analyze malware
  • Huge database of samples and IOCs
  • Custom VM setup
  • Unlimited submissions
  • Interactive approach
Sign up, it’s free
File name:

Norton Trial Resetter.exe

Full analysis: https://app.any.run/tasks/935eda90-d113-49a3-8f81-466aaf214f04
Verdict: Malicious activity
Analysis date: June 27, 2022, 10:20:42
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

165D1A82C46A493CEDE4E658E421D6DF

SHA1:

C59DE7C57311249E669759D7209D45AF35BDE5C1

SHA256:

E8089454234D6DA6123D3D326F2C08E95E970D75E231CED9F354E8118FCB8477

SSDEEP:

1536:jQ+lSFUQQi/vPCqiZB2owhpKqB6kicWbjTHbgBNX0YTHkflYT3NUvS3rPnFjdw/3:s+lSRC9Z/eYjTHbgFMlYj4or/vCi7mP

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops executable file immediately after starts

      • Norton Trial Resetter.exe (PID: 3420)
    • Loads dropped or rewritten executable

      • Norton Trial Resetter.exe (PID: 3420)
  • SUSPICIOUS

    • Reads the computer name

      • Norton Trial Resetter.exe (PID: 3420)
    • Checks supported languages

      • Norton Trial Resetter.exe (PID: 3420)
      • cmd.exe (PID: 2104)
    • Drops a file with a compile date too recent

      • Norton Trial Resetter.exe (PID: 3420)
    • Reads the Windows organization settings

      • Norton Trial Resetter.exe (PID: 3420)
    • Reads Windows owner or organization settings

      • Norton Trial Resetter.exe (PID: 3420)
    • Creates a directory in Program Files

      • Norton Trial Resetter.exe (PID: 3420)
    • Creates files in the program directory

      • Norton Trial Resetter.exe (PID: 3420)
    • Creates files in the user directory

      • Norton Trial Resetter.exe (PID: 3420)
    • Executable content was dropped or overwritten

      • Norton Trial Resetter.exe (PID: 3420)
    • Starts CMD.EXE for commands execution

      • Norton Trial Resetter.exe (PID: 3420)
    • Creates a software uninstall entry

      • Norton Trial Resetter.exe (PID: 3420)
  • INFO

    • Reads the computer name

      • explorer.exe (PID: 2992)
    • Checks supported languages

      • explorer.exe (PID: 2992)
    • Manual execution by user

      • explorer.exe (PID: 2992)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.dll | Win32 Dynamic Link Library (generic) (43.5)
.exe | Win32 Executable (generic) (29.8)
.exe | Generic Win/DOS Executable (13.2)
.exe | DOS Executable Generic (13.2)

EXIF

EXE

Subsystem: Windows GUI
SubsystemVersion: 4
ImageVersion: -
OSVersion: 4
EntryPoint: 0x1d20
UninitializedDataSize: -
InitializedDataSize: 110592
CodeSize: 4096
LinkerVersion: 6
PEType: PE32
TimeStamp: 2011:01:31 18:44:13+01:00
MachineType: Intel 386 or later, and compatibles

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 31-Jan-2011 17:44:13
Detected languages:
  • English - United States

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000D8

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 31-Jan-2011 17:44:13
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x00000EAC
0x00001000
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
5.942
.rdata
0x00002000
0x00000488
0x00001000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
1.73331
.data
0x00003000
0x00000560
0x00001000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
1.01054
.gentee
0x00004000
0x00012C16
0x00013000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.98097
.rsrc
0x00017000
0x00005F0C
0x00006000
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
7.36115

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.07499
1914
Latin 1 / Western European
English - United States
RT_MANIFEST
1000
2.23119
54
Latin 1 / Western European
English - United States
RT_DIALOG
IDD_DLGFIN2
2.59268
472
Latin 1 / Western European
English - United States
RT_DIALOG
IDD_DLGPATH
2.68908
544
Latin 1 / Western European
English - United States
RT_DIALOG
IDD_DLGPROG
2.78207
600
Latin 1 / Western European
English - United States
RT_DIALOG
IDD_DLGUCONF2
2.49586
344
Latin 1 / Western European
English - United States
RT_DIALOG
IDD_DLGUFIN2
2.57386
440
Latin 1 / Western European
UNKNOWN
RT_DIALOG
IDD_DLGUNDEL
2.66424
408
Latin 1 / Western European
UNKNOWN
RT_DIALOG
IDD_DLGUPROG
2.68145
408
Latin 1 / Western European
UNKNOWN
RT_DIALOG
IDD_DLGWEL2
2.49586
344
Latin 1 / Western European
English - United States
RT_DIALOG

Imports

KERNEL32.dll
MSVCRT.dll
USER32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
43
Monitored processes
4
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start norton trial resetter.exe no specs norton trial resetter.exe cmd.exe no specs explorer.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2616"C:\Users\admin\AppData\Local\Temp\Norton Trial Resetter.exe" C:\Users\admin\AppData\Local\Temp\Norton Trial Resetter.exeExplorer.EXE
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
3420"C:\Users\admin\AppData\Local\Temp\Norton Trial Resetter.exe" C:\Users\admin\AppData\Local\Temp\Norton Trial Resetter.exe
Explorer.EXE
User:
admin
Integrity Level:
HIGH
Exit code:
0
2104cmd.exe /c deldll.batC:\Windows\system32\cmd.exeNorton Trial Resetter.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
1
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
2992"C:\Windows\explorer.exe" C:\Windows\explorer.exeExplorer.EXE
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
1
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Total events
573
Read events
566
Write events
6
Delete events
1

Modification events

(PID) Process:(3420) Norton Trial Resetter.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\tmp
Operation:delete keyName:(default)
Value:
(PID) Process:(3420) Norton Trial Resetter.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Norton Trial Resetter
Operation:writeName:UninstallString
Value:
C:\Program Files\Norton Trial Resetter\uninstall.exe
(PID) Process:(3420) Norton Trial Resetter.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Norton Trial Resetter
Operation:writeName:DisplayName
Value:
Norton Trial Resetter
(PID) Process:(3420) Norton Trial Resetter.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Norton Trial Resetter
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Norton Trial Resetter\uninstall.exe
(PID) Process:(3420) Norton Trial Resetter.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Norton Trial Resetter
Operation:writeName:InstallLocation
Value:
C:\Program Files\Norton Trial Resetter
(PID) Process:(3420) Norton Trial Resetter.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Norton Trial Resetter
Operation:writeName:NoModify
Value:
1
(PID) Process:(3420) Norton Trial Resetter.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Norton Trial Resetter
Operation:writeName:NoRepair
Value:
1
Executable files
3
Suspicious files
1
Text files
4
Unknown types
2

Dropped files

PID
Process
Filename
Type
3420Norton Trial Resetter.exeC:\Users\admin\AppData\Local\Temp\gentee3A\setup_temp.geabs
MD5:BD268F92B54BABCB42ECF09E140793DA
SHA256:A5B2B927BB4107DEA5ED9B247699A0EE1D41BE5327AE2581D133692F4FDD6801
3420Norton Trial Resetter.exeC:\Program Files\Norton Trial Resetter\uninstall.exeexecutable
MD5:1C00ADD50C2EDAA4DDCAE38F667F029D
SHA256:F93EBCA84915101A8F659C758C20DA0BED6359DA519AD282B9E7682C0D9D691A
3420Norton Trial Resetter.exeC:\Users\admin\AppData\Local\Temp\~DF0CA52FD012D22D18.TMPbinary
MD5:CE9D92B5ED9B4DADD3F22759EEC47381
SHA256:16D039E360113DB96710F16DF0726FC3F1FEBBD4B83314D067C066DC162588E9
3420Norton Trial Resetter.exeC:\Users\admin\AppData\Local\Temp\gentee3A\4default - 2.bmpimage
MD5:5CDF0741BEAD2AFDC7F381D82D43A1B3
SHA256:7294B02EEBBE31D7A01026883FA8A95D94F47AB408F611E9E4A7421BEF2673C8
3420Norton Trial Resetter.exeC:\Users\admin\AppData\Local\Temp\deldll.battext
MD5:EA190EF9B139757A890CD48BDD44B0EE
SHA256:9131DE0FCAAF968896AF9D58B6F37B4AA443455BB97C97BC142F295CEE577BC4
3420Norton Trial Resetter.exeC:\Users\admin\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\Norton Trial Resetter\Uninstall.lnklnk
MD5:661D26CAD97C42D4CB2E269972E610E7
SHA256:66A436C0D4A1F7A1158A7F91EEB77C905E493B47AF53580BE0962AA1EFC34B15
3420Norton Trial Resetter.exeC:\Program Files\Norton Trial Resetter\uninstall.initext
MD5:E14E370422537F74E4BE6CFC385775A7
SHA256:D98848F0E37525D5A6F1335D5F58F3AE89B45984B69B7EFAC0EEC56D10CC07E7
3420Norton Trial Resetter.exeC:\Users\admin\AppData\Local\Temp\genteert.dllexecutable
MD5:6CE814FD1AD7AE07A9E462C26B3A0F69
SHA256:54C0DA1735BB1CB02B60C321DE938488345F8D1D26BF389C8CB2ACAD5D01B831
3420Norton Trial Resetter.exeC:\Users\admin\AppData\Local\Temp\gentee3A\2install - 1.bmpimage
MD5:E168634D6C44995C14608F16C2E28693
SHA256:06263008AB7AB756D1254CE744B389F71B0DFFB186EBFA8BB0D2603271E9C6DA
3420Norton Trial Resetter.exeC:\Users\admin\AppData\Local\Temp\gentee3A\guig.dllexecutable
MD5:D3F8C0334C19198A109E44D074DAC5FD
SHA256:005C251C21D6A5BA1C3281E7B9F3B4F684D007E0C3486B34A545BB370D8420AA
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
0
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

No data

DNS requests

No data

Threats

No threats detected
No debug info