| File name: | financials-unpacked.exe |
| Full analysis: | https://app.any.run/tasks/3096262c-b457-488d-9ba6-744dfabecf5d |
| Verdict: | Malicious activity |
| Analysis date: | November 22, 2023, 03:23:42 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 795A6A646C793A041B8BDCA0EA5C75F3 |
| SHA1: | 3CD6955C8C7CCE1C6057EE24871AA23A5F1DC92D |
| SHA256: | CF694369BD2DDF57296A4BDF9C5F45A8AEFC193D8F6B861B9A074F3E507D7382 |
| SSDEEP: | 12288:E3H6yScLnqOl0r5Zu0LMFbtizFJ6rAPvOxrcg0i7u48X+OxsSl:E3HzLnqOaNMCFJ6kPvOxrcg0i7uFdsE |
| .exe | | | Win32 Executable Borland Delphi 7 (92.8) |
|---|---|---|
| .exe | | | Win32 EXE Yoda's Crypter (3.7) |
| .exe | | | Win32 Executable Delphi generic (1.9) |
| .exe | | | Win32 Executable (generic) (0.6) |
| .exe | | | Win16/32 Executable Delphi generic (0.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:20 00:22:17+02:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 629760 |
| InitializedDataSize: | 198144 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x9ab80 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.4 |
| ProductVersionNumber: | 1.0.0.4 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Turkish |
| CharacterSet: | Windows, Turkish |
| CompanyName: | Synaptics |
| FileDescription: | Synaptics Pointing Device Driver |
| FileVersion: | 1.0.0.4 |
| InternalName: | - |
| LegalCopyright: | - |
| LegalTrademarks: | - |
| OriginalFileName: | - |
| ProductName: | Synaptics Pointing Device Driver |
| ProductVersion: | 1.0.0.0 |
| Comments: | - |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 752 | "C:\ProgramData\Synaptics\Synaptics.exe" | C:\ProgramData\Synaptics\Synaptics.exe | — | explorer.exe | |||||||||||
User: admin Company: Synaptics Integrity Level: MEDIUM Description: Synaptics Pointing Device Driver Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 1032 | "C:\ProgramData\Synaptics\Synaptics.exe" | C:\ProgramData\Synaptics\Synaptics.exe | — | explorer.exe | |||||||||||
User: admin Company: Synaptics Integrity Level: MEDIUM Description: Synaptics Pointing Device Driver Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 1088 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\timesclients.rtf" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 1276 | "C:\ProgramData\Synaptics\Synaptics.exe" | C:\ProgramData\Synaptics\Synaptics.exe | — | explorer.exe | |||||||||||
User: admin Company: Synaptics Integrity Level: MEDIUM Description: Synaptics Pointing Device Driver Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 1344 | "C:\ProgramData\Synaptics\Synaptics.exe" | C:\ProgramData\Synaptics\Synaptics.exe | — | explorer.exe | |||||||||||
User: admin Company: Synaptics Integrity Level: MEDIUM Description: Synaptics Pointing Device Driver Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 1360 | "C:\ProgramData\Synaptics\Synaptics.exe" | C:\ProgramData\Synaptics\Synaptics.exe | — | explorer.exe | |||||||||||
User: admin Company: Synaptics Integrity Level: MEDIUM Description: Synaptics Pointing Device Driver Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 1608 | "C:\ProgramData\Synaptics\Synaptics.exe" | C:\ProgramData\Synaptics\Synaptics.exe | — | explorer.exe | |||||||||||
User: admin Company: Synaptics Integrity Level: MEDIUM Description: Synaptics Pointing Device Driver Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 1752 | "C:\ProgramData\Synaptics\Synaptics.exe" | C:\ProgramData\Synaptics\Synaptics.exe | — | explorer.exe | |||||||||||
User: admin Company: Synaptics Integrity Level: MEDIUM Description: Synaptics Pointing Device Driver Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 1904 | "C:\ProgramData\Synaptics\Synaptics.exe" | C:\ProgramData\Synaptics\Synaptics.exe | — | explorer.exe | |||||||||||
User: admin Company: Synaptics Integrity Level: MEDIUM Description: Synaptics Pointing Device Driver Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 2000 | "C:\ProgramData\Synaptics\Synaptics.exe" | C:\ProgramData\Synaptics\Synaptics.exe | — | explorer.exe | |||||||||||
User: admin Company: Synaptics Integrity Level: MEDIUM Description: Synaptics Pointing Device Driver Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| (PID) Process: | (2928) financials-unpacked.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2928) financials-unpacked.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2928) financials-unpacked.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2928) financials-unpacked.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2928) financials-unpacked.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17A\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3444) Synaptics.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (3444) Synaptics.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 4600000059010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3444) Synaptics.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3444) Synaptics.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3444) Synaptics.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1088 | WINWORD.EXE | C:\Users\admin\AppData\Local\Temp\CVR621B.tmp.cvr | — | |
MD5:— | SHA256:— | |||
| 2928 | financials-unpacked.exe | C:\ProgramData\Synaptics\RCX760F.tmp | executable | |
MD5:7C5967CA0A1A5E84618BFC5B2020F402 | SHA256:B2C86764D4422C52C108A08E705092DD9AD4D0AECDC4E3165BC7A33DDBD4DD9D | |||
| 2928 | financials-unpacked.exe | C:\ProgramData\Synaptics\Synaptics.exe | executable | |
MD5:795A6A646C793A041B8BDCA0EA5C75F3 | SHA256:CF694369BD2DDF57296A4BDF9C5F45A8AEFC193D8F6B861B9A074F3E507D7382 | |||
| 2928 | financials-unpacked.exe | C:\Users\admin\AppData\Local\Temp\._cache_financials-unpacked.exe | executable | |
MD5:A78CDBEEC7E5DCE0E6985A16EECBE639 | SHA256:726A072434E751B2781D49F4F85EC213B60DF0EF6AA6377D5D55FAD0171E7DE9 | |||
| 2988 | CCleaner.exe | C:\Program Files\CCleaner\LOG\event_manager.log | text | |
MD5:D1047DD6A972B16749366BB8A4971013 | SHA256:9670069CBFEED97289B0F7A7D9C05038227A5FE00694E4277F64FB356FF752F4 | |||
| 2988 | CCleaner.exe | C:\Program Files\CCleaner\gcapi_dll.dll | executable | |
MD5:F637D5D3C3A60FDDB5DD397556FE9B1D | SHA256:641B843CB6EE7538EC267212694C9EF0616B9AC9AB14A0ABD7CF020678D50B02 | |||
| 2988 | CCleaner.exe | C:\Program Files\CCleaner\gcapi_17006236372988.dll | executable | |
MD5:F637D5D3C3A60FDDB5DD397556FE9B1D | SHA256:641B843CB6EE7538EC267212694C9EF0616B9AC9AB14A0ABD7CF020678D50B02 | |||
| 2988 | CCleaner.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\TJ5SY3JYV2PF2ZJEMXBQ.temp | binary | |
MD5:DDCC92272AB20811861845FED7737339 | SHA256:F7EEA6CE6DF66CBCFF9919108E9DA220C7C30565B54A773BA8A505B7596C8BA9 | |||
| 2988 | CCleaner.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Recent\CustomDestinations\ed7a5cc3cca8d52a.customDestinations-ms~RF199ee6.TMP | binary | |
MD5:DA39F131D86385E1285BF5489BA6B6F9 | SHA256:38C92C3B93D15CCF2E5E59D01D223366D60FF508037EF997C0CDCC11CEC8BAD0 | |||
| 2988 | CCleaner.exe | C:\Program Files\CCleaner\LOG\DriverUpdaterLib.log | text | |
MD5:C65E65557F5280D56D1062BDF8DD8E47 | SHA256:E782AEF0FC1324E9F658F7F81108DBD07792B99B7E45162FB575D58765B7E328 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2896 | ._cache_financials-unpacked.exe | GET | 404 | 69.50.175.181:80 | http://download.bravesentry.com/download.php?&advid=00000717&u=0&p=29945068 | unknown | xml | 341 b | unknown |
3444 | Synaptics.exe | GET | 404 | 69.42.215.252:80 | http://freedns.afraid.org/api/?action=getdyndns&sha=a30fa98efc092684e8d1c5cff797bcc613562978 | unknown | xml | 341 b | unknown |
2988 | CCleaner.exe | GET | 404 | 23.192.45.89:80 | http://ncc.avast.com/ncc.txt | unknown | xml | 341 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2896 | ._cache_financials-unpacked.exe | 69.50.175.181:80 | — | SOHOSKYWAY1 | CA | unknown |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3444 | Synaptics.exe | 69.42.215.252:80 | freedns.afraid.org | AWKNET | US | unknown |
3444 | Synaptics.exe | 142.250.76.142:443 | docs.google.com | GOOGLE | US | unknown |
2988 | CCleaner.exe | 23.192.45.89:80 | ncc.avast.com | Akamai International B.V. | JP | unknown |
2988 | CCleaner.exe | 34.117.223.223:443 | analytics.ff.avast.com | GOOGLE-CLOUD-PLATFORM | US | unknown |
2988 | CCleaner.exe | 104.94.216.88:443 | www.ccleaner.com | AKAMAI-AS | KR | unknown |
Domain | IP | Reputation |
|---|---|---|
xred.mooo.com |
| unknown |
freedns.afraid.org |
| whitelisted |
docs.google.com |
| shared |
ncc.avast.com |
| whitelisted |
analytics.ff.avast.com |
| whitelisted |
www.ccleaner.com |
| whitelisted |
ipm-provider.ff.avast.com |
| whitelisted |
shepherd.ff.avast.com |
| whitelisted |
ip-info.ff.avast.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
1080 | svchost.exe | Misc activity | ET INFO DYNAMIC_DNS Query to Abused Domain *.mooo.com |
Process | Message |
|---|---|
CCleaner.exe | [2023-11-22 03:27:17.455] [error ] [settings ] [ 2988: 3108] [6000C4: 356] Failed to get program directory
Exception: Unable to determine program folder of product 'piriform-cc'!
Code: 0x000000c0 (192)
|
CCleaner.exe | Failed to open log file 'C:\Program Files\CCleaner' |
CCleaner.exe | OnLanguage - en
|
CCleaner.exe | [2023-11-22 03:27:17.970] [error ] [settings ] [ 2988: 1984] [9434E9: 359] Failed to get program directory
Exception: Unable to determine program folder of product 'piriform-cc'!
Code: 0x000000c0 (192)
|
CCleaner.exe | [2023-11-22 03:27:17.986] [error ] [Burger ] [ 2988: 1984] [FDA25D: 244] [23.1.806.0] [BurgerReporter.cpp] [244] asw::standalone_svc::BurgerReporter::BurgerSwitch: Could not read property BURGER_SETTINGS_PANCAKE_HOSTNAME (0x00000003)
|
CCleaner.exe | [2023-11-22 03:27:17.986] [error ] [Burger ] [ 2988: 1984] [FDA25D: 244] [23.1.806.0] [BurgerReporter.cpp] [244] asw::standalone_svc::BurgerReporter::BurgerSwitch: Could not read property BURGER_SETTINGS_PANCAKE_HOSTNAME (0x00000003)
|
CCleaner.exe | startCheckingLicense()
|
CCleaner.exe | OnLanguage - en
|
CCleaner.exe | OnLanguage - en
|
CCleaner.exe | OnLanguage - en
|