| File name: | 98ac8964b677346d7f5b012327eaddf5102255f1abf256e4951893fbc5759816.exe |
| Full analysis: | https://app.any.run/tasks/61d668de-729e-4081-a55a-7d2e0de49bb2 |
| Verdict: | Malicious activity |
| Analysis date: | February 17, 2024, 19:26:20 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 12ED79692BF630627105C30D92C76FD3 |
| SHA1: | A6BB689316D87268559D38DFB5340BD4B6F01423 |
| SHA256: | 98AC8964B677346D7F5B012327EADDF5102255F1ABF256E4951893FBC5759816 |
| SSDEEP: | 98304:qO7UY7BGRmoqWseW/sygVXIGdPdr2CNkcfPVK9Jk0qnIqkVHZcb+LmYPpfrU5sGf:9u3bZ |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:11:15 13:33:00+00:00 |
| ImageFileCharacteristics: | Executable, Large address aware, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 14.37 |
| CodeSize: | 2604032 |
| InitializedDataSize: | 1226240 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1f0aa6 |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 5.8.2.0 |
| ProductVersionNumber: | 5.8.2.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | Debug |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | vuw cuvi |
| FileDescription: | AppGbi Installer |
| FileVersion: | 5.8.2 |
| InternalName: | installer_b |
| LegalCopyright: | Copyright (C) 2024 vuw cuvi |
| OriginalFileName: | installer_b.exe |
| ProductName: | AppGbi |
| ProductVersion: | 5.8.2 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1176 | "C:\Windows\system32\msiexec.exe" /i "C:\Users\admin\AppData\Roaming\vuw cuvi\AppGbi 5.8.2\install\02BAB42\installer_b.msi" AI_SETUPEXEPATH=C:\Users\admin\AppData\Local\Temp\98ac8964b677346d7f5b012327eaddf5102255f1abf256e4951893fbc5759816.exe SETUPEXEDIR=C:\Users\admin\AppData\Local\Temp\ EXE_CMD_LINE="/exenoupdates /forcecleanup /wintime 1708196654 " AI_EUIMSI="" | C:\Windows\SysWOW64\msiexec.exe | — | 98ac8964b677346d7f5b012327eaddf5102255f1abf256e4951893fbc5759816.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2248 | "C:\Users\admin\AppData\Local\Temp\98ac8964b677346d7f5b012327eaddf5102255f1abf256e4951893fbc5759816.exe" | C:\Users\admin\AppData\Local\Temp\98ac8964b677346d7f5b012327eaddf5102255f1abf256e4951893fbc5759816.exe | explorer.exe | ||||||||||||
User: admin Company: vuw cuvi Integrity Level: MEDIUM Description: AppGbi Installer Exit code: 0 Version: 5.8.2 Modules
| |||||||||||||||
| (PID) Process: | (2248) 98ac8964b677346d7f5b012327eaddf5102255f1abf256e4951893fbc5759816.exe | Key: | HKEY_CURRENT_USER\Software\AiTemp |
| Operation: | delete value | Name: | C__Users_admin_AppData_Local_Temp_98ac8964b677346d7f5b012327eaddf5102255f1abf256e4951893fbc5759816.exe |
Value: | |||
| (PID) Process: | (2248) 98ac8964b677346d7f5b012327eaddf5102255f1abf256e4951893fbc5759816.exe | Key: | HKEY_CURRENT_USER\Software\AiTemp |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (2248) 98ac8964b677346d7f5b012327eaddf5102255f1abf256e4951893fbc5759816.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\RunOnce |
| Operation: | delete value | Name: | C__Users_admin_AppData_Local_Temp_98ac8964b677346d7f5b012327eaddf5102255f1abf256e4951893fbc5759816.exe |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2248 | 98ac8964b677346d7f5b012327eaddf5102255f1abf256e4951893fbc5759816.exe | C:\Users\admin\AppData\Roaming\vuw cuvi\AppGbi 5.8.2\install\holder0.aiph | — | |
MD5:— | SHA256:— | |||
| 2248 | 98ac8964b677346d7f5b012327eaddf5102255f1abf256e4951893fbc5759816.exe | C:\Users\admin\AppData\Local\Temp\MSI9BA2.LOG | — | |
MD5:— | SHA256:— | |||
| 2248 | 98ac8964b677346d7f5b012327eaddf5102255f1abf256e4951893fbc5759816.exe | C:\Users\admin\AppData\Roaming\vuw cuvi\AppGbi 5.8.2\install\02BAB42\installer_b.msi | executable | |
MD5:2C8F384AB1330F787958A79E073ECA57 | SHA256:64B4FA4A0CA09BB84EE4DA2060E370BDE6DB1524E84387BC14BDD88B0C2140FF | |||
| 2248 | 98ac8964b677346d7f5b012327eaddf5102255f1abf256e4951893fbc5759816.exe | C:\Users\admin\AppData\Roaming\vuw cuvi\AppGbi 5.8.2\install\02BAB42\gpgtar.exe | executable | |
MD5:A33215C3311B5819D6F12400B49333AB | SHA256:45D80A39499A2DBFA3352169A7FB78492F7A253CA3EC6B0A6F61825B7C3A235D | |||
| 2248 | 98ac8964b677346d7f5b012327eaddf5102255f1abf256e4951893fbc5759816.exe | C:\Users\admin\AppData\Roaming\vuw cuvi\AppGbi 5.8.2\install\02BAB42\gpgsm.exe | executable | |
MD5:C1BB0E52C1E07B706804C5262207852A | SHA256:E7D50BFC7EA031E4438B227E5F3C1C231AAC831CCB709B08F6D4E3106D448B5E | |||
| 2248 | 98ac8964b677346d7f5b012327eaddf5102255f1abf256e4951893fbc5759816.exe | C:\Users\admin\AppData\Roaming\vuw cuvi\AppGbi 5.8.2\install\02BAB42\dirmngr.exe | executable | |
MD5:2E94C3258F7863B6BF4EA937AA12A144 | SHA256:2CC38C48EB742A28A4562BC62C9DCA7EF525A62164752135B45A4CFF89064E6E | |||
| 2248 | 98ac8964b677346d7f5b012327eaddf5102255f1abf256e4951893fbc5759816.exe | C:\Users\admin\AppData\Roaming\vuw cuvi\AppGbi 5.8.2\install\02BAB42\gnupg.exe | executable | |
MD5:E7A712A20275825B93D9B86464755870 | SHA256:4E6F3F339DED64578816DFC3DC1D74BA198F7D698109C15AC658BB9891E2EA9E | |||
| 2248 | 98ac8964b677346d7f5b012327eaddf5102255f1abf256e4951893fbc5759816.exe | C:\Users\admin\AppData\Roaming\vuw cuvi\AppGbi 5.8.2\install\02BAB42\api-ms-win-core-namedpipe-l1-1-0.dll | executable | |
MD5:CFF476BB11CC50C41D8D3BF5183D07EC | SHA256:B57E70798AF248F91C8C46A3F3B2952EFFAE92CA8EF9640C952467BC6726F363 | |||
| 2248 | 98ac8964b677346d7f5b012327eaddf5102255f1abf256e4951893fbc5759816.exe | C:\Users\admin\AppData\Roaming\vuw cuvi\AppGbi 5.8.2\install\02BAB42\gpg-wks-client.exe | executable | |
MD5:EE38AB14557B765C80856531582F4F89 | SHA256:4B0DFCC928A127B65928F6A941823B0E43C4CF08E2792E1E054A3886D51D8005 | |||
| 2248 | 98ac8964b677346d7f5b012327eaddf5102255f1abf256e4951893fbc5759816.exe | C:\Users\admin\AppData\Roaming\vuw cuvi\AppGbi 5.8.2\install\02BAB42\stylers.model.xml | xml | |
MD5:343B8F55F376E88674733286D027F834 | SHA256:F002B36E70F0FB159885C21FA6E6395176CD50A254201A94CBED756D9843FA9A | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2612 | powershell.exe | GET | 301 | 172.67.153.234:80 | http://aprel88.com/getLicenseInfo.php?requirements=time&checkMethod=2 | unknown | — | — | unknown |
2612 | powershell.exe | GET | 200 | 23.32.238.131:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?340edf81c1664760 | unknown | compressed | 65.2 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1220 | svchost.exe | 239.255.255.250:3702 | — | — | — | unknown |
352 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2612 | powershell.exe | 172.67.153.234:80 | aprel88.com | CLOUDFLARENET | US | unknown |
2612 | powershell.exe | 172.67.153.234:443 | aprel88.com | CLOUDFLARENET | US | unknown |
2612 | powershell.exe | 23.32.238.131:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
aprel88.com |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
2612 | powershell.exe | Not Suspicious Traffic | ET INFO Windows Powershell User-Agent Usage |