File name: | XnView-win.exe |
Full analysis: | https://app.any.run/tasks/1565d7f8-cf9e-42de-957c-21a064de128e |
Verdict: | Malicious activity |
Analysis date: | July 09, 2021, 16:31:47 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 30A21FB78DA2EB8F4512092DC347A195 |
SHA1: | 496F6FC1619A947721ACED529C813D1A32434AA5 |
SHA256: | 900B967C77DFE39452CCDF53C404E5EC8DD414256BE63B0CB497CC1A034F7C53 |
SSDEEP: | 98304:pPzZj9gSo2h40qJWlsLzsPwpYLon/iZjxvN2b5eTcy0adA1vbniIEBk1iOnUfrwC:xz597VTlsUPiqk/inEbQbxdAdTiBi8rL |
.exe | | | Inno Setup installer (77.7) |
---|---|---|
.exe | | | Win32 Executable Delphi generic (10) |
.dll | | | Win32 Dynamic Link Library (generic) (4.6) |
.exe | | | Win32 Executable (generic) (3.1) |
.exe | | | Win16/32 Executable Delphi generic (1.4) |
ProductVersion: | 2.50 |
---|---|
ProductName: | XnView |
LegalCopyright: | Copyright © 1991-2021 Pierre-e Gougelet |
FileVersion: | 2.50 |
FileDescription: | XnView Setup |
CompanyName: | Gougelet Pierre-e |
Comments: | This installation was built with Inno Setup. |
CharacterSet: | Unicode |
LanguageCode: | Neutral |
FileSubtype: | - |
ObjectFileType: | Executable application |
FileOS: | Win32 |
FileFlags: | (none) |
FileFlagsMask: | 0x003f |
ProductVersionNumber: | 2.50.0.0 |
FileVersionNumber: | 2.50.0.0 |
Subsystem: | Windows GUI |
SubsystemVersion: | 4 |
ImageVersion: | 6 |
OSVersion: | 1 |
EntryPoint: | 0xa5f8 |
UninitializedDataSize: | - |
InitializedDataSize: | 37888 |
CodeSize: | 40448 |
LinkerVersion: | 2.25 |
PEType: | PE32 |
TimeStamp: | 1992:06:20 00:22:17+02:00 |
MachineType: | Intel 386 or later, and compatibles |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 19-Jun-1992 22:22:17 |
Detected languages: |
|
Comments: | This installation was built with Inno Setup. |
CompanyName: | Gougelet Pierre-e |
FileDescription: | XnView Setup |
FileVersion: | 2.50 |
LegalCopyright: | Copyright © 1991-2021 Pierre-e Gougelet |
ProductName: | XnView |
ProductVersion: | 2.50 |
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x0050 |
Pages in file: | 0x0002 |
Relocations: | 0x0000 |
Size of header: | 0x0004 |
Min extra paragraphs: | 0x000F |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x00B8 |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0000 |
Overlay number: | 0x001A |
OEM identifier: | 0x0000 |
OEM information: | 0x0000 |
Address of NE header: | 0x00000100 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 8 |
Time date stamp: | 19-Jun-1992 22:22:17 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
CODE | 0x00001000 | 0x00009D30 | 0x00009E00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.63175 |
DATA | 0x0000B000 | 0x00000250 | 0x00000400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.75472 |
BSS | 0x0000C000 | 0x00000E90 | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.idata | 0x0000D000 | 0x00000950 | 0x00000A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.43073 |
.tls | 0x0000E000 | 0x00000008 | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rdata | 0x0000F000 | 0x00000018 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED | 0.204488 |
.reloc | 0x00010000 | 0x000008C4 | 0x00000000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED | 0 |
.rsrc | 0x00011000 | 0x00008234 | 0x00008400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED | 4.07391 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 5.13965 | 1580 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 3.3922 | 1736 | Latin 1 / Western European | English - United States | RT_ICON |
3 | 3.94362 | 2216 | Latin 1 / Western European | English - United States | RT_ICON |
4 | 4.09534 | 3752 | Latin 1 / Western European | English - United States | RT_ICON |
5 | 4.51378 | 1128 | Latin 1 / Western European | English - United States | RT_ICON |
6 | 3.74896 | 2440 | Latin 1 / Western European | English - United States | RT_ICON |
7 | 3.53457 | 4264 | Latin 1 / Western European | English - United States | RT_ICON |
8 | 3.2398 | 9640 | Latin 1 / Western European | English - United States | RT_ICON |
4089 | 3.21823 | 754 | Latin 1 / Western European | UNKNOWN | RT_STRING |
4090 | 3.31515 | 780 | Latin 1 / Western European | UNKNOWN | RT_STRING |
advapi32.dll |
comctl32.dll |
kernel32.dll |
oleaut32.dll |
user32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1400 | "C:\Users\admin\AppData\Local\Temp\XnView-win.exe" /SPAWNWND=$1013C /NOTIFYWND=$20138 | C:\Users\admin\AppData\Local\Temp\XnView-win.exe | XnView-win.tmp | ||||||||||||
User: admin Company: Gougelet Pierre-e Integrity Level: HIGH Description: XnView Setup Exit code: 0 Version: 2.50 Modules
| |||||||||||||||
2044 | "C:\Users\admin\AppData\Local\Temp\is-RCDOQ.tmp\XnView-win.tmp" /SL5="$20138,5393192,79360,C:\Users\admin\AppData\Local\Temp\XnView-win.exe" | C:\Users\admin\AppData\Local\Temp\is-RCDOQ.tmp\XnView-win.tmp | — | XnView-win.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
2276 | "C:\Users\admin\AppData\Local\Temp\XnView-win.exe" | C:\Users\admin\AppData\Local\Temp\XnView-win.exe | Explorer.EXE | ||||||||||||
User: admin Company: Gougelet Pierre-e Integrity Level: MEDIUM Description: XnView Setup Exit code: 0 Version: 2.50 Modules
| |||||||||||||||
2596 | "C:\Program Files\Internet Explorer\iexplore.exe" http://www.xnview.com/xnview_install.html | C:\Program Files\Internet Explorer\iexplore.exe | — | XnView-win.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 1 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
3204 | "C:\Program Files\XnView\xnview.exe" | C:\Program Files\XnView\xnview.exe | Explorer.EXE | ||||||||||||
User: admin Company: XnView, http://www.xnview.com Integrity Level: MEDIUM Description: XnView Classic for Windows Exit code: 0 Version: 2.50 Modules
| |||||||||||||||
3324 | "C:\Users\admin\AppData\Local\Temp\is-LRRNL.tmp\XnView-win.tmp" /SL5="$2013E,5393192,79360,C:\Users\admin\AppData\Local\Temp\XnView-win.exe" /SPAWNWND=$1013C /NOTIFYWND=$20138 | C:\Users\admin\AppData\Local\Temp\is-LRRNL.tmp\XnView-win.tmp | XnView-win.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
3524 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2596 CREDAT:267521 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
|
(PID) Process: | (3324) XnView-win.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | Owner |
Value: FC0C00000F66EAF6DF74D701 | |||
(PID) Process: | (3324) XnView-win.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | SessionHash |
Value: 89ACEDD9C090BCAD107F43D240C563C557AB310E15F0CE268A9C4AA7384BF65A | |||
(PID) Process: | (3324) XnView-win.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | Sequence |
Value: 1 | |||
(PID) Process: | (3324) XnView-win.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | RegFiles0000 |
Value: C:\Program Files\XnView\xnview.exe | |||
(PID) Process: | (3324) XnView-win.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
Operation: | write | Name: | RegFilesHash |
Value: 2A42611AC71C7684F15017D1E829A4850550C66878A0833D867E7D1B4A41AEBB | |||
(PID) Process: | (3324) XnView-win.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.sld |
Operation: | write | Name: | (default) |
Value: XnView.Slide | |||
(PID) Process: | (3324) XnView-win.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\XnView.Slide\DefaultIcon |
Operation: | write | Name: | (default) |
Value: C:\Program Files\XnView\xnview.exe,0 | |||
(PID) Process: | (3324) XnView-win.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\XnView.Slide\shell\open\command |
Operation: | write | Name: | (default) |
Value: "C:\Program Files\XnView\xnview.exe" -slide "%1" | |||
(PID) Process: | (3324) XnView-win.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\XnView.Image\DefaultIcon |
Operation: | write | Name: | (default) |
Value: C:\Program Files\XnView\xnview.exe,1 | |||
(PID) Process: | (3324) XnView-win.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\XnView.Image\shell\open\command |
Operation: | write | Name: | (default) |
Value: "C:\Program Files\XnView\xnview.exe" "%1" |
PID | Process | Filename | Type | |
---|---|---|---|---|
3324 | XnView-win.tmp | C:\Program Files\XnView\WhatsNew.txt | text | |
MD5:— | SHA256:— | |||
1400 | XnView-win.exe | C:\Users\admin\AppData\Local\Temp\is-LRRNL.tmp\XnView-win.tmp | executable | |
MD5:— | SHA256:— | |||
3324 | XnView-win.tmp | C:\Program Files\XnView\is-6V34P.tmp | text | |
MD5:— | SHA256:— | |||
3324 | XnView-win.tmp | C:\Program Files\XnView\ReadMe.txt | text | |
MD5:— | SHA256:— | |||
2276 | XnView-win.exe | C:\Users\admin\AppData\Local\Temp\is-RCDOQ.tmp\XnView-win.tmp | executable | |
MD5:— | SHA256:— | |||
3324 | XnView-win.tmp | C:\Program Files\XnView\is-54C2G.tmp | text | |
MD5:— | SHA256:— | |||
3324 | XnView-win.tmp | C:\Program Files\XnView\is-JIGA4.tmp | executable | |
MD5:— | SHA256:— | |||
3324 | XnView-win.tmp | C:\Program Files\XnView\unins000.exe | executable | |
MD5:— | SHA256:— | |||
3324 | XnView-win.tmp | C:\Program Files\XnView\is-3VJU1.tmp | executable | |
MD5:— | SHA256:— | |||
3324 | XnView-win.tmp | C:\Users\admin\AppData\Local\Temp\is-467R8.tmp\_isetup\_shfoldr.dll | executable | |
MD5:92DC6EF532FBB4A5C3201469A5B5EB63 | SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3524 | iexplore.exe | GET | 200 | 23.55.163.57:80 | http://crl.identrust.com/DSTROOTCAX3CRL.crl | US | der | 1.16 Kb | whitelisted |
3524 | iexplore.exe | GET | 200 | 104.117.200.9:80 | http://x1.c.lencr.org/ | US | der | 717 b | whitelisted |
3524 | iexplore.exe | GET | 200 | 172.217.18.99:80 | http://ocsp.pki.goog/gsr1/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCEHe9DWzbNvka6iEPxPBY0w0%3D | US | der | 1.41 Kb | whitelisted |
3524 | iexplore.exe | GET | 200 | 172.217.18.99:80 | http://ocsp.pki.goog/gts1c3/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCEQD%2Bk7JzdJrHjAoAAAAA6DGx | US | der | 472 b | whitelisted |
3524 | iexplore.exe | GET | 200 | 172.217.18.99:80 | http://ocsp.pki.goog/gts1o1core/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEEPADVwzSh7mAwAAAADMUdQ%3D | US | der | 471 b | whitelisted |
3524 | iexplore.exe | GET | 200 | 172.217.18.99:80 | http://ocsp.pki.goog/gts1c3/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTHLnmK3f9hNLO67UdCuLvGwCQHYwQUinR%2Fr4XN7pXNPZzQ4kYU83E1HScCECxnvN4MUipXCgAAAADoMbo%3D | US | der | 471 b | whitelisted |
3524 | iexplore.exe | GET | 301 | 178.33.105.203:80 | http://www.xnview.com/xnview_install.html | FR | html | 330 b | suspicious |
3524 | iexplore.exe | GET | 200 | 172.217.18.99:80 | http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D | US | der | 468 b | whitelisted |
3204 | xnview.exe | GET | 301 | 178.33.105.203:80 | http://www.xnview.com/xnview_update.txt | FR | html | 328 b | suspicious |
3524 | iexplore.exe | GET | 200 | 172.217.18.99:80 | http://ocsp.pki.goog/gtsr1/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBQwkcLWD4LqGJ7bE7B1XZsEbmfwUAQU5K8rJnEaK0gnhS9SZizv8IkTcT4CDQIDvFNZazTHGPUBUGY%3D | US | der | 724 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3524 | iexplore.exe | 178.33.105.203:80 | www.xnview.com | OVH SAS | FR | suspicious |
3524 | iexplore.exe | 178.33.105.203:443 | www.xnview.com | OVH SAS | FR | suspicious |
3524 | iexplore.exe | 23.55.163.57:80 | crl.identrust.com | Akamai International B.V. | US | unknown |
3524 | iexplore.exe | 104.117.200.9:80 | x1.c.lencr.org | TPG Telecom Limited | US | unknown |
3524 | iexplore.exe | 142.250.185.200:443 | www.googletagmanager.com | Google Inc. | US | suspicious |
3524 | iexplore.exe | 23.55.163.48:80 | r3.o.lencr.org | Akamai International B.V. | US | unknown |
3524 | iexplore.exe | 216.58.212.170:443 | fonts.googleapis.com | Google Inc. | US | whitelisted |
3524 | iexplore.exe | 142.250.185.194:443 | pagead2.googlesyndication.com | Google Inc. | US | suspicious |
3524 | iexplore.exe | 172.217.18.99:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
3204 | xnview.exe | 178.33.105.203:80 | www.xnview.com | OVH SAS | FR | suspicious |
Domain | IP | Reputation |
---|---|---|
www.xnview.com |
| suspicious |
ctldl.windowsupdate.com |
| whitelisted |
crl.identrust.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
r3.o.lencr.org |
| shared |
www.googletagmanager.com |
| whitelisted |
fonts.googleapis.com |
| whitelisted |
pagead2.googlesyndication.com |
| whitelisted |
ocsp.pki.goog |
| whitelisted |