File name: | SDManager2_Setup.exe |
Full analysis: | https://app.any.run/tasks/05ea4540-d4f5-4fdd-8d48-be7652698cb9 |
Verdict: | Malicious activity |
Analysis date: | May 15, 2019, 13:05:07 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Tags: | |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | CB71100DB623CF9DAB97428EC6912392 |
SHA1: | 8C953276017FFF65B38865DC54A3AC8F07D753E5 |
SHA256: | E60535D82BB2734E05DFCD2499A0F819745819027C517775CDE8C006EEA6FCBF |
SSDEEP: | 98304:riYNlZJfyQZzTB7u5zusl03bGX8S6YEl5kI3I4abiYNlZ9L:9bJKQGH5El5n3KNb9L |
.ax | | | DirectShow filter (37.6) |
---|---|---|
.exe | | | Win32 EXE PECompact compressed (v2.x) (11) |
.exe | | | InstallShield setup (8) |
.exe | | | Win32 EXE PECompact compressed (generic) (7.7) |
ISInternalDescription: | InstallScript Setup Launcher Unicode |
---|---|
ISInternalVersion: | 20.0.496 |
InternalBuildNumber: | 133442 |
ProductVersion: | 1.3 |
ProductName: | SD Manager 2 |
OriginalFileName: | InstallShield Setup.exe |
LegalCopyright: | Copyright (c) 2013 Flexera Software LLC. All Rights Reserved. |
InternalName: | Setup |
FileVersion: | 1.3 |
FileDescription: | InstallScript Setup Launcher Unicode |
CompanyName: | OMRON Corporation |
CharacterSet: | Unicode |
LanguageCode: | English (U.S.) |
FileSubtype: | - |
ObjectFileType: | Dynamic link library |
FileOS: | Win32 |
FileFlags: | (none) |
FileFlagsMask: | 0x003f |
ProductVersionNumber: | 1.30.0.0 |
FileVersionNumber: | 1.30.0.0 |
Subsystem: | Windows GUI |
SubsystemVersion: | 5 |
ImageVersion: | - |
OSVersion: | 5 |
EntryPoint: | 0x40181 |
UninitializedDataSize: | - |
InitializedDataSize: | 389632 |
CodeSize: | 421888 |
LinkerVersion: | 9 |
PEType: | PE32 |
TimeStamp: | 2013:10:02 06:08:55+02:00 |
MachineType: | Intel 386 or later, and compatibles |
Architecture: | IMAGE_FILE_MACHINE_I386 |
---|---|
Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
Compilation Date: | 02-Oct-2013 04:08:55 |
Detected languages: |
|
CompanyName: | OMRON Corporation |
FileDescription: | InstallScript Setup Launcher Unicode |
FileVersion: | 1.30 |
InternalName: | Setup |
LegalCopyright: | Copyright (c) 2013 Flexera Software LLC. All Rights Reserved. |
OriginalFilename: | InstallShield Setup.exe |
ProductName: | SD Manager 2 |
ProductVersion: | 1.30 |
Internal Build Number: | 133442 |
ISInternalVersion: | 20.0.496 |
ISInternalDescription: | InstallScript Setup Launcher Unicode |
Magic number: | MZ |
---|---|
Bytes on last page of file: | 0x0090 |
Pages in file: | 0x0003 |
Relocations: | 0x0000 |
Size of header: | 0x0004 |
Min extra paragraphs: | 0x0000 |
Max extra paragraphs: | 0xFFFF |
Initial SS value: | 0x0000 |
Initial SP value: | 0x00B8 |
Checksum: | 0x0000 |
Initial IP value: | 0x0000 |
Initial CS value: | 0x0000 |
Overlay number: | 0x0000 |
OEM identifier: | 0x0000 |
OEM information: | 0x0000 |
Address of NE header: | 0x000000F8 |
Signature: | PE |
---|---|
Machine: | IMAGE_FILE_MACHINE_I386 |
Number of sections: | 4 |
Time date stamp: | 02-Oct-2013 04:08:55 |
Pointer to Symbol Table: | 0x00000000 |
Number of symbols: | 0 |
Size of Optional Header: | 0x00E0 |
Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
---|---|---|---|---|---|
.text | 0x00001000 | 0x00066F49 | 0x00067000 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.57783 |
.rdata | 0x00068000 | 0x000142A6 | 0x00014400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.61083 |
.data | 0x0007D000 | 0x0000449C | 0x00002400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.2695 |
.rsrc | 0x00082000 | 0x0004881C | 0x00048A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 6.40758 |
Title | Entropy | Size | Codepage | Language | Type |
---|---|---|---|---|---|
1 | 5.23257 | 1206 | Latin 1 / Western European | UNKNOWN | RT_MANIFEST |
2 | 3.835 | 744 | Latin 1 / Western European | UNKNOWN | RT_ICON |
3 | 3.35696 | 296 | Latin 1 / Western European | UNKNOWN | RT_ICON |
4 | 6.14965 | 3752 | Latin 1 / Western European | UNKNOWN | RT_ICON |
5 | 6.18448 | 2216 | Latin 1 / Western European | UNKNOWN | RT_ICON |
6 | 4.85842 | 1384 | Latin 1 / Western European | UNKNOWN | RT_ICON |
7 | 5.57777 | 9640 | Latin 1 / Western European | UNKNOWN | RT_ICON |
8 | 5.81004 | 4264 | Latin 1 / Western European | UNKNOWN | RT_ICON |
9 | 6.06596 | 1128 | Latin 1 / Western European | UNKNOWN | RT_ICON |
10 | 3.22977 | 744 | Latin 1 / Western European | UNKNOWN | RT_ICON |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
LZ32.dll |
OLEAUT32.dll |
RPCRT4.dll |
SHELL32.dll |
USER32.dll |
VERSION.dll |
PID | CMD | Path | Indicators | Parent process |
---|---|---|---|---|
392 | "C:\Users\admin\AppData\Local\Temp\SDManager2_Setup.exe" | C:\Users\admin\AppData\Local\Temp\SDManager2_Setup.exe | — | explorer.exe |
User: admin Company: OMRON Corporation Integrity Level: MEDIUM Description: InstallScript Setup Launcher Unicode Exit code: 3221226540 Version: 1.30 | ||||
3144 | "C:\Users\admin\AppData\Local\Temp\SDManager2_Setup.exe" | C:\Users\admin\AppData\Local\Temp\SDManager2_Setup.exe | explorer.exe | |
User: admin Company: OMRON Corporation Integrity Level: HIGH Description: InstallScript Setup Launcher Unicode Version: 1.30 | ||||
1108 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
3468 | DrvInst.exe "1" "200" "STORAGE\VolumeSnapshot\HarddiskVolumeSnapshot18" "" "" "6792c44eb" "00000000" "00000580" "00000388" | C:\Windows\system32\DrvInst.exe | — | svchost.exe |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2208 | "C:\Users\admin\AppData\Local\Temp\{D0ABD06D-9B92-4C72-965A-C0CE0ACEA9E8}\DotNetInstaller.exe" "C:\Program Files\OMRON\SD Manager 2\SDManager2.exe" | C:\Users\admin\AppData\Local\Temp\{D0ABD06D-9B92-4C72-965A-C0CE0ACEA9E8}\DotNetInstaller.exe | — | SDManager2_Setup.exe |
User: admin Company: InstallShield Software Corporation Integrity Level: HIGH Description: DotNetInstaller Exit code: 0 Version: 20.0.0.376 | ||||
2744 | "C:\Users\admin\AppData\Local\Temp\{D0ABD06D-9B92-4C72-965A-C0CE0ACEA9E8}\DotNetInstaller.exe" "C:\Program Files\OMRON\SD Manager 2\en-US\SDManager2.resources.dll" | C:\Users\admin\AppData\Local\Temp\{D0ABD06D-9B92-4C72-965A-C0CE0ACEA9E8}\DotNetInstaller.exe | — | SDManager2_Setup.exe |
User: admin Company: InstallShield Software Corporation Integrity Level: HIGH Description: DotNetInstaller Exit code: 0 Version: 20.0.0.376 | ||||
2280 | "C:\Users\admin\AppData\Local\Temp\{D0ABD06D-9B92-4C72-965A-C0CE0ACEA9E8}\{69FC2104-E57B-4175-B91C-80929FDE1654}\dpinst32.exe" /F /SW /C /PATH "C:\Program Files\OMRON\SD Manager 2\Driver\x86" | C:\Users\admin\AppData\Local\Temp\{D0ABD06D-9B92-4C72-965A-C0CE0ACEA9E8}\{69FC2104-E57B-4175-B91C-80929FDE1654}\dpinst32.exe | SDManager2_Setup.exe | |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Driver Package Installer Exit code: 256 Version: 2.1 | ||||
704 | DrvInst.exe "4" "0" "C:\Users\admin\AppData\Local\Temp\{0a2e5e60-74de-1a2d-e008-51413c9c6b16}\f39-gif.inf" "0" "64be229f3" "000005B8" "WinSta0\Default" "000005C8" "208" "c:\program files\omron\sd manager 2\driver\x86" | C:\Windows\system32\DrvInst.exe | — | svchost.exe |
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
2860 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{235f2b39-f52b-3c6e-bdf5-4e038f649d5a} Global\{07fbaf35-b879-4472-8b00-7352c43ba302} C:\Windows\System32\DriverStore\Temp\{3b3b32f1-58cf-3742-fdfc-9437dd49332f}\f39-gif.inf C:\Windows\System32\DriverStore\Temp\{3b3b32f1-58cf-3742-fdfc-9437dd49332f}\F39GIF_IFU.cat | C:\Windows\system32\rundll32.exe | — | DrvInst.exe |
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) | ||||
1364 | "C:\Program Files\OMRON\SD Manager 2\SDManager2.exe" | C:\Program Files\OMRON\SD Manager 2\SDManager2.exe | — | explorer.exe |
User: admin Integrity Level: MEDIUM Description: SDManager2 Version: 1.3.0.0 |
(PID) Process: | (3144) SDManager2_Setup.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
Operation: | write | Name: | SrCreateRp (Enter) |
Value: 40000000000000000C82BBE71E0BD501480C00002C0C0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (3144) SDManager2_Setup.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
Operation: | write | Name: | SppCreate (Enter) |
Value: 40000000000000000C82BBE71E0BD501480C00002C0C0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (3144) SDManager2_Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
Operation: | write | Name: | LastIndex |
Value: 20 | |||
(PID) Process: | (3144) SDManager2_Setup.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 4000000000000000980803E81E0BD501480C00002C0C0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (3144) SDManager2_Setup.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000F26A05E81E0BD501480C0000D80B0000E803000001000000000000000000000037DD6990CDE9524295E50BD39CE8C31F0000000000000000 | |||
(PID) Process: | (1108) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000681B16E81E0BD5015404000084010000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (1108) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000681B16E81E0BD50154040000340C0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (1108) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000681B16E81E0BD50154040000000F0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (1108) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
Operation: | write | Name: | IDENTIFY (Enter) |
Value: 4000000000000000681B16E81E0BD50154040000FC030000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
(PID) Process: | (1108) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
Operation: | write | Name: | IDENTIFY (Leave) |
Value: 40000000000000002A0722E81E0BD50154040000000F0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3144 | SDManager2_Setup.exe | C:\Users\admin\AppData\Local\Temp\{D0ABD06D-9B92-4C72-965A-C0CE0ACEA9E8}\{69FC2104-E57B-4175-B91C-80929FDE1654}\set51DD.tmp | — | |
MD5:— | SHA256:— | |||
3144 | SDManager2_Setup.exe | C:\Users\admin\AppData\Local\Temp\{D0ABD06D-9B92-4C72-965A-C0CE0ACEA9E8}\{69FC2104-E57B-4175-B91C-80929FDE1654}\lic51EE.tmp | — | |
MD5:— | SHA256:— | |||
3144 | SDManager2_Setup.exe | C:\Users\admin\AppData\Local\Temp\{D0ABD06D-9B92-4C72-965A-C0CE0ACEA9E8}\{69FC2104-E57B-4175-B91C-80929FDE1654}\dpi51EF.tmp | — | |
MD5:— | SHA256:— | |||
3144 | SDManager2_Setup.exe | C:\Users\admin\AppData\Local\Temp\{D0ABD06D-9B92-4C72-965A-C0CE0ACEA9E8}\{69FC2104-E57B-4175-B91C-80929FDE1654}\dpi520F.tmp | — | |
MD5:— | SHA256:— | |||
3144 | SDManager2_Setup.exe | C:\Users\admin\AppData\Local\Temp\{D0ABD06D-9B92-4C72-965A-C0CE0ACEA9E8}\{69FC2104-E57B-4175-B91C-80929FDE1654}\EUL5220.tmp | — | |
MD5:— | SHA256:— | |||
3144 | SDManager2_Setup.exe | C:\Users\admin\AppData\Local\Temp\{D0ABD06D-9B92-4C72-965A-C0CE0ACEA9E8}\{69FC2104-E57B-4175-B91C-80929FDE1654}\EUL5221.tmp | — | |
MD5:— | SHA256:— | |||
3144 | SDManager2_Setup.exe | C:\Users\admin\AppData\Local\Temp\{D0ABD06D-9B92-4C72-965A-C0CE0ACEA9E8}\{69FC2104-E57B-4175-B91C-80929FDE1654}\Fon5222.tmp | — | |
MD5:— | SHA256:— | |||
3144 | SDManager2_Setup.exe | C:\Users\admin\AppData\Local\Temp\{D0ABD06D-9B92-4C72-965A-C0CE0ACEA9E8}\{69FC2104-E57B-4175-B91C-80929FDE1654}\DIF5232.tmp | — | |
MD5:— | SHA256:— | |||
3144 | SDManager2_Setup.exe | C:\Users\admin\AppData\Local\Temp\{F242A29C-673E-4020-915A-F3324B639CB0}\Disk1\setup.inx | binary | |
MD5:6EF4C3973A0A688A58DBDA791BA8759E | SHA256:FDBB178B5F3A21E8BB4B934E8475AD39BDEBA09F45678722BCDAC79E71D2D166 | |||
3144 | SDManager2_Setup.exe | C:\Users\admin\AppData\Local\Temp\{F242A29C-673E-4020-915A-F3324B639CB0}\Disk1\ISSetup.dll | executable | |
MD5:8A42A1E8F32AB18BFFFECD0553316C5C | SHA256:B522B6274D11AB9BB6CF878F7EF570B53369DF075BAC56C966A3870CE819180A |