| File name: | openfin-installer.exe | 
| Full analysis: | https://app.any.run/tasks/f1a2c446-815f-49fe-9b8e-d51f5aa76baf | 
| Verdict: | Suspicious activity | 
| Analysis date: | July 04, 2019, 04:05:10 | 
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) | 
| Indicators: | |
| MIME: | application/x-dosexec | 
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows | 
| MD5: | 02A388E99F9225F2F7A5DDACC1FEA6D1 | 
| SHA1: | 72078C5B28BB58161AEACF69B8CAF512C5D087DC | 
| SHA256: | 9D731DDC1536D992060124C2E7D54F99D19BD5F7ED26FBABA064794136ECF078 | 
| SSDEEP: | 98304:gI57RvqiwV6eGf4cOzqGeRy1BJXTcyhuZ:G6g4RyBJXTc/Z | 
| .exe | | | Win64 Executable (generic) (64.6) | 
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (15.4) | 
| .exe | | | Win32 Executable (generic) (10.5) | 
| .exe | | | Generic Win/DOS Executable (4.6) | 
| .exe | | | DOS Executable Generic (4.6) | 
| MachineType: | Intel 386 or later, and compatibles | 
|---|---|
| TimeStamp: | 2019:05:15 20:12:21+02:00 | 
| PEType: | PE32 | 
| LinkerVersion: | 12 | 
| CodeSize: | 2043904 | 
| InitializedDataSize: | 1175552 | 
| UninitializedDataSize: | - | 
| EntryPoint: | 0x13abf9 | 
| OSVersion: | 5.1 | 
| ImageVersion: | - | 
| SubsystemVersion: | 5.1 | 
| Subsystem: | Windows GUI | 
| FileVersionNumber: | 5.0.0.9 | 
| ProductVersionNumber: | 5.0.0.9 | 
| FileFlagsMask: | 0x003f | 
| FileFlags: | (none) | 
| FileOS: | Windows NT 32-bit | 
| ObjectFileType: | Executable application | 
| FileSubtype: | - | 
| LanguageCode: | English (U.S.) | 
| CharacterSet: | Unicode | 
| CompanyName: | OpenFin Inc. | 
| FileDescription: | OpenFin RVM | 
| FileVersion: | 5.0.0.9 | 
| InternalName: | OpenFinRVM.exe | 
| LegalCopyright: | Copyright (C) 2019 | 
| OriginalFileName: | OpenFinRVM.exe | 
| ProductName: | RVM | 
| ProductVersion: | 5.0.0.9 | 
| Architecture: | IMAGE_FILE_MACHINE_I386 | 
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI | 
| Compilation Date: | 15-May-2019 18:12:21 | 
| Detected languages: | 
  | 
| Debug artifacts: | 
  | 
| CompanyName: | OpenFin Inc. | 
| FileDescription: | OpenFin RVM | 
| FileVersion: | 5.0.0.9 | 
| InternalName: | OpenFinRVM.exe | 
| LegalCopyright: | Copyright (C) 2019 | 
| OriginalFilename: | OpenFinRVM.exe | 
| ProductName: | RVM | 
| ProductVersion: | 5.0.0.9 | 
| Magic number: | MZ | 
|---|---|
| Bytes on last page of file: | 0x0090 | 
| Pages in file: | 0x0003 | 
| Relocations: | 0x0000 | 
| Size of header: | 0x0004 | 
| Min extra paragraphs: | 0x0000 | 
| Max extra paragraphs: | 0xFFFF | 
| Initial SS value: | 0x0000 | 
| Initial SP value: | 0x00B8 | 
| Checksum: | 0x0000 | 
| Initial IP value: | 0x0000 | 
| Initial CS value: | 0x0000 | 
| Overlay number: | 0x0000 | 
| OEM identifier: | 0x0000 | 
| OEM information: | 0x0000 | 
| Address of NE header: | 0x00000110 | 
| Signature: | PE | 
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 | 
| Number of sections: | 5 | 
| Time date stamp: | 15-May-2019 18:12:21 | 
| Pointer to Symbol Table: | 0x00000000 | 
| Number of symbols: | 0 | 
| Size of Optional Header: | 0x00E0 | 
| Characteristics: | 
  | 
Name  | Virtual Address  | Virtual Size  | Raw Size  | Charateristics  | Entropy  | 
|---|---|---|---|---|---|
.text  | 0x00001000  | 0x001F2E7B  | 0x001F3000  | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ  | 6.57522  | 
.rdata  | 0x001F4000  | 0x0007C678  | 0x0007C800  | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ  | 4.89557  | 
.data  | 0x00271000  | 0x0001DEAC  | 0x00017800  | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE  | 4.80353  | 
.rsrc  | 0x0028F000  | 0x00067CD0  | 0x00067E00  | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ  | 2.71699  | 
.reloc  | 0x002F7000  | 0x0001C9A8  | 0x0001CA00  | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ  | 6.64458  | 
Title  | Entropy  | Size  | Codepage  | Language  | Type  | 
|---|---|---|---|---|---|
1  | 5.06467  | 638  | UNKNOWN  | English - United States  | RT_MANIFEST  | 
2  | 2.95035  | 2440  | UNKNOWN  | English - United States  | RT_ICON  | 
3  | 2.81524  | 4264  | UNKNOWN  | English - United States  | RT_ICON  | 
4  | 2.44666  | 9640  | UNKNOWN  | English - United States  | RT_ICON  | 
5  | 2.30122  | 16936  | UNKNOWN  | English - United States  | RT_ICON  | 
6  | 2.11591  | 38056  | UNKNOWN  | English - United States  | RT_ICON  | 
7  | 2.02836  | 72  | UNKNOWN  | English - United States  | RT_STRING  | 
8  | 1.92614  | 152104  | UNKNOWN  | English - United States  | RT_ICON  | 
9  | 7.85651  | 7833  | UNKNOWN  | English - United States  | RT_ICON  | 
103  | 3.19659  | 316  | UNKNOWN  | English - United States  | RT_DIALOG  | 
ADVAPI32.dll  | 
COMCTL32.dll  | 
CRYPT32.dll  | 
GDI32.dll  | 
KERNEL32.dll  | 
SHELL32.dll  | 
SHLWAPI.dll  | 
USER32.dll  | 
VERSION.dll  | 
WININET.dll  | 
PID  | CMD  | Path  | Indicators  | Parent process  | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2616 | "C:\Users\admin\AppData\Local\Temp\rvm-installer-2088-6f9d-baf8-a233.exe" --config=https://marquee.gs.com/desktop-resources/config.json --support-email=gs-marquee-desktop@gs.com --parent-source="explorer.exe" --session-id="c81da5a5-3439-4c34-8708-fbd7940803ec" --wait-for-parent=488 | C:\Users\admin\AppData\Local\Temp\rvm-installer-2088-6f9d-baf8-a233.exe | openfin-installer.exe | ||||||||||||
User: admin Company: OpenFin Inc. Integrity Level: MEDIUM Description: OpenFin RVM Exit code: 3 Version: 5.0.0.9 Modules
  | |||||||||||||||
| 2772 | "C:\Users\admin\AppData\Local\OpenFin\OpenFinRVM.exe" --config=https://marquee.gs.com/desktop-resources/config.json --support-email=gs-marquee-desktop@gs.com --parent-source="explorer.exe" --session-id="c81da5a5-3439-4c34-8708-fbd7940803ec" --wait-for-parent=456 | C:\Users\admin\AppData\Local\OpenFin\OpenFinRVM.exe | rvm-installer-2088-6f9d-baf8-a233.exe | ||||||||||||
User: admin Company: OpenFin Inc. Integrity Level: MEDIUM Description: OpenFin RVM Exit code: 303 Version: 5.0.0.9 Modules
  | |||||||||||||||
| 3300 | "C:\Users\admin\AppData\Local\Temp\openfin-installer.exe" | C:\Users\admin\AppData\Local\Temp\openfin-installer.exe | explorer.exe | ||||||||||||
User: admin Company: OpenFin Inc. Integrity Level: MEDIUM Description: OpenFin RVM Exit code: 0 Version: 5.0.0.9 Modules
  | |||||||||||||||
| (PID) Process: | (3300) openfin-installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\openfin-installer_RASAPI32 | 
| Operation: | write | Name: | EnableFileTracing | 
Value: 0  | |||
| (PID) Process: | (3300) openfin-installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\openfin-installer_RASAPI32 | 
| Operation: | write | Name: | EnableConsoleTracing | 
Value: 0  | |||
| (PID) Process: | (3300) openfin-installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\openfin-installer_RASAPI32 | 
| Operation: | write | Name: | FileTracingMask | 
Value: 4294901760  | |||
| (PID) Process: | (3300) openfin-installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\openfin-installer_RASAPI32 | 
| Operation: | write | Name: | ConsoleTracingMask | 
Value: 4294901760  | |||
| (PID) Process: | (3300) openfin-installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\openfin-installer_RASAPI32 | 
| Operation: | write | Name: | MaxFileSize | 
Value: 1048576  | |||
| (PID) Process: | (3300) openfin-installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\openfin-installer_RASAPI32 | 
| Operation: | write | Name: | FileDirectory | 
Value: %windir%\tracing  | |||
| (PID) Process: | (3300) openfin-installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\openfin-installer_RASMANCS | 
| Operation: | write | Name: | EnableFileTracing | 
Value: 0  | |||
| (PID) Process: | (3300) openfin-installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\openfin-installer_RASMANCS | 
| Operation: | write | Name: | EnableConsoleTracing | 
Value: 0  | |||
| (PID) Process: | (3300) openfin-installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\openfin-installer_RASMANCS | 
| Operation: | write | Name: | FileTracingMask | 
Value: 4294901760  | |||
| (PID) Process: | (3300) openfin-installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Tracing\openfin-installer_RASMANCS | 
| Operation: | write | Name: | ConsoleTracingMask | 
Value: 4294901760  | |||
PID  | Process  | Filename  | Type  | |
|---|---|---|---|---|
| 3300 | openfin-installer.exe | C:\Users\admin\AppData\Local\OpenFin\logs\archive\[2019-07-04]-[05-05-35]\rvm.log | — | |
MD5:—  | SHA256:—  | |||
| 2616 | rvm-installer-2088-6f9d-baf8-a233.exe | C:\Users\admin\AppData\Local\OpenFin\logs\archive\[2019-07-04]-[05-05-36]\rvm.log | — | |
MD5:—  | SHA256:—  | |||
| 2772 | OpenFinRVM.exe | C:\Users\admin\AppData\Local\OpenFin\logs\archive\[2019-07-04]-[05-06-01]\rvm.log | — | |
MD5:—  | SHA256:—  | |||
| 2772 | OpenFinRVM.exe | C:\Users\admin\AppData\Local\OpenFin\cache.dat | text | |
MD5:—  | SHA256:—  | |||
| 3300 | openfin-installer.exe | C:\Users\admin\AppData\Local\OpenFin\logs\archive\[2019-07-04]-[05-05-35].zip | compressed | |
MD5:—  | SHA256:—  | |||
| 3300 | openfin-installer.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\IETldCache\index.dat | dat | |
MD5:D7A950FEFD60DBAA01DF2D85FEFB3862  | SHA256:75D0B1743F61B76A35B1FEDD32378837805DE58D79FA950CB6E8164BFA72073A  | |||
| 2772 | OpenFinRVM.exe | C:\Users\admin\AppData\Local\OpenFin\logs\rvm.log | text | |
MD5:—  | SHA256:—  | |||
| 2772 | OpenFinRVM.exe | C:\Users\admin\AppData\Local\OpenFin\logs\archive\[2019-07-04]-[05-06-01].zip | compressed | |
MD5:—  | SHA256:—  | |||
| 2616 | rvm-installer-2088-6f9d-baf8-a233.exe | C:\Users\admin\AppData\Local\OpenFin\logs\archive\[2019-07-04]-[05-05-36].zip | compressed | |
MD5:—  | SHA256:—  | |||
| 3300 | openfin-installer.exe | C:\Users\admin\AppData\Local\Temp\rvm-installer-2088-6f9d-baf8-a233.exe | executable | |
MD5:5D093A6398D2463E2E356FDB4019BFC8  | SHA256:576DC14AB45B47AFE0BA96DDC68653A25339AC3E93B6C0E2DBBBDD5A7E91AF32  | |||
PID  | Process  | IP  | Domain  | ASN  | CN  | Reputation  | 
|---|---|---|---|---|---|---|
3300  | openfin-installer.exe  | 54.86.235.160:443  | ingest.openfin.co  | Amazon.com, Inc.  | US  | unknown  | 
—  | —  | 104.111.235.101:443  | marquee.gs.com  | Akamai International B.V.  | NL  | whitelisted  | 
2772  | OpenFinRVM.exe  | 104.111.235.101:443  | marquee.gs.com  | Akamai International B.V.  | NL  | whitelisted  | 
2616  | rvm-installer-2088-6f9d-baf8-a233.exe  | 54.86.235.160:443  | ingest.openfin.co  | Amazon.com, Inc.  | US  | unknown  | 
2772  | OpenFinRVM.exe  | 13.249.33.110:443  | cdn.openfin.co  | —  | US  | unknown  | 
2772  | OpenFinRVM.exe  | 54.86.235.160:443  | ingest.openfin.co  | Amazon.com, Inc.  | US  | unknown  | 
Domain  | IP  | Reputation  | 
|---|---|---|
ingest.openfin.co  | 
  | suspicious  | 
cdn.openfin.co  | 
  | suspicious  | 
marquee.gs.com  | 
  | malicious  |