| File name: | Crypmod' in file 'eTimeTrackLite Error Solver.exe' |
| Full analysis: | https://app.any.run/tasks/c0e1ef26-d214-4912-a0fa-999192ae2696 |
| Verdict: | Malicious activity |
| Analysis date: | November 22, 2023, 14:02:40 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 1E3C0A215AEF721CFD6C78923323DB3B |
| SHA1: | AF30C85D88D4219D3895DBD40DAC22B9242F7641 |
| SHA256: | 810A6BDAAEF5CD8D68932F933F9ED4A3B4648195293384880B162DEC4E7396A3 |
| SSDEEP: | 24576:Dk+h9ahIg5zmlJ344Iz6Kx1/gBITm+zqp41AA5qxmZ+Uog+xSGeYbjAOg34zSFeI:Dk+hsGgBmlJ344Iz6Kx1/gBITm+zqp45 |
| .exe | | | InstallShield setup (49.2) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (16.2) |
| .scr | | | Windows screen saver (14.9) |
| .dll | | | Win32 Dynamic Link Library (generic) (7.5) |
| .exe | | | Win32 Executable (generic) (5.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:20 00:22:17+02:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 148992 |
| InitializedDataSize: | 31744 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x25468 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| Comments: | - |
| CompanyName: | Viral InfoTech |
| FileDescription: | ErrorSolver 1.00 Installation |
| FileVersion: | 1.00 |
| LegalCopyright: | Viral InfoTech |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2904 | "C:\Users\admin\AppData\Local\Temp\Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe" | C:\Users\admin\AppData\Local\Temp\Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | explorer.exe | ||||||||||||
User: admin Company: Viral InfoTech Integrity Level: HIGH Description: ErrorSolver 1.00 Installation Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 3376 | "C:\Users\admin\AppData\Local\Temp\Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe" | C:\Users\admin\AppData\Local\Temp\Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | — | explorer.exe | |||||||||||
User: admin Company: Viral InfoTech Integrity Level: MEDIUM Description: ErrorSolver 1.00 Installation Exit code: 3221226540 Version: 1.00 Modules
| |||||||||||||||
| 3444 | icacls "C:\Program Files (x86)\eSSL" /grant Everyone:(OI)(CI)F | C:\Windows\System32\icacls.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Exit code: 3 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3504 | "C:\Program Files\Viral InfoTech\ErrorSolver\ErrorSolver.exe" | C:\Program Files\Viral InfoTech\ErrorSolver\ErrorSolver.exe | — | Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3564 | "C:\Windows\system32\cmd" /c "C:\Users\admin\AppData\Local\Temp\715C.tmp\715D.tmp\716E.bat "C:\Program Files\Viral InfoTech\ErrorSolver\ErrorSolver.exe"" | C:\Windows\System32\cmd.exe | — | ErrorSolver.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3572 | taskkill /im etimetracklite.exe /t | C:\Windows\System32\taskkill.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3604 | icacls "C:\Program Files\eSSL" /grant Everyone:(OI)(CI)F | C:\Windows\System32\icacls.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3664 | regsvr32 C:\Windows\system32\zkemkeeper.dll | C:\Windows\System32\regsvr32.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | GlobalAssocChangedCounter |
Value: 115 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2904 | Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | C:\Program Files\Viral InfoTech\ErrorSolver\comms.dll | executable | |
MD5:538BE1536FCF87B1610086B3AA53B0DD | SHA256:1FA00CC8AB4786AACBF315DD73C222C296DA2F5F85ADBA0A6B74090152A673C1 | |||
| 2904 | Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | C:\Program Files\Viral InfoTech\ErrorSolver\plcommpro.dll | executable | |
MD5:5282D50FA899E26513D23F1ABC7C933B | SHA256:E58ED1ED55927624DAA7B28EF9C0DAEB29960199B067F047F034C57838BAEDC8 | |||
| 2904 | Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | C:\Users\admin\AppData\Local\Temp\$inst\2.tmp | compressed | |
MD5:8708699D2C73BED30A0A08D80F96D6D7 | SHA256:A32E0A83001D2C5D41649063217923DAC167809CAB50EC5784078E41C9EC0F0F | |||
| 2904 | Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | C:\Program Files\Viral InfoTech\ErrorSolver\plrscagent.dll | executable | |
MD5:C90F50041171653C0FD94C85BA15903D | SHA256:9987DDF22A42A87A8A232790BA00AAAA120B9741060E68406B7FE0BFFA9C0273 | |||
| 2904 | Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | C:\Program Files\Viral InfoTech\ErrorSolver\ErrorSolver.exe | executable | |
MD5:BB04CA1ADAA6FF15B826CE721C7DC308 | SHA256:2AF5CACA0C305855B879DC7F5F673D2DABDFA00857B654D8676B39967403627D | |||
| 2904 | Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | C:\Users\admin\AppData\Local\Temp\$inst\temp_0.tmp | compressed | |
MD5:6BAB8C5443FB66E58FAAD497B22B131E | SHA256:095DADAB55FDD57173F4B167371B15A430E3FBDBB188C63D0ACBF99BE8EE513D | |||
| 2904 | Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | C:\Program Files\Viral InfoTech\ErrorSolver\zkemkeeper.dll | executable | |
MD5:ECE16BE91BCBE8D7A351874497407B18 | SHA256:3D0DD4943DBD547784CA88B29579581764B2173D8EA3979DA470B6B902653DEA | |||
| 3564 | cmd.exe | C:\Windows\system32\commpro.dll | executable | |
MD5:AB822F58456CAB40E7CACC06C63C15AE | SHA256:A3F0879AD9AC4B230EA2EBFB5597E387F45F24F09E02F48DEAB50354B5970E01 | |||
| 2904 | Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | C:\Program Files\Viral InfoTech\ErrorSolver\zkemsdk.dll | executable | |
MD5:5B429C1F3277CFE32C66F2FAAB08A73C | SHA256:B6934E85F7271B5478907ECF14E7B041613A1226981B932CBA49868D101F1BBF | |||
| 2904 | Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | C:\Program Files\Viral InfoTech\ErrorSolver\Uninstall.exe | executable | |
MD5:499CCC8D6D7C08E135A91928CCC2FD7A | SHA256:1FA5D83A5766556CF2FF16AD279E73CB40584746BD388E0A4E818A2CC06613D3 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |