File name:

NetTimeSetup-314.exe

Full analysis: https://app.any.run/tasks/f97b70b1-7695-4cc4-b325-cb00bb2eb20b
Verdict: Malicious activity
Analysis date: February 10, 2024, 14:41:46
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

107C0E40D46936B166F362090D34AA4C

SHA1:

FCD9C88AA5F6E85E997BDA6F7DF02595F45329A4

SHA256:

7B489CBBC654FE26F39300387AE28A2A538CF76E68335F573A762EC18222A808

SSDEEP:

24576:CSdEn9rb+dgIc6FueA0illGacLmnPw5xUNEqCaiBoioIPvrJiS2dBVBXuKuC7Tu+:CSk9rb+dgIc6FueA0illGacLmnPyxWEI

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • NetTimeSetup-314.exe (PID: 3656)
      • NetTimeSetup-314.exe (PID: 3944)
      • NetTimeSetup-314.tmp (PID: 3228)
    • Changes the autorun value in the registry

      • NetTime.exe (PID: 1696)
      • NetTime.exe (PID: 2440)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • NetTimeSetup-314.exe (PID: 3656)
      • NetTimeSetup-314.exe (PID: 3944)
      • NetTimeSetup-314.tmp (PID: 3228)
    • Reads the Windows owner or organization settings

      • NetTimeSetup-314.tmp (PID: 3228)
    • Process drops legitimate windows executable

      • NetTimeSetup-314.tmp (PID: 3228)
    • Reads the Internet Settings

      • NetTime.exe (PID: 2860)
    • Executes as Windows Service

      • NetTimeService.exe (PID: 3428)
    • Application launched itself

      • NetTime.exe (PID: 2860)
    • Reads security settings of Internet Explorer

      • NetTime.exe (PID: 2860)
  • INFO

    • Checks supported languages

      • NetTimeSetup-314.tmp (PID: 1432)
      • NetTimeSetup-314.exe (PID: 3944)
      • NetTimeSetup-314.exe (PID: 3656)
      • NetTimeSetup-314.tmp (PID: 3228)
      • NetTime.exe (PID: 1040)
      • NetTimeService.exe (PID: 2624)
      • NetTimeService.exe (PID: 3428)
      • NetTime.exe (PID: 1696)
      • NetTime.exe (PID: 2860)
      • NetTime.exe (PID: 2440)
    • Reads the computer name

      • NetTimeSetup-314.tmp (PID: 1432)
      • NetTimeSetup-314.tmp (PID: 3228)
      • NetTimeService.exe (PID: 2624)
      • NetTimeService.exe (PID: 3428)
      • NetTime.exe (PID: 1696)
      • NetTime.exe (PID: 2860)
      • NetTime.exe (PID: 2440)
      • NetTime.exe (PID: 1040)
    • Create files in a temporary directory

      • NetTimeSetup-314.exe (PID: 3656)
      • NetTimeSetup-314.exe (PID: 3944)
      • NetTimeSetup-314.tmp (PID: 3228)
    • Creates files in the program directory

      • NetTimeSetup-314.tmp (PID: 3228)
      • NetTimeService.exe (PID: 3428)
    • Creates a software uninstall entry

      • NetTimeSetup-314.tmp (PID: 3228)
    • Process checks whether UAC notifications are on

      • NetTime.exe (PID: 2860)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Inno Setup installer (77.7)
.exe | Win32 Executable Delphi generic (10)
.dll | Win32 Dynamic Link Library (generic) (4.6)
.exe | Win32 Executable (generic) (3.1)
.exe | Win16/32 Executable Delphi generic (1.4)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:19 22:22:17+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 37888
InitializedDataSize: 17920
UninitializedDataSize: -
EntryPoint: 0x9c40
OSVersion: 1
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 0.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Neutral
CharacterSet: Unicode
Comments: This installation was built with Inno Setup.
CompanyName: Mark Griffiths
FileDescription: NetTime Setup
FileVersion:
LegalCopyright: Copyright © 1997, 2000 by Graham Mainwaring, Copyright © 2011, 2012 Mark Griffiths
ProductName: NetTime
ProductVersion:
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
50
Monitored processes
10
Malicious processes
4
Suspicious processes
3

Behavior graph

Click at the process to see the details
start nettimesetup-314.exe nettimesetup-314.tmp no specs nettimesetup-314.exe nettimesetup-314.tmp nettime.exe no specs nettimeservice.exe no specs nettimeservice.exe nettime.exe nettime.exe nettime.exe

Process information

PID
CMD
Path
Indicators
Parent process
1040"C:\Program Files\NetTime\NetTime.exe" /installserviceC:\Program Files\NetTime\NetTime.exeNetTimeSetup-314.tmp
User:
admin
Integrity Level:
HIGH
Description:
Network Time Synchronizer
Exit code:
0
Version:
3.1.4.220
Modules
Images
c:\program files\nettime\nettime.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1432"C:\Users\admin\AppData\Local\Temp\is-8AG60.tmp\NetTimeSetup-314.tmp" /SL5="$E0170,532342,54272,C:\Users\admin\AppData\Local\Temp\NetTimeSetup-314.exe" C:\Users\admin\AppData\Local\Temp\is-8AG60.tmp\NetTimeSetup-314.tmpNetTimeSetup-314.exe
User:
admin
Integrity Level:
MEDIUM
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-8ag60.tmp\nettimesetup-314.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
1696"C:\Program Files\NetTime\NetTime.exe" /enableautostartC:\Program Files\NetTime\NetTime.exe
NetTimeSetup-314.tmp
User:
admin
Integrity Level:
HIGH
Description:
Network Time Synchronizer
Exit code:
0
Version:
3.1.4.220
Modules
Images
c:\program files\nettime\nettime.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2440"C:\Program Files\NetTime\NetTime.exe" /showconfigC:\Program Files\NetTime\NetTime.exe
NetTime.exe
User:
admin
Integrity Level:
HIGH
Description:
Network Time Synchronizer
Exit code:
0
Version:
3.1.4.220
Modules
Images
c:\program files\nettime\nettime.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2624"C:\Program Files\NetTime\NetTimeService.exe" /install /silentC:\Program Files\NetTime\NetTimeService.exeNetTime.exe
User:
admin
Integrity Level:
HIGH
Description:
Network Time Synchronizer - NT Service
Exit code:
0
Version:
3.1.4.220
Modules
Images
c:\program files\nettime\nettimeservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2860"C:\Program Files\NetTime\NetTime.exe" /firstrunC:\Program Files\NetTime\NetTime.exe
NetTimeSetup-314.tmp
User:
admin
Integrity Level:
MEDIUM
Description:
Network Time Synchronizer
Exit code:
0
Version:
3.1.4.220
Modules
Images
c:\program files\nettime\nettime.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3228"C:\Users\admin\AppData\Local\Temp\is-DJ97D.tmp\NetTimeSetup-314.tmp" /SL5="$15019C,532342,54272,C:\Users\admin\AppData\Local\Temp\NetTimeSetup-314.exe" /SPAWNWND=$1A01BC /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\is-DJ97D.tmp\NetTimeSetup-314.tmp
NetTimeSetup-314.exe
User:
admin
Integrity Level:
HIGH
Description:
Setup/Uninstall
Exit code:
0
Version:
51.52.0.0
Modules
Images
c:\users\admin\appdata\local\temp\is-dj97d.tmp\nettimesetup-314.tmp
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3428"C:\Program Files\NetTime\NetTimeService.exe"C:\Program Files\NetTime\NetTimeService.exe
services.exe
User:
SYSTEM
Integrity Level:
SYSTEM
Description:
Network Time Synchronizer - NT Service
Exit code:
0
Version:
3.1.4.220
Modules
Images
c:\program files\nettime\nettimeservice.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3656"C:\Users\admin\AppData\Local\Temp\NetTimeSetup-314.exe" C:\Users\admin\AppData\Local\Temp\NetTimeSetup-314.exe
explorer.exe
User:
admin
Company:
Mark Griffiths
Integrity Level:
MEDIUM
Description:
NetTime Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\nettimesetup-314.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
3944"C:\Users\admin\AppData\Local\Temp\NetTimeSetup-314.exe" /SPAWNWND=$1A01BC /NOTIFYWND=$E0170 C:\Users\admin\AppData\Local\Temp\NetTimeSetup-314.exe
NetTimeSetup-314.tmp
User:
admin
Company:
Mark Griffiths
Integrity Level:
HIGH
Description:
NetTime Setup
Exit code:
0
Version:
Modules
Images
c:\users\admin\appdata\local\temp\nettimesetup-314.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\oleaut32.dll
Total events
5 060
Read events
5 000
Write events
57
Delete events
3

Modification events

(PID) Process:(3228) NetTimeSetup-314.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetTime_is1
Operation:writeName:Inno Setup: Setup Version
Value:
5.4.0 (a)
(PID) Process:(3228) NetTimeSetup-314.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetTime_is1
Operation:writeName:Inno Setup: App Path
Value:
C:\Program Files\NetTime
(PID) Process:(3228) NetTimeSetup-314.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetTime_is1
Operation:writeName:InstallLocation
Value:
C:\Program Files\NetTime\
(PID) Process:(3228) NetTimeSetup-314.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetTime_is1
Operation:writeName:Inno Setup: Icon Group
Value:
NetTime
(PID) Process:(3228) NetTimeSetup-314.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetTime_is1
Operation:writeName:Inno Setup: User
Value:
admin
(PID) Process:(3228) NetTimeSetup-314.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetTime_is1
Operation:writeName:Inno Setup: Selected Tasks
Value:
installservice
(PID) Process:(3228) NetTimeSetup-314.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetTime_is1
Operation:writeName:Inno Setup: Deselected Tasks
Value:
(PID) Process:(3228) NetTimeSetup-314.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetTime_is1
Operation:writeName:Inno Setup: Language
Value:
default
(PID) Process:(3228) NetTimeSetup-314.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetTime_is1
Operation:writeName:DisplayName
Value:
NetTime
(PID) Process:(3228) NetTimeSetup-314.tmpKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\NetTime_is1
Operation:writeName:UninstallString
Value:
"C:\Program Files\NetTime\unins000.exe"
Executable files
10
Suspicious files
2
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
3656NetTimeSetup-314.exeC:\Users\admin\AppData\Local\Temp\is-8AG60.tmp\NetTimeSetup-314.tmpexecutable
MD5:C080F73B1BDDE0853CB0258D9A02B0EC
SHA256:A0CFBC8DA39AD4A4D21C61D73873D225FFA5D7650FAE5938AB643F719D5F7363
3228NetTimeSetup-314.tmpC:\Program Files\NetTime\is-8MBM6.tmpexecutable
MD5:60B65F97C12BA30CD36450D376227C02
SHA256:D06598F2F203CEC7A7A3857F727BC2BA457C1C0CEF2787B90CE553407FBF8536
3944NetTimeSetup-314.exeC:\Users\admin\AppData\Local\Temp\is-DJ97D.tmp\NetTimeSetup-314.tmpexecutable
MD5:C080F73B1BDDE0853CB0258D9A02B0EC
SHA256:A0CFBC8DA39AD4A4D21C61D73873D225FFA5D7650FAE5938AB643F719D5F7363
3228NetTimeSetup-314.tmpC:\Program Files\NetTime\unins000.exeexecutable
MD5:212EE20B90FA4B06322CD488DFFA8259
SHA256:338D67A4C0B9E5262952E1FCDD943AF3804690040B8FA5BF00ED22E53AF28B5B
3228NetTimeSetup-314.tmpC:\Users\admin\AppData\Local\Temp\is-9C5ED.tmp\_isetup\_shfoldr.dllexecutable
MD5:92DC6EF532FBB4A5C3201469A5B5EB63
SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87
3228NetTimeSetup-314.tmpC:\Program Files\NetTime\NetTime.exeexecutable
MD5:60B65F97C12BA30CD36450D376227C02
SHA256:D06598F2F203CEC7A7A3857F727BC2BA457C1C0CEF2787B90CE553407FBF8536
3228NetTimeSetup-314.tmpC:\Users\admin\AppData\Local\Temp\is-9C5ED.tmp\_isetup\_RegDLL.tmpexecutable
MD5:0EE914C6F0BB93996C75941E1AD629C6
SHA256:4DC09BAC0613590F1FAC8771D18AF5BE25A1E1CB8FDBF4031AA364F3057E74A2
3228NetTimeSetup-314.tmpC:\Program Files\NetTime\is-N8M0M.tmpexecutable
MD5:94C08DF0F07C509D99FEA7CFC486C335
SHA256:0AAE40D7B5D57AED2A897161601A08123E64088033B03527DC1BA2B55E7A4E9A
3228NetTimeSetup-314.tmpC:\Program Files\NetTime\is-HODI5.tmpexecutable
MD5:212EE20B90FA4B06322CD488DFFA8259
SHA256:338D67A4C0B9E5262952E1FCDD943AF3804690040B8FA5BF00ED22E53AF28B5B
3228NetTimeSetup-314.tmpC:\Program Files\NetTime\NetTimeService.exeexecutable
MD5:94C08DF0F07C509D99FEA7CFC486C335
SHA256:0AAE40D7B5D57AED2A897161601A08123E64088033B03527DC1BA2B55E7A4E9A
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
1
TCP/UDP connections
9
DNS requests
3
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2860
NetTime.exe
GET
200
103.230.156.198:80
http://www.timesynctool.com/updatecheck?3.1.4.220
unknown
text
11 b
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
3428
NetTimeService.exe
144.76.0.164:123
0.nettime.pool.ntp.org
unknown
2860
NetTime.exe
103.230.156.198:80
www.timesynctool.com
Mammoth Media Pty Ltd
AU
unknown
2440
NetTime.exe
88.99.76.254:123
0.nettime.pool.ntp.org
unknown

DNS requests

Domain
IP
Reputation
0.nettime.pool.ntp.org
  • 144.76.0.164
  • 213.172.105.106
  • 162.159.200.123
  • 116.203.244.102
  • 88.99.76.254
  • 185.252.140.125
  • 129.70.132.35
  • 78.47.168.188
unknown
www.timesynctool.com
  • 103.230.156.198
unknown

Threats

PID
Process
Class
Message
2860
NetTime.exe
A Network Trojan was detected
ET USER_AGENTS Suspicious User-Agent (Mozilla/3.0 (compatible))
No debug info