download: | /codebase/WebComponents.exe |
Full analysis: | https://app.any.run/tasks/9582581f-1147-41ff-bf6d-ffb1aa92217f |
Verdict: | Malicious activity |
Analysis date: | July 22, 2024, 21:56:05 |
OS: | Windows 10 Professional (build: 19045, 64 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | F2791D947EDA0C930887E18A2D49747A |
SHA1: | D6B4E5C71AB6FFD15A91BCA4F1EBF1776A87319C |
SHA256: | 0FDCC55CCD23670429DEDDE4F66C93C0149E38A0E665D46FD3290D4EF7A83C61 |
SSDEEP: | 98304:ApWgxDYImYRqP4IpbplE0HpbH/g9aFAKbuErgAmFSku024CuLmeRAjlccJakSNwC:c |
.exe | | | Inno Setup installer (77.7) |
---|---|---|
.exe | | | Win32 Executable Delphi generic (10) |
.dll | | | Win32 Dynamic Link Library (generic) (4.6) |
.exe | | | Win32 Executable (generic) (3.1) |
.exe | | | Win16/32 Executable Delphi generic (1.4) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 1992:06:19 22:22:17+00:00 |
ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
PEType: | PE32 |
LinkerVersion: | 2.25 |
CodeSize: | 37376 |
InitializedDataSize: | 13312 |
UninitializedDataSize: | - |
EntryPoint: | 0x9978 |
OSVersion: | 1 |
ImageVersion: | 6 |
SubsystemVersion: | 4 |
Subsystem: | Windows GUI |
FileVersionNumber: | 3.0.5.51 |
ProductVersionNumber: | 0.0.0.0 |
FileFlagsMask: | 0x003f |
FileFlags: | (none) |
FileOS: | Win32 |
ObjectFileType: | Executable application |
FileSubtype: | - |
LanguageCode: | Chinese (Simplified) |
CharacterSet: | ASCII |
Comments: | 此安装程序由 Inno Setup 构建。 |
CompanyName: | |
FileDescription: | Web Components Setup |
FileVersion: | 3.0.5.51 |
LegalCopyright: | |
ProductName: | Web Components |
ProductVersion: | 3.0.5.51 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
1084 | "C:\Users\admin\AppData\Local\Temp\is-EA79J.tmp\WebComponents.tmp" /SL5="$501FC,1561784,51712,C:\Users\admin\AppData\Local\Temp\WebComponents.exe" | C:\Users\admin\AppData\Local\Temp\is-EA79J.tmp\WebComponents.tmp | — | WebComponents.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: 安装/卸载 Exit code: 0 Version: 51.49.0.0 Modules
| |||||||||||||||
1264 | "C:\Users\admin\AppData\Local\Temp\WebComponents.exe" | C:\Users\admin\AppData\Local\Temp\WebComponents.exe | explorer.exe | ||||||||||||
User: admin Company: Integrity Level: MEDIUM Description: Web Components Setup Exit code: 0 Version: 3.0.5.51 Modules
| |||||||||||||||
4196 | "C:\Users\admin\AppData\Local\Temp\WebComponents.exe" /SPAWNWND=$4003E /NOTIFYWND=$501FC | C:\Users\admin\AppData\Local\Temp\WebComponents.exe | WebComponents.tmp | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: Web Components Setup Exit code: 0 Version: 3.0.5.51 Modules
| |||||||||||||||
4444 | "C:\WINDOWS\system32\regsvr32.exe" /s "C:\Program Files (x86)\Web Components\WebVideoActiveX.ocx" | C:\Windows\SysWOW64\regsvr32.exe | WebComponents.tmp | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
5560 | C:\WINDOWS\System32\slui.exe -Embedding | C:\Windows\System32\slui.exe | — | svchost.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Activation Client Exit code: 0 Version: 10.0.19041.1 (WinBuild.160101.0800) Modules
| |||||||||||||||
5576 | "C:\Users\admin\AppData\Local\Temp\is-3MLF5.tmp\WebComponents.tmp" /SL5="$40054,1561784,51712,C:\Users\admin\AppData\Local\Temp\WebComponents.exe" /SPAWNWND=$4003E /NOTIFYWND=$501FC | C:\Users\admin\AppData\Local\Temp\is-3MLF5.tmp\WebComponents.tmp | WebComponents.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: 安装/卸载 Exit code: 0 Version: 51.49.0.0 Modules
|
(PID) Process: | (5576) WebComponents.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\MozillaPlugins\Web Components |
Operation: | write | Name: | Path |
Value: C:\Program Files (x86)\Web Components\npWebVideoPlugin.dll | |||
(PID) Process: | (4444) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{7F79CD87-2D7A-4086-807E-D5E1A3E37BE5}\TypeLib |
Operation: | write | Name: | Version |
Value: 1.0 | |||
(PID) Process: | (4444) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{7F79CD87-2D7A-4086-807E-D5E1A3E37BE5}\TypeLib |
Operation: | write | Name: | Version |
Value: 1.0 | |||
(PID) Process: | (4444) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\Interface\{DE8B9108-0847-49C1-8E58-5972B6137DFD}\TypeLib |
Operation: | write | Name: | Version |
Value: 1.0 | |||
(PID) Process: | (4444) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\Interface\{DE8B9108-0847-49C1-8E58-5972B6137DFD}\TypeLib |
Operation: | write | Name: | Version |
Value: 1.0 | |||
(PID) Process: | (4444) regsvr32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\WOW6432Node\CLSID\{E7EF736D-B4E6-4A5A-BA94-732D71107808}\InprocServer32 |
Operation: | write | Name: | ThreadingModel |
Value: Apartment | |||
(PID) Process: | (5576) WebComponents.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{03B13AF8-9625-478A-AF0E-205337B9415A}_is1 |
Operation: | write | Name: | Inno Setup: Setup Version |
Value: 5.2.3 | |||
(PID) Process: | (5576) WebComponents.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{03B13AF8-9625-478A-AF0E-205337B9415A}_is1 |
Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files (x86)\Web Components | |||
(PID) Process: | (5576) WebComponents.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{03B13AF8-9625-478A-AF0E-205337B9415A}_is1 |
Operation: | write | Name: | InstallLocation |
Value: C:\Program Files (x86)\Web Components\ | |||
(PID) Process: | (5576) WebComponents.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\WOW6432Node\Microsoft\Windows\CurrentVersion\Uninstall\{03B13AF8-9625-478A-AF0E-205337B9415A}_is1 |
Operation: | write | Name: | Inno Setup: Icon Group |
Value: WebComponents |
PID | Process | Filename | Type | |
---|---|---|---|---|
5576 | WebComponents.tmp | C:\Users\admin\AppData\Local\Temp\is-EQ220.tmp\_isetup\_setup64.tmp | executable | |
MD5:B4604F8CD050D7933012AE4AA98E1796 | SHA256:B50B7AC03EC6DA865BF4504C7AC1E52D9F5B67C7BCB3EC0DB59FAB24F1B471C5 | |||
1264 | WebComponents.exe | C:\Users\admin\AppData\Local\Temp\is-EA79J.tmp\WebComponents.tmp | executable | |
MD5:ADBBCF3057B0BA83F1DFEFFF18D0B116 | SHA256:D6E6BB562616B544BF7CF5F4AB515A6189B5ABDB29AE91A8C9189841CA8A7A47 | |||
5576 | WebComponents.tmp | C:\Program Files (x86)\Web Components\is-EPVA2.tmp | executable | |
MD5:1613EB7D65B23F96A8157C1034E72C2B | SHA256:8CCE7201A6254C357A0231E78485307F34A5182CD6A03CD235858FAA87E7FFF1 | |||
5576 | WebComponents.tmp | C:\Program Files (x86)\Web Components\unins000.exe | executable | |
MD5:5B319219B7AF9E89FB97B678ADB3CEDE | SHA256:7C432970740E1EEE682D3A9E3FBA1CCF5C68B0BB070F9DE303CE4D366824002E | |||
5576 | WebComponents.tmp | C:\Program Files (x86)\Web Components\is-QL0L4.tmp | executable | |
MD5:5B319219B7AF9E89FB97B678ADB3CEDE | SHA256:7C432970740E1EEE682D3A9E3FBA1CCF5C68B0BB070F9DE303CE4D366824002E | |||
5576 | WebComponents.tmp | C:\Program Files (x86)\Web Components\is-V6ST0.tmp | executable | |
MD5:50F700D0306CCEAF132E6B176BC081B3 | SHA256:5F7623FDC0C9592A5F4FD39AE639BFEF27EDD18141541A3BFF0AA6D67763E5CB | |||
5576 | WebComponents.tmp | C:\Program Files (x86)\Web Components\AudioIntercom.dll | executable | |
MD5:50F700D0306CCEAF132E6B176BC081B3 | SHA256:5F7623FDC0C9592A5F4FD39AE639BFEF27EDD18141541A3BFF0AA6D67763E5CB | |||
5576 | WebComponents.tmp | C:\Program Files (x86)\Web Components\NetStream.dll | executable | |
MD5:1613EB7D65B23F96A8157C1034E72C2B | SHA256:8CCE7201A6254C357A0231E78485307F34A5182CD6A03CD235858FAA87E7FFF1 | |||
5576 | WebComponents.tmp | C:\Program Files (x86)\Web Components\is-TUEF0.tmp | executable | |
MD5:52C83A72943B529B7F495B0606C117B6 | SHA256:B21AE0059A8182A51D1645A44F403429E60E26453353C0D708D7F501557CA01C | |||
5576 | WebComponents.tmp | C:\Program Files (x86)\Web Components\OpenAL32.dll | executable | |
MD5:52C83A72943B529B7F495B0606C117B6 | SHA256:B21AE0059A8182A51D1645A44F403429E60E26453353C0D708D7F501557CA01C |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
3076 | RUXIMICS.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
6012 | MoUsoCoreWorker.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
3704 | svchost.exe | 40.127.240.158:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
— | — | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4204 | svchost.exe | 4.209.32.198:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
3704 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5720 | slui.exe | 40.91.76.224:443 | activation-v2.sls.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
5368 | SearchApp.exe | 92.122.215.53:443 | www.bing.com | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
google.com |
| whitelisted |
activation-v2.sls.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
arc.msn.com |
| whitelisted |
client.wns.windows.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
Process | Message |
---|---|
regsvr32.exe | [Debug]StreamTranClient---Create asyncio queue succ!
|
regsvr32.exe | [Info]StreamTranClient---version:this RTSP version is 1.1.2.18 2015_02_04..
|
regsvr32.exe | [Info]StreamTranClient---version:this RTSP version is asyn..
|
regsvr32.exe | [Debug]StreamTranClient---Destroy asyncio queue succ!
|