| download: | hex-editor-neo.exe |
| Full analysis: | https://app.any.run/tasks/bf0a9119-bb90-479e-b85b-7af15e8ec53e |
| Verdict: | Malicious activity |
| Analysis date: | April 13, 2018, 11:30:16 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 5F8290BCCB25E03C99195FCEE8C9C53D |
| SHA1: | B3E67B1EA87BB85447CAE96E088952EA1BC6291E |
| SHA256: | E585479D25D51152BC372564038BE08A603FAFB07434B1111AFF03863AA6668A |
| SSDEEP: | 393216:yfQ4elUiPdA1P8Sy8ICOJFjE5sJIG3Svq9Btx6TxARD1urE:gQUkw8SlIC8FQskvqntYTKl1qE |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2009:10:22 16:06:47+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 98816 |
| InitializedDataSize: | 76288 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x10086 |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.1 |
| ProductVersionNumber: | 1.0.0.1 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | HHD Software Ltd. |
| FileDescription: | HHD Software Setup Package |
| FileVersion: | 1, 0, 0, 1 |
| InternalName: | elevate |
| LegalCopyright: | Copyright (C) 2009 HHD Software, Ltd. |
| OriginalFileName: | elevate.exe |
| ProductName: | HHD Software Setup Package |
| ProductVersion: | 1, 0, 0, 1 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 22-Oct-2009 14:06:47 |
| Detected languages: |
|
| Debug artifacts: |
|
| CompanyName: | HHD Software Ltd. |
| FileDescription: | Hex Editor Neo Setup Package |
| FileVersion: | 6.31.00.5980 |
| LegalCopyright: | © 2017 by HHD Software Ltd. All rights reserved. |
| InternalName: | setup.exe |
| OriginalFilename: | setup.exe |
| ProductName: | Hex Editor Neo |
| ProductVersion: | 6.31.00.5980 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000E8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 22-Oct-2009 14:06:47 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00018044 | 0x00018200 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.55453 |
.rdata | 0x0001A000 | 0x0000551E | 0x00005600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.96248 |
.data | 0x00020000 | 0x00001FDC | 0x00001000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 2.76131 |
.rsrc | 0x00022000 | 0x00009B1C | 0x00009C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.8171 |
.reloc | 0x0002C000 | 0x00002614 | 0x00002800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.38843 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.23739 | 1207 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 5.65352 | 2216 | Latin 1 / Western European | English - United States | RT_ICON |
3 | 4.98977 | 16936 | Latin 1 / Western European | English - United States | RT_ICON |
4 | 6.19716 | 9640 | Latin 1 / Western European | English - United States | RT_ICON |
5 | 2.88987 | 168 | Latin 1 / Western European | English - United States | RT_STRING |
6 | 5.00852 | 1128 | Latin 1 / Western European | English - United States | RT_ICON |
7 | 0.545897 | 36 | Latin 1 / Western European | English - United States | RT_STRING |
500 | 3.07919 | 184 | Latin 1 / Western European | English - United States | RT_DIALOG |
4567 | 2.76737 | 90 | Latin 1 / Western European | English - United States | RT_GROUP_ICON |
VS_VERSION_INFO | 3.38846 | 812 | Latin 1 / Western European | English - United States | RT_VERSION |
KERNEL32.dll |
OLEAUT32.dll |
SHELL32.dll |
SHLWAPI.dll |
USER32.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2140 | C:\Users\admin\AppData\Local\Temp\{E93F2B64-627D-4EA9-8275-3BBC334A4C8D}\setup_x86.exe -7z "C:\Users\admin\AppData\Local\Temp\hex-editor-neo.exe" | C:\Users\admin\AppData\Local\Temp\{E93F2B64-627D-4EA9-8275-3BBC334A4C8D}\setup_x86.exe | hex-editor-neo.exe | ||||||||||||
User: admin Company: HHD Software Ltd. Integrity Level: MEDIUM Description: Hex Editor Neo Setup Package Exit code: 1000 Version: 6.31.00.5980 Modules
| |||||||||||||||
| 2404 | "C:\Users\admin\AppData\Local\Temp\hex-editor-neo.exe" | C:\Users\admin\AppData\Local\Temp\hex-editor-neo.exe | explorer.exe | ||||||||||||
User: admin Company: HHD Software Ltd. Integrity Level: MEDIUM Description: Hex Editor Neo Setup Package Exit code: 0 Version: 6.31.00.5980 Modules
| |||||||||||||||
| 3184 | "C:\Users\admin\AppData\Local\HHD Software\Hex Editor Neo\HexFrame.exe" | C:\Users\admin\AppData\Local\HHD Software\Hex Editor Neo\HexFrame.exe | — | setup_x86.exe | |||||||||||
User: admin Company: HHD Software Ltd. Integrity Level: MEDIUM Description: HHD Software Hex Editor Neo Exit code: 0 Version: 6.31.00.5980 Modules
| |||||||||||||||
| 3532 | C:\Windows\servicing\TrustedInstaller.exe | C:\Windows\servicing\TrustedInstaller.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows Modules Installer Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 4032 | "C:\Users\admin\AppData\Local\HHD Software\Hex Editor Neo\HexFrame.exe" | C:\Users\admin\AppData\Local\HHD Software\Hex Editor Neo\HexFrame.exe | — | setup_x86.exe | |||||||||||
User: admin Company: HHD Software Ltd. Integrity Level: MEDIUM Description: HHD Software Hex Editor Neo Exit code: 0 Version: 6.31.00.5980 Modules
| |||||||||||||||
| (PID) Process: | (3532) TrustedInstaller.exe | Key: | HKEY_LOCAL_MACHINE\COMPONENTS\ServicingStackVersions |
| Operation: | write | Name: | 6.1.7601.17514 (win7sp1_rtm.101119-1850) |
Value: 2018/4/13:11:30:48.186 6.1.7601.17514 (win7sp1_rtm.101119-1850) | |||
| (PID) Process: | (3532) TrustedInstaller.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing |
| Operation: | write | Name: | SessionIdHigh |
Value: 30659354 | |||
| (PID) Process: | (3532) TrustedInstaller.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing |
| Operation: | write | Name: | SessionIdLow |
Value: 3735686966 | |||
| (PID) Process: | (3532) TrustedInstaller.exe | Key: | HKEY_USERS\.DEFAULT\Software\Classes\Local Settings\MuiCache\91\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (3532) TrustedInstaller.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-Client-Refresh-LanguagePack-Package~31bf3856ad364e35~x86~en-US~6.1.7601.17514 |
| Operation: | write | Name: | Trusted |
Value: 1 | |||
| (PID) Process: | (3532) TrustedInstaller.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-PowerShell-Client-WTR-Package~31bf3856ad364e35~x86~~7.3.7601.1023 |
| Operation: | write | Name: | Trusted |
Value: 1 | |||
| (PID) Process: | (3532) TrustedInstaller.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB123456_client~31bf3856ad364e35~x86~~7.3.7601.1023 |
| Operation: | write | Name: | Trusted |
Value: 1 | |||
| (PID) Process: | (3532) TrustedInstaller.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Package_for_KB123456_client~31bf3856ad364e35~x86~en-US~7.3.7601.1023 |
| Operation: | write | Name: | Trusted |
Value: 1 | |||
| (PID) Process: | (3532) TrustedInstaller.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-PowerShell-Client-WTR-Package~31bf3856ad364e35~x86~en-US~7.3.7601.1023 |
| Operation: | write | Name: | Trusted |
Value: 1 | |||
| (PID) Process: | (3532) TrustedInstaller.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Component Based Servicing\Packages\Microsoft-Windows-WinMan-WinIP-Package-MiniLP~31bf3856ad364e35~x86~en-US~7.3.7601.1023 |
| Operation: | write | Name: | Trusted |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2404 | hex-editor-neo.exe | C:\Users\admin\AppData\Local\Temp\{038A5772-CCA9-4C19-A1CA-0B8C8FE3C9DB} | executable | |
MD5:— | SHA256:— | |||
| 2404 | hex-editor-neo.exe | C:\Users\admin\AppData\Local\Temp\{E93F2B64-627D-4EA9-8275-3BBC334A4C8D}\Components\deditor.dll\deditor.cdx | binary | |
MD5:— | SHA256:— | |||
| 2404 | hex-editor-neo.exe | C:\Users\admin\AppData\Local\Temp\{E93F2B64-627D-4EA9-8275-3BBC334A4C8D}\Components\FileDocument.dll\FileDocument.cdx | binary | |
MD5:— | SHA256:— | |||
| 2404 | hex-editor-neo.exe | C:\Users\admin\AppData\Local\Temp\{E93F2B64-627D-4EA9-8275-3BBC334A4C8D}\Components\bookmarks.dll\bookmarks.cdx | binary | |
MD5:73A10829A3F05AA76022AAFD5FAA5D61 | SHA256:B4029F7187978B1AD5014FD1F4CC7464FEF8236CD0AE066DD89DD3BFADE8D1FB | |||
| 2404 | hex-editor-neo.exe | C:\Users\admin\AppData\Local\Temp\{E93F2B64-627D-4EA9-8275-3BBC334A4C8D}\Components\HexFrame.exe\default.hexdwc | hexdwc | |
MD5:— | SHA256:— | |||
| 2404 | hex-editor-neo.exe | C:\Users\admin\AppData\Local\Temp\{E93F2B64-627D-4EA9-8275-3BBC334A4C8D}\Components\Hex Editor.chm\Hex Editor.chm | chm | |
MD5:— | SHA256:— | |||
| 2404 | hex-editor-neo.exe | C:\Users\admin\AppData\Local\Temp\{E93F2B64-627D-4EA9-8275-3BBC334A4C8D}\Components\checksum.dll\checksum.cdx | binary | |
MD5:B7C25203CEFD4ACCC458C13054C6510E | SHA256:728376AC3B3947FD72AB25233DB5A6814AEDBE555F770F2CE8C7B4B3BB3A6BB4 | |||
| 2404 | hex-editor-neo.exe | C:\Users\admin\AppData\Local\Temp\{E93F2B64-627D-4EA9-8275-3BBC334A4C8D}\Components\expint\Install Explorer Integration HKLM.rgs | text | |
MD5:A9352B8E96B479E3BB784C0E4F669BC5 | SHA256:BC07744711353C5132B60440C09F97CA2FF7CC6E540C8C649A37AA8A1D8288B1 | |||
| 2404 | hex-editor-neo.exe | C:\Users\admin\AppData\Local\Temp\{E93F2B64-627D-4EA9-8275-3BBC334A4C8D}\Components\default.hexset\default.hexset | hexset | |
MD5:9BC3544D2F798E929FA90CFF5C4C637B | SHA256:FC2138F6BD72B7FD7A5AB4AF644F9FE0C6657CF6243D9E33EB8C15DDCF4205BC | |||
| 2404 | hex-editor-neo.exe | C:\Users\admin\AppData\Local\Temp\{E93F2B64-627D-4EA9-8275-3BBC334A4C8D}\Components\editor.dll\editor.cdx | binary | |
MD5:97A3890070B01A06225918DA956C0EC4 | SHA256:119D243BBF2F43533F0BD061AFC9BD5D8A7023392A7C238A12884B2B099A6BFB | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 304 | 2.16.186.56:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | unknown | — | — | whitelisted |
— | — | GET | 200 | 104.31.74.124:80 | http://crl.globalsign.com/gs/gscodesigng3.crl | US | der | 555 b | whitelisted |
— | — | GET | 200 | 104.31.74.124:80 | http://ocsp.globalsign.com/rootr1/ME8wTTBLMEkwRzAJBgUrDgMCGgUABBS3V7W2nAf4FiMTjpDJKg6%2BMgGqMQQUYHtmGkUNl8qJUC99BM00qP%2F8%2FUsCDkfDD%2F78IrsoD5b%2Bp1JR | US | der | 1.49 Kb | whitelisted |
— | — | GET | 200 | 104.31.74.124:80 | http://ocsp2.globalsign.com/gscodesigng3/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBTHTu2Y6Nr%2FMkfa3PrlxnwonnIpxQQUs9Pm1XFWfTlYs3jSK7j3oR%2F9S5sCDFpzJU%2BEgGHq8Ks6Pw%3D%3D | US | der | 1.49 Kb | whitelisted |
— | — | GET | 301 | 184.107.220.188:80 | http://www.hhdsoftware.com/dispatch/hex/get-beta?betaid=%7B9592772D-F4AD-411D-B6C9-6BB6D6447BEC%7D&mode=x86 | CA | html | 235 b | unknown |
— | — | GET | 301 | 184.107.220.188:80 | http://www.hhdsoftware.com/dispatch/hex/beta-versions?version=631005980 | CA | html | 195 b | unknown |
— | — | HEAD | — | 184.107.220.188:80 | http://www.hhdsoftware.com/dispatch/hex/checkforupdates | CA | — | — | unknown |
— | — | GET | 301 | 184.107.220.188:80 | http://www.hhdsoftware.com/dispatch/hex/checkforupdates | CA | text | 179 b | unknown |
— | — | GET | 304 | 2.16.186.56:80 | http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab | unknown | — | — | whitelisted |
— | — | GET | 301 | 184.107.220.188:80 | http://www.hhdsoftware.com/dispatch/hex/beta-versions?version=631005980 | CA | html | 195 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 104.31.74.124:80 | ocsp.globalsign.com | Cloudflare Inc | US | shared |
— | — | 2.16.186.56:80 | www.download.windowsupdate.com | Akamai International B.V. | — | whitelisted |
— | — | 184.107.220.188:80 | www.hhdsoftware.com | iWeb Technologies Inc. | CA | unknown |
— | — | 184.107.220.188:443 | www.hhdsoftware.com | iWeb Technologies Inc. | CA | unknown |
Domain | IP | Reputation |
|---|---|---|
ocsp.globalsign.com |
| whitelisted |
ocsp2.globalsign.com |
| whitelisted |
crl.globalsign.com |
| whitelisted |
www.download.windowsupdate.com |
| whitelisted |
www.hhdsoftware.com |
| unknown |