| File name: | TNODUP-Portable.exe |
| Full analysis: | https://app.any.run/tasks/4ef5c0f0-0a50-4b03-903c-b5f7c3e1ac53 |
| Verdict: | Suspicious activity |
| Analysis date: | August 04, 2020, 00:47:53 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 96EF754B87E1591D21DDE23C4CA9CA36 |
| SHA1: | 25F5482B8410D00B139C551067F1BCA6A07F6221 |
| SHA256: | D5703DE5DE5DE58B86351DB6375D85B9E5ACDBB7DEBFC57830E4ECAD03C19331 |
| SSDEEP: | 98304:5Y5xcmAva+/kw7W922o2i6K/uAcaJ2m/UDnGyxcVZa:EV+/tCO67goc |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:10:26 13:25:11+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 3632128 |
| InitializedDataSize: | 1667584 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x26b4f1 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.7.0.0 |
| ProductVersionNumber: | 1.7.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Unknown (300A) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Tukero[X]Team |
| FileDescription: | TNod User & Password Finder |
| FileVersion: | , |
| LegalCopyright: | Copyleft 2007-2017 |
| ProductName: | TNod User & Password Finder |
| ProductVersion: | , |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1268 | "C:\Users\admin\Desktop\TNODUP-Portable.exe" | C:\Users\admin\Desktop\TNODUP-Portable.exe | explorer.exe | ||||||||||||
User: admin Company: Tukero[X]Team Integrity Level: MEDIUM Description: TNod User & Password Finder Exit code: 0 Version: , Modules
| |||||||||||||||
| 1800 | "C:\Users\admin\Desktop\TNODUP-Portable.exe" | C:\Users\admin\Desktop\TNODUP-Portable.exe | explorer.exe | ||||||||||||
User: admin Company: Tukero[X]Team Integrity Level: MEDIUM Description: TNod User & Password Finder Exit code: 0 Version: , Modules
| |||||||||||||||
| 2308 | "C:\Users\admin\Desktop\TNODUP-Portable.exe" | C:\Users\admin\Desktop\TNODUP-Portable.exe | explorer.exe | ||||||||||||
User: admin Company: Tukero[X]Team Integrity Level: MEDIUM Description: TNod User & Password Finder Exit code: 0 Version: , Modules
| |||||||||||||||
| 2604 | "C:\Users\admin\Desktop\TNODUP-Portable.exe" | C:\Users\admin\Desktop\TNODUP-Portable.exe | explorer.exe | ||||||||||||
User: admin Company: Tukero[X]Team Integrity Level: MEDIUM Description: TNod User & Password Finder Exit code: 0 Version: , Modules
| |||||||||||||||
| 2976 | "C:\Users\admin\Desktop\TNODUP-Portable.exe" | C:\Users\admin\Desktop\TNODUP-Portable.exe | explorer.exe | ||||||||||||
User: admin Company: Tukero[X]Team Integrity Level: MEDIUM Description: TNod User & Password Finder Exit code: 0 Version: , Modules
| |||||||||||||||
| 3692 | "C:\Users\admin\Desktop\TNODUP-Portable.exe" | C:\Users\admin\Desktop\TNODUP-Portable.exe | explorer.exe | ||||||||||||
User: admin Company: Tukero[X]Team Integrity Level: MEDIUM Description: TNod User & Password Finder Exit code: 0 Version: , Modules
| |||||||||||||||
| 3836 | "C:\Users\admin\Desktop\TNODUP-Portable.exe" | C:\Users\admin\Desktop\TNODUP-Portable.exe | explorer.exe | ||||||||||||
User: admin Company: Tukero[X]Team Integrity Level: MEDIUM Description: TNod User & Password Finder Exit code: 0 Version: , Modules
| |||||||||||||||
| 4000 | "C:\Users\admin\Desktop\TNODUP-Portable.exe" | C:\Users\admin\Desktop\TNODUP-Portable.exe | explorer.exe | ||||||||||||
User: admin Company: Tukero[X]Team Integrity Level: MEDIUM Description: TNod User & Password Finder Exit code: 0 Version: , Modules
| |||||||||||||||
| (PID) Process: | (4000) TNODUP-Portable.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (4000) TNODUP-Portable.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 46000000A3000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000 | |||
| (PID) Process: | (4000) TNODUP-Portable.exe | Key: | HKEY_CURRENT_USER\Software\Tukero[X]Team\TNod User & Password Finder |
| Operation: | write | Name: | SecsWaitForInternet |
Value: 100 | |||
| (PID) Process: | (4000) TNODUP-Portable.exe | Key: | HKEY_CURRENT_USER\Software\Tukero[X]Team\TNod User & Password Finder |
| Operation: | write | Name: | ExpirationServer |
Value: http://expire.eset.com/getlicexp | |||
| (PID) Process: | (4000) TNODUP-Portable.exe | Key: | HKEY_CURRENT_USER\Software\Tukero[X]Team\TNod User & Password Finder |
| Operation: | write | Name: | Lines2SkipXml |
Value: 0 | |||
| (PID) Process: | (4000) TNODUP-Portable.exe | Key: | HKEY_CURRENT_USER\Software\Tukero[X]Team\TNod User & Password Finder |
| Operation: | write | Name: | HideMode |
Value: 0 | |||
| (PID) Process: | (4000) TNODUP-Portable.exe | Key: | HKEY_CURRENT_USER\Software\Tukero[X]Team\TNod User & Password Finder |
| Operation: | write | Name: | NewVersions |
Value: 1 | |||
| (PID) Process: | (4000) TNODUP-Portable.exe | Key: | HKEY_CURRENT_USER\Software\Tukero[X]Team\TNod User & Password Finder |
| Operation: | write | Name: | AvoidNearExpiration |
Value: 0 | |||
| (PID) Process: | (4000) TNODUP-Portable.exe | Key: | HKEY_CURRENT_USER\Software\Tukero[X]Team\TNod User & Password Finder |
| Operation: | write | Name: | UseKey |
Value: 0 | |||
| (PID) Process: | (4000) TNODUP-Portable.exe | Key: | HKEY_CURRENT_USER\Software\Tukero[X]Team\TNod User & Password Finder |
| Operation: | write | Name: | KeyUnlock |
Value: | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2308 | TNODUP-Portable.exe | GET | 200 | 91.228.165.81:80 | http://iploc.eset.com/ip_locate_iso2 | SK | xml | 245 b | whitelisted |
2976 | TNODUP-Portable.exe | GET | 200 | 91.228.165.81:80 | http://iploc.eset.com/ip_locate_iso2 | SK | xml | 245 b | whitelisted |
2604 | TNODUP-Portable.exe | GET | 200 | 91.228.165.81:80 | http://iploc.eset.com/ip_locate_iso2 | SK | xml | 245 b | whitelisted |
3692 | TNODUP-Portable.exe | GET | 200 | 91.228.165.81:80 | http://iploc.eset.com/ip_locate_iso2 | SK | xml | 245 b | whitelisted |
3836 | TNODUP-Portable.exe | GET | 200 | 91.228.165.81:80 | http://iploc.eset.com/ip_locate_iso2 | SK | xml | 245 b | whitelisted |
1268 | TNODUP-Portable.exe | GET | 200 | 91.228.165.81:80 | http://iploc.eset.com/ip_locate_iso2 | SK | xml | 245 b | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4000 | TNODUP-Portable.exe | 91.228.167.125:80 | iploc.eset.com | ESET, spol. s r.o. | SK | unknown |
2308 | TNODUP-Portable.exe | 91.228.165.81:80 | iploc.eset.com | ESET, spol. s r.o. | SK | unknown |
2604 | TNODUP-Portable.exe | 91.228.165.81:80 | iploc.eset.com | ESET, spol. s r.o. | SK | unknown |
1268 | TNODUP-Portable.exe | 91.228.165.81:80 | iploc.eset.com | ESET, spol. s r.o. | SK | unknown |
1800 | TNODUP-Portable.exe | 91.228.165.81:80 | iploc.eset.com | ESET, spol. s r.o. | SK | unknown |
3692 | TNODUP-Portable.exe | 91.228.165.81:80 | iploc.eset.com | ESET, spol. s r.o. | SK | unknown |
2976 | TNODUP-Portable.exe | 91.228.165.81:80 | iploc.eset.com | ESET, spol. s r.o. | SK | unknown |
3836 | TNODUP-Portable.exe | 91.228.165.81:80 | iploc.eset.com | ESET, spol. s r.o. | SK | unknown |
Domain | IP | Reputation |
|---|---|---|
iploc.eset.com |
| whitelisted |