| File name: | Offline eBIRForms Package v7.9.4.2 setup.exe |
| Full analysis: | https://app.any.run/tasks/01bfe109-7ace-43d0-8998-e276d35a4a40 |
| Verdict: | Malicious activity |
| Analysis date: | January 31, 2024, 06:43:05 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 60B5CE3A4D54CA6638507F616F8146F3 |
| SHA1: | B52E7FFF67848598FCBF7AAC63F8048B1A3566A9 |
| SHA256: | 323E9CC65C1EE182191237F4A01103EFC6DA692A0059004F4B33D8093156E3F8 |
| SSDEEP: | 98304:wqDWMGjhkzTA3QLaszuAybIM+ld6SrFjT6uH1d39rbzznuwN5RVqFCGtGDSFJHtK:D1/OhMgWYxw9jBt3YPlD2xx |
| .exe | | | Inno Setup installer (77.7) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (10) |
| .dll | | | Win32 Dynamic Link Library (generic) (4.6) |
| .exe | | | Win32 Executable (generic) (3.1) |
| .exe | | | Win16/32 Executable Delphi generic (1.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:20 00:22:17+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 41472 |
| InitializedDataSize: | 17920 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xaa98 |
| OSVersion: | 1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | |
| FileDescription: | eBIRForms Setup |
| FileVersion: | |
| LegalCopyright: | |
| ProductName: | eBIRForms |
| ProductVersion: | v7.9.4.2 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 752 | "C:\Users\admin\AppData\Local\Temp\is-Q5EUP.tmp\Offline eBIRForms Package v7.9.4.2 setup.tmp" /SL5="$F0184,11779280,57856,C:\Users\admin\AppData\Local\Temp\Offline eBIRForms Package v7.9.4.2 setup.exe" | C:\Users\admin\AppData\Local\Temp\is-Q5EUP.tmp\Offline eBIRForms Package v7.9.4.2 setup.tmp | — | Offline eBIRForms Package v7.9.4.2 setup.exe | |||||||||||
User: admin Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 1264 | "C:\Users\admin\AppData\Local\Temp\Offline eBIRForms Package v7.9.4.2 setup.exe" | C:\Users\admin\AppData\Local\Temp\Offline eBIRForms Package v7.9.4.2 setup.exe | explorer.exe | ||||||||||||
User: admin Company: Integrity Level: MEDIUM Description: eBIRForms Setup Exit code: 0 Version: Modules
| |||||||||||||||
| 2032 | "C:\Users\admin\AppData\Local\Temp\is-3H3H5.tmp\Offline eBIRForms Package v7.9.4.2 setup.tmp" /SL5="$100130,11779280,57856,C:\Users\admin\AppData\Local\Temp\Offline eBIRForms Package v7.9.4.2 setup.exe" /SPAWNWND=$100166 /NOTIFYWND=$F0184 | C:\Users\admin\AppData\Local\Temp\is-3H3H5.tmp\Offline eBIRForms Package v7.9.4.2 setup.tmp | Offline eBIRForms Package v7.9.4.2 setup.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 2776 | "C:\eBIRForms\BIRForms.exe" | C:\eBIRForms\BIRForms.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 3156 | "C:\Windows\System32\mshta.exe" "C:\Users\admin\AppData\Local\Temp\{3B1D7364-9D06-4894-812C-CEAD409FE3FE}\BIRForms.hta" | C:\Windows\System32\mshta.exe | BIRForms.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft (R) HTML Application host Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 3472 | "C:\Users\admin\AppData\Local\Temp\Offline eBIRForms Package v7.9.4.2 setup.exe" /SPAWNWND=$100166 /NOTIFYWND=$F0184 | C:\Users\admin\AppData\Local\Temp\Offline eBIRForms Package v7.9.4.2 setup.exe | Offline eBIRForms Package v7.9.4.2 setup.tmp | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: eBIRForms Setup Exit code: 0 Version: Modules
| |||||||||||||||
| (PID) Process: | (2032) Offline eBIRForms Package v7.9.4.2 setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFilesHash |
Value: 998E61C2CC91915DF1A2CDD3C3A4AA28873152EED9BC33019FDBE52DA10CCC4D | |||
| (PID) Process: | (2032) Offline eBIRForms Package v7.9.4.2 setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFiles0000 |
Value: C:\eBIRForms\BIRForms.exe | |||
| (PID) Process: | (2032) Offline eBIRForms Package v7.9.4.2 setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (2032) Offline eBIRForms Package v7.9.4.2 setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | SessionHash |
Value: B8701CE0A24467E57DD9AB6929A08FF21DDDF73659984EEC4F47CD9868BDEEC9 | |||
| (PID) Process: | (2032) Offline eBIRForms Package v7.9.4.2 setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Owner |
Value: F007000084EAA8C51054DA01 | |||
| (PID) Process: | (2032) Offline eBIRForms Package v7.9.4.2 setup.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (2776) BIRForms.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2776) BIRForms.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2776) BIRForms.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2776) BIRForms.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2032 | Offline eBIRForms Package v7.9.4.2 setup.tmp | C:\eBIRForms\is-UJN5M.tmp | — | |
MD5:— | SHA256:— | |||
| 2032 | Offline eBIRForms Package v7.9.4.2 setup.tmp | C:\eBIRForms\BIRForms.exe | — | |
MD5:— | SHA256:— | |||
| 2032 | Offline eBIRForms Package v7.9.4.2 setup.tmp | C:\eBIRForms\Encrypt.exe | executable | |
MD5:00457E27FE7D048E51D9746845AF2E7A | SHA256:429337F44F84B93CD1095DF48C8F3265E5EDE7C646D1B48D9B80F4F92DE74D2C | |||
| 2032 | Offline eBIRForms Package v7.9.4.2 setup.tmp | C:\eBIRForms\is-EPP3T.tmp | executable | |
MD5:451E0561438B36DEB68D360655808D11 | SHA256:5D3DBDA56E3FFFFEFB23F2FD46A5AF0C0DECC389D70921C453C3F813BB806262 | |||
| 2032 | Offline eBIRForms Package v7.9.4.2 setup.tmp | C:\eBIRForms\is-TMPCM.tmp | executable | |
MD5:BDB0D33964B81735AA98C860C3F8B666 | SHA256:19C46F63075E1D759CF92575EABEE9D40E170098EC9F928FF1E9A3093E620E5A | |||
| 2032 | Offline eBIRForms Package v7.9.4.2 setup.tmp | C:\eBIRForms\is-SCC18.tmp | executable | |
MD5:00457E27FE7D048E51D9746845AF2E7A | SHA256:429337F44F84B93CD1095DF48C8F3265E5EDE7C646D1B48D9B80F4F92DE74D2C | |||
| 2032 | Offline eBIRForms Package v7.9.4.2 setup.tmp | C:\eBIRForms\xml\province.xml | xml | |
MD5:D6B9F004215D5E3A4EFA521ADD6E22C4 | SHA256:70CA11A770C9BF6B4B2BD4C613218405EE000DB31DCE9699CD3EE9B61D5D2A29 | |||
| 2032 | Offline eBIRForms Package v7.9.4.2 setup.tmp | C:\eBIRForms\cFTPSend.exe | executable | |
MD5:451E0561438B36DEB68D360655808D11 | SHA256:5D3DBDA56E3FFFFEFB23F2FD46A5AF0C0DECC389D70921C453C3F813BB806262 | |||
| 2032 | Offline eBIRForms Package v7.9.4.2 setup.tmp | C:\eBIRForms\is-2T0J6.tmp | executable | |
MD5:83633F731C54A30F5747F78D3EEEE7A3 | SHA256:C00BD4131A725AF53F48C6385D3332C4B789E15441BF52BBAC73117C96C1B0AC | |||
| 2032 | Offline eBIRForms Package v7.9.4.2 setup.tmp | C:\eBIRForms\savefile\is-Q5Q2E.tmp | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3156 | mshta.exe | GET | 200 | 162.250.122.202:80 | http://birgovph.com/ebirformsVersion.php?data=0.006923462549879911 | unknown | text | 54 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3156 | mshta.exe | 162.250.122.202:80 | birgovph.com | IS-AS-1 | US | unknown |
Domain | IP | Reputation |
|---|---|---|
birgovph.com |
| unknown |