| File name: | TIB,TIBX-ShellEx-25.8.1.39216.exe |
| Full analysis: | https://app.any.run/tasks/485b79af-1171-40f2-9e2a-798a155cb3cd |
| Verdict: | Malicious activity |
| Analysis date: | February 10, 2022, 14:28:02 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 029AC5F90BFFEFEE0F0804058BE8B85D |
| SHA1: | 3390FF88FE068DC01B491754F9C37F3C4F71648A |
| SHA256: | C058D7643A6514945716676B2095629B37CA81F8E5A958901085E6EE68B203C7 |
| SSDEEP: | 393216:DzNKqKTtyeu6iX5efOsR1zhpdfuHdHMh3MHl19m4l/9NdM:fof5zoXoOsRPIsMJm4l/FM |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| Subsystem: | Windows GUI |
|---|---|
| SubsystemVersion: | 4 |
| ImageVersion: | 6 |
| OSVersion: | 4 |
| EntryPoint: | 0x3348 |
| UninitializedDataSize: | 1024 |
| InitializedDataSize: | 162816 |
| CodeSize: | 26112 |
| LinkerVersion: | 6 |
| PEType: | PE32 |
| TimeStamp: | 2020:08:01 04:44:50+02:00 |
| MachineType: | Intel 386 or later, and compatibles |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 01-Aug-2020 02:44:50 |
| Detected languages: |
|
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000C8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 01-Aug-2020 02:44:50 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00006457 | 0x00006600 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.43499 |
.rdata | 0x00008000 | 0x00001380 | 0x00001400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.261 |
.data | 0x0000A000 | 0x00025538 | 0x00000600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.13373 |
.ndata | 0x00030000 | 0x00009000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x00039000 | 0x000010F8 | 0x00001200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.38336 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.29035 | 843 | UNKNOWN | English - United States | RT_MANIFEST |
103 | 2.16096 | 20 | UNKNOWN | English - United States | RT_GROUP_ICON |
104 | 2.6935 | 316 | UNKNOWN | English - United States | RT_DIALOG |
105 | 2.66174 | 256 | UNKNOWN | English - United States | RT_DIALOG |
106 | 2.88094 | 284 | UNKNOWN | English - United States | RT_DIALOG |
110 | 3.22336 | 872 | UNKNOWN | English - United States | RT_BITMAP |
111 | 2.48825 | 96 | UNKNOWN | English - United States | RT_DIALOG |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
SHELL32.dll |
USER32.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1380 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2604 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL C:\Users\admin\Documents\bigwhy.rtf | C:\Windows\system32\rundll32.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2712 | "C:\Users\admin\AppData\Local\Temp\TIB,TIBX-ShellEx-25.8.1.39216.exe" | C:\Users\admin\AppData\Local\Temp\TIB,TIBX-ShellEx-25.8.1.39216.exe | Explorer.EXE | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 4056 | "C:\Users\admin\AppData\Local\Temp\TIB,TIBX-ShellEx-25.8.1.39216.exe" | C:\Users\admin\AppData\Local\Temp\TIB,TIBX-ShellEx-25.8.1.39216.exe | — | Explorer.EXE | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| (PID) Process: | (2712) TIB,TIBX-ShellEx-25.8.1.39216.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tibx\OpenWithList |
| Operation: | write | Name: | (default) |
Value: | |||
| (PID) Process: | (2712) TIB,TIBX-ShellEx-25.8.1.39216.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tibx\OpenWithProgids |
| Operation: | write | Name: | tibxfile |
Value: | |||
| (PID) Process: | (2712) TIB,TIBX-ShellEx-25.8.1.39216.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tib\OpenWithList |
| Operation: | write | Name: | a |
Value: {1AC14E77-02E7-4E5D-B744-2EB1AE5198B7}\OpenWith.exe | |||
| (PID) Process: | (2712) TIB,TIBX-ShellEx-25.8.1.39216.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tib\OpenWithList |
| Operation: | write | Name: | MRUList |
Value: a | |||
| (PID) Process: | (2712) TIB,TIBX-ShellEx-25.8.1.39216.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\FileExts\.tib\OpenWithProgids |
| Operation: | write | Name: | tibfile |
Value: | |||
| (PID) Process: | (2712) TIB,TIBX-ShellEx-25.8.1.39216.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\tibfile |
| Operation: | write | Name: | (default) |
Value: Acronis True Image backup | |||
| (PID) Process: | (2712) TIB,TIBX-ShellEx-25.8.1.39216.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\tibfile\CLSID |
| Operation: | write | Name: | (default) |
Value: {C539A15B-3AF9-4c92-B771-50CB78F5C751} | |||
| (PID) Process: | (2712) TIB,TIBX-ShellEx-25.8.1.39216.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\tibfile\DefaultIcon |
| Operation: | write | Name: | (default) |
Value: C:\Program Files\Acronis\TIB-TIBX ShellEx\tishell_25_8_39216.dll,-4 | |||
| (PID) Process: | (2712) TIB,TIBX-ShellEx-25.8.1.39216.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\tibfile\Shell\open |
| Operation: | write | Name: | (default) |
Value: | |||
| (PID) Process: | (2712) TIB,TIBX-ShellEx-25.8.1.39216.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\tibfile\Shell\open\command |
| Operation: | write | Name: | (default) |
Value: explorer /idlist,%I,%L | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2712 | TIB,TIBX-ShellEx-25.8.1.39216.exe | C:\Program Files\Acronis\TIB-TIBX ShellEx\TIB_Shell-uninst.exe | executable | |
MD5:— | SHA256:— | |||
| 2712 | TIB,TIBX-ShellEx-25.8.1.39216.exe | C:\Users\admin\AppData\Local\Temp\nsy7201.tmp\System.dll | executable | |
MD5:FCCFF8CB7A1067E23FD2E2B63971A8E1 | SHA256:6FCEA34C8666B06368379C6C402B5321202C11B00889401C743FB96C516C679E | |||
| 2712 | TIB,TIBX-ShellEx-25.8.1.39216.exe | C:\Program Files\Acronis\TIB-TIBX ShellEx\tishell_25_8_39216.dll | executable | |
MD5:76F9B12FF2C3DCCBC08883F79852388F | SHA256:77E494B25DA0352415F30DF818D091D1AA78E1C8BCDEE988AA6EDEC265C4EEA7 | |||
| 2712 | TIB,TIBX-ShellEx-25.8.1.39216.exe | C:\Program Files\Acronis\TIB-TIBX ShellEx\astor_client.dll | executable | |
MD5:8558E8CE6F3052199F31B793548471CB | SHA256:332FC7747308166428D2B660A16F729C896ABD433BBB47D17057DF98DF08E318 | |||
| 2712 | TIB,TIBX-ShellEx-25.8.1.39216.exe | C:\Program Files\Acronis\TIB-TIBX ShellEx\libssl10.dll | executable | |
MD5:FD40C4DB1642E69DAE627379EEFF42E7 | SHA256:0329393F556AA2F301FC9243145284B063319041F1A44080F83869217038E5AC | |||
| 2712 | TIB,TIBX-ShellEx-25.8.1.39216.exe | C:\Program Files\Acronis\TIB-TIBX ShellEx\icudt38.dll | executable | |
MD5:A7A8139EF4C0DF2E6A797CECD097B60F | SHA256:B320843A62FBBD2DA49D0FEAE8FA13A0BC2C31B12D49F0A1BC5DD465A2128597 | |||
| 2712 | TIB,TIBX-ShellEx-25.8.1.39216.exe | C:\Program Files\Acronis\TIB-TIBX ShellEx\archive3.dll | executable | |
MD5:F242027B019C8040B592AD30776E6878 | SHA256:CFC16D5F03661927620887CE80029CB89A9184845D109D873418EDE5BB6A04CD | |||
| 2712 | TIB,TIBX-ShellEx-25.8.1.39216.exe | C:\Program Files\Acronis\TIB-TIBX ShellEx\pcs_io.dll | executable | |
MD5:6E6F5C7066DA879D3615D378078F96EA | SHA256:D80AB5DA59227A6C4751832688754C998A63EEFBF1C1A4D2A42D0E3E1E3E05A1 | |||
| 2712 | TIB,TIBX-ShellEx-25.8.1.39216.exe | C:\Program Files\Acronis\TIB-TIBX ShellEx\tishell32_25_8_39216.dll | executable | |
MD5:D2710CDFA09FB9EECCC95EA7C7CF2449 | SHA256:FDCF086E5A4BA8AC5B1A9522F6A19FB673CC5603EE418967D09477CC3EAA732D | |||
| 2712 | TIB,TIBX-ShellEx-25.8.1.39216.exe | C:\Program Files\Acronis\TIB-TIBX ShellEx\logging.dll | executable | |
MD5:B7C0EB03958A276D1CF453979B7DDCAB | SHA256:B13964BCE11B83A32FABA3B1BB8C929017436475EBAED3B08A82DDC3A17DAE16 | |||