| File name: | HSN21FE305X.EXE |
| Full analysis: | https://app.any.run/tasks/3bc6ccc4-76c5-445c-ad48-821c4e6ea5c5 |
| Verdict: | Malicious activity |
| Analysis date: | March 20, 2024, 10:53:30 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 959E6D23C48F43FA081396F599F0201D |
| SHA1: | BB717B07C96F02F078C00DE788CBF82B39CC0D6A |
| SHA256: | 9650A7AA4B23C0B46FF5B82DD7CAD824036BEE9209F3192A47B446940ADCCFE2 |
| SSDEEP: | 49152:ssQGh7KD20hrMvtXkM2td78DC9tbZO1U+WtRzt5fykQMBQxWnxFU/Zfdbyd8GoPs:5v7KDcYxFUBfdbyd8Pe33yXzeA0Mrzw5 |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2011:02:07 06:35:56+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 155648 |
| InitializedDataSize: | 151552 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x15061 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 5.23.0.0 |
| ProductVersionNumber: | 5.23.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Private build, Special build |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Japanese |
| CharacterSet: | Unicode |
| Comments: | Self Extractable Archive by EXEpress CX Copyright(C) 1998-2011 Web Technology Corp. http://www.webtech.co.jp/ |
| FileDescription: | Self Extractable Archive |
| FileVersion: | 5.23 |
| InternalName: | EPSFX |
| OriginalFileName: | EPSFX.EXE |
| ProductVersion: | 5.23 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 956 | "C:\Program Files\husen2K\Husen2K.exe" | C:\Program Files\husen2K\Husen2K.exe | — | HSN21FE305X.EXE.exe | |||||||||||
User: admin Company: ROTO Integrity Level: HIGH Description: 付箋紙21FE Exit code: 0 Version: 3.0.5.2911 Modules
| |||||||||||||||
| 3392 | "C:\Users\admin\AppData\Local\Temp\HSN21FE305X.EXE.exe" | C:\Users\admin\AppData\Local\Temp\HSN21FE305X.EXE.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Self Extractable Archive Exit code: 0 Version: 5.23 Modules
| |||||||||||||||
| 3992 | "C:\Users\admin\AppData\Local\Temp\HSN21FE305X.EXE.exe" | C:\Users\admin\AppData\Local\Temp\HSN21FE305X.EXE.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Self Extractable Archive Exit code: 3221226540 Version: 5.23 Modules
| |||||||||||||||
| (PID) Process: | (3392) HSN21FE305X.EXE.exe | Key: | HKEY_CURRENT_USER\Software\Husen2000\Config |
| Operation: | write | Name: | path |
Value: C:\Program Files\husen2K\ | |||
| (PID) Process: | (3392) HSN21FE305X.EXE.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\husen2000 |
| Operation: | write | Name: | DisplayName |
Value: •tⳎ†21FE | |||
| (PID) Process: | (3392) HSN21FE305X.EXE.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\husen2000 |
| Operation: | write | Name: | UninstallString |
Value: "C:\Program Files\husen2K\epuninst.exe" /s | |||
| (PID) Process: | (3392) HSN21FE305X.EXE.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\husen2000 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\husen2K\ | |||
| (PID) Process: | (3392) HSN21FE305X.EXE.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\husen2000 |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files\husen2K\Husen2K.exe,0 | |||
| (PID) Process: | (3392) HSN21FE305X.EXE.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\husen2000 |
| Operation: | write | Name: | Publisher |
Value: ROTO | |||
| (PID) Process: | (3392) HSN21FE305X.EXE.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\husen2000 |
| Operation: | write | Name: | HelpLink |
Value: http://www.roto21.net/husen/index.html | |||
| (PID) Process: | (956) Husen2K.exe | Key: | HKEY_CURRENT_USER\Software\Husen2000\Config |
| Operation: | write | Name: | PATH |
Value: C:\Program Files\husen2K\ | |||
| (PID) Process: | (956) Husen2K.exe | Key: | HKEY_CURRENT_USER\Software\Husen2000\Config |
| Operation: | write | Name: | MultiUser |
Value: 1 | |||
| (PID) Process: | (956) Husen2K.exe | Key: | HKEY_CURRENT_USER\Software\Husen2000\Config |
| Operation: | write | Name: | UseNetwork |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3392 | HSN21FE305X.EXE.exe | C:\Program Files\husen2K\FAQ.txt | text | |
MD5:BD350DC0C51E02728A26E717515A0796 | SHA256:E6EA0F70E20DBB85FAC0523703BDF227F68639D8704375B3C2B6C4F19D60C01B | |||
| 3392 | HSN21FE305X.EXE.exe | C:\Program Files\husen2K\History.txt | text | |
MD5:15FEEECC04D1726C25CE2EAC99DDC295 | SHA256:5E859770C75DD7E3F6C5B492FC625FE4A3A598FB380C06F664CCE93B0877F30C | |||
| 3392 | HSN21FE305X.EXE.exe | C:\Users\admin\AppData\Local\Temp\cabBF34.tmp | executable | |
MD5:93B72C947554A7CF084F6C8520936275 | SHA256:AB99FBBC47A664CDF04325BABD2259657B25DE614E43077989DE27408E82DF2E | |||
| 3392 | HSN21FE305X.EXE.exe | C:\Program Files\husen2K\epuninst.exe | compressed | |
MD5:0BF8B269DA5203D8D1DDB319F3151E5A | SHA256:C723F7AD4D6BDE8AFF4F5CADD15D9D50C5AB47AE4D85E4089B80D3E89B96756F | |||
| 3392 | HSN21FE305X.EXE.exe | C:\Program Files\husen2K\HUSEN2K.CHM | chm | |
MD5:268CD8FFFBAD2C145181C5D4AC04BA41 | SHA256:572474AD6EDAF107C0849635BA32CB970FB5653112267B09B010826A592FB669 | |||
| 3392 | HSN21FE305X.EXE.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\•tⳎ†21FE\•tⳎ†21.lnk | lnk | |
MD5:97B918AF017767D771F6F2795BC886C3 | SHA256:83AB8E7428E5642509F2F3865D5CC6C42C275D05432277E47AEAD9A9D3AA1C29 | |||
| 3392 | HSN21FE305X.EXE.exe | C:\Program Files\husen2K\Husen2K.exe | executable | |
MD5:00013663C589F00353DFC1B0AF5E47BA | SHA256:E1BE961A925A3FCF6DD772523A88C6D86DE6112D4C966B6E5E16FF24B1B6B723 | |||
| 3392 | HSN21FE305X.EXE.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\•tⳎ†21FE\•tⳎ†21ƒwƒ‹ƒv.lnk | lnk | |
MD5:79885A974E27FFF9F2554CD0FBF443FC | SHA256:769252CFDF61368B160B51EF370391AD705F4E87CFDC0335F2D3646814756D59 | |||
| 3392 | HSN21FE305X.EXE.exe | C:\Program Files\husen2K\husen2k.exe.manifest | xml | |
MD5:44A55D2253AEE809F0C00CFEA3190955 | SHA256:BC2FC21DA9263AC73CBA88465D0AE3D187F3A8BFE346401580E8A39145C1930D | |||
| 3392 | HSN21FE305X.EXE.exe | C:\Program Files\husen2K\README.TXT | text | |
MD5:93EC7A5E5C68950773B5C9703968236D | SHA256:558574DB33C930CEACA93D2EF389556F21F4CBB4CAC359410121BD5E82144FAF | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |