File name: | MPC-HC.1.7.13.x86.exe |
Full analysis: | https://app.any.run/tasks/12a21b34-dd1a-4162-aa7f-01ff58bb7a54 |
Verdict: | Malicious activity |
Analysis date: | December 06, 2022, 06:02:41 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 07DD6120F2AC4EB24E3E456A8605D9A6 |
SHA1: | 213E67B32DF5585F9FB50302AA317918064C6F62 |
SHA256: | BA6F1F617E9C4D3CE535A85C2FCDA39E66FC13781F4CF6197FE802994D71F0EC |
SSDEEP: | 196608:f2NlMs62Odh6YQGGPniTaBX6baBjpzU6cwexUUbkZ/+1SflWVLbVFn:2lj7GGPiTa0i9dUhgh+2WTF |
.exe | | | Win32 Executable Delphi generic (57.2) |
---|---|---|
.exe | | | Win32 Executable (generic) (18.2) |
.exe | | | Win16/32 Executable Delphi generic (8.3) |
.exe | | | Generic Win/DOS Executable (8) |
.exe | | | DOS Executable Generic (8) |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 2016-Apr-06 14:39:04 |
Detected languages: |
|
Comments: | This installation was built with Inno Setup. |
CompanyName: | MPC-HC Team |
FileDescription: | MPC-HC Setup |
FileVersion: | 1.7.13 |
LegalCopyright: | Copyright © 2002-2017 all contributors, see Authors.txt |
ProductName: | MPC-HC |
ProductVersion: | 1.7.13 |
e_magic: | MZ |
---|---|
e_cblp: | 80 |
e_cp: | 2 |
e_crlc: | - |
e_cparhdr: | 4 |
e_minalloc: | 15 |
e_maxalloc: | 65535 |
e_ss: | - |
e_sp: | 184 |
e_csum: | - |
e_ip: | - |
e_cs: | - |
e_ovno: | 26 |
e_oemid: | - |
e_oeminfo: | - |
e_lfanew: | 256 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
NumberofSections: | 8 |
TimeDateStamp: | 2016-Apr-06 14:39:04 |
PointerToSymbolTable: | - |
NumberOfSymbols: | - |
SizeOfOptionalHeader: | 224 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 4096 | 62020 | 62464 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.37521 |
.itext | 69632 | 3940 | 4096 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 5.7322 |
.data | 73728 | 3208 | 3584 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.29672 |
.bss | 77824 | 22204 | 0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | |
.idata | 102400 | 3588 | 4096 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.59781 |
.tls | 106496 | 8 | 0 | IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | |
.rdata | 110592 | 24 | 512 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.204488 |
.rsrc | 114688 | 109252 | 109568 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.34576 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 3.44483 | 744 | Latin 1 / Western European | English - United States | RT_ICON |
2 | 3.59151 | 488 | Latin 1 / Western European | English - United States | RT_ICON |
3 | 3.43939 | 296 | Latin 1 / Western European | English - United States | RT_ICON |
4 | 5.16175 | 3752 | Latin 1 / Western European | English - United States | RT_ICON |
5 | 5.58395 | 2216 | Latin 1 / Western European | English - United States | RT_ICON |
6 | 5.55458 | 1736 | Latin 1 / Western European | English - United States | RT_ICON |
7 | 5.32358 | 1384 | Latin 1 / Western European | English - United States | RT_ICON |
8 | 7.98176 | 40125 | Latin 1 / Western European | English - United States | RT_ICON |
9 | 4.54767 | 9640 | Latin 1 / Western European | English - United States | RT_ICON |
10 | 4.89498 | 4264 | Latin 1 / Western European | English - United States | RT_ICON |
advapi32.dll |
advapi32.dll (#2) |
advapi32.dll (#3) |
comctl32.dll |
kernel32.dll |
kernel32.dll (#2) |
kernel32.dll (#3) |
kernel32.dll (#4) |
oleaut32.dll |
user32.dll |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
1596 | "C:\Users\admin\AppData\Local\Temp\MPC-HC.1.7.13.x86.exe" | C:\Users\admin\AppData\Local\Temp\MPC-HC.1.7.13.x86.exe | — | Explorer.EXE |
User: admin Company: MPC-HC Team Integrity Level: MEDIUM Description: MPC-HC Setup Version: 1.7.13 | ||||
1388 | "C:\Users\admin\AppData\Local\Temp\is-9348H.tmp\MPC-HC.1.7.13.x86.tmp" /SL5="$50198,12693260,185344,C:\Users\admin\AppData\Local\Temp\MPC-HC.1.7.13.x86.exe" | C:\Users\admin\AppData\Local\Temp\is-9348H.tmp\MPC-HC.1.7.13.x86.tmp | — | MPC-HC.1.7.13.x86.exe |
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Version: 51.1052.0.0 | ||||
1128 | "C:\Users\admin\AppData\Local\Temp\MPC-HC.1.7.13.x86.exe" /SPAWNWND=$501C8 /NOTIFYWND=$50198 | C:\Users\admin\AppData\Local\Temp\MPC-HC.1.7.13.x86.exe | MPC-HC.1.7.13.x86.tmp | |
User: admin Company: MPC-HC Team Integrity Level: HIGH Description: MPC-HC Setup Version: 1.7.13 | ||||
3440 | "C:\Users\admin\AppData\Local\Temp\is-99GN5.tmp\MPC-HC.1.7.13.x86.tmp" /SL5="$6019E,12693260,185344,C:\Users\admin\AppData\Local\Temp\MPC-HC.1.7.13.x86.exe" /SPAWNWND=$501C8 /NOTIFYWND=$50198 | C:\Users\admin\AppData\Local\Temp\is-99GN5.tmp\MPC-HC.1.7.13.x86.tmp | MPC-HC.1.7.13.x86.exe | |
User: admin Integrity Level: HIGH Description: Setup/Uninstall Version: 51.1052.0.0 | ||||
1820 | "C:\Program Files\MPC-HC\mpc-hc.exe" | C:\Program Files\MPC-HC\mpc-hc.exe | — | Explorer.EXE |
User: admin Company: MPC-HC Team Integrity Level: MEDIUM Description: MPC-HC Exit code: 0 Version: 1.7.13 (e37826845) |
PID | Process | Filename | Type | |
---|---|---|---|---|
1596 | MPC-HC.1.7.13.x86.exe | C:\Users\admin\AppData\Local\Temp\is-9348H.tmp\MPC-HC.1.7.13.x86.tmp | executable | |
MD5:03BABAD995ABDD59AAAD13C389D822B7 | SHA256:E32BAE825C665ED173F8616626FBD921CCD0BA44221BD3899195730D33C663C8 | |||
3440 | MPC-HC.1.7.13.x86.tmp | C:\Program Files\MPC-HC\unins000.exe | executable | |
MD5:03BABAD995ABDD59AAAD13C389D822B7 | SHA256:E32BAE825C665ED173F8616626FBD921CCD0BA44221BD3899195730D33C663C8 | |||
3440 | MPC-HC.1.7.13.x86.tmp | C:\Program Files\MPC-HC\is-DV99O.tmp | executable | |
MD5:03BABAD995ABDD59AAAD13C389D822B7 | SHA256:E32BAE825C665ED173F8616626FBD921CCD0BA44221BD3899195730D33C663C8 | |||
3440 | MPC-HC.1.7.13.x86.tmp | C:\Program Files\MPC-HC\Lang\is-8M2MH.tmp | executable | |
MD5:FC24BD7D6CCEF6A5579DF534164E48FF | SHA256:54F705BE2E77F111C6FAAEA06E09C46CE774F3367378E5DAE73433FC84536764 | |||
3440 | MPC-HC.1.7.13.x86.tmp | C:\Program Files\MPC-HC\Lang\is-CJN7G.tmp | executable | |
MD5:FFDF6C697F6E8AD77531AADED9DB6937 | SHA256:CB56B36CA62F9846B5D8A3FEB4923B0C28EDB0AF9FAA13422CA38216DF028C35 | |||
3440 | MPC-HC.1.7.13.x86.tmp | C:\Program Files\MPC-HC\Lang\mpcresources.be.dll | executable | |
MD5:2E534CC9D4876349CDC67C5F281E93EF | SHA256:10058D71E320029787EDEB673B2766453EB33A98AFF17F76467F7499BB0FCD35 | |||
3440 | MPC-HC.1.7.13.x86.tmp | C:\Program Files\MPC-HC\Lang\is-HPR1Q.tmp | executable | |
MD5:59B71400AFAFFA8BFF147890487E1CB0 | SHA256:B7FFCEAADBA5E182C1F737C2C75C5B4304B4D5AAFD2E9861E3DB922D629B53D1 | |||
3440 | MPC-HC.1.7.13.x86.tmp | C:\Program Files\MPC-HC\Lang\is-RT40A.tmp | executable | |
MD5:797DA26022C64C49B34DC0BA52CAFF63 | SHA256:53C4BDBCBAD81EA8763F7D78F75624BB18BE951A23D9CD3867DFD5513188C659 | |||
3440 | MPC-HC.1.7.13.x86.tmp | C:\Program Files\MPC-HC\Lang\is-LE37I.tmp | executable | |
MD5:2E534CC9D4876349CDC67C5F281E93EF | SHA256:10058D71E320029787EDEB673B2766453EB33A98AFF17F76467F7499BB0FCD35 | |||
3440 | MPC-HC.1.7.13.x86.tmp | C:\Program Files\MPC-HC\Lang\mpcresources.ar.dll | executable | |
MD5:B8F1DB9F221A0390F17463B1CDA55514 | SHA256:0A19735FC0132BFA52187E122E552A26C296431B43D5270E91159E8865063DE3 |