| File name: | PSemuX-7z2201-x64.exe_931005.exe |
| Full analysis: | https://app.any.run/tasks/a684b431-97e4-44a3-a1a1-60f968b8126a |
| Verdict: | Malicious activity |
| Analysis date: | September 10, 2024, 11:09:37 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 29D75CBD37E14F0EB50947520665A89B |
| SHA1: | A7F430821DB451A833D2B623F8043E9D82DF9DF4 |
| SHA256: | C599D5ADB4C86F3491630618231C52A834D5ED31CE7DDB2C2A12D231BBA955ED |
| SSDEEP: | 49152:NyWQW1ex4ShDaM4hhnFYDENYq0n8a4SzFphdFt1oHWJgvcVz3s:NyRxPH26qG8a1zFDTVg |
| .exe | | | Win32 Executable MS Visual C++ (generic) (78.5) |
|---|---|---|
| .exe | | | Win32 Executable (generic) (11.3) |
| .exe | | | Generic Win/DOS Executable (5) |
| .exe | | | DOS Executable Generic (5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2024:09:06 13:34:09+00:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 10012672 |
| InitializedDataSize: | 501760 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x9142ca |
| OSVersion: | 6 |
| ImageVersion: | - |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 1.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Sniff Natural World Solutions |
| LegalCopyright: | Sniff Natural World Solutions 2023 |
| FileDescription: | Sniff Util |
| FileVersion: | 1.0.0.0 |
| ProductVersion: | 1.0.0.0 |
| OriginalFileName: | SniffNatural.exe |
| ProductName: | SniffUtil |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 5128 | "C:\Program Files (x86)\SniffNaturaldpiUtil\SniffoUtil.exe" | C:\Program Files (x86)\SniffNaturaldpiUtil\SniffoUtil.exe | PSemuX-7z2201-x64.exe_931005.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: HIGH Description: 7-Zip Installer Exit code: 0 Version: 24.07 Modules
| |||||||||||||||
| 5712 | "C:\Users\admin\AppData\Local\Temp\PSemuX-7z2201-x64.exe_931005.exe" /uirest | C:\Users\admin\AppData\Local\Temp\PSemuX-7z2201-x64.exe_931005.exe | PSemuX-7z2201-x64.exe_931005.exe | ||||||||||||
User: admin Company: Sniff Natural World Solutions Integrity Level: HIGH Description: Sniff Util Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 7144 | "C:\Users\admin\AppData\Local\Temp\PSemuX-7z2201-x64.exe_931005.exe" | C:\Users\admin\AppData\Local\Temp\PSemuX-7z2201-x64.exe_931005.exe | — | explorer.exe | |||||||||||
User: admin Company: Sniff Natural World Solutions Integrity Level: MEDIUM Description: Sniff Util Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| (PID) Process: | (5128) SniffoUtil.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\7-Zip |
| Operation: | write | Name: | Path32 |
Value: C:\Program Files (x86)\7-Zip\ | |||
| (PID) Process: | (5128) SniffoUtil.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\7-Zip |
| Operation: | write | Name: | Path |
Value: C:\Program Files (x86)\7-Zip\ | |||
| (PID) Process: | (5128) SniffoUtil.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\7-Zip |
| Operation: | write | Name: | Path32 |
Value: C:\Program Files (x86)\7-Zip\ | |||
| (PID) Process: | (5128) SniffoUtil.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\7-Zip |
| Operation: | write | Name: | Path |
Value: C:\Program Files (x86)\7-Zip\ | |||
| (PID) Process: | (5128) SniffoUtil.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{23170F69-40C1-278A-1000-000100020000}\InprocServer32 |
| Operation: | write | Name: | ThreadingModel |
Value: Apartment | |||
| (PID) Process: | (5128) SniffoUtil.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Shell Extensions\Approved |
| Operation: | write | Name: | {23170F69-40C1-278A-1000-000100020000} |
Value: 7-Zip Shell Extension | |||
| (PID) Process: | (5128) SniffoUtil.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\7zFM.exe |
| Operation: | write | Name: | Path |
Value: C:\Program Files (x86)\7-Zip\ | |||
| (PID) Process: | (5128) SniffoUtil.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\7-Zip |
| Operation: | write | Name: | DisplayName |
Value: 7-Zip 24.07 | |||
| (PID) Process: | (5128) SniffoUtil.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\7-Zip |
| Operation: | write | Name: | DisplayVersion |
Value: 24.07 | |||
| (PID) Process: | (5128) SniffoUtil.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\7-Zip |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files (x86)\7-Zip\7zFM.exe | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5128 | SniffoUtil.exe | C:\Program Files (x86)\7-Zip\History.txt | text | |
MD5:553A02739D516379833451440076F884 | SHA256:83B1AE6D3486C2653766A28806AC110C9A0AFDE17020CA6AA0B7550A2F10E147 | |||
| 5128 | SniffoUtil.exe | C:\Program Files (x86)\7-Zip\descript.ion | text | |
MD5:EB7E322BDC62614E49DED60E0FB23845 | SHA256:1DA513F5A4E8018B9AE143884EB3EAF72454B606FD51F2401B7CFD9BE4DBBF4F | |||
| 5128 | SniffoUtil.exe | C:\Program Files (x86)\7-Zip\Lang\bn.txt | text | |
MD5:771C8B73A374CB30DF4DF682D9C40EDF | SHA256:3F55B2EC5033C39C159593C6F5ECE667B92F32938B38FCAF58B4B2A98176C1FC | |||
| 5128 | SniffoUtil.exe | C:\Program Files (x86)\7-Zip\Lang\an.txt | text | |
MD5:F16218139E027338A16C3199091D0600 | SHA256:3AB9F7AACD38C4CDE814F86BC37EEC2B9DF8D0DDDB95FC1D09A5F5BCB11F0EEB | |||
| 5128 | SniffoUtil.exe | C:\Program Files (x86)\7-Zip\7-zip.chm | binary | |
MD5:B79894FBEE3C882C3EFC71FF3D4A21BB | SHA256:2D55CA494A8B6DCC739D84BDD112F5C50D612F8ABF409C9FB5F2B5C2C84C37A0 | |||
| 5128 | SniffoUtil.exe | C:\Program Files (x86)\7-Zip\Lang\az.txt | text | |
MD5:3C297FBE9B1ED5582BEABFC112B55523 | SHA256:055EC86AED86ABBDBD52D8E99FEC6E868D073A6DF92C60225ADD16676994C314 | |||
| 5128 | SniffoUtil.exe | C:\Program Files (x86)\7-Zip\Lang\be.txt | text | |
MD5:B1DD654E9D8C8C1B001F7B3A15D7B5D3 | SHA256:32071222AF04465A3D98BB30E253579AA4BECEAEB6B21AC7C15B25F46620BF30 | |||
| 5128 | SniffoUtil.exe | C:\Program Files (x86)\7-Zip\Lang\ast.txt | text | |
MD5:1CF6411FF9154A34AFB512901BA3EE02 | SHA256:F5F2174DAF36E65790C7F0E9A4496B12E14816DAD2EE5B1D48A52307076BE35F | |||
| 5128 | SniffoUtil.exe | C:\Program Files (x86)\7-Zip\Lang\ba.txt | text | |
MD5:387FF78CF5F524FC44640F3025746145 | SHA256:8A85C3FCB5F81157490971EE4F5E6B9E4F80BE69A802EBED04E6724CE859713F | |||
| 5128 | SniffoUtil.exe | C:\Program Files (x86)\7-Zip\Lang\de.txt | text | |
MD5:1E30A705DA680AAECEAEC26DCF2981DE | SHA256:895F76BFA4B1165E4C5A11BDAB70A774E7D05D4BBDAEC0230F29DCC85D5D3563 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5796 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
8 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
5796 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
6412 | RUXIMICS.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
2120 | MoUsoCoreWorker.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5712 | PSemuX-7z2201-x64.exe_931005.exe | 104.21.90.216:443 | bestappinstaller.com | CLOUDFLARENET | — | unknown |
5796 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
5796 | svchost.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | whitelisted |
3260 | svchost.exe | 40.115.3.253:443 | client.wns.windows.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2120 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
8 | svchost.exe | 40.126.32.136:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
bestappinstaller.com |
| unknown |
www.microsoft.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
login.live.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |