IOC Report
logioptionsplus_installer.exe

loading gif

Files

File Path
Type
Category
Malicious
logioptionsplus_installer.exe
PE32+ executable (GUI) x86-64, for MS Windows
initial sample
C:\ProgramData\LogiOptionsPlus\next.json
JSON data
dropped
C:\ProgramData\LogiOptionsPlus\periodic_check.json
JSON data
modified
C:\ProgramData\Logishrd\{5c4ad735-8c88-42f2-b573-9c8beef54821}_logioptionsplus_setup\PageInstalled.gif
GIF image data, version 89a, 800 x 400
dropped
C:\ProgramData\Logishrd\{5c4ad735-8c88-42f2-b573-9c8beef54821}_logioptionsplus_setup\PageLegacyOptions.gif
GIF image data, version 89a, 800 x 400
dropped
C:\ProgramData\Logishrd\{5c4ad735-8c88-42f2-b573-9c8beef54821}_logioptionsplus_setup\PageUnsupportedOs.gif
GIF image data, version 89a, 800 x 400
dropped
C:\ProgramData\Logishrd\{5c4ad735-8c88-42f2-b573-9c8beef54821}_logioptionsplus_setup\logi_installer_shared_optionsplus.dll
PE32+ executable (DLL) (console) x86-64, for MS Windows
dropped
C:\ProgramData\Logishrd\{5c4ad735-8c88-42f2-b573-9c8beef54821}_logioptionsplus_setup\vc_redist.x64.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.DTD
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.XML
exported SGML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\com.logi.optionsplus.installer.logs\20240829T201147-installer-6980.log
ASCII text, with CRLF, LF line terminators
dropped
C:\Users\user\AppData\Local\Temp\dd_vcredist_amd64_20240829161143.log
ASCII text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\optionsplus-21c9-ea0e-f34c-ee3a\logioptionsplus_setup.exe
PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
dropped
C:\Windows\Temp\{290B7A63-DF99-4623-AAC0-79B88F78147A}\.cr\vc_redist.x64.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1028\license.rtf
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1028\thm.wxl
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1029\license.rtf
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1029\thm.wxl
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1031\license.rtf
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1031\thm.wxl
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1036\license.rtf
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1036\thm.wxl
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1040\license.rtf
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1040\thm.wxl
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1041\license.rtf
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1041\thm.wxl
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1042\license.rtf
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1042\thm.wxl
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1045\license.rtf
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1045\thm.wxl
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1046\license.rtf
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1046\thm.wxl
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1049\license.rtf
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1049\thm.wxl
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1055\license.rtf
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1055\thm.wxl
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\2052\license.rtf
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\2052\thm.wxl
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\3082\license.rtf
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\3082\thm.wxl
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\BootstrapperApplicationData.xml
XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (591), with CRLF line terminators
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\license.rtf
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\logo.png
PNG image data, 64 x 64, 8-bit colormap, non-interlaced
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\thm.wxl
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\thm.xml
XML 1.0 document, ASCII text, with CRLF line terminators
dropped
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\wixstdba.dll
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
There are 36 hidden files, click here to show them.

Domains

Name
IP
Malicious
d2gcbobjbpeml4.cloudfront.net
18.66.112.27
updates.optionsplus.logitechg.com
unknown

IPs

IP
Domain
Country
Malicious
18.66.112.27
d2gcbobjbpeml4.cloudfront.net
United States
127.0.0.1
unknown
unknown