| File name: | SetPoint6.67.83_smart.exe |
| Full analysis: | https://app.any.run/tasks/a1da5246-20ba-4e6c-859c-efd5cabe3305 |
| Verdict: | Malicious activity |
| Analysis date: | July 18, 2018, 01:34:05 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 36A9E64CCA0CA2AAF635B8AD1A5DDF73 |
| SHA1: | B73410EA4D04B3E0E8E77C87C309A4DA602917A8 |
| SHA256: | B7C5E01FC7E6452FC582EE93B19743AF54C8F6762BF6DD6B88D15E62F0858EBE |
| SSDEEP: | 98304:AQZ2M/VEQpgGqzGb12femhBy/JHm2wawQvZBlhQUNRG:AQR/VEUwzE12VG/Nm2w0fluAY |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2009:09:09 15:23:14+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 25600 |
| InitializedDataSize: | 431104 |
| UninitializedDataSize: | 16896 |
| EntryPoint: | 0x33e9 |
| OSVersion: | 5 |
| ImageVersion: | 6.1 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 6.67.83.0 |
| ProductVersionNumber: | 6.67.83.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| CompanyName: | Logitech Inc. |
| FileDescription: | Setup |
| FileVersion: | 6.67.83 |
| LegalCopyright: | Copyright � 2005-2013 Logitech. All Rights Reserved |
| ProductName: | WEB_SCore Setup |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 09-Sep-2009 13:23:14 |
| Detected languages: |
|
| CompanyName: | Logitech Inc. |
| FileDescription: | Setup |
| FileVersion: | 6.67.83 |
| LegalCopyright: | Copyright � 2005-2013 Logitech. All Rights Reserved |
| ProductName: | WEB_SCore Setup |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000E0 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 09-Sep-2009 13:23:14 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00006240 | 0x00006400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.42174 |
.rdata | 0x00008000 | 0x000018CA | 0x00001A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.87837 |
.data | 0x0000A000 | 0x0006667C | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.35872 |
.ndata | 0x00071000 | 0x00175000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x001E6000 | 0x000009F8 | 0x00000A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.5993 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.20816 | 724 | UNKNOWN | English - United States | RT_MANIFEST |
103 | 2.16096 | 20 | UNKNOWN | English - United States | RT_GROUP_ICON |
111 | 2.48825 | 96 | UNKNOWN | English - United States | RT_DIALOG |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
SHELL32.dll |
USER32.dll |
VERSION.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 340 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 916 | C:\Users\admin\AppData\Roaming\LogiShrd\SetClean\LDConfig.exe -PS2MOU:QUERY | C:\Users\admin\AppData\Roaming\LogiShrd\SetClean\LDConfig.exe | — | SetClean.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1073741825 Modules
| |||||||||||||||
| 992 | "C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\6-Unifying\Setup.exe" /S /instMode=embedded /check=yes | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\6-Unifying\Setup.exe | — | MSetup.exe | |||||||||||
User: admin Company: $Co_Name Inc. Integrity Level: HIGH Description: Setup Exit code: 0 Version: 2.50.25 Modules
| |||||||||||||||
| 1176 | C:\Users\admin\AppData\Roaming\LogiShrd\SetClean\RunNE /wait C:\Users\admin\AppData\Roaming\LogiShrd\SetClean\LDConfig.exe @-KHAL:C:\Users\admin\AppData\Local\Temp\Logishrd\SaveSettings\Khal\devices.ini | C:\Users\admin\AppData\Roaming\LogiShrd\SetClean\RunNE.exe | — | SetClean.exe | |||||||||||
User: admin Company: Logitech, Inc. Integrity Level: HIGH Description: Unifying Software (UNICODE) Exit code: 1 Version: 1.10.2 Modules
| |||||||||||||||
| 1380 | C:\Windows\Explorer.EXE | C:\Windows\explorer.exe | — | — | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1944 | "C:\Users\admin\AppData\Roaming\Logishrd\SetClean\LDConfig.exe" -KHAL:C:\Users\admin\AppData\Local\Temp\Logishrd\SaveSettings\Khal\devices.ini | C:\Users\admin\AppData\Roaming\Logishrd\SetClean\LDConfig.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 5 Modules
| |||||||||||||||
| 2424 | "C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\5-SetPoint\Setup.exe" /check=yes /level=1 /indent=2 | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\5-SetPoint\Setup.exe | — | MSetup.exe | |||||||||||
User: admin Company: Logitech Inc. Integrity Level: HIGH Description: Setup Exit code: 0 Version: 6.67.83 Modules
| |||||||||||||||
| 2440 | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\Setup.exe /smartcheck expr=SetVar(level,"1")==SetVar(indent,"2") | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\Setup.exe | SetPoint6.67.83_smart.exe | ||||||||||||
User: admin Company: Logitech, Inc. Integrity Level: MEDIUM Description: Logitech Installer Exit code: 0 Version: 2.20.0.13 Modules
| |||||||||||||||
| 3548 | "C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\MSetup.exe" /smartcheck expr=SetVar(level,"1")==SetVar(indent,"2") | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\MSetup.exe | — | Setup.exe | |||||||||||
User: admin Company: Logitech, Inc. Integrity Level: MEDIUM Description: Logitech Installer Exit code: 3221226540 Version: 2.20.0.13 Modules
| |||||||||||||||
| 3624 | "C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\tools\SetClean.exe" /check_legacy /regKey=Logitech\sp6\Legacy /savedFilesFolder=C:\Users\admin\AppData\Local\Temp\Logishrd\SaveSettings /level=1 /indent=2 | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\tools\SetClean.exe | MSetup.exe | ||||||||||||
User: admin Company: Logitech Inc. Integrity Level: HIGH Description: Setup Exit code: 0 Version: 3.20.36 Modules
| |||||||||||||||
| (PID) Process: | (2440) Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2440) Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (4020) MSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (4020) MSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2424) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Logitech\Parameters |
| Operation: | write | Name: | MIeRVar |
Value: Errors | |||
| (PID) Process: | (2424) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Logitech\Parameters |
| Operation: | write | Name: | channel |
Value: retail | |||
| (PID) Process: | (2424) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Logitech\Parameters |
| Operation: | write | Name: | LU |
Value: | |||
| (PID) Process: | (2424) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Logitech\Parameters |
| Operation: | write | Name: | LogPath |
Value: sp6_log | |||
| (PID) Process: | (2424) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Logitech\Parameters |
| Operation: | write | Name: | LogFileName |
Value: sp6_setup.log | |||
| (PID) Process: | (2424) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Logitech\sp6 |
| Operation: | write | Name: | Errors |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4008 | SetPoint6.67.83_smart.exe | C:\Users\admin\AppData\Roaming\Logishrd\sp6_log\sp6_setup.log | binary | |
MD5:— | SHA256:— | |||
| 4008 | SetPoint6.67.83_smart.exe | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\5-SetPoint\Setup.exe | executable | |
MD5:— | SHA256:— | |||
| 4008 | SetPoint6.67.83_smart.exe | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\SetupDll.dll | executable | |
MD5:6716F4E5EE82FFEF2991B925DEC0C760 | SHA256:DACA629F2FC1C97340F4FE77CF25677952E58A369CFA8953F9F11D599924ED6D | |||
| 4008 | SetPoint6.67.83_smart.exe | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\Setup.exe | executable | |
MD5:467C3855DB3135F24A747244567D5A92 | SHA256:7CE76D6F05C3292760563FF9E4AAE997A1EADAFEDD707131757E9E0B83E17410 | |||
| 4008 | SetPoint6.67.83_smart.exe | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\autorun.inf | text | |
MD5:267582ABA213F64445B8FC1A10B8794B | SHA256:16EEDFE8525B0044943BFD8FA3AE560CC74C0EA91C361C7BF338C0A193E11960 | |||
| 4008 | SetPoint6.67.83_smart.exe | C:\Users\admin\AppData\Local\Temp\nsj3F9A.tmp\System.dll | executable | |
MD5:B9F430F71C7144D8FF4AB94BE2785AA6 | SHA256:B496E81A74CE871236ABCD096FB9A6B210B456BEBAA7464FA844B3241E51A655 | |||
| 4008 | SetPoint6.67.83_smart.exe | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\MSetup.exe | executable | |
MD5:46E4C130532DD44F81CC545970B1BA7D | SHA256:48DA3AA7910F3DCF8739DCDDABB25F0F877B68ABF3EE161B884428BCC864EEE9 | |||
| 4008 | SetPoint6.67.83_smart.exe | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\10-Uninstall\compcfg.ini | text | |
MD5:C0CAF31CADD9BA3D2E7163B46A8F3E64 | SHA256:79CFF3ED076ADA8D5024742F5FA78FB7897C7847547E469C7C280DB36A35106B | |||
| 4008 | SetPoint6.67.83_smart.exe | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\11-Unifying\compcfg.ini | text | |
MD5:CD20E442BA53C88F8B19BFA70C5C9BF5 | SHA256:E961C4458A7E2AA36C00127ACE56660E35511BB73B3EE3219DABD12EBA1475E2 | |||
| 4008 | SetPoint6.67.83_smart.exe | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\2-Install\compcfg.ini | text | |
MD5:7695A6DE598CD3A8C1F81762C6A4E668 | SHA256:5B9628DE725C6F61EC6652A2350EBE9BF1F516A4585C8CA2EA4AF47DFA311EBC | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4020 | MSetup.exe | GET | — | 54.192.98.22:80 | http://d23iz4esrwkib6.cloudfront.net/lu/depot/cdbu/setpoint_new/6.67/0/files.latest/6_unifying_logitech_32.exe?/lu/depot/cdbu/setpoint_new/6.67/0/files.latest/6_unifying_logitech_32.exe%3f& | US | — | — | shared |
4020 | MSetup.exe | GET | — | 54.192.98.22:80 | http://d23iz4esrwkib6.cloudfront.net/lu/depot/cdbu/setpoint_new/6.67/0/files.latest/5_setpoint_logitech_32.exe?/lu/depot/cdbu/setpoint_new/6.67/0/files.latest/5_setpoint_logitech_32.exe%3f& | US | — | — | shared |
4020 | MSetup.exe | GET | — | 54.192.98.22:80 | http://d23iz4esrwkib6.cloudfront.net/lu/depot/cdbu/setpoint_new/6.67/0/files.latest/3a_redistr32_logitech_32.exe?/lu/depot/cdbu/setpoint_new/6.67/0/files.latest/3a_redistr32_logitech_32.exe%3f& | US | — | — | shared |
4020 | MSetup.exe | GET | 302 | 52.86.141.238:80 | http://updates.logitech.com/logitech/controldevices/sp/6.67.1234_install_ml/0/_w7/32/sp.man.xml?lu.uos=_w7&lu.ubi=32&lu.ulv=2.40.29&lu.hp=setpoint&lu.hv=6.67.1234_install_ml&lu.hpo=0&lu.hl=enu&lu.hbr=logitech&h.10-uninstall=&h.2-install=&h.3a-redistr32=9.00.00&h.5-setpoint=6.65.00&h.6-unifying=2.00.00&h.7b-postcheck=&h.20-legacypre=&h.11-unifying=&h.3b-redistr64=9.00.00&h.7a-lu=9.990000&h.30-legacypost= | US | text | 9 b | suspicious |
4020 | MSetup.exe | GET | 302 | 52.86.141.238:80 | http://updates.logitech.com/lu/depot/cdbu/setpoint_new/6.67/0/files.latest/6_unifying_logitech_32.exe?& | US | text | 9 b | suspicious |
4020 | MSetup.exe | GET | 302 | 52.86.141.238:80 | http://updates.logitech.com/logitech/controldevices/sp/6.67.1234_install_ml/0/_w7/32/sp.man.xml?lu.uos=_w7&lu.ubi=32&lu.ulv=2.40.29&lu.hp=setpoint&lu.hv=6.67.1234_install_ml&lu.hpo=0&lu.hl=enu&lu.hbr=logitech&h.10-uninstall=&h.2-install=&h.3a-redistr32=9.00.00&h.5-setpoint=6.65.00&h.6-unifying=2.00.00&h.7b-postcheck=&h.20-legacypre=&h.11-unifying=&h.3b-redistr64=9.00.00&h.7a-lu=9.990000&h.30-legacypost= | US | text | 9 b | suspicious |
4020 | MSetup.exe | GET | 200 | 54.192.98.22:80 | http://d23iz4esrwkib6.cloudfront.net/lu/depot/cdbu/setpoint_new/6.67/0/files.latest/5_setpoint_logitech_32.exe.sig?/lu/depot/cdbu/setpoint_new/6.67/0/files.latest/5_setpoint_logitech_32.exe.sig%3f& | US | text | 128 b | shared |
4020 | MSetup.exe | GET | 200 | 54.192.98.22:80 | http://d23iz4esrwkib6.cloudfront.net/lu/depot/cdbu/setpoint_new/6.67/0/manif_from_ml_installer.latest/setpoint_ml_logitech.man.xml?/logitech/controldevices/sp/6.67.1234_install_ml/0/_w7/32/sp.man.xml%3flu.uos=_w7&lu.ubi=32&lu.ulv=2.40.29&lu.hp=setpoint&lu.hv=6.67.1234_install_ml&lu.hpo=0&lu.hl=enu&lu.hbr=logitech&h.10-uninstall=&h.2-install=&h.3a-redistr32=9.00.00&h.5-setpoint=6.65.00&h.6-unifying=2.00.00&h.7b-postcheck=&h.20-legacypre=&h.11-unifying=&h.3b-redistr64=9.00.00&h.7a-lu=9.990000&h.30-legacypost= | US | xml | 22.8 Kb | shared |
4020 | MSetup.exe | GET | 200 | 54.192.98.22:80 | http://d23iz4esrwkib6.cloudfront.net/lu/depot/cdbu/setpoint_new/6.67/0/manif_from_ml_installer.latest/setpoint_ml_logitech.man.xml.sig?/logitech/controldevices/sp/6.67.1234_install_ml/0/_w7/32/sp.man.xml.sig%3flu.uos=_w7&lu.ubi=32&lu.ulv=2.40.29&lu.hp=setpoint&lu.hv=6.67.1234_install_ml&lu.hpo=0&lu.hl=enu&lu.hbr=logitech&h.10-uninstall=&h.2-install=&h.3a-redistr32=9.00.00&h.5-setpoint=6.65.00&h.6-unifying=2.00.00&h.7b-postcheck=&h.20-legacypre=&h.11-unifying=&h.3b-redistr64=9.00.00&h.7a-lu=9.990000&h.30-legacypost= | US | text | 128 b | shared |
4020 | MSetup.exe | GET | 302 | 52.86.141.238:80 | http://updates.logitech.com/lu/depot/cdbu/setpoint_new/6.67/0/files.latest/5_setpoint_logitech_32.exe.sig?& | US | text | 9 b | suspicious |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4020 | MSetup.exe | 52.86.141.238:80 | updates.logitech.com | Amazon.com, Inc. | US | unknown |
4020 | MSetup.exe | 54.192.98.22:80 | d23iz4esrwkib6.cloudfront.net | Amazon.com, Inc. | US | unknown |
Domain | IP | Reputation |
|---|---|---|
updates.logitech.com |
| suspicious |
d23iz4esrwkib6.cloudfront.net |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
4020 | MSetup.exe | Potentially Bad Traffic | ET POLICY Executable served from Amazon S3 |
4020 | MSetup.exe | Potentially Bad Traffic | ET POLICY Executable served from Amazon S3 |
4020 | MSetup.exe | Potentially Bad Traffic | ET POLICY Executable served from Amazon S3 |
4020 | MSetup.exe | Potentially Bad Traffic | ET POLICY Executable served from Amazon S3 |
4020 | MSetup.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
4020 | MSetup.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
4020 | MSetup.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
4020 | MSetup.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
Process | Message |
|---|---|
Setup.exe | BOOTLOADER: -- Startup did not find file extension [/smartcheck expr=SetVar(level,"1")==SetVar(indent,"2") ]
|
MSetup.exe | 02:35:24:523[4020] C:\Users\admin\AppData\Local\Temp\MSetup_2018-07-18_023524.log |