File name:

Crypmod' in file 'eTimeTrackLite Error Solver.exe'

Full analysis: https://app.any.run/tasks/c0e1ef26-d214-4912-a0fa-999192ae2696
Verdict: Malicious activity
Analysis date: November 22, 2023, 14:02:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

1E3C0A215AEF721CFD6C78923323DB3B

SHA1:

AF30C85D88D4219D3895DBD40DAC22B9242F7641

SHA256:

810A6BDAAEF5CD8D68932F933F9ED4A3B4648195293384880B162DEC4E7396A3

SSDEEP:

24576:Dk+h9ahIg5zmlJ344Iz6Kx1/gBITm+zqp41AA5qxmZ+Uog+xSGeYbjAOg34zSFeI:Dk+hsGgBmlJ344Iz6Kx1/gBITm+zqp45

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe (PID: 2904)
      • cmd.exe (PID: 3564)
    • Creates a writable file in the system directory

      • cmd.exe (PID: 3564)
    • Registers / Runs the DLL via REGSVR32.EXE

      • cmd.exe (PID: 3564)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • ErrorSolver.exe (PID: 3504)
    • Executing commands from a ".bat" file

      • ErrorSolver.exe (PID: 3504)
    • Reads the Internet Settings

      • Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe (PID: 2904)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 3564)
    • Uses ICACLS.EXE to modify access control lists

      • cmd.exe (PID: 3564)
  • INFO

    • Reads the computer name

      • Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe (PID: 2904)
    • Create files in a temporary directory

      • Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe (PID: 2904)
      • ErrorSolver.exe (PID: 3504)
    • Checks supported languages

      • Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe (PID: 2904)
      • ErrorSolver.exe (PID: 3504)
    • Creates files in the program directory

      • Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe (PID: 2904)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (49.2)
.exe | Win32 Executable Delphi generic (16.2)
.scr | Windows screen saver (14.9)
.dll | Win32 Dynamic Link Library (generic) (7.5)
.exe | Win32 Executable (generic) (5.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:20 00:22:17+02:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 148992
InitializedDataSize: 31744
UninitializedDataSize: -
EntryPoint: 0x25468
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: -
CompanyName: Viral InfoTech
FileDescription: ErrorSolver 1.00 Installation
FileVersion: 1.00
LegalCopyright: Viral InfoTech
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start crypmod' in file 'etimetracklite error solver.exe'.exe errorsolver.exe no specs cmd.exe no specs taskkill.exe no specs icacls.exe no specs icacls.exe no specs regsvr32.exe no specs crypmod' in file 'etimetracklite error solver.exe'.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2904"C:\Users\admin\AppData\Local\Temp\Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe" C:\Users\admin\AppData\Local\Temp\Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe
explorer.exe
User:
admin
Company:
Viral InfoTech
Integrity Level:
HIGH
Description:
ErrorSolver 1.00 Installation
Exit code:
0
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\crypmod' in file 'etimetracklite error solver.exe'.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3376"C:\Users\admin\AppData\Local\Temp\Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe" C:\Users\admin\AppData\Local\Temp\Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeexplorer.exe
User:
admin
Company:
Viral InfoTech
Integrity Level:
MEDIUM
Description:
ErrorSolver 1.00 Installation
Exit code:
3221226540
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\crypmod' in file 'etimetracklite error solver.exe'.exe
c:\windows\system32\ntdll.dll
3444icacls "C:\Program Files (x86)\eSSL" /grant Everyone:(OI)(CI)FC:\Windows\System32\icacls.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
3
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3504"C:\Program Files\Viral InfoTech\ErrorSolver\ErrorSolver.exe" C:\Program Files\Viral InfoTech\ErrorSolver\ErrorSolver.exeCrypmod' in file 'eTimeTrackLite Error Solver.exe'.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\viral infotech\errorsolver\errorsolver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
3564"C:\Windows\system32\cmd" /c "C:\Users\admin\AppData\Local\Temp\715C.tmp\715D.tmp\716E.bat "C:\Program Files\Viral InfoTech\ErrorSolver\ErrorSolver.exe""C:\Windows\System32\cmd.exeErrorSolver.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3572taskkill /im etimetracklite.exe /tC:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
3604icacls "C:\Program Files\eSSL" /grant Everyone:(OI)(CI)FC:\Windows\System32\icacls.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
2
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3664regsvr32 C:\Windows\system32\zkemkeeper.dllC:\Windows\System32\regsvr32.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
222
Read events
213
Write events
9
Delete events
0

Modification events

(PID) Process:(2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
115
Executable files
29
Suspicious files
2
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\comms.dllexecutable
MD5:538BE1536FCF87B1610086B3AA53B0DD
SHA256:1FA00CC8AB4786AACBF315DD73C222C296DA2F5F85ADBA0A6B74090152A673C1
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\plcommpro.dllexecutable
MD5:5282D50FA899E26513D23F1ABC7C933B
SHA256:E58ED1ED55927624DAA7B28EF9C0DAEB29960199B067F047F034C57838BAEDC8
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Users\admin\AppData\Local\Temp\$inst\2.tmpcompressed
MD5:8708699D2C73BED30A0A08D80F96D6D7
SHA256:A32E0A83001D2C5D41649063217923DAC167809CAB50EC5784078E41C9EC0F0F
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\plrscagent.dllexecutable
MD5:C90F50041171653C0FD94C85BA15903D
SHA256:9987DDF22A42A87A8A232790BA00AAAA120B9741060E68406B7FE0BFFA9C0273
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\ErrorSolver.exeexecutable
MD5:BB04CA1ADAA6FF15B826CE721C7DC308
SHA256:2AF5CACA0C305855B879DC7F5F673D2DABDFA00857B654D8676B39967403627D
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Users\admin\AppData\Local\Temp\$inst\temp_0.tmpcompressed
MD5:6BAB8C5443FB66E58FAAD497B22B131E
SHA256:095DADAB55FDD57173F4B167371B15A430E3FBDBB188C63D0ACBF99BE8EE513D
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\zkemkeeper.dllexecutable
MD5:ECE16BE91BCBE8D7A351874497407B18
SHA256:3D0DD4943DBD547784CA88B29579581764B2173D8EA3979DA470B6B902653DEA
3564cmd.exeC:\Windows\system32\commpro.dllexecutable
MD5:AB822F58456CAB40E7CACC06C63C15AE
SHA256:A3F0879AD9AC4B230EA2EBFB5597E387F45F24F09E02F48DEAB50354B5970E01
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\zkemsdk.dllexecutable
MD5:5B429C1F3277CFE32C66F2FAAB08A73C
SHA256:B6934E85F7271B5478907ECF14E7B041613A1226981B932CBA49868D101F1BBF
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\Uninstall.exeexecutable
MD5:499CCC8D6D7C08E135A91928CCC2FD7A
SHA256:1FA5D83A5766556CF2FF16AD279E73CB40584746BD388E0A4E818A2CC06613D3
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info