| File name: | CLodop_Setup_for_Win32NT (1).exe |
| Full analysis: | https://app.any.run/tasks/8f305750-d902-4f15-981f-a83abc51918e |
| Verdict: | Malicious activity |
| Threats: | Metamorfo is a trojan malware family that has been active since 2018. It remains a top threat, focusing on stealing victims’ financial information, including banking credentials and other data. The malware is known for targeting users in Brazil. |
| Analysis date: | October 25, 2023, 13:08:29 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | EAC342A26A394ECDCF95E668121F6526 |
| SHA1: | C5EE45D5CD506DC330DDE8DE3779DC83BF286400 |
| SHA256: | 81B89CC0B3659C6E250B5ECF6B86D3E8CCBA14CDA64E51E7B8DC1747113EF4EF |
| SSDEEP: | 98304:+xUNtgBzrIWreDvt4vPprIpk6pjcnguWlV3eaEL/l2Yh+hOoBo0l2sAgX/gZmhEA:4E2jnkyk6K7C21Bbv |
| .exe | | | Inno Setup installer (77.7) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (10) |
| .dll | | | Win32 Dynamic Link Library (generic) (4.6) |
| .exe | | | Win32 Executable (generic) (3.1) |
| .exe | | | Win16/32 Executable Delphi generic (1.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:20 00:22:17+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 36864 |
| InitializedDataSize: | 15872 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x97f8 |
| OSVersion: | 1 |
| ImageVersion: | - |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 6.5.7.7 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Chinese (Simplified) |
| CharacterSet: | ASCII |
| Comments: | 此安装程序由 Inno Setup 构建。 |
| CompanyName: | MTSoftware(CN) |
| FileDescription: | C-Lodop(32-bit) Setup |
| FileVersion: | 6.5.7.7 |
| LegalCopyright: |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1556 | "C:\Program Files\MountTaiSoftware\CLodop32\CLodopService32.exe" | C:\Program Files\MountTaiSoftware\CLodop32\CLodopService32.exe | services.exe | ||||||||||||
User: SYSTEM Company: (中国)梦泰尔软件 MTSoftware(CN) Integrity Level: SYSTEM Description: C-Lodop 云打印“免登录”启动服务 Exit code: 0 Version: 6.5.7.1 Modules
| |||||||||||||||
| 1736 | "C:\Program Files\MountTaiSoftware\CLodop32\CLodopPrint32.exe" setup_noauto | C:\Program Files\MountTaiSoftware\CLodop32\CLodopPrint32.exe | is-8SFLL.tmp | ||||||||||||
User: admin Company: (中国)梦泰尔软件 MTSoftware(CN) Integrity Level: HIGH Description: Web打印服务C-Lodop Exit code: 0 Version: 6.5.7.7 Modules
| |||||||||||||||
| 2328 | "C:\Users\admin\AppData\Local\Temp\CLodop_Setup_for_Win32NT (1).exe" | C:\Users\admin\AppData\Local\Temp\CLodop_Setup_for_Win32NT (1).exe | explorer.exe | ||||||||||||
User: admin Company: MTSoftware(CN) Integrity Level: HIGH Description: C-Lodop(32-bit) Setup Exit code: 0 Version: 6.5.7.7 Modules
| |||||||||||||||
| 2440 | "C:\Users\admin\AppData\Local\Temp\is-9AKG9.tmp\is-8SFLL.tmp" /SL4 $1001CA "C:\Users\admin\AppData\Local\Temp\CLodop_Setup_for_Win32NT (1).exe" 4701871 51200 | C:\Users\admin\AppData\Local\Temp\is-9AKG9.tmp\is-8SFLL.tmp | — | CLodop_Setup_for_Win32NT (1).exe | |||||||||||
User: admin Integrity Level: HIGH Description: 安装/卸载 Exit code: 0 Version: 51.46.0.0 Modules
| |||||||||||||||
| 2568 | "C:\Program Files\MountTaiSoftware\CLodop32\CLodopPrint32_backup.exe" | C:\Program Files\MountTaiSoftware\CLodop32\CLodopPrint32_backup.exe | CLodopPrint32.exe | ||||||||||||
User: admin Company: (中国)梦泰尔软件 MTSoftware(CN) Integrity Level: HIGH Description: Web打印服务C-Lodop Exit code: 0 Version: 6.5.7.7 Modules
| |||||||||||||||
| 2628 | "C:\Program Files\MountTaiSoftware\CLodop32\CLodopService32.exe" -INSTALL -SILENT | C:\Program Files\MountTaiSoftware\CLodop32\CLodopService32.exe | — | CLodopPrint32.exe | |||||||||||
User: admin Company: (中国)梦泰尔软件 MTSoftware(CN) Integrity Level: HIGH Description: C-Lodop 云打印“免登录”启动服务 Exit code: 0 Version: 6.5.7.1 Modules
| |||||||||||||||
| 3420 | "C:\Program Files\MountTaiSoftware\CLodop32\CLodopPrint32_backup.exe" | C:\Program Files\MountTaiSoftware\CLodop32\CLodopPrint32_backup.exe | — | CLodopPrint32.exe | |||||||||||
User: admin Company: (中国)梦泰尔软件 MTSoftware(CN) Integrity Level: HIGH Description: Web打印服务C-Lodop Exit code: 0 Version: 6.5.7.7 Modules
| |||||||||||||||
| 3820 | "C:\Users\admin\AppData\Local\Temp\CLodop_Setup_for_Win32NT (1).exe" | C:\Users\admin\AppData\Local\Temp\CLodop_Setup_for_Win32NT (1).exe | — | explorer.exe | |||||||||||
User: admin Company: MTSoftware(CN) Integrity Level: MEDIUM Description: C-Lodop(32-bit) Setup Exit code: 3221226540 Version: 6.5.7.7 Modules
| |||||||||||||||
| (PID) Process: | (1736) CLodopPrint32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLodop.protocol |
| Operation: | write | Name: | URL Protocol |
Value: | |||
| (PID) Process: | (1736) CLodopPrint32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLodop.protocol\Application |
| Operation: | write | Name: | ApplicationName |
Value: Web打印服务C-Lodop | |||
| (PID) Process: | (1736) CLodopPrint32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLodop.protocol\Application |
| Operation: | write | Name: | ApplicationCompany |
Value: MTSoftware | |||
| (PID) Process: | (1736) CLodopPrint32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLodop.protocol\Application |
| Operation: | write | Name: | ApplicationDescription |
Value: Web打印服务C-Lodop | |||
| (PID) Process: | (1736) CLodopPrint32.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLodop.protocol\Application |
| Operation: | write | Name: | ApplicationIcon |
Value: C:\Program Files\MountTaiSoftware\CLodop32\CLodopPrint32.exe,0 | |||
| (PID) Process: | (1736) CLodopPrint32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1736) CLodopPrint32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1736) CLodopPrint32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1736) CLodopPrint32.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2440 | is-8SFLL.tmp | C:\Users\admin\AppData\Local\Temp\is-JI52T.tmp\_isetup\_shfoldr.dll | executable | |
MD5:92DC6EF532FBB4A5C3201469A5B5EB63 | SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87 | |||
| 2440 | is-8SFLL.tmp | C:\Program Files\MountTaiSoftware\CLodop32\SSL\is-JKUQ0.tmp | — | |
MD5:— | SHA256:— | |||
| 2440 | is-8SFLL.tmp | C:\Program Files\MountTaiSoftware\CLodop32\SSL\localhost_c_bak.pem | — | |
MD5:— | SHA256:— | |||
| 2440 | is-8SFLL.tmp | C:\Program Files\MountTaiSoftware\CLodop32\SSL\is-9S9DN.tmp | — | |
MD5:— | SHA256:— | |||
| 2440 | is-8SFLL.tmp | C:\Program Files\MountTaiSoftware\CLodop32\SSL\localhost_c_bak.key | — | |
MD5:— | SHA256:— | |||
| 2440 | is-8SFLL.tmp | C:\Users\admin\AppData\Local\Temp\is-JI52T.tmp\_isetup\_RegDLL.tmp | executable | |
MD5:C594B792B9C556EA62A30DE541D2FB03 | SHA256:5DCC1E0A197922907BCA2C4369F778BD07EE4B1BBBDF633E987A028A314D548E | |||
| 2440 | is-8SFLL.tmp | C:\Program Files\MountTaiSoftware\CLodop32\is-M1TDV.tmp | executable | |
MD5:7A6D009BB8F758C5DCE0830CC3FFD25B | SHA256:A5E18AA27305328549D9606BA47417285527758F61EC9DB494473CC8B1AC0BF7 | |||
| 2440 | is-8SFLL.tmp | C:\Program Files\MountTaiSoftware\CLodop32\unins000.exe | executable | |
MD5:7A6D009BB8F758C5DCE0830CC3FFD25B | SHA256:A5E18AA27305328549D9606BA47417285527758F61EC9DB494473CC8B1AC0BF7 | |||
| 2328 | CLodop_Setup_for_Win32NT (1).exe | C:\Users\admin\AppData\Local\Temp\is-9AKG9.tmp\is-8SFLL.tmp | executable | |
MD5:79551E7F460CE4A92B6C9C0F0B714108 | SHA256:06AE7ABCEC424F92569CD67E55E27C7E91F84F6108F91876CD3F135262341BEF | |||
| 2440 | is-8SFLL.tmp | C:\Users\admin\AppData\Local\Temp\is-JI52T.tmp\TaskDll.dll | executable | |
MD5:3A57389802E43A5BC4F13E99742C218E | SHA256:25CD485DD2A9E692637A6860ED3F75F810D8883781D169EE4954170FB800DCA6 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |