| File name: | EasyBCD 2.4.exe |
| Full analysis: | https://app.any.run/tasks/dde938d0-e787-49bb-bf11-0c69b020e770 |
| Verdict: | Malicious activity |
| Analysis date: | March 16, 2024, 16:35:24 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 89E26B29BD0DBBE6E862CC9D0CE6800C |
| SHA1: | 21096276E04C4A6E1F66B255F3AA579BCF2E0E02 |
| SHA256: | 34FC8652E14714536B73479AD2F8277A79051D423F1EFBAC9C7CBC9BFE526722 |
| SSDEEP: | 98304:LlHlURur2ooGWFdzLmi9pimQ43ZIbI7KjDgXC5b7V6n0pWzvx4X1aex55V9WSdz6:4Bmu |
| .exe | | | Win32 Executable MS Visual C++ (generic) (67.4) |
|---|---|---|
| .dll | | | Win32 Dynamic Link Library (generic) (14.2) |
| .exe | | | Win32 Executable (generic) (9.7) |
| .exe | | | Generic Win/DOS Executable (4.3) |
| .exe | | | DOS Executable Generic (4.3) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:01:30 03:57:38+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 25088 |
| InitializedDataSize: | 118784 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x3328 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1348 | "C:\Windows\System32\taskkill.exe" /f /im easybcd.exe | C:\Windows\System32\taskkill.exe | — | EasyBCD 2.4.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1696 | "C:\Users\admin\AppData\Local\Temp\EasyBCD 2.4.exe" | C:\Users\admin\AppData\Local\Temp\EasyBCD 2.4.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 1784 | "C:\Program Files\NeoSmart Technologies\EasyBCD\bin\UtfRedirect.exe" | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\UtfRedirect.exe | — | EasyBCD.exe | |||||||||||
User: admin Company: NeoSmart Technologies Integrity Level: HIGH Description: UTF8 codepage proxy application Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 2172 | "C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bcdedit.exe" /export "C:\Users\admin\Documents\EasyBCD Backup (2024-03-16).bcd" | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bcdedit.exe | — | UtfRedirect.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Boot Configuration Data Editor Exit code: 0 Version: 6.2.8250.0 (winmain_win8beta.120217-1520) Modules
| |||||||||||||||
| 2240 | "C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bootgrabber.exe" /tlist | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bootgrabber.exe | — | EasyBCD.exe | |||||||||||
User: admin Company: NeoSmart Technologies Integrity Level: HIGH Description: EasyBCD boot helper Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 2384 | "C:\Program Files\NeoSmart Technologies\EasyBCD\bin\UtfRedirect.exe" | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\UtfRedirect.exe | — | EasyBCD.exe | |||||||||||
User: admin Company: NeoSmart Technologies Integrity Level: HIGH Description: UTF8 codepage proxy application Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 2576 | "C:\Windows\System32\msfeedssync.exe" forcesync | C:\Windows\System32\msfeedssync.exe | EasyBCD.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Feeds Synchronization Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2668 | msfeedssync.exe sync | C:\Windows\System32\msfeedssync.exe | — | EasyBCD.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft Feeds Synchronization Exit code: 1 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 2756 | "C:\Users\admin\AppData\Local\Temp\EasyBCD 2.4.exe" | C:\Users\admin\AppData\Local\Temp\EasyBCD 2.4.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2772 | "C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bcdedit.exe" /enum all | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bcdedit.exe | — | UtfRedirect.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Boot Configuration Data Editor Exit code: 0 Version: 6.2.8250.0 (winmain_win8beta.120217-1520) Modules
| |||||||||||||||
| (PID) Process: | (2756) EasyBCD 2.4.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2756) EasyBCD 2.4.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2756) EasyBCD 2.4.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2756) EasyBCD 2.4.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2756) EasyBCD 2.4.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyBCD |
| Operation: | write | Name: | DisplayName |
Value: EasyBCD 2.4 | |||
| (PID) Process: | (2756) EasyBCD 2.4.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyBCD |
| Operation: | write | Name: | UninstallString |
Value: C:\Program Files\NeoSmart Technologies\EasyBCD\uninstall.exe | |||
| (PID) Process: | (2756) EasyBCD 2.4.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyBCD |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files\NeoSmart Technologies\EasyBCD\EasyBCD.exe | |||
| (PID) Process: | (2756) EasyBCD 2.4.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyBCD |
| Operation: | write | Name: | HelpLink |
Value: http://neosmart.net/forums/ | |||
| (PID) Process: | (2756) EasyBCD 2.4.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyBCD |
| Operation: | write | Name: | URLUpdateInfo |
Value: http://neosmart.net/EasyBCD/ | |||
| (PID) Process: | (2756) EasyBCD 2.4.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EasyBCD |
| Operation: | write | Name: | VersionMajor |
Value: 2 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2756 | EasyBCD 2.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\NST Downloader.exe | executable | |
MD5:A5B3EA9EE11E9752417159BA1C618B95 | SHA256:B92B2FA8916C78CCFFEF058D3BE900C840CB996028D373BA55985FD1D1DDDAC8 | |||
| 2756 | EasyBCD 2.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\NeoSmart.Localization.dll | executable | |
MD5:AD0A59AE87D4BA106E965C62F0BC3D88 | SHA256:3A56005B2EFB34620019EF432FE90EEB63726FC78B37BE841F25C2AED82EB1DB | |||
| 2756 | EasyBCD 2.4.exe | C:\Users\admin\AppData\Local\Temp\nsj241F.tmp\ioSpecial.ini | ini | |
MD5:E2D5070BC28DB1AC745613689FF86067 | SHA256:D95AED234F932A1C48A2B1B0D98C60CA31F962310C03158E2884AB4DDD3EA1E0 | |||
| 2756 | EasyBCD 2.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\Newtonsoft.Json.dll | executable | |
MD5:0953851089821550EF013B487DA3915A | SHA256:4A56EF352F84AD19C1B4486C7C9E64FEF9A67C464C62E51BABABA79CD2D89551 | |||
| 2756 | EasyBCD 2.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\LICENSE | text | |
MD5:2458D2762467CD07CC91448A30A2E572 | SHA256:FFBFE4D5757BD4315B79F55B9151625C29110EA16ABF81517D27E17136BF4094 | |||
| 2756 | EasyBCD 2.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\bcdedit.exe | executable | |
MD5:A60CBAEA0F8AC802D21C0CC7BC2589BE | SHA256:8BF1B71182FED18D6B4112BDC4D496800B5BF6681DE4C4F6536BA67378F38A12 | |||
| 2756 | EasyBCD 2.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\BootGrabber.exe | executable | |
MD5:2E12B37D32C8BCF8920F5EBB6D24A6B9 | SHA256:F9842333F0B562B4AB5349A09FC173B0B2971C1F600502C4284781C78A735D7E | |||
| 2756 | EasyBCD 2.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\EasyBCD.exe | executable | |
MD5:E478C92160A3C73C77CDC9F515DFD8B0 | SHA256:6A6E16C176004128B918EF3F9ECF1D51D828E6099FBA6542B5AC6ABDB67C1030 | |||
| 2756 | EasyBCD 2.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\UtfRedirect.exe | executable | |
MD5:5B40791899FA37507E7C08BC3D9F5294 | SHA256:5A87D9485F6E13EE2C3BA4AC289A3E237D17A43ED428B8A5BD5F00FC4800D1AC | |||
| 2756 | EasyBCD 2.4.exe | C:\Program Files\NeoSmart Technologies\EasyBCD\bin\udefrag.dll | executable | |
MD5:CEA23B2E0C8EB462EDFA442B1CCF4CB7 | SHA256:F62D78F847F8FB37992D4024ECE99D6C82DD3C83FCA04527D2A06F6AF3FB4BFF | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3400 | EasyBCD.exe | GET | 302 | 65.182.170.12:80 | http://feeds.neosmart.net/neosmart | unknown | html | 145 b | unknown |
2576 | msfeedssync.exe | GET | 302 | 23.35.238.131:80 | http://go.microsoft.com/fwlink/?LinkId=44406 | unknown | — | — | unknown |
2576 | msfeedssync.exe | GET | 302 | 23.35.238.131:80 | http://go.microsoft.com/fwlink/?LinkId=129794 | unknown | — | — | unknown |
3400 | EasyBCD.exe | GET | 200 | 142.250.186.51:80 | http://rss.neosmart.net/neosmart | unknown | html | 15.6 Kb | unknown |
2576 | msfeedssync.exe | GET | 302 | 23.35.238.131:80 | http://go.microsoft.com/fwlink/?LinkId=68928 | unknown | — | — | unknown |
2576 | msfeedssync.exe | GET | 304 | 184.24.77.194:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?26338873a277df25 | unknown | — | — | unknown |
2576 | msfeedssync.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEA7y5dg2gVICVeksYI%2B8L%2FQ%3D | unknown | binary | 312 b | unknown |
2576 | msfeedssync.exe | GET | 302 | 65.182.170.12:80 | http://feeds.neosmart.net/neosmart | unknown | html | 145 b | unknown |
2576 | msfeedssync.exe | GET | 302 | 23.35.238.131:80 | http://go.microsoft.com/fwlink/?LinkId=129793 | unknown | — | — | unknown |
2576 | msfeedssync.exe | GET | 200 | 2.21.20.151:80 | http://rssgov.windows.microsoft.com/usagovrssfeed.rss | unknown | xml | 658 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
3400 | EasyBCD.exe | 18.245.60.51:443 | api.neosmart.net | — | US | unknown |
3400 | EasyBCD.exe | 65.182.170.12:80 | feeds.neosmart.net | NETSOURCE | US | unknown |
2576 | msfeedssync.exe | 23.35.238.131:80 | go.microsoft.com | AKAMAI-AS | DE | unknown |
3400 | EasyBCD.exe | 142.250.186.51:80 | rss.neosmart.net | GOOGLE | US | unknown |
2576 | msfeedssync.exe | 23.32.100.24:443 | rss.msn.com | AKAMAI-AS | SE | unknown |
2576 | msfeedssync.exe | 2.21.20.137:80 | rssgov.windows.microsoft.com | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
api.neosmart.net |
| unknown |
feeds.neosmart.net |
| unknown |
go.microsoft.com |
| whitelisted |
rss.neosmart.net |
| unknown |
rss.msn.com |
| whitelisted |
rssgov.windows.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |