File name:

Crypmod' in file 'eTimeTrackLite Error Solver.exe'

Full analysis: https://app.any.run/tasks/c0e1ef26-d214-4912-a0fa-999192ae2696
Verdict: Malicious activity
Analysis date: November 22, 2023, 14:02:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

1E3C0A215AEF721CFD6C78923323DB3B

SHA1:

AF30C85D88D4219D3895DBD40DAC22B9242F7641

SHA256:

810A6BDAAEF5CD8D68932F933F9ED4A3B4648195293384880B162DEC4E7396A3

SSDEEP:

24576:Dk+h9ahIg5zmlJ344Iz6Kx1/gBITm+zqp41AA5qxmZ+Uog+xSGeYbjAOg34zSFeI:Dk+hsGgBmlJ344Iz6Kx1/gBITm+zqp45

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe (PID: 2904)
      • cmd.exe (PID: 3564)
    • Creates a writable file in the system directory

      • cmd.exe (PID: 3564)
    • Registers / Runs the DLL via REGSVR32.EXE

      • cmd.exe (PID: 3564)
  • SUSPICIOUS

    • Starts CMD.EXE for commands execution

      • ErrorSolver.exe (PID: 3504)
    • Reads the Internet Settings

      • Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe (PID: 2904)
    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 3564)
    • Executing commands from a ".bat" file

      • ErrorSolver.exe (PID: 3504)
    • Uses ICACLS.EXE to modify access control lists

      • cmd.exe (PID: 3564)
  • INFO

    • Create files in a temporary directory

      • Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe (PID: 2904)
      • ErrorSolver.exe (PID: 3504)
    • Checks supported languages

      • Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe (PID: 2904)
      • ErrorSolver.exe (PID: 3504)
    • Reads the computer name

      • Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe (PID: 2904)
    • Creates files in the program directory

      • Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe (PID: 2904)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (49.2)
.exe | Win32 Executable Delphi generic (16.2)
.scr | Windows screen saver (14.9)
.dll | Win32 Dynamic Link Library (generic) (7.5)
.exe | Win32 Executable (generic) (5.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:20 00:22:17+02:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 148992
InitializedDataSize: 31744
UninitializedDataSize: -
EntryPoint: 0x25468
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: -
CompanyName: Viral InfoTech
FileDescription: ErrorSolver 1.00 Installation
FileVersion: 1.00
LegalCopyright: Viral InfoTech
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start crypmod' in file 'etimetracklite error solver.exe'.exe errorsolver.exe no specs cmd.exe no specs taskkill.exe no specs icacls.exe no specs icacls.exe no specs regsvr32.exe no specs crypmod' in file 'etimetracklite error solver.exe'.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2904"C:\Users\admin\AppData\Local\Temp\Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe" C:\Users\admin\AppData\Local\Temp\Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe
explorer.exe
User:
admin
Company:
Viral InfoTech
Integrity Level:
HIGH
Description:
ErrorSolver 1.00 Installation
Exit code:
0
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\crypmod' in file 'etimetracklite error solver.exe'.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3376"C:\Users\admin\AppData\Local\Temp\Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe" C:\Users\admin\AppData\Local\Temp\Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeexplorer.exe
User:
admin
Company:
Viral InfoTech
Integrity Level:
MEDIUM
Description:
ErrorSolver 1.00 Installation
Exit code:
3221226540
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\crypmod' in file 'etimetracklite error solver.exe'.exe
c:\windows\system32\ntdll.dll
3444icacls "C:\Program Files (x86)\eSSL" /grant Everyone:(OI)(CI)FC:\Windows\System32\icacls.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
3
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3504"C:\Program Files\Viral InfoTech\ErrorSolver\ErrorSolver.exe" C:\Program Files\Viral InfoTech\ErrorSolver\ErrorSolver.exeCrypmod' in file 'eTimeTrackLite Error Solver.exe'.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\viral infotech\errorsolver\errorsolver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
3564"C:\Windows\system32\cmd" /c "C:\Users\admin\AppData\Local\Temp\715C.tmp\715D.tmp\716E.bat "C:\Program Files\Viral InfoTech\ErrorSolver\ErrorSolver.exe""C:\Windows\System32\cmd.exeErrorSolver.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3572taskkill /im etimetracklite.exe /tC:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
3604icacls "C:\Program Files\eSSL" /grant Everyone:(OI)(CI)FC:\Windows\System32\icacls.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
2
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3664regsvr32 C:\Windows\system32\zkemkeeper.dllC:\Windows\System32\regsvr32.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
222
Read events
213
Write events
9
Delete events
0

Modification events

(PID) Process:(2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
115
Executable files
29
Suspicious files
2
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\plrscagent.dllexecutable
MD5:C90F50041171653C0FD94C85BA15903D
SHA256:9987DDF22A42A87A8A232790BA00AAAA120B9741060E68406B7FE0BFFA9C0273
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Users\admin\AppData\Local\Temp\$inst\temp_0.tmpcompressed
MD5:6BAB8C5443FB66E58FAAD497B22B131E
SHA256:095DADAB55FDD57173F4B167371B15A430E3FBDBB188C63D0ACBF99BE8EE513D
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\rscagent.dllexecutable
MD5:85992B5C6FB3EE60D77E1BC54D9C3930
SHA256:4666DD1FCBD5FAF0D6ED96462965A9A5115CC922AE8D6D96EEF5898988F584EC
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\plrscomm.dllexecutable
MD5:1813E9D6FC17EAD842C0FEDF7E5F5131
SHA256:D2EF9D7EDC5E0B48C8EA3F78A568E80DAA15577B380C5324F0B5BC013647F205
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\usbcomm.dllexecutable
MD5:DA00BA053CB7798D5003D0F1AAAE9612
SHA256:CD8892497AD5E885986C768FEB897D41AA7EE75EDD93FFAF551AC31A7E41801A
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\Uninstall.exeexecutable
MD5:499CCC8D6D7C08E135A91928CCC2FD7A
SHA256:1FA5D83A5766556CF2FF16AD279E73CB40584746BD388E0A4E818A2CC06613D3
3504ErrorSolver.exeC:\Users\admin\AppData\Local\Temp\715C.tmp\715D.tmp\716E.battext
MD5:B73BCD54F93BB9B2357F686D262F3494
SHA256:C4A60C8424CDA03D0AE9AE637AF70C7AFE40D5869B5A4DF8F18BD6F05406B71C
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\Uninstall.initext
MD5:790CBE784BCF62845F4FF0DE29B9E188
SHA256:09C260F6B3507EB75B16AB84377E0E113B4C8BB4C063C6146D5E4B764D2B6D49
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Users\admin\AppData\Local\Temp\$inst\2.tmpcompressed
MD5:8708699D2C73BED30A0A08D80F96D6D7
SHA256:A32E0A83001D2C5D41649063217923DAC167809CAB50EC5784078E41C9EC0F0F
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\pltcpcomm.dllexecutable
MD5:594C3A44B547191E6C259C5677700FC2
SHA256:2F2E4E54D01E6E173894DEA14B97A1E30A2AE2B01B75715B76394EFE562A312D
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info