| File name: | s3browser-11-5-7.exe |
| Full analysis: | https://app.any.run/tasks/5cb76730-fb54-439b-99a7-2cbd2ce75b4e |
| Verdict: | Malicious activity |
| Analysis date: | February 14, 2024, 12:59:39 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 8FA72046C580279257B607BB2826804E |
| SHA1: | 5DC9437DF1661055518F8FA1BC952FAD7083C844 |
| SHA256: | F81C51F37F3F0F7B8AA904A8F94A555E65B77DF921DFBFEC8DA43B462F88F4E6 |
| SSDEEP: | 98304:1+QqZ8f1TAhUYrXVGeHkm3bv54GepGhiFGZ3sOvWERyvzGB8VyKigqcI+lVjgQ7e:FhpXvEP9Cz4hMs1+6l7 |
| .exe | | | Inno Setup installer (53.5) |
|---|---|---|
| .exe | | | InstallShield setup (21) |
| .exe | | | Win32 EXE PECompact compressed (generic) (20.2) |
| .exe | | | Win32 Executable (generic) (2.1) |
| .exe | | | Win16/32 Executable Delphi generic (1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2021:06:03 08:09:11+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741376 |
| InitializedDataSize: | 89088 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6.1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 11.5.7.0 |
| ProductVersionNumber: | 11.5.7.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Netsdk Software FZE |
| FileDescription: | S3 Browser version 11.5.7 |
| FileVersion: | 11.5.7 |
| LegalCopyright: | Copyright © 2008-2024 Netsdk Software FZE |
| OriginalFileName: | |
| ProductName: | S3 Browser |
| ProductVersion: | 11.5.7 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2332 | "C:\Users\admin\AppData\Local\Temp\is-6I6JF.tmp\s3browser-cli.exe" /license o C:\Users\admin\AppData\Local\Temp\is-6I6JF.tmp\Xf7eae1c5435f4405a0cea8cf7f79d058 | C:\Users\admin\AppData\Local\Temp\is-6I6JF.tmp\s3browser-cli.exe | — | s3browser-11-5-7.tmp | |||||||||||
User: admin Company: Netsdk Software FZE Integrity Level: HIGH Description: S3 Browser Command Line Interface Exit code: 0 Version: 11.5.7 Modules
| |||||||||||||||
| 2472 | "C:\Users\admin\Downloads\s3browser-11-5-7.exe" | C:\Users\admin\Downloads\s3browser-11-5-7.exe | explorer.exe | ||||||||||||
User: admin Company: Netsdk Software FZE Integrity Level: MEDIUM Description: S3 Browser version 11.5.7 Exit code: 0 Version: 11.5.7 Modules
| |||||||||||||||
| 2896 | "C:\Program Files\S3 Browser\s3browser-win32.exe" | C:\Program Files\S3 Browser\s3browser-win32.exe | — | explorer.exe | |||||||||||
User: admin Company: Netsdk Software FZE Integrity Level: MEDIUM Description: S3 Browser - User Interface for Amazon S3 Service Exit code: 0 Version: 11.5.7 Modules
| |||||||||||||||
| 3392 | "C:\Program Files\S3 Browser\s3browser-win32.exe" | C:\Program Files\S3 Browser\s3browser-win32.exe | — | s3browser-11-5-7.tmp | |||||||||||
User: admin Company: Netsdk Software FZE Integrity Level: MEDIUM Description: S3 Browser - User Interface for Amazon S3 Service Exit code: 0 Version: 11.5.7 Modules
| |||||||||||||||
| 3700 | "C:\Users\admin\AppData\Local\Temp\is-LPHHV.tmp\s3browser-11-5-7.tmp" /SL5="$E0170,9165163,831488,C:\Users\admin\Downloads\s3browser-11-5-7.exe" | C:\Users\admin\AppData\Local\Temp\is-LPHHV.tmp\s3browser-11-5-7.tmp | — | s3browser-11-5-7.exe | |||||||||||
User: admin Company: Netsdk Software FZE Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 3848 | "C:\Users\admin\Downloads\s3browser-11-5-7.exe" /SPAWNWND=$17013E /NOTIFYWND=$E0170 | C:\Users\admin\Downloads\s3browser-11-5-7.exe | s3browser-11-5-7.tmp | ||||||||||||
User: admin Company: Netsdk Software FZE Integrity Level: HIGH Description: S3 Browser version 11.5.7 Exit code: 0 Version: 11.5.7 Modules
| |||||||||||||||
| 3948 | "C:\Users\admin\AppData\Local\Temp\is-28J4F.tmp\s3browser-11-5-7.tmp" /SL5="$100130,9165163,831488,C:\Users\admin\Downloads\s3browser-11-5-7.exe" /SPAWNWND=$17013E /NOTIFYWND=$E0170 | C:\Users\admin\AppData\Local\Temp\is-28J4F.tmp\s3browser-11-5-7.tmp | s3browser-11-5-7.exe | ||||||||||||
User: admin Company: Netsdk Software FZE Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 4008 | "C:\Windows\explorer.exe" | C:\Windows\explorer.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Explorer Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (3948) s3browser-11-5-7.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 6C0F00005E9009B4455FDA01 | |||
| (PID) Process: | (3948) s3browser-11-5-7.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: A9BDE9E938B566223EB3130CF10D118CF7787F552E71EF567700888A35FB3C4D | |||
| (PID) Process: | (3948) s3browser-11-5-7.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (3948) s3browser-11-5-7.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Program Files\S3 Browser\s3browser-win32.exe | |||
| (PID) Process: | (3948) s3browser-11-5-7.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFilesHash |
Value: 7ED80E5DCFA0E01D420D543B2A36D88453536DCC7E7E9B9091769E35801B482B | |||
| (PID) Process: | (3948) s3browser-11-5-7.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S3 Browser_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 6.2.0 | |||
| (PID) Process: | (3948) s3browser-11-5-7.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S3 Browser_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files\S3 Browser | |||
| (PID) Process: | (3948) s3browser-11-5-7.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S3 Browser_is1 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\S3 Browser\ | |||
| (PID) Process: | (3948) s3browser-11-5-7.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S3 Browser_is1 |
| Operation: | write | Name: | Inno Setup: Icon Group |
Value: S3 Browser | |||
| (PID) Process: | (3948) s3browser-11-5-7.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\S3 Browser_is1 |
| Operation: | write | Name: | Inno Setup: User |
Value: admin | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2472 | s3browser-11-5-7.exe | C:\Users\admin\AppData\Local\Temp\is-LPHHV.tmp\s3browser-11-5-7.tmp | executable | |
MD5:C9D54D4DED3D395F6F5530EA567A9F77 | SHA256:40E79285F90AE7A8DEF88FBA6D8DAC114A3779312F8FEC9982DB12A243405EAB | |||
| 3948 | s3browser-11-5-7.tmp | C:\Program Files\S3 Browser\is-2UNDF.tmp | executable | |
MD5:8DB0DEEFB5F229D2CAE3D3F50DAE3A09 | SHA256:B244DD73285D7FCB80AF772C8EF3BDC1EE96833A751EAEF43FFB775757DF73C3 | |||
| 3948 | s3browser-11-5-7.tmp | C:\Program Files\S3 Browser\unins000.exe | executable | |
MD5:8DB0DEEFB5F229D2CAE3D3F50DAE3A09 | SHA256:B244DD73285D7FCB80AF772C8EF3BDC1EE96833A751EAEF43FFB775757DF73C3 | |||
| 3948 | s3browser-11-5-7.tmp | C:\Users\admin\AppData\Local\Temp\is-6I6JF.tmp\BouncyCastle.Crypto.dll | executable | |
MD5:B25DAA8EFC39E339925ECB3219DE6922 | SHA256:994D789C57B167249C131890355A951A9706D9283E149C66149B562548074B1C | |||
| 3948 | s3browser-11-5-7.tmp | C:\Users\admin\AppData\Local\Temp\is-6I6JF.tmp\s3browser-cli.exe | executable | |
MD5:B712D1BAF2D1C6837C0203FF03A70322 | SHA256:E2E53825F531A35305B1B3B6A8717523DD0D49BB0A10BB12BACD3291CA821623 | |||
| 3848 | s3browser-11-5-7.exe | C:\Users\admin\AppData\Local\Temp\is-28J4F.tmp\s3browser-11-5-7.tmp | executable | |
MD5:C9D54D4DED3D395F6F5530EA567A9F77 | SHA256:40E79285F90AE7A8DEF88FBA6D8DAC114A3779312F8FEC9982DB12A243405EAB | |||
| 3948 | s3browser-11-5-7.tmp | C:\Program Files\S3 Browser\is-QQNFN.tmp | executable | |
MD5:B712D1BAF2D1C6837C0203FF03A70322 | SHA256:E2E53825F531A35305B1B3B6A8717523DD0D49BB0A10BB12BACD3291CA821623 | |||
| 3948 | s3browser-11-5-7.tmp | C:\Program Files\S3 Browser\is-10H8Q.tmp | executable | |
MD5:590E5AFE220A0C3026F74D3755FA02D0 | SHA256:AF5B1FB39057401C23777A5A93EB262DD3202322A4B33C39AAEBBBCBA4E19258 | |||
| 3948 | s3browser-11-5-7.tmp | C:\Program Files\S3 Browser\s3browser-win32.exe | executable | |
MD5:590E5AFE220A0C3026F74D3755FA02D0 | SHA256:AF5B1FB39057401C23777A5A93EB262DD3202322A4B33C39AAEBBBCBA4E19258 | |||
| 3948 | s3browser-11-5-7.tmp | C:\Program Files\S3 Browser\s3browser-cli.exe | executable | |
MD5:B712D1BAF2D1C6837C0203FF03A70322 | SHA256:E2E53825F531A35305B1B3B6A8717523DD0D49BB0A10BB12BACD3291CA821623 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |