| File name: | Install.exe |
| Full analysis: | https://app.any.run/tasks/e643f132-27cf-4b7f-812f-4b4ff82a9581 |
| Verdict: | Malicious activity |
| Analysis date: | May 20, 2022, 17:04:04 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Petite compressed, ACE self-extracting archive |
| MD5: | CD9566B81C030E2B7561E5C7F84A9075 |
| SHA1: | 9F56EB92177DF277C7A769205CEE6165D566432E |
| SHA256: | 9979E5C59F5F20AE75C1242DD9AFC6C5023632C3F1CE460CCCB21D8EB818886E |
| SSDEEP: | 12288:Mmmc/l/xXRqXXtMHnGVa2/Wj0IMOS+15wU5DRc7Nxhu4wLzqUSvGg0x:Nl/xXRqX94nfOk0rOSOD9ONAXTxxx |
| .dll | | | Win32 Dynamic Link Library (generic) (43.5) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (29.8) |
| .exe | | | Generic Win/DOS Executable (13.2) |
| .exe | | | DOS Executable Generic (13.2) |
| Subsystem: | Windows GUI |
|---|---|
| SubsystemVersion: | 4 |
| ImageVersion: | - |
| OSVersion: | 1 |
| EntryPoint: | 0x3b042 |
| UninitializedDataSize: | - |
| InitializedDataSize: | 75776 |
| CodeSize: | 83968 |
| LinkerVersion: | 2.25 |
| PEType: | PE32 |
| TimeStamp: | 1992:06:20 00:22:17+02:00 |
| MachineType: | Intel 386 or later, and compatibles |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2040 | "C:\Users\admin\AppData\Local\Temp\Install.exe" | C:\Users\admin\AppData\Local\Temp\Install.exe | — | Explorer.EXE | |||||||||||
User: admin Company: e-merge GmbH Integrity Level: MEDIUM Description: Sfx-Factory! Self-Extractor Exit code: 3221226540 Version: 2.1.0.0 Modules
| |||||||||||||||
| 3696 | "C:\Users\admin\AppData\Local\Temp\Install.exe" | C:\Users\admin\AppData\Local\Temp\Install.exe | Explorer.EXE | ||||||||||||
User: admin Company: e-merge GmbH Integrity Level: HIGH Description: Sfx-Factory! Self-Extractor Exit code: 0 Version: 2.1.0.0 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3696 | Install.exe | C:\program files\DivX_311alpha\DIVX_c32.ax | executable | |
MD5:— | SHA256:— | |||
| 3696 | Install.exe | C:\program files\DivX_311alpha\SetStereo.exe | executable | |
MD5:— | SHA256:— | |||
| 3696 | Install.exe | C:\program files\DivX_311alpha\DivX Site.url | text | |
MD5:— | SHA256:— | |||
| 3696 | Install.exe | C:\program files\DivX_311alpha\DivXc32f.dll | executable | |
MD5:— | SHA256:— | |||
| 3696 | Install.exe | C:\program files\DivX_311alpha\Register_DivX.exe | executable | |
MD5:— | SHA256:— | |||
| 3696 | Install.exe | C:\program files\DivX_311alpha\DivXc32.dll | executable | |
MD5:— | SHA256:— | |||
| 3696 | Install.exe | C:\program files\DivX_311alpha\DivXa32.acm | acm | |
MD5:— | SHA256:— | |||
| 3696 | Install.exe | C:\program files\DivX_311alpha\DivX MPEG4 Video Codec.txt | text | |
MD5:— | SHA256:— | |||
| 3696 | Install.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\DivX ;-) MPEG-4 Video Codec\DivX ;-) Site.lnk | lnk | |
MD5:— | SHA256:— | |||
| 3696 | Install.exe | C:\program files\DivX_311alpha\DivX.inf | binary | |
MD5:— | SHA256:— | |||