File name:

ecussign_proportable.exe

Full analysis: https://app.any.run/tasks/ce67bf6d-95d4-4a93-a8fc-0840b01a83e0
Verdict: Malicious activity
Analysis date: April 22, 2024, 15:19:02
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

24B612072A97E6FBD2BDF63598EE8F77

SHA1:

662D3F9D56FE3D96E45708AEEA8CC0928A4DC5D3

SHA256:

578AC0941C51083CBCA77B5604E915419494230FC99F3D0EED305D629891B056

SSDEEP:

98304:NYu9tV3eeExH7toZ0dCZ3xvORStZigAjBC2emkYOwbWQUvPMYKB3IxSibpvlBD6k:xFwBggrrVIJczttG8O

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • ecussign_proportable.exe (PID: 3108)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • ecussign_proportable.exe (PID: 3108)
    • Process drops legitimate windows executable

      • ecussign_proportable.exe (PID: 3108)
    • The process creates files with name similar to system file names

      • ecussign_proportable.exe (PID: 3108)
    • Creates a software uninstall entry

      • ecussign_proportable.exe (PID: 3108)
    • Non-standard symbols in registry

      • ecussign_proportable.exe (PID: 3108)
    • Reads security settings of Internet Explorer

      • ECUSSIGN_PRO.exe (PID: 2528)
    • Reads the Internet Settings

      • ECUSSIGN_PRO.exe (PID: 2528)
  • INFO

    • Checks supported languages

      • ecussign_proportable.exe (PID: 3108)
      • ECUSSIGN_PRO.exe (PID: 2528)
    • Reads the computer name

      • ecussign_proportable.exe (PID: 3108)
      • ECUSSIGN_PRO.exe (PID: 2528)
    • Reads Microsoft Office registry keys

      • ecussign_proportable.exe (PID: 3108)
    • Reads the machine GUID from the registry

      • ecussign_proportable.exe (PID: 3108)
      • ECUSSIGN_PRO.exe (PID: 2528)
    • Create files in a temporary directory

      • ecussign_proportable.exe (PID: 3108)
    • Reads Environment values

      • ecussign_proportable.exe (PID: 3108)
      • ECUSSIGN_PRO.exe (PID: 2528)
    • Creates files in the program directory

      • ecussign_proportable.exe (PID: 3108)
    • Manual execution by a user

      • ECUSSIGN_PRO.exe (PID: 2528)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (42.2)
.exe | Win64 Executable (generic) (37.3)
.dll | Win32 Dynamic Link Library (generic) (8.8)
.exe | Win32 Executable (generic) (6)
.exe | Generic Win/DOS Executable (2.7)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2018:04:06 10:13:23+00:00
ImageFileCharacteristics: Executable, 32-bit
PEType: PE32
LinkerVersion: 8
CodeSize: 8192
InitializedDataSize: 6052864
UninitializedDataSize: -
EntryPoint: 0x15a9
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 2023.9.7.1521
ProductVersionNumber: 2.1.0.0
FileFlagsMask: 0x003f
FileFlags: Special build
FileOS: Windows NT 32-bit
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
ProductName: ECUSSIGN_PRO
ProductVersion: 2.1
CompanyName: TSD
LegalCopyright: Copyright © 2023 TSD
Email: phunv@thaison.vn
WebSite: https://www.thaison.vn
FileDescription: Installer for ECUSSIGN_PRO
FileVersion: 2023.9.7.1521
OriginalFileName: ECUSSIGN_PRO-Setup.exe
InternalName: TSULoader
Comments: WinNT (x86) Unicode Lib Rel
ProductCode: {1A05959C-4751-43D5-BA71-942A85E59DA1}
PackageCode: {580F646C-31DA-49C4-5334-69D9E0BF1888}
Arguments: -
SpecialBuild: -
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
48
Monitored processes
3
Malicious processes
1
Suspicious processes
0

Behavior graph

Click at the process to see the details
start ecussign_proportable.exe ecussign_pro.exe ecussign_proportable.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
324"C:\Users\admin\AppData\Local\Temp\ecussign_proportable.exe" C:\Users\admin\AppData\Local\Temp\ecussign_proportable.exeexplorer.exe
User:
admin
Company:
TSD
Integrity Level:
MEDIUM
Description:
Installer for ECUSSIGN_PRO
Exit code:
3221226540
Version:
2023.9.7.1521
Modules
Images
c:\users\admin\appdata\local\temp\ecussign_proportable.exe
c:\windows\system32\ntdll.dll
2528"C:\Users\admin\Desktop\aaa\ECUSSIGN_PRO.exe" C:\Users\admin\Desktop\aaa\ECUSSIGN_PRO.exe
explorer.exe
User:
admin
Company:
TSD
Integrity Level:
MEDIUM
Description:
Ký số dữ liệu trình ký
Exit code:
0
Version:
20.5.22.1
Modules
Images
c:\users\admin\desktop\aaa\ecussign_pro.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
3108"C:\Users\admin\AppData\Local\Temp\ecussign_proportable.exe" C:\Users\admin\AppData\Local\Temp\ecussign_proportable.exe
explorer.exe
User:
admin
Company:
TSD
Integrity Level:
HIGH
Description:
Installer for ECUSSIGN_PRO
Exit code:
0
Version:
2023.9.7.1521
Modules
Images
c:\users\admin\appdata\local\temp\ecussign_proportable.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\imm32.dll
Total events
4 347
Read events
4 273
Write events
50
Delete events
24

Modification events

(PID) Process:(3108) ecussign_proportable.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Owner
Value:
240C00000E30376FC894DA01
(PID) Process:(3108) ecussign_proportable.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:SessionHash
Value:
89581DBC33AF7C6A2A0FF3CC13EB4A8643CA423D6E79D493B367DFF95C16C526
(PID) Process:(3108) ecussign_proportable.exeKey:HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000
Operation:writeName:Sequence
Value:
1
(PID) Process:(3108) ecussign_proportable.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3108) ecussign_proportable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\Fonts
Operation:writeName:Times New Roman (TrueType)
Value:
C:\Users\admin\Desktop\aaa\times.ttf
(PID) Process:(3108) ecussign_proportable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1A05959C-4751-43D5-BA71-942A85E59DA1}
Operation:writeName:UninstallString
Value:
C:\PROGRA~2\TSD\UNINST~1\{1A059~1\Setup.exe /remove /q0
(PID) Process:(3108) ecussign_proportable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1A05959C-4751-43D5-BA71-942A85E59DA1}
Operation:writeName:QuietUninstallString
Value:
C:\PROGRA~2\TSD\UNINST~1\{1A059~1\Setup.exe /remove /q
(PID) Process:(3108) ecussign_proportable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1A05959C-4751-43D5-BA71-942A85E59DA1}
Operation:writeName:ModifyPath
Value:
C:\PROGRA~2\TSD\UNINST~1\{1A059~1\Setup.exe /q0
(PID) Process:(3108) ecussign_proportable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1A05959C-4751-43D5-BA71-942A85E59DA1}
Operation:writeName:Version
Value:
33619968
(PID) Process:(3108) ecussign_proportable.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\{1A05959C-4751-43D5-BA71-942A85E59DA1}
Operation:writeName:VersionMajor
Value:
2
Executable files
39
Suspicious files
8
Text files
39
Unknown types
0

Dropped files

PID
Process
Filename
Type
3108ecussign_proportable.exeC:\Users\admin\Desktop\aaa\ErrLog.Log
MD5:
SHA256:
3108ecussign_proportable.exeC:\Users\admin\Desktop\aaa\ECUSSIGN.db
MD5:
SHA256:
3108ecussign_proportable.exeC:\Users\admin\Desktop\aaa\Template\ToKhaiHQ7X.xls._tm
MD5:
SHA256:
3108ecussign_proportable.exeC:\Users\admin\Desktop\aaa\Template\ToKhaiHQ7N.xls
MD5:
SHA256:
3108ecussign_proportable.exeC:\Users\admin\Desktop\aaa\Bin5\ExcelApi.dll._tm
MD5:
SHA256:
3108ecussign_proportable.exeC:\Users\admin\AppData\Local\Temp\Tsu91057078.dllexecutable
MD5:08794F2309B793CB8FFA34BBAFD7535E
SHA256:326E4CCD562FA13ABF20A66B5ECFA842279BBC46621EF598D8F783A173F9F6C0
3108ecussign_proportable.exeC:\Users\admin\AppData\Local\Temp\11E63978\Setup.icoimage
MD5:C3926CEF276C0940DADBC8142153CEC9
SHA256:0EC48E3C1886BC0169A4BC262F012E9B7914E3B440BB0ECC4D8123924ABC9B93
3108ecussign_proportable.exeC:\Users\admin\AppData\Local\Temp\11E63978.datbinary
MD5:2A45EF4F11DBF00F99479F6F65363AFA
SHA256:8BEFF210EA88FB43E06DE0723A7028CC0F5FB9AEE8993BFD01215DFC9E0F35A7
3108ecussign_proportable.exeC:\ProgramData\TSD\Uninstall\{1A05959C-4751-43D5-BA71-942A85E59DA1}\Setup.exeexecutable
MD5:A748AE8A60655E3B429A5D1E70B1C8B6
SHA256:F620919E79667033724977C186AD8F02B9C29A84AB1143F67379842A78438872
3108ecussign_proportable.exeC:\Users\admin\Desktop\aaa\Bin5\C1.Win.C1TrueDBGrid.2.dll._tm
MD5:
SHA256:
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
3
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
224.0.0.252:5355
unknown
4
System
192.168.100.255:137
unknown

DNS requests

No data

Threats

No threats detected
Process
Message
ECUSSIGN_PRO.exe
Native library pre-loader is trying to load native SQLite library "C:\Users\admin\Desktop\aaa\bin5\x86\SQLite.Interop.dll"...