| File name: | empty-folder-nuker-1.3.0.exe |
| Full analysis: | https://app.any.run/tasks/9a6d248c-e234-4c2b-92ce-d1bb4e4fef81 |
| Verdict: | Malicious activity |
| Analysis date: | May 02, 2024, 13:11:28 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 3525CE11BDCB75C17C15C759C1239DC6 |
| SHA1: | 5C1C963F1048CC638E83DF49BB6F790FDB76F440 |
| SHA256: | D2FCD834A5E2979EA7D745ED31EF72EE94505B85027428FE57830DFC21397D82 |
| SSDEEP: | 6144:uwAt/lMaKxngT5aUGbqp8d/c2XpzpIRzRe:uwAZlMfxnca1bqqd/ceuRe |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2007:09:01 19:28:26+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 237568 |
| InitializedDataSize: | 106496 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1b060 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.3.0.0 |
| ProductVersionNumber: | 1.3.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Simon Wai |
| FileDescription: | Empty Folder Nuker |
| FileVersion: | 1.3.0.0 |
| InternalName: | EmptyFolderNuker.exe |
| LegalCopyright: | (c) Simon Wai. All rights reserved. |
| LegalTrademarks: | http://efn.simonwai.com |
| OriginalFileName: | EmptyFolderNuker.exe |
| ProductName: | Empty Folder Nuker |
| ProductVersion: | 1.3.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3968 | "C:\Users\admin\Desktop\empty-folder-nuker-1.3.0.exe" | C:\Users\admin\Desktop\empty-folder-nuker-1.3.0.exe | explorer.exe | ||||||||||||
User: admin Company: Simon Wai Integrity Level: MEDIUM Description: Empty Folder Nuker Version: 1.3.0.0 Modules
| |||||||||||||||
| (PID) Process: | (3968) empty-folder-nuker-1.3.0.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3968) empty-folder-nuker-1.3.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume\{e1a82db4-a9f0-11e7-b142-806e6f6e6963} |
| Operation: | write | Name: | NeedToPurge |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$I8FQITJ | cdxl | |
MD5:E263910FC55E353237615B2BDBCC3C61 | SHA256:C595E64B736D48C43CD0D87BB238A2EA65E702C141A97B12A4FF858A46792EA5 | |||
| 3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IBJOW6P | cdxl | |
MD5:5A6A584E7B260EE0259AB0DB612577DF | SHA256:0C9C1F9507502A48D4BA14289D2560E55E770DB6BA08D6AFDA781CB26D4A07A6 | |||
| 3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IAISLPC | cdxl | |
MD5:0799955176502BD480E40CA44DDACAC7 | SHA256:42E5E8618A89957D73FC8B00E66A970DABBE0E7379A919981026A52156043F24 | |||
| 3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IKFH77W | cdxl | |
MD5:2A980CCE5D2A9461E9C33E122D647454 | SHA256:D89A1C0F7F19F81C9F4FE3F624C427C7A34EA1959FB349D8C20EF3C93A6C4E53 | |||
| 3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IG6P5NZ | binary | |
MD5:EE5EBF2447DC41BEC8F79C3AA94119B3 | SHA256:0B90064269FBA5A943A8DAAF5BE98C50235B7FB6F99759BB2E69E6249E7D4CE8 | |||
| 3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IOWJM82 | binary | |
MD5:D316BA7AEDCEE11A2A1482828C3F96AE | SHA256:962C82DCC8F9DB66C73D8C6FEB4622B0DC4BFD3A50E9D46ABEE6BFA0BB62EC59 | |||
| 3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$I2XRB63 | binary | |
MD5:F8EAB6F4E0F1180A2B13F92A10B48863 | SHA256:97B357DE4D52868E13BA20A526E3BB51FD3999442C41CCBE3566078F7FCD5E02 | |||
| 3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IKWGZ0B | binary | |
MD5:508935AE32D3E699C8DF8464AF079D03 | SHA256:99954FD56DDF0D05C3D03356DBE98A4A3D6DDDF31314EEB45272FD501DAE18B6 | |||
| 3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IJ8PA6F | cdxl | |
MD5:807A7965CB0105C6D391811A4B373A64 | SHA256:4FB0557B5ECAA5E1CC20FEEC6AAEBE1B21C40771464640AE0F0A844D549C8A44 | |||
| 3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$I12BKS4 | binary | |
MD5:C008F6C355241B84346C1B4432F7BC6C | SHA256:7C4A10E19FFB196F22BF0474430704265525EED980C567371FB3D541D75CEDAF | |||