| File name: | EasyBCD2.4.exe |
| Full analysis: | https://app.any.run/tasks/a2b0d85f-e3d8-448a-b7d1-6f1d64a69c5c |
| Verdict: | Malicious activity |
| Analysis date: | December 13, 2023, 03:07:52 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 2E06476EBE1137F543EE7176D34716E7 |
| SHA1: | 6EAA6AA0E829CE8AF54213F6DE77E748C4388E23 |
| SHA256: | 0A94A43AF2DB7BDBADA87B34BF03D3B221110D1CA21BBEBEC55B08767C1281CC |
| SSDEEP: | 98304:ilHlURur2ooGWFdzLmi9pimQ43ZIbI7KjDgXC5b7V6n0pWzvx4X1aex55V9WSdzu:hBma |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:01:30 04:57:38+01:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 25088 |
| InitializedDataSize: | 118784 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x3328 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 276 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2064 | "C:\Program Files\NeoSmart Technologies\EasyBCD\bin\UtfRedirect.exe" | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\UtfRedirect.exe | — | EasyBCD.exe | |||||||||||
User: admin Company: NeoSmart Technologies Integrity Level: HIGH Description: UTF8 codepage proxy application Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 2076 | "C:\Users\admin\AppData\Local\Temp\EasyBCD2.4.exe" | C:\Users\admin\AppData\Local\Temp\EasyBCD2.4.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 2424 | "C:\Users\admin\AppData\Local\Temp\EasyBCD2.4.exe" | C:\Users\admin\AppData\Local\Temp\EasyBCD2.4.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2544 | "C:\Windows\System32\taskkill.exe" /f /im easybcd.exe | C:\Windows\System32\taskkill.exe | — | EasyBCD2.4.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2608 | "C:\Windows\System32\msfeedssync.exe" forcesync | C:\Windows\System32\msfeedssync.exe | EasyBCD.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Feeds Synchronization Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2716 | "C:\Program Files\NeoSmart Technologies\EasyBCD\EasyBCD.exe" | C:\Program Files\NeoSmart Technologies\EasyBCD\EasyBCD.exe | EasyBCD2.4.exe | ||||||||||||
User: admin Company: NeoSmart Technologies Integrity Level: HIGH Description: EasyBCD Exit code: 0 Version: 2.4.0.237 Modules
| |||||||||||||||
| 3124 | "C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bcdedit.exe" /v | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bcdedit.exe | — | UtfRedirect.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Boot Configuration Data Editor Exit code: 0 Version: 6.2.8250.0 (winmain_win8beta.120217-1520) Modules
| |||||||||||||||
| 3496 | msfeedssync.exe sync | C:\Windows\System32\msfeedssync.exe | — | EasyBCD.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Feeds Synchronization Exit code: 1 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 3656 | "C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bcdedit.exe" /export "C:\Users\admin\Documents\EasyBCD Backup (2023-12-13).bcd" | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bcdedit.exe | — | UtfRedirect.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Boot Configuration Data Editor Exit code: 0 Version: 6.2.8250.0 (winmain_win8beta.120217-1520) Modules
| |||||||||||||||
| (PID) Process: | (2424) EasyBCD2.4.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2424) EasyBCD2.4.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2424) EasyBCD2.4.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2424) EasyBCD2.4.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2716) EasyBCD.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2716) EasyBCD.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2716) EasyBCD.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2716) EasyBCD.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2716) EasyBCD.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
| Operation: | write | Name: | CachePrefix |
Value: Cookie: | |||
| (PID) Process: | (2716) EasyBCD.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\History |
| Operation: | write | Name: | CachePrefix |
Value: Visited: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2424 | EasyBCD2.4.exe | C:\Users\admin\AppData\Local\Temp\nsnBD.tmp\InstallOptions.dll | executable | |
MD5:8D5A5529462A9BA1AC068EE0502578C7 | SHA256:E625DCD0188594B1289891B64DEBDDEB5159ACA182B83A12675427B320BF7790 | |||
| 2424 | EasyBCD2.4.exe | C:\Users\admin\AppData\Local\Temp\nsnBD.tmp\ioSpecial.ini | text | |
MD5:E2D5070BC28DB1AC745613689FF86067 | SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0 | |||
| 2424 | EasyBCD2.4.exe | C:\Users\admin\AppData\Local\Temp\nsnBD.tmp\System.dll | executable | |
MD5:B0C77267F13B2F87C084FD86EF51CCFC | SHA256:A0CAC4CF4852895619BC7743EBEB89F9E4927CCDB9E66B1BCD92A4136D0F9C77 | |||
| 2424 | EasyBCD2.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\Newtonsoft.Json.dll | executable | |
MD5:0953851089821550EF013B487DA3915A | SHA256:4A56EF352F84AD19C1B4486C7C9E64FEF9A67C464C62E51BABABA79CD2D89551 | |||
| 2424 | EasyBCD2.4.exe | C:\Users\admin\AppData\Local\Temp\nsnBD.tmp\modern-wizard.bmp | image | |
MD5:1ED71CEF099AE50505B5F495CC50E2A2 | SHA256:B177ADA6638B5869390C39405CAF5BEF6FA74AFAFE00BCD14DE5282867E47A26 | |||
| 2424 | EasyBCD2.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\LICENSE | text | |
MD5:2458D2762467CD07CC91448A30A2E572 | SHA256:FFBFE4D5757BD4315B79F55B9151625C29110EA16ABF81517D27E17136BF4094 | |||
| 2424 | EasyBCD2.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bcdboot.exe | executable | |
MD5:9F9E397630A146E875735F2F42339E6B | SHA256:9898F537B8D3097A05B42F42523CD66FCA7C020E8083EDBE461E6D9A12DD168E | |||
| 2424 | EasyBCD2.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\NeoSmart.Localization.dll | executable | |
MD5:AD0A59AE87D4BA106E965C62F0BC3D88 | SHA256:3A56005B2EFB34620019EF432FE90EEB63726FC78B37BE841F25C2AED82EB1DB | |||
| 2424 | EasyBCD2.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\EasyBCD.exe | executable | |
MD5:E478C92160A3C73C77CDC9F515DFD8B0 | SHA256:6A6E16C176004128B918EF3F9ECF1D51D828E6099FBA6542B5AC6ABDB67C1030 | |||
| 2424 | EasyBCD2.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bcdedit.exe | executable | |
MD5:A60CBAEA0F8AC802D21C0CC7BC2589BE | SHA256:8BF1B71182FED18D6B4112BDC4D496800B5BF6681DE4C4F6536BA67378F38A12 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 302 | 65.182.170.12:80 | http://feeds.neosmart.net/neosmart | unknown | html | 145 b | unknown |
2716 | EasyBCD.exe | GET | 200 | 142.250.187.115:80 | http://rss.neosmart.net/neosmart | unknown | xml | 73.4 Kb | unknown |
2608 | msfeedssync.exe | GET | 302 | 184.30.17.189:80 | http://go.microsoft.com/fwlink/?LinkId=68929 | unknown | — | — | unknown |
2608 | msfeedssync.exe | GET | 200 | 93.184.221.240:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?705e3222d91267aa | unknown | compressed | 4.66 Kb | unknown |
2608 | msfeedssync.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEA177el9ggmWelJjG4vdGL0%3D | unknown | binary | 471 b | unknown |
2608 | msfeedssync.exe | GET | 302 | 184.30.17.189:80 | http://go.microsoft.com/fwlink/?LinkId=44406 | unknown | — | — | unknown |
2608 | msfeedssync.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEA7y5dg2gVICVeksYI%2B8L%2FQ%3D | unknown | binary | 313 b | unknown |
2608 | msfeedssync.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D | unknown | binary | 471 b | unknown |
2608 | msfeedssync.exe | GET | 200 | 142.250.187.115:80 | http://rss.neosmart.net/neosmart | unknown | xml | 73.4 Kb | unknown |
2608 | msfeedssync.exe | GET | 302 | 184.30.17.189:80 | http://go.microsoft.com/fwlink/?LinkId=129794 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2716 | EasyBCD.exe | 18.245.60.5:443 | api.neosmart.net | — | US | unknown |
2716 | EasyBCD.exe | 65.182.170.12:80 | feeds.neosmart.net | NETSOURCE | US | unknown |
2608 | msfeedssync.exe | 184.30.17.189:80 | go.microsoft.com | AKAMAI-AS | DE | unknown |
2608 | msfeedssync.exe | 184.30.21.171:443 | www.microsoft.com | AKAMAI-AS | DE | unknown |
2608 | msfeedssync.exe | 204.79.197.203:443 | www.msn.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2716 | EasyBCD.exe | 142.250.187.115:80 | rss.neosmart.net | GOOGLE | US | unknown |
Domain | IP | Reputation |
|---|---|---|
api.neosmart.net |
| unknown |
feeds.neosmart.net |
| unknown |
go.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
rss.neosmart.net |
| unknown |
www.msn.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
rss.msn.com |
| whitelisted |
rssgov.windows.microsoft.com |
| whitelisted |