File name: | cpu-z_1.97-en.exe |
Full analysis: | https://app.any.run/tasks/02c7f322-8d25-4b18-8b57-912e6582654e |
Verdict: | Malicious activity |
Analysis date: | December 06, 2022, 06:15:52 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 9E3CE08750B875EAC894F245B0271FDC |
SHA1: | C29E78099CDF3A3A8C2E23FE75F38BBABC631D92 |
SHA256: | 825A5E768DF385AD651B16256755A63D91FB710E46296D3B0D05E9DF7EEEDAFF |
SSDEEP: | 49152:wy+Sh4r+VNPvJ3x19XX3QZcBJwHjniXZsILcKvQ1aB:B+Sh4revJB/XX3QZkqDiXWXKI1a |
.exe | | | Inno Setup installer (77.7) |
---|---|---|
.exe | | | Win32 Executable Delphi generic (10) |
.dll | | | Win32 Dynamic Link Library (generic) (4.6) |
.exe | | | Win32 Executable (generic) (3.1) |
.exe | | | Win16/32 Executable Delphi generic (1.4) |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 1992-Jun-19 22:22:17 |
Detected languages: |
|
Comments: | This installation was built with Inno Setup. |
CompanyName: | CPUID, Inc. |
FileDescription: | CPUID CPU-Z Setup |
FileVersion: | - |
LegalCopyright: | - |
ProductName: | CPUID CPU-Z |
ProductVersion: | 1.97 |
e_magic: | MZ |
---|---|
e_cblp: | 80 |
e_cp: | 2 |
e_crlc: | - |
e_cparhdr: | 4 |
e_minalloc: | 15 |
e_maxalloc: | 65535 |
e_ss: | - |
e_sp: | 184 |
e_csum: | - |
e_ip: | - |
e_cs: | - |
e_ovno: | 26 |
e_oemid: | - |
e_oeminfo: | - |
e_lfanew: | 256 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
NumberofSections: | 8 |
TimeDateStamp: | 1992-Jun-19 22:22:17 |
PointerToSymbolTable: | - |
NumberOfSymbols: | - |
SizeOfOptionalHeader: | 224 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
CODE | 4096 | 41480 | 41984 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.60167 |
DATA | 49152 | 592 | 1024 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.77135 |
BSS | 53248 | 3732 | 0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | |
.idata | 57344 | 2428 | 2560 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.48608 |
.tls | 61440 | 8 | 0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | |
.rdata | 65536 | 24 | 512 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED | 0.190489 |
.reloc | 69632 | 2336 | 0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED | |
.rsrc | 73728 | 11264 | 11264 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED | 4.58902 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 3.25755 | 296 | UNKNOWN | Dutch - Netherlands | RT_ICON |
2 | 3.47151 | 1384 | UNKNOWN | Dutch - Netherlands | RT_ICON |
3 | 3.91708 | 744 | UNKNOWN | Dutch - Netherlands | RT_ICON |
4 | 3.91366 | 2216 | UNKNOWN | Dutch - Netherlands | RT_ICON |
4089 | 3.21823 | 754 | UNKNOWN | UNKNOWN | RT_STRING |
4090 | 3.31515 | 780 | UNKNOWN | UNKNOWN | RT_STRING |
4091 | 3.25024 | 718 | UNKNOWN | UNKNOWN | RT_STRING |
4093 | 2.86149 | 104 | UNKNOWN | UNKNOWN | RT_STRING |
4094 | 3.20731 | 180 | UNKNOWN | UNKNOWN | RT_STRING |
4095 | 3.04592 | 174 | UNKNOWN | UNKNOWN | RT_STRING |
advapi32.dll |
advapi32.dll (#2) |
comctl32.dll |
kernel32.dll |
kernel32.dll (#2) |
oleaut32.dll |
user32.dll |
user32.dll (#2) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1328 | "C:\Users\admin\AppData\Local\Temp\cpu-z_1.97-en.exe" | C:\Users\admin\AppData\Local\Temp\cpu-z_1.97-en.exe | — | Explorer.EXE | |||||||||||
User: admin Company: CPUID, Inc. Integrity Level: MEDIUM Description: CPUID CPU-Z Setup Version: Modules
| |||||||||||||||
2284 | "C:\Users\admin\AppData\Local\Temp\is-O805F.tmp\cpu-z_1.97-en.tmp" /SL5="$50198,1823662,58368,C:\Users\admin\AppData\Local\Temp\cpu-z_1.97-en.exe" | C:\Users\admin\AppData\Local\Temp\is-O805F.tmp\cpu-z_1.97-en.tmp | — | cpu-z_1.97-en.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Version: 51.52.0.0 Modules
| |||||||||||||||
3304 | "C:\Users\admin\AppData\Local\Temp\cpu-z_1.97-en.exe" /SPAWNWND=$601B0 /NOTIFYWND=$50198 | C:\Users\admin\AppData\Local\Temp\cpu-z_1.97-en.exe | cpu-z_1.97-en.tmp | ||||||||||||
User: admin Company: CPUID, Inc. Integrity Level: HIGH Description: CPUID CPU-Z Setup Version: Modules
| |||||||||||||||
3460 | "C:\Users\admin\AppData\Local\Temp\is-8FTHL.tmp\cpu-z_1.97-en.tmp" /SL5="$601C8,1823662,58368,C:\Users\admin\AppData\Local\Temp\cpu-z_1.97-en.exe" /SPAWNWND=$601B0 /NOTIFYWND=$50198 | C:\Users\admin\AppData\Local\Temp\is-8FTHL.tmp\cpu-z_1.97-en.tmp | cpu-z_1.97-en.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Version: 51.52.0.0 Modules
| |||||||||||||||
2800 | "C:\Program Files\CPUID\CPU-Z\cpuz.exe" | C:\Program Files\CPUID\CPU-Z\cpuz.exe | — | Explorer.EXE | |||||||||||
User: admin Company: CPUID Integrity Level: MEDIUM Description: CPU-Z Application Exit code: 3221226540 Version: 1, 9, 7, 0 Modules
| |||||||||||||||
3228 | "C:\Program Files\CPUID\CPU-Z\cpuz.exe" | C:\Program Files\CPUID\CPU-Z\cpuz.exe | Explorer.EXE | ||||||||||||
User: admin Company: CPUID Integrity Level: HIGH Description: CPU-Z Application Exit code: 0 Version: 1, 9, 7, 0 Modules
|
(PID) Process: | (3460) cpu-z_1.97-en.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | Owner |
Value: 840D0000C0758A353A09D901 | |||
(PID) Process: | (3460) cpu-z_1.97-en.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | SessionHash |
Value: C8F0F279122FD28834184E6F4F328AADE2ED33CB8EF7BE12E8035A2F35FFC809 | |||
(PID) Process: | (3460) cpu-z_1.97-en.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | Sequence |
Value: 1 | |||
(PID) Process: | (3460) cpu-z_1.97-en.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | RegFiles0000 |
Value: C:\Program Files\CPUID\CPU-Z\cpuz.exe | |||
(PID) Process: | (3460) cpu-z_1.97-en.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | RegFilesHash |
Value: ADABDCACF587EC8F9CFA671D13F200AA30A67735DB241B9CC97715CF9C375422 | |||
(PID) Process: | (3460) cpu-z_1.97-en.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CPUID\CPU-Z |
Operation: | write | Name: | PATH |
Value: C:\Program Files\CPUID\CPU-Z | |||
(PID) Process: | (3460) cpu-z_1.97-en.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CPUID\CPU-Z |
Operation: | write | Name: | PRODUCT_NAME |
Value: CPUID CPU-Z | |||
(PID) Process: | (3460) cpu-z_1.97-en.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CPUID\CPU-Z |
Operation: | write | Name: | VERSION |
Value: 1.97 | |||
(PID) Process: | (3460) cpu-z_1.97-en.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CPUID CPU-Z_is1 |
Operation: | write | Name: | Inno Setup: Setup Version |
Value: 5.6.1 (a) | |||
(PID) Process: | (3460) cpu-z_1.97-en.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CPUID CPU-Z_is1 |
Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files\CPUID\CPU-Z |
PID | Process | Filename | Type | |
---|---|---|---|---|
3460 | cpu-z_1.97-en.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\CPU-Z\Uninstall CPU-Z.lnk | lnk | |
MD5:C7160BD723789F8BE7D7084B63068E67 | SHA256:1DB7E20991458B6DD4DC07D0EB70E6ADCC3142CBC15B43BA8BBE4A05B673CE7D | |||
3460 | cpu-z_1.97-en.tmp | C:\Program Files\CPUID\CPU-Z\unins000.dat | dat | |
MD5:9A5C3D63CAA25066B12FABEF42C66863 | SHA256:88716F099AA7AD7AC53F4EFA8EBAFBCA086B2C5CD9C05F20E12E12F4C0F6B56C | |||
3228 | cpuz.exe | C:\Windows\temp\cpuz152\cpuz152_x32.sys | executable | |
MD5:7ABF3D484905A6335F79A306FD138A24 | SHA256:86C07833EC88C93F01689103390032335B95C52E0E9B4994A63014A72428DBF5 | |||
3460 | cpu-z_1.97-en.tmp | C:\Program Files\CPUID\CPU-Z\is-HMFU8.tmp | text | |
MD5:99694811A33139D2C4B89CF033A01A5F | SHA256:0B15131AF3B8D32450A3774CFC06F9797B9435D921EACBD33D8B1F8BD43EB401 | |||
3460 | cpu-z_1.97-en.tmp | C:\Program Files\CPUID\CPU-Z\is-UKDDF.tmp | text | |
MD5:15130D155F7DDAFB034A62077B051F16 | SHA256:3E0364795D926935AB038CD9197AD10AFFB55983198858C6BF70B4D01F7F5529 | |||
3460 | cpu-z_1.97-en.tmp | C:\Program Files\CPUID\CPU-Z\cpuz_readme.txt | text | |
MD5:99694811A33139D2C4B89CF033A01A5F | SHA256:0B15131AF3B8D32450A3774CFC06F9797B9435D921EACBD33D8B1F8BD43EB401 | |||
3460 | cpu-z_1.97-en.tmp | C:\Program Files\CPUID\CPU-Z\cpuz.ini | text | |
MD5:15130D155F7DDAFB034A62077B051F16 | SHA256:3E0364795D926935AB038CD9197AD10AFFB55983198858C6BF70B4D01F7F5529 | |||
3460 | cpu-z_1.97-en.tmp | C:\Program Files\CPUID\CPU-Z\unins000.exe | executable | |
MD5:D1C46C8FC337C9C4CBAB797137939D53 | SHA256:798EECEBB059F2C27383816BE38A2E8EE9A2F05EABD2028FB8D7BCDA58CAA597 | |||
3460 | cpu-z_1.97-en.tmp | C:\Program Files\CPUID\CPU-Z\is-5KN8A.tmp | executable | |
MD5:D1C46C8FC337C9C4CBAB797137939D53 | SHA256:798EECEBB059F2C27383816BE38A2E8EE9A2F05EABD2028FB8D7BCDA58CAA597 | |||
3460 | cpu-z_1.97-en.tmp | C:\Program Files\CPUID\CPU-Z\cpuz.exe | executable | |
MD5:FDE5901182C8ACB96CF1F5DB75239E36 | SHA256:C266AFF3BB636A13F287DD4E00F81CA4DDDB562C0AE83E849F1C8FEE4C5DAF9F |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3228 | cpuz.exe | GET | 200 | 2.16.202.121:80 | http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgMx09HkWS07es1rXypVKP5qnA%3D%3D | NL | der | 503 b | shared |
3228 | cpuz.exe | GET | 200 | 8.238.28.126:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?da17bc9153a68836 | US | compressed | 4.70 Kb | whitelisted |
3228 | cpuz.exe | GET | 200 | 184.24.9.54:80 | http://x1.c.lencr.org/ | DE | der | 717 b | whitelisted |
3228 | cpuz.exe | GET | 200 | 8.238.28.126:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?941522294cdd5116 | US | compressed | 61.4 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3228 | cpuz.exe | 2.16.202.121:80 | r3.o.lencr.org | Akamai International B.V. | NL | suspicious |
3228 | cpuz.exe | 8.238.28.126:80 | ctldl.windowsupdate.com | LEVEL3 | US | suspicious |
3228 | cpuz.exe | 195.154.81.43:443 | download.cpuid.com | Online S.a.s. | FR | suspicious |
3228 | cpuz.exe | 184.24.9.54:80 | x1.c.lencr.org | AKAMAI-AS | DE | unknown |
Domain | IP | Reputation |
---|---|---|
download.cpuid.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
r3.o.lencr.org |
| shared |