File name:

3.0_X-Lite_Win32_1006e_34025 12.exe

Full analysis: https://app.any.run/tasks/a227bf09-3b58-4232-80e6-67142fee315d
Verdict: Malicious activity
Analysis date: May 08, 2024, 06:12:17
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

6A58E670C74172D230613A0489C742FC

SHA1:

59B1F6191A68FED6C3AF4D2DF352EEA2C40D355D

SHA256:

09ECDB655E66D9ACA5F9534576D969670D49AF62F68688E8817E7A7EB6C57843

SSDEEP:

196608:icaS297x3CE8pXar9zDsWzaHp1AAf7GfX4:icaSWBn8pKr9zzaJ1/DoI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • 3.0_X-Lite_Win32_1006e_34025 12.exe (PID: 4092)
      • is-333QV.tmp (PID: 1020)
      • is-0HBFQ.exe (PID: 1092)
    • Changes the autorun value in the registry

      • is-333QV.tmp (PID: 1020)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 3.0_X-Lite_Win32_1006e_34025 12.exe (PID: 4092)
      • is-333QV.tmp (PID: 1020)
      • is-0HBFQ.exe (PID: 1092)
    • Process drops legitimate windows executable

      • is-333QV.tmp (PID: 1020)
    • Reads the Windows owner or organization settings

      • is-333QV.tmp (PID: 1020)
    • The process drops C-runtime libraries

      • is-333QV.tmp (PID: 1020)
    • Searches for installed software

      • is-333QV.tmp (PID: 1020)
    • The process executes via Task Scheduler

      • ctfmon.exe (PID: 1616)
      • sipnotify.exe (PID: 1540)
    • Reads the Internet Settings

      • sipnotify.exe (PID: 1540)
      • runonce.exe (PID: 1452)
      • x-lite.exe (PID: 2164)
    • Creates/Modifies COM task schedule object

      • is-0HBFQ.exe (PID: 1092)
    • Reads Microsoft Outlook installation path

      • x-lite.exe (PID: 2164)
    • Reads security settings of Internet Explorer

      • x-lite.exe (PID: 2164)
    • Reads Internet Explorer settings

      • x-lite.exe (PID: 2164)
    • Reads the BIOS version

      • x-lite.exe (PID: 2164)
  • INFO

    • Create files in a temporary directory

      • 3.0_X-Lite_Win32_1006e_34025 12.exe (PID: 4092)
      • is-333QV.tmp (PID: 1020)
    • Checks supported languages

      • 3.0_X-Lite_Win32_1006e_34025 12.exe (PID: 4092)
      • is-333QV.tmp (PID: 1020)
      • is-0HBFQ.exe (PID: 1092)
      • IMEKLMG.EXE (PID: 2140)
      • IMEKLMG.EXE (PID: 2132)
      • wmpnscfg.exe (PID: 2764)
      • wmpnscfg.exe (PID: 2788)
      • x-lite.exe (PID: 2164)
    • Reads the computer name

      • is-333QV.tmp (PID: 1020)
      • 3.0_X-Lite_Win32_1006e_34025 12.exe (PID: 4092)
      • IMEKLMG.EXE (PID: 2140)
      • IMEKLMG.EXE (PID: 2132)
      • x-lite.exe (PID: 2164)
      • wmpnscfg.exe (PID: 2764)
      • wmpnscfg.exe (PID: 2788)
    • Creates files in the program directory

      • is-333QV.tmp (PID: 1020)
    • Creates a software uninstall entry

      • is-333QV.tmp (PID: 1020)
    • Manual execution by a user

      • runonce.exe (PID: 1452)
      • IMEKLMG.EXE (PID: 2132)
      • IMEKLMG.EXE (PID: 2140)
      • x-lite.exe (PID: 2164)
      • wmpnscfg.exe (PID: 2788)
      • wmpnscfg.exe (PID: 2764)
    • Reads the time zone

      • runonce.exe (PID: 1452)
    • Reads security settings of Internet Explorer

      • runonce.exe (PID: 1452)
    • Process checks whether UAC notifications are on

      • IMEKLMG.EXE (PID: 2132)
      • IMEKLMG.EXE (PID: 2140)
    • Creates files or folders in the user directory

      • x-lite.exe (PID: 2164)
    • Checks proxy server information

      • x-lite.exe (PID: 2164)
    • Reads the machine GUID from the registry

      • x-lite.exe (PID: 2164)
    • Reads CPU info

      • x-lite.exe (PID: 2164)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable PowerBASIC/Win 9.x (51.2)
.exe | Inno Setup installer (37.9)
.exe | Win32 Executable Delphi generic (4.9)
.dll | Win32 Dynamic Link Library (generic) (2.2)
.exe | Win32 Executable (generic) (1.5)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 36864
InitializedDataSize: 16896
UninitializedDataSize: -
EntryPoint: 0x97f0
OSVersion: 1
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: This installation was built with Inno Setup: http://www.innosetup.com
CompanyName: CounterPath Solutions Inc.
FileDescription: X-Lite Setup
FileVersion:
LegalCopyright: (c) 2006 CounterPath Solutions Inc. All rights reserved.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
90
Monitored processes
12
Malicious processes
3
Suspicious processes
1

Behavior graph

Click at the process to see the details
start 3.0_x-lite_win32_1006e_34025 12.exe is-333qv.tmp ctfmon.exe no specs sipnotify.exe runonce.exe is-0hbfq.exe imeklmg.exe no specs imeklmg.exe no specs x-lite.exe no specs wmpnscfg.exe no specs wmpnscfg.exe no specs 3.0_x-lite_win32_1006e_34025 12.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1020"C:\Users\admin\AppData\Local\Temp\is-LOU6J.tmp\is-333QV.tmp" /SL4 $30138 "C:\Users\admin\AppData\Local\Temp\3.0_X-Lite_Win32_1006e_34025 12.exe" 7311221 52224 C:\Users\admin\AppData\Local\Temp\is-LOU6J.tmp\is-333QV.tmp
3.0_X-Lite_Win32_1006e_34025 12.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.42.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-lou6j.tmp\is-333qv.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1092"C:\Windows\is-0HBFQ.exe" /REGC:\Windows\is-0HBFQ.exe
runonce.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.42.0.0
Modules
Images
c:\windows\is-0hbfq.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1452runonce.exe /ExplorerC:\Windows\System32\runonce.exe
explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Run Once Wrapper
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\runonce.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
1540C:\Windows\system32\sipnotify.exe -LogonOrUnlockC:\Windows\System32\sipnotify.exe
taskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
sipnotify
Version:
6.1.7602.20480 (win7sp1_ldr_escrow.191010-1716)
Modules
Images
c:\windows\system32\sipnotify.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1616C:\Windows\System32\ctfmon.exe C:\Windows\System32\ctfmon.exetaskeng.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
CTF Loader
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\ctfmon.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\msctfmonitor.dll
c:\windows\system32\msctf.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
2132"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /JPN /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
2140"C:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXE" /SetPreload /KOR /LogC:\Program Files\Common Files\microsoft shared\IME14\SHARED\IMEKLMG.EXEexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Microsoft Office IME 2010
Exit code:
1
Version:
14.0.4734.1000
Modules
Images
c:\program files\common files\microsoft shared\ime14\shared\imeklmg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\userenv.dll
2164"C:\Program Files\CounterPath\X-Lite\x-lite.exe" C:\Program Files\CounterPath\X-Lite\x-lite.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Modules
Images
c:\program files\counterpath\x-lite\x-lite.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
2764"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2788"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
Total events
8 864
Read events
8 764
Write events
89
Delete events
11

Modification events

(PID) Process:(1020) is-333QV.tmpKey:HKEY_CURRENT_USER\Software\EBInstaller
Operation:writeName:InstallerName
Value:
3.0_X-Lite_Win32_1006e_34025 12.exe
(PID) Process:(1020) is-333QV.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Common Files\Intel\ataplugin\msvcr71.dll
Value:
1
(PID) Process:(1020) is-333QV.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Common Files\Intel\ataplugin\ATAPlugIn.ax
Value:
1
(PID) Process:(1020) is-333QV.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\SharedDLLs
Operation:writeName:C:\Program Files\Common Files\Microsoft Shared\Triedit\dhtmled.ocx
Value:
1
(PID) Process:(1020) is-333QV.tmpKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:eyeBeam SIP Client
Value:
"C:\Program Files\CounterPath\X-Lite\x-lite.exe"
(PID) Process:(1020) is-333QV.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\.eba
Operation:writeName:Content Type
Value:
application/eyebeam
(PID) Process:(1020) is-333QV.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\MIME\Database\Content Type\application/eyebeam
Operation:writeName:Extension
Value:
.eba
(PID) Process:(1020) is-333QV.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\eyeBeam.args
Operation:writeName:EditFlags
Value:
D8070100
(PID) Process:(1020) is-333QV.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Classes\sip
Operation:writeName:EditFlags
Value:
02000000
(PID) Process:(1020) is-333QV.tmpKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\Tcpip\Parameters
Operation:writeName:DisableUserTOSSetting
Value:
0
Executable files
34
Suspicious files
8
Text files
27
Unknown types
0

Dropped files

PID
Process
Filename
Type
1020is-333QV.tmpC:\Program Files\CounterPath\X-Lite\is-SDSKH.tmpexecutable
MD5:86F1895AE8C5E8B17D99ECE768A70732
SHA256:8094AF5EE310714CAEBCCAEEE7769FFB08048503BA478B879EDFEF5F1A24FEFE
1020is-333QV.tmpC:\Program Files\CounterPath\X-Lite\uninstall.icoimage
MD5:5A77AB01BB917BB0F539B07614A6135F
SHA256:16C1B2FA5AD3D758B51E1757B3AB6A1DD1E79391703010E7793CBC4B8F85E55F
1020is-333QV.tmpC:\Program Files\CounterPath\X-Lite\is-7VCLE.tmpexecutable
MD5:A7793B8B9FB0FF5B30B58F4FA173FCBA
SHA256:6B3B20611908A6A392B366D6D553F77E80DCFA18EFCD3B217D99BEDD65B0DC22
1020is-333QV.tmpC:\Program Files\CounterPath\X-Lite\unins000.exeexecutable
MD5:6831E53C1F7AAA8F5F0104E0E0CD6A9E
SHA256:A367BE631C73A8516BEB6F01045100B1DD1C033F7AF0D6F94B44A4F95E70AE46
1020is-333QV.tmpC:\Program Files\CounterPath\X-Lite\is-POM47.tmpexecutable
MD5:6831E53C1F7AAA8F5F0104E0E0CD6A9E
SHA256:A367BE631C73A8516BEB6F01045100B1DD1C033F7AF0D6F94B44A4F95E70AE46
1020is-333QV.tmpC:\Users\admin\AppData\Local\Temp\is-J9IE0.tmp\psvince.dllexecutable
MD5:A4E5C512B047A6D9DC38549161CAC4DE
SHA256:C7F1E7E866834D9024F97C2B145C09D106E447E8ABD65A10A1732116D178E44E
1020is-333QV.tmpC:\Program Files\CounterPath\X-Lite\msvcp71.dllexecutable
MD5:561FA2ABB31DFA8FAB762145F81667C2
SHA256:DF96156F6A548FD6FE5672918DE5AE4509D3C810A57BFFD2A91DE45A3ED5B23B
1020is-333QV.tmpC:\Program Files\CounterPath\X-Lite\AEC_PC_DLL.dllexecutable
MD5:1A0C0BBF24B8F710584E3DF14A77BF42
SHA256:3708906FE3B0493C161FA2EACD6A5E25FF752A0C9AEA719515AC0B1AB1FC3E8E
1020is-333QV.tmpC:\Program Files\CounterPath\X-Lite\is-UH9CB.tmpexecutable
MD5:561FA2ABB31DFA8FAB762145F81667C2
SHA256:DF96156F6A548FD6FE5672918DE5AE4509D3C810A57BFFD2A91DE45A3ED5B23B
1020is-333QV.tmpC:\Program Files\CounterPath\X-Lite\x-lite.exeexecutable
MD5:BA00755C6793E249F5A278BCC144C2CC
SHA256:C9503A656245A8D463946B47D8709CD2E468E72E54447238D9419179F5A16627
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
8
DNS requests
2
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1540
sipnotify.exe
HEAD
104.107.20.123:80
http://query.prod.cms.rt.microsoft.com/cms/api/am/binary/RE2JgkA?v=133596259984210000
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
unknown
224.0.0.252:5355
unknown
1100
svchost.exe
224.0.0.252:5355
unknown
1540
sipnotify.exe
104.107.20.123:80
query.prod.cms.rt.microsoft.com
AKAMAI-AS
US
unknown

DNS requests

Domain
IP
Reputation
query.prod.cms.rt.microsoft.com
  • 104.107.20.123
whitelisted
xlite.counterpath.com
  • 127.0.0.1
unknown

Threats

No threats detected
No debug info