File name: | synology-assistant-7.0.4-50051.exe |
Full analysis: | https://app.any.run/tasks/1ada8be9-f2f8-431f-9871-982cffd30190 |
Verdict: | Malicious activity |
Analysis date: | July 19, 2024, 18:04:52 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
MD5: | 52E3A08DB193757A35011A942AC8C6C8 |
SHA1: | 027E80A4A334035DE2DE84E65170B6DAB60FE510 |
SHA256: | 0858F796EB7FCEBE6B7108B247B28A47519E9A103CA57A66C6AD45161FE00249 |
SSDEEP: | 98304:7pqVROEewkySv3Jdvt6/jJCJ1vNZWvVIxjXWFvnbjqTcnRmWUWdUYuZagWO65eQn:qq/WFDMEncnRWwOMhxp2u/zW |
.exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
---|---|---|
.dll | | | Win32 Dynamic Link Library (generic) (14.2) |
.exe | | | Win32 Executable (generic) (9.7) |
.exe | | | Generic Win/DOS Executable (4.3) |
.exe | | | DOS Executable Generic (4.3) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2021:09:25 21:57:46+00:00 |
ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
PEType: | PE32 |
LinkerVersion: | 6 |
CodeSize: | 27136 |
InitializedDataSize: | 186880 |
UninitializedDataSize: | 2048 |
EntryPoint: | 0x352d |
OSVersion: | 4 |
ImageVersion: | 6 |
SubsystemVersion: | 4 |
Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1952 | UsbClientService.exe -start | C:\Program Files\Synology\Assistant\UsbClientService.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
2036 | rundll32.exe C:\Windows\system32\pnpui.dll,InstallSecurityPromptRunDllW 20 Global\{5b5ff258-363d-1286-6c62-0e446c62a004} Global\{259cad78-942f-3eff-a1c1-e2260613dd01} C:\Windows\System32\DriverStore\Temp\{7aec7285-626c-440e-b75b-2823d98a3d1a}\bus.inf C:\Windows\System32\DriverStore\Temp\{7aec7285-626c-440e-b75b-2823d98a3d1a}\synodriverx86.cat | C:\Windows\System32\rundll32.exe | — | drvinst.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2408 | "C:\Program Files\Synology\Assistant\UsbClientService.exe" | C:\Program Files\Synology\Assistant\UsbClientService.exe | — | services.exe | |||||||||||
User: SYSTEM Integrity Level: SYSTEM Modules
| |||||||||||||||
2524 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2580 | ..\devcon.exe update bus.inf root\busenum | C:\Program Files\Synology\Assistant\driver\version_release\x86\devcon.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Setup API Exit code: 2 Version: 6.1.7600.16385 (win7_wdk.100208-1538) Modules
| |||||||||||||||
2724 | DrvInst.exe "2" "211" "ROOT\USB\0000" "C:\Windows\INF\oem2.inf" "bus.inf:Standard:Virutal_USB:1.0.2.4:root\busenum" "674a88703" "0000030C" "000005F4" "000005F8" | C:\Windows\System32\drvinst.exe | svchost.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Driver Installation Module Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2852 | UsbClientService.exe -setup | C:\Program Files\Synology\Assistant\UsbClientService.exe | — | cmd.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
2900 | C:\Windows\system32\cmd.exe /c ""C:\Program Files\Synology\Assistant\install-service.bat" " | C:\Windows\System32\cmd.exe | — | synology-assistant-7.0.4-50051.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
2948 | C:\Windows\system32\cmd.exe /c ""C:\Program Files\Synology\Assistant\driver\version_release\x86\win7\install-driver.bat" " | C:\Windows\System32\cmd.exe | — | synology-assistant-7.0.4-50051.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
3324 | "C:\Program Files\Synology\Assistant\DSAssistant.exe" | C:\Program Files\Synology\Assistant\DSAssistant.exe | synology-assistant-7.0.4-50051.exe | ||||||||||||
User: admin Integrity Level: HIGH Modules
|
(PID) Process: | (3372) synology-assistant-7.0.4-50051.exe | Key: | HKEY_CURRENT_USER\Software\Synology\DSAssistant |
Operation: | write | Name: | Installer Language |
Value: 1033 | |||
(PID) Process: | (3372) synology-assistant-7.0.4-50051.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Synology Assistant |
Operation: | write | Name: | DisplayName |
Value: Synology Assistant (remove only) | |||
(PID) Process: | (3372) synology-assistant-7.0.4-50051.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Synology Assistant |
Operation: | write | Name: | UninstallString |
Value: C:\Program Files\Synology\Assistant\Uninstall.exe | |||
(PID) Process: | (3372) synology-assistant-7.0.4-50051.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Synology Assistant |
Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files\Synology\Assistant\DSAssistant.exe,0 | |||
(PID) Process: | (3372) synology-assistant-7.0.4-50051.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Synology Assistant |
Operation: | write | Name: | InstalledVersion |
Value: 50051 | |||
(PID) Process: | (3372) synology-assistant-7.0.4-50051.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Synology Assistant |
Operation: | write | Name: | DisplayVersion |
Value: 7.0.4-50051 | |||
(PID) Process: | (3372) synology-assistant-7.0.4-50051.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\Synology Assistant |
Operation: | write | Name: | Publisher |
Value: Synology | |||
(PID) Process: | (3372) synology-assistant-7.0.4-50051.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (3372) synology-assistant-7.0.4-50051.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (3372) synology-assistant-7.0.4-50051.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 |
PID | Process | Filename | Type | |
---|---|---|---|---|
3372 | synology-assistant-7.0.4-50051.exe | C:\Users\admin\AppData\Local\Temp\nsnE4A0.tmp\modern-wizard.bmp | image | |
MD5:CBE40FD2B1EC96DAEDC65DA172D90022 | SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2 | |||
3372 | synology-assistant-7.0.4-50051.exe | C:\Program Files\Synology\Assistant\concrt140.dll | executable | |
MD5:BB7293ADD679A5688FCDD03F44DE4B90 | SHA256:F3093CB216BF8ECC8D869E46D8CDA3AACA28A326CB865CCBEF329E1B13ABC834 | |||
3372 | synology-assistant-7.0.4-50051.exe | C:\Program Files\Synology\Assistant\DSAssistant.exe | executable | |
MD5:0F0D0AD7422CEA1A8AB66B2ED0213630 | SHA256:74C6F7420EA70EBCFE208605441D5B87ED1C940A8258D6936C6045C9CFF7C196 | |||
3372 | synology-assistant-7.0.4-50051.exe | C:\Users\admin\AppData\Local\Temp\nsnE4A0.tmp\UserInfo.dll | executable | |
MD5:2F69AFA9D17A5245EC9B5BB03D56F63C | SHA256:E54989D2B83E7282D0BEC56B098635146AAB5D5A283F1F89486816851EF885A0 | |||
3372 | synology-assistant-7.0.4-50051.exe | C:\Program Files\Synology\Assistant\DSAssistantStart.bat | text | |
MD5:2DCDEF6F4816BC89380022A043941DB1 | SHA256:4AFF687B7B613DC7A4619CB0F03872BCE685353AA3D41B774D51F2B786370061 | |||
3372 | synology-assistant-7.0.4-50051.exe | C:\Program Files\Synology\Assistant\Qt5Gui.dll | executable | |
MD5:D268011D393AB81C3BE2F7A20435BCB0 | SHA256:EB1111379DFDF84CF7F027837F54C4854EE4B1AC45A1716D8CF6D5A2D38A46A6 | |||
3372 | synology-assistant-7.0.4-50051.exe | C:\Program Files\Synology\Assistant\LICENSE | text | |
MD5:35AD1BA57C692DB0A3842EF181CA5593 | SHA256:B734A5EB74465F09DC6DE8E3355B9E181FC2949D12DD3654708F3B1DA5554794 | |||
3372 | synology-assistant-7.0.4-50051.exe | C:\Users\admin\AppData\Local\Temp\nsnE4A0.tmp\nsDialogs.dll | executable | |
MD5:6C3F8C94D0727894D706940A8A980543 | SHA256:56B96ADD1978B1ABBA286F7F8982B0EFBE007D4A48B3DED6A4D408E01D753FE2 | |||
3372 | synology-assistant-7.0.4-50051.exe | C:\Program Files\Synology\Assistant\UsbClientService.exe | executable | |
MD5:51581A26573D6FC3F9626C1B5F2CC508 | SHA256:F5CA6CCC3880204C25F7D83426927B13A6B0E787E1B8EF3DD3EAC51B9B617483 | |||
3372 | synology-assistant-7.0.4-50051.exe | C:\Program Files\Synology\Assistant\Qt5Widgets.dll | executable | |
MD5:6BCC8769D857F72E20C607B2B172D404 | SHA256:3866964F40840E6FA323494880578EA1D4D803B128FC12CDC5271F9072FF4696 |
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
---|---|---|---|---|---|---|---|---|---|
1372 | svchost.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?33775f6043c93e33 | unknown | — | — | whitelisted |
1372 | svchost.exe | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | whitelisted |
1372 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | whitelisted |
1060 | svchost.exe | GET | 304 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?fbe613066ac7852b | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1372 | svchost.exe | 4.231.128.59:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
1060 | svchost.exe | 224.0.0.252:5355 | — | — | — | whitelisted |
2564 | svchost.exe | 239.255.255.250:3702 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1372 | svchost.exe | 20.73.194.208:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1372 | svchost.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
1372 | svchost.exe | 23.48.23.143:80 | crl.microsoft.com | Akamai International B.V. | DE | unknown |
1372 | svchost.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | unknown |
Domain | IP | Reputation |
---|---|---|
google.com |
| whitelisted |
dns.msftncsi.com |
| whitelisted |
settings-win.data.microsoft.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
Process | Message |
---|---|
DSAssistant.exe | src\main.cpp:172 Version: 7.0.4-50051
|
DSAssistant.exe | ..\libcommon\SynoLocale.cpp:64 qPrintable(qstrLocaleLower)=[en_us
]
|
DSAssistant.exe | ..\libcommon\SynoLocale.cpp:80 qPrintable(qstrLocaleLower)=[en_us]
|
DSAssistant.exe | ..\libcommon\SynoLocale.cpp:161 qPrintable(qstrLangFileName)=[:/enu.qm]
|
DSAssistant.exe | ..\libcommon\SynoLocale.cpp:138 qPrintable(qstrDef)=[enu
]
|
DSAssistant.exe | ..\libcommon\SynoLocale.cpp:64 qPrintable(qstrLocaleLower)=[en_us
]
|
DSAssistant.exe | ..\libcommon\SynoLocale.cpp:80 qPrintable(qstrLocaleLower)=[en_us]
|
DSAssistant.exe | ..\libcommon\SynoLocale.cpp:161 qPrintable(qstrLangFileName)=[:/enu.qm]
|
DSAssistant.exe | ..\libcommon\SynoLocale.cpp:138 qPrintable(qstrDef)=[enu
]
|
DSAssistant.exe | src\WizardAddPrinter\CMultiFuncPtr.cpp:385 open PtrConf-file failed.
|