File name:

xdiarys-setup-v3.exe

Full analysis: https://app.any.run/tasks/f31536c9-3b85-4840-8ce0-2f50370e97c7
Verdict: Malicious activity
Analysis date: January 22, 2025, 06:36:18
OS: Windows 10 Professional (build: 19045, 64 bit)
Tags:
lua
Indicators:
MIME: application/vnd.microsoft.portable-executable
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections
MD5:

3CC0ED5B796334F5289847CF2C5A5A63

SHA1:

E252ECCBE10F95533E7A8069C0CC4FB4A15558FC

SHA256:

280940BD8596AF876AFD81838B4BEDBCA034000CAC0D74523B94C68ECDF3E44F

SSDEEP:

98304:TgwrX83Bzeu8D7+bcFw0nQV2ywVHJlQXRB6tNycB3w+JHYoQ39z1nvOcRbbw3k4B:GCr0ZZUcLMMW

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Changes the autorun value in the registry

      • desktopcal.exe (PID: 7032)
  • SUSPICIOUS

    • The process creates files with name similar to system file names

      • xdiarys-setup-v3.exe (PID: 6368)
    • There is functionality for taking screenshot (YARA)

      • xdiarys-setup-v3.exe (PID: 6368)
    • Executable content was dropped or overwritten

      • xdiarys-setup-v3.exe (PID: 6368)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • xdiarys-setup-v3.exe (PID: 6368)
    • The process drops C-runtime libraries

      • xdiarys-setup-v3.exe (PID: 6368)
    • Process drops legitimate windows executable

      • xdiarys-setup-v3.exe (PID: 6368)
    • Creates a software uninstall entry

      • xdiarys-setup-v3.exe (PID: 6368)
    • Checks Windows Trust Settings

      • dkupdate.exe (PID: 6220)
    • Reads security settings of Internet Explorer

      • dkupdate.exe (PID: 6220)
      • desktopcal.exe (PID: 7068)
    • Potential Corporate Privacy Violation

      • desktopcal.exe (PID: 7068)
  • INFO

    • Checks supported languages

      • xdiarys-setup-v3.exe (PID: 6368)
      • desktopcal.exe (PID: 7000)
      • desktopcal.exe (PID: 7032)
      • dkupdate.exe (PID: 6220)
      • desktopcal.exe (PID: 7068)
      • dkdockhost.exe (PID: 7152)
    • Create files in a temporary directory

      • xdiarys-setup-v3.exe (PID: 6368)
    • The sample compiled with english language support

      • xdiarys-setup-v3.exe (PID: 6368)
    • Reads the computer name

      • xdiarys-setup-v3.exe (PID: 6368)
      • desktopcal.exe (PID: 7032)
      • dkupdate.exe (PID: 6220)
      • desktopcal.exe (PID: 7000)
      • desktopcal.exe (PID: 7068)
    • The sample compiled with chinese language support

      • xdiarys-setup-v3.exe (PID: 6368)
    • Creates files or folders in the user directory

      • desktopcal.exe (PID: 7032)
      • desktopcal.exe (PID: 7068)
      • dkupdate.exe (PID: 6220)
      • desktopcal.exe (PID: 7000)
      • xdiarys-setup-v3.exe (PID: 6368)
    • The process uses the downloaded file

      • desktopcal.exe (PID: 7068)
      • dkupdate.exe (PID: 6220)
    • Reads the software policy settings

      • dkupdate.exe (PID: 6220)
    • Process checks computer location settings

      • desktopcal.exe (PID: 7068)
    • Checks proxy server information

      • dkupdate.exe (PID: 6220)
    • Reads the machine GUID from the registry

      • dkupdate.exe (PID: 6220)
    • The process uses Lua

      • desktopcal.exe (PID: 7068)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:04:10 12:19:31+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 25600
InitializedDataSize: 431104
UninitializedDataSize: 16896
EntryPoint: 0x354b
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 3.20.220.6960
ProductVersionNumber: 3.20.220.6960
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: ASCII
Comments: https://service.xdiarys.com/api/jump/$CURRENTLANUAGE/1015?fp=client&cver=3.20.220.6960
CompanyName: Xiaowei Cloud, Inc.
FileDescription: CalendarTask Installer
FileVersion: 3.20.220.6960
LegalCopyright: Copyright (C) 2022 Beijing Xiaowei Cloud Inc.
LegalTrademarks: Xiaowei Cloud, Inc.
ProductName: XDiarys
ProductVersion: 3.20.220.6960
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
136
Monitored processes
6
Malicious processes
1
Suspicious processes
2

Behavior graph

Click at the process to see the details
start xdiarys-setup-v3.exe desktopcal.exe no specs desktopcal.exe desktopcal.exe dkdockhost.exe no specs dkupdate.exe

Process information

PID
CMD
Path
Indicators
Parent process
6220C:\Users\admin\AppData\Roaming\CalendarTask\dkupdate.exeC:\Users\admin\AppData\Roaming\CalendarTask\dkupdate.exe
desktopcal.exe
User:
admin
Company:
Beijing Xiaowei Cloud Inc.
Integrity Level:
MEDIUM
Description:
dkupdate Module
Exit code:
0
Version:
3.20.220.6960
Modules
Images
c:\users\admin\appdata\roaming\calendartask\dkupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
6368"C:\Users\admin\Desktop\xdiarys-setup-v3.exe" C:\Users\admin\Desktop\xdiarys-setup-v3.exe
explorer.exe
User:
admin
Company:
Xiaowei Cloud, Inc.
Integrity Level:
MEDIUM
Description:
CalendarTask Installer
Exit code:
0
Version:
3.20.220.6960
Modules
Images
c:\users\admin\desktop\xdiarys-setup-v3.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7000"C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe" -savelang.usaC:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exexdiarys-setup-v3.exe
User:
admin
Company:
Beijing Xiaowei Cloud Inc.
Integrity Level:
MEDIUM
Description:
CalendarTask
Exit code:
0
Version:
3.20.220.6960
Modules
Images
c:\users\admin\appdata\roaming\calendartask\desktopcal.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7032"C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe" -savestartC:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe
xdiarys-setup-v3.exe
User:
admin
Company:
Beijing Xiaowei Cloud Inc.
Integrity Level:
MEDIUM
Description:
CalendarTask
Exit code:
0
Version:
3.20.220.6960
Modules
Images
c:\users\admin\appdata\roaming\calendartask\desktopcal.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7068C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exeC:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe
xdiarys-setup-v3.exe
User:
admin
Company:
Beijing Xiaowei Cloud Inc.
Integrity Level:
MEDIUM
Description:
CalendarTask
Version:
3.20.220.6960
Modules
Images
c:\users\admin\appdata\roaming\calendartask\desktopcal.exe
c:\windows\system32\ntdll.dll
c:\windows\syswow64\ntdll.dll
c:\windows\system32\wow64.dll
c:\windows\system32\wow64win.dll
c:\windows\system32\wow64cpu.dll
c:\windows\syswow64\kernel32.dll
c:\windows\syswow64\kernelbase.dll
c:\windows\syswow64\apphelp.dll
c:\windows\syswow64\user32.dll
7152"C:\Users\admin\AppData\Roaming\CalendarTask\dkdockhost.exe" C:\Users\admin\AppData\Roaming\CalendarTask\dkdockhost.exedesktopcal.exe
User:
admin
Company:
Beijing Xiaowei Cloud Inc.
Integrity Level:
MEDIUM
Description:
dkdockhostx64 Main Exe
Version:
3.20.220.6960
Modules
Images
c:\users\admin\appdata\roaming\calendartask\dkdockhost.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\system32\user32.dll
c:\windows\system32\win32u.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\gdi32full.dll
c:\windows\system32\msvcp_win.dll
Total events
3 426
Read events
3 416
Write events
9
Delete events
1

Modification events

(PID) Process:(6368) xdiarys-setup-v3.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys
Operation:writeName:DisplayName
Value:
CalendarTask
(PID) Process:(6368) xdiarys-setup-v3.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Roaming\CalendarTask\uninst.exe"
(PID) Process:(6368) xdiarys-setup-v3.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys
Operation:writeName:DisplayIcon
Value:
"C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe"
(PID) Process:(6368) xdiarys-setup-v3.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Roaming\CalendarTask
(PID) Process:(6368) xdiarys-setup-v3.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys
Operation:writeName:Publisher
Value:
Xiaowei Cloud, Inc.
(PID) Process:(6368) xdiarys-setup-v3.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys
Operation:writeName:HelpLink
Value:
https://service.xdiarys.com/api/jump/usa/1015?fp=client&cver=3.20.220.6960
(PID) Process:(6368) xdiarys-setup-v3.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys
Operation:writeName:DisplayVersion
Value:
3.20.220.6960
(PID) Process:(6368) xdiarys-setup-v3.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:DesktopCal
Value:
(PID) Process:(7032) desktopcal.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:DesktopCal
Value:
C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe
(PID) Process:(6368) xdiarys-setup-v3.exeKey:HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
105
Executable files
29
Suspicious files
97
Text files
53
Unknown types
0

Dropped files

PID
Process
Filename
Type
6368xdiarys-setup-v3.exeC:\Users\admin\AppData\Local\Temp\dkc_background.pngimage
MD5:7F10E2778BE436731DD8491D492F5207
SHA256:A0586FE99C9E0D1E94FBDC4173015DBC28735684813F50AED517AF8CF61BFFE0
6368xdiarys-setup-v3.exeC:\Users\admin\AppData\Local\Temp\dkc_install_button.pngimage
MD5:F517DD84352F5D249835C88F0A84036A
SHA256:05D9ABAE8A846365382F49906E81FA9188F245DC3FE1FE501A5DB68DEB07EC8E
6368xdiarys-setup-v3.exeC:\Users\admin\AppData\Local\Temp\nsm5BB2.tmp\System.dllexecutable
MD5:959EA64598B9A3E494C00E8FA793BE7E
SHA256:03CD57AB00236C753E7DDEEE8EE1C10839ACE7C426769982365531042E1F6F8B
6368xdiarys-setup-v3.exeC:\Users\admin\AppData\Local\Temp\dkc_onseldirbutton.pngimage
MD5:0589AADD0B30D883048C78A2D8153CCD
SHA256:EB4699A367DA4E4D91AB4D221EE684AE21ADA346E29DC8064486EB314B27BF5F
6368xdiarys-setup-v3.exeC:\Users\admin\AppData\Local\Temp\dkc_progress_bar_bk.pngimage
MD5:5017B8B0EDC93FBCA26CB412262AC6EC
SHA256:0A9286DBA766DE0EABD58E9BFB489782C64DB16BFB3F978E94E5990E58CA09C8
6368xdiarys-setup-v3.exeC:\Users\admin\AppData\Local\Temp\dkc_onkeyfinish.pngimage
MD5:69E620A0A7483BC216B55D02E89D6D17
SHA256:487DC7FFEB8439965DDA611A49455DD0C44B0487286E121795A147E65C6DFB7F
6368xdiarys-setup-v3.exeC:\Users\admin\AppData\Local\Temp\dkc_progress_title.pngimage
MD5:A6AF35E0DB291DC9505E9438F9E97CE9
SHA256:E540880ADE05D1826D5D6610A348E74B05E181D0330687BBDD039DC0EE4A6FAA
6368xdiarys-setup-v3.exeC:\Users\admin\AppData\Local\Temp\dkc_onkeyuninstall_cancel.pngimage
MD5:9850CD6E0A2A0BD62BB31296B8868719
SHA256:0620BA0669B5756B8FCBDB01940CA6DF9ADC0727FB2604FA804072BE317A82FB
6368xdiarys-setup-v3.exeC:\Users\admin\AppData\Local\Temp\dkc_progress_background.pngimage
MD5:348F6DE2FBC51323084AC4BA3C9D2002
SHA256:C43168DAA882B6715028D6FD6D69272DEF885FA13B94836B730BEC3FAF6854AF
6368xdiarys-setup-v3.exeC:\Users\admin\AppData\Local\Temp\dkc_progress_bar_bk2.pngimage
MD5:B5DA69E41CCC3680DB7FA588D976E551
SHA256:AFF54D285ABCE69B58F19E0E4D6625535F611AD39DD546E3F9BCB789FF6B17DC
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
6
TCP/UDP connections
31
DNS requests
18
Threats
4

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
1176
svchost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D
unknown
whitelisted
7068
desktopcal.exe
GET
200
47.92.228.218:80
http://start.xdiarys.com/xdiarys/3.20.220.6960/usa/10/?uid=C_0-D_QM00001-M_40B9A9B2664A-V_26B799FA-T_F0_1737527803&login=0&vip=0&tn=&ec=0&c=&sd=&nets=0
unknown
unknown
5308
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl
unknown
whitelisted
7068
desktopcal.exe
GET
200
47.92.228.218:80
http://install.xdiarys.com/xdiarys/3.20.220.6960/usa/10/?uid=C_0-D_QM00001-M_40B9A9B2664A-V_26B799FA-T_F0_1737527803&login=0&vip=0&tn=&ec=0&c=&sd=&nets=0
unknown
unknown
5308
SIHClient.exe
GET
200
95.101.149.131:80
http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl
unknown
whitelisted
5208
backgroundTaskHost.exe
GET
200
2.23.77.188:80
http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D
unknown
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
40.127.240.158:443
MICROSOFT-CORP-MSN-AS-BLOCK
IE
unknown
4
System
192.168.100.255:138
whitelisted
1176
svchost.exe
40.126.32.140:443
login.live.com
MICROSOFT-CORP-MSN-AS-BLOCK
NL
whitelisted
1176
svchost.exe
2.23.77.188:80
ocsp.digicert.com
AKAMAI-AS
DE
whitelisted
1076
svchost.exe
184.28.89.167:443
go.microsoft.com
AKAMAI-AS
US
whitelisted
4
System
192.168.100.255:137
whitelisted
7068
desktopcal.exe
47.254.26.67:443
service2.xdiarys.com
Alibaba US Technology Co., Ltd.
US
suspicious
7068
desktopcal.exe
47.92.228.218:80
install.xdiarys.com
Hangzhou Alibaba Advertising Co.,Ltd.
CN
suspicious
6220
dkupdate.exe
47.254.26.67:443
service2.xdiarys.com
Alibaba US Technology Co., Ltd.
US
suspicious
6092
svchost.exe
51.104.136.2:443
settings-win.data.microsoft.com
MICROSOFT-CORP-MSN-AS-BLOCK
IE
whitelisted

DNS requests

Domain
IP
Reputation
login.live.com
  • 40.126.32.140
  • 40.126.32.133
  • 20.190.160.17
  • 40.126.32.76
  • 40.126.32.68
  • 40.126.32.138
  • 40.126.32.134
  • 20.190.160.20
whitelisted
go.microsoft.com
  • 184.28.89.167
whitelisted
service2.xdiarys.com
  • 47.254.26.67
unknown
install.xdiarys.com
  • 47.92.228.218
unknown
api-update2.xdiarys.com
  • 47.254.26.67
unknown
start.xdiarys.com
  • 47.92.228.218
unknown
settings-win.data.microsoft.com
  • 51.104.136.2
  • 51.124.78.146
whitelisted
slscr.update.microsoft.com
  • 4.175.87.197
whitelisted
www.microsoft.com
  • 95.101.149.131
whitelisted
fe3cr.delivery.mp.microsoft.com
  • 40.69.42.241
whitelisted

Threats

PID
Process
Class
Message
7068
desktopcal.exe
Potential Corporate Privacy Violation
ET INFO Windows 98 User-Agent Detected - Possible Malware or Non-Updated System
7068
desktopcal.exe
Potential Corporate Privacy Violation
ET INFO Unsupported/Fake Internet Explorer Version MSIE 5.
7068
desktopcal.exe
Potential Corporate Privacy Violation
ET INFO Windows 98 User-Agent Detected - Possible Malware or Non-Updated System
7068
desktopcal.exe
Potential Corporate Privacy Violation
ET INFO Unsupported/Fake Internet Explorer Version MSIE 5.
No debug info