| File name: | FTS_D3167A1xFlashBIOSUpdateDeskFlashInstant_V4653R1230_1119437.EXE |
| Full analysis: | https://app.any.run/tasks/c11452f1-be70-4cb2-8608-c478e684dc75 |
| Verdict: | Malicious activity |
| Analysis date: | July 15, 2019, 14:54:53 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | DF238631CE06025C752F3222A9D8B88C |
| SHA1: | 67C36E09A4912F1BEC81AF2A6C7242B994B37E9A |
| SHA256: | 82E203623DE8B6540BBDBB19894676E57A66A429E339A66E6303641CC2A0BF7E |
| SSDEEP: | 196608:NaeNpy5KjdroAhxOmLIXxHlaIKQd94U+q2g9u1u4rSR:AeNPjJoxX5laIKQXH+Xg92u |
| .exe | | | InstallShield setup (30.7) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (22.2) |
| .exe | | | Win64 Executable (generic) (19.7) |
| .exe | | | Winzip Win32 self-extracting archive (generic) (16.4) |
| .dll | | | Win32 Dynamic Link Library (generic) (4.6) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2009:02:24 16:50:34+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 77824 |
| InitializedDataSize: | 40960 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xaf1e |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 24-Feb-2009 15:50:34 |
| Detected languages: |
|
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000F0 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 24-Feb-2009 15:50:34 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00012775 | 0x00013000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.50181 |
.rdata | 0x00014000 | 0x00003822 | 0x00004000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.98659 |
.data | 0x00018000 | 0x0000E6E4 | 0x00002000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.97548 |
.rsrc | 0x00027000 | 0x0000368C | 0x00004000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.41968 |
_winzip_ | 0x0002B000 | 0x008CC000 | 0x008CC000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 7.99962 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 4.82954 | 989 | Latin 1 / Western European | English - United States | RT_MANIFEST |
63 | 3.18826 | 764 | Latin 1 / Western European | English - United States | RT_STRING |
64 | 3.37002 | 1496 | Latin 1 / Western European | English - United States | RT_STRING |
65 | 3.39511 | 2382 | Latin 1 / Western European | English - United States | RT_STRING |
66 | 3.44643 | 2322 | Latin 1 / Western European | English - United States | RT_STRING |
67 | 3.39393 | 1278 | Latin 1 / Western European | English - United States | RT_STRING |
100 | 3.08197 | 290 | Latin 1 / Western European | English - United States | RT_DIALOG |
126 | 3.58134 | 1304 | Latin 1 / Western European | English - United States | RT_STRING |
127 | 2.47759 | 110 | Latin 1 / Western European | English - United States | RT_STRING |
400 | 3.46881 | 402 | Latin 1 / Western European | English - United States | RT_DIALOG |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
SHELL32.dll |
USER32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 332 | "C:\Users\admin\AppData\Local\Temp\_TinDel.exe" | C:\Users\admin\AppData\Local\Temp\_TinDel.exe | — | Setup.exe | |||||||||||
User: admin Company: Tarma Software Research Pty Ltd Integrity Level: HIGH Description: Final cleanup helper Exit code: 0 Version: 2011.06.24.0909A Modules
| |||||||||||||||
| 352 | "C:\Users\admin\AppData\Local\Temp\13ECEBAA\x86\regsvr32.exe" "C:\Program Files\Common Files\Fujitsu\Manageability\AcGabi.dll\1.14\AcGabi.dll" /u | C:\Users\admin\AppData\Local\Temp\13ECEBAA\x86\regsvr32.exe | — | Setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Out-of-process DLL registration helper Exit code: 0 Version: 2011.06.24.0909A Modules
| |||||||||||||||
| 656 | "C:\Program Files\Fujitsu\DeskView\Instant\DeskFlash\DskFlash.exe" /UPD /OV /ARB /waithandlerend /quickhandlerend /instant | C:\Program Files\Fujitsu\DeskView\Instant\DeskFlash\DskFlash.exe | — | DskFlash.exe | |||||||||||
User: admin Company: Fujitsu Technology Solutions Integrity Level: HIGH Description: DeskView tool to update and archive BIOS and BIOS settings Exit code: 1040 Version: 6.17 Modules
| |||||||||||||||
| 1088 | "C:\Users\admin\AppData\Local\Temp\13ECEBAA\x86\regsvr32.exe" "C:\Program Files\Common Files\Fujitsu\Manageability\BlBFlash.dll\1.15\BlBFlash.dll" /u | C:\Users\admin\AppData\Local\Temp\13ECEBAA\x86\regsvr32.exe | — | Setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Out-of-process DLL registration helper Exit code: 0 Version: 2011.06.24.0909A Modules
| |||||||||||||||
| 1332 | "C:\Program Files\Common Files\Fujitsu\Manageability\HaBFlash.exe\1.15\HaBFlash.exe" /s /regserver | C:\Program Files\Common Files\Fujitsu\Manageability\HaBFlash.exe\1.15\HaBFlash.exe | — | DF_UEFI.exe | |||||||||||
User: admin Company: Fujitsu Technology Solutions Integrity Level: HIGH Description: HaBFlash.exe Exit code: 0 Version: 1.15 Modules
| |||||||||||||||
| 1372 | "C:\Program Files\Fujitsu\DeskView\Instant\Install\SRP.exe" Enable | C:\Program Files\Fujitsu\DeskView\Instant\Install\SRP.exe | — | DF_UEFI.exe | |||||||||||
User: admin Company: Fujitsu Technology Solutions Integrity Level: HIGH Description: SystemRestorePoints functionality Exit code: 0 Version: 1.02 Modules
| |||||||||||||||
| 1412 | DrvInst.exe "2" "211" "ROOT\SYSTEM\0002" "C:\Windows\INF\oem5.inf" "fscgabi.inf:DeviceList.NTx86:DriverInstall:6.0.1.19:root\fscgabi" "69173570f" "000005B4" "00000544" "0000060C" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1440 | "C:\Program Files\Fujitsu\DeskView\Instant\Install\CertMgr.exe" /add "C:\Program Files\Fujitsu\DeskView\Instant\Install\3_vs_c3_cs_2010_ca.cer" -s CA -r localMachine | C:\Program Files\Fujitsu\DeskView\Instant\Install\CertMgr.exe | — | DF_UEFI.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: ECM Certificate Manager Exit code: 0 Version: 6.0.6001.18000 (longhorn_rtm.080118-1840) Modules
| |||||||||||||||
| 1664 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2156 | "C:\Users\admin\AppData\Local\Temp\13ECEBAA\x86\regsvr32.exe" "C:\Program Files\Common Files\Fujitsu\Manageability\CIAsmbly.dll\1.09\CIAsmbly.dll" /r | C:\Users\admin\AppData\Local\Temp\13ECEBAA\x86\regsvr32.exe | — | DF_UEFI.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Out-of-process DLL registration helper Exit code: 0 Version: 2011.06.24.0909A Modules
| |||||||||||||||
| (PID) Process: | (3764) DF_UEFI.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: B40E0000A6F7FD521D3BD501 | |||
| (PID) Process: | (3764) DF_UEFI.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: 6FB585177165265A815B2ACFC9C501799B50E8CF1BA3AE1C4FEAA9714D217F9E | |||
| (PID) Process: | (3764) DF_UEFI.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (3764) DF_UEFI.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs |
| Operation: | write | Name: | C:\Program Files\Common Files\Fujitsu\Manageability\DVLang.dll\1.22\DVLANG.dll |
Value: 1 | |||
| (PID) Process: | (3764) DF_UEFI.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs |
| Operation: | write | Name: | C:\Program Files\Common Files\Fujitsu\Manageability\HaBFlash.evt\1.10\HaBFlash.Evt |
Value: 1 | |||
| (PID) Process: | (3764) DF_UEFI.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs |
| Operation: | write | Name: | C:\Program Files\Common Files\Fujitsu\Manageability\DVAnPMan.exe\1.21\DVAnPMan.exe |
Value: 1 | |||
| (PID) Process: | (3668) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\{42E21DD3-55FA-435a-B400-C88C7E744182} |
| Operation: | write | Name: | |
Value: BlBFlash | |||
| (PID) Process: | (3668) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\AppID\BlBFlash.DLL |
| Operation: | write | Name: | AppID |
Value: {42E21DD3-55FA-435a-B400-C88C7E744182} | |||
| (PID) Process: | (3668) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BlBFlash.BlBFlashObj.1.15 |
| Operation: | write | Name: | |
Value: CBlBFlashObj Object | |||
| (PID) Process: | (3668) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\BlBFlash.BlBFlashObj.1.15\CLSID |
| Operation: | write | Name: | |
Value: {0792294A-5FD0-4062-8B4C-FF3C8B98E5C5} | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3764 | DF_UEFI.exe | C:\Users\admin\AppData\Local\Temp\13ECEBAA.dat | — | |
MD5:— | SHA256:— | |||
| 3956 | FTS_D3167A1xFlashBIOSUpdateDeskFlashInstant_V4653R1230_1119437.EXE | C:\Users\admin\AppData\Local\Temp\WZSE0.TMP\D3167-A1x.R1.23.0.DFI.bup | compressed | |
MD5:— | SHA256:— | |||
| 3764 | DF_UEFI.exe | C:\Program Files\Fujitsu\DeskView\Instant\Driver\amd64\fscgabi.cat._tm | — | |
MD5:— | SHA256:— | |||
| 3956 | FTS_D3167A1xFlashBIOSUpdateDeskFlashInstant_V4653R1230_1119437.EXE | C:\Users\admin\AppData\Local\Temp\WZSE0.TMP\DATA\DF_UEFI.exe | executable | |
MD5:A3ECF2CF74B296B1CA9E4416314344AF | SHA256:453D11FD754F6CAC05EB7E5E4EFAAA8DF860A42757B67389FBC1F285AF56ACD7 | |||
| 3764 | DF_UEFI.exe | C:\Program Files\Fujitsu\DeskView\Instant\Driver\amd64\fscefdmi.cat._tm | — | |
MD5:— | SHA256:— | |||
| 3956 | FTS_D3167A1xFlashBIOSUpdateDeskFlashInstant_V4653R1230_1119437.EXE | C:\Users\admin\AppData\Local\Temp\WZSE0.TMP\DskFlsh2.bat | text | |
MD5:E5A1B93092B6BBCD21E45F68C2F99050 | SHA256:EAAB60ADB152C74CB2724C32AA5D47DC1C37FC489FC3BC7A810B2DFCA56F059A | |||
| 3764 | DF_UEFI.exe | C:\Program Files\Fujitsu\DeskView\Instant\Driver\i386\fscgabi.cat._tm | — | |
MD5:— | SHA256:— | |||
| 3956 | FTS_D3167A1xFlashBIOSUpdateDeskFlashInstant_V4653R1230_1119437.EXE | C:\Users\admin\AppData\Local\Temp\WZSE0.TMP\DskFlash.exe | executable | |
MD5:BA4C3F666CB70D262A46ED005D25ADDC | SHA256:E873C1D604255D493C09639E910D455C5C8C954FA49A05926B75046D1014AC4B | |||
| 3764 | DF_UEFI.exe | C:\Program Files\Fujitsu\DeskView\Instant\Driver\i386\fscefdmi.cat._tm | — | |
MD5:— | SHA256:— | |||
| 3956 | FTS_D3167A1xFlashBIOSUpdateDeskFlashInstant_V4653R1230_1119437.EXE | C:\Users\admin\AppData\Local\Temp\WZSE0.TMP\ThirdPartyLicenseReadme.txt | text | |
MD5:0C24BEEF5B7FEF10C2FA8C5C0C74BB11 | SHA256:DEAC1954979E3A65AF866FD5CC1ED6761955480855F337605F4C9D7E57A935AD | |||