| File name: | Dipiscan.exe |
| Full analysis: | https://app.any.run/tasks/4bcf9069-7eb0-4ede-be51-d23edc7e8adc |
| Verdict: | Malicious activity |
| Analysis date: | January 10, 2024, 14:21:08 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| MD5: | 8C2E81D0A7E6700B2081CF2C7B54EA89 |
| SHA1: | D49832631CC5A19751FCBA31187EBDBFD3C0CDD3 |
| SHA256: | 7ABCC9C1EBD859826177EA2A67802FE81466622BA44FB92674B27D9393A7FC77 |
| SSDEEP: | 24576:p4PFNlBf/bE8Gef2sXpubpuFw6LfSASpIRQbxp:p4PF7Bf/bE8GA2sXpubpuFw6LfSASpIw |
| .exe | | | Win32 Executable MS Visual C++ (generic) (41) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (36.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.6) |
| .exe | | | Win32 Executable (generic) (5.9) |
| .exe | | | Win16/32 Executable Delphi generic (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2017:10:01 11:54:42+02:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 48 |
| CodeSize: | 387584 |
| InitializedDataSize: | 437760 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xd200a |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.1.6483.21441 |
| ProductVersionNumber: | 2.1.6483.21441 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | - |
| CompanyName: | Dipisoft (www.dipisoft.com) |
| FileDescription: | Dipiscan |
| FileVersion: | 2.1.6483.21441 |
| InternalName: | Dipiscan.exe |
| LegalCopyright: | noCopyright © 2017, Dipisoft (www.dipisoft.com) |
| LegalTrademarks: | par Damien PONNELLE |
| OriginalFileName: | Dipiscan.exe |
| ProductName: | Dipiscan |
| ProductVersion: | 2.1.6483.21441 |
| AssemblyVersion: | 2.1.6483.21441 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 128 | "C:\Users\admin\AppData\Local\Temp\Dipiscan.exe" | C:\Users\admin\AppData\Local\Temp\Dipiscan.exe | explorer.exe | ||||||||||||
User: admin Company: Dipisoft (www.dipisoft.com) Integrity Level: MEDIUM Description: Dipiscan Exit code: 0 Version: 2.1.6483.21441 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 128 | Dipiscan.exe | \Device\Mup:\192.168.100.48\PIPE\srvsvc | — | |
MD5:— | SHA256:— | |||
| 128 | Dipiscan.exe | C:\Users\admin\AppData\Local\Temp\Dipiscan.ini | text | |
MD5:04FC6F4DD182AF9DF1C0E35CA88B7BF1 | SHA256:A560D6CD1603C14DBB692BAD5070AEF3A14C44D55CA4E286C43D5C659218710B | |||
| 128 | Dipiscan.exe | C:\Users\admin\AppData\Local\Temp\oui.dat | text | |
MD5:0C3554D938E39AA5F59B2852E109E8E2 | SHA256:BE46DA494456A69A649B09CBF969D91A18BE064011900E4DE419D56E8462E4C1 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
128 | Dipiscan.exe | GET | — | 185.49.20.101:80 | http://www.dipisoft.com/file/oui.dat | unknown | — | — | unknown |
128 | Dipiscan.exe | GET | 200 | 185.49.20.101:80 | http://www.dipisoft.com/file/oui.dat | unknown | text | 1.04 Mb | unknown |
128 | Dipiscan.exe | GET | — | 185.49.20.101:80 | http://www.dipisoft.com/file/oui.dat | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
128 | Dipiscan.exe | 185.49.20.101:80 | www.dipisoft.com | Ineonet SAS | FR | unknown |
128 | Dipiscan.exe | 192.168.100.2:139 | — | — | — | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.dipisoft.com |
| unknown |
Process | Message |
|---|---|
Dipiscan.exe | Un fabricant existe déjà sous la référence 0001C8
|
Dipiscan.exe | Un fabricant existe déjà sous la référence 080030
|
Dipiscan.exe | Un fabricant existe déjà sous la référence 080030
|
Dipiscan.exe | ---------- début analyse plage 1/10/2024 2:21:36 PM ----------
|
Dipiscan.exe | 192.168.100.1-constructor
|
Dipiscan.exe | 192.168.100.1-enqueue
|
Dipiscan.exe | 192.168.100.1-ping #1 (timeout 300)
|
Dipiscan.exe | 192.168.100.1-start thread analyseadresseip
|
Dipiscan.exe | 192.168.100.1-start ping
|
Dipiscan.exe | 192.168.100.2-start pingport (port 139)
|