| File name: | xdiarys-setup-v3.exe |
| Full analysis: | https://app.any.run/tasks/3cf58f38-394f-44a9-bd6f-9138730b5d4b |
| Verdict: | Malicious activity |
| Analysis date: | March 19, 2024, 05:07:35 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | C5D686E67D2FF55A064D6698AD848576 |
| SHA1: | 558316855FBE75E3AE1181E34F5562CD3174CD53 |
| SHA256: | 2F403DCF44183B84708B5020AA063FF6DD7DFAE94549D6562E76A909156C4722 |
| SSDEEP: | 98304:yT65+kpmbQQWAlZyHxypzjlk7hiHw13fOUDsUVXYovBS9Gul/4xBWx5fKlyIXu6L:hi6C559kT |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2010:04:10 12:19:31+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 25600 |
| InitializedDataSize: | 431104 |
| UninitializedDataSize: | 16896 |
| EntryPoint: | 0x354b |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.10.180.6460 |
| ProductVersionNumber: | 3.10.180.6460 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | ASCII |
| Comments: | https://service.xdiarys.com/api/jump/$CURRENTLANUAGE/1015?fp=client&cver=3.10.180.6460 |
| CompanyName: | Xiaowei Cloud, Inc. |
| FileDescription: | CalendarTask Installer |
| FileVersion: | 3.10.180.6460 |
| LegalCopyright: | Copyright (C) 2022 Beijing Xiaowei Cloud Inc. |
| LegalTrademarks: | Xiaowei Cloud, Inc. |
| ProductName: | XDiarys |
| ProductVersion: | 3.10.180.6460 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1572 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2292 | C:\Users\admin\AppData\Roaming\CalendarTask\dkupdate.exe | C:\Users\admin\AppData\Roaming\CalendarTask\dkupdate.exe | desktopcal.exe | ||||||||||||
User: admin Company: Beijing Xiaowei Cloud Inc. Integrity Level: MEDIUM Description: dkupdate Module Exit code: 0 Version: 3.10.180.6460 Modules
| |||||||||||||||
| 2692 | "C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe" -savestart | C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe | xdiarys-setup-v3.exe | ||||||||||||
User: admin Company: Beijing Xiaowei Cloud Inc. Integrity Level: MEDIUM Description: CalendarTask Exit code: 0 Version: 3.10.180.6460 Modules
| |||||||||||||||
| 3092 | "C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe" -savelang.usa | C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe | — | xdiarys-setup-v3.exe | |||||||||||
User: admin Company: Beijing Xiaowei Cloud Inc. Integrity Level: MEDIUM Description: CalendarTask Exit code: 0 Version: 3.10.180.6460 Modules
| |||||||||||||||
| 3392 | C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe | C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe | xdiarys-setup-v3.exe | ||||||||||||
User: admin Company: Beijing Xiaowei Cloud Inc. Integrity Level: MEDIUM Description: CalendarTask Exit code: 0 Version: 3.10.180.6460 Modules
| |||||||||||||||
| 4008 | "C:\Users\admin\AppData\Local\Temp\xdiarys-setup-v3.exe" | C:\Users\admin\AppData\Local\Temp\xdiarys-setup-v3.exe | explorer.exe | ||||||||||||
User: admin Company: Xiaowei Cloud, Inc. Integrity Level: MEDIUM Description: CalendarTask Installer Exit code: 0 Version: 3.10.180.6460 Modules
| |||||||||||||||
| (PID) Process: | (4008) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys |
| Operation: | write | Name: | DisplayName |
Value: CalendarTask 3.10.180.6460 | |||
| (PID) Process: | (4008) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys |
| Operation: | write | Name: | UninstallString |
Value: "C:\Users\admin\AppData\Roaming\CalendarTask\uninst.exe" | |||
| (PID) Process: | (4008) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys |
| Operation: | write | Name: | DisplayIcon |
Value: "C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe" | |||
| (PID) Process: | (4008) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys |
| Operation: | write | Name: | InstallLocation |
Value: C:\Users\admin\AppData\Roaming\CalendarTask | |||
| (PID) Process: | (4008) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys |
| Operation: | write | Name: | Publisher |
Value: Xiaowei Cloud, Inc. | |||
| (PID) Process: | (4008) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys |
| Operation: | write | Name: | HelpLink |
Value: https://service.xdiarys.com/api/jump/usa/1015?fp=client&cver=3.10.180.6460 | |||
| (PID) Process: | (4008) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\XDiarys |
| Operation: | write | Name: | DisplayVersion |
Value: 3.10.180.6460 | |||
| (PID) Process: | (4008) xdiarys-setup-v3.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run |
| Operation: | delete value | Name: | DesktopCal |
Value: | |||
| (PID) Process: | (2692) desktopcal.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | DesktopCal |
Value: C:\Users\admin\AppData\Roaming\CalendarTask\desktopcal.exe | |||
| (PID) Process: | (2292) dkupdate.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4008 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_background.png | image | |
MD5:7F10E2778BE436731DD8491D492F5207 | SHA256:A0586FE99C9E0D1E94FBDC4173015DBC28735684813F50AED517AF8CF61BFFE0 | |||
| 4008 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_onkeyfinish.png | image | |
MD5:69E620A0A7483BC216B55D02E89D6D17 | SHA256:487DC7FFEB8439965DDA611A49455DD0C44B0487286E121795A147E65C6DFB7F | |||
| 4008 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_install_button.png | image | |
MD5:F517DD84352F5D249835C88F0A84036A | SHA256:05D9ABAE8A846365382F49906E81FA9188F245DC3FE1FE501A5DB68DEB07EC8E | |||
| 4008 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_bottom.png | image | |
MD5:0F07FE3EEC21FCDC8BF97BD865C6500B | SHA256:6F8CC3644F2095B33CBD5C31C4870D15EF04C9C7BE0126E4E66D40E888EB964D | |||
| 4008 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_onkeyuninstall_cancel.png | image | |
MD5:9850CD6E0A2A0BD62BB31296B8868719 | SHA256:0620BA0669B5756B8FCBDB01940CA6DF9ADC0727FB2604FA804072BE317A82FB | |||
| 4008 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_close.png | image | |
MD5:E7A889B50AE9AFEFA73045BA670DB165 | SHA256:2A9DEF0150983B2D7176B61146DD57D05A44E0F4452AC0574E309542F3D9782B | |||
| 4008 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_onseldirbutton.png | image | |
MD5:0589AADD0B30D883048C78A2D8153CCD | SHA256:EB4699A367DA4E4D91AB4D221EE684AE21ADA346E29DC8064486EB314B27BF5F | |||
| 4008 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_progress_bar_go.png | image | |
MD5:0A535097BF2375674264D93DB75B7C87 | SHA256:2D0A117F54A5DF5CBD75620BFA70FCAFC098DBBF882F1FDA2C6AF73FA483C8AD | |||
| 4008 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_onlangbutton.png | image | |
MD5:3A9674DBCF2F39809A5E118A3A512409 | SHA256:2BE27CE3398D5F58504524F580C948F89712FF1DE89A99B54706C0E0C93BFF45 | |||
| 4008 | xdiarys-setup-v3.exe | C:\Users\admin\AppData\Local\Temp\dkc_progress_background.png | image | |
MD5:348F6DE2FBC51323084AC4BA3C9D2002 | SHA256:C43168DAA882B6715028D6FD6D69272DEF885FA13B94836B730BEC3FAF6854AF | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3392 | desktopcal.exe | GET | 200 | 8.210.118.237:80 | http://start.xdiarys.com/xdiarys/3.10.180.6460/usa/7/?uid=C_0-D_QM00001-M_12A9866C77DE-V_C4BA3647-T_F0_1710824879&login=0&vip=0&tn=&ec=0&c=&sd=&nets=0 | unknown | binary | 27 b | unknown |
2292 | dkupdate.exe | GET | 200 | 47.254.26.67:80 | http://api-update2.xdiarys.com/api/update?debug=0&t=1594984&ver=3.10.180.6460&lang=usa&os=7&key=&tn=&auto=1 | unknown | text | 188 b | unknown |
3392 | desktopcal.exe | GET | 200 | 47.254.26.67:80 | http://service2.xdiarys.com/api/holidays/legal | unknown | binary | 2.31 Kb | unknown |
3392 | desktopcal.exe | GET | 200 | 47.254.26.67:80 | http://service2.xdiarys.com/api/holidays/legal | unknown | binary | 2.31 Kb | unknown |
3392 | desktopcal.exe | GET | 200 | 8.210.118.237:80 | http://install.xdiarys.com/xdiarys/3.10.180.6460/usa/7/?uid=C_0-D_QM00001-M_12A9866C77DE-V_C4BA3647-T_F0_1710824879&login=0&vip=0&tn=&ec=0&c=&sd=&nets=0 | unknown | binary | 27 b | unknown |
3392 | desktopcal.exe | GET | 200 | 47.254.26.67:80 | http://analytics2.xdiarys.com/?ver=3.10.180.6460&lang=usa&os=7&ec=click&ea=maincal&el=link.cell.festival&uid=C_0-D_QM00001-M_12A9866C77DE-V_C4BA3647-T_F0_1710824879&t=1616546<=0 | unknown | text | 3 b | unknown |
3392 | desktopcal.exe | GET | 200 | 47.254.26.67:80 | http://api-update2.xdiarys.com/api/updateinfo/windows?os=6.1&ver=3.10.180.6460&iev=11.0&dwb=msedge.exe&lang=usa&uid=C_0-D_QM00001-M_12A9866C77DE-V_C4BA3647-T_F0_1710824879&v=0&login=0&tn=&rcmd=&ec=0&edc=0&sd=&hd=0&t=1595734 | unknown | binary | 1.14 Kb | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3392 | desktopcal.exe | 47.254.26.67:80 | api-update2.xdiarys.com | Alibaba US Technology Co., Ltd. | US | unknown |
2292 | dkupdate.exe | 47.254.26.67:80 | api-update2.xdiarys.com | Alibaba US Technology Co., Ltd. | US | unknown |
3392 | desktopcal.exe | 8.210.118.237:80 | install.xdiarys.com | Alibaba US Technology Co., Ltd. | HK | unknown |
Domain | IP | Reputation |
|---|---|---|
api-update2.xdiarys.com |
| unknown |
service2.xdiarys.com |
| unknown |
install.xdiarys.com |
| unknown |
start.xdiarys.com |
| unknown |
analytics2.xdiarys.com |
| unknown |
PID | Process | Class | Message |
|---|---|---|---|
3392 | desktopcal.exe | Potential Corporate Privacy Violation | ET POLICY Windows 98 User-Agent Detected - Possible Malware or Non-Updated System |
3392 | desktopcal.exe | Potential Corporate Privacy Violation | ET POLICY Windows 98 User-Agent Detected - Possible Malware or Non-Updated System |
3392 | desktopcal.exe | Potential Corporate Privacy Violation | ET POLICY Unsupported/Fake Internet Explorer Version MSIE 5. |
3392 | desktopcal.exe | Potential Corporate Privacy Violation | ET POLICY Unsupported/Fake Internet Explorer Version MSIE 5. |
3392 | desktopcal.exe | Potential Corporate Privacy Violation | ET POLICY Windows 98 User-Agent Detected - Possible Malware or Non-Updated System |
3392 | desktopcal.exe | Potential Corporate Privacy Violation | ET POLICY Windows 98 User-Agent Detected - Possible Malware or Non-Updated System |
3392 | desktopcal.exe | Potential Corporate Privacy Violation | ET POLICY Windows 98 User-Agent Detected - Possible Malware or Non-Updated System |
3392 | desktopcal.exe | Potentially Bad Traffic | ET HUNTING Suspicious Windows NT version 3 User-Agent |