Files
File Path
|
Type
|
Category
|
Malicious
|
|
---|---|---|---|---|
logioptionsplus_installer.exe
|
PE32+ executable (GUI) x86-64, for MS Windows
|
initial sample
|
||
C:\ProgramData\LogiOptionsPlus\next.json
|
JSON data
|
dropped
|
||
C:\ProgramData\LogiOptionsPlus\periodic_check.json
|
JSON data
|
modified
|
||
C:\ProgramData\Logishrd\{5c4ad735-8c88-42f2-b573-9c8beef54821}_logioptionsplus_setup\PageInstalled.gif
|
GIF image data, version 89a, 800 x 400
|
dropped
|
||
C:\ProgramData\Logishrd\{5c4ad735-8c88-42f2-b573-9c8beef54821}_logioptionsplus_setup\PageLegacyOptions.gif
|
GIF image data, version 89a, 800 x 400
|
dropped
|
||
C:\ProgramData\Logishrd\{5c4ad735-8c88-42f2-b573-9c8beef54821}_logioptionsplus_setup\PageUnsupportedOs.gif
|
GIF image data, version 89a, 800 x 400
|
dropped
|
||
C:\ProgramData\Logishrd\{5c4ad735-8c88-42f2-b573-9c8beef54821}_logioptionsplus_setup\logi_installer_shared_optionsplus.dll
|
PE32+ executable (DLL) (console) x86-64, for MS Windows
|
dropped
|
||
C:\ProgramData\Logishrd\{5c4ad735-8c88-42f2-b573-9c8beef54821}_logioptionsplus_setup\vc_redist.x64.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.DTD
|
XML 1.0 document, ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Microsoft\Windows Media\12.0\WMSDKNS.XML
|
exported SGML document, Unicode text, UTF-8 (with BOM) text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\com.logi.optionsplus.installer.logs\20240829T201147-installer-6980.log
|
ASCII text, with CRLF, LF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\dd_vcredist_amd64_20240829161143.log
|
ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Users\user\AppData\Local\Temp\optionsplus-21c9-ea0e-f34c-ee3a\logioptionsplus_setup.exe
|
PE32+ executable (GUI) x86-64 Mono/.Net assembly, for MS Windows
|
dropped
|
||
C:\Windows\Temp\{290B7A63-DF99-4623-AAC0-79B88F78147A}\.cr\vc_redist.x64.exe
|
PE32 executable (GUI) Intel 80386, for MS Windows
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1028\license.rtf
|
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1028\thm.wxl
|
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1029\license.rtf
|
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1029\thm.wxl
|
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1031\license.rtf
|
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1031\thm.wxl
|
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1036\license.rtf
|
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1036\thm.wxl
|
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1040\license.rtf
|
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1040\thm.wxl
|
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1041\license.rtf
|
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1041\thm.wxl
|
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1042\license.rtf
|
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1042\thm.wxl
|
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1045\license.rtf
|
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1045\thm.wxl
|
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1046\license.rtf
|
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1046\thm.wxl
|
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1049\license.rtf
|
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1049\thm.wxl
|
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1055\license.rtf
|
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\1055\thm.wxl
|
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\2052\license.rtf
|
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\2052\thm.wxl
|
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\3082\license.rtf
|
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\3082\thm.wxl
|
XML 1.0 document, Unicode text, UTF-8 text, with CRLF line terminators
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\BootstrapperApplicationData.xml
|
XML 1.0 document, Unicode text, UTF-16, little-endian text, with very long lines (591), with CRLF line terminators
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\license.rtf
|
Rich Text Format data, version 1, ANSI, code page 1252, default language ID 1033
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\logo.png
|
PNG image data, 64 x 64, 8-bit colormap, non-interlaced
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\thm.wxl
|
XML 1.0 document, ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\thm.xml
|
XML 1.0 document, ASCII text, with CRLF line terminators
|
dropped
|
||
C:\Windows\Temp\{C7C1DD64-5C4D-4753-A82D-A5722BC14B7C}\.ba\wixstdba.dll
|
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
|
dropped
|
There are 36 hidden files, click here to show them.
Domains
Name
|
IP
|
Malicious
|
|
---|---|---|---|
d2gcbobjbpeml4.cloudfront.net
|
18.66.112.27
|
||
updates.optionsplus.logitechg.com
|
unknown
|
IPs
IP
|
Domain
|
Country
|
Malicious
|
|
---|---|---|---|---|
18.66.112.27
|
d2gcbobjbpeml4.cloudfront.net
|
United States
|
||
127.0.0.1
|
unknown
|
unknown
|