File name: | Ableton Suite 10.1 (x64) Multilingual + Keygen[BabuPC].exe |
Full analysis: | https://app.any.run/tasks/cc00d806-c971-490a-8956-8e12143cffa0 |
Verdict: | Malicious activity |
Threats: | Ficker Stealer is a malware that steals passwords, files, credit card details, and other types of sensitive information on Windows systems. It is most often distributed via phishing emails and can perform keylogging, process injection, and browser tracking. |
Analysis date: | January 11, 2021, 21:01:54 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 0C8B4806DA01A65EACBC215EEB695398 |
SHA1: | 1EFABA5A351C7314B84A6637769ADA8AF61C0B27 |
SHA256: | 9972E82055DDB1DE629485D923B38767CAF5F6CA99C91B1B0DCD78DFDA9BCF8B |
SSDEEP: | 24576:ec/OmpmztxR6S4Bz/YPbF2Q2Ma2XTJfSV/hOJp+g+Msam/+ppnYCFRmYe+vpQ/:ecGmCD/4Bz/YPbtpKUJfbA+MCFRmb+B |
.exe | | | Win32 Executable Borland Delphi 7 (90.8) |
---|---|---|
.exe | | | InstallShield setup (5.8) |
.scr | | | Windows screen saver (1.7) |
.exe | | | Win32 Executable (generic) (0.6) |
.exe | | | Win16/32 Executable Delphi generic (0.2) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 1992:06:20 00:22:17+02:00 |
PEType: | PE32 |
LinkerVersion: | 2.25 |
CodeSize: | 727040 |
InitializedDataSize: | 418816 |
UninitializedDataSize: | - |
EntryPoint: | 0xb2600 |
OSVersion: | 4 |
ImageVersion: | - |
SubsystemVersion: | 4 |
Subsystem: | Windows GUI |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 19-Jun-1992 22:22:17 |
Detected languages: |
|
Comments: | This installation was built with Inno Setup. |
CompanyName: | The GIMP Team |
FileDescription: | GIMP Setup |
FileVersion: | 2.10.22 |
LegalCopyright: | - |
OriginalFileName: | - |
ProductName: | GIMP |
ProductVersion: | 2.10.22 |
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x0050 |
Pages in file: | 0x0002 |
Relocations: | 0x0000 |
Size of header: | 0x0004 |
Min extra paragraphs: | 0x000F |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x00B8 |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0000 |
Overlay number: | 0x001A |
OEM identifier: | 0x0000 |
OEM information: | 0x0000 |
Address of NE header: | 0x00000100 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 10 |
Time date stamp: | 19-Jun-1992 22:22:17 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
CODE | 0x00001000 | 0x000B1678 | 0x000B1800 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.3431 |
DATA | 0x000B3000 | 0x000024B0 | 0x00002600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.86465 |
BSS | 0x000B6000 | 0x00000DF5 | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.idata | 0x000B7000 | 0x000028EE | 0x00002A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.9405 |
.tls | 0x000BA000 | 0x00000010 | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rdata | 0x000BB000 | 0x00000018 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED | 0.195201 |
.reloc | 0x0011E000 | 0x0008F000 | 0x0008F000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 7.95728 |
0x000C9000 | 0x00054F44 | 0x00055000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_SHARED | 7.34801 | |
FindingwrS\x02 | 0x001AD000 | 0x00025372 | 0x00024600 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 0 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 2.56791 | 1412 | Latin 1 / Western European | Process Default Language | RT_VERSION |
2 | 3.32022 | 744 | Latin 1 / Western European | UNKNOWN | RT_ICON |
3 | 3.11493 | 488 | Latin 1 / Western European | UNKNOWN | RT_ICON |
4 | 3.08229 | 296 | Latin 1 / Western European | UNKNOWN | RT_ICON |
5 | 4.51548 | 3752 | Latin 1 / Western European | UNKNOWN | RT_ICON |
6 | 4.29607 | 2216 | Latin 1 / Western European | UNKNOWN | RT_ICON |
7 | 3.77534 | 1736 | Latin 1 / Western European | UNKNOWN | RT_ICON |
8 | 2.67407 | 1384 | Latin 1 / Western European | UNKNOWN | RT_ICON |
9 | 7.90221 | 17959 | Latin 1 / Western European | UNKNOWN | RT_ICON |
10 | 3.43191 | 9640 | Latin 1 / Western European | UNKNOWN | RT_ICON |
kernel32.dll |
ole32.dll |
user32.dll |
version.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
2920 | "C:\Users\admin\AppData\Local\Temp\Ableton Suite 10.1 (x64) Multilingual + Keygen[BabuPC].exe" | C:\Users\admin\AppData\Local\Temp\Ableton Suite 10.1 (x64) Multilingual + Keygen[BabuPC].exe | — | explorer.exe | |||||||||||
User: admin Company: The GIMP Team Integrity Level: MEDIUM Description: GIMP Setup Exit code: 3221226540 Version: 2.10.22 Modules
| |||||||||||||||
3016 | "C:\Users\admin\AppData\Local\Temp\Ableton Suite 10.1 (x64) Multilingual + Keygen[BabuPC].exe" | C:\Windows\system32\calc.exe | Ableton Suite 10.1 (x64) Multilingual + Keygen[BabuPC].exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Calculator Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
3164 | "C:\Users\admin\AppData\Local\Temp\Ableton Suite 10.1 (x64) Multilingual + Keygen[BabuPC].exe" | C:\Users\admin\AppData\Local\Temp\Ableton Suite 10.1 (x64) Multilingual + Keygen[BabuPC].exe | explorer.exe | ||||||||||||
User: admin Company: The GIMP Team Integrity Level: HIGH Description: GIMP Setup Exit code: 0 Version: 2.10.22 Modules
|
(PID) Process: | (3016) calc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
(PID) Process: | (3016) calc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 1 | |||
(PID) Process: | (3016) calc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
(PID) Process: | (3016) calc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
Operation: | write | Name: | SavedLegacySettings |
Value: 46000000A5000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
(PID) Process: | (3016) calc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
Operation: | write | Name: | CachePrefix |
Value: | |||
(PID) Process: | (3016) calc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
(PID) Process: | (3016) calc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
(PID) Process: | (3016) calc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer |
Operation: | write | Name: | DisallowRun |
Value: 1 | |||
(PID) Process: | (3016) calc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun |
Operation: | write | Name: | 1 |
Value: 1.exe | |||
(PID) Process: | (3016) calc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Policies\Explorer\DisallowRun |
Operation: | write | Name: | 2 |
Value: irsetup.exe |
PID | Process | Filename | Type | |
---|---|---|---|---|
3016 | calc.exe | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\6Z2BCOUL\6T2CD9JL.txt | text | |
MD5:— | SHA256:— | |||
3016 | calc.exe | C:\ProgramData\krosqm.txt | text | |
MD5:— | SHA256:— |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
3016 | calc.exe | GET | 200 | 184.73.247.141:80 | http://api.ipify.org/?format=xml | US | text | 13 b | shared |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
3016 | calc.exe | 184.73.247.141:80 | api.ipify.org | Amazon.com, Inc. | US | suspicious |
3016 | calc.exe | 85.17.190.28:80 | — | LeaseWeb Netherlands B.V. | NL | malicious |
Domain | IP | Reputation |
---|---|---|
api.ipify.org |
| shared |
PID | Process | Class | Message |
---|---|---|---|
— | — | Potential Corporate Privacy Violation | ET POLICY External IP Lookup (ipify .org) |
— | — | A Network Trojan was detected | ET TROJAN Win32/Ficker Stealer Activity M3 |
— | — | A Network Trojan was detected | STEALER [PTsecurity] Ficker |
— | — | A Network Trojan was detected | ET TROJAN Win32/Ficker Stealer Activity M3 |
— | — | A Network Trojan was detected | STEALER [PTsecurity] Ficker |