| File name: | win.exe |
| Full analysis: | https://app.any.run/tasks/662f1681-975d-4b72-b50c-f320b7f1a8fc |
| Verdict: | Malicious activity |
| Analysis date: | January 13, 2024, 19:50:14 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | F1B9E6D9099806706ECD27FDC8674EF4 |
| SHA1: | 3CDF8ACBD158A8637433D19DBD820B56C49BB09F |
| SHA256: | AE27B300F27DA450594A53CFADF8A68943112358EBEB69254BB590D16107753B |
| SSDEEP: | 98304:2r7ayGJ6kHOSiPBzkc8PJc8L4tNdN0OhngxqNfLFg+rcu6RO7V+8Q5YYN:Kdg5B |
| .exe | | | Win32 Executable Borland Delphi 7 (90.7) |
|---|---|---|
| .exe | | | InstallShield setup (5.8) |
| .exe | | | Win32 Executable Delphi generic (1.9) |
| .exe | | | Win32 Executable (generic) (0.6) |
| .exe | | | Win16/32 Executable Delphi generic (0.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:20 00:22:17+02:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 629760 |
| InitializedDataSize: | 2413056 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x9ab80 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.4 |
| ProductVersionNumber: | 1.0.0.4 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Turkish |
| CharacterSet: | Windows, Turkish |
| CompanyName: | Synaptics |
| FileDescription: | Synaptics Pointing Device Driver |
| FileVersion: | 1.0.0.4 |
| InternalName: | - |
| LegalCopyright: | - |
| LegalTrademarks: | - |
| OriginalFileName: | - |
| ProductName: | Synaptics Pointing Device Driver |
| ProductVersion: | 1.0.0.0 |
| Comments: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 128 | "C:\Users\admin\Desktop\win.exe" | C:\Users\admin\Desktop\win.exe | explorer.exe | ||||||||||||
User: admin Company: Synaptics Integrity Level: MEDIUM Description: Synaptics Pointing Device Driver Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 296 | "C:\Users\admin\AppData\Local\Temp\3582-490\._cache_win.exe" | C:\Users\admin\AppData\Local\Temp\3582-490\._cache_win.exe | ._cache_win.exe | ||||||||||||
User: admin Company: Alexander Roshal Integrity Level: MEDIUM Description: WinRAR archiver Exit code: 0 Version: 5.71.0 Modules
| |||||||||||||||
| 1404 | "C:\Users\admin\Desktop\._cache_win.exe" | C:\Users\admin\Desktop\._cache_win.exe | win.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2640 | "C:\ProgramData\Synaptics\Synaptics.exe" InjUpdate | C:\ProgramData\Synaptics\Synaptics.exe | win.exe | ||||||||||||
User: admin Company: Synaptics Integrity Level: HIGH Description: Synaptics Pointing Device Driver Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| (PID) Process: | (128) win.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (128) win.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (128) win.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (128) win.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1404) ._cache_win.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1404) ._cache_win.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1404) ._cache_win.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1404) ._cache_win.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (128) win.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (296) ._cache_win.exe | Key: | HKEY_CURRENT_USER\Software\WinRAR\General |
| Operation: | write | Name: | VerInfo |
Value: 005B050098688F18FFB0D601 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1404 | ._cache_win.exe | C:\Users\admin\AppData\Local\Temp\3582-490\._cache_win.exe | executable | |
MD5:F59F4F7BEA12DD7C8D44F0A717C21C8E | SHA256:F150B01C1CBC540C880DC00D812BCCA1A8ABE1166233227D621408F3E75B57D4 | |||
| 128 | win.exe | C:\Users\admin\Desktop\._cache_win.exe | executable | |
MD5:AD8C28860563C005D49E0BE37537A6A1 | SHA256:65F5BFED7496D565549CCD055F143D63E625E9756E50B85C0260E043359A4919 | |||
| 128 | win.exe | C:\ProgramData\Synaptics\Synaptics.exe | executable | |
MD5:F1B9E6D9099806706ECD27FDC8674EF4 | SHA256:AE27B300F27DA450594A53CFADF8A68943112358EBEB69254BB590D16107753B | |||
| 1404 | ._cache_win.exe | C:\MSOCache\All Users\{90140000-006E-0410-0000-0000000FF1CE}-C\DW20.EXE | executable | |
MD5:02EE6A3424782531461FB2F10713D3C1 | SHA256:EAD58C483CB20BCD57464F8A4929079539D634F469B213054BF737D227C026DC | |||
| 1404 | ._cache_win.exe | C:\MSOCache\All Users\{90140000-006E-0411-0000-0000000FF1CE}-C\DW20.EXE | executable | |
MD5:02EE6A3424782531461FB2F10713D3C1 | SHA256:EAD58C483CB20BCD57464F8A4929079539D634F469B213054BF737D227C026DC | |||
| 1404 | ._cache_win.exe | C:\MSOCache\All Users\{90140000-006E-0407-0000-0000000FF1CE}-C\DW20.EXE | executable | |
MD5:02EE6A3424782531461FB2F10713D3C1 | SHA256:EAD58C483CB20BCD57464F8A4929079539D634F469B213054BF737D227C026DC | |||
| 1404 | ._cache_win.exe | C:\MSOCache\All Users\{90140000-006E-0411-0000-0000000FF1CE}-C\dwtrig20.exe | executable | |
MD5:CF6C595D3E5E9667667AF096762FD9C4 | SHA256:593E60CC30AE0789448547195AF77F550387F6648D45847EA244DD0DD7ABF03D | |||
| 1404 | ._cache_win.exe | C:\MSOCache\All Users\{90140000-006E-040C-0000-0000000FF1CE}-C\dwtrig20.exe | executable | |
MD5:CF6C595D3E5E9667667AF096762FD9C4 | SHA256:593E60CC30AE0789448547195AF77F550387F6648D45847EA244DD0DD7ABF03D | |||
| 1404 | ._cache_win.exe | C:\MSOCache\All Users\{90140000-006E-0407-0000-0000000FF1CE}-C\dwtrig20.exe | executable | |
MD5:CF6C595D3E5E9667667AF096762FD9C4 | SHA256:593E60CC30AE0789448547195AF77F550387F6648D45847EA244DD0DD7ABF03D | |||
| 1404 | ._cache_win.exe | C:\MSOCache\All Users\{90140000-003D-0000-0000-0000000FF1CE}-C\setup.exe | executable | |
MD5:566ED4F62FDC96F175AFEDD811FA0370 | SHA256:E17CD94C08FC0E001A49F43A0801CEA4625FB9AEE211B6DFEBEBEC446C21F460 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
296 | ._cache_win.exe | GET | 301 | 51.195.68.172:80 | http://notifier.rarlab.com/?language=English&source=RARLAB&landingpage=first&version=571&architecture=32 | unknown | — | — | unknown |
296 | ._cache_win.exe | GET | 200 | 2.19.198.162:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?d6c4a4994da7c3ec | unknown | compressed | 4.66 Kb | unknown |
296 | ._cache_win.exe | GET | 200 | 69.192.161.44:80 | http://x1.c.lencr.org/ | unknown | binary | 717 b | unknown |
296 | ._cache_win.exe | GET | 200 | 184.24.77.59:80 | http://r3.o.lencr.org/MFMwUTBPME0wSzAJBgUrDgMCGgUABBRI2smg%2ByvTLU%2Fw3mjS9We3NfmzxAQUFC6zF7dYVsuuUAlA5h%2BvnYsUwsYCEgQfWrSaz3wC6Nw06o%2Fe9WFN2A%3D%3D | unknown | binary | 503 b | unknown |
296 | ._cache_win.exe | GET | 200 | 2.19.198.162:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?8744af06b0e0ce08 | unknown | compressed | 65.2 Kb | unknown |
1080 | svchost.exe | GET | 304 | 178.79.238.0:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?1b8fee253118cbef | unknown | — | — | unknown |
2640 | Synaptics.exe | GET | 200 | 174.128.246.100:80 | http://freedns.afraid.org/api/?action=getdyndns&sha=a30fa98efc092684e8d1c5cff797bcc613562978 | unknown | text | 31 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
296 | ._cache_win.exe | 51.195.68.172:80 | notifier.rarlab.com | OVH SAS | FR | unknown |
296 | ._cache_win.exe | 51.195.68.172:443 | notifier.rarlab.com | OVH SAS | FR | unknown |
296 | ._cache_win.exe | 2.19.198.162:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
296 | ._cache_win.exe | 69.192.161.44:80 | x1.c.lencr.org | AKAMAI-AS | DE | unknown |
296 | ._cache_win.exe | 184.24.77.59:80 | r3.o.lencr.org | Akamai International B.V. | DE | unknown |
2640 | Synaptics.exe | 174.128.246.100:80 | freedns.afraid.org | ST-BGP | US | unknown |
1080 | svchost.exe | 178.79.238.0:80 | ctldl.windowsupdate.com | LLNW | FR | unknown |
Domain | IP | Reputation |
|---|---|---|
notifier.rarlab.com |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
x1.c.lencr.org |
| whitelisted |
r3.o.lencr.org |
| shared |
xred.mooo.com |
| unknown |
freedns.afraid.org |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Misc activity | ET INFO DYNAMIC_DNS Query to Abused Domain *.mooo.com |