| File name: | xdiarys-setup-v3.exe |
| Full analysis: | https://app.any.run/tasks/f31536c9-3b85-4840-8ce0-2f50370e97c7 |
| Verdict: | Malicious activity |
| Analysis date: | January 22, 2025, 06:36:18 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/vnd.microsoft.portable-executable |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive, 5 sections |
| MD5: | 3CC0ED5B796334F5289847CF2C5A5A63 |
| SHA1: | E252ECCBE10F95533E7A8069C0CC4FB4A15558FC |
| SHA256: | 280940BD8596AF876AFD81838B4BEDBCA034000CAC0D74523B94C68ECDF3E44F |
| SSDEEP: | 98304:TgwrX83Bzeu8D7+bcFw0nQV2ywVHJlQXRB6tNycB3w+JHYoQ39z1nvOcRbbw3k4B:GCr0ZZUcLMMW |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2010:04:10 12:19:31+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 25600 |
| InitializedDataSize: | 431104 |
| UninitializedDataSize: | 16896 |
| EntryPoint: | 0x354b |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.20.220.6960 |
| ProductVersionNumber: | 3.20.220.6960 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | ASCII |
| Comments: | https://service.xdiarys.com/api/jump/$CURRENTLANUAGE/1015?fp=client&cver=3.20.220.6960 |
| CompanyName: | Xiaowei Cloud, Inc. |
| FileDescription: | CalendarTask Installer |
| FileVersion: | 3.20.220.6960 |
| LegalCopyright: | Copyright (C) 2022 Beijing Xiaowei Cloud Inc. |
| LegalTrademarks: | Xiaowei Cloud, Inc. |
| ProductName: | XDiarys |
| ProductVersion: | 3.20.220.6960 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 6220 | C:\Users\admin\AppData\Roaming\CalendarTask\dkupdate.exe | C:\Users\admin\AppData\Roaming\CalendarTask\dkupdate.exe | desktopcal.exe | ||||||||||||
User: admin Company: Beijing Xiaowei Cloud Inc. Integrity Level: MEDIUM Description: dkupdate Module Exit code: 0 Version: 3.20.220.6960 Modules
| |||||||||||||||
| 6368 | "C:\Users\admin\Desktop\xdiarys-setup-v3.exe" | C:\Users\admin\Desktop\xdiarys-setup-v3.exe | explorer.exe | ||||||||||||
User: admin Company: Xiaowei Cloud, Inc. Integrity Level: MEDIUM Description: CalendarTask Installer Exit code: 0 Version: 3.20.220.6960 Modules
| |||||||||||||||
| 7000 | "C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe" -savelang.usa | C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe | — | xdiarys-setup-v3.exe | |||||||||||
User: admin Company: Beijing Xiaowei Cloud Inc. Integrity Level: MEDIUM Description: CalendarTask Exit code: 0 Version: 3.20.220.6960 Modules
| |||||||||||||||
| 7032 | "C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe" -savestart | C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe | xdiarys-setup-v3.exe | ||||||||||||
User: admin Company: Beijing Xiaowei Cloud Inc. Integrity Level: MEDIUM Description: CalendarTask Exit code: 0 Version: 3.20.220.6960 Modules
| |||||||||||||||
| 7068 | C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe | C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe | xdiarys-setup-v3.exe | ||||||||||||
User: admin Company: Beijing Xiaowei Cloud Inc. Integrity Level: MEDIUM Description: CalendarTask Version: 3.20.220.6960 Modules
| |||||||||||||||
| 7152 | "C:\Users\admin\AppData\Roaming\CalendarTask\dkdockhost.exe" | C:\Users\admin\AppData\Roaming\CalendarTask\dkdockhost.exe | — | desktopcal.exe | |||||||||||
User: admin Company: Beijing Xiaowei Cloud Inc. Integrity Level: MEDIUM Description: dkdockhostx64 Main Exe Version: 3.20.220.6960 Modules
| |||||||||||||||
| (PID) Process: | (6368) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys |
| Operation: | write | Name: | DisplayName |
Value: CalendarTask | |||
| (PID) Process: | (6368) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys |
| Operation: | write | Name: | UninstallString |
Value: "C:\Users\admin\AppData\Roaming\CalendarTask\uninst.exe" | |||
| (PID) Process: | (6368) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys |
| Operation: | write | Name: | DisplayIcon |
Value: "C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe" | |||
| (PID) Process: | (6368) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys |
| Operation: | write | Name: | InstallLocation |
Value: C:\Users\admin\AppData\Roaming\CalendarTask | |||
| (PID) Process: | (6368) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys |
| Operation: | write | Name: | Publisher |
Value: Xiaowei Cloud, Inc. | |||
| (PID) Process: | (6368) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys |
| Operation: | write | Name: | HelpLink |
Value: https://service.xdiarys.com/api/jump/usa/1015?fp=client&cver=3.20.220.6960 | |||
| (PID) Process: | (6368) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys |
| Operation: | write | Name: | DisplayVersion |
Value: 3.20.220.6960 | |||
| (PID) Process: | (6368) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | delete value | Name: | DesktopCal |
Value: | |||
| (PID) Process: | (7032) desktopcal.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | DesktopCal |
Value: C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe | |||
| (PID) Process: | (6368) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | GlobalAssocChangedCounter |
Value: 105 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 6368 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\nsm5BB2.tmp\System.dll | executable | |
MD5:959EA64598B9A3E494C00E8FA793BE7E | SHA256:03CD57AB00236C753E7DDEEE8EE1C10839ACE7C426769982365531042E1F6F8B | |||
| 6368 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_progress_title.png | image | |
MD5:A6AF35E0DB291DC9505E9438F9E97CE9 | SHA256:E540880ADE05D1826D5D6610A348E74B05E181D0330687BBDD039DC0EE4A6FAA | |||
| 6368 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_onkeyfinish.png | image | |
MD5:69E620A0A7483BC216B55D02E89D6D17 | SHA256:487DC7FFEB8439965DDA611A49455DD0C44B0487286E121795A147E65C6DFB7F | |||
| 6368 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_progress_bar_go.png | image | |
MD5:0A535097BF2375674264D93DB75B7C87 | SHA256:2D0A117F54A5DF5CBD75620BFA70FCAFC098DBBF882F1FDA2C6AF73FA483C8AD | |||
| 6368 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_onkeybutton.png | image | |
MD5:F49B9FCF13339ED99722F9976CE0F32D | SHA256:AA24761F9FA2596C6C51FC81ADFCE41424F1F8F8E7A0047653A62FC8137F3E6F | |||
| 6368 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_bottom.png | image | |
MD5:0F07FE3EEC21FCDC8BF97BD865C6500B | SHA256:6F8CC3644F2095B33CBD5C31C4870D15EF04C9C7BE0126E4E66D40E888EB964D | |||
| 6368 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_install_button.png | image | |
MD5:F517DD84352F5D249835C88F0A84036A | SHA256:05D9ABAE8A846365382F49906E81FA9188F245DC3FE1FE501A5DB68DEB07EC8E | |||
| 6368 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_onkeyupgrade_upgrade.png | image | |
MD5:9C25F3AD7A18D989E0F3B569F60FC98B | SHA256:4783668B62E1062DD8D269D629EF66A32CC6F3E4615B7149A7C08C8F0374C2E9 | |||
| 6368 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_progress_bar_bk.png | image | |
MD5:5017B8B0EDC93FBCA26CB412262AC6EC | SHA256:0A9286DBA766DE0EABD58E9BFB489782C64DB16BFB3F978E94E5990E58CA09C8 | |||
| 6368 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkcuninstall.dll | executable | |
MD5:43563F07FF92D4968CF89F476023726D | SHA256:7AACD33A636F3D71CCA5251C56AE992FEBD14317E1F7793BC1370F292D1166B7 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1176 | svchost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | whitelisted |
7068 | desktopcal.exe | GET | 200 | 47.92.228.218:80 | http://start.xdiarys.com/xdiarys/3.20.220.6960/usa/10/?uid=C_0-D_QM00001-M_40B9A9B2664A-V_26B799FA-T_F0_1737527803&login=0&vip=0&tn=&ec=0&c=&sd=&nets=0 | unknown | — | — | unknown |
7068 | desktopcal.exe | GET | 200 | 47.92.228.218:80 | http://install.xdiarys.com/xdiarys/3.20.220.6960/usa/10/?uid=C_0-D_QM00001-M_40B9A9B2664A-V_26B799FA-T_F0_1737527803&login=0&vip=0&tn=&ec=0&c=&sd=&nets=0 | unknown | — | — | unknown |
5208 | backgroundTaskHost.exe | GET | 200 | 2.23.77.188:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAUZZSZEml49Gjh0j13P68w%3D | unknown | — | — | whitelisted |
5308 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | whitelisted |
5308 | SIHClient.exe | GET | 200 | 95.101.149.131:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 40.127.240.158:443 | — | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1176 | svchost.exe | 40.126.32.140:443 | login.live.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
1176 | svchost.exe | 2.23.77.188:80 | ocsp.digicert.com | AKAMAI-AS | DE | whitelisted |
1076 | svchost.exe | 184.28.89.167:443 | go.microsoft.com | AKAMAI-AS | US | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
7068 | desktopcal.exe | 47.254.26.67:443 | service2.xdiarys.com | Alibaba US Technology Co., Ltd. | US | suspicious |
7068 | desktopcal.exe | 47.92.228.218:80 | install.xdiarys.com | Hangzhou Alibaba Advertising Co.,Ltd. | CN | suspicious |
6220 | dkupdate.exe | 47.254.26.67:443 | service2.xdiarys.com | Alibaba US Technology Co., Ltd. | US | suspicious |
6092 | svchost.exe | 51.104.136.2:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | whitelisted |
Domain | IP | Reputation |
|---|---|---|
login.live.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
service2.xdiarys.com |
| unknown |
install.xdiarys.com |
| unknown |
api-update2.xdiarys.com |
| unknown |
start.xdiarys.com |
| unknown |
settings-win.data.microsoft.com |
| whitelisted |
slscr.update.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
fe3cr.delivery.mp.microsoft.com |
| whitelisted |
PID | Process | Class | Message |
|---|---|---|---|
7068 | desktopcal.exe | Potential Corporate Privacy Violation | ET INFO Windows 98 User-Agent Detected - Possible Malware or Non-Updated System |
7068 | desktopcal.exe | Potential Corporate Privacy Violation | ET INFO Unsupported/Fake Internet Explorer Version MSIE 5. |
7068 | desktopcal.exe | Potential Corporate Privacy Violation | ET INFO Windows 98 User-Agent Detected - Possible Malware or Non-Updated System |
7068 | desktopcal.exe | Potential Corporate Privacy Violation | ET INFO Unsupported/Fake Internet Explorer Version MSIE 5. |