| download: | UPEditorEdge_1.exe |
| Full analysis: | https://app.any.run/tasks/4952539a-b4e0-42a5-bc38-1c20bc58df5f |
| Verdict: | Malicious activity |
| Analysis date: | April 30, 2018, 02:04:36 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 97BA111FE5EA891D97D429A79B32F718 |
| SHA1: | B890D5087E1B66CD97668E61D6E5291B3509D260 |
| SHA256: | 4B6E96CC8167657D2C92B050008DCBEFEE9356DC986DA24DCFCE1CCF4A0F5E27 |
| SSDEEP: | 196608:41qb1cMI4oiEh7flaBOtIJR2TMw4fG7J4ATz:/2Mx+7fkpREJ4az |
| .exe | | | NSIS - Nullsoft Scriptable Install System (91.9) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (3.3) |
| .exe | | | Win64 Executable (generic) (3) |
| .dll | | | Win32 Dynamic Link Library (generic) (0.7) |
| .exe | | | Win32 Executable (generic) (0.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2014:05:11 22:03:30+02:00 |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 23552 |
| InitializedDataSize: | 117760 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x30b6 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.4 |
| ProductVersionNumber: | 1.0.0.4 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Traditional) |
| CharacterSet: | Windows, Taiwan (Big5) |
| CompanyName: | China UnionPay |
| FileDescription: | UnionPay Security Control |
| FileVersion: | 1.0.0.4 |
| LegalCopyright: | (C) 2017 China UnionPay copyright reserved. |
| ProductName: | UnionPay Security Control |
| ProductVersion: | 1.0.0.4 |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 11-May-2014 20:03:30 |
| Detected languages: |
|
| CompanyName: | China UnionPay |
| FileDescription: | UnionPay Security Control |
| FileVersion: | 1.0.0.4 |
| LegalCopyright: | (C) 2017 China UnionPay copyright reserved. |
| ProductName: | UnionPay Security Control |
| ProductVersion: | 1.0.0.4 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000C8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 11-May-2014 20:03:30 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00005A68 | 0x00005C00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.4187 |
.rdata | 0x00007000 | 0x000011CE | 0x00001200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.23558 |
.data | 0x00009000 | 0x0001A7B8 | 0x00000400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.87123 |
.ndata | 0x00024000 | 0x00011000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x00035000 | 0x00009A60 | 0x00009C00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.8054 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.26024 | 1013 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 4.68658 | 9640 | UNKNOWN | English - United States | RT_ICON |
3 | 5.11994 | 4264 | UNKNOWN | English - United States | RT_ICON |
103 | 2.51589 | 48 | UNKNOWN | English - United States | RT_GROUP_ICON |
105 | 2.67385 | 512 | UNKNOWN | English - United States | RT_DIALOG |
106 | 2.91148 | 248 | UNKNOWN | English - United States | RT_DIALOG |
111 | 2.89887 | 238 | UNKNOWN | English - United States | RT_DIALOG |
205 | 2.6156 | 492 | UNKNOWN | English - United States | RT_DIALOG |
206 | 2.86626 | 228 | UNKNOWN | English - United States | RT_DIALOG |
211 | 2.9304 | 218 | UNKNOWN | English - United States | RT_DIALOG |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
SHELL32.dll |
USER32.dll |
VERSION.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1636 | "C:\Users\admin\AppData\Local\Temp\UPEditorEdge_1.exe" | C:\Users\admin\AppData\Local\Temp\UPEditorEdge_1.exe | — | explorer.exe | |||||||||||
User: admin Company: China UnionPay Integrity Level: MEDIUM Description: UnionPay Security Control Exit code: 3221226540 Version: 1.0.0.4 Modules
| |||||||||||||||
| 2128 | "C:\Windows\system32\UPEditNew\UPService.exe" "-install" | C:\Windows\system32\UPEditNew\UPService.exe | — | UPEditorEdge_1.exe | |||||||||||
User: admin Company: 中国银联股份有限公司 Integrity Level: HIGH Description: UPSecurityInputService Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 2592 | C:\Windows\system32\UPEditNew\UPSecurityInput.exe | C:\Windows\system32\UPEditNew\UPSecurityInput.exe | — | UPEditorEdge_1.exe | |||||||||||
User: admin Company: 中国银联股份有限公司 Integrity Level: HIGH Description: UPSecurityInput Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 2672 | "C:\Windows\system32\UPEditNew\UPEditor.exe" "-s" | C:\Windows\system32\UPEditNew\UPEditor.exe | UPEditorEdge_1.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: passguar Application Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 2692 | certutil.exe -A -d "C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\hggh073w.default" -i .\root_bundle.crt -n "WoSign Class 1 DV Server CA G2" -t "C,," | C:\Windows\system32\UPEditNew\certutil.exe | — | UPSecurityInput.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2704 | "C:\Windows\system32\UPEditNew\UPService.exe" "-control" "UPSecurityInputService" "start" | C:\Windows\system32\UPEditNew\UPService.exe | — | UPEditorEdge_1.exe | |||||||||||
User: admin Company: 中国银联股份有限公司 Integrity Level: HIGH Description: UPSecurityInputService Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 2788 | C:\Windows\system32\schtasks.exe /create /tn "ÒøÁªÔÚÏß°²È«ÊäÈë³ÌÐò" /tr "C:\Windows\system32\UPEditNew\UPSecurityInput.exe" /sc onlogon | C:\Windows\system32\schtasks.exe | — | UPSecurityInput.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2836 | "C:\Users\admin\AppData\Local\Temp\UPEditorEdge_1.exe" | C:\Users\admin\AppData\Local\Temp\UPEditorEdge_1.exe | explorer.exe | ||||||||||||
User: admin Company: China UnionPay Integrity Level: HIGH Description: UnionPay Security Control Exit code: 0 Version: 1.0.0.4 Modules
| |||||||||||||||
| 3424 | "C:\Users\admin\AppData\Local\Temp\certmgr.exe" -add "C:\Users\admin\AppData\Local\Temp\mysign.cer" -c -s -r localMachine CA | C:\Users\admin\AppData\Local\Temp\certmgr.exe | — | UPEditorEdge_1.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3504 | C:\Windows\system32\UPEditNew\UPService.exe | C:\Windows\system32\UPEditNew\UPService.exe | — | services.exe | |||||||||||
User: SYSTEM Company: 中国银联股份有限公司 Integrity Level: SYSTEM Description: UPSecurityInputService Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| (PID) Process: | (3960) certmgr.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\ROOT\Certificates\FF9CEB13C83F15B800E6EFF987B2C72E01B4B320 |
| Operation: | write | Name: | Blob |
Value: 030000000100000014000000FF9CEB13C83F15B800E6EFF987B2C72E01B4B3202000000001000000D2040000308204CE308203B6A003020102021026DDD22B46C9C44D5A694D39807E72AD300D06092A864886F70D01010B0500307E310B300906035504061302504C31223020060355040A1319556E697A65746F20546563686E6F6C6F6769657320532E412E31273025060355040B131E43657274756D2043657274696669636174696F6E20417574686F72697479312230200603550403131943657274756D2054727573746564204E6574776F726B204341301E170D3134303931313132303030305A170D3237303630393130343633395A308185310B300906035504061302504C31223020060355040A1319556E697A65746F20546563686E6F6C6F6769657320532E412E31273025060355040B131E43657274756D2043657274696669636174696F6E20417574686F72697479312930270603550403132043657274756D20446F6D61696E2056616C69646174696F6E204341205348413230820122300D06092A864886F70D01010105000382010F003082010A0282010100A12563DF8DE42007D954D1D104F617E23E47FBC37425B8C4BF1212BCE070D13905C217B3F78270A04E07FE102AFFDB0D465E2494A38B459F189BCE42C4AEDB8333BCC2BBB430B6A73787787B48CB252C82BB0A4812607689EC8ECC8F1E5248E986025AC2B08A7C853DD9FF604F336CA6A1A085E1D753F2EA273D65A972C10883CCB0259C114624E03EF4A7EFED51B1659342B4F6E6860A1079323658B26BA8DCD57A1E9D14EE40E7B2464CBD9A29C2ECF830C162022AE21C8362D085361A83DE12842965EFD232BE316042A8CFF8DDEAD056471DBD76962413E7BED9992BFA3064F18A387AA6E12A9602B09DBAD88F6D4E7A94697DB093AA74E5939013FAA2990203010001A382013E3082013A300F0603551D130101FF040530030101FF301D0603551D0E04160414E531ADBF3A1196F483BC503CD4B7909B90EEDE25301F0603551D230418301680140876CDCB07FF24F6C5CDEDBB90BCE284374675F7300E0603551D0F0101FF040403020106302F0603551D1F042830263024A022A020861E687474703A2F2F63726C2E63657274756D2E706C2F63746E63612E63726C306B06082B06010505070101045F305D302806082B06010505073001861C687474703A2F2F73756263612E6F6373702D63657274756D2E636F6D303106082B060105050730028625687474703A2F2F7265706F7369746F72792E63657274756D2E706C2F63746E63612E63657230390603551D2004323030302E0604551D20003026302406082B060105050702011618687474703A2F2F7777772E63657274756D2E706C2F435053300D06092A864886F70D01010B05000382010100BABFF0E1DD4D2B42436458DF64F3FF801A5F56BE3BA9B276F7547A4C30C199244B72D2CAD4FA08C690DE8812EDF890F9FCA984FD92F278E5DBC92257AB4130426B0B9FD77333FB01671C425C8F2767C76E07038D0E96CB0A03CC3EF8873C3530CD188CD571DDCDDD61B013A364464EFE714E6B65E91404F23FA8BD0C363D2A5D9E07F2C24F90C55E4D1837D1272880A436E5CA936A650EF893B9AF52584B7A71D8BAF3EFD2F3F6A297E45D14029ACBE5AEB693E1239F9B3F46F7EE8EA1005B66C31E6823860F5D77BA53ADF952FB7015C575EBCF79AD497CF27662AE442FC55F513425416A120A5F8EAE10C4438935FDECFF31E6EC1E87E93A7C29504541A314 | |||
| (PID) Process: | (2836) UPEditorEdge_1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (2836) UPEditorEdge_1.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (3424) certmgr.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\SystemCertificates\CA\Certificates\07E032E020B72C3F192F0628A2593A19A70F069E |
| Operation: | write | Name: | Blob |
Value: 03000000010000001400000007E032E020B72C3F192F0628A2593A19A70F069E2000000001000000BF030000308203BB308202A3A00302010202030444C0300D06092A864886F70D0101050500307E310B300906035504061302504C31223020060355040A1319556E697A65746F20546563686E6F6C6F6769657320532E412E31273025060355040B131E43657274756D2043657274696669636174696F6E20417574686F72697479312230200603550403131943657274756D2054727573746564204E6574776F726B204341301E170D3038313032323132303733375A170D3239313233313132303733375A307E310B300906035504061302504C31223020060355040A1319556E697A65746F20546563686E6F6C6F6769657320532E412E31273025060355040B131E43657274756D2043657274696669636174696F6E20417574686F72697479312230200603550403131943657274756D2054727573746564204E6574776F726B20434130820122300D06092A864886F70D01010105000382010F003082010A0282010100E3FB7DA372BAC2F0C91487F56B014EE16E4007BA6D275D7FF75B2DB35AC7515FABA432A66187B66E0F86D2300297F8D76957A118395D6A6479C60159AC3C314A387CD204D24B28E8205F3B07A2CC4D73DBF3AE4FC756D55AA79689FAF3AB68D423865927CF0927BCAC6E72831C3072DFE0A2E9D2E1747519BD2A9E7B1554041BD74339AD5528C5E21ABBF4C0E4AE384933CC76859F3945D2A49EF2128C51F87CE42D7FF5AC5FEB169FB12DD1BACC9142774C25C990386FDBF0CCFB8E1E97593ED5604EE60528ED4979134BBA48DB2FF972D339CAFE1FD83472F5B440CF3101C3ECDE112D175D1FB850D15E19A769DE073328CA5095F9A754CB54865045A9F9490203010001A3423040300F0603551D130101FF040530030101FF301D0603551D0E041604140876CDCB07FF24F6C5CDEDBB90BCE284374675F7300E0603551D0F0101FF040403020106300D06092A864886F70D01010505000382010100A6A8AD22CE013DA6A3FF62D0489D8B5E72B07844E3DC1CAF09FD2348FABD2AC4B95504B510A38D27DE0B8263D0EEDE0C3779415B22B2B09A415CA670E0D4D077CB23D300E06C562FE1690D0DD9AABF218150D906A5A8FF9537D0AAFEE2B3F5992D45848AE54209D774022FF789D899E9BC27D4478DBA0D461C77CF14A41CB9A431C49C28740334FF331926A5E90D74B73E97C676E82796A366DDE1AEF2415BCA9856837370E4861AD23141BA2FBE2D135A766F4EE84E810E3F5B0322A012BE6658114ACB03C4B42A2A2D9617E03954BC48D376279D9A2D06A6C9EC39D2ABDB9F9A0B27023529B14095E7F9E89C55881946D6B734F57ECE399AD938F151F74F2C | |||
| (PID) Process: | (2836) UPEditorEdge_1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UnionPay Security Non plug |
| Operation: | write | Name: | DisplayName |
Value: UnionPay Security Non plug 1.0.0.4 | |||
| (PID) Process: | (2836) UPEditorEdge_1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UnionPay Security Non plug |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Windows\system32\UPEditNew\uninst.exe | |||
| (PID) Process: | (2836) UPEditorEdge_1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UnionPay Security Non plug |
| Operation: | write | Name: | UninstallString |
Value: C:\Windows\system32\UPEditNew\uninst.exe | |||
| (PID) Process: | (2836) UPEditorEdge_1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UnionPay Security Non plug |
| Operation: | write | Name: | DisplayVersion |
Value: 1.0.0.4 | |||
| (PID) Process: | (2836) UPEditorEdge_1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UnionPay Security Non plug |
| Operation: | write | Name: | URLInfoAbout |
Value: http://cn.unionpay.com/ | |||
| (PID) Process: | (2836) UPEditorEdge_1.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\UnionPay Security Non plug |
| Operation: | write | Name: | Publisher |
Value: China UnionPay | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2836 | UPEditorEdge_1.exe | C:\Windows\system32\UPEditNew\UPEditor.exe | executable | |
MD5:— | SHA256:— | |||
| 2836 | UPEditorEdge_1.exe | C:\Windows\system32\UPEditNew\UPService.exe | executable | |
MD5:— | SHA256:— | |||
| 2836 | UPEditorEdge_1.exe | C:\Windows\system32\UPEditNew\UPSecurityInput.exe | executable | |
MD5:— | SHA256:— | |||
| 2836 | UPEditorEdge_1.exe | C:\Users\admin\AppData\Local\Temp\nsrA30E.tmp\killer.dll | executable | |
MD5:16205CD992D3B3827573F93AB8923E4E | SHA256:967D66F23CF3D9D3E5A4D6A9C6E366E792A98CC8A293196095B10CD82DA9A695 | |||
| 2836 | UPEditorEdge_1.exe | C:\Users\admin\AppData\Local\Temp\nsrA30E.tmp\nsDialogs.dll | executable | |
MD5:E75AE7CFE06FF9692D98A934F6AA2D3C | SHA256:1F861AEB145EBBB9A2628414E6DCA6B06D0BFB252F2DE624B86814CFEC8097D0 | |||
| 2836 | UPEditorEdge_1.exe | C:\Users\admin\AppData\Local\Temp\nsrA30E.tmp\modern-wizard.bmp | image | |
MD5:91F4841138F8FB23CA3422662EBE1441 | SHA256:5193152942FE5B5C40E077F3093A0E74A9083F543BD3AC58CE2D3FE39FF5DE4D | |||
| 2836 | UPEditorEdge_1.exe | C:\Users\admin\AppData\Local\Temp\nsrA30E.tmp\System.dll | executable | |
MD5:A436DB0C473A087EB61FF5C53C34BA27 | SHA256:75ED40311875312617D6711BAED0BE29FCAEE71031CA27A8D308A72B15A51E49 | |||
| 2672 | UPEditor.exe | C:\Windows\system32\drivers\PassGuard.sys | executable | |
MD5:4A48F0DA01A4D47D394BB53E438542E5 | SHA256:5E727C26E03D2C2287BB9770A43760C4390AFD43EE8DBC234228917C00A62C17 | |||
| 2836 | UPEditorEdge_1.exe | C:\Users\admin\AppData\Local\Temp\nsrA30E.tmp\FindProcDLL.dll | executable | |
MD5:8614C450637267AFACAD1645E23BA24A | SHA256:0FA04F06A6DE18D316832086891E9C23AE606D7784D5D5676385839B21CA2758 | |||
| 2836 | UPEditorEdge_1.exe | C:\Users\admin\AppData\Local\Temp\nsrA30E.tmp\KillProcDLL.dll | executable | |
MD5:99F345CF51B6C3C317D20A81ACB11012 | SHA256:C2689BA1F66066AFCE85CA6457ECD36370BE0FE351C58422E45EFD0948655C93 | |||
Domain | IP | Reputation |
|---|---|---|
teredo.ipv6.microsoft.com |
| whitelisted |
Process | Message |
|---|---|
UPEditor.exe | ¸±°æ±¾ = 1 |
UPEditor.exe | ¸±°æ±¾ = 1 |
UPEditor.exe | buildnumber = 7601 |