| File name: | SetPoint6.67.83_smart.exe |
| Full analysis: | https://app.any.run/tasks/a1da5246-20ba-4e6c-859c-efd5cabe3305 |
| Verdict: | Malicious activity |
| Analysis date: | July 18, 2018, 01:34:05 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 36A9E64CCA0CA2AAF635B8AD1A5DDF73 |
| SHA1: | B73410EA4D04B3E0E8E77C87C309A4DA602917A8 |
| SHA256: | B7C5E01FC7E6452FC582EE93B19743AF54C8F6762BF6DD6B88D15E62F0858EBE |
| SSDEEP: | 98304:AQZ2M/VEQpgGqzGb12femhBy/JHm2wawQvZBlhQUNRG:AQR/VEUwzE12VG/Nm2w0fluAY |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2009:09:09 15:23:14+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 25600 |
| InitializedDataSize: | 431104 |
| UninitializedDataSize: | 16896 |
| EntryPoint: | 0x33e9 |
| OSVersion: | 5 |
| ImageVersion: | 6.1 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 6.67.83.0 |
| ProductVersionNumber: | 6.67.83.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| CompanyName: | Logitech Inc. |
| FileDescription: | Setup |
| FileVersion: | 6.67.83 |
| LegalCopyright: | Copyright � 2005-2013 Logitech. All Rights Reserved |
| ProductName: | WEB_SCore Setup |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 09-Sep-2009 13:23:14 |
| Detected languages: |
|
| CompanyName: | Logitech Inc. |
| FileDescription: | Setup |
| FileVersion: | 6.67.83 |
| LegalCopyright: | Copyright � 2005-2013 Logitech. All Rights Reserved |
| ProductName: | WEB_SCore Setup |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000E0 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 09-Sep-2009 13:23:14 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00006240 | 0x00006400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.42174 |
.rdata | 0x00008000 | 0x000018CA | 0x00001A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.87837 |
.data | 0x0000A000 | 0x0006667C | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 1.35872 |
.ndata | 0x00071000 | 0x00175000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x001E6000 | 0x000009F8 | 0x00000A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.5993 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.20816 | 724 | UNKNOWN | English - United States | RT_MANIFEST |
103 | 2.16096 | 20 | UNKNOWN | English - United States | RT_GROUP_ICON |
111 | 2.48825 | 96 | UNKNOWN | English - United States | RT_DIALOG |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
SHELL32.dll |
USER32.dll |
VERSION.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 340 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 916 | C:\Users\admin\AppData\Roaming\LogiShrd\SetClean\LDConfig.exe -PS2MOU:QUERY | C:\Users\admin\AppData\Roaming\LogiShrd\SetClean\LDConfig.exe | — | SetClean.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 1073741825 Modules
| |||||||||||||||
| 992 | "C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\6-Unifying\Setup.exe" /S /instMode=embedded /check=yes | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\6-Unifying\Setup.exe | — | MSetup.exe | |||||||||||
User: admin Company: $Co_Name Inc. Integrity Level: HIGH Description: Setup Exit code: 0 Version: 2.50.25 Modules
| |||||||||||||||
| 1176 | C:\Users\admin\AppData\Roaming\LogiShrd\SetClean\RunNE /wait C:\Users\admin\AppData\Roaming\LogiShrd\SetClean\LDConfig.exe @-KHAL:C:\Users\admin\AppData\Local\Temp\Logishrd\SaveSettings\Khal\devices.ini | C:\Users\admin\AppData\Roaming\LogiShrd\SetClean\RunNE.exe | — | SetClean.exe | |||||||||||
User: admin Company: Logitech, Inc. Integrity Level: HIGH Description: Unifying Software (UNICODE) Exit code: 1 Version: 1.10.2 Modules
| |||||||||||||||
| 1380 | C:\Windows\Explorer.EXE | C:\Windows\explorer.exe | — | — | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1944 | "C:\Users\admin\AppData\Roaming\Logishrd\SetClean\LDConfig.exe" -KHAL:C:\Users\admin\AppData\Local\Temp\Logishrd\SaveSettings\Khal\devices.ini | C:\Users\admin\AppData\Roaming\Logishrd\SetClean\LDConfig.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 5 Modules
| |||||||||||||||
| 2424 | "C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\5-SetPoint\Setup.exe" /check=yes /level=1 /indent=2 | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\5-SetPoint\Setup.exe | — | MSetup.exe | |||||||||||
User: admin Company: Logitech Inc. Integrity Level: HIGH Description: Setup Exit code: 0 Version: 6.67.83 Modules
| |||||||||||||||
| 2440 | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\Setup.exe /smartcheck expr=SetVar(level,"1")==SetVar(indent,"2") | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\Setup.exe | SetPoint6.67.83_smart.exe | ||||||||||||
User: admin Company: Logitech, Inc. Integrity Level: MEDIUM Description: Logitech Installer Exit code: 0 Version: 2.20.0.13 Modules
| |||||||||||||||
| 3548 | "C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\MSetup.exe" /smartcheck expr=SetVar(level,"1")==SetVar(indent,"2") | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\MSetup.exe | — | Setup.exe | |||||||||||
User: admin Company: Logitech, Inc. Integrity Level: MEDIUM Description: Logitech Installer Exit code: 3221226540 Version: 2.20.0.13 Modules
| |||||||||||||||
| 3624 | "C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\tools\SetClean.exe" /check_legacy /regKey=Logitech\sp6\Legacy /savedFilesFolder=C:\Users\admin\AppData\Local\Temp\Logishrd\SaveSettings /level=1 /indent=2 | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\tools\SetClean.exe | MSetup.exe | ||||||||||||
User: admin Company: Logitech Inc. Integrity Level: HIGH Description: Setup Exit code: 0 Version: 3.20.36 Modules
| |||||||||||||||
| (PID) Process: | (2440) Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2440) Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (4020) MSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (4020) MSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2424) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Logitech\Parameters |
| Operation: | write | Name: | MIeRVar |
Value: Errors | |||
| (PID) Process: | (2424) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Logitech\Parameters |
| Operation: | write | Name: | channel |
Value: retail | |||
| (PID) Process: | (2424) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Logitech\Parameters |
| Operation: | write | Name: | LU |
Value: | |||
| (PID) Process: | (2424) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Logitech\Parameters |
| Operation: | write | Name: | LogPath |
Value: sp6_log | |||
| (PID) Process: | (2424) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Logitech\Parameters |
| Operation: | write | Name: | LogFileName |
Value: sp6_setup.log | |||
| (PID) Process: | (2424) Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Logitech\sp6 |
| Operation: | write | Name: | Errors |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4008 | SetPoint6.67.83_smart.exe | C:\Users\admin\AppData\Roaming\Logishrd\sp6_log\sp6_setup.log | binary | |
MD5:— | SHA256:— | |||
| 4008 | SetPoint6.67.83_smart.exe | C:\Users\admin\AppData\Local\Temp\nsj3F9A.tmp\System.dll | executable | |
MD5:B9F430F71C7144D8FF4AB94BE2785AA6 | SHA256:B496E81A74CE871236ABCD096FB9A6B210B456BEBAA7464FA844B3241E51A655 | |||
| 4008 | SetPoint6.67.83_smart.exe | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\MSetup.exe | executable | |
MD5:46E4C130532DD44F81CC545970B1BA7D | SHA256:48DA3AA7910F3DCF8739DCDDABB25F0F877B68ABF3EE161B884428BCC864EEE9 | |||
| 4008 | SetPoint6.67.83_smart.exe | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\30-LegacyPost\compcfg.ini | text | |
MD5:F3589090A17AC8EEFF0AF57B17B36368 | SHA256:E24B4E34B8DE789F2411F7F1C3609BBDDEEBA0F5EDF75EF05B28422FB0D111F8 | |||
| 4008 | SetPoint6.67.83_smart.exe | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\5-SetPoint\Setup.exe | executable | |
MD5:— | SHA256:— | |||
| 4008 | SetPoint6.67.83_smart.exe | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\2-Install\setup.exe | executable | |
MD5:222AA7F9DD28A7775E1BC7BEB4CE1C40 | SHA256:6ECE33B6710BD668A2B90BBFB1424A298A23102D966A437412F40F8E2492EEF0 | |||
| 4008 | SetPoint6.67.83_smart.exe | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\5-SetPoint\compcfg.ini | text | |
MD5:E119905414F985238B0DF742E73A5DE6 | SHA256:13D40BEC3C7BB3B372C8297272E97C621ADE2A4DE7B244EBBE4F81E0E6D9914F | |||
| 4008 | SetPoint6.67.83_smart.exe | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\3a-Redistr32\compcfg.ini | text | |
MD5:FD64BBF67733BDD9BD75EFEEE0528F68 | SHA256:15FED05A30DAD844D9F7104C77C8B5E2B8E7B424FCBAC7ABADC75107D2D4AE20 | |||
| 4008 | SetPoint6.67.83_smart.exe | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\setup.ini | text | |
MD5:D404282EE97DE455F4DE311AA0CF0095 | SHA256:5431F1EB17C6101B161D241A30672D744584980DF4E631DFCAEE111E39B29C2C | |||
| 4008 | SetPoint6.67.83_smart.exe | C:\Users\admin\AppData\Local\Temp\Logitech\SetPointSI_1\10-Uninstall\compcfg.ini | text | |
MD5:C0CAF31CADD9BA3D2E7163B46A8F3E64 | SHA256:79CFF3ED076ADA8D5024742F5FA78FB7897C7847547E469C7C280DB36A35106B | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4020 | MSetup.exe | GET | — | 54.192.98.22:80 | http://d23iz4esrwkib6.cloudfront.net/lu/depot/cdbu/setpoint_new/6.67/0/files.latest/5_setpoint_logitech_32.exe?/lu/depot/cdbu/setpoint_new/6.67/0/files.latest/5_setpoint_logitech_32.exe%3f& | US | — | — | shared |
4020 | MSetup.exe | GET | — | 54.192.98.22:80 | http://d23iz4esrwkib6.cloudfront.net/lu/depot/cdbu/setpoint_new/6.67/0/files.latest/7a_lu_logitech_32.exe?/lu/depot/cdbu/setpoint_new/6.67/0/files.latest/7a_lu_logitech_32.exe%3f& | US | — | — | shared |
4020 | MSetup.exe | GET | — | 54.192.98.22:80 | http://d23iz4esrwkib6.cloudfront.net/lu/depot/cdbu/setpoint_new/6.67/0/files.latest/6_unifying_logitech_32.exe?/lu/depot/cdbu/setpoint_new/6.67/0/files.latest/6_unifying_logitech_32.exe%3f& | US | — | — | shared |
4020 | MSetup.exe | GET | — | 54.192.98.22:80 | http://d23iz4esrwkib6.cloudfront.net/lu/depot/cdbu/setpoint_new/6.67/0/files.latest/3a_redistr32_logitech_32.exe?/lu/depot/cdbu/setpoint_new/6.67/0/files.latest/3a_redistr32_logitech_32.exe%3f& | US | — | — | shared |
4020 | MSetup.exe | GET | 302 | 52.86.141.238:80 | http://updates.logitech.com/lu/depot/cdbu/setpoint_new/6.67/0/files.latest/3a_redistr32_logitech_32.exe?& | US | text | 9 b | suspicious |
4020 | MSetup.exe | GET | 302 | 52.86.141.238:80 | http://updates.logitech.com/lu/depot/cdbu/setpoint_new/6.67/0/files.latest/5_setpoint_logitech_32.exe?& | US | text | 9 b | suspicious |
4020 | MSetup.exe | GET | 302 | 52.86.141.238:80 | http://updates.logitech.com/logitech/controldevices/sp/6.67.1234_install_ml/0/_w7/32/sp.man.xml.sig?lu.uos=_w7&lu.ubi=32&lu.ulv=2.40.29&lu.hp=setpoint&lu.hv=6.67.1234_install_ml&lu.hpo=0&lu.hl=enu&lu.hbr=logitech&h.10-uninstall=&h.2-install=&h.3a-redistr32=9.00.00&h.5-setpoint=6.65.00&h.6-unifying=2.00.00&h.7b-postcheck=&h.20-legacypre=&h.11-unifying=&h.3b-redistr64=9.00.00&h.7a-lu=9.990000&h.30-legacypost= | US | text | 9 b | suspicious |
4020 | MSetup.exe | GET | 302 | 52.86.141.238:80 | http://updates.logitech.com/logitech/controldevices/sp/6.67.1234_install_ml/0/_w7/32/sp.man.xml?lu.uos=_w7&lu.ubi=32&lu.ulv=2.40.29&lu.hp=setpoint&lu.hv=6.67.1234_install_ml&lu.hpo=0&lu.hl=enu&lu.hbr=logitech&h.10-uninstall=&h.2-install=&h.3a-redistr32=9.00.00&h.5-setpoint=6.65.00&h.6-unifying=2.00.00&h.7b-postcheck=&h.20-legacypre=&h.11-unifying=&h.3b-redistr64=9.00.00&h.7a-lu=9.990000&h.30-legacypost= | US | text | 9 b | suspicious |
4020 | MSetup.exe | GET | 200 | 54.192.98.22:80 | http://d23iz4esrwkib6.cloudfront.net/lu/depot/cdbu/setpoint_new/6.67/0/manif_from_ml_installer.latest/setpoint_ml_logitech.man.xml?/logitech/controldevices/sp/6.67.1234_install_ml/0/_w7/32/sp.man.xml%3flu.uos=_w7&lu.ubi=32&lu.ulv=2.40.29&lu.hp=setpoint&lu.hv=6.67.1234_install_ml&lu.hpo=0&lu.hl=enu&lu.hbr=logitech&h.10-uninstall=&h.2-install=&h.3a-redistr32=9.00.00&h.5-setpoint=6.65.00&h.6-unifying=2.00.00&h.7b-postcheck=&h.20-legacypre=&h.11-unifying=&h.3b-redistr64=9.00.00&h.7a-lu=9.990000&h.30-legacypost= | US | xml | 22.8 Kb | shared |
4020 | MSetup.exe | GET | 200 | 54.192.98.22:80 | http://d23iz4esrwkib6.cloudfront.net/lu/depot/cdbu/setpoint_new/6.67/0/manif_from_ml_installer.latest/setpoint_ml_logitech.man.xml?/logitech/controldevices/sp/6.67.1234_install_ml/0/_w7/32/sp.man.xml%3flu.uos=_w7&lu.ubi=32&lu.ulv=2.40.29&lu.hp=setpoint&lu.hv=6.67.1234_install_ml&lu.hpo=0&lu.hl=enu&lu.hbr=logitech&h.10-uninstall=&h.2-install=&h.3a-redistr32=9.00.00&h.5-setpoint=6.65.00&h.6-unifying=2.00.00&h.7b-postcheck=&h.20-legacypre=&h.11-unifying=&h.3b-redistr64=9.00.00&h.7a-lu=9.990000&h.30-legacypost= | US | xml | 22.8 Kb | shared |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4020 | MSetup.exe | 54.192.98.22:80 | d23iz4esrwkib6.cloudfront.net | Amazon.com, Inc. | US | unknown |
4020 | MSetup.exe | 52.86.141.238:80 | updates.logitech.com | Amazon.com, Inc. | US | unknown |
Domain | IP | Reputation |
|---|---|---|
updates.logitech.com |
| suspicious |
d23iz4esrwkib6.cloudfront.net |
| shared |
PID | Process | Class | Message |
|---|---|---|---|
4020 | MSetup.exe | Potentially Bad Traffic | ET POLICY Executable served from Amazon S3 |
4020 | MSetup.exe | Potentially Bad Traffic | ET POLICY Executable served from Amazon S3 |
4020 | MSetup.exe | Potentially Bad Traffic | ET POLICY Executable served from Amazon S3 |
4020 | MSetup.exe | Potentially Bad Traffic | ET POLICY Executable served from Amazon S3 |
4020 | MSetup.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
4020 | MSetup.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
4020 | MSetup.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
4020 | MSetup.exe | Potential Corporate Privacy Violation | ET POLICY PE EXE or DLL Windows file download HTTP |
Process | Message |
|---|---|
Setup.exe | BOOTLOADER: -- Startup did not find file extension [/smartcheck expr=SetVar(level,"1")==SetVar(indent,"2") ]
|
MSetup.exe | 02:35:24:523[4020] C:\Users\admin\AppData\Local\Temp\MSetup_2018-07-18_023524.log |