|
Analyzing...
|
File Name:   PUA_Patcher.BE55BE03ED4ED22E4AF0A4AA1B443E952B80E83D.exe
SHA1:   be55be03ed4ed22e4af0a4aa1b443e952b80e83d
MD5:   b1737e8d53a13d4b53426a042881f57c
First Seen Date:  2017-06-05 02:02:49.823782 ( )
Number of Clients Seen:   1
Last Analysis Date:  2017-06-05 02:02:49.823782 ( )
Human Expert Analysis Date:  2017-06-05 08:06:28.396709 ( )Human Expert Analysis Result:   Clean
Analysis Summary
| Analysis Type | Date | Verdict | |
|---|---|---|---|
| Signature Based Detection | 2017-06-05 02:02:49.823782 | Clean | |
| Static Analysis Overall Verdict | 2017-06-05 02:02:49.823782 | No Threat Found | help |
| Dynamic Analysis Overall Verdict | 2017-06-05 02:02:49.823782 | No Threat Found | help |
| Precise Detectors Overall Verdict | 2017-06-05 02:02:49.823782 | No Match | help |
| Human Expert Analysis Overall Verdict | 2017-06-05 08:06:28.396709 | Clean | |
Static Analysis
| Static Analysis Overall Verdict | Result |
|---|---|
| No Threat Found | help |
| Detector | Result | |
|---|---|---|
| Optional Header LoaderFlags field is valued illegal | Clean | |
| Non-ascii or empty section names detected | Clean | |
| Illegal size of optional Header | Clean | |
| Packer detection on signature database | Unknown | help |
| Based on the sections entropy check! file is possibly packed | Clean | |
| Timestamp value suspicious | Suspicious | |
| Header Checksum is zero! | Clean | |
| Enrty point is outside the 1st(.code) section! Binary is possibly packed | Clean | |
| Optional Header NumberOfRvaAndSizes field is valued illegal | Clean | |
| Anti-vm present | Clean | |
| The Size Of Raw data is valued illegal! Binary might crash your disassembler/debugger | Clean | |
| TLS callback functions array detected | Clean | |
Packer detection on signature database
BobSoft Mini Delphi -> BoB / BobSoft
Dynamic Analysis
| Dynamic Analysis Overall Verdict | Result |
|---|---|
| No Threat Found | help |
| Suspicious Behaviors | |
|---|---|
| Creates a child process | |
| Writes to address space of another process | |
| Reads memory of another process | |
| Opens a file in a system directory | |
| Has no visible windows | |
Behavioral Information
{"lDistanceToMove": "98", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "1b0"}
{"lDistanceToMove": "9d400", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "dc"}
{"lDistanceToMove": "ffffffdc", "dwMoveMethod": "2", "lpDistanceToMoveHigh": "0", "hFile": "dc"}
{"lDistanceToMove": "9ea93", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "1a4"}
{"lDistanceToMove": "aa", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "1b0"}
{"lDistanceToMove": "2c", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "1b0"}
{"lDistanceToMove": "0", "dwMoveMethod": "1", "lpDistanceToMoveHigh": "0", "hFile": "1a4"}
{"lDistanceToMove": "0", "dwMoveMethod": "1", "lpDistanceToMoveHigh": "0", "hFile": "ffffffff"}
{"lDistanceToMove": "e0", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "1b8"}
{"lDistanceToMove": "0", "dwMoveMethod": "1", "lpDistanceToMoveHigh": "0", "hFile": "1b0"}
{"lDistanceToMove": "bc", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "1b0"}
{"lDistanceToMove": "ffffc7c8", "dwMoveMethod": "2", "lpDistanceToMoveHigh": "0", "hFile": "27c"}
{"lDistanceToMove": "24", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "1b8"}
{"lDistanceToMove": "9ea73", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "dc"}
{"lDistanceToMove": "ce", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "1b0"}
{"lDistanceToMove": "50", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "1b0"}
{"lDistanceToMove": "86", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "1b0"}
{"lDistanceToMove": "62", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "1b0"}
{"lDistanceToMove": "0", "dwMoveMethod": "1", "lpDistanceToMoveHigh": "0", "hFile": "d8"}
{"lDistanceToMove": "74", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "1b0"}
{"lDistanceToMove": "3e", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "1b0"}
{"lDistanceToMove": "e0", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "1b0"}
{"lDistanceToMove": "24", "dwMoveMethod": "0", "lpDistanceToMoveHigh": "0", "hFile": "d8"}
200
1b0
ec
23c
238
228
204
C:\PUA_Patcher.BE55BE03ED4ED22E4AF0A4AA1B443E952B80E83D.exe
C:\Windows\system32\DUser.dll
C:\Windows\system32\msftedit.DLL
C:\Windows\syswow64\MSCTF.dll
C:\Windows\syswow64\USER32.dll
C:\Windows\syswow64\shlwapi.DLL
C:\Windows\system32\propsys.dll
.exe
program
file
Plane4
Plane5
Plane6
Plane7
Plane1
Plane2
Plane3
Plane8
Plane9
Disable
FrameTabWindow
DataFilePath
SystemSetupInProgress
EnablePunycode
DisableSecuritySettingsCheck
Plane16
Plane14
Plane15
Plane12
Plane13
Plane10
Plane11
TabProcGrowth
FrameMerging
CreateUriCacheSize
SpecialFoldersCacheSize
SessionMerging
AdminTabProcs
{"Reserved": "0", "hKey": "1b0", "lpData": "403af9", "dwType": "1", "lpValueName": "UninstallString", "cbData": "1"}
{"Reserved": "0", "hKey": "1b0", "lpData": "1d51994", "dwType": "1", "lpValueName": "DisplayVersion", "cbData": "a"}
{"Reserved": "0", "hKey": "1b0", "lpData": "18fe10", "dwType": "4", "lpValueName": "VersionMinor", "cbData": "4"}
{"Reserved": "0", "hKey": "1b0", "lpData": "1d60560", "dwType": "1", "lpValueName": "InstallLocation", "cbData": "32"}
{"Reserved": "0", "hKey": "1b0", "lpData": "18fe10", "dwType": "4", "lpValueName": "Language", "cbData": "4"}
{"Reserved": "0", "hKey": "1b0", "lpData": "18fe10", "dwType": "4", "lpValueName": "NoRepair", "cbData": "4"}
{"Reserved": "0", "hKey": "1b0", "lpData": "18fe10", "dwType": "4", "lpValueName": "VersionMajor", "cbData": "4"}
{"Reserved": "0", "hKey": "1b0", "lpData": "18fe10", "dwType": "4", "lpValueName": "NoModify", "cbData": "4"}
{"Reserved": "0", "hKey": "1b0", "lpData": "1d51ec8", "dwType": "1", "lpValueName": "URLInfoAbout", "cbData": "18"}
{"Reserved": "0", "hKey": "1b0", "lpData": "403af9", "dwType": "1", "lpValueName": "DisplayIcon", "cbData": "1"}
{"Reserved": "0", "hKey": "1b0", "lpData": "1d5208c", "dwType": "1", "lpValueName": "HelpLink", "cbData": "16"}
{"Reserved": "0", "hKey": "1b0", "lpData": "1d61600", "dwType": "1", "lpValueName": "InstallDate", "cbData": "9"}
{"Reserved": "0", "hKey": "1b0", "lpData": "18fe10", "dwType": "4", "lpValueName": "EstimatedSize", "cbData": "4"}
{"Reserved": "0", "hKey": "1b0", "lpData": "1d613ec", "dwType": "1", "lpValueName": "InstallSource", "cbData": "4"}
{"Reserved": "0", "hKey": "1b0", "lpData": "1d51a1c", "dwType": "1", "lpValueName": "Publisher", "cbData": "e"}
{"Reserved": "0", "hKey": "1b0", "lpData": "1d61f0c", "dwType": "1", "lpValueName": "DisplayName", "cbData": "44"}
{"h_key": "80000002", "samDesired": "f003f", "Reserved": "0", "lpSecurityAttributes": "0", "lpdwDisposition": "18fe10", "dwOptions": "0", "lpClass": "<NULL>", "phkResult": "18fe0c", "lpSubKey": "SOFTWARE\\Microsoft\\Windows\\CurrentVersion\\Uninstall\\C:\\Users\\win7\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu\\Programs"}
{"dwCreationDisposition": "2", "path": "C:\\Users\\win7\\AppData\\Local\\Temp\\$inst\\temp_0.tmp", "dwDesiredAccess": "40000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Local\\Temp\\$inst\\7.tmp", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Windows\\Fonts\\staticcache.dat", "dwDesiredAccess": "80000000", "dwShareMode": "5"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7", "dwDesiredAccess": "100081", "dwShareMode": "7"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Local\\Temp\\$inst\\2.tmp", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Roaming\\Microsoft\\desktop.ini", "dwDesiredAccess": "80000000", "dwShareMode": "7"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Roaming\\Microsoft\\Windows", "dwDesiredAccess": "100081", "dwShareMode": "7"}
{"dwCreationDisposition": "2", "path": "<NULL>", "dwDesiredAccess": "40000000", "dwShareMode": "0"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Roaming\\Microsoft", "dwDesiredAccess": "100081", "dwShareMode": "7"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Roaming\\Microsoft\\Windows\\Start Menu", "dwDesiredAccess": "100081", "dwShareMode": "7"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Local\\Temp\\$inst\\temp_0.tmp", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Local\\Microsoft\\Windows\\Caches\\{AFBF9F1A-8EE8-4C77-AF34-C647E37CA0D9}.1.ver0x0000000000000008.db", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "2", "path": "C:\\Users\\win7\\AppData\\Local\\Temp\\$inst\\2.tmp", "dwDesiredAccess": "40000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData", "dwDesiredAccess": "100081", "dwShareMode": "7"}
{"dwCreationDisposition": "3", "path": "C:\\PUA_Patcher.BE55BE03ED4ED22E4AF0A4AA1B443E952B80E83D.exe", "dwDesiredAccess": "80000000", "dwShareMode": "5"}
{"dwCreationDisposition": "3", "path": "C:\\", "dwDesiredAccess": "100081", "dwShareMode": "7"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\desktop.ini", "dwDesiredAccess": "80000000", "dwShareMode": "7"}
{"dwCreationDisposition": "3", "path": "C:\\Users", "dwDesiredAccess": "100081", "dwShareMode": "7"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Local\\Microsoft\\Windows\\Caches\\cversions.1.db", "dwDesiredAccess": "80000000", "dwShareMode": "3"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Roaming", "dwDesiredAccess": "100081", "dwShareMode": "7"}
{"dwCreationDisposition": "3", "path": "C:\\PUA_Patcher.BE55BE03ED4ED22E4AF0A4AA1B443E952B80E83D.exe", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"dwCreationDisposition": "3", "path": "C:\\Users\\win7\\AppData\\Local\\Temp\\$inst\\9.tmp", "dwDesiredAccess": "80000000", "dwShareMode": "1"}
{"hKey": "204", "phkResult": "0", "lpSubKey": "Tahoma"}
{"hKey": "1d4", "phkResult": "0", "lpSubKey": "FEATURE_IGNORE_POLICIES_ZONEMAP_IF_ESC_ENABLED_KB918915"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software"}
{"hKey": "1d4", "phkResult": "0", "lpSubKey": "FEATURE_ZONES_DEFAULT_DRIVE_INTRANET_KB941000"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Internet Explorer\\Main"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\DataStore_V1.0"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer\\Main"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer"}
{"hKey": "1d4", "phkResult": "0", "lpSubKey": "FEATURE_ZONES_CHECK_ZONEMAP_POLICY_KB941001"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer\\Main"}
{"hKey": "1d4", "phkResult": "0", "lpSubKey": "FEATURE_PROTOCOL_LOCKDOWN"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Internet Explorer\\Main"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software"}
{"hKey": "1d4", "phkResult": "0", "lpSubKey": "FEATURE_INITIALIZE_URLACTION_SHELLEXECUTE_TO_ALLOW_KB936610"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\ZoneMap"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings\\Zones\\"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer\\Main\\FeatureControl"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings"}
{"hKey": "208", "phkResult": "0", "lpSubKey": "Microsoft\\Internet Explorer\\Security"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Windows\\CurrentVersion\\Internet Settings"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Policies"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl"}
{"hKey": "1d4", "phkResult": "0", "lpSubKey": "FEATURE_ALLOW_REVERSE_SOLIDUS_IN_USERINFO_KB932562"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "System\\Setup"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies\\Microsoft\\Internet Explorer\\Main\\FeatureControl"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\LanguagePack\\SurrogateFallback"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Policies"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Explorer\\KindMap"}
{"hKey": "80000001", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Internet Explorer\\Main\\FeatureControl"}
{"hKey": "1e4", "phkResult": "0", "lpSubKey": "Microsoft\\Internet Explorer\\Security"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "Software\\Microsoft\\Windows\\CurrentVersion\\Internet Settings"}
{"hKey": "80000002", "phkResult": "0", "lpSubKey": "SOFTWARE\\Microsoft\\Windows NT\\CurrentVersion\\FontLink\\SystemLink"}
{"hKey": "1d4", "phkResult": "0", "lpSubKey": "FEATURE_LOCALMACHINE_LOCKDOWN"}
<NULL>
Local\ZonesCacheCounterMutex
Local\ZonesLockedCacheCounterMutex
Local\MSCTF.Asm.MutexDefault1
{"nNumberOfBytesToWrite": "4", "lpOverlapped": "0", "lpBuffer": "1d5c84c", "lpNumberOfBytesWritten": "18fda4", "hFile": "1b0"}
{"nNumberOfBytesToWrite": "2328", "lpOverlapped": "0", "lpBuffer": "1d70004", "lpNumberOfBytesWritten": "18fd4c", "hFile": "1ac"}
{"nNumberOfBytesToWrite": "a1", "lpOverlapped": "0", "lpBuffer": "1d737aa", "lpNumberOfBytesWritten": "18fd4c", "hFile": "1ac"}
{"nNumberOfBytesToWrite": "20a0", "lpOverlapped": "0", "lpBuffer": "1d75f64", "lpNumberOfBytesWritten": "18fd4c", "hFile": "1ac"}
{"nNumberOfBytesToWrite": "68f0", "lpOverlapped": "0", "lpBuffer": "1d71714", "lpNumberOfBytesWritten": "18fd4c", "hFile": "1ac"}
{"nNumberOfBytesToWrite": "4", "lpOverlapped": "0", "lpBuffer": "1d54edc", "lpNumberOfBytesWritten": "18fe14", "hFile": "d8"}
{"nNumberOfBytesToWrite": "8000", "lpOverlapped": "0", "lpBuffer": "1d70004", "lpNumberOfBytesWritten": "18fd4c", "hFile": "1ac"}
{"nNumberOfBytesToWrite": "28e0", "lpOverlapped": "0", "lpBuffer": "1d70004", "lpNumberOfBytesWritten": "18fd4c", "hFile": "1ac"}
{"nNumberOfBytesToWrite": "1470", "lpOverlapped": "0", "lpBuffer": "1d70004", "lpNumberOfBytesWritten": "18fd4c", "hFile": "1ac"}
{"nNumberOfBytesToWrite": "20", "lpOverlapped": "0", "lpBuffer": "1d54ed4", "lpNumberOfBytesWritten": "18fdf0", "hFile": "d8"}
{"nNumberOfBytesToWrite": "5cd8", "lpOverlapped": "0", "lpBuffer": "1d7232c", "lpNumberOfBytesWritten": "18fd4c", "hFile": "1ac"}
{"nNumberOfBytesToWrite": "6b90", "lpOverlapped": "0", "lpBuffer": "1d71474", "lpNumberOfBytesWritten": "18fd4c", "hFile": "1ac"}
{"nNumberOfBytesToWrite": "5720", "lpOverlapped": "0", "lpBuffer": "1d728e4", "lpNumberOfBytesWritten": "18fd4c", "hFile": "1ac"}
{"nNumberOfBytesToWrite": "1710", "lpOverlapped": "0", "lpBuffer": "1d70004", "lpNumberOfBytesWritten": "18fd4c", "hFile": "1ac"}
{"nNumberOfBytesToWrite": "7d98", "lpOverlapped": "0", "lpBuffer": "1d70004", "lpNumberOfBytesWritten": "18fd4c", "hFile": "1ac"}
{"nNumberOfBytesToWrite": "73ec2", "lpOverlapped": "0", "lpBuffer": "1d609f8", "lpNumberOfBytesWritten": "18fd34", "hFile": "1b0"}
{"nNumberOfBytesToWrite": "5f60", "lpOverlapped": "0", "lpBuffer": "1d70004", "lpNumberOfBytesWritten": "18fd4c", "hFile": "1ac"}
{"nNumberOfBytesToWrite": "37a6", "lpOverlapped": "0", "lpBuffer": "1d70004", "lpNumberOfBytesWritten": "18fd4c", "hFile": "1ac"}
{"nNumberOfBytesToWrite": "80000", "lpOverlapped": "0", "lpBuffer": "1d609f8", "lpNumberOfBytesWritten": "18fd34", "hFile": "1b0"}
{"nNumberOfBytesToWrite": "7ef8", "lpOverlapped": "0", "lpBuffer": "1d70004", "lpNumberOfBytesWritten": "18fd4c", "hFile": "1ac"}
{"nNumberOfBytesToWrite": "108", "lpOverlapped": "0", "lpBuffer": "1d77efc", "lpNumberOfBytesWritten": "18fd4c", "hFile": "1ac"}
{"nNumberOfBytesToWrite": "268", "lpOverlapped": "0", "lpBuffer": "1d77d9c", "lpNumberOfBytesWritten": "18fd4c", "hFile": "1ac"}
comctl32.dll
UxTheme.dll
msftedit
comctl32
IMM32.dll
ole32.dll
ADVAPI32.dll
propsys.dll
ntmarta.dll
API-MS-Win-Core-LocalRegistry-L1-1-0.dll
C:\Windows\system32\ole32.dll
C:\Windows\syswow64\MSCTF.dll
SHELL32.dll
OLEAUT32.DLL
ntdll.dll
DUser.dll
C:\Windows\system32\DUser.dll
user32.dll
dwmapi.dll
C:\Windows\system32\xmllite.dll
OLEAUT32.dll
kernel32.dll
imageres.dll
Secur32.dll
API-MS-WIN-DOWNLEVEL-SHLWAPI-L1-1-0.DLL
api-ms-win-downlevel-advapi32-l2-1-0.dll
C:\Users\win7\AppData\Local\Temp\$inst\temp_0.tmp
C:\Users\win7\AppData\Local\Temp\$inst\0.tmp
C:\Users\win7\AppData\Local\Temp\$inst\1.tmp
C:\Users\win7\AppData\Local\Temp\$inst\2.tmp
C:\Users\win7\AppData\Local\Temp\$inst\3.tmp
C:\Users\win7\AppData\Local\Temp\$inst\4.tmp
C:\Users\win7\AppData\Local\Temp\$inst\5.tmp
C:\Users\win7\AppData\Local\Temp\$inst\6.tmp
C:\Users\win7\AppData\Local\Temp\$inst\7.tmp
C:\Users\win7\AppData\Local\Temp\$inst\8.tmp
C:\Users\win7\AppData\Local\Temp\$inst\9.tmp
C:\Users\win7\AppData\Local\Temp\$inst\10.tmp
C:\Users\win7\AppData\Local\Temp\$inst\11.tmp
C:\Users\win7\AppData\Local\Temp\$inst\12.tmp
C:\Users\win7\AppData\Local\Temp\$inst\13.tmp
C:\Users\win7\AppData\Local\Temp\$inst\14.tmp
C:\Users\win7\AppData\Local\Temp\$inst\15.tmp
C:\Users\win7\AppData\Local\Temp\$inst\16.tmp
C:\Users\win7\AppData\Local\Temp\$inst\17.tmp
C:\Users\win7\AppData\Local\Temp\$inst\20.tmp
C:\Users\win7\AppData\Local\Temp\$inst\50.tmp
C:\Users\win7\AppData\Local\Temp\$inst\21.tmp
C:\Users\win7\AppData\Local\Temp\$inst\51.tmp
Precise Detectors Analysis Results
| Detector Name | Date | Verdict | Reason | |
|---|---|---|---|---|
| Uninstaller FP Detector | 2017-06-05 02:02:33.188471 | No Match | help | No match. |
| Yara Rule Static Malware Detector | 2017-06-05 02:02:33.302614 | No Match | help | No match. |
| Static Precise PUA Detector 1 | 2017-06-05 02:02:33.200503 | No Match | help | NotDetected |
| Static Precise Virus Detector | 2017-06-05 02:02:33.215992 | No Match | help | NotDetected |
| Static Precise Trojan Detector | 2017-06-05 02:02:33.209807 | No Match | help | NotDetected |
| Malicious Url Detector | 2017-06-05 02:02:49.754175 | No Match | help | No match. |
Advance Heuristics
No Advanced Heuristic Analysis Result Received
Human Expert Analysis Results
Analysis Start Date:   2017-06-05 05:15:07.342091 ( )
Analysis End Date:  2017-06-05 08:06:28.396709 ( )
File Upload Date:  2017-06-05 02:02:50.162306 ( )
Update Date:  2017-06-05 08:06:28.402821 ( )
Human Expert Analyst Feedback:   None
Verdict:   Clean
Additional File Information
| Property | Value |
|---|
| Name | Virtual Address | Virtual Size | Raw Size | Entropy | MD5 |
|---|