| File name: | festo fluidsim 4.2 pneumatics_eng.exe |
| Full analysis: | https://app.any.run/tasks/0b5bee52-5957-430f-aab7-50500494da1a |
| Verdict: | Malicious activity |
| Analysis date: | March 04, 2024, 09:05:33 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 4C0135CA286E77BAA3936C171DA17380 |
| SHA1: | 2CCD3899E788933DB6522B9127F7B9094F6A61E1 |
| SHA256: | 6459BB7630E62F33A1CC8068659CBF1BB4C63369415C9F0C444FDA5D02155879 |
| SSDEEP: | 98304:hfJBbod1Yc9hQo+Ra43hqAAOy09gX5BM7sPte7B6Z6n+HJ7CrfKpYSMpfBhgtVT8:/Z9Jgf42KCjTcIlbQqxngb7yCp |
| .exe | | | Inno Setup installer (77.7) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (10) |
| .dll | | | Win32 Dynamic Link Library (generic) (4.6) |
| .exe | | | Win32 Executable (generic) (3.1) |
| .exe | | | Win16/32 Executable Delphi generic (1.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:19 22:22:17+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 37888 |
| InitializedDataSize: | 17920 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x9c40 |
| OSVersion: | 1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | FESTO, Inc. |
| FileDescription: | FluidSIM Pneumatics V 4.2 English Setup |
| FileVersion: | |
| LegalCopyright: | |
| ProductName: | FluidSIM Pneumatics V 4.2 English |
| ProductVersion: | 4.2 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | "C:\Program Files\Didactic\fl_sim_p4.en\bin\fl_sim_p.exe" | C:\Program Files\Didactic\fl_sim_p4.en\bin\fl_sim_p.exe | — | festo fluidsim 4.2 pneumatics_eng.tmp | |||||||||||
User: admin Company: Art Systems Software GmbH, Festo Didactic GmbH & Co. KG Integrity Level: MEDIUM Description: FluidSIM - Fluidics Simulation Program Exit code: 0 Version: 4, 2, 16, 0 Modules
| |||||||||||||||
| 240 | "C:\Users\admin\Desktop\Festo FluidSim Hid-Neu 2020 V3.5.exe" | C:\Users\admin\Desktop\Festo FluidSim Hid-Neu 2020 V3.5.exe | explorer.exe | ||||||||||||
User: admin Company: DinproSolution Integrity Level: MEDIUM Description: www.dinprosolution.com Exit code: 0 Version: 1.1.0.1 Modules
| |||||||||||||||
| 880 | "C:\Users\admin\AppData\Local\Temp\ir_ext_temp_2\autorun.exe" "SFXSOURCE:C:\Users\admin\Desktop\Festo FluidSim Hid-Neu 2020 V3.5.exe" | C:\Users\admin\AppData\Local\Temp\ir_ext_temp_2\autorun.exe | — | Festo FluidSim Hid-Neu 2020 V3.5.exe | |||||||||||
User: admin Company: DinproSolution Integrity Level: MEDIUM Description: www.dinprosolution.com Exit code: 0 Version: 1.1.0.1 Modules
| |||||||||||||||
| 1540 | "C:\Users\admin\AppData\Local\Temp\RarSFX0\Festo Fluidsim.exe" | C:\Users\admin\AppData\Local\Temp\RarSFX0\Festo Fluidsim.exe | — | FESTO NEUMATICA.exe | |||||||||||
User: admin Company: Art Systems Software GmbH, Festo Didactic GmbH & Co. KG Integrity Level: MEDIUM Description: FluidSIM - Fluidics Simulation Program Exit code: 0 Version: 3, 6, 8, 0 Modules
| |||||||||||||||
| 1792 | "C:\Users\admin\AppData\Local\Temp\ir_ext_temp_2\AutoPlay\Docs\FESTO NEUMATICA.exe" | C:\Users\admin\AppData\Local\Temp\ir_ext_temp_2\AutoPlay\Docs\FESTO NEUMATICA.exe | — | autorun.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 1992 | "C:\Users\admin\Desktop\Festo FluidSim Hid-Neu 2020 V3.5.exe" | C:\Users\admin\Desktop\Festo FluidSim Hid-Neu 2020 V3.5.exe | explorer.exe | ||||||||||||
User: admin Company: DinproSolution Integrity Level: MEDIUM Description: www.dinprosolution.com Exit code: 0 Version: 1.1.0.1 Modules
| |||||||||||||||
| 2504 | "C:\Users\admin\AppData\Local\Temp\ir_ext_temp_1\autorun.exe" "SFXSOURCE:C:\Users\admin\Desktop\Festo FluidSim Hid-Neu 2020 V3.5.exe" | C:\Users\admin\AppData\Local\Temp\ir_ext_temp_1\autorun.exe | — | Festo FluidSim Hid-Neu 2020 V3.5.exe | |||||||||||
User: admin Company: DinproSolution Integrity Level: MEDIUM Description: www.dinprosolution.com Exit code: 0 Version: 1.1.0.1 Modules
| |||||||||||||||
| 2620 | "C:\Users\admin\AppData\Local\Temp\ir_ext_temp_2\AutoPlay\Docs\FESTO NEUMATICA.exe" | C:\Users\admin\AppData\Local\Temp\ir_ext_temp_2\AutoPlay\Docs\FESTO NEUMATICA.exe | — | autorun.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2660 | "C:\Users\admin\AppData\Local\Temp\RarSFX0\Festo Fluidsim.exe" | C:\Users\admin\AppData\Local\Temp\RarSFX0\Festo Fluidsim.exe | — | FESTO NEUMATICA.exe | |||||||||||
User: admin Company: Art Systems Software GmbH, Festo Didactic GmbH & Co. KG Integrity Level: MEDIUM Description: FluidSIM - Fluidics Simulation Program Exit code: 0 Version: 3, 6, 8, 0 Modules
| |||||||||||||||
| 2752 | "C:\Users\admin\AppData\Local\Temp\is-SK6UF.tmp\festo fluidsim 4.2 pneumatics_eng.tmp" /SL5="$19013E,14855402,54272,C:\Users\admin\AppData\Local\Temp\festo fluidsim 4.2 pneumatics_eng.exe" /SPAWNWND=$1A01BC /NOTIFYWND=$E0170 | C:\Users\admin\AppData\Local\Temp\is-SK6UF.tmp\festo fluidsim 4.2 pneumatics_eng.tmp | — | festo fluidsim 4.2 pneumatics_eng.exe | |||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| (PID) Process: | (2752) festo fluidsim 4.2 pneumatics_eng.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{fluidp42-engE-4D49-A917-2952BA1249D3}_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 5.4.3 (a) | |||
| (PID) Process: | (2752) festo fluidsim 4.2 pneumatics_eng.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{fluidp42-engE-4D49-A917-2952BA1249D3}_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files\Didactic\fl_sim_p4.en | |||
| (PID) Process: | (2752) festo fluidsim 4.2 pneumatics_eng.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{fluidp42-engE-4D49-A917-2952BA1249D3}_is1 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\Didactic\fl_sim_p4.en\ | |||
| (PID) Process: | (2752) festo fluidsim 4.2 pneumatics_eng.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{fluidp42-engE-4D49-A917-2952BA1249D3}_is1 |
| Operation: | write | Name: | Inno Setup: Icon Group |
Value: Festo Didactic | |||
| (PID) Process: | (2752) festo fluidsim 4.2 pneumatics_eng.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{fluidp42-engE-4D49-A917-2952BA1249D3}_is1 |
| Operation: | write | Name: | Inno Setup: User |
Value: admin | |||
| (PID) Process: | (2752) festo fluidsim 4.2 pneumatics_eng.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{fluidp42-engE-4D49-A917-2952BA1249D3}_is1 |
| Operation: | write | Name: | Inno Setup: Selected Tasks |
Value: | |||
| (PID) Process: | (2752) festo fluidsim 4.2 pneumatics_eng.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{fluidp42-engE-4D49-A917-2952BA1249D3}_is1 |
| Operation: | write | Name: | Inno Setup: Deselected Tasks |
Value: desktopicon | |||
| (PID) Process: | (2752) festo fluidsim 4.2 pneumatics_eng.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{fluidp42-engE-4D49-A917-2952BA1249D3}_is1 |
| Operation: | write | Name: | Inno Setup: Language |
Value: english | |||
| (PID) Process: | (2752) festo fluidsim 4.2 pneumatics_eng.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{fluidp42-engE-4D49-A917-2952BA1249D3}_is1 |
| Operation: | write | Name: | DisplayName |
Value: FluidSIM Pneumatics V 4.2 English version 4.2 | |||
| (PID) Process: | (2752) festo fluidsim 4.2 pneumatics_eng.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{fluidp42-engE-4D49-A917-2952BA1249D3}_is1 |
| Operation: | write | Name: | UninstallString |
Value: "C:\Program Files\Didactic\fl_sim_p4.en\unins000.exe" | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3864 | festo fluidsim 4.2 pneumatics_eng.exe | C:\Users\admin\AppData\Local\Temp\is-K0648.tmp\festo fluidsim 4.2 pneumatics_eng.tmp | — | |
MD5:67C5A4F36E1C91A3B85E440EDD7AD026 | SHA256:99C299D6565AB53D9AF66E0146737DC0ECFBC52ECF4740825B552DB0CC4210C6 | |||
| 2964 | festo fluidsim 4.2 pneumatics_eng.exe | C:\Users\admin\AppData\Local\Temp\is-SK6UF.tmp\festo fluidsim 4.2 pneumatics_eng.tmp | — | |
MD5:67C5A4F36E1C91A3B85E440EDD7AD026 | SHA256:99C299D6565AB53D9AF66E0146737DC0ECFBC52ECF4740825B552DB0CC4210C6 | |||
| 2752 | festo fluidsim 4.2 pneumatics_eng.tmp | C:\Users\admin\AppData\Local\Temp\is-Q0ITR.tmp\_isetup\_shfoldr.dll | — | |
MD5:92DC6EF532FBB4A5C3201469A5B5EB63 | SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87 | |||
| 2752 | festo fluidsim 4.2 pneumatics_eng.tmp | C:\Program Files\Didactic\fl_sim_p4.en\aq\mop.kb | — | |
MD5:A553655125FB4306420D5F8377610C92 | SHA256:64E34942CBCF9B309F4FC49429B4609AE5E188F27630F70DCAF58E561723B461 | |||
| 2752 | festo fluidsim 4.2 pneumatics_eng.tmp | C:\Program Files\Didactic\fl_sim_p4.en\is-2T9HR.tmp | — | |
MD5:20271C729EEA661DD16D0FFF9E47E329 | SHA256:37B3AADE153966813F3FA4B4267914539D4FD04421CEFA849A390EE8C3DEFB0D | |||
| 2752 | festo fluidsim 4.2 pneumatics_eng.tmp | C:\Program Files\Didactic\fl_sim_p4.en\bin\AdMoSim.dll | — | |
MD5:CC1311799208D73737C1690530A8AB14 | SHA256:3FF2E6A93980BCDA8B429A8C5FC29CA106226C3B053B7EC0083FF7A3BB6E263D | |||
| 2752 | festo fluidsim 4.2 pneumatics_eng.tmp | C:\Program Files\Didactic\fl_sim_p4.en\unins000.exe | — | |
MD5:20271C729EEA661DD16D0FFF9E47E329 | SHA256:37B3AADE153966813F3FA4B4267914539D4FD04421CEFA849A390EE8C3DEFB0D | |||
| 2752 | festo fluidsim 4.2 pneumatics_eng.tmp | C:\Program Files\Didactic\fl_sim_p4.en\fl_sim_p.exe | — | |
MD5:982ED2FE3CE92959EC9C1124EC8ECD8F | SHA256:7A7212C6A4146D06A1764810BE53EC97E1D01F644EB3BCCD21382FC9EF44B887 | |||
| 2752 | festo fluidsim 4.2 pneumatics_eng.tmp | C:\Program Files\Didactic\fl_sim_p4.en\aq\is-ARVO8.tmp | — | |
MD5:451F0F3221A39D096614C2C6E8AB0928 | SHA256:8F31426003F743296E3B5FDC92E7DE584A0E01218F035CBAD551C3C926FFC988 | |||
| 2752 | festo fluidsim 4.2 pneumatics_eng.tmp | C:\Program Files\Didactic\fl_sim_p4.en\aq\is-HC2H0.tmp | — | |
MD5:A553655125FB4306420D5F8377610C92 | SHA256:64E34942CBCF9B309F4FC49429B4609AE5E188F27630F70DCAF58E561723B461 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |