download: | MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw |
Full analysis: | https://app.any.run/tasks/417f5b55-c573-4125-a1b7-2815af7cb566 |
Verdict: | Malicious activity |
Analysis date: | December 06, 2022, 06:18:14 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 9E3CE08750B875EAC894F245B0271FDC |
SHA1: | C29E78099CDF3A3A8C2E23FE75F38BBABC631D92 |
SHA256: | 825A5E768DF385AD651B16256755A63D91FB710E46296D3B0D05E9DF7EEEDAFF |
SSDEEP: | 49152:wy+Sh4r+VNPvJ3x19XX3QZcBJwHjniXZsILcKvQ1aB:B+Sh4revJB/XX3QZkqDiXWXKI1a |
.exe | | | Inno Setup installer (77.7) |
---|---|---|
.exe | | | Win32 Executable Delphi generic (10) |
.dll | | | Win32 Dynamic Link Library (generic) (4.6) |
.exe | | | Win32 Executable (generic) (3.1) |
.exe | | | Win16/32 Executable Delphi generic (1.4) |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 1992-Jun-19 22:22:17 |
Detected languages: |
|
Comments: | This installation was built with Inno Setup. |
CompanyName: | CPUID, Inc. |
FileDescription: | CPUID CPU-Z Setup |
FileVersion: | - |
LegalCopyright: | - |
ProductName: | CPUID CPU-Z |
ProductVersion: | 1.97 |
e_magic: | MZ |
---|---|
e_cblp: | 80 |
e_cp: | 2 |
e_crlc: | - |
e_cparhdr: | 4 |
e_minalloc: | 15 |
e_maxalloc: | 65535 |
e_ss: | - |
e_sp: | 184 |
e_csum: | - |
e_ip: | - |
e_cs: | - |
e_ovno: | 26 |
e_oemid: | - |
e_oeminfo: | - |
e_lfanew: | 256 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
NumberofSections: | 8 |
TimeDateStamp: | 1992-Jun-19 22:22:17 |
PointerToSymbolTable: | - |
NumberOfSymbols: | - |
SizeOfOptionalHeader: | 224 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
CODE | 4096 | 41480 | 41984 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.60167 |
DATA | 49152 | 592 | 1024 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.77135 |
BSS | 53248 | 3732 | 0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | |
.idata | 57344 | 2428 | 2560 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.48608 |
.tls | 61440 | 8 | 0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | |
.rdata | 65536 | 24 | 512 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED | 0.190489 |
.reloc | 69632 | 2336 | 0 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED | |
.rsrc | 73728 | 11264 | 11264 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED | 4.58902 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 3.25755 | 296 | UNKNOWN | Dutch - Netherlands | RT_ICON |
2 | 3.47151 | 1384 | UNKNOWN | Dutch - Netherlands | RT_ICON |
3 | 3.91708 | 744 | UNKNOWN | Dutch - Netherlands | RT_ICON |
4 | 3.91366 | 2216 | UNKNOWN | Dutch - Netherlands | RT_ICON |
4089 | 3.21823 | 754 | UNKNOWN | UNKNOWN | RT_STRING |
4090 | 3.31515 | 780 | UNKNOWN | UNKNOWN | RT_STRING |
4091 | 3.25024 | 718 | UNKNOWN | UNKNOWN | RT_STRING |
4093 | 2.86149 | 104 | UNKNOWN | UNKNOWN | RT_STRING |
4094 | 3.20731 | 180 | UNKNOWN | UNKNOWN | RT_STRING |
4095 | 3.04592 | 174 | UNKNOWN | UNKNOWN | RT_STRING |
advapi32.dll |
advapi32.dll (#2) |
comctl32.dll |
kernel32.dll |
kernel32.dll (#2) |
oleaut32.dll |
user32.dll |
user32.dll (#2) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1580 | "C:\Users\admin\AppData\Local\Temp\MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.exe" | C:\Users\admin\AppData\Local\Temp\MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.exe | — | Explorer.EXE | |||||||||||
User: admin Company: CPUID, Inc. Integrity Level: MEDIUM Description: CPUID CPU-Z Setup Version: Modules
| |||||||||||||||
2480 | "C:\Users\admin\AppData\Local\Temp\is-716B9.tmp\MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp" /SL5="$50198,1823662,58368,C:\Users\admin\AppData\Local\Temp\MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.exe" | C:\Users\admin\AppData\Local\Temp\is-716B9.tmp\MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp | — | MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Version: 51.52.0.0 Modules
| |||||||||||||||
1400 | "C:\Users\admin\AppData\Local\Temp\MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.exe" /SPAWNWND=$601B0 /NOTIFYWND=$50198 | C:\Users\admin\AppData\Local\Temp\MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.exe | MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp | ||||||||||||
User: admin Company: CPUID, Inc. Integrity Level: HIGH Description: CPUID CPU-Z Setup Version: Modules
| |||||||||||||||
3244 | "C:\Users\admin\AppData\Local\Temp\is-GMSDT.tmp\MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp" /SL5="$601C8,1823662,58368,C:\Users\admin\AppData\Local\Temp\MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.exe" /SPAWNWND=$601B0 /NOTIFYWND=$50198 | C:\Users\admin\AppData\Local\Temp\is-GMSDT.tmp\MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp | MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Version: 51.52.0.0 Modules
| |||||||||||||||
2400 | "C:\Program Files\CPUID\CPU-Z\cpuz.exe" | C:\Program Files\CPUID\CPU-Z\cpuz.exe | — | Explorer.EXE | |||||||||||
User: admin Company: CPUID Integrity Level: MEDIUM Description: CPU-Z Application Exit code: 3221226540 Version: 1, 9, 7, 0 Modules
| |||||||||||||||
604 | "C:\Program Files\CPUID\CPU-Z\cpuz.exe" | C:\Program Files\CPUID\CPU-Z\cpuz.exe | Explorer.EXE | ||||||||||||
User: admin Company: CPUID Integrity Level: HIGH Description: CPU-Z Application Version: 1, 9, 7, 0 Modules
|
(PID) Process: | (3244) MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | Owner |
Value: AC0C0000EA23C58B3A09D901 | |||
(PID) Process: | (3244) MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | SessionHash |
Value: D2FC91787C8F527CC3467CB0CE11ACA83140D003D5374A7B3C5218E77463659C | |||
(PID) Process: | (3244) MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | Sequence |
Value: 1 | |||
(PID) Process: | (3244) MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | RegFiles0000 |
Value: C:\Program Files\CPUID\CPU-Z\cpuz.exe | |||
(PID) Process: | (3244) MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | RegFilesHash |
Value: C31EE9155AD781A03BB6282AF8A2757B8996B80366A29B8DF81B64CF6BC62A12 | |||
(PID) Process: | (3244) MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CPUID\CPU-Z |
Operation: | write | Name: | PATH |
Value: C:\Program Files\CPUID\CPU-Z | |||
(PID) Process: | (3244) MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CPUID\CPU-Z |
Operation: | write | Name: | PRODUCT_NAME |
Value: CPUID CPU-Z | |||
(PID) Process: | (3244) MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\CPUID\CPU-Z |
Operation: | write | Name: | VERSION |
Value: 1.97 | |||
(PID) Process: | (3244) MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CPUID CPU-Z_is1 |
Operation: | write | Name: | Inno Setup: Setup Version |
Value: 5.6.1 (a) | |||
(PID) Process: | (3244) MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CPUID CPU-Z_is1 |
Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files\CPUID\CPU-Z |
PID | Process | Filename | Type | |
---|---|---|---|---|
3244 | MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp | C:\Users\Public\Desktop\CPUID CPU-Z.lnk | lnk | |
MD5:7EB9A6A487AAA8FF183D53D0A90ADC03 | SHA256:4CF77BB85556BD4FC957552C84E816C7F3A8D8A998B6E9AE07C547C0A2914D60 | |||
604 | cpuz.exe | C:\Windows\temp\cpuz152\cpuz152_x32.sys | executable | |
MD5:7ABF3D484905A6335F79A306FD138A24 | SHA256:86C07833EC88C93F01689103390032335B95C52E0E9B4994A63014A72428DBF5 | |||
3244 | MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\CPU-Z\Edit CPU-Z Config File.lnk | lnk | |
MD5:BAB4C20AE44EA536B767EF45F9BB0FF0 | SHA256:343C08E259C24F54ED98540E4C85FFCB5DFDECDCFE9F83832E5B28EA53537AAC | |||
3244 | MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\CPU-Z\CPU-Z.lnk | lnk | |
MD5:98F1ED4751EFEE4F5613542EDE3833FF | SHA256:BA1682742BA3CD98B54417794B6C67931CB6E0DA3A67F071FBF1C4C4F09ADE4F | |||
3244 | MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\CPUID\CPU-Z\Uninstall CPU-Z.lnk | lnk | |
MD5:0768F80567A5B0F403D51E71E307FEBE | SHA256:60E37B10DB16B881C933FA73ED8F962C10DED8D2E2E46FF735FCE599490C8343 | |||
3244 | MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp | C:\Program Files\CPUID\CPU-Z\unins000.dat | dat | |
MD5:CEDE72CD91201DBF2A4454B86BC0C248 | SHA256:52F7C933301BC2DECF3DB4AFBC3AC0EA7CC1F6F791B0D64A209D082B473FE2E2 | |||
604 | cpuz.exe | C:\Windows\temp\cpuz_driver_604.log | text | |
MD5:4015F76944FFB53111F9B0A41F1DF460 | SHA256:7C48C5DCE403EBE99BBE089D3C12973E79E7FEC6BE5EB6478AA371103A9580AA | |||
3244 | MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp | C:\Program Files\CPUID\CPU-Z\is-62I25.tmp | text | |
MD5:15130D155F7DDAFB034A62077B051F16 | SHA256:3E0364795D926935AB038CD9197AD10AFFB55983198858C6BF70B4D01F7F5529 | |||
3244 | MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp | C:\Program Files\CPUID\CPU-Z\is-PE09N.tmp | text | |
MD5:99694811A33139D2C4B89CF033A01A5F | SHA256:0B15131AF3B8D32450A3774CFC06F9797B9435D921EACBD33D8B1F8BD43EB401 | |||
3244 | MDNEqUr9u_ZHKnPDHwXzdOnYA0bl-4NkZFadCa3TnQM_CLBkWRXwfsrlu_bNhfddmvan-lE-1QHDPOGQfA6_2tCD6C1YAUbCnCtdCjsdEOw.tmp | C:\Program Files\CPUID\CPU-Z\is-7ACH8.tmp | text | |
MD5:E44F547A3378E46171D56A8A80CE9A40 | SHA256:AB086F912FF00C8C3AB42B8CA6D01395A96ECA253FAE4B186A3CA72C230B66B0 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
604 | cpuz.exe | GET | 200 | 8.238.30.254:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d3e03ff165925991 | US | compressed | 4.70 Kb | whitelisted |
604 | cpuz.exe | GET | 200 | 184.24.9.54:80 | http://x1.c.lencr.org/ | DE | der | 717 b | whitelisted |
604 | cpuz.exe | GET | 200 | 95.101.54.131:80 | http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgMx09HkWS07es1rXypVKP5qnA%3D%3D | DE | der | 503 b | shared |
604 | cpuz.exe | GET | 200 | 8.238.30.254:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?d7d733ce0b900b66 | US | compressed | 61.4 Kb | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
604 | cpuz.exe | 8.238.30.254:80 | ctldl.windowsupdate.com | LEVEL3 | US | suspicious |
604 | cpuz.exe | 95.101.54.131:80 | r3.o.lencr.org | Akamai International B.V. | DE | suspicious |
604 | cpuz.exe | 195.154.81.43:443 | download.cpuid.com | Online S.a.s. | FR | suspicious |
604 | cpuz.exe | 184.24.9.54:80 | x1.c.lencr.org | AKAMAI-AS | DE | unknown |
Domain | IP | Reputation |
---|---|---|
download.cpuid.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
r3.o.lencr.org |
| shared |