| File name: | cold-turkey-4-3.exe |
| Full analysis: | https://app.any.run/tasks/039a0d6a-1afc-42c6-9b3a-7a4e84dd5341 |
| Verdict: | Malicious activity |
| Analysis date: | November 19, 2023, 12:05:07 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 4E1FEEDEF4784AD3031A9BA22B3DE6C8 |
| SHA1: | 7404A10F0F165263ABAB779D25A8E5D1D0256663 |
| SHA256: | C23C718E0B75E6990D9B08076B52418AABDC286766C62EF8E2B2C6DE02081EC6 |
| SSDEEP: | 98304:W+QqZ8fzB4oKfYlMmzoe93sY3XpTkfMrzonRADXey61Um7VGOY1ib91cbVmMmeC6:4t+MqEbjmV45nUi |
| .exe | | | Inno Setup installer (67.7) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (25.6) |
| .exe | | | Win32 Executable (generic) (2.7) |
| .exe | | | Win16/32 Executable Delphi generic (1.2) |
| .exe | | | Generic Win/DOS Executable (1.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:09:13 11:00:51+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741376 |
| InitializedDataSize: | 95232 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6.1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Cold Turkey Software, Inc. |
| FileDescription: | Cold Turkey Blocker Setup |
| FileVersion: | |
| LegalCopyright: | |
| OriginalFileName: | |
| ProductName: | Cold Turkey Blocker |
| ProductVersion: | 4.3 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 752 | "C:\Program Files\Cold Turkey\ServiceHub.Helper.exe" | C:\Program Files\Cold Turkey\ServiceHub.Helper.exe | ServiceHub.Power.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: ServiceHub.Helper Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 1508 | "C:\Program Files\Cold Turkey\ServiceHub.Power.exe" | C:\Program Files\Cold Turkey\ServiceHub.Power.exe | services.exe | ||||||||||||
User: SYSTEM Integrity Level: SYSTEM Description: ServiceHub.Power Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2056 | "C:\Program Files\Cold Turkey\CTServiceInstaller.exe" | C:\Program Files\Cold Turkey\CTServiceInstaller.exe | — | cold-turkey-4-3.tmp | |||||||||||
User: admin Company: Cold Turkey Software Inc. Integrity Level: HIGH Description: CTServiceInstaller Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2116 | "C:\Program Files\Cold Turkey\Cold Turkey Blocker.exe" | C:\Program Files\Cold Turkey\Cold Turkey Blocker.exe | explorer.exe | ||||||||||||
User: admin Company: Cold Turkey Software Inc. Integrity Level: MEDIUM Description: Cold Turkey Blocker Exit code: 0 Version: 4.3.0.0 Modules
| |||||||||||||||
| 2300 | "C:\Program Files\Cold Turkey\Cold Turkey Blocker.exe" | C:\Program Files\Cold Turkey\Cold Turkey Blocker.exe | explorer.exe | ||||||||||||
User: admin Company: Cold Turkey Software Inc. Integrity Level: MEDIUM Description: Cold Turkey Blocker Exit code: 0 Version: 4.3.0.0 Modules
| |||||||||||||||
| 3028 | SetupUtility.exe /screboot | C:\bee957f231a1b8949513f6b1f2b7c4\SetupUtility.exe | — | Setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft .NET Framework 4.5 Setup Exit code: 0 Version: 14.7.2558.0 built by: NET471REL1 Modules
| |||||||||||||||
| 3156 | "C:\Users\admin\AppData\Local\Temp\is-510S3.tmp\cold-turkey-4-3.tmp" /SL5="$60134,6728624,837632,C:\Users\admin\AppData\Local\Temp\cold-turkey-4-3.exe" | C:\Users\admin\AppData\Local\Temp\is-510S3.tmp\cold-turkey-4-3.tmp | — | cold-turkey-4-3.exe | |||||||||||
User: admin Company: Cold Turkey Software, Inc. Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 3448 | "C:\Users\admin\AppData\Local\Temp\cold-turkey-4-3.exe" | C:\Users\admin\AppData\Local\Temp\cold-turkey-4-3.exe | — | explorer.exe | |||||||||||
User: admin Company: Cold Turkey Software, Inc. Integrity Level: MEDIUM Description: Cold Turkey Blocker Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 3464 | "C:\Users\admin\AppData\Local\Temp\is-0IPPR.tmp\cold-turkey-4-3.tmp" /SL5="$70186,6728624,837632,C:\Users\admin\AppData\Local\Temp\cold-turkey-4-3.exe" /SPAWNWND=$501F6 /NOTIFYWND=$60134 | C:\Users\admin\AppData\Local\Temp\is-0IPPR.tmp\cold-turkey-4-3.tmp | — | cold-turkey-4-3.exe | |||||||||||
User: admin Company: Cold Turkey Software, Inc. Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 3572 | "C:\Users\admin\AppData\Local\Temp\cold-turkey-4-3.exe" /SPAWNWND=$501F6 /NOTIFYWND=$60134 | C:\Users\admin\AppData\Local\Temp\cold-turkey-4-3.exe | cold-turkey-4-3.tmp | ||||||||||||
User: admin Company: Cold Turkey Software, Inc. Integrity Level: HIGH Description: Cold Turkey Blocker Setup Exit code: 0 Version: Modules
| |||||||||||||||
| (PID) Process: | (3464) cold-turkey-4-3.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3464) cold-turkey-4-3.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3464) cold-turkey-4-3.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3464) cold-turkey-4-3.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3596) netsh.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3888) netsh.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3988) Setup.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (4040) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{784E2847-F83C-4B00-AE03-5AF10C50E479}\{50830C6A-FC7F-4591-8A53-F202885CA60F} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (4040) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{784E2847-F83C-4B00-AE03-5AF10C50E479} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (4040) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{2769D8E4-923F-48BB-9411-BF680144BCCE} |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3464 | cold-turkey-4-3.tmp | C:\Program Files\Cold Turkey\is-UHP5R.tmp | executable | |
MD5:0E086B159AD8DD140C08AC2915A6EFFE | SHA256:085BA841A7A4DF1DF4574DE1C292ED488BC2E80E269157CA0056BDFC70FB1CD0 | |||
| 3464 | cold-turkey-4-3.tmp | C:\Program Files\Cold Turkey\is-912NL.tmp | executable | |
MD5:10749CDC412FE224B1105231598C85EC | SHA256:06B916E9C702168ABBBF8FA197B812ACA5068DCE1EB3112307270AF0568C027B | |||
| 3464 | cold-turkey-4-3.tmp | C:\Program Files\Cold Turkey\CTHostInstaller.exe | executable | |
MD5:BFE27AE92274F2861C135912ECB120D0 | SHA256:2389CF414553F7E66DC83CC007C87F7C7D2C7328D83480EB0FFEC7F3A9F055AF | |||
| 3448 | cold-turkey-4-3.exe | C:\Users\admin\AppData\Local\Temp\is-510S3.tmp\cold-turkey-4-3.tmp | executable | |
MD5:BD1E68FBA4152B139E4E7B8718B86366 | SHA256:D1A45B8D5F9C898356726DCBD0A4CA35BE1F31C979823C2BA601FCD492DD5267 | |||
| 3464 | cold-turkey-4-3.tmp | C:\Program Files\Cold Turkey\unins000.exe | executable | |
MD5:500B83216DD3683D1A8D850E370100C4 | SHA256:AA5C169EE43F1D8111B458D6620A511C23DBF4B966B2B2309C56397CEFCE4EA0 | |||
| 3464 | cold-turkey-4-3.tmp | C:\Program Files\Cold Turkey\is-1FA5Q.tmp | binary | |
MD5:06F8A880BDA481AF8FDE7B1E85276085 | SHA256:DB65EF15747F119E6645381F3EF1E7F9C2F7F48B227D5B079C5EE10D64DE79C6 | |||
| 3464 | cold-turkey-4-3.tmp | C:\Program Files\Cold Turkey\CTMsgHostEdge.exe | executable | |
MD5:C7E99DB3117C14B9D3CEE1FBEF0E1661 | SHA256:2D84A9129B5A18D25DA47821274407599F3211BD345C8F9FE6EE7C4BA3AE2EBF | |||
| 3464 | cold-turkey-4-3.tmp | C:\Program Files\Cold Turkey\is-HIE20.tmp | binary | |
MD5:0A8AF25D1F9D0A3D27C8DCE58C8E4B86 | SHA256:6949974F9F8BC30A1EBA5747B854C2F8C9B9CA0D315251830DF3EB2044D9C53D | |||
| 3464 | cold-turkey-4-3.tmp | C:\Program Files\Cold Turkey\CTMsgHostEdge.json | binary | |
MD5:0A8AF25D1F9D0A3D27C8DCE58C8E4B86 | SHA256:6949974F9F8BC30A1EBA5747B854C2F8C9B9CA0D315251830DF3EB2044D9C53D | |||
| 3464 | cold-turkey-4-3.tmp | C:\Program Files\Cold Turkey\CTMsgHostFirefox.json | binary | |
MD5:06F8A880BDA481AF8FDE7B1E85276085 | SHA256:DB65EF15747F119E6645381F3EF1E7F9C2F7F48B227D5B079C5EE10D64DE79C6 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
868 | svchost.exe | HEAD | 302 | 23.32.186.57:80 | http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net471Rel1&plcid=0x409&clcid=0x409&ar=02558.00&sar=x86&o1=netfx_Full.mzz | unknown | — | — | unknown |
868 | svchost.exe | GET | 302 | 23.32.186.57:80 | http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net471Rel1&plcid=0x409&clcid=0x409&ar=02558.00&sar=x86&o1=netfx_Full.mzz | unknown | — | — | unknown |
3988 | Setup.exe | GET | 302 | 23.32.186.57:80 | http://go.microsoft.com/fwlink/?prd=11324&pver=netfx&sbp=Net471Rel1&plcid=0x409&clcid=0x409&ar=02558.00&sar=x86&o1=netfx_Full.mzz | unknown | — | — | unknown |
3988 | Setup.exe | GET | 200 | 88.221.125.143:80 | http://www.microsoft.com/pkiops/crl/MicCodSigPCA2011_2011-07-08.crl | unknown | binary | 1.05 Kb | unknown |
3988 | Setup.exe | GET | 200 | 2.16.164.9:80 | http://crl.microsoft.com/pki/crl/products/MicrosoftTimeStampPCA.crl | unknown | binary | 519 b | unknown |
3988 | Setup.exe | GET | 200 | 67.27.235.126:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?abbb1ee64cc68804 | unknown | compressed | 4.66 Kb | unknown |
3988 | Setup.exe | GET | 200 | 2.16.164.9:80 | http://crl.microsoft.com/pki/crl/products/microsoftrootcert.crl | unknown | binary | 767 b | unknown |
3988 | Setup.exe | GET | 200 | 2.16.164.9:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | binary | 1.11 Kb | unknown |
3988 | Setup.exe | GET | 200 | 2.16.164.9:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut_2010-06-23.crl | unknown | binary | 824 b | unknown |
3988 | Setup.exe | GET | 200 | 2.16.164.9:80 | http://crl.microsoft.com/pki/crl/products/MicTimStaPCA_2010-07-01.crl | unknown | binary | 555 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3988 | Setup.exe | 67.27.235.126:80 | ctldl.windowsupdate.com | LEVEL3 | US | unknown |
3988 | Setup.exe | 2.16.164.9:80 | crl.microsoft.com | Akamai International B.V. | NL | unknown |
868 | svchost.exe | 23.32.186.57:80 | go.microsoft.com | AKAMAI-AS | BR | unknown |
868 | svchost.exe | 68.232.34.200:443 | download.visualstudio.microsoft.com | EDGECAST | US | whitelisted |
3988 | Setup.exe | 88.221.125.143:80 | www.microsoft.com | AKAMAI-AS | DE | unknown |
3988 | Setup.exe | 23.32.186.57:80 | go.microsoft.com | AKAMAI-AS | BR | unknown |
Domain | IP | Reputation |
|---|---|---|
ctldl.windowsupdate.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
download.visualstudio.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
Cold Turkey Blocker.exe | Native library pre-loader is trying to load native SQLite library "C:\Program Files\Cold Turkey\x86\SQLite.Interop.dll"...
|
Cold Turkey Blocker.exe | Native library pre-loader is trying to load native SQLite library "C:\Program Files\Cold Turkey\x86\SQLite.Interop.dll"...
|
Setup.exe | User cancelled installation.
|
ServiceHub.Power.exe | Native library pre-loader is trying to load native SQLite library "C:\Program Files\Cold Turkey\x86\SQLite.Interop.dll"...
|
ServiceHub.Helper.exe | Native library pre-loader is trying to load native SQLite library "C:\Program Files\Cold Turkey\x86\SQLite.Interop.dll"...
|
ServiceHub.Helper.exe | SQLite error (1): no such table: settings
|
Cold Turkey Blocker.exe | Native library pre-loader is trying to load native SQLite library "C:\Program Files\Cold Turkey\x86\SQLite.Interop.dll"...
|