| File name: | VestCertSetup.exe |
| Full analysis: | https://app.any.run/tasks/bd1643ae-8c0d-4f37-b236-9fc87cb3a55e |
| Verdict: | Malicious activity |
| Analysis date: | July 25, 2019, 14:13:41 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 47C91FF04B0E809CF61E27698F980E3D |
| SHA1: | 3B4A93E8A749B15C83C7D4108F4CA1F85F8BB3B1 |
| SHA256: | 0834903F7C5815197B17866844B364736DD1F3372127B1F1CBDEF58250A5BF4D |
| SSDEEP: | 98304:hddUBlVr421AdapHkri9kR/xRn47Zc4mxoKajUdgZjRcfInh/An+ha4SjvMoRKqT:hddmlCFdahkri2qZ7Kajm6jZon+h+7DT |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2010:11:18 17:27:32+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 82944 |
| InitializedDataSize: | 30208 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1373c |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 9.20.0.0 |
| ProductVersionNumber: | 9.20.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Igor Pavlov |
| FileDescription: | 7z Setup SFX |
| FileVersion: | 9.2 |
| InternalName: | 7zS.sfx |
| LegalCopyright: | Copyright (c) 1999-2010 Igor Pavlov |
| OriginalFileName: | 7zS.sfx.exe |
| ProductName: | 7-Zip |
| ProductVersion: | 9.2 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 18-Nov-2010 16:27:32 |
| Detected languages: |
|
| CompanyName: | Igor Pavlov |
| FileDescription: | 7z Setup SFX |
| FileVersion: | 9.20 |
| InternalName: | 7zS.sfx |
| LegalCopyright: | Copyright (c) 1999-2010 Igor Pavlov |
| OriginalFilename: | 7zS.sfx.exe |
| ProductName: | 7-Zip |
| ProductVersion: | 9.20 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000F8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 18-Nov-2010 16:27:32 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x000143CA | 0x00014400 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.53688 |
.rdata | 0x00016000 | 0x00003CA6 | 0x00003E00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.04219 |
.data | 0x0001A000 | 0x0000292C | 0x00000800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 3.44382 |
.sxdata | 0x0001D000 | 0x00000004 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_LNK_INFO, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.0203931 |
.rsrc | 0x0001E000 | 0x00000A60 | 0x00000C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 3.30387 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 3.44049 | 700 | UNKNOWN | English - United States | RT_VERSION |
2 | 3.18403 | 296 | UNKNOWN | English - United States | RT_ICON |
5 | 1.43775 | 52 | UNKNOWN | English - United States | RT_STRING |
500 | 3.09294 | 184 | UNKNOWN | English - United States | RT_DIALOG |
KERNEL32.dll |
MSVCRT.dll |
OLEAUT32.dll |
SHELL32.dll |
USER32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2212 | "C:\Users\admin\AppData\Local\Temp\VestCertSetup.exe" | C:\Users\admin\AppData\Local\Temp\VestCertSetup.exe | explorer.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: HIGH Description: 7z Setup SFX Exit code: 0 Version: 9.20 Modules
| |||||||||||||||
| 3016 | "C:\Program Files\VestCert\Goji.exe" "SnowDaemonMaker" | C:\Program Files\VestCert\Goji.exe | services.exe | ||||||||||||
User: SYSTEM Company: Yettiesoft Co., Ltd. Integrity Level: SYSTEM Description: Goji Windows Service Exit code: 0 Version: 1.0.5.0 Modules
| |||||||||||||||
| 3484 | "C:\Program Files\VestCert\MangoWireInitializer.exe" V F C | C:\Program Files\VestCert\MangoWireInitializer.exe | VestCert.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3668 | "C:\Users\admin\AppData\Local\Temp\VestCertSetup.exe" | C:\Users\admin\AppData\Local\Temp\VestCertSetup.exe | — | explorer.exe | |||||||||||
User: admin Company: Igor Pavlov Integrity Level: MEDIUM Description: 7z Setup SFX Exit code: 3221226540 Version: 9.20 Modules
| |||||||||||||||
| 3744 | .\SetupPKG.exe -iv | C:\Users\admin\AppData\Local\Temp\7zSE1F5.tmp\SetupPKG.exe | VestCertSetup.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3992 | "C:\Program Files\VestCert\Goji.exe" -i | C:\Program Files\VestCert\Goji.exe | — | SetupPKG.exe | |||||||||||
User: admin Company: Yettiesoft Co., Ltd. Integrity Level: HIGH Description: Goji Windows Service Exit code: 0 Version: 1.0.5.0 Modules
| |||||||||||||||
| 4032 | "C:\Program Files\VestCert\VestCert.exe" | C:\Program Files\VestCert\VestCert.exe | Goji.exe | ||||||||||||
User: admin Company: Yettiesoft Integrity Level: MEDIUM Description: VestCert Exit code: 0 Version: 2.5.11.63 Modules
| |||||||||||||||
| (PID) Process: | (3992) Goji.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\SnowDaemonMaker |
| Operation: | write | Name: | Description |
Value: YettieSoft Service Daemon | |||
| (PID) Process: | (3992) Goji.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Yettiesoft\SnowDaemonMaker |
| Operation: | write | Name: | ConfigPath |
Value: conf\yDaemon.json | |||
| (PID) Process: | (3744) SetupPKG.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VestCert.{35C98F4B-AABD-43CB-9E08-B84B70B7FC07} |
| Operation: | write | Name: | DisplayName |
Value: VestCert | |||
| (PID) Process: | (3744) SetupPKG.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VestCert.{35C98F4B-AABD-43CB-9E08-B84B70B7FC07} |
| Operation: | write | Name: | UninstallString |
Value: C:\Program Files\SetupPkg.exe -uv | |||
| (PID) Process: | (3744) SetupPKG.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VestCert.{35C98F4B-AABD-43CB-9E08-B84B70B7FC07} |
| Operation: | write | Name: | Publisher |
Value: Crosscert | |||
| (PID) Process: | (3744) SetupPKG.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\VestCert.{35C98F4B-AABD-43CB-9E08-B84B70B7FC07} |
| Operation: | write | Name: | DisplayVersion |
Value: 2.5.11.63 | |||
| (PID) Process: | (3744) SetupPKG.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | VestCert Client |
Value: C:\Program Files\VestCert\VestCert.exe | |||
| (PID) Process: | (3744) SetupPKG.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MangoWire\shell\open\command |
| Operation: | write | Name: | |
Value: C:\Program Files\VestCert\VestCert.exe "%1" | |||
| (PID) Process: | (3744) SetupPKG.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MangoWire |
| Operation: | write | Name: | URL Protocol |
Value: | |||
| (PID) Process: | (3744) SetupPKG.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2212 | VestCertSetup.exe | C:\Users\admin\AppData\Local\Temp\7zSE1F5.tmp\NPKI\SignKorea\279696BEF384DC5901622423E2187BD3418D2D42_4098.der | der | |
MD5:0D3DD8492DA7764424902C30346A4EEF | SHA256:EFB2BAC7FDB49528B0ED679DBEF8C323FD42B472095192EBD94A9C3CA3AD54B6 | |||
| 2212 | VestCertSetup.exe | C:\Users\admin\AppData\Local\Temp\7zSE1F5.tmp\NPKI\TradeSign\2B7602AE825C7DEE81919EF5895BB9E2995BA9AF_10084.der | der | |
MD5:C2E0273D364B8629744D6B9F5AB50126 | SHA256:88C274840638CC0B2C8ACFDAD6F9594ECA423C197A39032A40C45F603C69F04A | |||
| 2212 | VestCertSetup.exe | C:\Users\admin\AppData\Local\Temp\7zSE1F5.tmp\NPKI\CrossCert\43D6F3657F659DCD6BC1CE730ABF3210A051E711_4126.der | der | |
MD5:78D9211607E40E4529A4EBD8950A5D65 | SHA256:1A37A4BB6A65E2E06466A250779D22DA2E90CD0C305FB057E78BD32A0111D237 | |||
| 2212 | VestCertSetup.exe | C:\Users\admin\AppData\Local\Temp\7zSE1F5.tmp\NPKI\SignKorea\045445B0DE12C4279CA04F02698BD55B14146307_4128.der | der | |
MD5:5BFE0C9F3CB29500F663B4B7F836AA64 | SHA256:F3F56CD450922C6E770996AF7A7EF733D5A0ED2BCB451488B85025164C9A9492 | |||
| 2212 | VestCertSetup.exe | C:\Users\admin\AppData\Local\Temp\7zSE1F5.tmp\NPKI\TradeSign\4D5D560A0703DF83CAF3D56D8F19FC12AC90A28A_4105.der | der | |
MD5:913113A4E0AE839CCA81C060475CD91F | SHA256:16AFC10A401DB5C68A50EAEDC76198757FD677CA20AA3F2FE6791C89F2C9B07F | |||
| 2212 | VestCertSetup.exe | C:\Users\admin\AppData\Local\Temp\7zSE1F5.tmp\NPKI\yessign\4AFBBD332D8BB1D18C946BFFE042365F1C91CB08_10080.der | der | |
MD5:3C358D13A20A45F6E879030550E35844 | SHA256:7C48FD35F6ABA2B1980E0DC0C041BEFA56A01D805A45A27DF44EECF182F4D881 | |||
| 2212 | VestCertSetup.exe | C:\Users\admin\AppData\Local\Temp\7zSE1F5.tmp\NPKI\KICA\B909F2B621489A2ABA025980862793166A77F559_10081.der | der | |
MD5:E84B8B1D46BF4C78B2A0534F0BBB10D1 | SHA256:1FCCBD01EDFC39A9D0A17695D8F7F5BC66A5C75EC05278C06F91BA5DCE321F62 | |||
| 2212 | VestCertSetup.exe | C:\Users\admin\AppData\Local\Temp\7zSE1F5.tmp\NPKI\TradeSign\B507236C57CF3EAE8EB532819F91A720DBE8EBE3_4127.der | der | |
MD5:7FA865B6927BBA7BE2E2AA4CE6CF3152 | SHA256:DF545CDEF6BC70A461534F15E9588AF2578EA41CFBAF2D0D5DFF6AB91866BD6E | |||
| 2212 | VestCertSetup.exe | C:\Users\admin\AppData\Local\Temp\7zSE1F5.tmp\NPKI\TradeSign\CE671644B27E73FD85A7CD0D1ED3F0D3A52D2639_10023.der | der | |
MD5:C453A50B70F62DF19580AF11E3FEF0B6 | SHA256:61A182145B4C94E982D3EA6C9D4F643EFA7ECFED2D56F11D805BD35F296CF12C | |||
| 2212 | VestCertSetup.exe | C:\Users\admin\AppData\Local\Temp\7zSE1F5.tmp\NPKI\KISA\BFB627D8035A76654C6101415631E58B7B3AD9CC_4.der | der | |
MD5:689B17C654E0E0E099551642F75A86D8 | SHA256:6FDB3F76C8B801A75338D8A50A7C02879F6198B57E594D318D3832900FEDCD79 | |||
Process | Message |
|---|---|
Goji.exe | TID:003892( INFO) PipeMonitor run.. |
Goji.exe | TID:003888( INFO) VestCert is not alive |
VestCert.exe |
%s------------------------------------------------
--- WinLicense Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|
Goji.exe | TID:003892( INFO) Pipe Client Connected(0) |
Goji.exe | TID:003892( INFO) Client programExeName : SetupPKG.exe autoStart = 1
|
VestCert.exe |
%s------------------------------------------------
--- WinLicense Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|