IOC Report
Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe

loading gif

Files

File Path
Type
Category
Malicious
Lakes_Environmental_WRPLOT_View_Freeware_V.8.0.2.exe
PE32 executable (GUI) Intel 80386, for MS Windows, RAR self-extracting archive
initial sample
C:\Users\user\AppData\Local\Temp\MSI9A55.tmp
PE32 executable (DLL) (GUI) Intel 80386, for MS Windows
dropped
C:\Users\user\AppData\Local\Temp\RarSFX0\0x0409.ini
Unicode text, UTF-16, little-endian text, with CRLF line terminators
dropped
C:\Users\user\AppData\Local\Temp\RarSFX0\Data1.cab
Microsoft Cabinet archive data, many, 14538947 bytes, 19 files, at 0x5c +A "_05552B74CCDE077E19276A4B56E61CF6", iFolder 0x1 +A "_B05A2AB076DDA62641C63DBF405CBA38", 7 cffolders, ID 1111, number 1, 105 datablocks, 0x1 compression
dropped
C:\Users\user\AppData\Local\Temp\RarSFX0\Lakes Environmental WRPLOT View - Freeware V.8.0.2.MSI
Composite Document File V2 Document, Little Endian, Os: Windows, Version 6.0, MSI Installer, Code page: 1252, Title: Installation Database, Author: InstallShield Software Corporation, Keywords: Installer,MSI,Database, Comments: Contact: Your local administrator, Template: Intel;1033, Last Saved By: InstallShield, Revision Number: {79A894FC-A5C1-4F47-BD8C-296A0B8F9A34}, Last Printed: Wed Mar 21 11:30:00 2018, Create Time/Date: Wed Mar 21 11:30:00 2018, Last Saved Time/Date: Wed Mar 21 11:30:00 2018, Number of Pages: 200, Number of Words: 0, Number of Characters: 0, Name of Creating Application: InstallShield 2009 - Express Edition 15, Security: 1
dropped
C:\Users\user\AppData\Local\Temp\RarSFX0\Setup.ini
Generic INItialization configuration [Startup]
dropped
C:\Users\user\AppData\Local\Temp\RarSFX0\instmsia.exe
PE32 executable (GUI) Intel 80386, for MS Windows, MS CAB-Installer self-extracting archive
dropped
C:\Users\user\AppData\Local\Temp\RarSFX0\instmsiw.exe
PE32 executable (GUI) Intel 80386, for MS Windows, MS CAB-Installer self-extracting archive
dropped
C:\Users\user\AppData\Local\Temp\RarSFX0\setup.exe
PE32 executable (GUI) Intel 80386, for MS Windows
dropped