| File name: | Crypmod' in file 'eTimeTrackLite Error Solver.exe' |
| Full analysis: | https://app.any.run/tasks/c0e1ef26-d214-4912-a0fa-999192ae2696 |
| Verdict: | Malicious activity |
| Analysis date: | November 22, 2023, 14:02:40 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 1E3C0A215AEF721CFD6C78923323DB3B |
| SHA1: | AF30C85D88D4219D3895DBD40DAC22B9242F7641 |
| SHA256: | 810A6BDAAEF5CD8D68932F933F9ED4A3B4648195293384880B162DEC4E7396A3 |
| SSDEEP: | 24576:Dk+h9ahIg5zmlJ344Iz6Kx1/gBITm+zqp41AA5qxmZ+Uog+xSGeYbjAOg34zSFeI:Dk+hsGgBmlJ344Iz6Kx1/gBITm+zqp45 |
| .exe | | | InstallShield setup (49.2) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (16.2) |
| .scr | | | Windows screen saver (14.9) |
| .dll | | | Win32 Dynamic Link Library (generic) (7.5) |
| .exe | | | Win32 Executable (generic) (5.1) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:20 00:22:17+02:00 |
| ImageFileCharacteristics: | Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 148992 |
| InitializedDataSize: | 31744 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x25468 |
| OSVersion: | 4 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| Comments: | - |
| CompanyName: | Viral InfoTech |
| FileDescription: | ErrorSolver 1.00 Installation |
| FileVersion: | 1.00 |
| LegalCopyright: | Viral InfoTech |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 2904 | "C:\Users\admin\AppData\Local\Temp\Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe" | C:\Users\admin\AppData\Local\Temp\Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | explorer.exe | ||||||||||||
User: admin Company: Viral InfoTech Integrity Level: HIGH Description: ErrorSolver 1.00 Installation Exit code: 0 Version: 1.00 Modules
| |||||||||||||||
| 3376 | "C:\Users\admin\AppData\Local\Temp\Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe" | C:\Users\admin\AppData\Local\Temp\Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | — | explorer.exe | |||||||||||
User: admin Company: Viral InfoTech Integrity Level: MEDIUM Description: ErrorSolver 1.00 Installation Exit code: 3221226540 Version: 1.00 Modules
| |||||||||||||||
| 3444 | icacls "C:\Program Files (x86)\eSSL" /grant Everyone:(OI)(CI)F | C:\Windows\System32\icacls.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Exit code: 3 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3504 | "C:\Program Files\Viral InfoTech\ErrorSolver\ErrorSolver.exe" | C:\Program Files\Viral InfoTech\ErrorSolver\ErrorSolver.exe | — | Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3564 | "C:\Windows\system32\cmd" /c "C:\Users\admin\AppData\Local\Temp\715C.tmp\715D.tmp\716E.bat "C:\Program Files\Viral InfoTech\ErrorSolver\ErrorSolver.exe"" | C:\Windows\System32\cmd.exe | — | ErrorSolver.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows Command Processor Exit code: 0 Version: 6.1.7601.17514 (win7sp1_rtm.101119-1850) Modules
| |||||||||||||||
| 3572 | taskkill /im etimetracklite.exe /t | C:\Windows\System32\taskkill.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Terminates Processes Exit code: 128 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3604 | icacls "C:\Program Files\eSSL" /grant Everyone:(OI)(CI)F | C:\Windows\System32\icacls.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3664 | regsvr32 C:\Windows\system32\zkemkeeper.dll | C:\Windows\System32\regsvr32.exe | — | cmd.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| (PID) Process: | (2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer |
| Operation: | write | Name: | GlobalAssocChangedCounter |
Value: 115 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2904 | Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | C:\Users\admin\AppData\Local\Temp\$inst\temp_0.tmp | compressed | |
MD5:6BAB8C5443FB66E58FAAD497B22B131E | SHA256:095DADAB55FDD57173F4B167371B15A430E3FBDBB188C63D0ACBF99BE8EE513D | |||
| 2904 | Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | C:\Program Files\Viral InfoTech\ErrorSolver\ErrorSolver.exe | executable | |
MD5:BB04CA1ADAA6FF15B826CE721C7DC308 | SHA256:2AF5CACA0C305855B879DC7F5F673D2DABDFA00857B654D8676B39967403627D | |||
| 2904 | Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | C:\Program Files\Viral InfoTech\ErrorSolver\plcomms.dll | executable | |
MD5:310C6228147458725B1BF6B2C93E4E43 | SHA256:5F1AE0F41999F096DFC8728C53F56D0F2322521CBD69EA20015ADDCD8F0AFC38 | |||
| 2904 | Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | C:\Program Files\Viral InfoTech\ErrorSolver\commpro.dll | executable | |
MD5:AB822F58456CAB40E7CACC06C63C15AE | SHA256:A3F0879AD9AC4B230EA2EBFB5597E387F45F24F09E02F48DEAB50354B5970E01 | |||
| 2904 | Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | C:\Program Files\Viral InfoTech\ErrorSolver\rscomm.dll | executable | |
MD5:DCA6CB95F28715404E67F89F86787F15 | SHA256:D717ED31950AF23BC21DAE6CB19BCC748F85FF5BD4F2A93A2737C97BA40FB17A | |||
| 2904 | Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | C:\Program Files\Viral InfoTech\ErrorSolver\plcommpro.dll | executable | |
MD5:5282D50FA899E26513D23F1ABC7C933B | SHA256:E58ED1ED55927624DAA7B28EF9C0DAEB29960199B067F047F034C57838BAEDC8 | |||
| 2904 | Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | C:\Program Files\Viral InfoTech\ErrorSolver\plrscagent.dll | executable | |
MD5:C90F50041171653C0FD94C85BA15903D | SHA256:9987DDF22A42A87A8A232790BA00AAAA120B9741060E68406B7FE0BFFA9C0273 | |||
| 2904 | Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | C:\Program Files\Viral InfoTech\ErrorSolver\pltcpcomm.dll | executable | |
MD5:594C3A44B547191E6C259C5677700FC2 | SHA256:2F2E4E54D01E6E173894DEA14B97A1E30A2AE2B01B75715B76394EFE562A312D | |||
| 2904 | Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | C:\Program Files\Viral InfoTech\ErrorSolver\rscagent.dll | executable | |
MD5:85992B5C6FB3EE60D77E1BC54D9C3930 | SHA256:4666DD1FCBD5FAF0D6ED96462965A9A5115CC922AE8D6D96EEF5898988F584EC | |||
| 2904 | Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe | C:\Program Files\Viral InfoTech\ErrorSolver\tcpcomm.dll | executable | |
MD5:ABCAC16DB838829D89FA36372C821741 | SHA256:9D1F7B8D2C3E5A4B7248F03BABDBE403D1043138DE01198DED4664A73CB95C38 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |