File name:

Crypmod' in file 'eTimeTrackLite Error Solver.exe'

Full analysis: https://app.any.run/tasks/c0e1ef26-d214-4912-a0fa-999192ae2696
Verdict: Malicious activity
Analysis date: November 22, 2023, 14:02:40
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows
MD5:

1E3C0A215AEF721CFD6C78923323DB3B

SHA1:

AF30C85D88D4219D3895DBD40DAC22B9242F7641

SHA256:

810A6BDAAEF5CD8D68932F933F9ED4A3B4648195293384880B162DEC4E7396A3

SSDEEP:

24576:Dk+h9ahIg5zmlJ344Iz6Kx1/gBITm+zqp41AA5qxmZ+Uog+xSGeYbjAOg34zSFeI:Dk+hsGgBmlJ344Iz6Kx1/gBITm+zqp45

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Registers / Runs the DLL via REGSVR32.EXE

      • cmd.exe (PID: 3564)
    • Creates a writable file in the system directory

      • cmd.exe (PID: 3564)
    • Drops the executable file immediately after the start

      • Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe (PID: 2904)
      • cmd.exe (PID: 3564)
  • SUSPICIOUS

    • Uses TASKKILL.EXE to kill process

      • cmd.exe (PID: 3564)
    • Starts CMD.EXE for commands execution

      • ErrorSolver.exe (PID: 3504)
    • Executing commands from a ".bat" file

      • ErrorSolver.exe (PID: 3504)
    • Uses ICACLS.EXE to modify access control lists

      • cmd.exe (PID: 3564)
    • Reads the Internet Settings

      • Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe (PID: 2904)
  • INFO

    • Creates files in the program directory

      • Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe (PID: 2904)
    • Checks supported languages

      • Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe (PID: 2904)
      • ErrorSolver.exe (PID: 3504)
    • Reads the computer name

      • Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe (PID: 2904)
    • Create files in a temporary directory

      • Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe (PID: 2904)
      • ErrorSolver.exe (PID: 3504)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | InstallShield setup (49.2)
.exe | Win32 Executable Delphi generic (16.2)
.scr | Windows screen saver (14.9)
.dll | Win32 Dynamic Link Library (generic) (7.5)
.exe | Win32 Executable (generic) (5.1)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 1992:06:20 00:22:17+02:00
ImageFileCharacteristics: Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi
PEType: PE32
LinkerVersion: 2.25
CodeSize: 148992
InitializedDataSize: 31744
UninitializedDataSize: -
EntryPoint: 0x25468
OSVersion: 4
ImageVersion: -
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 1.0.0.0
ProductVersionNumber: 0.0.0.0
FileFlagsMask: 0x003f
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: English (U.S.)
CharacterSet: Windows, Latin1
Comments: -
CompanyName: Viral InfoTech
FileDescription: ErrorSolver 1.00 Installation
FileVersion: 1.00
LegalCopyright: Viral InfoTech
No data.
screenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
47
Monitored processes
8
Malicious processes
3
Suspicious processes
0

Behavior graph

Click at the process to see the details
start crypmod' in file 'etimetracklite error solver.exe'.exe errorsolver.exe no specs cmd.exe no specs taskkill.exe no specs icacls.exe no specs icacls.exe no specs regsvr32.exe no specs crypmod' in file 'etimetracklite error solver.exe'.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
2904"C:\Users\admin\AppData\Local\Temp\Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe" C:\Users\admin\AppData\Local\Temp\Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe
explorer.exe
User:
admin
Company:
Viral InfoTech
Integrity Level:
HIGH
Description:
ErrorSolver 1.00 Installation
Exit code:
0
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\crypmod' in file 'etimetracklite error solver.exe'.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
3376"C:\Users\admin\AppData\Local\Temp\Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exe" C:\Users\admin\AppData\Local\Temp\Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeexplorer.exe
User:
admin
Company:
Viral InfoTech
Integrity Level:
MEDIUM
Description:
ErrorSolver 1.00 Installation
Exit code:
3221226540
Version:
1.00
Modules
Images
c:\users\admin\appdata\local\temp\crypmod' in file 'etimetracklite error solver.exe'.exe
c:\windows\system32\ntdll.dll
3444icacls "C:\Program Files (x86)\eSSL" /grant Everyone:(OI)(CI)FC:\Windows\System32\icacls.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
3
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3504"C:\Program Files\Viral InfoTech\ErrorSolver\ErrorSolver.exe" C:\Program Files\Viral InfoTech\ErrorSolver\ErrorSolver.exeCrypmod' in file 'eTimeTrackLite Error Solver.exe'.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\program files\viral infotech\errorsolver\errorsolver.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\winsxs\x86_microsoft.windows.common-controls_6595b64144ccf1df_6.0.7601.24483_none_2b200f664577e14b\comctl32.dll
3564"C:\Windows\system32\cmd" /c "C:\Users\admin\AppData\Local\Temp\715C.tmp\715D.tmp\716E.bat "C:\Program Files\Viral InfoTech\ErrorSolver\ErrorSolver.exe""C:\Windows\System32\cmd.exeErrorSolver.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Windows Command Processor
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\cmd.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\winbrand.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
3572taskkill /im etimetracklite.exe /tC:\Windows\System32\taskkill.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Terminates Processes
Exit code:
128
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\taskkill.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\version.dll
c:\windows\system32\user32.dll
3604icacls "C:\Program Files\eSSL" /grant Everyone:(OI)(CI)FC:\Windows\System32\icacls.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Exit code:
2
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\icacls.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
3664regsvr32 C:\Windows\system32\zkemkeeper.dllC:\Windows\System32\regsvr32.execmd.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
Total events
222
Read events
213
Write events
9
Delete events
0

Modification events

(PID) Process:(2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
(PID) Process:(2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
1
(PID) Process:(2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
0
(PID) Process:(2904) Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Explorer
Operation:writeName:GlobalAssocChangedCounter
Value:
115
Executable files
29
Suspicious files
2
Text files
1
Unknown types
0

Dropped files

PID
Process
Filename
Type
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Users\admin\AppData\Local\Temp\$inst\temp_0.tmpcompressed
MD5:6BAB8C5443FB66E58FAAD497B22B131E
SHA256:095DADAB55FDD57173F4B167371B15A430E3FBDBB188C63D0ACBF99BE8EE513D
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\ErrorSolver.exeexecutable
MD5:BB04CA1ADAA6FF15B826CE721C7DC308
SHA256:2AF5CACA0C305855B879DC7F5F673D2DABDFA00857B654D8676B39967403627D
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\plcomms.dllexecutable
MD5:310C6228147458725B1BF6B2C93E4E43
SHA256:5F1AE0F41999F096DFC8728C53F56D0F2322521CBD69EA20015ADDCD8F0AFC38
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\commpro.dllexecutable
MD5:AB822F58456CAB40E7CACC06C63C15AE
SHA256:A3F0879AD9AC4B230EA2EBFB5597E387F45F24F09E02F48DEAB50354B5970E01
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\rscomm.dllexecutable
MD5:DCA6CB95F28715404E67F89F86787F15
SHA256:D717ED31950AF23BC21DAE6CB19BCC748F85FF5BD4F2A93A2737C97BA40FB17A
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\plcommpro.dllexecutable
MD5:5282D50FA899E26513D23F1ABC7C933B
SHA256:E58ED1ED55927624DAA7B28EF9C0DAEB29960199B067F047F034C57838BAEDC8
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\plrscagent.dllexecutable
MD5:C90F50041171653C0FD94C85BA15903D
SHA256:9987DDF22A42A87A8A232790BA00AAAA120B9741060E68406B7FE0BFFA9C0273
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\pltcpcomm.dllexecutable
MD5:594C3A44B547191E6C259C5677700FC2
SHA256:2F2E4E54D01E6E173894DEA14B97A1E30A2AE2B01B75715B76394EFE562A312D
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\rscagent.dllexecutable
MD5:85992B5C6FB3EE60D77E1BC54D9C3930
SHA256:4666DD1FCBD5FAF0D6ED96462965A9A5115CC922AE8D6D96EEF5898988F584EC
2904Crypmod' in file 'eTimeTrackLite Error Solver.exe'.exeC:\Program Files\Viral InfoTech\ErrorSolver\tcpcomm.dllexecutable
MD5:ABCAC16DB838829D89FA36372C821741
SHA256:9D1F7B8D2C3E5A4B7248F03BABDBE403D1043138DE01198DED4664A73CB95C38
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
0
TCP/UDP connections
4
DNS requests
0
Threats
0

HTTP requests

No HTTP requests
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:138
whitelisted
4
System
192.168.100.255:137
whitelisted
2588
svchost.exe
239.255.255.250:1900
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown

DNS requests

No data

Threats

No threats detected
No debug info