File name:

UpdPack_ECService.exe

Full analysis: https://app.any.run/tasks/0bf80a2c-c8d6-46bd-8117-b6ea704f3764
Verdict: Malicious activity
Analysis date: November 08, 2023, 20:04:58
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

ACE99F2307520BA3234DED4710760097

SHA1:

F96B186F3394F731E7A5CC3148FAF0F812CCA530

SHA256:

360AB4661FF70E861ADD2116C78736E62F5760684624A0CDCB5B5149A46EA2AB

SSDEEP:

98304:qmxyENGiEzrkIr+i1eW6TK5eDN3coujjDA7By0N70n9nPF7N2+Y4NxxgKQHG5UCM:TPCiD

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • UpdPack_ECService.exe (PID: 3496)
      • setup.exe (PID: 3688)
      • msiexec.exe (PID: 3640)
    • Uses Task Scheduler to autorun other applications

      • cmd.exe (PID: 4032)
  • SUSPICIOUS

    • Reads the Internet Settings

      • InstUpd.exe (PID: 3516)
    • Reads the Windows owner or organization settings

      • setup.exe (PID: 3688)
    • Searches for installed software

      • setup.exe (PID: 3688)
    • Executing commands from a ".bat" file

      • setup.exe (PID: 3688)
    • Starts CMD.EXE for commands execution

      • setup.exe (PID: 3688)
    • Executes as Windows Service

      • VSSVC.exe (PID: 3860)
  • INFO

    • Checks supported languages

      • UpdPack_ECService.exe (PID: 3496)
      • wmpnscfg.exe (PID: 3420)
      • InstUpd.exe (PID: 3516)
      • setup.exe (PID: 3688)
      • msiexec.exe (PID: 3640)
    • Reads the computer name

      • wmpnscfg.exe (PID: 3420)
      • InstUpd.exe (PID: 3516)
      • setup.exe (PID: 3688)
      • msiexec.exe (PID: 3640)
    • Manual execution by a user

      • wmpnscfg.exe (PID: 3420)
    • Create files in a temporary directory

      • UpdPack_ECService.exe (PID: 3496)
      • setup.exe (PID: 3688)
      • msiexec.exe (PID: 3640)
    • Reads the machine GUID from the registry

      • InstUpd.exe (PID: 3516)
      • wmpnscfg.exe (PID: 3420)
      • setup.exe (PID: 3688)
      • msiexec.exe (PID: 3640)
    • Creates files in the program directory

      • setup.exe (PID: 3688)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2010:11:18 17:27:32+01:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 82944
InitializedDataSize: 30208
UninitializedDataSize: -
EntryPoint: 0x1373c
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 9.20.0.0
ProductVersionNumber: 9.20.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Unicode
CompanyName: Igor Pavlov
FileDescription: 7z Setup SFX
FileVersion: 9.2
InternalName: 7zS.sfx
LegalCopyright: Copyright (c) 1999-2010 Igor Pavlov
OriginalFileName: 7zS.sfx.exe
ProductName: 7-Zip
ProductVersion: 9.2
No data.
screenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
9
Malicious processes
4
Suspicious processes
0

Behavior graph

Click at the process to see the details
start updpack_ecservice.exe wmpnscfg.exe no specs instupd.exe no specs setup.exe no specs msiexec.exe no specs vssvc.exe no specs cmd.exe schtasks.exe no specs updpack_ecservice.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2116schtasks.exe /create /tn "GBTECService" /tr '"\GIGABYTE\GBTECService\LiquidSensord.exe"' /sc onlogon /DELAY 0000:10 /RL HIGHESTC:\Windows\System32\schtasks.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Manages scheduled tasks
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\schtasks.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\ole32.dll
3420"C:\Program Files\Windows Media Player\wmpnscfg.exe"C:\Program Files\Windows Media Player\wmpnscfg.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Media Player Network Sharing Service Configuration Application
Exit code:
0
Version:
12.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\program files\windows media player\wmpnscfg.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\sspicli.dll
c:\windows\system32\ole32.dll
3436"C:\Users\admin\Desktop\UpdPack_ECService.exe" C:\Users\admin\Desktop\UpdPack_ECService.exeexplorer.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
MEDIUM
Description:
7z Setup SFX
Exit code:
3221226540
Version:
9.20
Modules
Images
c:\users\admin\desktop\updpack_ecservice.exe
c:\windows\system32\ntdll.dll
3496"C:\Users\admin\Desktop\UpdPack_ECService.exe" C:\Users\admin\Desktop\UpdPack_ECService.exe
explorer.exe
User:
admin
Company:
Igor Pavlov
Integrity Level:
HIGH
Description:
7z Setup SFX
Exit code:
0
Version:
9.20
Modules
Images
c:\users\admin\desktop\updpack_ecservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\oleaut32.dll
c:\windows\system32\ole32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3516.\GBTECService\InstUpd.exeC:\Users\admin\AppData\Local\Temp\7zS6B51.tmp\GBTECService\InstUpd.exeUpdPack_ECService.exe
User:
admin
Company:
GIGA-BYTE TECHNOLOGY CO., LTD.
Integrity Level:
HIGH
Description:
InstUpd
Exit code:
0
Version:
1.0.10.0
Modules
Images
c:\users\admin\appdata\local\temp\7zs6b51.tmp\gbtecservice\instupd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\apphelp.dll
c:\windows\apppatch\acgenral.dll
c:\windows\system32\sechost.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\rpcrt4.dll
3640C:\Windows\system32\msiexec.exe /VC:\Windows\System32\msiexec.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Windows® installer
Exit code:
0
Version:
5.0.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\msiexec.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
3688"C:\Users\admin\AppData\Local\Temp\7zS6B51.tmp\GBTECService\setup.exe" -s -f1"C:\Users\admin\AppData\Local\Temp\7zS6B51.tmp\GBTECService\proginstall.iss"C:\Users\admin\AppData\Local\Temp\7zS6B51.tmp\GBTECService\setup.exeInstUpd.exe
User:
admin
Company:
Gigabyte
Integrity Level:
HIGH
Description:
Setup Launcher Unicode
Exit code:
0
Version:
1.22.0218
Modules
Images
c:\users\admin\appdata\local\temp\7zs6b51.tmp\gbtecservice\setup.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\version.dll
c:\windows\system32\msvcrt.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
3860C:\Windows\system32\vssvc.exeC:\Windows\System32\VSSVC.exeservices.exe
User:
SYSTEM
Company:
Microsoft Corporation
Integrity Level:
SYSTEM
Description:
Microsoft® Volume Shadow Copy Service
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\vssvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
4032C:\Windows\system32\cmd.exe /c ""C:\Program Files\Gigabyte\GBTECService\install.bat" "C:\Windows\System32\cmd.exe
setup.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
3 374
Read events
3 337
Write events
24
Delete events
13

Modification events

(PID) Process:(3420) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{AC029DAC-E25E-4E43-8F37-BBA271749118}\{7C21E634-757B-4A6A-B8A0-39645AE17A8E}
Operation:delete keyName:(default)
Value:
(PID) Process:(3420) wmpnscfg.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{AC029DAC-E25E-4E43-8F37-BBA271749118}
Operation:delete keyName:(default)
Value:
(PID) Process:(3420) wmpnscfg.exeKey:HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{7935C721-396C-41FF-A0D5-CCDBB0FD22E7}
Operation:delete keyName:(default)
Value:
(PID) Process:(3516) InstUpd.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3516) InstUpd.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(3516) InstUpd.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(3516) InstUpd.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(3688) setup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore
Operation:writeName:SrCreateRp (Enter)
Value:
4000000000000000F2B487BA16B0D901C80700002C0A0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3688) setup.exeKey:HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP
Operation:writeName:SppCreate (Enter)
Value:
4000000000000000F2B487BA16B0D901C80700002C0A0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000
(PID) Process:(3688) setup.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP
Operation:writeName:LastIndex
Value:
72
Executable files
29
Suspicious files
23
Text files
16
Unknown types
0

Dropped files

PID
Process
Filename
Type
3496UpdPack_ECService.exeC:\Users\admin\AppData\Local\Temp\7zS6B51.tmp\GBTECService\setup.exeexecutable
MD5:76CBDC5EA666F4D4D6FF798E43A3FC1D
SHA256:5B5911C6F52F7FAA31BA9D35CDD7434B4636A3B475F8C3227D873BF71EFF9FC7
3496UpdPack_ECService.exeC:\Users\admin\AppData\Local\Temp\7zS6B51.tmp\GBTECService\AppExeInfo.xmlxml
MD5:E155C20B02FDA4DA462975AA7090BB6C
SHA256:7BA2EF6542B2019F4DF5B6891CBC324762F2F5549CB857A3BE856A850C761CAA
3496UpdPack_ECService.exeC:\Users\admin\AppData\Local\Temp\7zS6B51.tmp\GBTECService\AppInfo.xmlxml
MD5:D5C779F7CAFB7A81980D1D47A79AEE64
SHA256:8D91092231D9645D918DE4434024B0EE9E608D54F69EA139D1D440745AD931FD
3496UpdPack_ECService.exeC:\Users\admin\AppData\Local\Temp\7zS6B51.tmp\GBTECService\InstUpd.exeexecutable
MD5:7E62EC0EA5FC851AECC5896B82DFF9A9
SHA256:223BBCEF932D9D4E80FC1D29A3D2C8DAF5B0984F1B9323F274DF2807296E1602
3688setup.exeC:\Users\admin\AppData\Local\Temp\{644085D2-C8F8-404B-8E87-9A42BD237CDE}\_ISMSIDEL.INItext
MD5:F5CA7654954D816DD0A9260FDCFD3DE9
SHA256:AD2E06CC2A1FBBB78954E81313308D8BF1762814CB64C9D8DFDF7F65BC27592D
3688setup.exeC:\Users\admin\AppData\Local\Temp\~6E60.tmptext
MD5:E5AFF098D35C47070D9B0AF90762EE52
SHA256:FDB3110091BD88E884F29D5512932C383DF466C767995E03B0B2766DA05F9190
3688setup.exeC:\Users\admin\AppData\Local\Temp\_is6E4F.tmpbinary
MD5:3859AB21B567D95F5A4D1D7A2F311F10
SHA256:65300A96A28454D827C474E134A0533E8C2450C348428222786BC5DC2B7DC067
3688setup.exeC:\Users\admin\AppData\Local\Temp\{644085D2-C8F8-404B-8E87-9A42BD237CDE}\ISSetup.dllexecutable
MD5:82E9C6775C737ECF16FD8A8DA49309C2
SHA256:E3304A28DCC1E50B56E49530D395D716C1B4255F0DCC4CFE0C4CEC718F8B1DB1
3688setup.exeC:\Users\admin\AppData\Local\Temp\{644085D2-C8F8-404B-8E87-9A42BD237CDE}\Setup.INItext
MD5:E5AFF098D35C47070D9B0AF90762EE52
SHA256:FDB3110091BD88E884F29D5512932C383DF466C767995E03B0B2766DA05F9190
3688setup.exeC:\Users\admin\AppData\Local\Temp\_is6E61.tmpbinary
MD5:3859AB21B567D95F5A4D1D7A2F311F10
SHA256:65300A96A28454D827C474E134A0533E8C2450C348428222786BC5DC2B7DC067
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info