| File name: | financials-unpacked.exe |
| Full analysis: | https://app.any.run/tasks/3096262c-b457-488d-9ba6-744dfabecf5d |
| Verdict: | Malicious activity |
| Analysis date: | November 22, 2023, 03:23:42 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 795A6A646C793A041B8BDCA0EA5C75F3 |
| SHA1: | 3CD6955C8C7CCE1C6057EE24871AA23A5F1DC92D |
| SHA256: | CF694369BD2DDF57296A4BDF9C5F45A8AEFC193D8F6B861B9A074F3E507D7382 |
| SSDEEP: | 12288:E3H6yScLnqOl0r5Zu0LMFbtizFJ6rAPvOxrcg0i7u48X+OxsSl:E3HzLnqOaNMCFJ6kPvOxrcg0i7uFdsE |
| .exe | | | Win32 Executable Borland Delphi 7 (92.8) |
|---|---|---|
| .exe | | | Win32 EXE Yoda's Crypter (3.7) |
| .exe | | | Win32 Executable Delphi generic (1.9) |
| .exe | | | Win32 Executable (generic) (0.6) |
| .exe | | | Win16/32 Executable Delphi generic (0.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:20 00:22:17+02:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 629760 |
| InitializedDataSize: | 198144 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x9ab80 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.4 |
| ProductVersionNumber: | 1.0.0.4 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Turkish |
| CharacterSet: | Windows, Turkish |
| CompanyName: | Synaptics |
| FileDescription: | Synaptics Pointing Device Driver |
| FileVersion: | 1.0.0.4 |
| InternalName: | - |
| LegalCopyright: | - |
| LegalTrademarks: | - |
| OriginalFileName: | - |
| ProductName: | Synaptics Pointing Device Driver |
| ProductVersion: | 1.0.0.0 |
| Comments: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 752 | "C:\ProgramData\Synaptics\Synaptics.exe" | C:\ProgramData\Synaptics\Synaptics.exe | — | explorer.exe | |||||||||||
User: admin Company: Synaptics Integrity Level: MEDIUM Description: Synaptics Pointing Device Driver Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 1032 | "C:\ProgramData\Synaptics\Synaptics.exe" | C:\ProgramData\Synaptics\Synaptics.exe | — | explorer.exe | |||||||||||
User: admin Company: Synaptics Integrity Level: MEDIUM Description: Synaptics Pointing Device Driver Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 1088 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\timesclients.rtf" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 1276 | "C:\ProgramData\Synaptics\Synaptics.exe" | C:\ProgramData\Synaptics\Synaptics.exe | — | explorer.exe | |||||||||||
User: admin Company: Synaptics Integrity Level: MEDIUM Description: Synaptics Pointing Device Driver Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 1344 | "C:\ProgramData\Synaptics\Synaptics.exe" | C:\ProgramData\Synaptics\Synaptics.exe | — | explorer.exe | |||||||||||
User: admin Company: Synaptics Integrity Level: MEDIUM Description: Synaptics Pointing Device Driver Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 1360 | "C:\ProgramData\Synaptics\Synaptics.exe" | C:\ProgramData\Synaptics\Synaptics.exe | — | explorer.exe | |||||||||||
User: admin Company: Synaptics Integrity Level: MEDIUM Description: Synaptics Pointing Device Driver Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 1608 | "C:\ProgramData\Synaptics\Synaptics.exe" | C:\ProgramData\Synaptics\Synaptics.exe | — | explorer.exe | |||||||||||
User: admin Company: Synaptics Integrity Level: MEDIUM Description: Synaptics Pointing Device Driver Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 1752 | "C:\ProgramData\Synaptics\Synaptics.exe" | C:\ProgramData\Synaptics\Synaptics.exe | — | explorer.exe | |||||||||||
User: admin Company: Synaptics Integrity Level: MEDIUM Description: Synaptics Pointing Device Driver Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 1904 | "C:\ProgramData\Synaptics\Synaptics.exe" | C:\ProgramData\Synaptics\Synaptics.exe | — | explorer.exe | |||||||||||
User: admin Company: Synaptics Integrity Level: MEDIUM Description: Synaptics Pointing Device Driver Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 2000 | "C:\ProgramData\Synaptics\Synaptics.exe" | C:\ProgramData\Synaptics\Synaptics.exe | — | explorer.exe | |||||||||||
User: admin Company: Synaptics Integrity Level: MEDIUM Description: Synaptics Pointing Device Driver Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| (PID) Process: | (2928) financials-unpacked.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2928) financials-unpacked.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2928) financials-unpacked.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2928) financials-unpacked.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2928) financials-unpacked.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3444) Synaptics.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3444) Synaptics.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000059010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3444) Synaptics.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3444) Synaptics.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3444) Synaptics.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1088 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVR621B.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 2928 | financials-unpacked.exe | C:\Users\admin\AppData\Local\Temp\._cache_financials-unpacked.exe | executable | |
MD5:A78CDBEEC7E5DCE0E6985A16EECBE639 | SHA256:726A072434E751B2781D49F4F85EC213B60DF0EF6AA6377D5D55FAD0171E7DE9 | |||
| 1088 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\index.dat | text | |
MD5:1A43B8262A397B8C532BBBE621731386 | SHA256:7EABFC6E014A93A84C6B57A0306665842A08DA89BF1F27905CD0D4C799D6A0D0 | |||
| 1088 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRF{7198CD94-EEBF-466B-B028-35694BE8B790}.tmp | binary | |
MD5:55CDD40D0308139548B139AAF3FA84FD | SHA256:44F55301168DEE9D94442EE3D84DE251E5B49CEEAFFC262F5CAB0476546C938B | |||
| 1088 | WINWORD.EXE | C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.Word\~WRS{9F9BC9E9-A484-4202-85D0-7BF171B7A6F2}.tmp | binary | |
MD5:F01BEED93574664491594B1420BFB156 | SHA256:4CC3AF31FFF50BEDA1982E61F43F8BFAEEC8FB3103A601B2902B8CC9F5FB764A | |||
| 1088 | WINWORD.EXE | C:\Users\admin\AppData\Roaming\Microsoft\Office\Recent\timesclients.rtf.LNK | binary | |
MD5:35F660C51E3E2197854BF6F7B2A94372 | SHA256:7A4CB0B6E2EA6FA832E079143E4F17AC43F6C6882DDB5E2648BA9326B9EB34CE | |||
| 2928 | financials-unpacked.exe | C:\ProgramData\Synaptics\Synaptics.exe | executable | |
MD5:795A6A646C793A041B8BDCA0EA5C75F3 | SHA256:CF694369BD2DDF57296A4BDF9C5F45A8AEFC193D8F6B861B9A074F3E507D7382 | |||
| 2928 | financials-unpacked.exe | C:\ProgramData\Synaptics\RCX760F.tmp | executable | |
MD5:7C5967CA0A1A5E84618BFC5B2020F402 | SHA256:B2C86764D4422C52C108A08E705092DD9AD4D0AECDC4E3165BC7A33DDBD4DD9D | |||
| 2896 | ._cache_financials-unpacked.exe | C:\Users\admin\AppData\Roaming\Install.dat | html | |
MD5:3D2AF64352C586A0680D91DC107A2114 | SHA256:891C4ADE1F17A74346D9AC427418F8BA7FEB82C672E6E8C216562F238C01CE53 | |||
| 1088 | WINWORD.EXE | C:\Users\admin\Desktop\~$mesclients.rtf | binary | |
MD5:D3E2837D0580014122A3C1449203B0A0 | SHA256:D3DD76940EF0C9F612F3B4282930241891ADA40267BCA682DA7BE5BCBCD6D78F | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2988 | CCleaner.exe | GET | 404 | 23.192.45.89:80 | http://ncc.avast.com/ncc.txt | unknown | xml | 341 b | unknown |
3444 | Synaptics.exe | GET | 404 | 69.42.215.252:80 | http://freedns.afraid.org/api/?action=getdyndns&sha=a30fa98efc092684e8d1c5cff797bcc613562978 | unknown | xml | 341 b | unknown |
2896 | ._cache_financials-unpacked.exe | GET | 404 | 69.50.175.181:80 | http://download.bravesentry.com/download.php?&advid=00000717&u=0&p=29945068 | unknown | xml | 341 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2896 | ._cache_financials-unpacked.exe | 69.50.175.181:80 | — | SOHOSKYWAY1 | CA | unknown |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3444 | Synaptics.exe | 69.42.215.252:80 | freedns.afraid.org | AWKNET | US | unknown |
3444 | Synaptics.exe | 142.250.76.142:443 | docs.google.com | GOOGLE | US | unknown |
2988 | CCleaner.exe | 23.192.45.89:80 | ncc.avast.com | Akamai International B.V. | JP | unknown |
2988 | CCleaner.exe | 34.117.223.223:443 | analytics.ff.avast.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
2988 | CCleaner.exe | 104.94.216.88:443 | www.ccleaner.com | AKAMAI-AS | KR | unknown |
Domain | IP | Reputation |
|---|---|---|
xred.mooo.com |
| unknown |
freedns.afraid.org |
| whitelisted |
docs.google.com |
| shared |
ncc.avast.com |
| whitelisted |
analytics.ff.avast.com |
| whitelisted |
www.ccleaner.com |
| whitelisted |
ipm-provider.ff.avast.com |
| whitelisted |
shepherd.ff.avast.com |
| whitelisted |
ip-info.ff.avast.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Misc activity | ET INFO DYNAMIC_DNS Query to Abused Domain *.mooo.com |
Process | Message |
|---|---|
CCleaner.exe | [2023-11-22 03:27:17.455] [error ] [settings ] [ 2988: 3108] [6000C4: 356] Failed to get program directory
Exception: Unable to determine program folder of product 'piriform-cc'!
Code: 0x000000c0 (192)
|
CCleaner.exe | Failed to open log file 'C:\Program Files\CCleaner' |
CCleaner.exe | OnLanguage - en
|
CCleaner.exe | [2023-11-22 03:27:17.970] [error ] [settings ] [ 2988: 1984] [9434E9: 359] Failed to get program directory
Exception: Unable to determine program folder of product 'piriform-cc'!
Code: 0x000000c0 (192)
|
CCleaner.exe | [2023-11-22 03:27:17.986] [error ] [Burger ] [ 2988: 1984] [FDA25D: 244] [23.1.806.0] [BurgerReporter.cpp] [244] asw::standalone_svc::BurgerReporter::BurgerSwitch: Could not read property BURGER_SETTINGS_PANCAKE_HOSTNAME (0x00000003)
|
CCleaner.exe | [2023-11-22 03:27:17.986] [error ] [Burger ] [ 2988: 1984] [FDA25D: 244] [23.1.806.0] [BurgerReporter.cpp] [244] asw::standalone_svc::BurgerReporter::BurgerSwitch: Could not read property BURGER_SETTINGS_PANCAKE_HOSTNAME (0x00000003)
|
CCleaner.exe | startCheckingLicense()
|
CCleaner.exe | OnLanguage - en
|
CCleaner.exe | OnLanguage - en
|
CCleaner.exe | OnLanguage - en
|