| File name: | Stellar Repair for MS SQL Technician v9.0 Portable.exe |
| Full analysis: | https://app.any.run/tasks/8ec5b30e-968b-455e-b065-302edf435af3 |
| Verdict: | Malicious activity |
| Analysis date: | October 28, 2020, 23:24:25 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | F7C817144CC5F68D420C42630CCD3642 |
| SHA1: | 77BC1941BEF52EA7457516862D37F44C2C47B001 |
| SHA256: | 55F38672C40D8ADFC63D400DB6CB275E15F6C5CC0C298B4A4CF58C6D8A993FF3 |
| SSDEEP: | 196608:FLQ8otS/7kuV5jEgJ9q1kUqQaqnQFoDW7bnCnVJdixw+KH7ppFu3GXlo8aUtULn:FLQ83ke5Rq1EQJBGOriCjHdu2Voat+n |
| .exe | | | Win64 Executable (generic) (76.4) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (12.4) |
| .exe | | | Generic Win/DOS Executable (5.5) |
| .exe | | | DOS Executable Generic (5.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:06:24 17:04:40+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 190464 |
| InitializedDataSize: | 503296 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1d4f9 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 24-Jun-2018 15:04:40 |
| Detected languages: |
|
| Debug artifacts: |
|
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000108 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 6 |
| Time date stamp: | 24-Jun-2018 15:04:40 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x0002E7E4 | 0x0002E800 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.70246 |
.rdata | 0x00030000 | 0x00009A8C | 0x00009C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.12921 |
.data | 0x0003A000 | 0x000203A0 | 0x00000C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.23928 |
.gfids | 0x0005B000 | 0x000000E8 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.0785 |
.rsrc | 0x0005C000 | 0x0006E31C | 0x0006E400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.23443 |
.reloc | 0x000CB000 | 0x00001FD0 | 0x00002000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.68222 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.26192 | 1875 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 1.54306 | 67624 | Latin 1 / Western European | Process Default Language | RT_ICON |
3 | 2.40525 | 38056 | Latin 1 / Western European | Process Default Language | RT_ICON |
4 | 3.0179 | 21640 | Latin 1 / Western European | Process Default Language | RT_ICON |
5 | 1.78429 | 16936 | Latin 1 / Western European | Process Default Language | RT_ICON |
6 | 3.03196 | 9640 | Latin 1 / Western European | Process Default Language | RT_ICON |
7 | 3.1586 | 482 | Latin 1 / Western European | English - United States | RT_STRING |
8 | 3.11685 | 460 | Latin 1 / Western European | English - United States | RT_STRING |
9 | 3.15447 | 494 | Latin 1 / Western European | English - United States | RT_STRING |
10 | 2.99727 | 326 | Latin 1 / Western European | English - United States | RT_STRING |
KERNEL32.dll |
USER32.dll (delay-loaded) |
gdiplus.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 396 | "C:\Users\admin\AppData\Local\Temp\Stellar Repair for MS SQL Technician v9.0 Portable.exe" | C:\Users\admin\AppData\Local\Temp\Stellar Repair for MS SQL Technician v9.0 Portable.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 2504 | "C:\Program Files\Stellar Toolkit for MS SQL\EKAG20NT.EXE" 0200906578FD5A5A 0 | C:\Program Files\Stellar Toolkit for MS SQL\EKAG20NT.EXE | — | ssdt.exe | |||||||||||
User: admin Company: Software Security System Integrity Level: HIGH Description: EK Agent (Interface version SRV 2.01) Exit code: 0 Version: 2.0.8.40 Modules
| |||||||||||||||
| 2764 | "C:\Program Files\Stellar Toolkit for MS SQL\ssdt.exe" | C:\Program Files\Stellar Toolkit for MS SQL\ssdt.exe | — | Stellar Repair for MS SQL Technician v9.0 Portable.exe | |||||||||||
User: admin Company: Stellar Information Technology Pvt. Ltd. Integrity Level: HIGH Description: Stellar Toolkit for MS SQL Exit code: 0 Version: 8.0.0.0 Modules
| |||||||||||||||
| 3436 | "C:\Users\admin\AppData\Local\Temp\Stellar Repair for MS SQL Technician v9.0 Portable.exe" | C:\Users\admin\AppData\Local\Temp\Stellar Repair for MS SQL Technician v9.0 Portable.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (3436) Stellar Repair for MS SQL Technician v9.0 Portable.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3436) Stellar Repair for MS SQL Technician v9.0 Portable.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3436 | Stellar Repair for MS SQL Technician v9.0 Portable.exe | C:\Program Files\Stellar Toolkit for MS SQL\SQLPass.chm | chm | |
MD5:2BE9C165C992033EE9865112D423B758 | SHA256:B95010DEDD0E9283BCE3AE11B3D2456C94E2D91B6F71D89DDB27E971816C99E3 | |||
| 3436 | Stellar Repair for MS SQL Technician v9.0 Portable.exe | C:\Program Files\Stellar Toolkit for MS SQL\Default_popup.hlp | hlp | |
MD5:53B074B6BCC854CA7ABA3FAD53AA268C | SHA256:72A9455B3DF11CC8B580958C2D0B28B77FF0BEBF3462FFEE3194F604335FD088 | |||
| 3436 | Stellar Repair for MS SQL Technician v9.0 Portable.exe | C:\Program Files\Stellar Toolkit for MS SQL\animation.avi | avi | |
MD5:8D591A74C70C61CCF1CB7A6ED1B1E2F2 | SHA256:9B4583999F1635DEA188CA92DED1315B343E669C03FBAB3B3B26607B2D8C726C | |||
| 3436 | Stellar Repair for MS SQL Technician v9.0 Portable.exe | C:\Program Files\Stellar Toolkit for MS SQL\SQLBackupRecovery.chm | chm | |
MD5:143F20631E69B1DB7D81D91587458F2D | SHA256:BFE1291EE0FE8B131055825B3E4C108B9BFA0D9B4413C1F8527D02CC10A71142 | |||
| 3436 | Stellar Repair for MS SQL Technician v9.0 Portable.exe | C:\Program Files\Stellar Toolkit for MS SQL\SQLRecovery.chm | chm | |
MD5:9BB802ACF0769016BA5EAB261B9CED8E | SHA256:3EC220B42081608DC30966EF781E0D5E96818A9420BC20155DD230116EA5095C | |||
| 3436 | Stellar Repair for MS SQL Technician v9.0 Portable.exe | C:\Program Files\Stellar Toolkit for MS SQL\SQLToolkit.chm | chm | |
MD5:49A795B4458930CA268DC3E5F796FC93 | SHA256:69669078E449E1BB98288FB2DBD2F5EF5E1E93CA8897F235C481D236DF691BBB | |||
| 3436 | Stellar Repair for MS SQL Technician v9.0 Portable.exe | C:\Program Files\Stellar Toolkit for MS SQL\#.txt | text | |
MD5:65D499534D9A2F155C5E3775E2F56887 | SHA256:B1356AADEB8DAADDD8D989876BC8065C12BD33F648DEF6934F7B753F6FC08BD4 | |||
| 3436 | Stellar Repair for MS SQL Technician v9.0 Portable.exe | C:\Program Files\Stellar Toolkit for MS SQL\spspt.exe | executable | |
MD5:641BA126E189C1FD7B615ABC4FDBBBFD | SHA256:69D476B7438EB79B2953F1E2D3C14AB20311ED961540DAEE3C0479C6F51A7DBE | |||
| 3436 | Stellar Repair for MS SQL Technician v9.0 Portable.exe | C:\Program Files\Stellar Toolkit for MS SQL\Ekag20nt.exe | executable | |
MD5:3D48C7247AFA1C0AD0EFAEAC613DC2EC | SHA256:D420F02791D6E45711EB06D7AD02F6B63066B8C09002B7474495AE6C3BDB9106 | |||
| 3436 | Stellar Repair for MS SQL Technician v9.0 Portable.exe | C:\Program Files\Stellar Toolkit for MS SQL\Rockey2.dll | executable | |
MD5:FE4AC9B90B33776638C3DCE2FA70A2F6 | SHA256:041736A518B0BB96725AD0A68F1B9BCA646091AFF2C9D3D262A145EDE40BD3EB | |||