| File name: | inis_ex_sha2.exe |
| Full analysis: | https://app.any.run/tasks/c1191442-7153-4dda-8bd1-38c5f0133856 |
| Verdict: | Malicious activity |
| Analysis date: | January 19, 2024, 02:04:34 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | FBCBCD5B908000BC48F232FC52CEE436 |
| SHA1: | AF8F23A6FE96FB70124CF4CD0C3CE33A127FDCC3 |
| SHA256: | 78E3F562E4A1ADED479D9632DE0ACE8C4765EEE77B39435B9E1DAE60A46A4E57 |
| SSDEEP: | 98304:XGajmcNRfyth2YY94pHEvmIKYfLQxscnIR/vTAWvWJk0Vk6iDS/Qndu9aiT2oiQi:L5ipxw5uxaL5fX0UOZVD+3k2P |
| .exe | | | NSIS - Nullsoft Scriptable Install System (91.9) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (3.3) |
| .exe | | | Win64 Executable (generic) (3) |
| .dll | | | Win32 Dynamic Link Library (generic) (0.7) |
| .exe | | | Win32 Executable (generic) (0.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2015:08:05 02:46:27+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 24064 |
| InitializedDataSize: | 117760 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x3217 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 3.4.1.2 |
| ProductVersionNumber: | 3.4.1.2 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Korean |
| CharacterSet: | Windows, Korea (Shift - KSC 5601) |
| Comments: | - |
| CompanyName: | Initech (c) |
| FileDescription: | INISAFE CrossWeb EX V3 Installer |
| FileVersion: | 3.4.1.2 |
| LegalCopyright: | Initech Co., Ltd. All right reserved. |
| LegalTrademarks: | INISAFE CrossWeb EX V3 is a trademark of Initech |
| ProductName: | INISAFE CrossWeb EX V3 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | "C:\Users\admin\AppData\Local\Temp\inis_ex_sha2.exe" | C:\Users\admin\AppData\Local\Temp\inis_ex_sha2.exe | explorer.exe | ||||||||||||
User: admin Company: Initech (c) Integrity Level: MEDIUM Description: INISAFE CrossWeb EX V3 Installer Exit code: 0 Version: 3.4.1.2 Modules
| |||||||||||||||
| 492 | "C:\Users\admin\AppData\Local\Temp\inis_ex_sha2.exe" /UAC:30152 /NCRC | C:\Users\admin\AppData\Local\Temp\inis_ex_sha2.exe | inis_ex_sha2.exe | ||||||||||||
User: admin Company: Initech (c) Integrity Level: HIGH Description: INISAFE CrossWeb EX V3 Installer Exit code: 0 Version: 3.4.1.2 Modules
| |||||||||||||||
| 1044 | "C:\Users\admin\AppData\Local\Temp\nsx2FB.tmp\ns11C1.tmp" "C:\Program Files\INITECH\INISAFE Web EX Client\INISAFETrayEX.exe" /RegServer | C:\Users\admin\AppData\Local\Temp\nsx2FB.tmp\ns11C1.tmp | — | inis_ex_sha2.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1236 | C:\Windows\system32\cmd.exe /C ""C:\Program Files\INITECH\INISAFE Web EX Client\certutil.exe" -D -d "C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles/qldyz51w.default" -n "Initech Root Authority - CrossWeb EX"" | C:\Windows\System32\cmd.exe | — | inis_ex_sha2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1592 | C:\Windows\system32\cmd.exe /C ""C:\Program Files\INITECH\INISAFE Web EX Client\certutil.exe" -D -d "sql:C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles/qldyz51w.default" -n "Initech Root Authority - CrossWeb EX"" | C:\Windows\System32\cmd.exe | — | inis_ex_sha2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 1 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1608 | "C:\Program Files\INITECH\INISAFE Web EX Client\INISAFETrayEX.exe" /RegServer | C:\Program Files\INITECH\INISAFE Web EX Client\INISAFETrayEX.exe | — | ns11C1.tmp | |||||||||||
User: admin Company: INITECH (C) Integrity Level: HIGH Description: INISAFE CrossWeb EX Client Tray Exit code: 0 Version: 1, 3, 0, 7 Modules
| |||||||||||||||
| 1624 | "C:\Program Files\INITECH\INISAFE Web EX Client\INISAFECrossWebEXSvc.exe" | C:\Program Files\INITECH\INISAFE Web EX Client\INISAFECrossWebEXSvc.exe | — | explorer.exe | |||||||||||
User: admin Company: Initech Co., Ltd. Integrity Level: MEDIUM Description: INISAFECrossWebEX Svc Exit code: 0 Version: 3, 0, 0, 15 Modules
| |||||||||||||||
| 1636 | "C:\Program Files\INITECH\INISAFE Web EX Client\certutil.exe" -A -n "Initech Root Authority - CrossWeb EX" -t "TCu,Cu,Tu" -i "inirootcert.cer" -d "sql:C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles/qldyz51w.default" | C:\Program Files\INITECH\INISAFE Web EX Client\certutil.exe | cmd.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1740 | C:\Windows\system32\cmd.exe /C ""C:\Program Files\INITECH\INISAFE Web EX Client\certutil.exe" -A -n "Initech Root Authority - CrossWeb EX" -t "TCu,Cu,Tu" -i "inirootcert.cer" -d "sql:C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles/qldyz51w.default"" | C:\Windows\System32\cmd.exe | — | inis_ex_sha2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 1820 | C:\Windows\system32\cmd.exe /C ""C:\Program Files\INITECH\INISAFE Web EX Client\certutil.exe" -A -n "Initech Root Authority - CrossWeb EX" -t "TCu,Cuw,Tuw" -i "inirootcert.cer" -d "C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles/qldyz51w.default"" | C:\Windows\System32\cmd.exe | — | inis_ex_sha2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| (PID) Process: | (116) inis_ex_sha2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (116) inis_ex_sha2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (116) inis_ex_sha2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (116) inis_ex_sha2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (492) inis_ex_sha2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery |
| Operation: | write | Name: | AutoRecover |
Value: 0 | |||
| (PID) Process: | (492) inis_ex_sha2.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery |
| Operation: | write | Name: | AutoRecover |
Value: 2 | |||
| (PID) Process: | (1892) INISAFECrossWebEXSvc.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (1892) INISAFECrossWebEXSvc.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main |
| Operation: | write | Name: | DOMStorage |
Value: 1 | |||
| (PID) Process: | (492) inis_ex_sha2.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\INISAFEClientManager |
| Operation: | write | Name: | ImagePath |
Value: C:\Program Files\initech\common\ClientService\IniClientSvc.exe | |||
| (PID) Process: | (492) inis_ex_sha2.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\Control\Session Manager |
| Operation: | write | Name: | PendingFileRenameOperations |
Value: \??\C:\Users\admin\AppData\Local\Temp\nsx2FB.tmp\UAC.dll | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 492 | inis_ex_sha2.exe | C:\Users\admin\AppData\Local\Temp\nsx2FB.tmp\UAC.dll | executable | |
MD5:E910A8BD10B97065EE3B1C024FAFC4AC | SHA256:1C62037E97B5EEBB102B879B5D6D11724C7F757D6163D369A5507EE7DFFD284D | |||
| 116 | inis_ex_sha2.exe | C:\Users\admin\AppData\Local\Temp\nsgFEF4.tmp\UAC.dll | executable | |
MD5:E910A8BD10B97065EE3B1C024FAFC4AC | SHA256:1C62037E97B5EEBB102B879B5D6D11724C7F757D6163D369A5507EE7DFFD284D | |||
| 492 | inis_ex_sha2.exe | C:\Windows\system32\ISF_CheckSFilter.dll | executable | |
MD5:A7FD2662E0955749042A8C35BDAFC248 | SHA256:E8A74825F159F00B5B0A2EAA1008FC25BA6F0EB4EAFE231F0899D21A8863A05F | |||
| 492 | inis_ex_sha2.exe | C:\Users\admin\AppData\Local\Temp\nsx2FB.tmp\UAC.LNG | text | |
MD5:1E72C0B7743619809B7CDA824D2A1ECF | SHA256:F2E214452E69EDAF602E30D06EE186D072B1D2EC04B813B458C1E31B56ECE16B | |||
| 492 | inis_ex_sha2.exe | C:\Program Files\NPKI\KISA\FF8A46723358E8488822AA1768DA1648098B3591_3.der | binary | |
MD5:9F6C1F0F07AC1921F915BBD5C72CD82A | SHA256:956057517FF3BB35049342288C1C9DCE852DACA652B465E9747253B5F93B1F5E | |||
| 492 | inis_ex_sha2.exe | C:\Windows\system32\msvcr71.dll | executable | |
MD5:F06F36C0E55E5B4312792D6FCACC8042 | SHA256:2404659784ADE7F874FEEFBB4816DB4E42852EDE0693FB2A7B45145501EA24CD | |||
| 492 | inis_ex_sha2.exe | C:\Windows\system32\MFC71.dll | executable | |
MD5:F35A584E947A5B401FEB0FE01DB4A0D7 | SHA256:4DA5EFDC46D126B45DAEEE8BC69C0BA2AA243589046B7DFD12A7E21B9BEE6A32 | |||
| 492 | inis_ex_sha2.exe | C:\Windows\system32\msvcp71.dll | executable | |
MD5:561FA2ABB31DFA8FAB762145F81667C2 | SHA256:DF96156F6A548FD6FE5672918DE5AE4509D3C810A57BFFD2A91DE45A3ED5B23B | |||
| 492 | inis_ex_sha2.exe | C:\Windows\Application Data\initech\KeyContainer\CACert\ccefed47.0 | binary | |
MD5:65E6E6FD7D5924852B5081A828E7C6C7 | SHA256:C842D352ECD67A57261224EE0CCC99DB84699BF2F12B70D3EB7D1811DB5817FC | |||
| 492 | inis_ex_sha2.exe | C:\Windows\Application Data\initech\KeyContainer\CACert\af049c7a.0 | text | |
MD5:46A785C7F8BC5D80C6C1CF63787B399C | SHA256:8747F7D2ADC46D155F0B392DCBD2C01E0ED4D97AEA7AEB861747A587B1DFDB98 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2884 | chrome.exe | 142.250.184.227:443 | clientservices.googleapis.com | GOOGLE | US | whitelisted |
2260 | chrome.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
2884 | chrome.exe | 66.102.1.84:443 | accounts.google.com | GOOGLE | US | unknown |
2884 | chrome.exe | 142.250.186.36:443 | www.google.com | GOOGLE | US | whitelisted |
2884 | chrome.exe | 142.250.186.35:443 | www.gstatic.com | GOOGLE | US | whitelisted |
2884 | chrome.exe | 142.250.186.174:443 | apis.google.com | GOOGLE | US | whitelisted |
2884 | chrome.exe | 142.250.186.170:443 | www.googleapis.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
clientservices.googleapis.com |
| whitelisted |
accounts.google.com |
| shared |
www.google.com |
| whitelisted |
www.gstatic.com |
| whitelisted |
apis.google.com |
| whitelisted |
www.googleapis.com |
| whitelisted |
update.googleapis.com |
| whitelisted |
Process | Message |
|---|---|
inis_ex_sha2.exe | !@!@!@!@ ISF_NSIS_UTIL::KillProcessByFileShortName Not Existing process: INISAFECROSSWEBEXSVC.EXE
|
inis_ex_sha2.exe | !@!@!@!@ ISF_NSIS_UTIL::KillProcessByFileShortName Not Existing process: INISAFEADMINUTIL.EXE
|
inis_ex_sha2.exe | [INISAFEWebV6] ExitInstance() called |