| File name: | bit_che_3_5_50_install.exe |
| Full analysis: | https://app.any.run/tasks/a18e6b0e-9590-4c09-9b70-22ef68dac2b3 |
| Verdict: | Malicious activity |
| Analysis date: | March 03, 2024, 17:52:15 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | C66C9733EC0DA702EF05FA1B8C47F623 |
| SHA1: | 8D77FE9AF010028DBFA2FA9957D16A16FB8B064C |
| SHA256: | 905BB4D2DC1D5C1598E2EF16462A75937322CF03C6F28B81E77F9A87AE10F173 |
| SSDEEP: | 98304:S6mXYmJDVtia0Z3Epw4ccNX+WIuLYwTGqI078ep5rN/QdSjeoJC/Iw9e0YlvQH+1:DRkBYpUd |
| .exe | | | Inno Setup installer (74.3) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (9.6) |
| .scr | | | Windows screen saver (8.8) |
| .exe | | | Win32 Executable (generic) (3) |
| .exe | | | Win16/32 Executable Delphi generic (1.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:19 22:22:17+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 40448 |
| InitializedDataSize: | 118784 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xa5f8 |
| OSVersion: | 1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.5.50.0 |
| ProductVersionNumber: | 3.5.50.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Convivea Inc. |
| FileDescription: | Bit Che Installer |
| FileVersion: | 3.5.50 |
| LegalCopyright: | |
| ProductName: | Bit Che |
| ProductVersion: | 3.5 build 50 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 864 | "C:\Windows\system32\regsvr32.exe" /s "C:\Windows\system32\mscomctl.OCX" | C:\Windows\System32\regsvr32.exe | — | bit_che_3_5_50_install.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1392 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4064 --field-trial-handle=1352,i,4255289628856376549,3796938189763264568,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1696 | "C:\Program Files\Bit Che\Bit_Che.exe" | C:\Program Files\Bit Che\Bit_Che.exe | — | bit_che_3_5_50_install.tmp | |||||||||||
User: admin Company: Convivea, Inc. Integrity Level: MEDIUM Description: Bit Che -- a fast search tool Exit code: 0 Version: 3.05.0050 Modules
| |||||||||||||||
| 1812 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=25 --mojo-platform-channel-handle=672 --field-trial-handle=1352,i,4255289628856376549,3796938189763264568,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1976 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1336 --field-trial-handle=1352,i,4255289628856376549,3796938189763264568,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2156 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1300 --field-trial-handle=1352,i,4255289628856376549,3796938189763264568,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2376 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=3868 --field-trial-handle=1352,i,4255289628856376549,3796938189763264568,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2380 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=entity_extraction_service.mojom.Extractor --lang=en-US --service-sandbox-type=entity_extraction --onnx-enabled-for-ee --mojo-platform-channel-handle=4032 --field-trial-handle=1352,i,4255289628856376549,3796938189763264568,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2432 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2224 --field-trial-handle=1352,i,4255289628856376549,3796938189763264568,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2564 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2244 --field-trial-handle=1352,i,4255289628856376549,3796938189763264568,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (3944) bit_che_3_5_50_install.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 680F000028E4D38D936DDA01 | |||
| (PID) Process: | (3944) bit_che_3_5_50_install.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: 2C2BD57701D256CCA7F84184E3BB3F5F79965599AA0B8785A0D2840E4776C13C | |||
| (PID) Process: | (3944) bit_che_3_5_50_install.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (3944) bit_che_3_5_50_install.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Users\admin\AppData\Roaming\Convivea\Bit_Che\3\zlibwapi.dll | |||
| (PID) Process: | (3944) bit_che_3_5_50_install.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFilesHash |
Value: B4D2EED806FDFF0D0D2C46F575EF5F24529593DC7537E783F9F1106967CD0B78 | |||
| (PID) Process: | (3944) bit_che_3_5_50_install.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs |
| Operation: | write | Name: | C:\Windows\system32\mscomctl.OCX |
Value: 2 | |||
| (PID) Process: | (864) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCDB0DF2-FD1A-4856-80BC-32929D8359B7} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (864) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{CCDB0DF2-FD1A-4856-80BC-32929D8359B7}\InprocServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Apartment | |||
| (PID) Process: | (864) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{979127D3-7D01-4FDE-AF65-A698091468AF} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (864) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{979127D3-7D01-4FDE-AF65-A698091468AF}\InprocServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Apartment | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3944 | bit_che_3_5_50_install.tmp | C:\Users\admin\AppData\Roaming\Convivea\Bit_Che\3\scripts\default\is-IJJGO.tmp | ini | |
MD5:28DA9E17C823E9F613B925BDB10FD30B | SHA256:81924335A46BBFA18DB3561A619CC505AA7FAB01E9CFC5ED8B31DB07BBC89E52 | |||
| 3944 | bit_che_3_5_50_install.tmp | C:\Users\admin\AppData\Roaming\Convivea\Bit_Che\3\scripts\default\is-3TAQ8.tmp | ini | |
MD5:6CA956066DB7748EB6A71E41C3A9F85A | SHA256:0AB811FAA5AC087E577C6740575EE2FADC47039784C60B8265E859B3A0735D61 | |||
| 3944 | bit_che_3_5_50_install.tmp | C:\Program Files\Bit Che\unins000.exe | executable | |
MD5:B980B067D09F384F0CFB8369E7AEC5B3 | SHA256:4E964EAFAE87C52370C4EF678E076EB9B04EE98E3E2833F84D80D9ADE2F87863 | |||
| 3944 | bit_che_3_5_50_install.tmp | C:\Users\admin\AppData\Roaming\Convivea\Bit_Che\3\is-DUGF9.tmp | executable | |
MD5:C18A773139A0BD79DBE94E338E9AB29B | SHA256:AF5F8302C1B3B105A7F17A262B806975243EEC77050642D9B7D71BE2CCDF0B6F | |||
| 3944 | bit_che_3_5_50_install.tmp | C:\Users\admin\AppData\Roaming\Convivea\Bit_Che\3\zlibwapi.dll | executable | |
MD5:C18A773139A0BD79DBE94E338E9AB29B | SHA256:AF5F8302C1B3B105A7F17A262B806975243EEC77050642D9B7D71BE2CCDF0B6F | |||
| 3944 | bit_che_3_5_50_install.tmp | C:\Program Files\Bit Che\is-RMSSN.tmp | executable | |
MD5:B980B067D09F384F0CFB8369E7AEC5B3 | SHA256:4E964EAFAE87C52370C4EF678E076EB9B04EE98E3E2833F84D80D9ADE2F87863 | |||
| 3944 | bit_che_3_5_50_install.tmp | C:\Windows\system32\is-6CGL9.tmp | executable | |
MD5:E52859FCB7A827CACFCE7963184C7D24 | SHA256:45B6EEF5BBF223CF8FF78F5014B68A72F0BC2CCEAED030DECE0A1ABACF88F1F8 | |||
| 3944 | bit_che_3_5_50_install.tmp | C:\Users\admin\AppData\Roaming\Convivea\Bit_Che\3\scripts\bcs.default.ini | text | |
MD5:A4DED56AEE97C12A6C91E52B144166B5 | SHA256:2EF261BB37A68D584E0ECE5362CB93DC89241460A25082CFBA7F4FFBB51767FF | |||
| 3944 | bit_che_3_5_50_install.tmp | C:\Users\admin\AppData\Roaming\Convivea\Bit_Che\3\scripts\is-UT8DK.tmp | text | |
MD5:A4DED56AEE97C12A6C91E52B144166B5 | SHA256:2EF261BB37A68D584E0ECE5362CB93DC89241460A25082CFBA7F4FFBB51767FF | |||
| 3944 | bit_che_3_5_50_install.tmp | C:\Windows\System32\mscomctl.OCX | executable | |
MD5:E52859FCB7A827CACFCE7963184C7D24 | SHA256:45B6EEF5BBF223CF8FF78F5014B68A72F0BC2CCEAED030DECE0A1ABACF88F1F8 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2156 | msedge.exe | GET | 301 | 185.15.59.224:80 | http://en.wikipedia.org/wiki/Comparison_of_BitTorrent_software | unknown | — | — | unknown |
2156 | msedge.exe | GET | 200 | 45.79.74.161:80 | http://www.convivea.com/torrent_client.php | unknown | html | 100 b | unknown |
2156 | msedge.exe | GET | 200 | 104.18.38.233:80 | http://crt.sectigo.com/SectigoRSADomainValidationSecureServerCA.crt | unknown | binary | 1.52 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4004 | msedge.exe | 239.255.255.250:1900 | — | — | — | unknown |
2156 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
2156 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2156 | msedge.exe | 45.79.74.161:80 | www.convivea.com | Linode, LLC | US | unknown |
2156 | msedge.exe | 45.79.74.161:443 | www.convivea.com | Linode, LLC | US | unknown |
2156 | msedge.exe | 104.18.38.233:80 | crt.sectigo.com | CLOUDFLARENET | — | shared |
2156 | msedge.exe | 96.16.49.209:443 | www.bing.com | Akamai International B.V. | SE | unknown |
Domain | IP | Reputation |
|---|---|---|
www.convivea.com |
| unknown |
edge.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
convivea.com |
| unknown |
crt.sectigo.com |
| whitelisted |
www.bing.com |
| whitelisted |
img.photobucket.com |
| whitelisted |
www.danasoft.com |
| unknown |
www.speedtest.net |
| whitelisted |
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com |
| whitelisted |