| File name: | keepnote-0.7.8.exe |
| Full analysis: | https://app.any.run/tasks/ef23dd50-e28e-4b65-81d6-cf99c82c059c |
| Verdict: | Malicious activity |
| Analysis date: | October 21, 2023, 22:38:47 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | C7B70EF71EB35AEC6AA00FEE0168E152 |
| SHA1: | DB990907A061F96497CAE6B558A92FD229D322C5 |
| SHA256: | F39AAB387FF12C3E0C9DD0E641CF606FE0C2E1CE67D363AF2F4F593A543EFCE3 |
| SSDEEP: | 98304:5bkfLFJLI8dM1IICyvh2ePNEWkM5Oh9f6VWq5nZA3Ol/BbGz5CKm2IDDuUPHlbg2:VDhDigyhuxehj4IgDbp/ |
| .exe | | | Inno Setup installer (77.7) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (10) |
| .dll | | | Win32 Dynamic Link Library (generic) (4.6) |
| .exe | | | Win32 Executable (generic) (3.1) |
| .exe | | | Win16/32 Executable Delphi generic (1.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:20 00:22:17+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 37376 |
| InitializedDataSize: | 17408 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x9a58 |
| OSVersion: | 1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.7.8.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Matt Rasmussen |
| FileDescription: | KeepNote |
| FileVersion: | 0.7.8 |
| LegalCopyright: | |
| ProductName: | KeepNote |
| ProductVersion: | 0.7.8 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 592 | "C:\Users\admin\AppData\Local\Temp\is-KUD2L.tmp\keepnote-0.7.8.tmp" /SL5="$602FA,7746356,53248,C:\Users\admin\AppData\Local\Temp\keepnote-0.7.8.exe" | C:\Users\admin\AppData\Local\Temp\is-KUD2L.tmp\keepnote-0.7.8.tmp | — | keepnote-0.7.8.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.49.0.0 Modules
| |||||||||||||||
| 1796 | "C:\Users\admin\AppData\Local\Temp\keepnote-0.7.8.exe" | C:\Users\admin\AppData\Local\Temp\keepnote-0.7.8.exe | — | explorer.exe | |||||||||||
User: admin Company: Matt Rasmussen Integrity Level: MEDIUM Description: KeepNote Exit code: 0 Version: 0.7.8 Modules
| |||||||||||||||
| 2564 | "C:\Users\admin\AppData\Local\Temp\is-F3PH8.tmp\keepnote-0.7.8.tmp" /SL5="$150220,7746356,53248,C:\Users\admin\AppData\Local\Temp\keepnote-0.7.8.exe" /SPAWNWND=$5036C /NOTIFYWND=$602FA | C:\Users\admin\AppData\Local\Temp\is-F3PH8.tmp\keepnote-0.7.8.tmp | — | keepnote-0.7.8.exe | |||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.49.0.0 Modules
| |||||||||||||||
| 2568 | "C:\Users\admin\AppData\Local\Temp\keepnote-0.7.8.exe" /SPAWNWND=$5036C /NOTIFYWND=$602FA | C:\Users\admin\AppData\Local\Temp\keepnote-0.7.8.exe | keepnote-0.7.8.tmp | ||||||||||||
User: admin Company: Matt Rasmussen Integrity Level: HIGH Description: KeepNote Exit code: 0 Version: 0.7.8 Modules
| |||||||||||||||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2568 | keepnote-0.7.8.exe | C:\Users\admin\AppData\Local\Temp\is-F3PH8.tmp\keepnote-0.7.8.tmp | executable | |
MD5:52950AC9E2B481453082F096120E355A | SHA256:25FBC88C7C967266F041AE4D47C2EAE0B96086F9E440CCA10729103AEE7EF6CD | |||
| 2564 | keepnote-0.7.8.tmp | C:\Program Files\KeepNote\bz2.pyd | executable | |
MD5:544D2F7F849E0E99EB595891E5D44C76 | SHA256:50788BF4681D69977B5AE0A870D755F6BB715DBB45225872B7FC00DA1355BC13 | |||
| 2564 | keepnote-0.7.8.tmp | C:\Program Files\KeepNote\is-OEILO.tmp | executable | |
MD5:D7CBBEDFAD7AD68E12BF6FFCC01C3080 | SHA256:AA9EC502E20B927D236E19036B40A5DA5DDD4AE030553A6608F821BECD646EFB | |||
| 2564 | keepnote-0.7.8.tmp | C:\Program Files\KeepNote\atk.pyd | executable | |
MD5:1E17BCA68743BB834EA639099E9A4AAE | SHA256:52FB0B53FD43609098FFCEF31F0132763BEAAD367CCBBF0A1C991EE4C7DDA500 | |||
| 2564 | keepnote-0.7.8.tmp | C:\Program Files\KeepNote\intl.dll | executable | |
MD5:A283476338CF4CF8FB26CDC12E9D0044 | SHA256:B627D6F154DDA7421187A3A61059F95A0B5D46084478422B6A5F188363F900A7 | |||
| 2564 | keepnote-0.7.8.tmp | C:\Program Files\KeepNote\glade.pyd | executable | |
MD5:2FA2DD5B0BFD915DDD2BBFC108C4DA9B | SHA256:3346E06BB986B717AF9E354EB98F1B551FD7CA370F021837F2FD22FFD344583D | |||
| 2564 | keepnote-0.7.8.tmp | C:\Program Files\KeepNote\is-7B2UT.tmp | executable | |
MD5:A283476338CF4CF8FB26CDC12E9D0044 | SHA256:B627D6F154DDA7421187A3A61059F95A0B5D46084478422B6A5F188363F900A7 | |||
| 2564 | keepnote-0.7.8.tmp | C:\Users\admin\AppData\Local\Temp\is-8D9VK.tmp\_isetup\_shfoldr.dll | executable | |
MD5:92DC6EF532FBB4A5C3201469A5B5EB63 | SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87 | |||
| 2564 | keepnote-0.7.8.tmp | C:\Program Files\KeepNote\is-SGB2B.tmp | executable | |
MD5:544D2F7F849E0E99EB595891E5D44C76 | SHA256:50788BF4681D69977B5AE0A870D755F6BB715DBB45225872B7FC00DA1355BC13 | |||
| 2564 | keepnote-0.7.8.tmp | C:\Program Files\KeepNote\is-LCDCC.tmp | executable | |
MD5:1E17BCA68743BB834EA639099E9A4AAE | SHA256:52FB0B53FD43609098FFCEF31F0132763BEAAD367CCBBF0A1C991EE4C7DDA500 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |