File name:

01767717

Full analysis: https://app.any.run/tasks/56a2f5e2-3440-438a-9382-dabd5c99f924
Verdict: Malicious activity
Analysis date: January 13, 2020, 05:31:13
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

546B5620C8381F665B3A82215738D7A6

SHA1:

C8772D3C4686CE98B4062737EF07C48228142386

SHA256:

3929694E9A5F5A37DA0FB258CD4BA57D6DBB4A8ACFEF6768E0D50EC8B9C0CCAC

SSDEEP:

393216:MERiRuAPrCO+4gX/msxbr+pNsOEM4Bsn/hWX2jAQSN6VHLdy1:MERRY2WgPms5CpNsVBpX2XY6q

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Loads dropped or rewritten executable

      • 01767717.exe (PID: 3756)
      • InstaShare_BENQ.exe (PID: 3660)
    • Application was dropped or rewritten from another process

      • RemoteControlService.exe (PID: 3740)
      • VirtualAudioCable.exe (PID: 1848)
      • EShare Virtual Monitor.exe (PID: 496)
      • EDesktop.exe (PID: 3372)
      • EDesktopUAC.exe (PID: 3600)
      • ESystemService.exe (PID: 940)
      • InstaShare_BENQ.exe (PID: 3660)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • 01767717.exe (PID: 3756)
      • RemoteControlService.exe (PID: 3740)
      • VirtualAudioCable.exe (PID: 1848)
      • EShare Virtual Monitor.exe (PID: 496)
      • InstaShare_BENQ.exe (PID: 3660)
    • Creates files in the program directory

      • RemoteControlService.exe (PID: 3740)
      • VirtualAudioCable.exe (PID: 1848)
      • 01767717.exe (PID: 3756)
      • EShare Virtual Monitor.exe (PID: 496)
    • Executed as Windows Service

      • ESystemService.exe (PID: 940)
    • Creates a software uninstall entry

      • VirtualAudioCable.exe (PID: 1848)
      • RemoteControlService.exe (PID: 3740)
      • EShare Virtual Monitor.exe (PID: 496)
      • 01767717.exe (PID: 3756)
    • Starts application with an unusual extension

      • EShare Virtual Monitor.exe (PID: 496)
      • VirtualAudioCable.exe (PID: 1848)
    • Creates files in the user directory

      • InstaShare_BENQ.exe (PID: 3660)
  • INFO

    No info indicators.
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:01:30 04:57:34+01:00
PEType: PE32
LinkerVersion: 6
CodeSize: 25600
InitializedDataSize: 141824
UninitializedDataSize: 2048
EntryPoint: 0x3359
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI

Summary

Architecture: IMAGE_FILE_MACHINE_I386
Subsystem: IMAGE_SUBSYSTEM_WINDOWS_GUI
Compilation Date: 30-Jan-2018 03:57:34
Detected languages:
  • English - United States

DOS Header

Magic number: MZ
Bytes on last page of file: 0x0090
Pages in file: 0x0003
Relocations: 0x0000
Size of header: 0x0004
Min extra paragraphs: 0x0000
Max extra paragraphs: 0xFFFF
Initial SS value: 0x0000
Initial SP value: 0x00B8
Checksum: 0x0000
Initial IP value: 0x0000
Initial CS value: 0x0000
Overlay number: 0x0000
OEM identifier: 0x0000
OEM information: 0x0000
Address of NE header: 0x000000D8

PE Headers

Signature: PE
Machine: IMAGE_FILE_MACHINE_I386
Number of sections: 5
Time date stamp: 30-Jan-2018 03:57:34
Pointer to Symbol Table: 0x00000000
Number of symbols: 0
Size of Optional Header: 0x00E0
Characteristics:
  • IMAGE_FILE_32BIT_MACHINE
  • IMAGE_FILE_EXECUTABLE_IMAGE
  • IMAGE_FILE_LINE_NUMS_STRIPPED
  • IMAGE_FILE_LOCAL_SYMS_STRIPPED
  • IMAGE_FILE_RELOCS_STRIPPED

Sections

Name
Virtual Address
Virtual Size
Raw Size
Charateristics
Entropy
.text
0x00001000
0x000062A5
0x00006400
IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ
6.43139
.rdata
0x00008000
0x0000138E
0x00001400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.14645
.data
0x0000A000
0x00020318
0x00000600
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
3.90464
.ndata
0x0002B000
0x00014000
0x00000000
IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE
0
.rsrc
0x0003F000
0x0001B348
0x0001B400
IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ
5.69436

Resources

Title
Entropy
Size
Codepage
Language
Type
1
5.2974
1318
UNKNOWN
English - United States
RT_MANIFEST
2
5.44539
16936
UNKNOWN
English - United States
RT_ICON
3
5.59323
9640
UNKNOWN
English - United States
RT_ICON
4
7.87181
8438
UNKNOWN
English - United States
RT_ICON
5
5.60894
4264
UNKNOWN
English - United States
RT_ICON
6
5.56478
1128
UNKNOWN
English - United States
RT_ICON
103
2.74875
90
UNKNOWN
English - United States
RT_GROUP_ICON
105
2.73893
514
UNKNOWN
English - United States
RT_DIALOG
106
2.91148
248
UNKNOWN
English - United States
RT_DIALOG
111
2.89887
238
UNKNOWN
English - United States
RT_DIALOG

Imports

ADVAPI32.dll
COMCTL32.dll
GDI32.dll
KERNEL32.dll
SHELL32.dll
USER32.dll
ole32.dll
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
49
Monitored processes
11
Malicious processes
5
Suspicious processes
1

Behavior graph

Click at the process to see the details
drop and start drop and start drop and start drop and start start 01767717.exe remotecontrolservice.exe esystemservice.exe no specs edesktop.exe no specs edesktopuac.exe no specs virtualaudiocable.exe ns605c.tmp no specs eshare virtual monitor.exe ns6185.tmp no specs instashare_benq.exe 01767717.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
496"C:\Program Files\BenQ\InstaShare\EShare Virtual Monitor.exe"C:\Program Files\BenQ\InstaShare\EShare Virtual Monitor.exe
01767717.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\benq\instashare\eshare virtual monitor.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
940"C:\Program Files\ESystemService\ESystemService.exe"C:\Program Files\ESystemService\ESystemService.exeservices.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Version:
1.1.1.628
Modules
Images
c:\program files\esystemservice\esystemservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\wtsapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\userenv.dll
1848"C:\Program Files\BenQ\InstaShare\VirtualAudioCable.exe"C:\Program Files\BenQ\InstaShare\VirtualAudioCable.exe
01767717.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\benq\instashare\virtualaudiocable.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
2260"C:\Users\admin\AppData\Local\Temp\01767717.exe" C:\Users\admin\AppData\Local\Temp\01767717.exeexplorer.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\temp\01767717.exe
c:\systemroot\system32\ntdll.dll
2756"C:\Users\admin\AppData\Local\Temp\nsq6175.tmp\ns6185.tmp" "C:\Program Files\EShare Virtual Monitor Assistant\x86\devcon.exe" remove hid\vid_1b36&pid_0d11C:\Users\admin\AppData\Local\Temp\nsq6175.tmp\ns6185.tmpEShare Virtual Monitor.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3221225501
Modules
Images
c:\users\admin\appdata\local\temp\nsq6175.tmp\ns6185.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3372"C:/Program Files/ESystemService/EDesktop.exe"C:\Program Files\ESystemService\EDesktop.exeESystemService.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\program files\esystemservice\edesktop.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3600"C:/Program Files/ESystemService/EDesktopUAC.exe"C:\Program Files\ESystemService\EDesktopUAC.exeESystemService.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Exit code:
0
Modules
Images
c:\program files\esystemservice\edesktopuac.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
3660"C:\Program Files\BenQ\InstaShare\InstaShare_BENQ.exe"C:\Program Files\BenQ\InstaShare\InstaShare_BENQ.exe
01767717.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Version:
2.0.0.10
Modules
Images
c:\program files\benq\instashare\instashare_benq.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\program files\benq\instashare\avcodec-56.dll
c:\program files\benq\instashare\avutil-54.dll
3708"C:\Users\admin\AppData\Local\Temp\nsf604C.tmp\ns605C.tmp" "C:\Program Files\Virtual Audio Cable\devcon32.exe" install "C:\Program Files\Virtual Audio Cable\vrtaucbl.inf" EuMusDesign_VAC_WDMC:\Users\admin\AppData\Local\Temp\nsf604C.tmp\ns605C.tmpVirtualAudioCable.exe
User:
admin
Integrity Level:
HIGH
Exit code:
3221225501
Modules
Images
c:\users\admin\appdata\local\temp\nsf604c.tmp\ns605c.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3740"C:\Program Files\BenQ\InstaShare\RemoteControlService.exe"C:\Program Files\BenQ\InstaShare\RemoteControlService.exe
01767717.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\benq\instashare\remotecontrolservice.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
Total events
507
Read events
475
Write events
32
Delete events
0

Modification events

(PID) Process:(3756) 01767717.exeKey:HKEY_CURRENT_USER\Software\EShare
Operation:writeName:audio
Value:
true
(PID) Process:(1848) VirtualAudioCable.exeKey:HKEY_CURRENT_USER\Software\EShare
Operation:writeName:audio
Value:
true
(PID) Process:(1848) VirtualAudioCable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\devcon.exe
Operation:writeName:
Value:
C:\Program Files\Virtual Audio Cable\devcon.exe
(PID) Process:(1848) VirtualAudioCable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EShare Audio Card
Operation:writeName:DisplayName
Value:
EShare Audio Card 1.0.0
(PID) Process:(1848) VirtualAudioCable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EShare Audio Card
Operation:writeName:UninstallString
Value:
C:\Program Files\Virtual Audio Cable\uninst.exe
(PID) Process:(1848) VirtualAudioCable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EShare Audio Card
Operation:writeName:DisplayIcon
Value:
C:\Program Files\Virtual Audio Cable\devcon.exe
(PID) Process:(1848) VirtualAudioCable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EShare Audio Card
Operation:writeName:DisplayVersion
Value:
1.0.0
(PID) Process:(1848) VirtualAudioCable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EShare Audio Card
Operation:writeName:URLInfoAbout
Value:
www.ee-share.com
(PID) Process:(1848) VirtualAudioCable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\EShare Audio Card
Operation:writeName:Publisher
Value:
EShare
(PID) Process:(3740) RemoteControlService.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\App Paths\EDesktop.exe
Operation:writeName:
Value:
C:\Program Files\ESystemService\EDesktop.exe
Executable files
87
Suspicious files
0
Text files
22
Unknown types
11

Dropped files

PID
Process
Filename
Type
375601767717.exeC:\Users\admin\AppData\Local\Temp\nsoF760.tmp\ioSpecial.initext
MD5:
SHA256:
375601767717.exeC:\Users\admin\AppData\Local\Temp\nsoF760.tmp\modern-wizard.bmpimage
MD5:CBE40FD2B1EC96DAEDC65DA172D90022
SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2
375601767717.exeC:\Users\admin\AppData\Local\Temp\nsoF760.tmp\InstallOptions.dllexecutable
MD5:B06DFD343C2A80F584EC8968B942A839
SHA256:E546BCFA8D4ADF45CC0828F32C0607385688994E19B41E11E5CE9BADF923C0C6
375601767717.exeC:\Users\admin\AppData\Local\Temp\nsoF760.tmp\LangDLL.dllexecutable
MD5:30B091668111AB1D6C19F16586A9EEE5
SHA256:331CA4B3A311324B463167EC43851146E57A2D90500AC3FD57A7683F6B777FFB
375601767717.exeC:\Program Files\BenQ\InstaShare\libiconv-2.dllexecutable
MD5:69F77F942B2C2A6EB60AE0D69A24E886
SHA256:93B72525C6A70CF50CD92BF9A2F4F671FB162C88065A14415AE398EF2ADDC5A8
375601767717.exeC:\Program Files\BenQ\InstaShare\libplist.dllexecutable
MD5:D71010BBB4B4F42B09D0E37320C1D6B8
SHA256:9C93E0B6BC420829CF2BD61663B1B0D1E2DD5D42FEC76A1F177FF3E98940E031
375601767717.exeC:\Program Files\BenQ\InstaShare\avutil-54.dllexecutable
MD5:87AE85C3A0BAD376923D69164FFEC091
SHA256:AF209050A8500999BFB82D54A6F545771BA2957B455B3A301F832518C7DF348E
375601767717.exeC:\Program Files\BenQ\InstaShare\swscale-3.dllexecutable
MD5:1C0C6199F1EE258A23BF240B7300DCB3
SHA256:73E92BDA707CD9E22A6BB6517D087D874DE1F8BC34213DB6B8DD181A74AB23AB
375601767717.exeC:\Program Files\BenQ\InstaShare\libpthread-2.dllexecutable
MD5:7C761DCF8D4D1CC9DBEF1215E036622E
SHA256:8ACCFAAD7EA8122A478EC8C39168EA3C61476982681D199B2EBD86E785ECD5E3
375601767717.exeC:\Program Files\BenQ\InstaShare\DisplayAgent.dllexecutable
MD5:32A7DFBDD1303EF2A9F3E98E877CA64C
SHA256:A29312E4EBA7638B658C140D714D50F06CF95EF4FFA4384A2739C427D15652F8
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
1
DNS requests
1
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
3660
InstaShare_BENQ.exe
POST
200
97.64.45.39:80
http://update.ee-share.com/app_update.php
US
text
99 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
3660
InstaShare_BENQ.exe
97.64.45.39:80
update.ee-share.com
IT7 Networks Inc
US
unknown

DNS requests

Domain
IP
Reputation
update.ee-share.com
  • 97.64.45.39
unknown

Threats

No threats detected
Process
Message
InstaShare_BENQ.exe
load en.qm
InstaShare_BENQ.exe
QObject::startTimer: Timers cannot have negative intervals
InstaShare_BENQ.exe
EShareDeviceListView::showEmptyView
InstaShare_BENQ.exe
QMetaObject::connectSlotsByName: No matching signal for on_clicked_back_signal()
InstaShare_BENQ.exe
libpng warning: iCCP: known incorrect sRGB profile
InstaShare_BENQ.exe
QMetaObject::connectSlotsByName: No matching signal for on_clicked_mirror_start()
InstaShare_BENQ.exe
QMetaObject::connectSlotsByName: No matching signal for on_clicked_mirror_start()
InstaShare_BENQ.exe
InstaShare_BENQ.exe
ooooooooooooooooooooooooooooooooo
InstaShare_BENQ.exe
DEBUG 2020-01-13 05:32:30.853 update page widget 4