| File name: | cspy343.exe |
| Full analysis: | https://app.any.run/tasks/ce81c162-3857-47cb-a07a-2c2580773c4c |
| Verdict: | Malicious activity |
| Analysis date: | July 02, 2024, 14:55:15 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | F200BC324AE1C57EDE1476AEC22A9089 |
| SHA1: | 7E6E48325A7BDA96245010811E65D93C25D4A3AD |
| SHA256: | 6F1C39F521D7CCDC2C0CFB8A69D456C57B6094E95AFC9D9294D85F35EB116A45 |
| SSDEEP: | 98304:8b7O4WwEuG0ndnJXE3dV7uFKQulFadJ7mVKt9fh4ijLJW85ZO0+VP/upm7ge1xTk:IBJbqGrEG |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:12:15 22:24:32+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 25088 |
| InitializedDataSize: | 118784 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x3328 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.4.3.0 |
| ProductVersionNumber: | 3.4.3.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| Comments: | Duplicate file removal tool |
| CompanyName: | Marcus Kleinehagenbrock |
| FileDescription: | CloneSpy Installer |
| FileVersion: | 3.43 |
| InternalName: | CloneSpy |
| LegalCopyright: | © 2001 - 2019 Marcus Kleinehagenbrock |
| OriginalFileName: | cspy343.exe |
| ProductName: | CloneSpy |
| ProductVersion: | 3.43 |
| WWW: | http://www.clonespy.com |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 732 | "C:\Users\admin\AppData\Local\Temp\cspy343.exe" | C:\Users\admin\AppData\Local\Temp\cspy343.exe | explorer.exe | ||||||||||||
User: admin Company: Marcus Kleinehagenbrock Integrity Level: HIGH Description: CloneSpy Installer Exit code: 0 Version: 3.43 Modules
| |||||||||||||||
| 2440 | "C:\Users\admin\AppData\Local\Temp\cspy343.exe" | C:\Users\admin\AppData\Local\Temp\cspy343.exe | — | explorer.exe | |||||||||||
User: admin Company: Marcus Kleinehagenbrock Integrity Level: MEDIUM Description: CloneSpy Installer Exit code: 3221226540 Version: 3.43 Modules
| |||||||||||||||
| 4860 | "C:\Program Files\CloneSpy\CloneSpy64.exe" | C:\Program Files\CloneSpy\CloneSpy64.exe | explorer.exe | ||||||||||||
User: admin Company: Marcus Kleinehagenbrock Integrity Level: MEDIUM Description: CloneSpy Application Version: 3.43 Modules
| |||||||||||||||
| (PID) Process: | (732) cspy343.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\CloneSpy64.exe |
| Operation: | write | Name: | Path |
Value: C:\Program Files\CloneSpy | |||
| (PID) Process: | (732) cspy343.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CloneSpy |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files\CloneSpy\CloneSpy64.exe,0 | |||
| (PID) Process: | (732) cspy343.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CloneSpy |
| Operation: | write | Name: | DisplayName |
Value: CloneSpy 3.43 - 64 bit | |||
| (PID) Process: | (732) cspy343.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CloneSpy |
| Operation: | write | Name: | DisplayVersion |
Value: 3.43 | |||
| (PID) Process: | (732) cspy343.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CloneSpy |
| Operation: | write | Name: | EstimatedSize |
Value: 7520 | |||
| (PID) Process: | (732) cspy343.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CloneSpy |
| Operation: | write | Name: | HelpLink |
Value: http://www.clonespy.com | |||
| (PID) Process: | (732) cspy343.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CloneSpy |
| Operation: | write | Name: | InstallLocation |
Value: {C:\Program Files\CloneSpy} | |||
| (PID) Process: | (732) cspy343.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CloneSpy |
| Operation: | write | Name: | NoModify |
Value: 1 | |||
| (PID) Process: | (732) cspy343.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CloneSpy |
| Operation: | write | Name: | NoRepair |
Value: 1 | |||
| (PID) Process: | (732) cspy343.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CloneSpy |
| Operation: | write | Name: | Publisher |
Value: The CloneSpy Team | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 732 | cspy343.exe | C:\Users\admin\AppData\Local\Temp\nsuE06F.tmp | — | |
MD5:— | SHA256:— | |||
| 732 | cspy343.exe | C:\Users\admin\AppData\Local\Temp\nsuE070.tmp\nsDialogs.dll | executable | |
MD5:AB101F38562C8545A641E95172C354B4 | SHA256:3CDF3E24C87666ED5C582B8B028C01EE6AC16D5A9B8D8D684AE67605376786EA | |||
| 732 | cspy343.exe | C:\Users\admin\AppData\Local\Temp\nsuE070.tmp\modern-wizard.bmp | image | |
MD5:6EE89C3A81F6498BF40EBCD6CBB709BF | SHA256:BB7B5FE94607E65DD6E5E066051288E4CD7B87CDB52FA25BE69BEC4990F549BE | |||
| 732 | cspy343.exe | C:\Program Files\CloneSpy\Readme.txt | binary | |
MD5:395E46F2C8DD56F3F96AA0396FF06E90 | SHA256:641F3B8150BD162D7E67325187EDD8F5B46168169335C411AE8AAE10A8C32171 | |||
| 732 | cspy343.exe | C:\Users\admin\Desktop\CloneSpy.lnk | binary | |
MD5:AEB1E6559E657CC031165D45EBEA3298 | SHA256:EB16976A0BFE41E68E08577DC538D92E174609CB2702F03EEA61B5724812BDB9 | |||
| 732 | cspy343.exe | C:\Program Files\CloneSpy\CloneSpy64.exe | executable | |
MD5:D05BB94F0F09A0A90CC0F9E40D87E97F | SHA256:CA30738F63F1FAA851DEB020A39689678A8DC9497366DA95FB469715C5CE7E0C | |||
| 732 | cspy343.exe | C:\Users\admin\AppData\Local\Temp\nsr2598.tmp | text | |
MD5:9904D3F19A1668FD7536A3043681EEEE | SHA256:8E731CAB878B4CEA6D4AAF9F1432B52595A812C3FF52DF2C153D04189F2A5C63 | |||
| 732 | cspy343.exe | C:\Users\admin\AppData\Local\Temp\nsuE070.tmp\UserInfo.dll | executable | |
MD5:7836F464AE0102452E94A363B491B759 | SHA256:11ADF8916947B5A20A071B494FA034CF62769DCC6293A1340B29A5BB29AC8E87 | |||
| 732 | cspy343.exe | C:\Users\admin\AppData\Local\Temp\nsuE070.tmp\modern-header.bmp | image | |
MD5:732BEDF95585DFC1023573F0FA4F6E60 | SHA256:670ABB7576D8A890A7D4B480FA2F26FABACD873E11DA23C5D4D55720E0791DC6 | |||
| 4860 | CloneSpy64.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\INetCache\IE\AH8CR9J5\update_eng[1].txt | text | |
MD5:0DFA72D585AED76712A26EAB0B9852D2 | SHA256:32CEE3CB0A794DF3DCEBB281759DAD6F818C77A832FEC1771D27073BE39390CB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1544 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | unknown |
4656 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | unknown |
4656 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | unknown |
3040 | OfficeClickToRun.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | unknown |
3624 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | unknown |
5968 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | unknown |
4276 | SIHClient.exe | GET | 200 | 23.52.120.96:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | unknown |
4276 | SIHClient.exe | GET | 200 | 23.52.120.96:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | unknown |
4860 | CloneSpy64.exe | GET | 200 | 85.13.129.201:80 | http://www.clonespy.info/iupdate/update_eng.txt | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4032 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4656 | SearchApp.exe | 92.123.104.34:443 | www.bing.com | Akamai International B.V. | DE | unknown |
1544 | svchost.exe | 40.126.32.140:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | unknown |
1544 | svchost.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
4656 | SearchApp.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
4656 | SearchApp.exe | 13.107.21.200:443 | r.bing.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
1060 | svchost.exe | 23.35.238.131:443 | go.microsoft.com | AKAMAI-AS | DE | unknown |
3040 | OfficeClickToRun.exe | 20.189.173.26:443 | self.events.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
3040 | OfficeClickToRun.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.bing.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
r.bing.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
fd.api.iris.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
— | — | Not Suspicious Traffic | INFO [ANY.RUN] Request to Azure content delivery network (aadcdn .msftauth .net) |
Process | Message |
|---|---|
cspy343.exe | ExecShellAsUser: DLL_PROCESS_ATTACH |
cspy343.exe | ExecShellAsUser: got desktop |
cspy343.exe | ExecShellAsUser: elevated process detected |
cspy343.exe | ExecShellAsUser: NSPIM_UNLOAD wait... |
cspy343.exe | ExecShellAsUser: thread finished |
cspy343.exe | ExecShellAsUser: NSPIM_UNLOAD |
cspy343.exe | ExecShellAsUser: DLL_PROCESS_DETACH |