| File name: | Restoro.exe |
| Full analysis: | https://app.any.run/tasks/620070bd-0193-4b0e-af96-1f34a3f746ed |
| Verdict: | Malicious activity |
| Analysis date: | February 25, 2024, 20:12:12 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 149B7754E41E3330E87D3C303FECE58C |
| SHA1: | 609F69F21AF038A251698CA503AC0D1E3BF91693 |
| SHA256: | 5D99408FC2F7BC85F2C4BC6DCD762008BFECD5C8DCAAACF9C9BDC2914DDD22B1 |
| SSDEEP: | 12288:SEiLxas2VYHhJfEj2YxSjzbzbJln4GIyFNj+GRwWxsseOxd0:StxRBJMj2YxqnPn+GjiWxszOxy |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2012:02:24 19:19:59+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 10 |
| CodeSize: | 28672 |
| InitializedDataSize: | 446464 |
| UninitializedDataSize: | 16896 |
| EntryPoint: | 0x39e3 |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.0.2.8 |
| ProductVersionNumber: | 2.0.2.8 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| CompanyName: | Restoro |
| FileDescription: | Restoro Downloader |
| FileVersion: | 2.028 |
| InternalName: | Restoro Downloader |
| LegalCopyright: | © Restoro |
| LegalTrademarks: | Restoro |
| ProductName: | Restoro |
| ProductVersion: | 2.028 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 848 | "C:\Users\admin\AppData\Local\Temp\nssFB88.tmp\ns38F.tmp" cmd /C tasklist /FI "IMAGENAME eq avupdate.exe" > C:\Users\admin\AppData\Local\Temp\IsProcessActive.txt | C:\Users\admin\AppData\Local\Temp\nssFB88.tmp\ns38F.tmp | — | Restoro.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 880 | ping.exe -n 4 www.google.com | C:\Windows\System32\PING.EXE | — | Restoro.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: TCP/IP Ping Command Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 896 | tasklist /FI "IMAGENAME eq avupdate.exe" | C:\Windows\System32\tasklist.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Lists the current running tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1020 | "C:\Users\admin\AppData\Local\Temp\nsx37D1.tmp\ns393C.tmp" "C:\Users\admin\AppData\Local\Temp\FF.bat" > C:\Users\admin\AppData\Local\Temp\FF.txt | C:\Users\admin\AppData\Local\Temp\nsx37D1.tmp\ns393C.tmp | — | Restoro.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 1040 | C:\Windows\system32\cmd.exe /c ""C:\Users\admin\AppData\Local\Temp\FF.bat" > C:\Users\admin\AppData\Local\Temp\FF.txt" | C:\Windows\System32\cmd.exe | — | nsFC65.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1216 | "C:\Users\admin\AppData\Local\Temp\sqlite3.exe" "C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cookies.sqlite" "select value, expiry from moz_cookies where baseDomain like 'restoro.com' and name='_trackid_product_24';" | C:\Users\admin\AppData\Local\Temp\sqlite3.exe | cmd.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 1484 | "C:\Users\admin\AppData\Local\Temp\Restoro.exe" /ResumeInstall=2 /Language=1033 /ABver=Default /pxkp=Delete /StartScan=0 /ShowSettings=false /ScanConfirm=false | C:\Users\admin\AppData\Local\Temp\Restoro.exe | — | explorer.exe | |||||||||||
User: admin Company: Restoro Integrity Level: MEDIUM Description: Restoro Downloader Exit code: 3221226540 Version: 2.028 Modules
| |||||||||||||||
| 1624 | "tasklist.exe" | C:\Windows\System32\tasklist.exe | — | Restoro.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Lists the current running tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1636 | "C:\Users\admin\AppData\Local\Temp\nsx37D1.tmp\ns38BD.tmp" "C:\Users\admin\AppData\Local\Temp\FF.bat" > C:\Users\admin\AppData\Local\Temp\FF.txt | C:\Users\admin\AppData\Local\Temp\nsx37D1.tmp\ns38BD.tmp | — | Restoro.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1 Modules
| |||||||||||||||
| 1652 | "C:\Users\admin\AppData\Local\Temp\nsx37D1.tmp\ns3F3C.tmp" cmd /C tasklist /FI "IMAGENAME eq avupdate.exe" > C:\Users\admin\AppData\Local\Temp\IsProcessActive.txt | C:\Users\admin\AppData\Local\Temp\nsx37D1.tmp\ns3F3C.tmp | — | Restoro.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2848) Restoro.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (2848) Restoro.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyServer |
Value: | |||
| (PID) Process: | (2848) Restoro.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | ProxyOverride |
Value: | |||
| (PID) Process: | (2848) Restoro.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | AutoConfigURL |
Value: | |||
| (PID) Process: | (2848) Restoro.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | delete value | Name: | AutoDetect |
Value: | |||
| (PID) Process: | (2848) Restoro.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005C010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (2848) Restoro.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2848) Restoro.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2848) Restoro.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2848) Restoro.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2848 | Restoro.exe | C:\Users\admin\AppData\Local\Temp\nssFB88.tmp\System.dll | executable | |
MD5:BF712F32249029466FA86756F5546950 | SHA256:7851CB12FA4131F1FEE5DE390D650EF65CAC561279F1CFE70AD16CC9780210AF | |||
| 2848 | Restoro.exe | C:\Windows\restoro.ini | text | |
MD5:1C940039C154EE9A35DAC3A627A313D9 | SHA256:EFF0F4511EEF90A832E2C219E609B0D428AF8E12E7C1FEB065281DA0886A32F6 | |||
| 2848 | Restoro.exe | C:\Users\admin\AppData\Local\Temp\sqlite3.exe | executable | |
MD5:91CDCEA4BE94624E198D3012F5442584 | SHA256:CA4C0F1EC0CCBC9988EA3F43FF73FE84228FFB4D76BADDC386051DFFE7DDD8C2 | |||
| 2848 | Restoro.exe | C:\Users\admin\AppData\Local\Temp\nssFB88.tmp\UserInfo.dll | executable | |
MD5:C7CE0E47C83525983FD2C4C9566B4AAD | SHA256:6293408A5FA6D0F55F0A4D01528EB5B807EE9447A75A28B5986267475EBCD3AE | |||
| 2848 | Restoro.exe | C:\Users\admin\AppData\Local\Temp\nsnFC54.tmp | text | |
MD5:D843E45CE0B4070AC9A73177EAC866A4 | SHA256:3D95AB7F1C43E04A9181494AD60A569BFE4843EB90DEE314ED4BBE2E81A9D0D5 | |||
| 2848 | Restoro.exe | C:\Users\admin\AppData\Local\Temp\FF.bat | text | |
MD5:D843E45CE0B4070AC9A73177EAC866A4 | SHA256:3D95AB7F1C43E04A9181494AD60A569BFE4843EB90DEE314ED4BBE2E81A9D0D5 | |||
| 2420 | cmd.exe | C:\Users\admin\AppData\Local\Temp\IsProcessActive.txt | text | |
MD5:DEA052A2AD11945B1960577C0192F2EB | SHA256:943B315E065238B7073B033F534EF954B6B6461FB3F03A3F5B8555B11BC4C0A2 | |||
| 2848 | Restoro.exe | C:\Users\admin\AppData\Local\Temp\nssFB88.tmp\nsExec.dll | executable | |
MD5:132E6153717A7F9710DCEA4536F364CD | SHA256:D29AFCE2588D8DD7BB94C00CA91CAC0E85B80FFA6B221F5FFCB83A2497228EB2 | |||
| 2848 | Restoro.exe | C:\Users\admin\AppData\Local\Temp\nsoFCF3.tmp | text | |
MD5:B9A2323FDD9C157AB19E73DDB6C5E334 | SHA256:59E61CA9B1DBFB84C72DFF57EF401DFC5938891DCEF3A7A662AAE22E7F4B5F7B | |||
| 1656 | cmd.exe | C:\Users\admin\AppData\Local\Temp\IsProcessActive.txt | text | |
MD5:DEA052A2AD11945B1960577C0192F2EB | SHA256:943B315E065238B7073B033F534EF954B6B6461FB3F03A3F5B8555B11BC4C0A2 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2848 | Restoro.exe | GET | — | 104.22.60.250:80 | http://www.restoro.com/includes/install_start.php?m_trackid=&m_tracking=&m_campaign=&minorsessionid=eac35f91eaab48b59e830a838e&sessionid=ad11a0da-6758-4243-b96c-f5d11bd2f72f&t=CONSUMER&a=ENABLED&u=ENABLED&c=DISABLED&v=2028 | unknown | — | — | unknown |
2848 | Restoro.exe | GET | — | 104.22.60.250:80 | http://www.restoro.com/lib/version.php?type=downloader | unknown | — | — | unknown |
2848 | Restoro.exe | GET | — | 104.22.60.250:80 | http://www.restoro.com/lib/version.php?type=downloader | unknown | — | — | unknown |
2848 | Restoro.exe | GET | — | 104.22.60.250:80 | http://www.restoro.com/lib/evt.php?version=2028&SessionID=ad11a0da-6758-4243-b96c-f5d11bd2f72f&MinorSessionID=eac35f91eaab48b59e830a838e&id=INSST¶m=&trackutil= | unknown | — | — | unknown |
2848 | Restoro.exe | GET | 404 | 23.253.160.91:80 | http://org.restoro.com/lib/version.php?type=downloader | unknown | html | 1.22 Kb | unknown |
2848 | Restoro.exe | GET | — | 104.22.60.250:80 | http://www.restoro.com/lib/evt.php?version=2028&SessionID=ad11a0da-6758-4243-b96c-f5d11bd2f72f&MinorSessionID=eac35f91eaab48b59e830a838e&id=INPRC¶m=IMEDICTUPDATE*taskhost*taskeng*dwm*ctfmon*audiodg*msiexec*Restoro*&trackutil= | unknown | — | — | unknown |
2568 | Restoro.exe | GET | — | 104.22.60.250:80 | http://www.restoro.com/lib/version.php?type=downloader | unknown | — | — | unknown |
2848 | Restoro.exe | GET | — | 104.22.60.250:80 | http://www.restoro.com/lib/evt.php?version=2028&SessionID=ad11a0da-6758-4243-b96c-f5d11bd2f72f&MinorSessionID=eac35f91eaab48b59e830a838e&id=USERTYPE¶m=New&trackutil= | unknown | — | — | unknown |
2568 | Restoro.exe | GET | — | 104.22.60.250:80 | http://www.restoro.com/lib/version.php?type=downloader | unknown | — | — | unknown |
2848 | Restoro.exe | GET | — | 104.22.60.250:80 | http://www.restoro.com/lib/evt.php?version=2028&SessionID=ad11a0da-6758-4243-b96c-f5d11bd2f72f&MinorSessionID=eac35f91eaab48b59e830a838e&id=ININF¶m=OS=7<*>AV=<*>Firewall=<*>GooglePing=<*>nslookup=cloud.restoro.com<*>File=NotExitst<*>path=C:\Users\admin\AppData\Local\Temp\restoro-downloader.xml&trackutil= | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
2848 | Restoro.exe | 104.22.60.250:80 | www.restoro.com | CLOUDFLARENET | — | unknown |
2848 | Restoro.exe | 23.253.160.91:80 | org.restoro.com | RACKSPACE | US | unknown |
2568 | Restoro.exe | 104.22.60.250:80 | www.restoro.com | CLOUDFLARENET | — | unknown |
Domain | IP | Reputation |
|---|---|---|
www.restoro.com |
| malicious |
org.restoro.com |
| unknown |
www.google.com |
| whitelisted |
2.100.168.192.in-addr.arpa |
| unknown |
cloud.restoro.com |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
2848 | Restoro.exe | Potentially Bad Traffic | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) |
2848 | Restoro.exe | Potentially Bad Traffic | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) |
2848 | Restoro.exe | Potentially Bad Traffic | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) |
2848 | Restoro.exe | Potentially Bad Traffic | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) |
2848 | Restoro.exe | Potentially Bad Traffic | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) |
2848 | Restoro.exe | Possibly Unwanted Program Detected | ET ADWARE_PUP Win32/ReImageRepair.T CnC Checkin |
2848 | Restoro.exe | Potentially Bad Traffic | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) |
2848 | Restoro.exe | Possibly Unwanted Program Detected | ET ADWARE_PUP Win32/ReImageRepair.T CnC Checkin |
2848 | Restoro.exe | Potentially Bad Traffic | ET USER_AGENTS Observed Suspicious UA (NSIS_Inetc (Mozilla)) |
2848 | Restoro.exe | Possibly Unwanted Program Detected | ET ADWARE_PUP Win32/ReImageRepair.T CnC Checkin |