| File name: | xdiarys-setup-v3.exe |
| Full analysis: | https://app.any.run/tasks/f31536c9-3b85-4840-8ce0-2f50370e97c7 |
| Verdict: | Malicious activity |
| Analysis date: | January 22, 2025, 06:36:18 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections |
| MD5: | 3CC0ED5B796334F5289847CF2C5A5A63 |
| SHA1: | E252ECCBE10F95533E7A8069C0CC4FB4A15558FC |
| SHA256: | 280940BD8596AF876AFD81838B4BEDBCA034000CAC0D74523B94C68ECDF3E44F |
| SSDEEP: | 98304:TgwrX83Bzeu8D7+bcFw0nQV2ywVHJlQXRB6tNycB3w+JHYoQ39z1nvOcRbbw3k4B:GCr0ZZUcLMMW |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2010:04:10 12:19:31+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 25600 |
| InitializedDataSize: | 431104 |
| UninitializedDataSize: | 16896 |
| EntryPoint: | 0x354b |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.20.220.6960 |
| ProductVersionNumber: | 3.20.220.6960 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | ASCII |
| Comments: | https://service.xdiarys.com/api/jump/$CURRENTLANUAGE/1015?fp=client&cver=3.20.220.6960 |
| CompanyName: | Xiaowei Cloud, Inc. |
| FileDescription: | CalendarTask Installer |
| FileVersion: | 3.20.220.6960 |
| LegalCopyright: | Copyright (C) 2022 Beijing Xiaowei Cloud Inc. |
| LegalTrademarks: | Xiaowei Cloud, Inc. |
| ProductName: | XDiarys |
| ProductVersion: | 3.20.220.6960 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 6220 | C:\Users\admin\AppData\Roaming\CalendarTask\dkupdate.exe | C:\Users\admin\AppData\Roaming\CalendarTask\dkupdate.exe | desktopcal.exe | ||||||||||||
User: admin Company: Beijing Xiaowei Cloud Inc. Integrity Level: MEDIUM Description: dkupdate Module Exit code: 0 Version: 3.20.220.6960 Modules
| |||||||||||||||
| 6368 | "C:\Users\admin\Desktop\xdiarys-setup-v3.exe" | C:\Users\admin\Desktop\xdiarys-setup-v3.exe | explorer.exe | ||||||||||||
User: admin Company: Xiaowei Cloud, Inc. Integrity Level: MEDIUM Description: CalendarTask Installer Exit code: 0 Version: 3.20.220.6960 Modules
| |||||||||||||||
| 7000 | "C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe" -savelang.usa | C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe | — | xdiarys-setup-v3.exe | |||||||||||
User: admin Company: Beijing Xiaowei Cloud Inc. Integrity Level: MEDIUM Description: CalendarTask Exit code: 0 Version: 3.20.220.6960 Modules
| |||||||||||||||
| 7032 | "C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe" -savestart | C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe | xdiarys-setup-v3.exe | ||||||||||||
User: admin Company: Beijing Xiaowei Cloud Inc. Integrity Level: MEDIUM Description: CalendarTask Exit code: 0 Version: 3.20.220.6960 Modules
| |||||||||||||||
| 7068 | C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe | C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe | xdiarys-setup-v3.exe | ||||||||||||
User: admin Company: Beijing Xiaowei Cloud Inc. Integrity Level: MEDIUM Description: CalendarTask Version: 3.20.220.6960 Modules
| |||||||||||||||
| 7152 | "C:\Users\admin\AppData\Roaming\CalendarTask\dkdockhost.exe" | C:\Users\admin\AppData\Roaming\CalendarTask\dkdockhost.exe | — | desktopcal.exe | |||||||||||
User: admin Company: Beijing Xiaowei Cloud Inc. Integrity Level: MEDIUM Description: dkdockhostx64 Main Exe Version: 3.20.220.6960 Modules
| |||||||||||||||
| (PID) Process: | (6368) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys |
| Operation: | write | Name: | DisplayName |
Value: CalendarTask | |||
| (PID) Process: | (6368) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys |
| Operation: | write | Name: | UninstallString |
Value: "C:\Users\admin\AppData\Roaming\CalendarTask\uninst.exe" | |||
| (PID) Process: | (6368) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys |
| Operation: | write | Name: | DisplayIcon |
Value: "C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe" | |||
| (PID) Process: | (6368) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys |
| Operation: | write | Name: | InstallLocation |
Value: C:\Users\admin\AppData\Roaming\CalendarTask | |||
| (PID) Process: | (6368) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys |
| Operation: | write | Name: | Publisher |
Value: Xiaowei Cloud, Inc. | |||
| (PID) Process: | (6368) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys |
| Operation: | write | Name: | HelpLink |
Value: https://service.xdiarys.com/api/jump/usa/1015?fp=client&cver=3.20.220.6960 | |||
| (PID) Process: | (6368) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys |
| Operation: | write | Name: | DisplayVersion |
Value: 3.20.220.6960 | |||
| (PID) Process: | (6368) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | delete value | Name: | DesktopCal |
Value: | |||
| (PID) Process: | (7032) desktopcal.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | DesktopCal |
Value: C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe | |||
| (PID) Process: | (6368) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | GlobalAssocChangedCounter |
Value: 105 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6368 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_background.png | image | |
MD5:7F10E2778BE436731DD8491D492F5207 | SHA256:A0586FE99C9E0D1E94FBDC4173015DBC28735684813F50AED517AF8CF61BFFE0 | |||
| 6368 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_install_button.png | image | |
MD5:F517DD84352F5D249835C88F0A84036A | SHA256:05D9ABAE8A846365382F49906E81FA9188F245DC3FE1FE501A5DB68DEB07EC8E | |||
| 6368 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\nsm5BB2.tmp\System.dll | executable | |
MD5:959EA64598B9A3E494C00E8FA793BE7E | SHA256:03CD57AB00236C753E7DDEEE8EE1C10839ACE7C426769982365531042E1F6F8B | |||
| 6368 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_onseldirbutton.png | image | |
MD5:0589AADD0B30D883048C78A2D8153CCD | SHA256:EB4699A367DA4E4D91AB4D221EE684AE21ADA346E29DC8064486EB314B27BF5F | |||
| 6368 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_progress_bar_bk.png | image | |
MD5:5017B8B0EDC93FBCA26CB412262AC6EC | SHA256:0A9286DBA766DE0EABD58E9BFB489782C64DB16BFB3F978E94E5990E58CA09C8 | |||
| 6368 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_onkeyfinish.png | image | |
MD5:69E620A0A7483BC216B55D02E89D6D17 | SHA256:487DC7FFEB8439965DDA611A49455DD0C44B0487286E121795A147E65C6DFB7F | |||
| 6368 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_progress_title.png | image | |
MD5:A6AF35E0DB291DC9505E9438F9E97CE9 | SHA256:E540880ADE05D1826D5D6610A348E74B05E181D0330687BBDD039DC0EE4A6FAA | |||
| 6368 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_onkeyuninstall_cancel.png | image | |
MD5:9850CD6E0A2A0BD62BB31296B8868719 | SHA256:0620BA0669B5756B8FCBDB01940CA6DF9ADC0727FB2604FA804072BE317A82FB | |||
| 6368 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_progress_background.png | image | |
MD5:348F6DE2FBC51323084AC4BA3C9D2002 | SHA256:C43168DAA882B6715028D6FD6D69272DEF885FA13B94836B730BEC3FAF6854AF | |||
| 6368 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_progress_bar_bk2.png | image | |
MD5:B5DA69E41CCC3680DB7FA588D976E551 | SHA256:AFF54D285ABCE69B58F19E0E4D6625535F611AD39DD546E3F9BCB789FF6B17DC | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1176 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7068 | desktopcal.exe | GET | 200 | 47.92.228.218:80 | http://start.xdiarys.com/xdiarys/3.20.220.6960/usa/10/?uid=C_0-D_QM00001-M_40B9A9B2664A-V_26B799FA-T_F0_1737527803&login=0&vip=0&tn=&ec=0&c=&sd=&nets=0 | unknown | — | — | unknown |
5308 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
7068 | desktopcal.exe | GET | 200 | 47.92.228.218:80 | http://install.xdiarys.com/xdiarys/3.20.220.6960/usa/10/?uid=C_0-D_QM00001-M_40B9A9B2664A-V_26B799FA-T_F0_1737527803&login=0&vip=0&tn=&ec=0&c=&sd=&nets=0 | unknown | — | — | unknown |
5308 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
5208 | backgroundTaskHost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1176 | svchost.exe | 40.126.32.140:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1176 | svchost.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
1076 | svchost.exe | 184.28.89.167:443 | go.microsoft.com | AKAMAI-AS | US | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
7068 | desktopcal.exe | 47.254.26.67:443 | service2.xdiarys.com | Alibaba US Technology Co., Ltd. | US | suspicious |
7068 | desktopcal.exe | 47.92.228.218:80 | install.xdiarys.com | Hangzhou Alibaba Advertising Co.,Ltd. | CN | suspicious |
6220 | dkupdate.exe | 47.254.26.67:443 | service2.xdiarys.com | Alibaba US Technology Co., Ltd. | US | suspicious |
6092 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
service2.xdiarys.com |
| unknown |
install.xdiarys.com |
| unknown |
api-update2.xdiarys.com |
| unknown |
start.xdiarys.com |
| unknown |
settings-win.data.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
7068 | desktopcal.exe | Potential Corporate Privacy Violation | ET INFO Windows 98 User-Agent Detected - Possible Malware or Non-Updated System |
7068 | desktopcal.exe | Potential Corporate Privacy Violation | ET INFO Unsupported/Fake Internet Explorer Version MSIE 5. |
7068 | desktopcal.exe | Potential Corporate Privacy Violation | ET INFO Windows 98 User-Agent Detected - Possible Malware or Non-Updated System |
7068 | desktopcal.exe | Potential Corporate Privacy Violation | ET INFO Unsupported/Fake Internet Explorer Version MSIE 5. |