| File name: | empty-folder-nuker-1.3.0.exe |
| Full analysis: | https://app.any.run/tasks/9a6d248c-e234-4c2b-92ce-d1bb4e4fef81 |
| Verdict: | Malicious activity |
| Analysis date: | May 02, 2024, 13:11:28 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 3525CE11BDCB75C17C15C759C1239DC6 |
| SHA1: | 5C1C963F1048CC638E83DF49BB6F790FDB76F440 |
| SHA256: | D2FCD834A5E2979EA7D745ED31EF72EE94505B85027428FE57830DFC21397D82 |
| SSDEEP: | 6144:uwAt/lMaKxngT5aUGbqp8d/c2XpzpIRzRe:uwAZlMfxnca1bqqd/ceuRe |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2007:09:01 19:28:26+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 8 |
| CodeSize: | 237568 |
| InitializedDataSize: | 106496 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1b060 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.3.0.0 |
| ProductVersionNumber: | 1.3.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Simon Wai |
| FileDescription: | Empty Folder Nuker |
| FileVersion: | 1.3.0.0 |
| InternalName: | EmptyFolderNuker.exe |
| LegalCopyright: | (c) Simon Wai. All rights reserved. |
| LegalTrademarks: | http://efn.simonwai.com |
| OriginalFileName: | EmptyFolderNuker.exe |
| ProductName: | Empty Folder Nuker |
| ProductVersion: | 1.3.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3968 | "C:\Users\admin\Desktop\empty-folder-nuker-1.3.0.exe" | C:\Users\admin\Desktop\empty-folder-nuker-1.3.0.exe | explorer.exe | ||||||||||||
User: admin Company: Simon Wai Integrity Level: MEDIUM Description: Empty Folder Nuker Version: 1.3.0.0 Modules
| |||||||||||||||
| (PID) Process: | (3968) empty-folder-nuker-1.3.0.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3968) empty-folder-nuker-1.3.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume\{e1a82db4-a9f0-11e7-b142-806e6f6e6963} |
| Operation: | write | Name: | NeedToPurge |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IBA5NZ0 | cdxl | |
MD5:C4A50672DE736E294634D8017F7588FB | SHA256:660E42CD3020545CF259E1496ABB5B88E9C144ECA553B786A4ECDC4AB049D789 | |||
| 3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IBJOW6P | cdxl | |
MD5:5A6A584E7B260EE0259AB0DB612577DF | SHA256:0C9C1F9507502A48D4BA14289D2560E55E770DB6BA08D6AFDA781CB26D4A07A6 | |||
| 3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IAMHV7J | cdxl | |
MD5:497956064D8562CA3D6007D692073F0C | SHA256:BA91E586705360DEEE24D4A83366036D9F83F1E50A68D800DAFA2FA2953E8576 | |||
| 3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IKFH77W | cdxl | |
MD5:2A980CCE5D2A9461E9C33E122D647454 | SHA256:D89A1C0F7F19F81C9F4FE3F624C427C7A34EA1959FB349D8C20EF3C93A6C4E53 | |||
| 3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IJ8PA6F | cdxl | |
MD5:807A7965CB0105C6D391811A4B373A64 | SHA256:4FB0557B5ECAA5E1CC20FEEC6AAEBE1B21C40771464640AE0F0A844D549C8A44 | |||
| 3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IWR3MED | binary | |
MD5:C52716D88C6137630C6145524BCC4215 | SHA256:4691A5B71829266CC96DFDC85164BD79219269A3CB3130810E2D61773B63EEB1 | |||
| 3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IYIGLM2 | cdxl | |
MD5:CDA46917137D4963771458FAA27A2DA9 | SHA256:8C8B963B07E1AE7DBB4E14605A098C3511184110E026A72DDC6681654465B9D9 | |||
| 3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IG6P5NZ | binary | |
MD5:EE5EBF2447DC41BEC8F79C3AA94119B3 | SHA256:0B90064269FBA5A943A8DAAF5BE98C50235B7FB6F99759BB2E69E6249E7D4CE8 | |||
| 3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IF2EFWK | cdxl | |
MD5:E344EB89317C5B1C256EF8B1AF808276 | SHA256:A65FD0952B0E04B2A82053AF0DD6048CE5AC7254FC4BB3BCF1722D1D1C81734D | |||
| 3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IOWJM82 | binary | |
MD5:D316BA7AEDCEE11A2A1482828C3F96AE | SHA256:962C82DCC8F9DB66C73D8C6FEB4622B0DC4BFD3A50E9D46ABEE6BFA0BB62EC59 | |||