File name:

xdiarys-setup-v3.exe

Full analysis: https://app.any.run/tasks/3cf58f38-394f-44a9-bd6f-9138730b5d4b
Verdict: Malicious activity
Analysis date: March 19, 2024, 05:07:35
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

C5D686E67D2FF55A064D6698AD848576

SHA1:

558316855FBE75E3AE1181E34F5562CD3174CD53

SHA256:

2F403DCF44183B84708B5020AA063FF6DD7DFAE94549D6562E76A909156C4722

SSDEEP:

98304:yT65+kpmbQQWAlZyHxypzjlk7hiHw13fOUDsUVXYovBS9Gul/4xBWx5fKlyIXu6L:hi6C559kT

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • xdiarys-setup-v3.exe (PID: 4008)
    • Changes the autorun value in the registry

      • desktopcal.exe (PID: 2692)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • xdiarys-setup-v3.exe (PID: 4008)
    • Process drops legitimate windows executable

      • xdiarys-setup-v3.exe (PID: 4008)
    • The process drops C-runtime libraries

      • xdiarys-setup-v3.exe (PID: 4008)
    • The process creates files with name similar to system file names

      • xdiarys-setup-v3.exe (PID: 4008)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • xdiarys-setup-v3.exe (PID: 4008)
    • Creates a software uninstall entry

      • xdiarys-setup-v3.exe (PID: 4008)
    • Reads the Internet Settings

      • dkupdate.exe (PID: 2292)
    • Process requests binary or script from the Internet

      • desktopcal.exe (PID: 3392)
    • Reads security settings of Internet Explorer

      • dkupdate.exe (PID: 2292)
  • INFO

    • Checks supported languages

      • xdiarys-setup-v3.exe (PID: 4008)
      • desktopcal.exe (PID: 2692)
      • desktopcal.exe (PID: 3092)
      • desktopcal.exe (PID: 3392)
      • dkupdate.exe (PID: 2292)
      • wmpnscfg.exe (PID: 1572)
    • Reads the computer name

      • xdiarys-setup-v3.exe (PID: 4008)
      • dkupdate.exe (PID: 2292)
      • desktopcal.exe (PID: 3392)
      • wmpnscfg.exe (PID: 1572)
    • Reads Environment values

      • xdiarys-setup-v3.exe (PID: 4008)
    • Creates files or folders in the user directory

      • xdiarys-setup-v3.exe (PID: 4008)
      • desktopcal.exe (PID: 2692)
      • desktopcal.exe (PID: 3092)
      • desktopcal.exe (PID: 3392)
      • dkupdate.exe (PID: 2292)
    • Create files in a temporary directory

      • xdiarys-setup-v3.exe (PID: 4008)
    • Checks proxy server information

      • dkupdate.exe (PID: 2292)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 1572)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:04:10 12:19:31+00:00
ImageFileCharacteristics: No relocs, Executable, 32-bit
PEType: PE32
LinkerVersion: 9
CodeSize: 25600
InitializedDataSize: 431104
UninitializedDataSize: 16896
EntryPoint: 0x354b
OSVersion: 5
ImageVersion: 6
SubsystemVersion: 5
Subsystem: Windows GUI
FileVersionNumber: 3.10.180.6460
ProductVersionNumber: 3.10.180.6460
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: ASCII
Comments: https://service.xdiarys.com/api/jump/$CURRENTLANUAGE/1015?fp=client&cver=3.10.180.6460
CompanyName: Xiaowei Cloud, Inc.
FileDescription: CalendarTask Installer
FileVersion: 3.10.180.6460
LegalCopyright: Copyright (C) 2022 Beijing Xiaowei Cloud Inc.
LegalTrademarks: Xiaowei Cloud, Inc.
ProductName: XDiarys
ProductVersion: 3.10.180.6460
No data.
screenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
42
Monitored processes
6
Malicious processes
1
Suspicious processes
3

Behavior graph

Click at the process to see the details
start xdiarys-setup-v3.exe desktopcal.exe no specs desktopcal.exe desktopcal.exe dkupdate.exe wmpnscfg.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
1572"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
2292C:\Users\admin\AppData\Roaming\CalendarTask\dkupdate.exeC:\Users\admin\AppData\Roaming\CalendarTask\dkupdate.exe
desktopcal.exe
User:
admin
Company:
Beijing Xiaowei Cloud Inc.
Integrity Level:
MEDIUM
Description:
dkupdate Module
Exit code:
0
Version:
3.10.180.6460
Modules
Images
c:\users\admin\appdata\roaming\calendartask\dkupdate.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2692"C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe" -savestartC:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe
xdiarys-setup-v3.exe
User:
admin
Company:
Beijing Xiaowei Cloud Inc.
Integrity Level:
MEDIUM
Description:
CalendarTask
Exit code:
0
Version:
3.10.180.6460
Modules
Images
c:\users\admin\appdata\roaming\calendartask\desktopcal.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3092"C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe" -savelang.usaC:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exexdiarys-setup-v3.exe
User:
admin
Company:
Beijing Xiaowei Cloud Inc.
Integrity Level:
MEDIUM
Description:
CalendarTask
Exit code:
0
Version:
3.10.180.6460
Modules
Images
c:\users\admin\appdata\roaming\calendartask\desktopcal.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3392C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exeC:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe
xdiarys-setup-v3.exe
User:
admin
Company:
Beijing Xiaowei Cloud Inc.
Integrity Level:
MEDIUM
Description:
CalendarTask
Exit code:
0
Version:
3.10.180.6460
Modules
Images
c:\users\admin\appdata\roaming\calendartask\desktopcal.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
4008"C:\Users\admin\AppData\Local\Temp\xdiarys-setup-v3.exe" C:\Users\admin\AppData\Local\Temp\xdiarys-setup-v3.exe
explorer.exe
User:
admin
Company:
Xiaowei Cloud, Inc.
Integrity Level:
MEDIUM
Description:
CalendarTask Installer
Exit code:
0
Version:
3.10.180.6460
Modules
Images
c:\users\admin\appdata\local\temp\xdiarys-setup-v3.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
12 349
Read events
12 326
Write events
18
Delete events
5

Modification events

(PID) Process:(4008) xdiarys-setup-v3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys
Operation:writeName:DisplayName
Value:
CalendarTask 3.10.180.6460
(PID) Process:(4008) xdiarys-setup-v3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys
Operation:writeName:UninstallString
Value:
"C:\Users\admin\AppData\Roaming\CalendarTask\uninst.exe"
(PID) Process:(4008) xdiarys-setup-v3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys
Operation:writeName:DisplayIcon
Value:
"C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe"
(PID) Process:(4008) xdiarys-setup-v3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys
Operation:writeName:InstallLocation
Value:
C:\Users\admin\AppData\Roaming\CalendarTask
(PID) Process:(4008) xdiarys-setup-v3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys
Operation:writeName:Publisher
Value:
Xiaowei Cloud, Inc.
(PID) Process:(4008) xdiarys-setup-v3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys
Operation:writeName:HelpLink
Value:
https://service.xdiarys.com/api/jump/usa/1015?fp=client&cver=3.10.180.6460
(PID) Process:(4008) xdiarys-setup-v3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys
Operation:writeName:DisplayVersion
Value:
3.10.180.6460
(PID) Process:(4008) xdiarys-setup-v3.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:delete valueName:DesktopCal
Value:
(PID) Process:(2692) desktopcal.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:DesktopCal
Value:
C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe
(PID) Process:(2292) dkupdate.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
Executable files
27
Suspicious files
41
Text files
55
Unknown types
46

Dropped files

PID
Process
Filename
Type
4008xdiarys-setup-v3.exeC:\Users\admin\AppData\Local\Temp\dkc_background.pngimage
MD5:7F10E2778BE436731DD8491D492F5207
SHA256:A0586FE99C9E0D1E94FBDC4173015DBC28735684813F50AED517AF8CF61BFFE0
4008xdiarys-setup-v3.exeC:\Users\admin\AppData\Local\Temp\dkc_onkeyfinish.pngimage
MD5:69E620A0A7483BC216B55D02E89D6D17
SHA256:487DC7FFEB8439965DDA611A49455DD0C44B0487286E121795A147E65C6DFB7F
4008xdiarys-setup-v3.exeC:\Users\admin\AppData\Local\Temp\dkc_install_button.pngimage
MD5:F517DD84352F5D249835C88F0A84036A
SHA256:05D9ABAE8A846365382F49906E81FA9188F245DC3FE1FE501A5DB68DEB07EC8E
4008xdiarys-setup-v3.exeC:\Users\admin\AppData\Local\Temp\dkc_bottom.pngimage
MD5:0F07FE3EEC21FCDC8BF97BD865C6500B
SHA256:6F8CC3644F2095B33CBD5C31C4870D15EF04C9C7BE0126E4E66D40E888EB964D
4008xdiarys-setup-v3.exeC:\Users\admin\AppData\Local\Temp\dkc_onkeyuninstall_cancel.pngimage
MD5:9850CD6E0A2A0BD62BB31296B8868719
SHA256:0620BA0669B5756B8FCBDB01940CA6DF9ADC0727FB2604FA804072BE317A82FB
4008xdiarys-setup-v3.exeC:\Users\admin\AppData\Local\Temp\dkc_close.pngimage
MD5:E7A889B50AE9AFEFA73045BA670DB165
SHA256:2A9DEF0150983B2D7176B61146DD57D05A44E0F4452AC0574E309542F3D9782B
4008xdiarys-setup-v3.exeC:\Users\admin\AppData\Local\Temp\dkc_onseldirbutton.pngimage
MD5:0589AADD0B30D883048C78A2D8153CCD
SHA256:EB4699A367DA4E4D91AB4D221EE684AE21ADA346E29DC8064486EB314B27BF5F
4008xdiarys-setup-v3.exeC:\Users\admin\AppData\Local\Temp\dkc_progress_bar_go.pngimage
MD5:0A535097BF2375674264D93DB75B7C87
SHA256:2D0A117F54A5DF5CBD75620BFA70FCAFC098DBBF882F1FDA2C6AF73FA483C8AD
4008xdiarys-setup-v3.exeC:\Users\admin\AppData\Local\Temp\dkc_onlangbutton.pngimage
MD5:3A9674DBCF2F39809A5E118A3A512409
SHA256:2BE27CE3398D5F58504524F580C948F89712FF1DE89A99B54706C0E0C93BFF45
4008xdiarys-setup-v3.exeC:\Users\admin\AppData\Local\Temp\dkc_progress_background.pngimage
MD5:348F6DE2FBC51323084AC4BA3C9D2002
SHA256:C43168DAA882B6715028D6FD6D69272DEF885FA13B94836B730BEC3FAF6854AF
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
12
DNS requests
7
Threats
8

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3392
desktopcal.exe
GET
200
8.210.118.237:80
http://start.xdiarys.com/xdiarys/3.10.180.6460/usa/7/?uid=C_0-D_QM00001-M_12A9866C77DE-V_C4BA3647-T_F0_1710824879&login=0&vip=0&tn=&ec=0&c=&sd=&nets=0
unknown
binary
27 b
unknown
2292
dkupdate.exe
GET
200
47.254.26.67:80
http://api-update2.xdiarys.com/api/update?debug=0&t=1594984&ver=3.10.180.6460&lang=usa&os=7&key=&tn=&auto=1
unknown
text
188 b
unknown
3392
desktopcal.exe
GET
200
47.254.26.67:80
http://service2.xdiarys.com/api/holidays/legal
unknown
binary
2.31 Kb
unknown
3392
desktopcal.exe
GET
200
47.254.26.67:80
http://service2.xdiarys.com/api/holidays/legal
unknown
binary
2.31 Kb
unknown
3392
desktopcal.exe
GET
200
8.210.118.237:80
http://install.xdiarys.com/xdiarys/3.10.180.6460/usa/7/?uid=C_0-D_QM00001-M_12A9866C77DE-V_C4BA3647-T_F0_1710824879&login=0&vip=0&tn=&ec=0&c=&sd=&nets=0
unknown
binary
27 b
unknown
3392
desktopcal.exe
GET
200
47.254.26.67:80
http://analytics2.xdiarys.com/?ver=3.10.180.6460&lang=usa&os=7&ec=click&ea=maincal&el=link.cell.festival&uid=C_0-D_QM00001-M_12A9866C77DE-V_C4BA3647-T_F0_1710824879&t=1616546&lt=0
unknown
text
3 b
unknown
3392
desktopcal.exe
GET
200
47.254.26.67:80
http://api-update2.xdiarys.com/api/updateinfo/windows?os=6.1&ver=3.10.180.6460&iev=11.0&dwb=msedge.exe&lang=usa&uid=C_0-D_QM00001-M_12A9866C77DE-V_C4BA3647-T_F0_1710824879&v=0&login=0&tn=&rcmd=&ec=0&edc=0&sd=&hd=0&t=1595734
unknown
binary
1.14 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
224.0.0.252:5355
unknown
1080
svchost.exe
224.0.0.252:5355
unknown
3392
desktopcal.exe
47.254.26.67:80
api-update2.xdiarys.com
Alibaba US Technology Co., Ltd.
US
unknown
2292
dkupdate.exe
47.254.26.67:80
api-update2.xdiarys.com
Alibaba US Technology Co., Ltd.
US
unknown
3392
desktopcal.exe
8.210.118.237:80
install.xdiarys.com
Alibaba US Technology Co., Ltd.
HK
unknown

DNS requests

Domain
IP
Reputation
api-update2.xdiarys.com
  • 47.254.26.67
unknown
service2.xdiarys.com
  • 47.254.26.67
unknown
install.xdiarys.com
  • 8.210.118.237
unknown
start.xdiarys.com
  • 8.210.118.237
unknown
analytics2.xdiarys.com
  • 47.254.26.67
unknown

Threats

PID
Process
Class
Message
3392
desktopcal.exe
Potential Corporate Privacy Violation
ET POLICY Windows 98 User-Agent Detected - Possible Malware or Non-Updated System
3392
desktopcal.exe
Potential Corporate Privacy Violation
ET POLICY Windows 98 User-Agent Detected - Possible Malware or Non-Updated System
3392
desktopcal.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Internet Explorer Version MSIE 5.
3392
desktopcal.exe
Potential Corporate Privacy Violation
ET POLICY Unsupported/Fake Internet Explorer Version MSIE 5.
3392
desktopcal.exe
Potential Corporate Privacy Violation
ET POLICY Windows 98 User-Agent Detected - Possible Malware or Non-Updated System
3392
desktopcal.exe
Potential Corporate Privacy Violation
ET POLICY Windows 98 User-Agent Detected - Possible Malware or Non-Updated System
3392
desktopcal.exe
Potential Corporate Privacy Violation
ET POLICY Windows 98 User-Agent Detected - Possible Malware or Non-Updated System
3392
desktopcal.exe
Potentially Bad Traffic
ET HUNTING Suspicious Windows NT version 3 User-Agent
No debug info