File name: | setup.exe |
Full analysis: | https://app.any.run/tasks/6d9b0fb2-3e90-4062-893e-de9aa388c807 |
Verdict: | Malicious activity |
Analysis date: | March 30, 2020, 22:35:24 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 15FF81EC235A5F32B90BCA18776AD3D9 |
SHA1: | FE89AE009E99269E7DA5F217975888CDC00E485B |
SHA256: | A3447573C95D6DA682569CF186199FACB60CF47499088C478DE70B01CEBEFE8A |
SSDEEP: | 98304:zx0z2lgASNpJsesUOd1/ACNxyJFcbqymGlJ8Qsg:zx0zpsEOsCmcKGDh |
.exe | | | Inno Setup installer (77.7) |
---|---|---|
.exe | | | Win32 Executable Delphi generic (10) |
.dll | | | Win32 Dynamic Link Library (generic) (4.6) |
.exe | | | Win32 Executable (generic) (3.1) |
.exe | | | Win16/32 Executable Delphi generic (1.4) |
ProductVersion: | |
---|---|
ProductName: | Stellaris Galaxy Edition |
LegalCopyright: | |
FileVersion: | |
FileDescription: | Stellaris Galaxy Edition Setup |
CompanyName: | torrent-igruha.org |
Comments: | This installation was built with Inno Setup. |
CharacterSet: | Unicode |
LanguageCode: | Neutral |
FileSubtype: | - |
ObjectFileType: | Executable application |
FileOS: | Win32 |
FileFlags: | (none) |
FileFlagsMask: | 0x003f |
ProductVersionNumber: | 0.0.0.0 |
FileVersionNumber: | 0.0.0.0 |
Subsystem: | Windows GUI |
SubsystemVersion: | 5 |
ImageVersion: | 6 |
OSVersion: | 5 |
EntryPoint: | 0x16478 |
UninitializedDataSize: | - |
InitializedDataSize: | 53760 |
CodeSize: | 86016 |
LinkerVersion: | 2.25 |
PEType: | PE32 |
TimeStamp: | 2012:10:02 07:04:04+02:00 |
MachineType: | Intel 386 or later, and compatibles |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 02-Oct-2012 05:04:04 |
Detected languages: |
|
Comments: | This installation was built with Inno Setup. |
CompanyName: | torrent-igruha.org |
FileDescription: | Stellaris Galaxy Edition Setup |
FileVersion: | - |
LegalCopyright: | |
ProductName: | Stellaris Galaxy Edition |
ProductVersion: | - |
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x0050 |
Pages in file: | 0x0002 |
Relocations: | 0x0000 |
Size of header: | 0x0004 |
Min extra paragraphs: | 0x000F |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x00B8 |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0000 |
Overlay number: | 0x001A |
OEM identifier: | 0x0000 |
OEM information: | 0x0000 |
Address of NE header: | 0x00000100 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 8 |
Time date stamp: | 02-Oct-2012 05:04:04 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x000143F8 | 0x00014400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.4822 |
.itext | 0x00016000 | 0x00000BE8 | 0x00000C00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.01516 |
.data | 0x00017000 | 0x00000D9C | 0x00000E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.66929 |
.bss | 0x00018000 | 0x00005750 | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.idata | 0x0001E000 | 0x00000F9E | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.96778 |
.tls | 0x0001F000 | 0x00000008 | 0x00000000 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rdata | 0x00020000 | 0x00000018 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.190489 |
.rsrc | 0x00021000 | 0x0000B200 | 0x0000B200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.15899 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 5.06505 | 1376 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 3.47151 | 1384 | UNKNOWN | Chinese - PRC | RT_ICON |
3 | 3.91708 | 744 | UNKNOWN | Chinese - PRC | RT_ICON |
4 | 3.91366 | 2216 | UNKNOWN | Chinese - PRC | RT_ICON |
4091 | 3.13038 | 196 | UNKNOWN | UNKNOWN | RT_STRING |
4092 | 3.36196 | 204 | UNKNOWN | UNKNOWN | RT_STRING |
4093 | 3.34841 | 372 | UNKNOWN | UNKNOWN | RT_STRING |
4094 | 3.29351 | 924 | UNKNOWN | UNKNOWN | RT_STRING |
4095 | 3.34579 | 844 | UNKNOWN | UNKNOWN | RT_STRING |
4096 | 3.28057 | 660 | UNKNOWN | UNKNOWN | RT_STRING |
advapi32.dll |
comctl32.dll |
kernel32.dll |
oleaut32.dll |
user32.dll |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
3420 | "C:\Users\admin\AppData\Local\Temp\setup.exe" | C:\Users\admin\AppData\Local\Temp\setup.exe | — | explorer.exe |
User: admin Company: torrent-igruha.org Integrity Level: MEDIUM Description: Stellaris Galaxy Edition Setup Exit code: 3221226540 Version: | ||||
3236 | "C:\Users\admin\AppData\Local\Temp\setup.exe" | C:\Users\admin\AppData\Local\Temp\setup.exe | explorer.exe | |
User: admin Company: torrent-igruha.org Integrity Level: HIGH Description: Stellaris Galaxy Edition Setup Exit code: 0 Version: | ||||
1756 | "C:\Users\admin\AppData\Local\Temp\is-SG6UO.tmp\setup.tmp" /SL5="$A0140,4348482,140800,C:\Users\admin\AppData\Local\Temp\setup.exe" | C:\Users\admin\AppData\Local\Temp\is-SG6UO.tmp\setup.tmp | setup.exe | |
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 | ||||
3088 | "C:\Program Files\Stellaris Galaxy Edition\unins000.exe" /VERYSILENT | C:\Program Files\Stellaris Galaxy Edition\unins000.exe | setup.tmp | |
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 | ||||
2648 | "C:\Users\admin\AppData\Local\Temp\_iu14D2N.tmp" /SECONDPHASE="C:\Program Files\Stellaris Galaxy Edition\unins000.exe" /FIRSTPHASEWND=$501EA /VERYSILENT | C:\Users\admin\AppData\Local\Temp\_iu14D2N.tmp | unins000.exe | |
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 | ||||
2620 | "C:\Program Files\Internet Explorer\iexplore.exe" https://torrent-igruha.org/671-me-stellaris-download.html | C:\Program Files\Internet Explorer\iexplore.exe | setup.tmp | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) | ||||
2428 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:2620 CREDAT:275457 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) |
PID | Process | Filename | Type | |
---|---|---|---|---|
1756 | setup.tmp | C:\Users\admin\AppData\Local\Temp\is-FKNUM.tmp\arc.ini | text | |
MD5:12EAEABC5C70202B903CB43383073B56 | SHA256:64627B64416ED72905667844B69D86C50A1718FA213C4E0841D1B00A1AE121C5 | |||
1756 | setup.tmp | C:\Users\admin\AppData\Local\Temp\is-FKNUM.tmp\_isetup\_shfoldr.dll | executable | |
MD5:92DC6EF532FBB4A5C3201469A5B5EB63 | SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87 | |||
3236 | setup.exe | C:\Users\admin\AppData\Local\Temp\is-SG6UO.tmp\setup.tmp | executable | |
MD5:D50A6BDCF37D093FC472FCBB6489069A | SHA256:4252EF0EC82DE8B6634F1B873CBD0A73193BD64DD49CF36F598940817835E10E | |||
1756 | setup.tmp | C:\Users\admin\AppData\Local\Temp\is-FKNUM.tmp\English.ini | text | |
MD5:B031BEE9106D82782B43BDF5D4AD79B0 | SHA256:E1B6F4DC9BA12E110B33D370E8F06F176228059C42754BE5DA7B92AB939FF38E | |||
1756 | setup.tmp | C:\Users\admin\AppData\Local\Temp\is-FKNUM.tmp\cls-lolz_x86.exe | executable | |
MD5:7CBE7DB7FC9258B6A43551140C343BB3 | SHA256:6EA07AA4F5565AC289402ADE3B2E52BF8089AD6185E0ECF0E1F36CEA39C091A9 | |||
1756 | setup.tmp | C:\Users\admin\AppData\Local\Temp\is-FKNUM.tmp\unarc.dll | executable | |
MD5:C8600EE0BAD1CB2A899B792CB6C1869B | SHA256:B670F7E828AEFF88BBE6351BF3B0775AF39ADC1BFAC3B84AF4061A4C78ED174A | |||
1756 | setup.tmp | C:\Users\admin\AppData\Local\Temp\is-FKNUM.tmp\hif2raw_dll.dll | executable | |
MD5:0F17602430B63925C26929CA160BD7FE | SHA256:90A45A741501873B4BC2024222DBCF5EA4F97B62F95DB7BA433A13E43D34EA52 | |||
1756 | setup.tmp | C:\Users\admin\AppData\Local\Temp\is-FKNUM.tmp\Russian.ini | text | |
MD5:C2F6F1038DE8369B2E31067EA4D48536 | SHA256:1CFA41921DCE01991640DB414D4955B1A6DC6D6FA4F4333CA7552E2E8B81391E | |||
1756 | setup.tmp | C:\Users\admin\AppData\Local\Temp\is-FKNUM.tmp\xtool.exe | executable | |
MD5:EEA7C5573959D95A5CC2BA320F6CC3DA | SHA256:AAA25694962C89B880C9A31757D5337854A89FF51B58C98F5D36EAACEAC04296 | |||
1756 | setup.tmp | C:\Users\admin\AppData\Local\Temp\is-FKNUM.tmp\xtool.ini | text | |
MD5:047DE6726DDE4330213DD0CE54FBEC3F | SHA256:325A314002BC143EF8A89952D09DBB28264315123813F1E4F55C716B72C03118 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
2428 | iexplore.exe | GET | 200 | 93.184.220.29:80 | http://status.rapidssl.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRhhZrQET0hvbSHUJmNfBKqR%2FiT7wQUU8oXWfxrwAMhLxqu5KqoHIJW2nUCEAKht3RwAHu%2BUfHbCVSw1H0%3D | US | der | 471 b | shared |
2428 | iexplore.exe | GET | 200 | 172.217.23.163:80 | http://ocsp.pki.goog/gts1o1/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBRCRjDCJxnb3nDwj%2Fxz5aZfZjgXvAQUmNH4bhDrz5vsYJ8YkBug630J%2FSsCEQDL%2FQslYWVuogIAAAAAXGdc | US | der | 472 b | whitelisted |
2428 | iexplore.exe | GET | 200 | 172.217.23.163:80 | http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D | US | der | 468 b | whitelisted |
2428 | iexplore.exe | GET | 200 | 151.139.236.246:80 | http://subca.ocsp-certum.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBR5iK7tYk9tqQEoeQhZNkKcAol9bgQUjEPEy22YwaechGnr30oNYJY6w%2FsCEQCTkoVAAWVxX5R%2FKI%2FvyZso | US | der | 1.62 Kb | whitelisted |
2428 | iexplore.exe | GET | 200 | 72.21.91.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAilokbNS1yMg9cCtLurU0k%3D | US | der | 471 b | whitelisted |
2428 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.trust-provider.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEHbYt4bR81JP7pU%2BcUA9mdU%3D | US | der | 471 b | whitelisted |
2428 | iexplore.exe | GET | 200 | 151.139.236.246:80 | http://subca.ocsp-certum.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBR5iK7tYk9tqQEoeQhZNkKcAol9bgQUjEPEy22YwaechGnr30oNYJY6w%2FsCEQCTkoVAAWVxX5R%2FKI%2FvyZso | US | der | 1.62 Kb | whitelisted |
2428 | iexplore.exe | GET | 200 | 151.139.128.14:80 | http://ocsp.trust-provider.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBR8sWZUnKvbRO5iJhat9GV793rVlAQUrb2YejS0Jvf6xCZU7wO94CTLVBoCEHbYt4bR81JP7pU%2BcUA9mdU%3D | US | der | 471 b | whitelisted |
2428 | iexplore.exe | GET | 200 | 172.217.23.163:80 | http://ocsp.pki.goog/gsr2/ME4wTDBKMEgwRjAJBgUrDgMCGgUABBTgXIsxbvr2lBkPpoIEVRE6gHlCnAQUm%2BIHV2ccHsBqBt5ZtJot39wZhi4CDQHjtJqhjYqpgSVpULg%3D | US | der | 468 b | whitelisted |
2428 | iexplore.exe | GET | 200 | 72.21.91.29:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAilokbNS1yMg9cCtLurU0k%3D | US | der | 471 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
2620 | iexplore.exe | 204.79.197.200:80 | www.bing.com | Microsoft Corporation | US | whitelisted |
2428 | iexplore.exe | 93.184.220.29:80 | status.rapidssl.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2428 | iexplore.exe | 172.217.16.142:443 | www.youtube.com | Google Inc. | US | whitelisted |
2428 | iexplore.exe | 72.21.91.29:80 | ocsp.digicert.com | MCI Communications Services, Inc. d/b/a Verizon Business | US | whitelisted |
2428 | iexplore.exe | 93.158.134.119:443 | mc.yandex.ru | YANDEX LLC | RU | whitelisted |
2428 | iexplore.exe | 185.59.100.64:443 | torrent-igruha.org | Netversor GmbH | DE | unknown |
2428 | iexplore.exe | 88.212.201.210:443 | counter.yadro.ru | United Network LLC | RU | suspicious |
2428 | iexplore.exe | 172.217.23.163:80 | ocsp.pki.goog | Google Inc. | US | whitelisted |
2428 | iexplore.exe | 172.217.18.98:443 | googleads.g.doubleclick.net | Google Inc. | US | whitelisted |
2428 | iexplore.exe | 172.217.22.35:443 | fonts.gstatic.com | Google Inc. | US | whitelisted |
Domain | IP | Reputation |
---|---|---|
torrent-igruha.org |
| whitelisted |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
status.rapidssl.com |
| shared |
www.youtube.com |
| whitelisted |
counter.yadro.ru |
| whitelisted |
mc.yandex.ru |
| whitelisted |
ocsp.pki.goog |
| whitelisted |
subca.ocsp-certum.com |
| whitelisted |