 |
| Verdict: | Malicious activity |
| Analysis date: | September 19, 2018, 13:07:50 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | A6ABFC89867EECFBFC2B35CAD6A20BDF |
| SHA1: | 957CB49BBDE604C58089CF3F5FBD5DE8F10D76A0 |
| SHA256: | 55078FC1265628DC3F51A47F707CE012B8F394FB0DC8B184DDE2E493F56B4F6B |
| SSDEEP: | 49152:jRSmH5yWt0V1ekvZ9RakS4voxCnF0TSy8qRSQEGx:tSmZt01tvZ9oN4vo4ARz/ |
| .dll | | | Win32 Dynamic Link Library (generic) (43.5) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (29.8) |
| .exe | | | Generic Win/DOS Executable (13.2) |
| .exe | | | DOS Executable Generic (13.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2014:11:09 12:22:09+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 12 |
| CodeSize: | 30720 |
| InitializedDataSize: | 5580800 |
| UninitializedDataSize: | 90112 |
| EntryPoint: | 0x3be3 |
| OSVersion: | 6 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.2.3.4 |
| ProductVersionNumber: | 1.2.3.4 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | FileViewPro is cool application. |
| CompanyName: | Solvusoft |
| FileDescription: | FileViewPro |
| FileVersion: | 1.2.3 |
| LegalCopyright: | � Solvusoft 2016 |
| LegalTrademarks: | FileViewPro is a trademark of Solvusoft |
| ProductName: | FileViewPro |
| ProductVersion: | 1.2.3 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 09-Nov-2014 11:22:09 |
| Detected languages: |
|
| Comments: | FileViewPro is cool application. |
| CompanyName: | Solvusoft |
| FileDescription: | FileViewPro |
| FileVersion: | 1.2.3 |
| LegalCopyright: | � Solvusoft 2016 |
| LegalTrademarks: | FileViewPro is a trademark of Solvusoft |
| ProductName: | FileViewPro |
| ProductVersion: | 1.2.3 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000D8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 6 |
| Time date stamp: | 09-Nov-2014 11:22:09 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x0000764A | 0x00007800 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.48123 |
.rdata | 0x00009000 | 0x00002A9E | 0x00002C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.40905 |
.data | 0x0000C000 | 0x0054DDB8 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.43231 |
.ndata | 0x0055A000 | 0x00AD1000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x0102B000 | 0x00020D90 | 0x00020E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.22174 |
.reloc | 0x0104C000 | 0x00000A2C | 0x00000C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 2.58779 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.21712 | 968 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 7.98947 | 51193 | UNKNOWN | English - United States | RT_ICON |
3 | 0 | 2216 | UNKNOWN | English - United States | RT_ICON |
4 | 0 | 1384 | UNKNOWN | English - United States | RT_ICON |
5 | 0 | 1128 | UNKNOWN | English - United States | RT_ICON |
6 | 0 | 744 | UNKNOWN | English - United States | RT_ICON |
7 | 0 | 296 | UNKNOWN | English - United States | RT_ICON |
103 | 2.75235 | 104 | UNKNOWN | English - United States | RT_GROUP_ICON |
105 | 2.71364 | 642 | UNKNOWN | English - United States | RT_DIALOG |
106 | 2.89384 | 248 | UNKNOWN | English - United States | RT_DIALOG |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
SHELL32.dll |
USER32.dll |
VERSION.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 920 | "C:\Users\admin\AppData\Local\Temp\Setup_FileViewPro_2016.exe" | C:\Users\admin\AppData\Local\Temp\Setup_FileViewPro_2016.exe | explorer.exe | ||||||||||||
User: admin Company: Solvusoft Integrity Level: HIGH Description: FileViewPro Exit code: 0 Version: 1.2.3 Modules
| |||||||||||||||
| 1336 | "C:\Users\admin\AppData\Local\Temp\Setup_FileViewPro_2016.exe" | C:\Users\admin\AppData\Local\Temp\Setup_FileViewPro_2016.exe | — | explorer.exe | |||||||||||
User: admin Company: Solvusoft Integrity Level: MEDIUM Description: FileViewPro Exit code: 3221226540 Version: 1.2.3 Modules
| |||||||||||||||
| (PID) Process: | (920) Setup_FileViewPro_2016.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (920) Setup_FileViewPro_2016.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (920) Setup_FileViewPro_2016.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018091920180920 |
| Operation: | write | Name: | CachePath |
Value: %USERPROFILE%\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012018091920180920 | |||
| (PID) Process: | (920) Setup_FileViewPro_2016.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018091920180920 |
| Operation: | write | Name: | CachePrefix |
Value: :2018091920180920: | |||
| (PID) Process: | (920) Setup_FileViewPro_2016.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018091920180920 |
| Operation: | write | Name: | CacheLimit |
Value: 8192 | |||
| (PID) Process: | (920) Setup_FileViewPro_2016.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018091920180920 |
| Operation: | write | Name: | CacheOptions |
Value: 11 | |||
| (PID) Process: | (920) Setup_FileViewPro_2016.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Extensible Cache\MSHist012018091920180920 |
| Operation: | write | Name: | CacheRepair |
Value: 0 | |||
| (PID) Process: | (920) Setup_FileViewPro_2016.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Setup_FileViewPro_2016_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (920) Setup_FileViewPro_2016.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Setup_FileViewPro_2016_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (920) Setup_FileViewPro_2016.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\Setup_FileViewPro_2016_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: 4294901760 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 920 | Setup_FileViewPro_2016.exe | C:\Users\admin\AppData\Local\Temp\nsb191D.tmp\nsArray.pdb | pdb | |
MD5:6AEE0E72609A8610498D13269A9DFC54 | SHA256:62CAFD3146E0425ABAE0140D7A5624993BB7E7ADA0C7B67D7E07F7F650D338F2 | |||
| 920 | Setup_FileViewPro_2016.exe | C:\Users\admin\AppData\Local\Temp\nsb191D.tmp\nsArray.dll | executable | |
MD5:E9DF0C769FAB7F03CA4C24F1D5117381 | SHA256:62116DF27594BE55AAF70F6B63D5C393CA98E2133D1B3CC602592488F5ACE217 | |||
| 920 | Setup_FileViewPro_2016.exe | C:\Users\admin\AppData\Local\Temp\nsb191D.tmp\nsWeb.dll | executable | |
MD5:36382F1D8E93727900EFE9ED4388693E | SHA256:413FFCB2EBF34A2EF2873E2B03D21CF2021DBFAB7B259DE3EA2AC310F38EBD4E | |||
| 920 | Setup_FileViewPro_2016.exe | C:\Users\admin\AppData\Local\Temp\nsb191D.tmp\background.bmp | image | |
MD5:8DC8BAA51F18EFAE83D2367F0967770B | SHA256:C29E7BCE56C3E56D6E92A073769D8426281A84D3E1069A0D35845184A8C99C52 | |||
| 920 | Setup_FileViewPro_2016.exe | C:\Users\admin\AppData\Local\Temp\nsb191D.tmp\button.bmp | image | |
MD5:19AE63749B1247EFD5318E632DFBBE4D | SHA256:6F5E51BEABF1AE13E0F1D368D1FC0CFBDE7CD860204E02578C325CB6ECC1C25A | |||
| 920 | Setup_FileViewPro_2016.exe | C:\Users\admin\AppData\Local\Temp\nsb191D.tmp\Banner.dll | executable | |
MD5:978CE7033321CC4793AD7FBAB6E4EE2F | SHA256:893F154F62264786DEAD3DF552C671D48AAF757B89805F5AA864BE650C469D6D | |||
| 920 | Setup_FileViewPro_2016.exe | C:\Users\admin\AppData\Local\Temp\nsb191D.tmp\progress_finished.jpg | image | |
MD5:6437315E8B474DCE8FECC188C0777255 | SHA256:4D45354E30D6E44679E1D06F841F55141D5588EF14CE76ED85DB990EAB2C0579 | |||
| 920 | Setup_FileViewPro_2016.exe | C:\Users\admin\AppData\Local\Temp\nsb191D.tmp\progress_softwareoptions.jpg | image | |
MD5:BC4A9CFC9542E9A13554F20508D1DC10 | SHA256:6730B34C00AAD494516D6623287E4210C366FF569D84DFE1074008398F264748 | |||
| 920 | Setup_FileViewPro_2016.exe | C:\Users\admin\AppData\Local\Temp\nsb191D.tmp\progress_welcome.jpg | image | |
MD5:C31FF5F4C648C9239D91B47171104872 | SHA256:2D0F7CC6BA0B7259A5D5E2EADE1FACE762CF46DB335E7CC5D1982F3312B36B55 | |||
| 920 | Setup_FileViewPro_2016.exe | C:\Users\admin\AppData\Local\Temp\nsb191D.tmp\progress_installation.jpg | image | |
MD5:31221633075ADB7FF48AE59854A2EC8B | SHA256:655753019379B9A67DD11BCA07C33028ADA03ECFFE962751539F2961669E6CF9 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
920 | Setup_FileViewPro_2016.exe | GET | — | 2.19.43.105:80 | http://www.solvusoft.com/file-downloads/builds/static_delivery/file_parts/winthruster/spf/build_102315/WinThrusterSetup_1.16.7.exe | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
920 | Setup_FileViewPro_2016.exe | 2.19.43.105:80 | www.solvusoft.com | Akamai International B.V. | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.solvusoft.com |
| whitelisted |