| File name: | tam.exe |
| Full analysis: | https://app.any.run/tasks/6c2e92ef-8930-4f83-a649-8e095bf6fc3c |
| Verdict: | Malicious activity |
| Analysis date: | February 02, 2020, 13:43:53 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, WISE installer self-extracting archive |
| MD5: | 9D6A1460EC0CB3DD7A9CD7D778A68824 |
| SHA1: | 0FFE10F11A85547933918E09CD33F197207BB0AE |
| SHA256: | 53CF8292E664E9B41FBBB37DD498D8D0AB633D7BC58B856F26AA10344EB064D8 |
| SSDEEP: | 393216:8x1vcLfdaQapNygi5703hYAOJOnMA5u89G206kA:OYZapNygid0xYdg5VT065 |
| .exe | | | InstallShield setup (36.8) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (26.6) |
| .exe | | | Win64 Executable (generic) (23.6) |
| .dll | | | Win32 Dynamic Link Library (generic) (5.6) |
| .exe | | | Win32 Executable (generic) (3.8) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2006:12:15 22:21:24+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 7.1 |
| CodeSize: | 24576 |
| InitializedDataSize: | 15655424 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x4197 |
| OSVersion: | 4 |
| ImageVersion: | 4 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 6.3.5.9506 |
| ProductVersionNumber: | 6.3.5.9506 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Windows 16-bit |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| CompanyName: | Gamelectronics Co. |
| FileDescription: | Emwat Service |
| FileVersion: | 6.3.5.9506 |
| LegalCopyright: | Gamelectronics Co. |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 852 | "C:\Users\admin\AppData\Local\Temp\pb2DEA\zvprt5_setup.exe" | C:\Users\admin\AppData\Local\Temp\pb2DEA\zvprt5_setup.exe | — | GAMPrinterSetup.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 860 | C:\Windows\system32\svchost.exe -k netsvcs | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1188 | C:\Windows\System32\spoolsv.exe | C:\Windows\System32\spoolsv.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Spooler SubSystem App Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1524 | C:\Windows\system32\MsiExec.exe -Embedding 4627CF17513C5989D0C920DF4D538603 C | C:\Windows\system32\MsiExec.exe | msiexec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2152 | "C:\Windows\System32\msiexec.exe" /I "C:\Program Files\Common Files\Wise Installation Wizard\WIS09E731C7225A4BA5B1B0BA4560DCE42B_6_3_5_9506.MSI" WISE_SETUP_EXE_PATH="C:\Users\admin\AppData\Local\Temp\tam.exe" | C:\Windows\System32\msiexec.exe | — | tam.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2500 | "C:\Users\admin\AppData\Local\Temp\tam.exe" | C:\Users\admin\AppData\Local\Temp\tam.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 | |||||||||||||||
| 2780 | "C:\ProgramData\Gamelectronics\Emwat Service\GAMPrinterSetup.exe" | C:\ProgramData\Gamelectronics\Emwat Service\GAMPrinterSetup.exe | msiexec.exe | ||||||||||||
User: admin Company: GAM Electronics, info@gamelectronics.com Integrity Level: HIGH Description: Self-Extracting Package for GAM Virtual Printer Exit code: 0 Version: 1.1.0.0 Modules
| |||||||||||||||
| 2888 | "C:\Users\admin\AppData\Local\Temp\pb2DEA\AutoRegister.exe" | C:\Users\admin\AppData\Local\Temp\pb2DEA\AutoRegister.exe | — | GAMPrinterSetup.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2892 | C:\Windows\system32\MsiExec.exe -Embedding 29F8A8D97403B6C0DC42D0FAF4DCC1DD | C:\Windows\system32\MsiExec.exe | msiexec.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2988 | "C:\Windows\09E731C7225A4BA5B1B0BA4560DCE42B.TMP\WiseCustomCalla1.exe" | C:\Windows\09E731C7225A4BA5B1B0BA4560DCE42B.TMP\WiseCustomCalla1.exe | MsiExec.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (3404) tam.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (3404) tam.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (3988) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 400000000000000088F644EECED9D501940F0000040E0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3988) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 400000000000000088F644EECED9D501940F0000040E0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3912) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 400000000000000030CB9AEECED9D501480F0000C00E0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3912) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Shadow Copy Optimization Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 400000000000000030CB9AEECED9D501480F0000300C0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3912) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 400000000000000030CB9AEECED9D501480F0000080D0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3912) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 400000000000000030CB9AEECED9D501480F0000D40C0000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3912) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\COM+ REGDB Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 40000000000000003EF2A1EECED9D501480F0000D40C0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3912) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\Registry Writer |
| Operation: | write | Name: | IDENTIFY (Leave) |
Value: 40000000000000003EF2A1EECED9D501480F0000C00E0000E8030000000000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3404 | tam.exe | C:\Program Files\Common Files\Wise Installation Wizard\WIS09E731C7225A4BA5B1B0BA4560DCE42B_6_3_5_9506.MSI | — | |
MD5:— | SHA256:— | |||
| 2152 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI769F.tmp | — | |
MD5:— | SHA256:— | |||
| 2152 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI770E.tmp | — | |
MD5:— | SHA256:— | |||
| 2152 | msiexec.exe | C:\Users\admin\AppData\Local\Temp\MSI772E.tmp | — | |
MD5:— | SHA256:— | |||
| 3988 | msiexec.exe | C:\System Volume Information\SPP\metadata-2 | — | |
MD5:— | SHA256:— | |||
| 3988 | msiexec.exe | C:\Windows\Installer\a71c17.msi | — | |
MD5:— | SHA256:— | |||
| 2988 | WiseCustomCalla1.exe | C:\Users\admin\AppData\Local\Temp\GLG233E.tmp | — | |
MD5:— | SHA256:— | |||
| 3912 | vssvc.exe | C: | — | |
MD5:— | SHA256:— | |||
| 2892 | MsiExec.exe | C:\Windows\09E731C7225A4BA5B1B0BA4560DCE42B.TMP\WiseData.ini | — | |
MD5:— | SHA256:— | |||
| 1524 | MsiExec.exe | C:\Windows\09E731C7225A4BA5B1B0BA4560DCE42B.TMP\WiseCustomCall.dll | executable | |
MD5:— | SHA256:— | |||
Process | Message |
|---|---|
MsiExec.exe | UpgradeCheck: Begin...
|
MsiExec.exe | UpgradeCheck: ...End
|
zvprt5_setup_x86.exe | Setup finished successfully |