| File name: | Universal-USB-Installer-2.0.0.1.exe |
| Full analysis: | https://app.any.run/tasks/bac850f1-4e0f-4d3d-99f1-197fca397da9 |
| Verdict: | Malicious activity |
| Analysis date: | June 12, 2024, 03:59:28 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 1EE1CC50D1FE08E3799F4A16300387CC |
| SHA1: | 5FB141D54D912DA43FFAF7BA1D380DE515CB32DF |
| SHA256: | E57948610906FB0E13C406C2DE1541E2464EFA45568BA46058546151B881F8C7 |
| SSDEEP: | 98304:ltHB9kFplf7jWld9V4OV27tlEwhMdXl5JlWpXQID834bD0UmcHZQOli9jJ7OrIOb:4ehA |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2020:08:01 02:43:17+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 26112 |
| InitializedDataSize: | 141824 |
| UninitializedDataSize: | 2048 |
| EntryPoint: | 0x348f |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.0.0.1 |
| ProductVersionNumber: | 2.0.0.1 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | pendrivelinux.com |
| FileDescription: | Universal USB Installer |
| FileVersion: | 2.0.0.1 |
| LegalCopyright: | Copyright © Pendrivelinux.com |
| License: | GPL Version 2 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1020 | "C:\Users\admin\Desktop\Universal-USB-Installer-2.0.0.1.exe" | C:\Users\admin\Desktop\Universal-USB-Installer-2.0.0.1.exe | explorer.exe | ||||||||||||
User: admin Company: pendrivelinux.com Integrity Level: HIGH Description: Universal USB Installer Version: 2.0.0.1 Modules
| |||||||||||||||
| 3964 | "C:\Users\admin\Desktop\Universal-USB-Installer-2.0.0.1.exe" | C:\Users\admin\Desktop\Universal-USB-Installer-2.0.0.1.exe | — | explorer.exe | |||||||||||
User: admin Company: pendrivelinux.com Integrity Level: MEDIUM Description: Universal USB Installer Exit code: 3221226540 Version: 2.0.0.1 Modules
| |||||||||||||||
| (PID) Process: | (1020) Universal-USB-Installer-2.0.0.1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\FirstFolder |
| Operation: | delete value | Name: | MRUList |
Value: | |||
| (PID) Process: | (1020) Universal-USB-Installer-2.0.0.1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\FirstFolder |
| Operation: | write | Name: | 0 |
Value: 43003A005C00550073006500720073005C00610064006D0069006E005C004400650073006B0074006F0070005C0055006E006900760065007200730061006C002D005500530042002D0049006E007300740061006C006C00650072002D0032002E0030002E0030002E0031002E00650078006500000043003A005C00550073006500720073005C00610064006D0069006E005C004400650073006B0074006F0070000000 | |||
| (PID) Process: | (1020) Universal-USB-Installer-2.0.0.1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\FirstFolder |
| Operation: | write | Name: | MRUListEx |
Value: 00000000FFFFFFFF | |||
| (PID) Process: | (1020) Universal-USB-Installer-2.0.0.1.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
| Operation: | write | Name: | NodeSlots |
Value: 0202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202 | |||
| (PID) Process: | (1020) Universal-USB-Installer-2.0.0.1.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
| Operation: | write | Name: | MRUListEx |
Value: 01000000070000000200000006000000000000000B0000000C0000000D0000000A0000000900000008000000030000000500000004000000FFFFFFFF | |||
| (PID) Process: | (1020) Universal-USB-Installer-2.0.0.1.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1020) Universal-USB-Installer-2.0.0.1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU |
| Operation: | write | Name: | 4 |
Value: 55006E006900760065007200730061006C002D005500530042002D0049006E007300740061006C006C00650072002D0032002E0030002E0030002E0031002E00650078006500000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000087010000AF000000070400008F020000000000000000000000000000000000000100000000000000 | |||
| (PID) Process: | (1020) Universal-USB-Installer-2.0.0.1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU |
| Operation: | delete value | Name: | 4 |
Value: Universal-USB-Installer-2.0.0.1.exe | |||
| (PID) Process: | (1020) Universal-USB-Installer-2.0.0.1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU |
| Operation: | write | Name: | 4 |
Value: 55006E006900760065007200730061006C002D005500530042002D0049006E007300740061006C006C00650072002D0032002E0030002E0030002E0031002E0065007800650000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000084010000990000007B0300001B0200000000000000000000000000000000000087010000AF000000070400008F020000000000000000000000000000000000000100000000000000 | |||
| (PID) Process: | (1020) Universal-USB-Installer-2.0.0.1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Explorer\ComDlg32\CIDSizeMRU |
| Operation: | write | Name: | MRUListEx |
Value: 0400000000000000020000000300000001000000FFFFFFFF | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1020 | Universal-USB-Installer-2.0.0.1.exe | C:\Users\admin\AppData\Local\Temp\nsd5864.tmp\System.dll | executable | |
MD5:564BB0373067E1785CBA7E4C24AAB4BF | SHA256:7A9DDEE34562CD3703F1502B5C70E99CD5BBA15DE2B6845A3555033D7F6CB2A5 | |||
| 1020 | Universal-USB-Installer-2.0.0.1.exe | C:\Users\admin\AppData\Local\Temp\nsd5864.tmp\dd.exe | executable | |
MD5:07B1675393A6C80078E29C9EA72DE943 | SHA256:1625916B6838B89316EBD46704CB571C213C6D65C0B659D8D1AD67F6184322D7 | |||
| 1020 | Universal-USB-Installer-2.0.0.1.exe | C:\Users\admin\AppData\Local\Temp\nsd5864.tmp\modern-header.bmp | image | |
MD5:8CC1FC5217E1F6DB61F615F2FBBAB7B5 | SHA256:DD1EE4E2D6D7D7553882FBAB6B2D4D49F6681C03D0004D2F254BF124E070056C | |||
| 1020 | Universal-USB-Installer-2.0.0.1.exe | C:\Users\admin\AppData\Local\Temp\nsd5864.tmp\nsDialogs.dll | executable | |
MD5:48F3E7860E1DE2B4E63EC744A5E9582A | SHA256:6BF9CCCD8A600F4D442EFE201E8C07B49605BA35F49A4B3AB22FA2641748E156 | |||
| 1020 | Universal-USB-Installer-2.0.0.1.exe | C:\Users\admin\AppData\Local\Temp\nsd5864.tmp\diskpartformat.txt | text | |
MD5:F912FB889CC2B5789BE1A7C9FE0630E7 | SHA256:6BB876239381B4360393F15FE8F072BABA319CFA92824F1B1ED55A5261FB07A8 | |||
| 1020 | Universal-USB-Installer-2.0.0.1.exe | C:\Users\admin\AppData\Local\Temp\nsd5864.tmp\UserInfo.dll | executable | |
MD5:98FF85B635D9114A9F6A0CD7B9B649D0 | SHA256:933F93A30CE44DF96CBC4AC0B56A8B02EE01DA27E4EA665D1D846357A8FCA8DE | |||
| 1020 | Universal-USB-Installer-2.0.0.1.exe | C:\Users\admin\AppData\Local\Temp\nsd5864.tmp\fat32format.exe | executable | |
MD5:BD912813AE9D69A0D02CA09153CB0584 | SHA256:AE0DCB42F24BF147A07B1509D8BCF345CA88EA4FE5363527F26CF8859525E657 | |||
| 1020 | Universal-USB-Installer-2.0.0.1.exe | C:\Users\admin\AppData\Local\Temp\nsd5864.tmp\diskpartwipe2.txt | text | |
MD5:0FF3ACBFBE5B9EB00A2563E6DC11461C | SHA256:7372271F2D424ACBBFD3E9CC4DE7D832433219989B4F5DC6786EEC80B8B7BA4C | |||
| 1020 | Universal-USB-Installer-2.0.0.1.exe | C:\Users\admin\AppData\Local\Temp\nsd5864.tmp\diskpartwipe1.txt | text | |
MD5:79491BD2DC17EB0D462705626AB31FEF | SHA256:F99FE8878C9DEA32204B8D1B046E616C635B03A7A904BB9FBDD6F96041DE82BC | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |