| File name: | iShareaza_2.7.10.5_Win32_Release_2023-09-23.exe |
| Full analysis: | https://app.any.run/tasks/ec60d38c-e525-45e1-94a6-682b3e8c85f7 |
| Verdict: | Malicious activity |
| Analysis date: | December 09, 2023, 02:05:39 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | D10D03828537829CAE7C312054346648 |
| SHA1: | 54DD4A475FC96C75A7D46F1D307B6F5B090A5A66 |
| SHA256: | F06AB830ABB2F0AE9BCC705593D11D6EDB4E5708F13820AD7620E187DC3ADCB6 |
| SSDEEP: | 98304:d+cD4dno/J6YqhY1GAVeHpjDJr8KK3cREeMNSN3ztshLXxV2FMEqEiU+5w/Jess6:f/LYy5D4CkAB73wVD |
| .exe | | | Inno Setup installer (65.1) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (24.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (3.9) |
| .exe | | | Win32 Executable (generic) (2.6) |
| .exe | | | Win16/32 Executable Delphi generic (1.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2023:02:15 15:54:16+01:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741888 |
| InitializedDataSize: | 56320 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.7.10.5 |
| ProductVersionNumber: | 2.7.10.5 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Shareaza Development Team |
| FileDescription: | Shareaza Ultimate File Sharing |
| FileVersion: | 2.7.10.5 |
| LegalCopyright: | Copyright � Shareaza Development Team. All rights reserved. |
| OriginalFileName: | |
| ProductName: | Shareaza |
| ProductVersion: | 2.7.10.5 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 240 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Shareaza\ImageViewer.dll" | C:\Windows\System32\regsvr32.exe | — | iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 644 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Shareaza\RazaWebHook64.dll" | C:\Windows\System32\regsvr32.exe | — | iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 3 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1004 | "C:\Program Files\Shareaza\Shareaza.exe" | C:\Program Files\Shareaza\Shareaza.exe | iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp | ||||||||||||
User: admin Company: Shareaza Development Team Integrity Level: MEDIUM Description: Shareaza Ultimate File Sharing Exit code: 0 Version: 2.7.10.5 Modules
| |||||||||||||||
| 1276 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Shareaza\RARBuilder.dll" | C:\Windows\System32\regsvr32.exe | — | iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1328 | "C:\Users\admin\Downloads\iShareaza_2.7.10.5_Win32_Release_2023-09-23.exe" /SPAWNWND=$1B0142 /NOTIFYWND=$1301B8 | C:\Users\admin\Downloads\iShareaza_2.7.10.5_Win32_Release_2023-09-23.exe | iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp | ||||||||||||
User: admin Company: Shareaza Development Team Integrity Level: HIGH Description: Shareaza Ultimate File Sharing Exit code: 0 Version: 2.7.10.5 Modules
| |||||||||||||||
| 1360 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1696 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Shareaza\RatDVDReader.dll" | C:\Windows\System32\regsvr32.exe | — | iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1844 | "C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\Shareaza\GFLImageServices.dll" | C:\Windows\System32\regsvr32.exe | — | iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1864 | "C:\Users\admin\Downloads\iShareaza_2.7.10.5_Win32_Release_2023-09-23.exe" | C:\Users\admin\Downloads\iShareaza_2.7.10.5_Win32_Release_2023-09-23.exe | — | explorer.exe | |||||||||||
User: admin Company: Shareaza Development Team Integrity Level: MEDIUM Description: Shareaza Ultimate File Sharing Exit code: 0 Version: 2.7.10.5 Modules
| |||||||||||||||
| 1868 | "C:\Program Files\Shareaza\MediaLibraryBuilder.exe" /RegServerPerUser | C:\Program Files\Shareaza\MediaLibraryBuilder.exe | — | Shareaza.exe | |||||||||||
User: admin Company: Shareaza Development Team Integrity Level: MEDIUM Description: Media Library Builder Plugin Exit code: 0 Version: 1.1.0.1 Modules
| |||||||||||||||
| (PID) Process: | (1844) regsvr32.exe | Key: | HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Plugins\ImageService |
| Operation: | write | Name: | .sti |
Value: {E9F51B1E-DB0F-4EEE-9B36-46151994C715} | |||
| (PID) Process: | (2996) regsvr32.exe | Key: | HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Plugins\LibraryBuilder |
| Operation: | write | Name: | .sti |
Value: {E9F51B1E-DB0F-4EEE-9B36-46151994C715} | |||
| (PID) Process: | (2728) Shareaza.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\Shareaza.exe |
| Operation: | write | Name: | FriendlyAppName |
Value: Shareaza | |||
| (PID) Process: | (2728) Shareaza.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Applications\Shareaza.exe\shell\open\ddeexec |
| Operation: | write | Name: | WindowClassName |
Value: ShareazaMainWnd | |||
| (PID) Process: | (2728) Shareaza.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Shareaza.Collection\shell\open\ddeexec |
| Operation: | write | Name: | WindowClassName |
Value: ShareazaMainWnd | |||
| (PID) Process: | (2728) Shareaza.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Shareaza.Collection |
| Operation: | write | Name: | EditFlags |
Value: 65536 | |||
| (PID) Process: | (2728) Shareaza.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Shareaza.Collection |
| Operation: | write | Name: | AppUserModelID |
Value: Shareaza | |||
| (PID) Process: | (2544) iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | GlobalAssocChangedCounter |
Value: 115 | |||
| (PID) Process: | (1004) Shareaza.exe | Key: | HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Plugins\LibraryBuilder |
| Operation: | write | Name: | .7z |
Value: {B69F80CD-FB15-45E8-B359-92A41CC571A7} | |||
| (PID) Process: | (1004) Shareaza.exe | Key: | HKEY_CURRENT_USER\Software\Shareaza\Shareaza\Plugins\LibraryBuilder |
| Operation: | write | Name: | .cb7 |
Value: {B69F80CD-FB15-45E8-B359-92A41CC571A7} | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1864 | iShareaza_2.7.10.5_Win32_Release_2023-09-23.exe | C:\Users\admin\AppData\Local\Temp\is-UQENE.tmp\iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp | executable | |
MD5:36D3386F631A5A36CC2563E2C6A6F817 | SHA256:B9EA74EC1862F532A3C8231895D85549A1FD94FB1DB55E85519A96446B9E57F6 | |||
| 2544 | iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp | C:\Program Files\Shareaza\is-OEHBE.tmp | executable | |
MD5:AEE75271856C9C42F75D950FD8455C33 | SHA256:A66DAB2D51C4952024B7C2974ACBF3367D3BCEA0489EB1AE8EB41923157AFD5A | |||
| 2544 | iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp | C:\Program Files\Shareaza\Uninstall\is-QA39D.tmp | executable | |
MD5:584D9F48138F97A44495AC31B46F92DA | SHA256:A3F66D8F9C2AFD5233E376C20DF0C809FDD469078125525E5E775F82004D52B9 | |||
| 2544 | iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp | C:\Users\admin\AppData\Local\Temp\is-P9QMR.tmp\idp.dll | executable | |
MD5:55C310C0319260D798757557AB3BF636 | SHA256:54E7E0AD32A22B775131A6288F083ED3286A9A436941377FC20F85DD9AD983ED | |||
| 2544 | iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp | C:\Program Files\Shareaza\Skin.exe | executable | |
MD5:2331633B8BB4196B7C8054E6E27C47C6 | SHA256:21D16A63A59B20B679673FB14A500D9961217A051174F2637F085D0E2E07498F | |||
| 1328 | iShareaza_2.7.10.5_Win32_Release_2023-09-23.exe | C:\Users\admin\AppData\Local\Temp\is-V49QD.tmp\iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp | executable | |
MD5:36D3386F631A5A36CC2563E2C6A6F817 | SHA256:B9EA74EC1862F532A3C8231895D85549A1FD94FB1DB55E85519A96446B9E57F6 | |||
| 2544 | iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp | C:\Program Files\Shareaza\is-C76IR.tmp | executable | |
MD5:DBA1404EC119616A4995C197C1244C3F | SHA256:6D43B3CF0AFE3A9D98FFFE05B71F5971B762896D797C59196A7E4D25C744C478 | |||
| 2544 | iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp | C:\Program Files\Shareaza\Uninstall\unins000.exe | executable | |
MD5:584D9F48138F97A44495AC31B46F92DA | SHA256:A3F66D8F9C2AFD5233E376C20DF0C809FDD469078125525E5E775F82004D52B9 | |||
| 2544 | iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp | C:\Program Files\Shareaza\TorrentWizard.exe | executable | |
MD5:7B2E65D91AA5E9B5855C3C2C3284B093 | SHA256:0DC3640D0F29507A512F21579267E08CB2B795CB712DD2B29D0DCF8A406CF3E8 | |||
| 2544 | iShareaza_2.7.10.5_Win32_Release_2023-09-23.tmp | C:\Program Files\Shareaza\Shareaza.exe | executable | |
MD5:AEE75271856C9C42F75D950FD8455C33 | SHA256:A66DAB2D51C4952024B7C2974ACBF3367D3BCEA0489EB1AE8EB41923157AFD5A | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1004 | Shareaza.exe | GET | 200 | 172.67.130.169:80 | http://upd.emule-security.org/server.met | unknown | binary | 2.19 Kb | unknown |
1004 | Shareaza.exe | GET | 410 | 3.64.163.50:80 | http://gwc.centrump2p.com/skulls.php?get=1&hostfile=1&net=gnutella&client=RAZI&version=2.7.10.5&getleaves=1&getnetworks=1&getclusters=0&getvendors=1&getuptime=1 | unknown | html | 140 b | unknown |
1004 | Shareaza.exe | GET | 200 | 149.28.163.175:3558 | http://au.gnutella.dyslexicfish.net:3558/?get=1&hostfile=1&net=gnutella&client=RAZI&version=2.7.10.5&getleaves=1&getnetworks=1&getclusters=0&getvendors=1&getuptime=1 | unknown | text | 433 b | unknown |
1004 | Shareaza.exe | GET | 200 | 69.163.178.11:80 | http://dkac.trillinux.org/dkac/dkac.php?get=1&hostfile=1&net=gnutella2&ping=1&pv=4&client=RAZI2.7.10.5&getleaves=1&getnetworks=1&getclusters=0&getvendors=1&getuptime=1 | unknown | text | 1.35 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
868 | svchost.exe | 23.35.228.137:80 | armmf.adobe.com | AKAMAI-AS | DE | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1004 | Shareaza.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1004 | Shareaza.exe | 172.67.130.169:80 | upd.emule-security.org | CLOUDFLARENET | US | unknown |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1004 | Shareaza.exe | 67.215.246.10:6881 | router.bittorrent.com | — | — | unknown |
1004 | Shareaza.exe | 116.14.134.29:8691 | — | — | — | unknown |
1004 | Shareaza.exe | 34.229.89.117:6881 | dht.aelitis.com | — | — | unknown |
1004 | Shareaza.exe | 154.199.0.61:6881 | — | — | — | unknown |
Domain | IP | Reputation |
|---|---|---|
armmf.adobe.com |
| whitelisted |
uk.gnutella.dyslexicfish.net |
| unknown |
upd.emule-security.org |
| unknown |
router.bittorrent.com |
| shared |
router.utorrent.com |
| whitelisted |
dht.transmissionbt.com |
| unknown |
dht.aelitis.com |
| malicious |
ping.pongwar.com |
| unknown |
cache.ce3c.be |
| unknown |
dkac.trillinux.org |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
1004 | Shareaza.exe | Potential Corporate Privacy Violation | ET P2P BitTorrent DHT ping request |
1004 | Shareaza.exe | Potential Corporate Privacy Violation | ET P2P eDonkey Server Status Request |
1004 | Shareaza.exe | Potential Corporate Privacy Violation | ET P2P eDonkey Server Status Request |
1004 | Shareaza.exe | Potential Corporate Privacy Violation | ET P2P Gnutella Connect |
1004 | Shareaza.exe | Potential Corporate Privacy Violation | GPL P2P GNUTella client request |
1004 | Shareaza.exe | Potential Corporate Privacy Violation | GPL P2P GNUTella client request |
1004 | Shareaza.exe | Potential Corporate Privacy Violation | ET P2P Gnutella Connect |
1004 | Shareaza.exe | Potential Corporate Privacy Violation | GPL P2P GNUTella client request |
1004 | Shareaza.exe | Potential Corporate Privacy Violation | ET P2P Gnutella Connect |
1004 | Shareaza.exe | Potential Corporate Privacy Violation | GPL P2P GNUTella client request |