File name:

NetTimeSetup-314.exe

Full analysis: https://app.any.run/tasks/5c2dca44-2d56-4ba9-a79c-aa4067461c51
Verdict: Malicious activity
Analysis date: January 25, 2024, 09:49:32
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

107C0E40D46936B166F362090D34AA4C

SHA1:

FCD9C88AA5F6E85E997BDA6F7DF02595F45329A4

SHA256:

7B489CBBC654FE26F39300387AE28A2A538CF76E68335F573A762EC18222A808

SSDEEP:

24576:CSdEn9rb+dgIc6FueA0illGacLmnPw5xUNEqCaiBoioIPvrJiS2dBVBXuKuC7Tu+:CSk9rb+dgIc6FueA0illGacLmnPyxWEI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Antivirus name has been found in the command line (generic signature)

      • NetTimeSetup-314.tmp (PID: 2580)
      • NetTimeSetup-314.exe (PID: 3456)
      • NetTimeSetup-314.tmp (PID: 1880)
      • NetTimeSetup-314.exe (PID: 1388)
    • Drops the executable file immediately after the start

      • NetTimeSetup-314.exe (PID: 1388)
      • NetTimeSetup-314.exe (PID: 3456)
      • NetTimeSetup-314.tmp (PID: 1880)
    • Changes the autorun value in the registry

      • NetTime.exe (PID: 900)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • NetTimeSetup-314.exe (PID: 3456)
      • NetTimeSetup-314.exe (PID: 1388)
      • NetTimeSetup-314.tmp (PID: 1880)
    • Process drops legitimate windows executable

      • NetTimeSetup-314.tmp (PID: 1880)
    • Reads the Windows owner or organization settings

      • NetTimeSetup-314.tmp (PID: 1880)
    • Executes as Windows Service

      • NetTimeService.exe (PID: 2452)
    • Application launched itself

      • NetTime.exe (PID: 2908)
    • Reads the Internet Settings

      • NetTime.exe (PID: 2908)
  • INFO

    • Checks supported languages

      • NetTimeSetup-314.exe (PID: 3456)
      • NetTime.exe (PID: 2388)
      • NetTimeSetup-314.exe (PID: 1388)
      • NetTimeSetup-314.tmp (PID: 2580)
      • NetTimeSetup-314.tmp (PID: 1880)
      • NetTimeService.exe (PID: 2452)
      • NetTime.exe (PID: 2792)
      • NetTime.exe (PID: 2908)
      • NetTime.exe (PID: 900)
      • NetTime.exe (PID: 3332)
      • NetTimeService.exe (PID: 2804)
    • Reads the computer name

      • NetTimeSetup-314.tmp (PID: 2580)
      • NetTimeSetup-314.tmp (PID: 1880)
      • NetTimeService.exe (PID: 2452)
      • NetTimeService.exe (PID: 2804)
      • NetTime.exe (PID: 2908)
      • NetTime.exe (PID: 2792)
      • NetTime.exe (PID: 900)
      • NetTime.exe (PID: 2388)
      • NetTime.exe (PID: 3332)
    • Create files in a temporary directory

      • NetTimeSetup-314.exe (PID: 3456)
      • NetTimeSetup-314.exe (PID: 1388)
      • NetTimeSetup-314.tmp (PID: 1880)
    • Creates files in the program directory

      • NetTimeSetup-314.tmp (PID: 1880)
      • NetTimeService.exe (PID: 2452)
    • Process checks whether UAC notifications are on

      • NetTime.exe (PID: 2908)
    • Manual execution by a user

      • cmd.exe (PID: 2952)
      • taskmgr.exe (PID: 3032)
      • NetTime.exe (PID: 3332)
      • taskmgr.exe (PID: 3372)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:20 00:22:17+02:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 37888
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0x9c40
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Mark Griffiths
FileDescription: NetTime Setup
FileVersion:
LegalCopyright: Copyright © 1997, 2000 by Graham Mainwaring, Copyright © 2011, 2012 Mark Griffiths
ProductName: NetTime
ProductVersion:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
59
Monitored processes
15
Malicious processes
6
Suspicious processes
0

Behavior graph

Click at the process to see the details
start nettimesetup-314.exe nettimesetup-314.tmp no specs nettimesetup-314.exe nettimesetup-314.tmp nettime.exe no specs nettimeservice.exe no specs nettimeservice.exe nettime.exe no specs nettime.exe nettime.exe taskmgr.exe no specs nettime.exe no specs taskmgr.exe no specs cmd.exe no specs netstat.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
900"C:\Program Files\NetTime\NetTime.exe" /showconfigC:\Program Files\NetTime\NetTime.exe
NetTime.exe
User:
admin
Integrity Level:
HIGH
Description:
Network Time Synchronizer
Exit code:
0
Version:
3.1.4.220
Modules
Images
c:\program files\nettime\nettime.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1388"C:\Users\admin\AppData\Local\Temp\NetTimeSetup-314.exe" /SPAWNWND=$1501BC /NOTIFYWND=$8010A C:\Users\admin\AppData\Local\Temp\NetTimeSetup-314.exe
NetTimeSetup-314.tmp
User:
admin
Company:
Mark Griffiths
Integrity Level:
HIGH
Description:
NetTime Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\nettimesetup-314.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1880"C:\Users\admin\AppData\Local\Temp\is-QQH9H.tmp\NetTimeSetup-314.tmp" /SL5="$1800E6,532342,54272,C:\Users\admin\AppData\Local\Temp\NetTimeSetup-314.exe" /SPAWNWND=$1501BC /NOTIFYWND=$8010A C:\Users\admin\AppData\Local\Temp\is-QQH9H.tmp\NetTimeSetup-314.tmp
NetTimeSetup-314.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-qqh9h.tmp\nettimesetup-314.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2388"C:\Program Files\NetTime\NetTime.exe" /installserviceC:\Program Files\NetTime\NetTime.exeNetTimeSetup-314.tmp
User:
admin
Integrity Level:
HIGH
Description:
Network Time Synchronizer
Exit code:
0
Version:
3.1.4.220
Modules
Images
c:\program files\nettime\nettime.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2452"C:\Program Files\NetTime\NetTimeService.exe"C:\Program Files\NetTime\NetTimeService.exe
services.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Description:
Network Time Synchronizer - NT Service
Exit code:
0
Version:
3.1.4.220
Modules
Images
c:\program files\nettime\nettimeservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2580"C:\Users\admin\AppData\Local\Temp\is-FN4MM.tmp\NetTimeSetup-314.tmp" /SL5="$8010A,532342,54272,C:\Users\admin\AppData\Local\Temp\NetTimeSetup-314.exe" C:\Users\admin\AppData\Local\Temp\is-FN4MM.tmp\NetTimeSetup-314.tmpNetTimeSetup-314.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-fn4mm.tmp\nettimesetup-314.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
2792"C:\Program Files\NetTime\NetTime.exe" /enableautostartC:\Program Files\NetTime\NetTime.exeNetTimeSetup-314.tmp
User:
admin
Integrity Level:
HIGH
Description:
Network Time Synchronizer
Exit code:
0
Version:
3.1.4.220
Modules
Images
c:\program files\nettime\nettime.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2804"C:\Program Files\NetTime\NetTimeService.exe" /install /silentC:\Program Files\NetTime\NetTimeService.exeNetTime.exe
User:
admin
Integrity Level:
HIGH
Description:
Network Time Synchronizer - NT Service
Exit code:
0
Version:
3.1.4.220
Modules
Images
c:\program files\nettime\nettimeservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2908"C:\Program Files\NetTime\NetTime.exe" /firstrunC:\Program Files\NetTime\NetTime.exe
NetTimeSetup-314.tmp
User:
admin
Integrity Level:
MEDIUM
Description:
Network Time Synchronizer
Exit code:
0
Version:
3.1.4.220
Modules
Images
c:\program files\nettime\nettime.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2952"C:\Windows\system32\cmd.exe" C:\Windows\System32\cmd.exeexplorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
3 565
Read events
3 274
Write events
291
Delete events
0

Modification events

(PID) Process:(2908) NetTime.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2908) NetTime.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2908) NetTime.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2908) NetTime.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(900) NetTime.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run
Operation:writeName:NetTime
Value:
C:\Program Files\NetTime\NetTime.exe
(PID) Process:(900) NetTime.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Subjective Software\NetTime
Operation:writeName:Hostname
Value:
0.nettime.pool.ntp.org
(PID) Process:(900) NetTime.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Subjective Software\NetTime
Operation:writeName:Protocol
Value:
0
(PID) Process:(900) NetTime.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Subjective Software\NetTime
Operation:writeName:Port
Value:
123
(PID) Process:(900) NetTime.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Subjective Software\NetTime
Operation:writeName:Hostname1
Value:
1.nettime.pool.ntp.org
(PID) Process:(900) NetTime.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Subjective Software\NetTime
Operation:writeName:Protocol1
Value:
0
Executable files
10
Suspicious files
2
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
1880NetTimeSetup-314.tmpC:\Users\admin\AppData\Local\Temp\is-P2P93.tmp\_isetup\_RegDLL.tmpexecutable
MD5:0EE914C6F0BB93996C75941E1AD629C6
SHA256:4DC09BAC0613590F1FAC8771D18AF5BE25A1E1CB8FDBF4031AA364F3057E74A2
1880NetTimeSetup-314.tmpC:\Users\admin\AppData\Local\Temp\is-P2P93.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
1388NetTimeSetup-314.exeC:\Users\admin\AppData\Local\Temp\is-QQH9H.tmp\NetTimeSetup-314.tmpexecutable
MD5:C080F73B1BDDE0853CB0258D9A02B0EC
SHA256:A0CFBC8DA39AD4A4D21C61D73873D225FFA5D7650FAE5938AB643F719D5F7363
3456NetTimeSetup-314.exeC:\Users\admin\AppData\Local\Temp\is-FN4MM.tmp\NetTimeSetup-314.tmpexecutable
MD5:C080F73B1BDDE0853CB0258D9A02B0EC
SHA256:A0CFBC8DA39AD4A4D21C61D73873D225FFA5D7650FAE5938AB643F719D5F7363
1880NetTimeSetup-314.tmpC:\ProgramData\Microsoft\Windows\Start Menu\Programs\NetTime\NetTime.lnkbinary
MD5:F3350E22338800F3E0C2B23FE137F695
SHA256:307252EA6A158EF38A85F05ED6F8F38CCE48411494C1E2669F1745ED6984838D
1880NetTimeSetup-314.tmpC:\Program Files\NetTime\NetTime.exeexecutable
MD5:60B65F97C12BA30CD36450D376227C02
SHA256:D06598F2F203CEC7A7A3857F727BC2BA457C1C0CEF2787B90CE553407FBF8536
1880NetTimeSetup-314.tmpC:\Program Files\NetTime\is-OR1GF.tmpexecutable
MD5:94C08DF0F07C509D99FEA7CFC486C335
SHA256:0AAE40D7B5D57AED2A897161601A08123E64088033B03527DC1BA2B55E7A4E9A
1880NetTimeSetup-314.tmpC:\Program Files\NetTime\is-EFPEA.tmpexecutable
MD5:60B65F97C12BA30CD36450D376227C02
SHA256:D06598F2F203CEC7A7A3857F727BC2BA457C1C0CEF2787B90CE553407FBF8536
1880NetTimeSetup-314.tmpC:\Program Files\NetTime\unins000.datbinary
MD5:D61E9C8DA6921E36F0AF164969E28B1A
SHA256:9A44D2E81E84CCD703373CF42F754A090A2EF0A8DC6737DB5103DEB5D111063B
2452NetTimeService.exeC:\Program Files\NetTime\NetTimeLog.txttext
MD5:8B638291E2BF34F6C6BF58292C8D9B47
SHA256:997192CD6B76DDCD0F44F638D97B0087DFB420953EA28930F136B876F32D4F22
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
2
TCP/UDP connections
9
DNS requests
3
Threats
2

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2908
NetTime.exe
GET
200
103.230.156.198:80
http://www.timesynctool.com/updatecheck?3.1.4.220
unknown
text
11 b
unknown
900
NetTime.exe
GET
103.230.156.198:80
http://www.timesynctool.com/updatecheck?3.1.4.220
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2452
NetTimeService.exe
162.159.200.123:123
0.nettime.pool.ntp.org
unknown
2908
NetTime.exe
103.230.156.198:80
www.timesynctool.com
Mammoth Media Pty Ltd
AU
unknown
900
NetTime.exe
103.230.156.198:80
www.timesynctool.com
Mammoth Media Pty Ltd
AU
unknown
2452
NetTimeService.exe
162.159.200.1:123
0.nettime.pool.ntp.org
unknown

DNS requests

Domain
IP
Reputation
0.nettime.pool.ntp.org
  • 162.159.200.123
  • 144.76.66.156
  • 162.159.200.1
  • 164.68.124.74
  • 136.243.177.133
  • 217.91.44.17
  • 116.202.8.50
unknown
www.timesynctool.com
  • 103.230.156.198
unknown

Threats

PID
Process
Class
Message
2908
NetTime.exe
A Network Trojan was detected
ET USER_AGENTS Suspicious User-Agent (Mozilla/3.0 (compatible))
900
NetTime.exe
A Network Trojan was detected
ET USER_AGENTS Suspicious User-Agent (Mozilla/3.0 (compatible))
No debug info