| File name: | NetBalancer.9.4.1.exe |
| Full analysis: | https://app.any.run/tasks/f8072caa-ac15-4a3f-84ce-40b128d9b5d4 |
| Verdict: | Malicious activity |
| Analysis date: | September 06, 2018, 02:42:13 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | C893BFB4B62FA3F9C5C993D505014863 |
| SHA1: | 047AD00AD66A82539DA71B45B7BD7600483522F3 |
| SHA256: | 8A908C2647E460072595443D22F27449182386FA63395824010B48FBCC104E86 |
| SSDEEP: | 196608:8oKDIRX3NCi6fddgvz0vayGfHJrmDt7ES8mZW:Sc3NI7gvzYGfpymvmE |
| .exe | | | Win32 Executable Delphi generic (57.2) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (18.2) |
| .exe | | | Win16/32 Executable Delphi generic (8.3) |
| .exe | | | Generic Win/DOS Executable (8) |
| .exe | | | DOS Executable Generic (8) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2015:07:16 15:24:20+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 65024 |
| InitializedDataSize: | 394240 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x113bc |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 9.4.1.905 |
| ProductVersionNumber: | 9.4.1.905 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | SeriousBit |
| FileDescription: | NetBalancer Setup |
| FileVersion: | 9.4.1.905 |
| LegalCopyright: | |
| ProductName: | NetBalancer |
| ProductVersion: | 9.4.1.905 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 16-Jul-2015 13:24:20 |
| Detected languages: |
|
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | SeriousBit |
| FileDescription: | NetBalancer Setup |
| FileVersion: | 9.4.1.905 |
| LegalCopyright: | - |
| ProductName: | NetBalancer |
| ProductVersion: | 9.4.1.905 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0050 |
| Pages in file: | 0x0002 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x000F |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x001A |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000100 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 8 |
| Time date stamp: | 16-Jul-2015 13:24:20 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x0000F134 | 0x0000F200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.39165 |
.itext | 0x00011000 | 0x00000B44 | 0x00000C00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.74124 |
.data | 0x00012000 | 0x00000C88 | 0x00000E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.24753 |
.bss | 0x00013000 | 0x000056B8 | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.idata | 0x00019000 | 0x00000DD0 | 0x00000E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.97188 |
.tls | 0x0001A000 | 0x00000008 | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rdata | 0x0001B000 | 0x00000018 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.204488 |
.rsrc | 0x0001C000 | 0x0005E448 | 0x0005E600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.80149 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.13965 | 1580 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 5.159 | 152104 | Latin 1 / Western European | English - United States | RT_ICON |
3 | 5.21633 | 67624 | Latin 1 / Western European | English - United States | RT_ICON |
4 | 5.32408 | 38056 | Latin 1 / Western European | English - United States | RT_ICON |
5 | 5.4353 | 16936 | Latin 1 / Western European | English - United States | RT_ICON |
6 | 5.56773 | 9640 | Latin 1 / Western European | English - United States | RT_ICON |
7 | 5.78427 | 4264 | Latin 1 / Western European | English - United States | RT_ICON |
8 | 5.94592 | 2440 | Latin 1 / Western European | English - United States | RT_ICON |
9 | 6.46396 | 1128 | Latin 1 / Western European | English - United States | RT_ICON |
4091 | 2.56031 | 104 | Latin 1 / Western European | UNKNOWN | RT_STRING |
advapi32.dll |
comctl32.dll |
kernel32.dll |
oleaut32.dll |
user32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1196 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{55dc5f23-a8d4-0b23-27ce-1469339ff02b}\nbdrv.inf" "0" "676c9f2db" "000005FC" "WinSta0\Default" "00000600" "208" "C:\Program Files\NetBalancer\drv" | C:\Windows\system32\DrvInst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1376 | "nbcmd.exe" ass | C:\Program Files\NetBalancer\nbcmd.exe | — | NetHelper.exe | |||||||||||
User: admin Company: SeriousBit Integrity Level: HIGH Description: NBCMD Exit code: 0 Version: 9.4.1 Modules
| |||||||||||||||
| 1380 | C:\Windows\Explorer.EXE | C:\Windows\explorer.exe | — | — | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1073807364 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1552 | "C:\Users\admin\AppData\Local\Temp\NetBalancer.9.4.1.exe" | C:\Users\admin\AppData\Local\Temp\NetBalancer.9.4.1.exe | explorer.exe | ||||||||||||
User: admin Company: SeriousBit Integrity Level: MEDIUM Description: NetBalancer Setup Exit code: 0 Version: 9.4.1.905 Modules
| |||||||||||||||
| 1608 | "C:\Users\admin\AppData\Local\Temp\is-HA3GL.tmp\NetBalancer.9.4.1.tmp" /SL5="$3101A2,6004793,460288,C:\Users\admin\AppData\Local\Temp\NetBalancer.9.4.1.exe" /SPAWNWND=$180260 /NOTIFYWND=$220210 | C:\Users\admin\AppData\Local\Temp\is-HA3GL.tmp\NetBalancer.9.4.1.tmp | NetBalancer.9.4.1.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 2200 | C:\Windows\system32\net1 start NetBalancerService | C:\Windows\system32\net1.exe | — | net.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2504 | C:\Windows\system32\DllHost.exe /Processid:{F32D97DF-E3E5-4CB9-9E3E-0EB5B4E49801} | C:\Windows\system32\DllHost.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: COM Surrogate Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2596 | "drv/snetcfg.exe" -v -l nbdrv.inf -c s -i nt_nbdrv | C:\Program Files\NetBalancer\drv\snetcfg.exe | NetHelper.exe | ||||||||||||
User: admin Company: Windows (R) Server 2003 DDK provider Integrity Level: HIGH Description: network config sample Exit code: 0 Version: 5.2.3790.0 built by: WinDDK Modules
| |||||||||||||||
| 2888 | "C:\Program Files\NetBalancer\drv\CertMgr.exe" -add drv\certsha2.cer -c -s -r localMachine TrustedPublisher | C:\Program Files\NetBalancer\drv\CertMgr.exe | — | NetBalancer.9.4.1.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: ECM Certificate Manager Exit code: 0 Version: 6.1.7600.16385 (win7_wdk.100208-1538) Modules
| |||||||||||||||
| 2968 | "C:\Program Files\NetBalancer\drv\CertMgr.exe" -add drv\certsha1.cer -c -s -r localMachine TrustedPublisher | C:\Program Files\NetBalancer\drv\CertMgr.exe | — | NetBalancer.9.4.1.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: ECM Certificate Manager Exit code: 0 Version: 6.1.7600.16385 (win7_wdk.100208-1538) Modules
| |||||||||||||||
| (PID) Process: | (1608) NetBalancer.9.4.1.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 48060000642588478B45D401 | |||
| (PID) Process: | (1608) NetBalancer.9.4.1.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: D6B5955B1D3905977B3388D5BCAB1594823007DAF5D8A2D3A6AF75B62A27CA4B | |||
| (PID) Process: | (1608) NetBalancer.9.4.1.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (1608) NetBalancer.9.4.1.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Program Files\NetBalancer\SeriousBit.NetBalancer.Service.exe | |||
| (PID) Process: | (1608) NetBalancer.9.4.1.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFilesHash |
Value: 51E7DE343C9B00308C38563017B113685D6DADE891CFC3771D97FB74F0E31649 | |||
| (PID) Process: | (1380) explorer.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\59\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2968) CertMgr.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\TrustedPublisher\Certificates\D44B4DAB651CC7D7E95C1D6D7B328A7C0546C17D |
| Operation: | write | Name: | Blob |
Value: 030000000100000014000000D44B4DAB651CC7D7E95C1D6D7B328A7C0546C17D2000000001000000D2040000308204CE308203B6A00302010202121121BFDE2D050C40F081D52911807342ABB3300D06092A864886F70D01010505003051310B300906035504061302424531193017060355040A1310476C6F62616C5369676E206E762D7361312730250603550403131E476C6F62616C5369676E20436F64655369676E696E67204341202D204732301E170D3135303230353135343135355A170D3135313131343230323734335A3064310B3009060355040613024D443111300F060355040813085374726173656E693110300E06035504071307436F6A75736E6131173015060355040A130E536572696F75734269742053726C311730150603550403130E536572696F75734269742053726C30820122300D06092A864886F70D01010105000382010F003082010A0282010100A86D9CC5DF6070DE8467CAA208A64E40365BEE6C15954AA59EA43570BBA121D85C0932FDBCD0D7A3B51022E2071AB3B492ADFB1A376F67AF3386A8FBCEFEC6442A5C00DC8096A247127A595FCB61EA07235F6ADB06D0B07864CEB41227C73CC4E9EC555F0DBBE16642B714E43D2698DD6EE8A3FBCF08A793E035BD67D9E7BDE354FBC222F149BE7AAF368D1014F6B3AA5A07B1CEB78ACCBD528EF2884422A41F9C0D5896B00B795B37E07689596B9155F0F7ED0ED25BD0FD7C7E558A0ED574205E4B57DD31E4728C898949A1E12FF35706D1C26EAC17EFF33098769C250D0DDE0BA236A5CB23037A6A9E7D5DAB880CAB93407EE4BB60741C51E70D91635E76E50203010001A382018B30820187300E0603551D0F0101FF040403020780304C0603551D2004453043304106092B06010401A03201323034303206082B06010505070201162668747470733A2F2F7777772E676C6F62616C7369676E2E636F6D2F7265706F7369746F72792F30090603551D130402300030130603551D25040C300A06082B06010505070303303E0603551D1F043730353033A031A02F862D687474703A2F2F63726C2E676C6F62616C7369676E2E636F6D2F67732F6773636F64657369676E67322E63726C30818606082B06010505070101047A3078304006082B060105050730028634687474703A2F2F7365637572652E676C6F62616C7369676E2E636F6D2F6361636572742F6773636F64657369676E67322E637274303406082B060105050730018628687474703A2F2F6F637370322E676C6F62616C7369676E2E636F6D2F6773636F64657369676E6732301D0603551D0E041604148AFE84B8255FB72DD700559D66A3EDEB44F6597E301F0603551D23041830168014086ED8B69C8ABFED3ED7C3745DCC801FA82F507A300D06092A864886F70D0101050500038201010038E7505AFE93248F48844721BBFF9A5B8A366A98C8BA85850168063CBA8B237C310BAEA5945FDDDA0C6A5C931D8158BA9566FE958FB996E9BC1B422C677D788977FB2A484ACA3851AF7339B728FEAED45360862075662E6DBE1DF22A79C305648059B25BF520436A68A17C87DEE897877B88C7E261D8C603E0DAC5E0C94C12EA5CA02CDAD58A9FFC4E827E93E5BF5D3DB282618CFA504058A64C4A929BEB4CE19D594D8A4DFF2119088516B454813C894351ED1A1B1F245145B1D941CEF71D924F4F2418EF904FDD4D0DA25D28A1F1607035F0B6B86B3CD65DBDB7AB2678D2B8DF2C082A6BDDC4BFF90BD4BE616BBFFC945168EFDA90D8DDEBBD84723FE2FE4C | |||
| (PID) Process: | (1608) NetBalancer.9.4.1.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetBalancer_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 5.5.6 (u) | |||
| (PID) Process: | (1608) NetBalancer.9.4.1.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetBalancer_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files\NetBalancer | |||
| (PID) Process: | (1608) NetBalancer.9.4.1.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetBalancer_is1 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\NetBalancer\ | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1608 | NetBalancer.9.4.1.tmp | C:\Program Files\NetBalancer\is-LBEAB.tmp | — | |
MD5:— | SHA256:— | |||
| 1608 | NetBalancer.9.4.1.tmp | C:\Program Files\NetBalancer\is-5HD2S.tmp | — | |
MD5:— | SHA256:— | |||
| 1608 | NetBalancer.9.4.1.tmp | C:\Program Files\NetBalancer\is-B792O.tmp | — | |
MD5:— | SHA256:— | |||
| 1608 | NetBalancer.9.4.1.tmp | C:\Program Files\NetBalancer\is-AQ7SF.tmp | — | |
MD5:— | SHA256:— | |||
| 1608 | NetBalancer.9.4.1.tmp | C:\Program Files\NetBalancer\is-9N809.tmp | — | |
MD5:— | SHA256:— | |||
| 1608 | NetBalancer.9.4.1.tmp | C:\Program Files\NetBalancer\is-6AF3L.tmp | — | |
MD5:— | SHA256:— | |||
| 1608 | NetBalancer.9.4.1.tmp | C:\Program Files\NetBalancer\is-QDR5L.tmp | — | |
MD5:— | SHA256:— | |||
| 1608 | NetBalancer.9.4.1.tmp | C:\Program Files\NetBalancer\is-68A5V.tmp | — | |
MD5:— | SHA256:— | |||
| 1608 | NetBalancer.9.4.1.tmp | C:\Program Files\NetBalancer\is-IQQMQ.tmp | — | |
MD5:— | SHA256:— | |||
| 1608 | NetBalancer.9.4.1.tmp | C:\Program Files\NetBalancer\is-HLGNA.tmp | — | |
MD5:— | SHA256:— | |||
Domain | IP | Reputation |
|---|---|---|
teredo.ipv6.microsoft.com |
| whitelisted |