| File name: | lgs510_x64.exe |
| Full analysis: | https://app.any.run/tasks/ca80e879-b775-4e0d-87aa-ae9710a2753c |
| Verdict: | Malicious activity |
| Analysis date: | January 11, 2021, 23:33:19 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 6B07168CDB643FB7AD7661939944D490 |
| SHA1: | 165E410B6A9D7E34E14B081A7A6EE2D904D9C835 |
| SHA256: | E07A278EAB65DF9FA50B3C454627C7169BEB41824015839D2A0368CAF284CA76 |
| SSDEEP: | 393216:uLTJR6/h7HXd+LaQRI3Ln13WXWia/sCfV:WJkZTtO8D13WXW5tV |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2015:08:05 02:46:24+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 24064 |
| InitializedDataSize: | 141824 |
| UninitializedDataSize: | 2048 |
| EntryPoint: | 0x31ff |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 5.40.22.0 |
| ProductVersionNumber: | 5.40.22.0 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Logitech Inc. |
| FileDescription: | Setup |
| FileVersion: | 5.40.22 |
| LegalCopyright: | Copyright (c) 2005-2016 Logitech. All Rights Reserved |
| ProductName: | Install_64 Setup |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 05-Aug-2015 00:46:24 |
| Detected languages: |
|
| CompanyName: | Logitech Inc. |
| FileDescription: | Setup |
| FileVersion: | 5.40.22 |
| LegalCopyright: | Copyright (c) 2005-2016 Logitech. All Rights Reserved |
| ProductName: | Install_64 Setup |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000C8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 05-Aug-2015 00:46:24 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00005D98 | 0x00005E00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.47176 |
.rdata | 0x00007000 | 0x00001354 | 0x00001400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.0375 |
.data | 0x00009000 | 0x000202B8 | 0x00000600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.75053 |
.ndata | 0x0002A000 | 0x00031000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x0005B000 | 0x00000A78 | 0x00000C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.28399 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.28836 | 842 | UNKNOWN | English - United States | RT_MANIFEST |
103 | 2.16096 | 20 | UNKNOWN | English - United States | RT_GROUP_ICON |
111 | 2.48825 | 96 | UNKNOWN | English - United States | RT_DIALOG |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
SHELL32.dll |
USER32.dll |
VERSION.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1252 | "C:\Users\admin\AppData\Local\Temp\lgs510_x64.exe" | C:\Users\admin\AppData\Local\Temp\lgs510_x64.exe | explorer.exe | ||||||||||||
User: admin Company: Logitech Inc. Integrity Level: HIGH Description: Setup Exit code: 0 Version: 5.40.22 Modules
| |||||||||||||||
| 2096 | "C:\Users\admin\AppData\Local\Temp\pft95E1.tmp\MSetup.exe" | C:\Users\admin\AppData\Local\Temp\pft95E1.tmp\MSetup.exe | — | Setup.exe | |||||||||||
User: admin Company: Logitech, Inc. Integrity Level: HIGH Description: Logitech Installer Exit code: 0 Version: 1.1.0.41 Modules
| |||||||||||||||
| 2764 | "C:\Users\admin\AppData\Local\Temp\lgs510_x64.exe" | C:\Users\admin\AppData\Local\Temp\lgs510_x64.exe | — | explorer.exe | |||||||||||
User: admin Company: Logitech Inc. Integrity Level: MEDIUM Description: Setup Exit code: 3221226540 Version: 5.40.22 Modules
| |||||||||||||||
| 3076 | "C:\Users\admin\AppData\Local\Temp\pft95E1.tmp\Setup.exe" | C:\Users\admin\AppData\Local\Temp\pft95E1.tmp\Setup.exe | — | lgs510_x64.exe | |||||||||||
User: admin Company: Logitech, Inc. Integrity Level: HIGH Description: Logitech Installer Exit code: 0 Version: 1.1.0.41 Modules
| |||||||||||||||
| 3852 | C:\Users\admin\AppData\Local\Temp\Logitech\Logitech_Wingman510_w_SDK_1\lgs510_x64.exe | C:\Users\admin\AppData\Local\Temp\Logitech\Logitech_Wingman510_w_SDK_1\lgs510_x64.exe | lgs510_x64.exe | ||||||||||||
User: admin Company: Logitech Integrity Level: HIGH Description: Exit code: 0 Version: 5.10 Modules
| |||||||||||||||
| (PID) Process: | (3076) Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3076) Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2096) MSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2096) MSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (2096) MSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
| Operation: | write | Name: | CachePrefix |
Value: | |||
| (PID) Process: | (2096) MSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2096) MSetup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
| (PID) Process: | (1252) lgs510_x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{63bd165d-1584-4e75-ab56-08330350545f} |
| Operation: | write | Name: | (default) |
Value: Logitech Steering SDK DLL | |||
| (PID) Process: | (1252) lgs510_x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{63bd165d-1584-4e75-ab56-08330350545f}\ServerBinary |
| Operation: | write | Name: | (default) |
Value: C:\Program Files\Logitech\Gaming Software\SDKs\LogitechSteeringWheel.dll | |||
| (PID) Process: | (1252) lgs510_x64.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Wow6432Node\CLSID\{63bd165d-1584-4e75-ab56-08330350545f} |
| Operation: | write | Name: | (default) |
Value: Logitech Steering SDK DLL | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3852 | lgs510_x64.exe | C:\Users\admin\AppData\Local\Temp\ext95B1.tmp | — | |
MD5:— | SHA256:— | |||
| 3852 | lgs510_x64.exe | C:\Users\admin\AppData\Local\Temp\pft95E1.tmp\pftw1.pkg | — | |
MD5:— | SHA256:— | |||
| 1252 | lgs510_x64.exe | C:\Users\admin\AppData\Local\Temp\Logitech\Logitech_Wingman510_w_SDK_1\LogitechSteeringWheel.dll | executable | |
MD5:072D9F27A55E9956F1FCC4047E676767 | SHA256:ACDA0C6D7AA18DFD566B569F7ACD7114297D999EC165DC390720A06027719336 | |||
| 1252 | lgs510_x64.exe | C:\Users\admin\AppData\Roaming\Logishrd\LGS8_setup\WingmanWsdk_setup.log | text | |
MD5:— | SHA256:— | |||
| 3852 | lgs510_x64.exe | C:\Users\admin\AppData\Local\Temp\pft95E1.tmp\2b-LGS-x64\0x0408.ini | text | |
MD5:F860ECE04B6DE4A821D95F3AB9D64CCA | SHA256:E072E421A61482B7065D785B8676495CD7E8867EE7E0A5A7B1BCF7BA607BF29A | |||
| 1252 | lgs510_x64.exe | C:\Users\admin\AppData\Local\Temp\Logitech\Logitech_Wingman510_w_SDK_1\lgs510_x64.exe | executable | |
MD5:5F5B7B448089E2D35FD7FFECA1D4B4AC | SHA256:1F55ABB1C0857F1ADFF10D216B848B0F8BCC3FD2D35F9F84B27CFC3EB5A37C32 | |||
| 3852 | lgs510_x64.exe | C:\Users\admin\AppData\Local\Temp\pft95E1.tmp\2b-LGS-x64\0x0406.ini | text | |
MD5:74CB500770437C6DAF4687CF7DF1D032 | SHA256:AC2794DA361C7AE822445C36725A8D6E36E2DF4025E68FE8B0DCD3C16448D274 | |||
| 3852 | lgs510_x64.exe | C:\Users\admin\AppData\Local\Temp\pft95E1.tmp\2b-LGS-x64\0x0404.ini | text | |
MD5:4F35EFBC0549F42AC85966C1FB9A406A | SHA256:7586EC9EBF0979BEAB7DBEB5D4D08C0C77550E8FFBD8058A93FB3F37639DEC5F | |||
| 3852 | lgs510_x64.exe | C:\Users\admin\AppData\Local\Temp\pft95E1.tmp\2b-LGS-x64\0x0409.ini | text | |
MD5:36AFFBD6FF77D1515CFC1C5E998FBAF9 | SHA256:FCCC7F79D29318D8AE78850C262BAC762C28858709A6E6CF3B62BCD2729A61E3 | |||
| 3852 | lgs510_x64.exe | C:\Users\admin\AppData\Local\Temp\pft95E1.tmp\2b-LGS-x64\0x0407.ini | text | |
MD5:24C0525FB3E964776A84F8939D206656 | SHA256:FA297AAC13A7664C2A732A99CD2A91624F355B490155CE65152FBD3776FD7B43 | |||