| File name: | EasyBCD202.4.exe |
| Full analysis: | https://app.any.run/tasks/47fccdbb-5e44-443a-91ad-d230caa42ee4 |
| Verdict: | Malicious activity |
| Analysis date: | February 18, 2024, 21:28:31 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 2E06476EBE1137F543EE7176D34716E7 |
| SHA1: | 6EAA6AA0E829CE8AF54213F6DE77E748C4388E23 |
| SHA256: | 0A94A43AF2DB7BDBADA87B34BF03D3B221110D1CA21BBEBEC55B08767C1281CC |
| SSDEEP: | 98304:ilHlURur2ooGWFdzLmi9pimQ43ZIbI7KjDgXC5b7V6n0pWzvx4X1aex55V9WSdzu:hBma |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:01:30 03:57:38+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 25088 |
| InitializedDataSize: | 118784 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x3328 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 764 | "C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bcdedit.exe" /set {345b4700-a9f9-11e7-a83c-e8a4f72b1d33} device partition=C: | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bcdedit.exe | — | UtfRedirect.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Boot Configuration Data Editor Exit code: 0 Version: 6.2.8250.0 (winmain_win8beta.120217-1520) Modules
| |||||||||||||||
| 796 | "C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bootgrabber.exe" /tlist | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bootgrabber.exe | — | EasyBCD.exe | |||||||||||
User: admin Company: NeoSmart Technologies Integrity Level: HIGH Description: EasyBCD boot helper Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 924 | "C:\Program Files\NeoSmart Technologies\EasyBCD\bin\UtfRedirect.exe" | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\UtfRedirect.exe | — | EasyBCD.exe | |||||||||||
User: admin Company: NeoSmart Technologies Integrity Level: HIGH Description: UTF8 codepage proxy application Exit code: 1 Version: 1.0.0.1 Modules
| |||||||||||||||
| 968 | "C:\Program Files\NeoSmart Technologies\EasyBCD\bin\UtfRedirect.exe" | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\UtfRedirect.exe | — | EasyBCD.exe | |||||||||||
User: admin Company: NeoSmart Technologies Integrity Level: HIGH Description: UTF8 codepage proxy application Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 1336 | "C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bcdedit.exe" /export "C:\Users\admin\Documents\EasyBCD Backup (2024-02-18).bcd" | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bcdedit.exe | — | UtfRedirect.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Boot Configuration Data Editor Exit code: 0 Version: 6.2.8250.0 (winmain_win8beta.120217-1520) Modules
| |||||||||||||||
| 1368 | "C:\Program Files\NeoSmart Technologies\EasyBCD\bin\UtfRedirect.exe" | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\UtfRedirect.exe | — | EasyBCD.exe | |||||||||||
User: admin Company: NeoSmart Technologies Integrity Level: HIGH Description: UTF8 codepage proxy application Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 1624 | "C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bcdedit.exe" /set {current} BootMenuPolicy Standard | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bcdedit.exe | — | UtfRedirect.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Boot Configuration Data Editor Exit code: 0 Version: 6.2.8250.0 (winmain_win8beta.120217-1520) Modules
| |||||||||||||||
| 1636 | "C:\Program Files\NeoSmart Technologies\EasyBCD\bin\UtfRedirect.exe" | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\UtfRedirect.exe | — | EasyBCD.exe | |||||||||||
User: admin Company: NeoSmart Technologies Integrity Level: HIGH Description: UTF8 codepage proxy application Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 1728 | "C:\Program Files\NeoSmart Technologies\EasyBCD\bin\UtfRedirect.exe" | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\UtfRedirect.exe | — | EasyBCD.exe | |||||||||||
User: admin Company: NeoSmart Technologies Integrity Level: HIGH Description: UTF8 codepage proxy application Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 2068 | "C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bcdedit.exe" /displayorder {345b4700-a9f9-11e7-a83c-e8a4f72b1d33} /addlast | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bcdedit.exe | — | UtfRedirect.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Boot Configuration Data Editor Exit code: 0 Version: 6.2.8250.0 (winmain_win8beta.120217-1520) Modules
| |||||||||||||||
| (PID) Process: | (2844) EasyBCD202.4.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2844) EasyBCD202.4.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2844) EasyBCD202.4.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2844) EasyBCD202.4.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2844) EasyBCD202.4.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyBCD |
| Operation: | write | Name: | DisplayName |
Value: EasyBCD 2.4 | |||
| (PID) Process: | (2844) EasyBCD202.4.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyBCD |
| Operation: | write | Name: | UninstallString |
Value: C:\Program Files\NeoSmart Technologies\EasyBCD\uninstall.exe | |||
| (PID) Process: | (2844) EasyBCD202.4.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyBCD |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files\NeoSmart Technologies\EasyBCD\EasyBCD.exe | |||
| (PID) Process: | (2844) EasyBCD202.4.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyBCD |
| Operation: | write | Name: | HelpLink |
Value: http://neosmart.net/forums/ | |||
| (PID) Process: | (2844) EasyBCD202.4.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyBCD |
| Operation: | write | Name: | URLUpdateInfo |
Value: http://neosmart.net/EasyBCD/ | |||
| (PID) Process: | (2844) EasyBCD202.4.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyBCD |
| Operation: | write | Name: | VersionMajor |
Value: 2 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2844 | EasyBCD202.4.exe | C:\Users\admin\AppData\Local\Temp\nsyF0CA.tmp\modern-wizard.bmp | image | |
MD5:1ED71CEF099AE50505B5F495CC50E2A2 | SHA256:B177ADA6638B5869390C39405CAF5BEF6FA74AFAFE00BCD14DE5282867E47A26 | |||
| 2844 | EasyBCD202.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\NeoSmart.Localization.dll | executable | |
MD5:AD0A59AE87D4BA106E965C62F0BC3D88 | SHA256:3A56005B2EFB34620019EF432FE90EEB63726FC78B37BE841F25C2AED82EB1DB | |||
| 2844 | EasyBCD202.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\NST Downloader.exe | executable | |
MD5:A5B3EA9EE11E9752417159BA1C618B95 | SHA256:B92B2FA8916C78CCFFEF058D3BE900C840CB996028D373BA55985FD1D1DDDAC8 | |||
| 2844 | EasyBCD202.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\Newtonsoft.Json.dll | executable | |
MD5:0953851089821550EF013B487DA3915A | SHA256:4A56EF352F84AD19C1B4486C7C9E64FEF9A67C464C62E51BABABA79CD2D89551 | |||
| 2844 | EasyBCD202.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\LICENSE | text | |
MD5:2458D2762467CD07CC91448A30A2E572 | SHA256:FFBFE4D5757BD4315B79F55B9151625C29110EA16ABF81517D27E17136BF4094 | |||
| 2844 | EasyBCD202.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bcdedit.exe | executable | |
MD5:A60CBAEA0F8AC802D21C0CC7BC2589BE | SHA256:8BF1B71182FED18D6B4112BDC4D496800B5BF6681DE4C4F6536BA67378F38A12 | |||
| 2844 | EasyBCD202.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bcdboot.exe | executable | |
MD5:9F9E397630A146E875735F2F42339E6B | SHA256:9898F537B8D3097A05B42F42523CD66FCA7C020E8083EDBE461E6D9A12DD168E | |||
| 2844 | EasyBCD202.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\UtfRedirect.exe | executable | |
MD5:5B40791899FA37507E7C08BC3D9F5294 | SHA256:5A87D9485F6E13EE2C3BA4AC289A3E237D17A43ED428B8A5BD5F00FC4800D1AC | |||
| 2844 | EasyBCD202.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\EasyBCD.exe.config | xml | |
MD5:3379AC7243ADCFA51A02295DBEDC956A | SHA256:7EC2512B59E62A3AEB0A1025BF152A31291E17E7E469CE18EFAE153064665B03 | |||
| 2844 | EasyBCD202.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\udefrag.exe | executable | |
MD5:B28589BDE044417287D73EAC95142958 | SHA256:0863BE7C3A6D3FF526E2C333F605E6FC4ED96BF71DD8FD8F8B81489F721FFC52 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2072 | msfeedssync.exe | GET | 302 | 23.35.238.131:80 | http://go.microsoft.com/fwlink/?LinkId=121315 | unknown | — | — | unknown |
3960 | EasyBCD.exe | GET | 200 | 142.250.184.243:80 | http://rss.neosmart.net/neosmart | unknown | html | 15.6 Kb | unknown |
2072 | msfeedssync.exe | GET | 304 | 184.24.77.173:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?c9413ea79f67e7c7 | unknown | — | — | unknown |
2072 | msfeedssync.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D | unknown | binary | 471 b | unknown |
2072 | msfeedssync.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D | unknown | binary | 471 b | unknown |
2072 | msfeedssync.exe | GET | 302 | 23.35.238.131:80 | http://go.microsoft.com/fwlink/?LinkId=129794 | unknown | — | — | unknown |
2072 | msfeedssync.exe | GET | 200 | 2.21.20.137:80 | http://rssgov.windows.microsoft.com/usagovrssfeed.rss | unknown | xml | 658 b | unknown |
2072 | msfeedssync.exe | GET | 302 | 23.35.238.131:80 | http://go.microsoft.com/fwlink/?LinkId=129793 | unknown | — | — | unknown |
2072 | msfeedssync.exe | GET | 302 | 23.35.238.131:80 | http://go.microsoft.com/fwlink/?LinkId=68928 | unknown | — | — | unknown |
2072 | msfeedssync.exe | GET | 200 | 2.21.20.137:80 | http://rssgov.windows.microsoft.com/usagovrssfeed.rss | unknown | xml | 658 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3960 | EasyBCD.exe | 18.245.60.5:443 | api.neosmart.net | — | US | unknown |
3960 | EasyBCD.exe | 65.182.170.12:80 | feeds.neosmart.net | NETSOURCE | US | unknown |
2072 | msfeedssync.exe | 23.35.238.131:80 | go.microsoft.com | AKAMAI-AS | DE | unknown |
2072 | msfeedssync.exe | 204.79.197.203:443 | www.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2072 | msfeedssync.exe | 184.30.21.171:443 | www.microsoft.com | AKAMAI-AS | DE | unknown |
3960 | EasyBCD.exe | 142.250.184.243:80 | rss.neosmart.net | GOOGLE | US | unknown |
2072 | msfeedssync.exe | 184.24.77.173:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
api.neosmart.net |
| unknown |
feeds.neosmart.net |
| unknown |
go.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
www.msn.com |
| whitelisted |
rss.neosmart.net |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
rss.msn.com |
| whitelisted |
rssgov.windows.microsoft.com |
| whitelisted |