File name: | empty-folder-nuker-1.3.0.exe |
Full analysis: | https://app.any.run/tasks/9a6d248c-e234-4c2b-92ce-d1bb4e4fef81 |
Verdict: | Malicious activity |
Analysis date: | May 02, 2024, 13:11:28 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 3525CE11BDCB75C17C15C759C1239DC6 |
SHA1: | 5C1C963F1048CC638E83DF49BB6F790FDB76F440 |
SHA256: | D2FCD834A5E2979EA7D745ED31EF72EE94505B85027428FE57830DFC21397D82 |
SSDEEP: | 6144:uwAt/lMaKxngT5aUGbqp8d/c2XpzpIRzRe:uwAZlMfxnca1bqqd/ceuRe |
.exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
---|---|---|
.exe | | | Win64 Executable (generic) (37.3) |
.dll | | | Win32 Dynamic Link Library (generic) (8.8) |
.exe | | | Win32 Executable (generic) (6) |
.exe | | | Generic Win/DOS Executable (2.7) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2007:09:01 19:28:26+00:00 |
ImageFileCharacteristics: | No relocs, Executable, 32-bit |
PEType: | PE32 |
LinkerVersion: | 8 |
CodeSize: | 237568 |
InitializedDataSize: | 106496 |
UninitializedDataSize: | - |
EntryPoint: | 0x1b060 |
OSVersion: | 4 |
ImageVersion: | - |
SubsystemVersion: | 4 |
Subsystem: | Windows GUI |
FileVersionNumber: | 1.3.0.0 |
ProductVersionNumber: | 1.3.0.0 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | English (U.S.) |
CharacterSet: | Windows, Latin1 |
CompanyName: | Simon Wai |
FileDescription: | Empty Folder Nuker |
FileVersion: | 1.3.0.0 |
InternalName: | EmptyFolderNuker.exe |
LegalCopyright: | (c) Simon Wai. All rights reserved. |
LegalTrademarks: | http://efn.simonwai.com |
OriginalFileName: | EmptyFolderNuker.exe |
ProductName: | Empty Folder Nuker |
ProductVersion: | 1.3.0.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
3968 | "C:\Users\admin\Desktop\empty-folder-nuker-1.3.0.exe" | C:\Users\admin\Desktop\empty-folder-nuker-1.3.0.exe | explorer.exe | ||||||||||||
User: admin Company: Simon Wai Integrity Level: MEDIUM Description: Empty Folder Nuker Version: 1.3.0.0 Modules
|
(PID) Process: | (3968) empty-folder-nuker-1.3.0.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
Operation: | write | Name: | LanguageList |
Value: en-US | |||
(PID) Process: | (3968) empty-folder-nuker-1.3.0.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\BitBucket\Volume\{e1a82db4-a9f0-11e7-b142-806e6f6e6963} |
Operation: | write | Name: | NeedToPurge |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IBA5NZ0 | cdxl | |
MD5:C4A50672DE736E294634D8017F7588FB | SHA256:660E42CD3020545CF259E1496ABB5B88E9C144ECA553B786A4ECDC4AB049D789 | |||
3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IBJOW6P | cdxl | |
MD5:5A6A584E7B260EE0259AB0DB612577DF | SHA256:0C9C1F9507502A48D4BA14289D2560E55E770DB6BA08D6AFDA781CB26D4A07A6 | |||
3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IAISLPC | cdxl | |
MD5:0799955176502BD480E40CA44DDACAC7 | SHA256:42E5E8618A89957D73FC8B00E66A970DABBE0E7379A919981026A52156043F24 | |||
3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$I8FQITJ | cdxl | |
MD5:E263910FC55E353237615B2BDBCC3C61 | SHA256:C595E64B736D48C43CD0D87BB238A2EA65E702C141A97B12A4FF858A46792EA5 | |||
3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$I12BKS4 | binary | |
MD5:C008F6C355241B84346C1B4432F7BC6C | SHA256:7C4A10E19FFB196F22BF0474430704265525EED980C567371FB3D541D75CEDAF | |||
3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IKWGZ0B | binary | |
MD5:508935AE32D3E699C8DF8464AF079D03 | SHA256:99954FD56DDF0D05C3D03356DBE98A4A3D6DDDF31314EEB45272FD501DAE18B6 | |||
3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$I0UKFH3 | binary | |
MD5:8AB6BDB8B89CD5E7FADC99F7E29F337B | SHA256:B6CEE64E488C1AD58CB06A774BD7A01458C3873E83DAC0A00B7677589EFC0D1E | |||
3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IW91XGB | binary | |
MD5:10EAC3C692EE0DA712583522D4E6938B | SHA256:3AB2CEA7E23FCA21009FC6C59064F3A7C98DC62906BC2CEE38151F2A1D643570 | |||
3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$I7FETMK | binary | |
MD5:EB45BD8A1F3AD8CA1B7493113D01B725 | SHA256:62EFBE8CF78DF4DFD4E686186409ED41B6811A51BDD8CEDBC9BDAB8A875AFC07 | |||
3968 | empty-folder-nuker-1.3.0.exe | C:\$RECYCLE.BIN\S-1-5-21-1302019708-1500728564-335382590-1000\$IVSMUHA | binary | |
MD5:B80777B17AAE545DFC09046FC8BF97A7 | SHA256:16981B15366509F68DA81060F0E8A8FE7BE551A54445A363C9BBBF4B9AF0679D |