| File name: | UpdPack_ECService.exe |
| Full analysis: | https://app.any.run/tasks/0bf80a2c-c8d6-46bd-8117-b6ea704f3764 |
| Verdict: | Malicious activity |
| Analysis date: | November 08, 2023, 20:04:58 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | ACE99F2307520BA3234DED4710760097 |
| SHA1: | F96B186F3394F731E7A5CC3148FAF0F812CCA530 |
| SHA256: | 360AB4661FF70E861ADD2116C78736E62F5760684624A0CDCB5B5149A46EA2AB |
| SSDEEP: | 98304:qmxyENGiEzrkIr+i1eW6TK5eDN3coujjDA7By0N70n9nPF7N2+Y4NxxgKQHG5UCM:TPCiD |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2010:11:18 17:27:32+01:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 82944 |
| InitializedDataSize: | 30208 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x1373c |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 9.20.0.0 |
| ProductVersionNumber: | 9.20.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows NT 32-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Igor Pavlov |
| FileDescription: | 7z Setup SFX |
| FileVersion: | 9.2 |
| InternalName: | 7zS.sfx |
| LegalCopyright: | Copyright (c) 1999-2010 Igor Pavlov |
| OriginalFileName: | 7zS.sfx.exe |
| ProductName: | 7-Zip |
| ProductVersion: | 9.2 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2116 | schtasks.exe /create /tn "GBTECService" /tr '"\GIGABYTE\GBTECService\LiquidSensord.exe"' /sc onlogon /DELAY 0000:10 /RL HIGHEST | C:\Windows\System32\schtasks.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3420 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3436 | "C:\Users\admin\Desktop\UpdPack_ECService.exe" | C:\Users\admin\Desktop\UpdPack_ECService.exe | — | explorer.exe | |||||||||||
User: admin Company: Igor Pavlov Integrity Level: MEDIUM Description: 7z Setup SFX Exit code: 3221226540 Version: 9.20 Modules
| |||||||||||||||
| 3496 | "C:\Users\admin\Desktop\UpdPack_ECService.exe" | C:\Users\admin\Desktop\UpdPack_ECService.exe | explorer.exe | ||||||||||||
User: admin Company: Igor Pavlov Integrity Level: HIGH Description: 7z Setup SFX Exit code: 0 Version: 9.20 Modules
| |||||||||||||||
| 3516 | .\GBTECService\InstUpd.exe | C:\Users\admin\AppData\Local\Temp\7zS6B51.tmp\GBTECService\InstUpd.exe | — | UpdPack_ECService.exe | |||||||||||
User: admin Company: GIGA-BYTE TECHNOLOGY CO., LTD. Integrity Level: HIGH Description: InstUpd Exit code: 0 Version: 1.0.10.0 Modules
| |||||||||||||||
| 3640 | C:\Windows\system32\msiexec.exe /V | C:\Windows\System32\msiexec.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3688 | "C:\Users\admin\AppData\Local\Temp\7zS6B51.tmp\GBTECService\setup.exe" -s -f1"C:\Users\admin\AppData\Local\Temp\7zS6B51.tmp\GBTECService\proginstall.iss" | C:\Users\admin\AppData\Local\Temp\7zS6B51.tmp\GBTECService\setup.exe | — | InstUpd.exe | |||||||||||
User: admin Company: Gigabyte Integrity Level: HIGH Description: Setup Launcher Unicode Exit code: 0 Version: 1.22.0218 Modules
| |||||||||||||||
| 3860 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 4032 | C:\Windows\system32\cmd.exe /c ""C:\Program Files\Gigabyte\GBTECService\install.bat" " | C:\Windows\System32\cmd.exe | setup.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (3420) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{AC029DAC-E25E-4E43-8F37-BBA271749118}\{7C21E634-757B-4A6A-B8A0-39645AE17A8E} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3420) wmpnscfg.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows Media Player NSS\3.0\Events\{AC029DAC-E25E-4E43-8F37-BBA271749118} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3420) wmpnscfg.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\MediaPlayer\Health\{7935C721-396C-41FF-A0D5-CCDBB0FD22E7} |
| Operation: | delete key | Name: | (default) |
Value: | |||
| (PID) Process: | (3516) InstUpd.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3516) InstUpd.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3516) InstUpd.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3516) InstUpd.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3688) setup.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4000000000000000F2B487BA16B0D901C80700002C0A0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3688) setup.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 4000000000000000F2B487BA16B0D901C80700002C0A0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3688) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 72 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3496 | UpdPack_ECService.exe | C:\Users\admin\AppData\Local\Temp\7zS6B51.tmp\GBTECService\setup.exe | executable | |
MD5:76CBDC5EA666F4D4D6FF798E43A3FC1D | SHA256:5B5911C6F52F7FAA31BA9D35CDD7434B4636A3B475F8C3227D873BF71EFF9FC7 | |||
| 3496 | UpdPack_ECService.exe | C:\Users\admin\AppData\Local\Temp\7zS6B51.tmp\GBTECService\AppExeInfo.xml | xml | |
MD5:E155C20B02FDA4DA462975AA7090BB6C | SHA256:7BA2EF6542B2019F4DF5B6891CBC324762F2F5549CB857A3BE856A850C761CAA | |||
| 3496 | UpdPack_ECService.exe | C:\Users\admin\AppData\Local\Temp\7zS6B51.tmp\GBTECService\AppInfo.xml | xml | |
MD5:D5C779F7CAFB7A81980D1D47A79AEE64 | SHA256:8D91092231D9645D918DE4434024B0EE9E608D54F69EA139D1D440745AD931FD | |||
| 3496 | UpdPack_ECService.exe | C:\Users\admin\AppData\Local\Temp\7zS6B51.tmp\GBTECService\InstUpd.exe | executable | |
MD5:7E62EC0EA5FC851AECC5896B82DFF9A9 | SHA256:223BBCEF932D9D4E80FC1D29A3D2C8DAF5B0984F1B9323F274DF2807296E1602 | |||
| 3688 | setup.exe | C:\Users\admin\AppData\Local\Temp\{644085D2-C8F8-404B-8E87-9A42BD237CDE}\_ISMSIDEL.INI | text | |
MD5:F5CA7654954D816DD0A9260FDCFD3DE9 | SHA256:AD2E06CC2A1FBBB78954E81313308D8BF1762814CB64C9D8DFDF7F65BC27592D | |||
| 3688 | setup.exe | C:\Users\admin\AppData\Local\Temp\~6E60.tmp | text | |
MD5:E5AFF098D35C47070D9B0AF90762EE52 | SHA256:FDB3110091BD88E884F29D5512932C383DF466C767995E03B0B2766DA05F9190 | |||
| 3688 | setup.exe | C:\Users\admin\AppData\Local\Temp\_is6E4F.tmp | binary | |
MD5:3859AB21B567D95F5A4D1D7A2F311F10 | SHA256:65300A96A28454D827C474E134A0533E8C2450C348428222786BC5DC2B7DC067 | |||
| 3688 | setup.exe | C:\Users\admin\AppData\Local\Temp\{644085D2-C8F8-404B-8E87-9A42BD237CDE}\ISSetup.dll | executable | |
MD5:82E9C6775C737ECF16FD8A8DA49309C2 | SHA256:E3304A28DCC1E50B56E49530D395D716C1B4255F0DCC4CFE0C4CEC718F8B1DB1 | |||
| 3688 | setup.exe | C:\Users\admin\AppData\Local\Temp\{644085D2-C8F8-404B-8E87-9A42BD237CDE}\Setup.INI | text | |
MD5:E5AFF098D35C47070D9B0AF90762EE52 | SHA256:FDB3110091BD88E884F29D5512932C383DF466C767995E03B0B2766DA05F9190 | |||
| 3688 | setup.exe | C:\Users\admin\AppData\Local\Temp\_is6E61.tmp | binary | |
MD5:3859AB21B567D95F5A4D1D7A2F311F10 | SHA256:65300A96A28454D827C474E134A0533E8C2450C348428222786BC5DC2B7DC067 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |