Benign windows Download

ImputNet.Helium

Legitimate Chromium-based app installer

PE copies a file and installs Run or RunOnce persistenceAdjusts token privileges before launching with a user token

Evidence

Small code section in large PE 0x3c0–0x490
⋯3 more rows
0x3f000000000000000000000000000000000................
0x400558bec83ec5c837d0c0f742b837d0c46U....\.}..t+.}.F
0x4108b4514750d834818108b0d0847430089.E.u..H.....GC..
0x420480450ff7510ff750cff7508ff155c82H.P.u..u..u...\.
⋯7 more rows
NSIS self-extracting installer 0x2570–0x2640
⋯3 more rows
0x25a02e00008b45d8a9f0ffffff757c817ddc....E......u|.}.
0x25b0efbeadde7573817de8496e7374756a81....us.}.Instuj.
0x25c07de4736f66747561817de04e756c6c75}.softua.}.Nullu
0x25d0580945088b45088b0d186a410083e002X.E..E....jA....
⋯7 more rows
ExitWindowsEx shutdown/restart API symbol 0x8004–0x82f4
⋯16 more rows
0x81046172546f4d756c746942797465005001arToMultiByte.P.
0x81144765744469736b467265655370616365GetDiskFreeSpace
0x812457000a02476c6f62616c556e6c6f636bW...GlobalUnlock
0x813400000302476c6f62616c4c6f636b0000....GlobalLock..
0x81446f004372656174655468726561640000o.CreateThread..
⋯10 more rows
0x81f4797374656d4469726563746f72795700ystemDirectoryW.
0x8204a00147657450726f6341646472657373..GetProcAddress
0x821400007f014765744d6f64756c6548616e....GetModuleHan
0x8224646c654100005a014765744578697443dleA..Z.GetExitC
⋯13 more rows
NSIS runtime error URL in data 0x8410–0x8540
⋯3 more rows
0x844072003a00200025006400250025000000r.:. .%.d.%.%...
0x845049006e007300740061006c006c006500I.n.s.t.a.l.l.e.
0x84607200200069006e007400650067007200r. .i.n.t.e.g.r.
0x847069007400790020006300680065006300i.t.y. .c.h.e.c.
0x84806b002000680061007300200066006100k. .h.a.s. .f.a.
0x849069006c00650064002e00200043006f00i.l.e.d... .C.o.
0x84a06d006d006f006e002000630061007500m.m.o.n. .c.a.u.
0x84b0730065007300200069006e0063006c00s.e.s. .i.n.c.l.
0x84c07500640065000a0069006e0063006f00u.d.e...i.n.c.o.
0x84d06d0070006c0065007400650020006400m.p.l.e.t.e. .d.
⋯7 more rows
NSIS runtime error title in data 0x867c–0x873c
⋯3 more rows
0x86ac000000004e0043005200430000000000....N.C.R.C.....
0x86bc4e005300490053002000450072007200N.S.I.S. .E.r.r.
0x86cc6f007200000000000000000045007200o.r.........E.r.
⋯7 more rows
Accesses Windows CurrentVersion Run key setup.exe · 0x3445e0–0x344780
⋯5 more rows
0x34463063630000000000000000000000000000cc..............
0x34464053006f00660074007700610072006500S.o.f.t.w.a.r.e.
0x3446505c004d006900630072006f0073006f00\.M.i.c.r.o.s.o.
0x344660660074005c00570069006e0064006f00f.t.\.W.i.n.d.o.
0x344670770073005c0043007500720072006500w.s.\.C.u.r.r.e.
⋯17 more rows
References high-risk Windows token privilege setup.exe · 0x34b818–0x34b948
⋯5 more rows
0x34b868595a3233343536370000000000000000YZ234567........
0x34b8785300650049006d007000650072007300S.e.I.m.p.e.r.s.
0x34b8886f006e00610074006500500072006900o.n.a.t.e.P.r.i.
0x34b898760069006c0065006700650000000000v.i.l.e.g.e.....
⋯11 more rows
CreateProcessWithToken API reference setup.exe · 0x3671a0–0x3672d0
⋯5 more rows
0x3671f06f636573734173557365725700008d00ocessAsUserW....
0x36720043726561746550726f63657373576974CreateProcessWit
0x36721068546f6b656e57009100437265617465hTokenW...Create
0x36722053657276696365570000930043726561ServiceW....Crea
0x367230746557656c6c4b6e6f776e5369640000teWellKnownSid..
⋯10 more rows
Create registry key via WinAPI setup.exe · 0x367930–0x367c20
⋯3 more rows
0x367960696e646f774c6f6e675074725700a203indowLongPtrW...
0x36797053657457696e646f7773486f6f6b4578SetWindowsHookEx
0x3679805700d2035472616e736c6174654d6573W...TranslateMes
0x367990736167650000d703556e686f6f6b5769sage....UnhookWi
0x3679a06e646f7773486f6f6b457800dd03556endowsHookEx...Un
0x3679b07265676973746572436c617373570000registerClassW..
0x3679c00000416371756972655352574c6f636b..AcquireSRWLock
0x3679d04578636c757369766500140041646456Exclusive...AddV
0x3679e06563746f726564457863657074696f6eectoredException
0x3679f048616e646c657200270041737369676eHandler.'.Assign
0x367a0050726f63657373546f4a6f624f626a65ProcessToJobObje
0x367a1063740000a000436c6f736548616e646cct....CloseHandl
0x367a206500b600436f6d70617265537472696ee...CompareStrin
0x367a3067570000b700436f6e6e6563744e616dgW....ConnectNam
0x367a406564506970650000c800436f70794669edPipe....CopyFi
0x367a506c655700d70043726561746544697265leW...CreateDire
⋯3 more rows
0x367a9043726561746546696c655700ee004372CreateFileW...Cr
0x367aa065617465496f436f6d706c6574696f6eeateIoCompletion
0x367ab0506f72740000f9004372656174654d75Port....CreateMu
0x367ac0746578570000fb004372656174654e61texW....CreateNa
0x367ad06d656450697065570000050143726561medPipeW....Crea
0x367ae0746550726f636573735700000c014372teProcessW....Cr
0x367af06561746553656d6170686f7265570000eateSemaphoreW..
0x367b0012014372656174655468726561640000..CreateThread..
0x367b101b01437265617465546f6f6c68656c70..CreateToolhelp
0x367b203332536e617073686f7400003201446532Snapshot..2.De
0x367b306c657465437269746963616c53656374leteCriticalSect
0x367b40696f6e00390144656c65746546696c65ion.9.DeleteFile
0x367b5057003a0144656c65746550726f635468W.:.DeleteProcTh
0x367b60726561644174747269627574654c6973readAttributeLis
0x367b7074004401446576696365496f436f6e74t.D.DeviceIoCont
0x367b80726f6c004901446973636f6e6e656374rol.I.Disconnect
0x367b904e616d6564506970650052014475706cNamedPipe.R.Dupl
0x367ba0696361746548616e646c65005601456eicateHandle.V.En
0x367bb0636f6465506f696e746572005a01456ecodePointer.Z.En
0x367bc0746572437269746963616c5365637469terCriticalSecti
0x367bd06f6e00007e01456e756d53797374656don..~.EnumSystem
0x367be04c6f63616c6573570000890145786974LocalesW....Exit
0x367bf050726f63657373008d01457870616e64Process...Expand
0x367c00456e7669726f6e6d656e74537472696eEnvironmentStrin
0x367c1067735700950146696c6554696d65546fgsW...FileTimeTo
0x367c2053797374656d54696d650000a0014669SystemTime....Fi
Game combat-modification cheat controls chrome.dll · 0xed47c28–0xed47d48
⋯5 more rows
0xed47c7835000000302e393000000000000000005...0.90........
0xed47c886e6f2072656c6f616420616e696d6174no reload animat
0xed47c98696f6e000000000094a4b78e01000000ion.............
⋯11 more rows

Showing the top 5 files — 6 more files (98 regions) not shown.

Keyboard shortcuts on this page: j for the next sample, k for the previous one, x to go back to the feed, d to download the original bytes, r to re-queue the sample for analysis.