| download: | AnthemScore_installer_windows_x86_64.exe |
| Full analysis: | https://app.any.run/tasks/d60b78df-d400-4f02-bebc-543183ba51ab |
| Verdict: | Malicious activity |
| Analysis date: | June 26, 2020, 18:55:30 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | C9A39B56F76A5636899F5E40BA3E51BD |
| SHA1: | BAD8E98FDAF43CAA8DA820C002592D4F941AB465 |
| SHA256: | 5EEED86AE9B9F7387A97478657249E451D0D92714CA1E5B3DBA67CCAACBFFE67 |
| SSDEEP: | 393216:jpDr3vEQbtxwcTOdpthhhR9v7bjCJsv6tWKFdu9CvaZG:tDLvEQbtxwjhhhHjaaZ |
| .exe | | | Win32 EXE PECompact compressed (generic) (83) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (9) |
| .exe | | | Generic Win/DOS Executable (3.9) |
| .exe | | | DOS Executable Generic (3.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:12:13 12:07:29+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 14888448 |
| InitializedDataSize: | 6649344 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xd945a4 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.2.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| FileVersion: |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2228 | "C:\Users\admin\AppData\Local\Temp\AnthemScore_installer_windows_x86_64.exe" | C:\Users\admin\AppData\Local\Temp\AnthemScore_installer_windows_x86_64.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2228) AnthemScore_installer_windows_x86_64.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Direct3D\MostRecentApplication |
| Operation: | write | Name: | Name |
Value: AnthemScore_installer_windows_x86_64.exe | |||
| (PID) Process: | (2228) AnthemScore_installer_windows_x86_64.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\12F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2228 | AnthemScore_installer_windows_x86_64.exe | C:\Users\admin\AppData\Local\Temp\AnthemScore_installer_windows_x86_64.SueXaj | — | |
MD5:— | SHA256:— | |||
| 2228 | AnthemScore_installer_windows_x86_64.exe | C:\Users\admin\AppData\Local\Temp\remoterepo-qiydmV\lunaverus.anthemscore.windows_x86_64-4.9.0-meta.7z | compressed | |
MD5:— | SHA256:— | |||
| 2228 | AnthemScore_installer_windows_x86_64.exe | C:\Users\admin\AppData\Local\Temp\remoterepo-qiydmV\lunaverus.anthemscore.windows_x86_64\launch_when_done.ui | xml | |
MD5:— | SHA256:— | |||
| 2228 | AnthemScore_installer_windows_x86_64.exe | C:\Users\admin\AppData\Local\Temp\remoterepo-qiydmV\Updates.xml | html | |
MD5:— | SHA256:— | |||
| 2228 | AnthemScore_installer_windows_x86_64.exe | C:\Users\admin\AppData\Local\Temp\remoterepo-qiydmV\lunaverus.anthemscore.windows_x86_64\license.txt | text | |
MD5:— | SHA256:— | |||
| 2228 | AnthemScore_installer_windows_x86_64.exe | C:\Users\admin\AppData\Local\Temp\remoterepo-qiydmV\lunaverus.anthemscore.windows_x86_64\installscript.qs | text | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2228 | AnthemScore_installer_windows_x86_64.exe | GET | 301 | 167.99.105.254:80 | http://www.lunaverus.com/static/AnthemScore_repository_windows_x86_64/lunaverus.anthemscore.windows_x86_64/4.9.0meta.7z | US | — | — | suspicious |
2228 | AnthemScore_installer_windows_x86_64.exe | GET | 301 | 167.99.105.254:80 | http://www.lunaverus.com/static/AnthemScore_repository_windows_x86_64/Updates.xml?43210436 | US | — | — | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2228 | AnthemScore_installer_windows_x86_64.exe | 167.99.105.254:80 | www.lunaverus.com | — | US | suspicious |
2228 | AnthemScore_installer_windows_x86_64.exe | 167.99.105.254:443 | www.lunaverus.com | — | US | suspicious |
2228 | AnthemScore_installer_windows_x86_64.exe | 205.185.216.10:443 | static.lunaverus.com | Highwinds Network Group, Inc. | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.lunaverus.com |
| suspicious |
static.lunaverus.com |
| malicious |