File name:

TNODUP-Portable.exe

Full analysis: https://app.any.run/tasks/083388a5-675a-418d-a1e3-28f80bfa3988
Verdict: No threats detected
Analysis date: December 10, 2018, 21:12:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

123A5A2C572ACDF488F0956FA86D547D

SHA1:

8419AD630C331CF3EAFC18B8F53B38839D4C55B8

SHA256:

9D598EE47F5D800AEC7C11F29DE6FCBAFCCFFA187613E92B12C97E91308781D8

SSDEEP:

98304:nbvSLH5HbeTQ009sN4Xa0Yp4MJ1GsCA2:bvSLZT0F5TCA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    No malicious indicators.
  • SUSPICIOUS

    No suspicious indicators.
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable (generic) (52.9)
.exe | Generic Win/DOS Executable (23.5)
.exe | DOS Executable Generic (23.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2017:10:17 20:55:17+02:00
PEType: PE32
LinkerVersion: 14
CodeSize: 3627520
InitializedDataSize: 1672192
UninitializedDataSize: -
EntryPoint: 0x26bf36
OSVersion: 5.1
ImageVersion: -
SubsystemVersion: 5.1
Subsystem: Windows GUI
FileVersionNumber: 1.6.3.1
ProductVersionNumber: 1.6.3.1
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Unknown (300A)
CharacterSet: Windows, Latin1
CompanyName: Tukero[X]Team
FileDescription: TNod User & Password Finder
FileVersion: ,
LegalCopyright: Copyleft 2007-2017
ProductName: TNod User & Password Finder
ProductVersion: ,
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
31
Monitored processes
1
Malicious processes
0
Suspicious processes
0

Behavior graph

Click at the process to see the details
start tnodup-portable.exe

Process information

PID
CMD
Path
Indicators
Parent process
3820"C:\Users\admin\Desktop\TNODUP-Portable.exe" C:\Users\admin\Desktop\TNODUP-Portable.exe
explorer.exe
User:
admin
Company:
Tukero[X]Team
Integrity Level:
MEDIUM
Description:
TNod User & Password Finder
Exit code:
0
Version:
,
Modules
Images
c:\users\admin\desktop\tnodup-portable.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wininet.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
Total events
89
Read events
36
Write events
53
Delete events
0

Modification events

(PID) Process:(3820) TNODUP-Portable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\TNODUP-Portable_RASAPI32
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3820) TNODUP-Portable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\TNODUP-Portable_RASAPI32
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3820) TNODUP-Portable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\TNODUP-Portable_RASAPI32
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(3820) TNODUP-Portable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\TNODUP-Portable_RASAPI32
Operation:writeName:ConsoleTracingMask
Value:
4294901760
(PID) Process:(3820) TNODUP-Portable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\TNODUP-Portable_RASAPI32
Operation:writeName:MaxFileSize
Value:
1048576
(PID) Process:(3820) TNODUP-Portable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\TNODUP-Portable_RASAPI32
Operation:writeName:FileDirectory
Value:
%windir%\tracing
(PID) Process:(3820) TNODUP-Portable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\TNODUP-Portable_RASMANCS
Operation:writeName:EnableFileTracing
Value:
0
(PID) Process:(3820) TNODUP-Portable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\TNODUP-Portable_RASMANCS
Operation:writeName:EnableConsoleTracing
Value:
0
(PID) Process:(3820) TNODUP-Portable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\TNODUP-Portable_RASMANCS
Operation:writeName:FileTracingMask
Value:
4294901760
(PID) Process:(3820) TNODUP-Portable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\TNODUP-Portable_RASMANCS
Operation:writeName:ConsoleTracingMask
Value:
4294901760
Executable files
0
Suspicious files
0
Text files
0
Unknown types
0

Dropped files

No data
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3820
TNODUP-Portable.exe
GET
200
91.228.167.125:80
http://iploc.eset.com/ip_locate_iso2
SK
xml
247 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3820
TNODUP-Portable.exe
91.228.167.125:80
iploc.eset.com
ESET, spol. s r.o.
SK
unknown

DNS requests

Domain
IP
Reputation
iploc.eset.com
  • 91.228.167.125
whitelisted

Threats

No threats detected
No debug info