| File name: | PowerReg Scheduler.exe |
| Full analysis: | https://app.any.run/tasks/6f54444d-6c97-4c1d-9a9f-da2684977294 |
| Verdict: | Malicious activity |
| Analysis date: | March 02, 2024, 16:47:16 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | E7059F8D8B2C40E485E5A26DDF2EFFEF |
| SHA1: | AA78106320DF0E438FE25E8E1FCB7CF62392B18A |
| SHA256: | D9C7CAF0311D1C80F2BA36347C9EEFBBF9C1AFB5B970292E23EEDF8406A5BBAC |
| SSDEEP: | 6144:LDnr9690cFzNrwrAW7x2U6Y9pYxpA9LyoqhI+4KaF7Lmk:Hcy0Wd2U6c9LyoqhI+ohLP |
| .exe | | | Win32 Executable MS Visual C++ 4.x (50.4) |
|---|---|---|
| .exe | | | InstallShield setup (16.1) |
| .exe | | | Win32 Executable MS Visual C++ (generic) (11.6) |
| .exe | | | Win64 Executable (generic) (10.3) |
| .scr | | | Windows screen saver (4.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1999:06:02 22:01:38+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 5 |
| CodeSize: | 114176 |
| InitializedDataSize: | 157184 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x45000 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.0.0.1 |
| ProductVersionNumber: | 2.0.0.1 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | - |
| FileDescription: | PRegScheduler MFC Application |
| FileVersion: | 2, 0, 0, 1 |
| InternalName: | PRegScheduler |
| LegalCopyright: | Copyright (C) 1999 |
| OriginalFileName: | PRegScheduler.EXE |
| ProductName: | PRegScheduler Application |
| ProductVersion: | 2, 0, 0, 1 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2160 | "C:\Users\admin\AppData\Local\Temp\PowerReg Scheduler.exe" | C:\Users\admin\AppData\Local\Temp\PowerReg Scheduler.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Description: PRegScheduler MFC Application Exit code: 0 Version: 2, 0, 0, 1 Modules
| |||||||||||||||
| 3348 | "C:\Program Files\Internet Explorer\iexplore.exe" | C:\Program Files\Internet Explorer\iexplore.exe | PowerReg Schedulermgr.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 3652 | "C:\Users\admin\AppData\Local\Temp\PowerReg Schedulermgr.exe" | C:\Users\admin\AppData\Local\Temp\PowerReg Schedulermgr.exe | PowerReg Scheduler.exe | ||||||||||||
User: admin Company: Avira GmbH Integrity Level: MEDIUM Description: AntiVir Command Line Scanner for Windows Exit code: 0 Version: 7.6.0.59 Modules
| |||||||||||||||
| (PID) Process: | (3348) iexplore.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Winlogon |
| Operation: | write | Name: | Userinit |
Value: C:\Windows\system32\userinit.exe,,C:\Program Files\vkjsglxp\enbfqohg.exe | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3348 | iexplore.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Startup\enbfqohg.exe | executable | |
MD5:7657FCB7D772448A6D8504E4B20168B8 | SHA256:54BC950D46A0D1AA72048A17C8275743209E6C17BDACFC4CB9601C9CE3EC9A71 | |||
| 3652 | PowerReg Schedulermgr.exe | C:\Users\admin\AppData\Local\Temp\~TM858.tmp | executable | |
MD5:EBB2B4FD62087283D9448F7F8796727D | SHA256:9C9EA64C0D56BF17D388C58B36AB7A79CA6AA74446B6DD2F614F5CBF9D828529 | |||
| 2160 | PowerReg Scheduler.exe | C:\Users\admin\AppData\Local\Temp\PowerReg Schedulermgr.exe | executable | |
MD5:7657FCB7D772448A6D8504E4B20168B8 | SHA256:54BC950D46A0D1AA72048A17C8275743209E6C17BDACFC4CB9601C9CE3EC9A71 | |||
| 3652 | PowerReg Schedulermgr.exe | C:\Users\admin\AppData\Local\Temp\~TM8D6.tmp | executable | |
MD5:BFCB6AA8CEC2B46A696D9573BC3590B9 | SHA256:14C770C42C2AB9383540AF594CC546E6BEFEE0AFCCD48B4A24A9D8687711D689 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
3348 | iexplore.exe | 49.13.77.253:443 | stromoliks.com | Hetzner Online GmbH | DE | unknown |
3348 | iexplore.exe | 142.250.186.174:80 | — | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
stromoliks.com |
| malicious |