| File name: | INIS_EX.exe |
| Full analysis: | https://app.any.run/tasks/e587ad41-e776-48bb-9ced-128df2963de6 |
| Verdict: | Malicious activity |
| Analysis date: | February 07, 2022, 15:43:26 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | F7A5F7B778121073121A40D0AA5EF187 |
| SHA1: | 1B5D8EB672EF15F32239707D66AC1275BCA2BE18 |
| SHA256: | 34399A89DF3B5E8BC808D215A6D31574A1CF779CCCF68B1DC358F9F8CE18794C |
| SSDEEP: | 196608:6Y0SItE1hOJnmpb7FYTDV7AG+qEibWZwmbIGO874LfneBCd8uXJWDODk9:0SqE1hONm97evGlfzimbdAL78u4ODe |
| .exe | | | NSIS - Nullsoft Scriptable Install System (91.9) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (3.3) |
| .exe | | | Win64 Executable (generic) (3) |
| .dll | | | Win32 Dynamic Link Library (generic) (0.7) |
| .exe | | | Win32 Executable (generic) (0.4) |
| ProductName: | INISAFE CrossWeb EX v3.0 |
|---|---|
| LegalTrademarks: | INISAFE CrossWeb EX v3.0 is a trademark of Initech |
| LegalCopyright: | Initech Co., Ltd. All right reserved. |
| FileVersion: | 3.1.5.43 |
| FileDescription: | INISAFE CrossWeb EX v3.0 Installer |
| CompanyName: | Initech (c) |
| Comments: | - |
| CharacterSet: | Windows, Korea (Shift - KSC 5601) |
| LanguageCode: | Korean |
| FileSubtype: | - |
| ObjectFileType: | Executable application |
| FileOS: | Win32 |
| FileFlags: | (none) |
| FileFlagsMask: | 0x0000 |
| ProductVersionNumber: | 3.1.5.43 |
| FileVersionNumber: | 3.1.5.43 |
| Subsystem: | Windows GUI |
| SubsystemVersion: | 4 |
| ImageVersion: | 6 |
| OSVersion: | 4 |
| EntryPoint: | 0x3217 |
| UninitializedDataSize: | 1024 |
| InitializedDataSize: | 117760 |
| CodeSize: | 24064 |
| LinkerVersion: | 6 |
| PEType: | PE32 |
| TimeStamp: | 2015:08:05 02:46:27+02:00 |
| MachineType: | Intel 386 or later, and compatibles |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 05-Aug-2015 00:46:27 |
| Detected languages: |
|
| Comments: | - |
| CompanyName: | Initech (c) |
| FileDescription: | INISAFE CrossWeb EX v3.0 Installer |
| FileVersion: | 3.1.5.43 |
| LegalCopyright: | Initech Co., Ltd. All right reserved. |
| LegalTrademarks: | INISAFE CrossWeb EX v3.0 is a trademark of Initech |
| ProductName: | INISAFE CrossWeb EX v3.0 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000C8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 05-Aug-2015 00:46:27 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00005C3A | 0x00005E00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.41041 |
.rdata | 0x00007000 | 0x000011CE | 0x00001200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.23612 |
.data | 0x00009000 | 0x0001A7F8 | 0x00000400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.02661 |
.ndata | 0x00024000 | 0x0000A000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x0002E000 | 0x00001400 | 0x00001400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.0202 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.29702 | 1060 | UNKNOWN | English - United States | RT_MANIFEST |
103 | 1.91924 | 20 | UNKNOWN | English - United States | RT_GROUP_ICON |
105 | 2.65195 | 256 | UNKNOWN | English - United States | RT_DIALOG |
106 | 2.89971 | 284 | UNKNOWN | English - United States | RT_DIALOG |
111 | 2.48825 | 96 | UNKNOWN | English - United States | RT_DIALOG |
205 | 2.55952 | 236 | UNKNOWN | English - United States | RT_DIALOG |
206 | 2.86211 | 264 | UNKNOWN | English - United States | RT_DIALOG |
211 | 2.36476 | 76 | UNKNOWN | English - United States | RT_DIALOG |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
SHELL32.dll |
USER32.dll |
VERSION.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1668 | "C:\Program Files\initech\INISAFE Web EX Client\MyCertMgr.exe" /del "127.0.0.1" "Initech Root Authority - CrossWeb EX" | C:\Program Files\initech\INISAFE Web EX Client\MyCertMgr.exe | IniClientSvc.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| 2356 | "C:\Users\admin\AppData\Local\Temp\INIS_EX.exe" /UAC:30102 /NCRC | C:\Users\admin\AppData\Local\Temp\INIS_EX.exe | INIS_EX.exe | ||||||||||||
User: admin Company: Initech (c) Integrity Level: HIGH Description: INISAFE CrossWeb EX v3.0 Installer Exit code: 0 Version: 3.1.5.43 Modules
| |||||||||||||||
| 2408 | C:\Windows\system32\cmd.exe /C ""C:\Program Files\INITECH\INISAFE Web EX Client\MyCertMgr.exe" /del "Initech Root Authority - CrossWeb EX" "Initech Root Authority - CrossWeb EX"" | C:\Windows\system32\cmd.exe | — | INIS_EX.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2436 | C:\Windows\system32\cmd.exe /C ""C:\Program Files\INITECH\INISAFE Web EX Client\certutil.exe" -D -d "C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles/qldyz51w.default" -n "Initech Root Authority - CrossWeb EX"" | C:\Windows\system32\cmd.exe | — | INIS_EX.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 2664 | "C:\Program Files\INITECH\INISAFE Web EX Client\iniline_crosswebex_Install.exe" /S | C:\Program Files\INITECH\INISAFE Web EX Client\iniline_crosswebex_Install.exe | INIS_EX.exe | ||||||||||||
User: admin Company: iniLINE Co., Ltd. Integrity Level: HIGH Description: iniLINE CrossEX 32bit Exit code: 0 Version: 1.0.1.1101 Modules
| |||||||||||||||
| 2772 | "C:\Program Files\INITECH\INISAFE Web EX Client\MyCertMgr.exe" /del "Initech Root Authority - CrossWeb EX" "Initech Root Authority - CrossWeb EX" | C:\Program Files\INITECH\INISAFE Web EX Client\MyCertMgr.exe | cmd.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3068 | C:\Windows\system32\cmd.exe /C ""C:\Program Files\INITECH\INISAFE Web EX Client\certutil.exe" -A -n "Initech Root Authority - CrossWeb EX" -t "TCu,Cuw,Tuw" -i "inirootcert.cer" -d "C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles/qldyz51w.default"" | C:\Windows\system32\cmd.exe | — | INIS_EX.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3132 | "C:\Program Files\INITECH\INISAFE Web EX Client\certutil.exe" -A -n "Initech Root Authority - CrossWeb EX" -t "TCu,Cuw,Tuw" -i "inirootcert.cer" -d "C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles/qldyz51w.default" | C:\Program Files\INITECH\INISAFE Web EX Client\certutil.exe | cmd.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3340 | "C:\Program Files\initech\INISAFE Web EX Client\MyCertMgr.exe" /add "C:\Program Files\initech\INISAFE Web EX Client\inirootcert.cer" | C:\Program Files\initech\INISAFE Web EX Client\MyCertMgr.exe | IniClientSvc.exe | ||||||||||||
User: SYSTEM Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3548 | "C:\Program Files\initech\common\ClientService\IniClientSvc.exe" | C:\Program Files\initech\common\ClientService\IniClientSvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Initech Co., Ltd. Integrity Level: SYSTEM Description: Initech Client Manager Service Exit code: 0 Version: 1, 0, 0, 10 Modules
| |||||||||||||||
| (PID) Process: | (3572) INIS_EX.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3572) INIS_EX.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3572) INIS_EX.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3572) INIS_EX.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2356) INIS_EX.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery |
| Operation: | write | Name: | AutoRecover |
Value: 2 | |||
| (PID) Process: | (2356) INIS_EX.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery |
| Operation: | write | Name: | AutoRecover |
Value: 0 | |||
| (PID) Process: | (2356) INIS_EX.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7DAA4A48-E2DA-48e8-A133-653F364D5A23} |
| Operation: | write | Name: | AppPath |
Value: C:\Program Files\INITECH\INISAFE Web EX Client | |||
| (PID) Process: | (2356) INIS_EX.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7DAA4A48-E2DA-48e8-A133-653F364D5A23} |
| Operation: | write | Name: | AppName |
Value: INISAFETrayEX.exe | |||
| (PID) Process: | (2356) INIS_EX.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{7DAA4A48-E2DA-48e8-A133-653F364D5A23} |
| Operation: | write | Name: | Policy |
Value: 3 | |||
| (PID) Process: | (2356) INIS_EX.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Internet Explorer\Low Rights\ElevationPolicy\{A924B865-1CF0-46be-B570-16580372C622} |
| Operation: | write | Name: | AppPath |
Value: C:\Program Files\INITECH\INISAFE Web EX Client | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2356 | INIS_EX.exe | C:\Users\admin\AppData\Local\Temp\nsb3F87.tmp\UAC.dll | executable | |
MD5:E910A8BD10B97065EE3B1C024FAFC4AC | SHA256:1C62037E97B5EEBB102B879B5D6D11724C7F757D6163D369A5507EE7DFFD284D | |||
| 3572 | INIS_EX.exe | C:\Users\admin\AppData\Local\Temp\nsz3AF3.tmp\UAC.dll | executable | |
MD5:E910A8BD10B97065EE3B1C024FAFC4AC | SHA256:1C62037E97B5EEBB102B879B5D6D11724C7F757D6163D369A5507EE7DFFD284D | |||
| 2356 | INIS_EX.exe | C:\Users\admin\AppData\Local\Temp\nsb3F87.tmp\UAC.LNG | text | |
MD5:1E72C0B7743619809B7CDA824D2A1ECF | SHA256:F2E214452E69EDAF602E30D06EE186D072B1D2EC04B813B458C1E31B56ECE16B | |||
| 3572 | INIS_EX.exe | C:\Users\admin\AppData\Local\Temp\nsz3AF3.tmp\UAC.LNG | text | |
MD5:1E72C0B7743619809B7CDA824D2A1ECF | SHA256:F2E214452E69EDAF602E30D06EE186D072B1D2EC04B813B458C1E31B56ECE16B | |||
| 2356 | INIS_EX.exe | C:\Users\admin\AppData\Local\Temp\nsb3F87.tmp\ISF_NSIS_UTIL.dll | executable | |
MD5:— | SHA256:— | |||
| 2356 | INIS_EX.exe | C:\Program Files\INITECH\INISAFE Web EX Client\check\inicore_v2.3.16.dll | executable | |
MD5:C28012E443ACA95C0780994A7DA58A7A | SHA256:E9414BFFD5B0B26EF4D5AD7EDDD1FE3F560285902D3D2B437AB5C8CF6CBD1F1E | |||
| 2356 | INIS_EX.exe | C:\Program Files\NPKI\KISA\FF8A46723358E8488822AA1768DA1648098B3591_3.der | der | |
MD5:9F6C1F0F07AC1921F915BBD5C72CD82A | SHA256:956057517FF3BB35049342288C1C9DCE852DACA652B465E9747253B5F93B1F5E | |||
| 2356 | INIS_EX.exe | C:\Program Files\NPKI\KISA\troot-rsa-3280.der | der | |
MD5:D4DC5B27956B948CF53B548578602E84 | SHA256:6D5AC45F69A73D40F9717CBC60A1F420ED9C7B07D7CF63C2937B9C65138C33F9 | |||
| 2356 | INIS_EX.exe | C:\Program Files\NPKI\KISA\C8D08EC749AE1F2042B24B7F13C977580CA1CDC1_1.der | der | |
MD5:322B7C6659E177C6B2254060CA188D27 | SHA256:A002FF556C601863B08B9AA33A8E6666E97E72BBE552F66EB9F2395C68C7BC98 | |||
| 2356 | INIS_EX.exe | C:\Windows\system32\msvcr71.dll | executable | |
MD5:F06F36C0E55E5B4312792D6FCACC8042 | SHA256:2404659784ADE7F874FEEFBB4816DB4E42852EDE0693FB2A7B45145501EA24CD | |||
Process | Message |
|---|---|
INIS_EX.exe | !@!@ case2 |
INIS_EX.exe | !@!@ case2 |
INIS_EX.exe | !@!@ case2 |
INIS_EX.exe | !@!@ case2 |
INIS_EX.exe | !@!@ case2 |
INIS_EX.exe | !@!@ case2 |
INIS_EX.exe | !@!@ case2 |
INIS_EX.exe | !@!@ case2 |
INIS_EX.exe | !@!@ case2 |
INIS_EX.exe | !@!@ case2 |