| File name: | netrekinstall.exe |
| Full analysis: | https://app.any.run/tasks/5b3f3528-5f02-4f37-a9cb-c25d358602e6 |
| Verdict: | Malicious activity |
| Analysis date: | March 10, 2024, 10:02:09 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | E53C3E2BBEC22BAF273C01D70AF09FEA |
| SHA1: | 44F2A54B745EB2BFC60062D3BE8087829B3D392A |
| SHA256: | A0D34AB3B10F1E104969250DC5A341DA8647F1D748F4AB1A904DF22B43C8C1F8 |
| SSDEEP: | 98304:czv2pI9KShOKtxYKDjK5zb6HiXKKQeJX6ku/hOFXNKf2I0YZUirgHsD4i7p9w/EK:gzzFZbl/5uWAEGHLH |
| .exe | | | InstallShield setup (33) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (23.9) |
| .exe | | | Win64 Executable (generic) (21.2) |
| .scr | | | Windows screen saver (10) |
| .dll | | | Win32 Dynamic Link Library (generic) (5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2004:12:17 09:01:41+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 90112 |
| InitializedDataSize: | 45056 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x12ded |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.0.0.24 |
| ProductVersionNumber: | 2.0.0.24 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| Comments: | - |
| CompanyName: | - |
| FileDescription: | - |
| FileVersion: | 2, 0, 0, 24 |
| InternalName: | - |
| LegalCopyright: | - |
| LegalTrademarks: | - |
| OriginalFileName: | - |
| PrivateBuild: | - |
| ProductName: | Netrek XP 2010 v1.0 Install Program |
| ProductVersion: | 2, 0, 0, 24 |
| SpecialBuild: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 392 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=asset_store.mojom.AssetStoreService --lang=en-US --service-sandbox-type=asset_store_service --mojo-platform-channel-handle=2960 --field-trial-handle=1280,i,2759296458159529946,1611548967009235498,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 844 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=7 --mojo-platform-channel-handle=1556 --field-trial-handle=1280,i,2759296458159529946,1611548967009235498,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 864 | "C:\Windows\system32\NOTEPAD.EXE" C:\PROGRA~1\Netrek\controls.txt | C:\Windows\System32\notepad.exe | — | netrekinstall.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Notepad Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 884 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4032 --field-trial-handle=1280,i,2759296458159529946,1611548967009235498,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 968 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument http://www.netrek.org/ | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | netrek.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1112 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1264 --field-trial-handle=1280,i,2759296458159529946,1611548967009235498,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1172 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --disable-gpu-compositing --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=12 --mojo-platform-channel-handle=2320 --field-trial-handle=1280,i,2759296458159529946,1611548967009235498,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1236 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1536 --field-trial-handle=1280,i,2759296458159529946,1611548967009235498,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1352 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1592 --field-trial-handle=1280,i,2759296458159529946,1611548967009235498,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1604 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=3444 --field-trial-handle=1280,i,2759296458159529946,1611548967009235498,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| (PID) Process: | (3660) netrekinstall.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Netrek XP 2010 v1.0 |
| Operation: | write | Name: | DisplayName |
Value: Netrek XP 2010 v1.0 | |||
| (PID) Process: | (3660) netrekinstall.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Netrek XP 2010 v1.0 |
| Operation: | write | Name: | UninstallString |
Value: C:\Program Files\Netrek\Uninstall.exe | |||
| (PID) Process: | (2256) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (2256) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (2256) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (2256) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (2256) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (2256) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (2256) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (2256) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault |
| Operation: | write | Name: | S-1-5-21-1302019708-1500728564-335382590-1000 |
Value: 0A93C6D2E1712F00 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3660 | netrekinstall.exe | C:\Program Files\Netrek\Uninstall.$A | executable | |
MD5:1F34142BC16A800721F6024B24132253 | SHA256:EE05CF9C82C495242B6D68A9545E3F2E113E55360FE5893AA9042DF9C858C419 | |||
| 3660 | netrekinstall.exe | C:\Program Files\Netrek\SDL_mixer.dll | executable | |
MD5:CC3CD2330BA1FCB32662F3509E25E38C | SHA256:FCE8D4E1667717A51BF0FFED9EEFAAF5B55A7FA29011A49F8790DA9D8FAE62C3 | |||
| 3660 | netrekinstall.exe | C:\Program Files\Netrek\SDL.$A | executable | |
MD5:755242AA2DAA6AD888E94B21DCAF0449 | SHA256:0A48932C999FF1279C7BFA9E1117F49BF0F52CEE4077EDAF5858D28C7AF93D84 | |||
| 3660 | netrekinstall.exe | C:\Program Files\Netrek\SDL_mixer.$A | executable | |
MD5:CC3CD2330BA1FCB32662F3509E25E38C | SHA256:FCE8D4E1667717A51BF0FFED9EEFAAF5B55A7FA29011A49F8790DA9D8FAE62C3 | |||
| 3660 | netrekinstall.exe | C:\Program Files\Netrek\zlib1.$A | executable | |
MD5:80E41408F6D641DC1C0F5353A0CC8125 | SHA256:B09537250201236472CCD3CAFF5C0C12A5FAD262E1E951350E9E5ED2A81D9DDE | |||
| 3660 | netrekinstall.exe | C:\Program Files\Netrek\bitmaps\misclib\beepliteplayerm.bmp | binary | |
MD5:B341F4BE3ACF8058DC9744F77891E0B4 | SHA256:25B35F3830D6D2A9385B2219BF2601C12EB6EEAC55496FDA160BB6939F9DC32D | |||
| 3660 | netrekinstall.exe | C:\Program Files\Netrek\bitmaps\misclib\cloak.$A | image | |
MD5:06C972B472F78D0D954D801BCEACC9D2 | SHA256:38BC060D1AB8DF9C6236829F0390BBFF6EED24A2403234BAA3B54C08E43A734C | |||
| 3660 | netrekinstall.exe | C:\Program Files\Netrek\bitmaps\misclib\beepliteplayerm.$A | binary | |
MD5:B341F4BE3ACF8058DC9744F77891E0B4 | SHA256:25B35F3830D6D2A9385B2219BF2601C12EB6EEAC55496FDA160BB6939F9DC32D | |||
| 3660 | netrekinstall.exe | C:\Program Files\Netrek\bitmaps\misclib\color\clock.bmp | image | |
MD5:990DA740E4BA6525D5C0343F4F3D8CEF | SHA256:5FFA68438A2147E397C8E10DE65DD36C007434416BC3E2F1719F45E4BD940B41 | |||
| 3660 | netrekinstall.exe | C:\Program Files\Netrek\bitmaps\misclib\clock.$A | image | |
MD5:975A0D8E7B3F2EE8399AC5417B9D72F5 | SHA256:A409D0719D547C4A1FBAC78CF5E2CF19E4AB6ABEBB110CD8DB37929AB4DBEE16 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1236 | msedge.exe | GET | 302 | 63.170.91.10:80 | http://www.netrek.org/ | unknown | html | 287 b | unknown |
1236 | msedge.exe | GET | 302 | 63.170.91.10:80 | http://www.netrek.org/ | unknown | html | 287 b | unknown |
1236 | msedge.exe | GET | 302 | 63.170.91.10:80 | http://www.netrek.org/ | unknown | html | 287 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | unknown |
3212 | netrek.exe | 224.0.0.1:3521 | — | — | — | unknown |
1836 | netrek.exe | 224.0.0.1:3521 | — | — | — | unknown |
2208 | netrek.exe | 224.0.0.1:3521 | — | — | — | unknown |
1236 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
2256 | msedge.exe | 239.255.255.250:1900 | — | — | — | unknown |
1236 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
1236 | msedge.exe | 63.170.91.10:80 | www.netrek.org | REAL-TIME | US | unknown |
1236 | msedge.exe | 63.170.91.10:443 | www.netrek.org | REAL-TIME | US | unknown |
Domain | IP | Reputation |
|---|---|---|
metaserver.us.netrek.org |
| unknown |
metaserver2.us.netrek.org |
| unknown |
metaserver3.us.netrek.org |
| unknown |
metaserver.servegame.org |
| unknown |
www.netrek.org |
| unknown |
edge.microsoft.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
www.bing.com |
| whitelisted |
msedgeextensions.sf.tlu.dl.delivery.mp.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Potentially Bad Traffic | ET INFO DYNAMIC_DNS Query to a *.servegame .org Domain |