Windows Analysis Report
pf-setup-en.exe

Overview

General Information

Sample name: pf-setup-en.exe
Analysis ID: 1562231
MD5: a00d7a76edf06b1b0376c49a429c61fc
SHA1: 2f8608b7760be958200e77631cb777a66d479d21
SHA256: d3ef92dff42514142428c4e20012bb399a38a415abfe6f4ddc18f91ed16b2a12
Infos:

Detection

Score: 30
Range: 0 - 100
Whitelisted: false
Confidence: 40%

Signatures

Multi AV Scanner detection for dropped file
Multi AV Scanner detection for submitted file
Tries to harvest and steal browser information (history, passwords, etc)
Drops PE files
Drops files with a non-matching file extension (content does not match file extension)
Found dropped PE file which has not been started or loaded
IP address seen in connection with other malware
Queries the volume information (name, serial number etc) of a device
Sample file is different than original file name gathered from version info
Stores files to the Windows start menu directory
Suricata IDS alerts with low severity for network traffic
Uses 32bit PE files

Classification

AV Detection

barindex
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe ReversingLabs: Detection: 18%
Source: pf-setup-en.exe ReversingLabs: Detection: 22%
Source: pf-setup-en.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: C:\Users\user\Desktop\pf-setup-en.exe Window detected: < &Back&Next >CancelNSIS (c) - PhotoFiltre (c) - Antonio Da Cruz NSIS (c) - PhotoFiltre (c) - Antonio Da CruzLicense AgreementPlease review the license terms before installing PhotoFiltre.Press Page Down to see the rest of the agreement.PhotoFiltre End User License AgreementThe PhotoFiltre programme is supplied 'as is'. The user runs PhotoFiltreat his or her own risk without warranty or guarantee on the part of the author. The author is under no obligation to correct bugs or other insuffiencies in the programme.The author is not responsable for any damages suffered by the user resulting from the use or distribution of the programme.In the same way the author is not responsable for any loss of revenueor profit or of any loss of (records or) information or for direct or indirect damage which which may occur from the use of the programme nor for the reason that the programme may be inoperable and this nonobstantthe fact that the author may have been advised of the possibility of such damage.PhotoFiltre is supplied free of charge for private or educative use. Any commercial or professional use requires a registered copy of the programme.The use of the PhotoFiltre programme implies the acceptance by the user of the terms of this license agreement.If you accept the terms of the agreement select the first option below. You must accept the agreement to install PhotoFiltre. Click Next to continue.I &accept the terms of the License AgreementI &do not accept the terms of the License Agreement
Source: C:\Users\user\Desktop\pf-setup-en.exe Registry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PhotoFiltre Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe File created: C:\Program Files (x86)\PhotoFiltre\License.txt Jump to behavior
Source: Binary string: C:\hudson\jobs\Installchecker\workspace\build\installchecker\Release\AskInstallChecker.pdb source: pf-setup-en.exe, 00000000.00000003.1722833420.000000000280E000.00000004.00000020.00020000.00000000.sdmp, AskInstallChecker.exe, 00000001.00000000.1701570231.00000000005E3000.00000002.00000001.01000000.00000004.sdmp, AskInstallChecker.exe, 00000001.00000002.1721993807.00000000005E3000.00000002.00000001.01000000.00000004.sdmp, AskInstallChecker.exe.0.dr
Source: C:\Users\user\Desktop\pf-setup-en.exe File opened: C:\Users\user\AppData\Roaming Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe File opened: C:\Users\user Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe File opened: C:\Users\user\AppData\Roaming\Microsoft Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe File opened: C:\Users\user\AppData Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows Jump to behavior
Source: Joe Sandbox View IP Address: 34.117.224.112 34.117.224.112
Source: Network traffic Suricata IDS: 2803274 - Severity 2 - ETPRO MALWARE Common Downloader Header Pattern UH : 192.168.2.4:49730 -> 34.117.224.112:80
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: unknown UDP traffic detected without corresponding DNS query: 1.1.1.1
Source: global traffic HTTP traffic detected: GET /images/nocache/apn/tr.gif?ev=eichk&cb=&encb=&chk=invbr&ts=6pYIy&guid= HTTP/1.1User-Agent: AskInstallCheckerHost: img.apnanalytics.com
Source: global traffic DNS traffic detected: DNS query: websearch.ask.com
Source: global traffic DNS traffic detected: DNS query: img.apnanalytics.com
Source: pf-setup-en.exe, 00000000.00000003.1700236279.0000000002806000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://about.ask.com/en/docs/about/ask_eula.shtml
Source: pf-setup-en.exe, 00000000.00000003.2009189543.000000000077B000.00000004.00000020.00020000.00000000.sdmp, pf-setup-en.exe, 00000000.00000003.1700236279.0000000002806000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://about.ask.com/en/docs/about/ask_eula.shtmlhttp://sp.ask.com/en/docs/about/privacy.shtmlopen
Source: pf-setup-en.exe, 00000000.00000003.2009189543.000000000077B000.00000004.00000020.00020000.00000000.sdmp, pf-setup-en.exe, 00000000.00000003.1700236279.0000000002806000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://about.ask.com/en/docs/about/ask_eula.shtmlopen
Source: pf-setup-en.exe, 00000000.00000003.1927038130.000000000280E000.00000004.00000020.00020000.00000000.sdmp, PhotoFiltre.exe, 00000006.00000000.2007940063.0000000000401000.00000020.00000001.01000000.0000000E.sdmp, PhotoFiltre.exe.0.dr String found in binary or memory: http://forum.photofiltre.com
Source: pf-setup-en.exe, 00000000.00000003.1927038130.000000000280E000.00000004.00000020.00020000.00000000.sdmp, PhotoFiltre.exe, 00000006.00000000.2007940063.0000000000401000.00000020.00000001.01000000.0000000E.sdmp, PhotoFiltre.exe.0.dr String found in binary or memory: http://forum.photofiltre.comopen
Source: pf-setup-en.exe, 00000000.00000003.1722833420.000000000280E000.00000004.00000020.00020000.00000000.sdmp, AskInstallChecker.exe, 00000001.00000000.1701570231.00000000005E3000.00000002.00000001.01000000.00000004.sdmp, AskInstallChecker.exe, 00000001.00000002.1721993807.00000000005E3000.00000002.00000001.01000000.00000004.sdmp, AskInstallChecker.exe.0.dr String found in binary or memory: http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=eichk&cb=%s&encb=%s&chk=
Source: AskInstallChecker.exe, 00000001.00000002.1722179302.00000000012FC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=eichk&cb=&encb=&chk=invbr&ts=6pYIy&guid=
Source: AskInstallChecker.exe, 00000001.00000002.1722179302.000000000133C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=eichk&cb=&encb=&chk=invbr&ts=6pYIy&guid=L
Source: AskInstallChecker.exe, 00000001.00000002.1722179302.000000000133C000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://img.apnanalytics.com/images/nocache/apn/tr.gif?ev=eichk&cb=&encb=&chk=invbr&ts=6pYIy&guid=O
Source: pf-setup-en.exe, Uninst.exe.0.dr String found in binary or memory: http://nsis.sf.net/NSIS_Error
Source: pf-setup-en.exe, Uninst.exe.0.dr String found in binary or memory: http://nsis.sf.net/NSIS_ErrorError
Source: pf-setup-en.exe, 00000000.00000003.1700236279.0000000002806000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://sp.ask.com/en/docs/about/privacy.shtml
Source: pf-setup-en.exe, 00000000.00000003.1722833420.000000000280E000.00000004.00000020.00020000.00000000.sdmp, AskInstallChecker.exe.0.dr String found in binary or memory: http://sp.ask.com/en/docs/about/terms_of_service.shtml0
Source: pf-setup-en.exe, 00000000.00000003.1722833420.000000000280E000.00000004.00000020.00020000.00000000.sdmp, AskInstallChecker.exe, 00000001.00000000.1701570231.00000000005E3000.00000002.00000001.01000000.00000004.sdmp, AskInstallChecker.exe, 00000001.00000002.1721993807.00000000005E3000.00000002.00000001.01000000.00000004.sdmp, AskInstallChecker.exe.0.dr String found in binary or memory: http://websearch.ask.com/preinstall?client=ic&tb=%s&r=0&ipid=%s&npid=%s&iev=%d&ielu=%d&fflu=%d&iv=%s
Source: AskInstallChecker.exe, 00000001.00000002.1722179302.00000000012FC000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: http://websearch.ask.com/preinstall?client=ic&tb=PTF&r=0&ipid=&npid=PTF&iev=9&ielu=0&fflu=0&iv=&nv=1
Source: pf-setup-en.exe, 00000000.00000003.1927038130.000000000280E000.00000004.00000020.00020000.00000000.sdmp, PhotoFiltre.exe, 00000006.00000000.2008220430.0000000000627000.00000002.00000001.01000000.0000000E.sdmp, PhotoFiltre.exe, 00000006.00000000.2007940063.0000000000401000.00000020.00000001.01000000.0000000E.sdmp, PhotoFiltre.exe.0.dr String found in binary or memory: http://www.photofiltre.com
Source: pf-setup-en.exe, 00000000.00000003.1927038130.000000000280E000.00000004.00000020.00020000.00000000.sdmp, PhotoFiltre.exe, 00000006.00000000.2007940063.0000000000401000.00000020.00000001.01000000.0000000E.sdmp, PhotoFiltre.exe.0.dr String found in binary or memory: http://www.photofiltre.comopenU
Source: AskInstallChecker.exe, 00000001.00000002.1722407972.0000000002F80000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://bridge.lga1.admarketplace.net/ctp?version=16.0.0&key=1696332238301000001.2&ci=1696332238417.
Source: AskInstallChecker.exe, 00000001.00000002.1722407972.0000000002F80000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://bridge.lga1.ap01.net/ctp?version=16.0.0&key=1696332238301000001.1&ci=1696332238417.12791&cta
Source: AskInstallChecker.exe, 00000001.00000002.1722407972.0000000002F80000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://contile-images.services.mozilla.com/0TegrVVRalreHILhR2WvtD_CFzj13HCDcLqqpvXSOuY.10862.jpg
Source: AskInstallChecker.exe, 00000001.00000002.1722407972.0000000002F80000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://contile-images.services.mozilla.com/obgoOYObjIFea_bXuT6L4LbBJ8j425AD87S1HMD3BWg.9991.jpg
Source: AskInstallChecker.exe, 00000001.00000002.1722407972.0000000002F80000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://imp.mt48.net/static?id=7RHzfOIXjFEYsBdvIpkX4QqmfZfYfQfafZbXfpbWfpbX7ReNxR3UIG8zInwYIFIVs9eYi
Source: AskInstallChecker.exe, 00000001.00000002.1722407972.0000000002F80000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.amazon.com/?tag=admarketus-20&ref=pd_sl_7548d4575af019e4c148ccf1a78112802e66a0816a72fc94
Source: AskInstallChecker.exe, 00000001.00000002.1722407972.0000000002F80000.00000004.00000020.00020000.00000000.sdmp String found in binary or memory: https://www.expedia.com/?locale=en_US&siteid=1&semcid=US.UB.ADMARKETPLACE.GT-C-EN.HOTEL&SEMDTL=a1219
Source: pf-setup-en.exe, 00000000.00000003.1927038130.0000000002A9F000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: OriginalFilenamePhotoFiltre.exe8 vs pf-setup-en.exe
Source: pf-setup-en.exe Static PE information: RELOCS_STRIPPED, EXECUTABLE_IMAGE, LINE_NUMS_STRIPPED, LOCAL_SYMS_STRIPPED, 32BIT_MACHINE
Source: classification engine Classification label: sus30.spyw.winEXE@5/84@2/1
Source: C:\Users\user\Desktop\pf-setup-en.exe File created: C:\Program Files (x86)\PhotoFiltre Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhotoFiltre Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe File created: C:\Users\user\AppData\Local\Temp\nsmFF90.tmp Jump to behavior
Source: Yara match File source: 00000006.00000000.2007940063.0000000000401000.00000020.00000001.01000000.0000000E.sdmp, type: MEMORY
Source: Yara match File source: 00000000.00000003.1927038130.000000000280E000.00000004.00000020.00020000.00000000.sdmp, type: MEMORY
Source: Yara match File source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe, type: DROPPED
Source: pf-setup-en.exe Static PE information: Section: .text IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Key opened: HKEY_CURRENT_USER\Software\Borland\Delphi\Locales Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe File read: C:\Users\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Key opened: HKEY_CURRENT_USER\Software\Policies\Microsoft\Windows\Safer\CodeIdentifiers Jump to behavior
Source: pf-setup-en.exe ReversingLabs: Detection: 22%
Source: C:\Users\user\Desktop\pf-setup-en.exe File read: C:\Users\user\Desktop\pf-setup-en.exe Jump to behavior
Source: unknown Process created: C:\Users\user\Desktop\pf-setup-en.exe "C:\Users\user\Desktop\pf-setup-en.exe"
Source: C:\Users\user\Desktop\pf-setup-en.exe Process created: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe "C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe" PTF
Source: C:\Users\user\Desktop\pf-setup-en.exe Process created: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe "C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe"
Source: C:\Users\user\Desktop\pf-setup-en.exe Process created: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe "C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe" PTF Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process created: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe "C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe" Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: acgenral.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: shfolder.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: propsys.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: riched20.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: usp10.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: msls31.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: linkinfo.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: ntshrui.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Section loaded: cscapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: acgenral.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: version.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: wininet.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: windows.storage.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: wldp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: profapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: ondemandconnroutehelper.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: winhttp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: mswsock.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: iphlpapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: winnsi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: dnsapi.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: rasadhlp.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: msxml3.dll Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Section loaded: fwpuclnt.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: apphelp.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: acgenral.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: uxtheme.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: winmm.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: samcli.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: msacm32.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: version.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: userenv.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: dwmapi.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: urlmon.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: mpr.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: sspicli.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: winmmbase.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: iertutil.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: srvcli.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: netutils.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: aclayers.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: sfc.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: sfc_os.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: msvfw32.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: textshaping.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: kernel.appcore.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: textinputframework.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: coreuicomponents.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: coremessaging.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: ntmarta.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Section loaded: wintypes.dll Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Key value queried: HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{20D04FE0-3AEA-1069-A2D8-08002B30309D}\InProcServer32 Jump to behavior
Source: PhotoFiltre.lnk.0.dr LNK file: ..\..\..\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe
Source: PhotoFiltre.lnk0.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe
Source: PhotoFiltre Information.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files (x86)\PhotoFiltre\PhotoFiltre.htm
Source: PhotoMasque Information.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files (x86)\PhotoFiltre\PhotoMasque.htm
Source: Uninstall PhotoFiltre.lnk.0.dr LNK file: ..\..\..\..\..\..\..\..\..\Program Files (x86)\PhotoFiltre\Uninst.exe
Source: C:\Users\user\Desktop\pf-setup-en.exe File written: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\ioSpecial.ini Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Window found: window name: TMainForm Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Automated click: Next >
Source: C:\Users\user\Desktop\pf-setup-en.exe Automated click: I accept the terms of the License Agreement
Source: C:\Users\user\Desktop\pf-setup-en.exe Automated click: Next >
Source: C:\Users\user\Desktop\pf-setup-en.exe Automated click: Next >
Source: C:\Users\user\Desktop\pf-setup-en.exe Automated click: Next >
Source: C:\Users\user\Desktop\pf-setup-en.exe Automated click: Install
Source: Window Recorder Window detected: More than 3 window changes detected
Source: C:\Users\user\Desktop\pf-setup-en.exe Window detected: < &Back&Next >CancelNSIS (c) - PhotoFiltre (c) - Antonio Da Cruz NSIS (c) - PhotoFiltre (c) - Antonio Da CruzLicense AgreementPlease review the license terms before installing PhotoFiltre.Press Page Down to see the rest of the agreement.PhotoFiltre End User License AgreementThe PhotoFiltre programme is supplied 'as is'. The user runs PhotoFiltreat his or her own risk without warranty or guarantee on the part of the author. The author is under no obligation to correct bugs or other insuffiencies in the programme.The author is not responsable for any damages suffered by the user resulting from the use or distribution of the programme.In the same way the author is not responsable for any loss of revenueor profit or of any loss of (records or) information or for direct or indirect damage which which may occur from the use of the programme nor for the reason that the programme may be inoperable and this nonobstantthe fact that the author may have been advised of the possibility of such damage.PhotoFiltre is supplied free of charge for private or educative use. Any commercial or professional use requires a registered copy of the programme.The use of the PhotoFiltre programme implies the acceptance by the user of the terms of this license agreement.If you accept the terms of the agreement select the first option below. You must accept the agreement to install PhotoFiltre. Click Next to continue.I &accept the terms of the License AgreementI &do not accept the terms of the License Agreement
Source: C:\Users\user\Desktop\pf-setup-en.exe Registry value created: HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\PhotoFiltre Jump to behavior
Source: pf-setup-en.exe Static file information: File size 4118294 > 1048576
Source: Binary string: C:\hudson\jobs\Installchecker\workspace\build\installchecker\Release\AskInstallChecker.pdb source: pf-setup-en.exe, 00000000.00000003.1722833420.000000000280E000.00000004.00000020.00020000.00000000.sdmp, AskInstallChecker.exe, 00000001.00000000.1701570231.00000000005E3000.00000002.00000001.01000000.00000004.sdmp, AskInstallChecker.exe, 00000001.00000002.1721993807.00000000005E3000.00000002.00000001.01000000.00000004.sdmp, AskInstallChecker.exe.0.dr
Source: C:\Users\user\Desktop\pf-setup-en.exe File created: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Jump to dropped file
Source: C:\Users\user\Desktop\pf-setup-en.exe File created: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\StartMenu.dll Jump to dropped file
Source: C:\Users\user\Desktop\pf-setup-en.exe File created: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\nsDialogs.dll Jump to dropped file
Source: C:\Users\user\Desktop\pf-setup-en.exe File created: C:\Program Files (x86)\PhotoFiltre\TranslationEN.plg Jump to dropped file
Source: C:\Users\user\Desktop\pf-setup-en.exe File created: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\InstallOptions.dll Jump to dropped file
Source: C:\Users\user\Desktop\pf-setup-en.exe File created: C:\Program Files (x86)\PhotoFiltre\Uninst.exe Jump to dropped file
Source: C:\Users\user\Desktop\pf-setup-en.exe File created: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Jump to dropped file
Source: C:\Users\user\Desktop\pf-setup-en.exe File created: C:\Program Files (x86)\PhotoFiltre\TranslationEN.plg Jump to dropped file
Source: C:\Users\user\Desktop\pf-setup-en.exe File created: C:\Program Files (x86)\PhotoFiltre\License.txt Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhotoFiltre Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhotoFiltre\PhotoFiltre.lnk Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhotoFiltre\PhotoFiltre Information.lnk Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhotoFiltre\PhotoMasque Information.lnk Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe File created: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\Programs\PhotoFiltre\Uninstall PhotoFiltre.lnk Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Program Files (x86)\PhotoFiltre\PhotoFiltre.exe Process information set: NOOPENFILEERRORBOX Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\StartMenu.dll Jump to dropped file
Source: C:\Users\user\Desktop\pf-setup-en.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\nsDialogs.dll Jump to dropped file
Source: C:\Users\user\Desktop\pf-setup-en.exe Dropped PE file which has not been started: C:\Program Files (x86)\PhotoFiltre\TranslationEN.plg Jump to dropped file
Source: C:\Users\user\Desktop\pf-setup-en.exe Dropped PE file which has not been started: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\InstallOptions.dll Jump to dropped file
Source: C:\Users\user\Desktop\pf-setup-en.exe Dropped PE file which has not been started: C:\Program Files (x86)\PhotoFiltre\Uninst.exe Jump to dropped file
Source: C:\Users\user\Desktop\pf-setup-en.exe File Volume queried: C:\Program Files (x86) FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe File Volume queried: C:\Program Files (x86) FullSizeInformation Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe File opened: C:\Users\user\AppData\Roaming Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows\Start Menu\desktop.ini Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe File opened: C:\Users\user Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe File opened: C:\Users\user\AppData\Roaming\Microsoft Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe File opened: C:\Users\user\AppData Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe File opened: C:\Users\user\AppData\Roaming\Microsoft\Windows Jump to behavior
Source: AskInstallChecker.exe, 00000001.00000002.1722179302.0000000001377000.00000004.00000020.00020000.00000000.sdmp, AskInstallChecker.exe, 00000001.00000002.1722179302.00000000012FC000.00000004.00000020.00020000.00000000.sdmp Binary or memory string: Hyper-V RAW
Source: C:\Users\user\Desktop\pf-setup-en.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Queries volume information: C:\ VolumeInformation Jump to behavior
Source: C:\Users\user\Desktop\pf-setup-en.exe Queries volume information: C:\ VolumeInformation Jump to behavior

Stealing of Sensitive Information

barindex
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\Profiles\fqs92o4p.default-release\prefs.js Jump to behavior
Source: C:\Users\user\AppData\Local\Temp\nshFFC0.tmp\AskInstallChecker.exe File opened: C:\Users\user\AppData\Roaming\Mozilla\Firefox\profiles.ini Jump to behavior
  • No. of IPs < 25%
  • 25% < No. of IPs < 50%
  • 50% < No. of IPs < 75%
  • 75% < No. of IPs