| File name: | RealUI-Installer.exe |
| Full analysis: | https://app.any.run/tasks/8465f248-fd09-4b81-806e-18b1eb5d35ae |
| Verdict: | Malicious activity |
| Analysis date: | February 18, 2022, 22:17:07 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386 Mono/.Net assembly, for MS Windows |
| MD5: | 727E35715978D244D9FC67C11FB90152 |
| SHA1: | 460A00C15BED5F0CCE8EAE39B8DB1ECA737C413B |
| SHA256: | 97D32C688212D262D6124F186A639FF702A863C8D58CEFCB9929F1C04995CBEB |
| SSDEEP: | 49152:SkTZu5oHzb9usgNmRKVrgU2QVYTjdrWFzOEYe:d4oHdVyPV4TpWFzOf |
| .exe | | | Win32 Executable MS Visual C++ (generic) (64.5) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (13.6) |
| .exe | | | Win32 Executable (generic) (9.3) |
| .exe | | | Win16/32 Executable Delphi generic (4.2) |
| .exe | | | Generic Win/DOS Executable (4.1) |
| Subsystem: | Windows GUI |
|---|---|
| SubsystemVersion: | 6 |
| ImageVersion: | - |
| OSVersion: | 4 |
| EntryPoint: | 0x1c85f0 |
| UninitializedDataSize: | - |
| InitializedDataSize: | 23040 |
| CodeSize: | 844288 |
| LinkerVersion: | 48 |
| PEType: | PE32 |
| TimeStamp: | 2040:05:26 22:34:59+02:00 |
| MachineType: | Intel 386 or later, and compatibles |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 20-Apr-1904 14:06:43 |
| Comments: | RealUI Setup |
| CompanyName: | Reality Cheats |
| FileDescription: | RealUI Setup |
| FileVersion: | 1.0.0.0 |
| InternalName: | RealUI-Installer.exe |
| LegalCopyright: | Copyright © Reality Cheats INC. 2021 |
| LegalTrademarks: | Reality Cheats |
| OriginalFilename: | RealUI-Installer.exe |
| ProductName: | RealUI |
| ProductVersion: | 1.0.0.0 |
| Assembly Version: | 1.0.0.0 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x00000080 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 20-Apr-1904 14:06:43 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
0tL8@0``<\xe0\x0c | 0x00002000 | 0x000CE03C | 0x00000000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 0 |
XZj%#[z)\x1aK\x0f | 0x000D2000 | 0x000F4B1A | 0x00000000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 0 |
ppnrSadzdK\x1d | 0x001C8000 | 0x001D4B64 | 0x001D4C00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.94524 |
tB.iUGVd(V | 0x0039E000 | 0x00005628 | 0x00005800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.81991 |
&<<T*^EG\x0c | 0x003A4000 | 0x0000000C | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 0.122276 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.20735 | 3840 | UNKNOWN | UNKNOWN | RT_MANIFEST |
32512 | 1.91924 | 20 | UNKNOWN | UNKNOWN | RT_GROUP_ICON |
mscoree.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 748 | cacls C:\Windows\system32\drivers\etc\hosts /P Everyone:f | C:\Windows\system32\cacls.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Control ACLs Program Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1612 | "powershell" -Command "Add-MpPreference -ExclusionPath 'C:\Users\admin\AppData\Local\B30E0F0', 'C:\Users\admin\AppData\Local\Temp\', '\\localhost\C$\Users\admin\AppData\Local\B30E0F0', '\\localhost\C$\Users\admin\AppData\Local\Temp'" | C:\Windows\System32\WindowsPowerShell\v1.0\powershell.exe | — | RealUI-Installer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows PowerShell Exit code: 1 Version: 10.0.14409.1005 (rs1_srvoob.161208-1155) Modules
| |||||||||||||||
| 1888 | "C:\Windows\Temp\{F2E666BE-7521-4F43-9E1D-830144844882}\.be\VC_redist.x86.exe" -q -burn.elevated BurnPipe.{59889C6F-2C8C-42EB-A0C4-F0801EEC9BC1} {9C9C1FF5-2A84-4F7E-9C4C-BD89FF9EE95A} 3428 | C:\Windows\Temp\{F2E666BE-7521-4F43-9E1D-830144844882}\.be\VC_redist.x86.exe | vcredist_x86.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.31.31103 Exit code: 3010 Version: 14.31.31103.0 Modules
| |||||||||||||||
| 1984 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft� Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2044 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows� installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2068 | "C:\ProgramData\Package Cache\{49697869-be8e-427d-81a0-c334d1d14950}\VC_redist.x86.exe" -uninstall -quiet -burn.related.upgrade -burn.ancestors={41d7b770-418a-43b7-95a5-f925fff05789} -burn.filehandle.self=876 -burn.embedded BurnPipe.{A0446535-8CD8-4558-A7EE-76A495DB1E3B} {8989916B-BCC4-4DF1-A874-DBF445B74651} 1888 | C:\ProgramData\Package Cache\{49697869-be8e-427d-81a0-c334d1d14950}\VC_redist.x86.exe | — | VC_redist.x86.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 Exit code: 0 Version: 14.21.27702.2 Modules
| |||||||||||||||
| 2180 | "C:\Users\admin\AppData\Local\Temp\vcredist_x86.exe" /install /quiet /norestart | C:\Users\admin\AppData\Local\Temp\vcredist_x86.exe | RealUI-Installer.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Visual C++ 2015-2022 Redistributable (x86) - 14.31.31103 Exit code: 3010 Version: 14.31.31103.0 Modules
| |||||||||||||||
| 2184 | "C:\Users\admin\AppData\Local\Temp\RealUI-Installer.exe" | C:\Users\admin\AppData\Local\Temp\RealUI-Installer.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Reality Cheats Integrity Level: MEDIUM Description: RealUI Setup Exit code: 3221226540 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2344 | C:\Windows\system32\cmd.exe /S /D /c" echo y" | C:\Windows\system32\cmd.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2352 | "C:\ProgramData\Package Cache\{49697869-be8e-427d-81a0-c334d1d14950}\VC_redist.x86.exe" -q -burn.elevated BurnPipe.{27804676-F73E-43A8-AB5F-E73941E04727} {1E15384B-92E5-4B7B-9958-8261098DAC77} 3172 | C:\ProgramData\Package Cache\{49697869-be8e-427d-81a0-c334d1d14950}\VC_redist.x86.exe | VC_redist.x86.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Visual C++ 2015-2019 Redistributable (x86) - 14.21.27702 Exit code: 0 Version: 14.21.27702.2 Modules
| |||||||||||||||
| (PID) Process: | (3736) RealUI-Installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RealUI-Installer_RASAPI32 |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (3736) RealUI-Installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RealUI-Installer_RASAPI32 |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (3736) RealUI-Installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RealUI-Installer_RASAPI32 |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (3736) RealUI-Installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RealUI-Installer_RASAPI32 |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
| (PID) Process: | (3736) RealUI-Installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RealUI-Installer_RASAPI32 |
| Operation: | write | Name: | MaxFileSize |
Value: 1048576 | |||
| (PID) Process: | (3736) RealUI-Installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RealUI-Installer_RASAPI32 |
| Operation: | write | Name: | FileDirectory |
Value: %windir%\tracing | |||
| (PID) Process: | (3736) RealUI-Installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RealUI-Installer_RASMANCS |
| Operation: | write | Name: | EnableFileTracing |
Value: 0 | |||
| (PID) Process: | (3736) RealUI-Installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RealUI-Installer_RASMANCS |
| Operation: | write | Name: | EnableConsoleTracing |
Value: 0 | |||
| (PID) Process: | (3736) RealUI-Installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RealUI-Installer_RASMANCS |
| Operation: | write | Name: | FileTracingMask |
Value: | |||
| (PID) Process: | (3736) RealUI-Installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\RealUI-Installer_RASMANCS |
| Operation: | write | Name: | ConsoleTracingMask |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3428 | vcredist_x86.exe | C:\Windows\Temp\{F2E666BE-7521-4F43-9E1D-830144844882}\.ba\thm.xml | xml | |
MD5:F62729C6D2540015E072514226C121C7 | SHA256:F13BAE0EC08C91B4A315BB2D86EE48FADE597E7A5440DCE6F751F98A3A4D6916 | |||
| 3736 | RealUI-Installer.exe | C:\Users\admin\AppData\Local\Temp\vcredist_x86.exe | executable | |
MD5:D3B594464F2312CDE31AF3F2AA516F9E | SHA256:B7AE307237F869E09F7413691A2CD1944357B5CEE28049C0A0D3430B47BB3EDC | |||
| 1612 | powershell.exe | C:\Users\admin\AppData\Local\Temp\n4tk35kg.rwc.psm1 | binary | |
MD5:C4CA4238A0B923820DCC509A6F75849B | SHA256:— | |||
| 3428 | vcredist_x86.exe | C:\Windows\Temp\{F2E666BE-7521-4F43-9E1D-830144844882}\.ba\1028\license.rtf | text | |
MD5:2B063D92663595DFE4781AE687A03D86 | SHA256:44C76290F7A2E45940E8338912FEB49BCF4E071CFA85D2D34762857743ACBC8D | |||
| 3428 | vcredist_x86.exe | C:\Windows\Temp\{F2E666BE-7521-4F43-9E1D-830144844882}\.ba\1031\thm.wxl | xml | |
MD5:561F3F32DB2453647D1992D4D932E872 | SHA256:8E0DCA6E085744BFCBFF46F7DCBCFA6FBD722DFA52013EE8CEEAF682D7509581 | |||
| 3428 | vcredist_x86.exe | C:\Windows\Temp\{F2E666BE-7521-4F43-9E1D-830144844882}\.ba\1029\thm.wxl | xml | |
MD5:16343005D29EC431891B02F048C7F581 | SHA256:07FB3EC174F25DFBE532D9D739234D9DFDA8E9D34F01FE660C5B4D56989FA779 | |||
| 3428 | vcredist_x86.exe | C:\Windows\Temp\{F2E666BE-7521-4F43-9E1D-830144844882}\.ba\1031\license.rtf | text | |
MD5:2DDCA2866D76C850F68ACDFDB696D6DE | SHA256:28F63BAD9C2960395106011761993049546607F8A850D344D6A54042176BF03F | |||
| 3428 | vcredist_x86.exe | C:\Windows\Temp\{F2E666BE-7521-4F43-9E1D-830144844882}\.ba\1036\thm.wxl | xml | |
MD5:7B46AE8698459830A0F9116BC27DE7DF | SHA256:704DDF2E60C1F292BE95C7C79EE48FE8BA8534CEB7CCF9A9EA68B1AD788AE9D4 | |||
| 1612 | powershell.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\PowerShell\StartupProfileData-NonInteractive | dbf | |
MD5:446DD1CF97EABA21CF14D03AEBC79F27 | SHA256:A7DE5177C68A64BD48B36D49E2853799F4EBCFA8E4761F7CC472F333DC5F65CF | |||
| 2180 | vcredist_x86.exe | C:\Windows\Temp\{4128C8C4-8248-40E5-B64F-D986D97740A1}\.cr\vcredist_x86.exe | executable | |
MD5:0082D66B4BD5A3F6254DD749FE372CB6 | SHA256:C78B97480214FD42F989EB3B2DA72E325E1F6855ADB7D4660DEECA6CA63D5025 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
3736 | RealUI-Installer.exe | 185.199.110.133:443 | raw.githubusercontent.com | GitHub, Inc. | NL | malicious |
— | — | 192.168.100.2:53 | — | — | — | whitelisted |
3736 | RealUI-Installer.exe | 23.12.134.45:443 | aka.ms | Akamai Technologies, Inc. | US | suspicious |
3736 | RealUI-Installer.exe | 68.232.34.200:443 | download.visualstudio.microsoft.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
www.microsoft.com |
| whitelisted |
raw.githubusercontent.com |
| shared |
aka.ms |
| whitelisted |
download.visualstudio.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
msiexec.exe | Failed to release Service
|