| File name: | cadesplugin.exe |
| Full analysis: | https://app.any.run/tasks/13d7bf4a-7071-4159-8117-b50a06a6368d |
| Verdict: | Malicious activity |
| Analysis date: | August 05, 2021, 20:22:50 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 1EFEAFBDB992F6D7A29F3A5E1D877D55 |
| SHA1: | BCA69EC73241E11AA0AE0EFCE59C96FF41ED6814 |
| SHA256: | 84C84921A55C96D543895345E31DBB95A4438C977B599966CA582C6E44D509EA |
| SSDEEP: | 196608:RcfFUWoq6dsT9Njzc/rUG8Eo5/6ABf5qoYsRvhoA1fN4qbpotpcEXmd8Uq:Rcf+vCcDT8Eo5RB5qoxRfTnbSiqmV |
| .exe | | | Generic Win/DOS Executable (50) |
|---|---|---|
| .exe | | | DOS Executable Generic (49.9) |
| Tag040904B0: | - |
|---|---|
| ProductVersion: | 2.0.14071.0 |
| ProductName: | Подсистема усовершенствованной ЭЦП |
| OriginalFileName: | cadespluginsetup.exe |
| LegalCopyright: | © Компания КРИПТО-ПРО. Все права защищены. |
| InternalName: | cadespluginsetup |
| FileVersion: | 2.0.14071.0 |
| FileDescription: | Установщик КриптоПро ЭЦП Browser plug-in |
| CompanyName: | Компания КРИПТО-ПРО |
| CharacterSet: | Unicode |
| LanguageCode: | Russian |
| FileSubtype: | - |
| ObjectFileType: | Executable application |
| FileOS: | Win32 |
| FileFlags: | (none) |
| FileFlagsMask: | 0x003f |
| ProductVersionNumber: | 2.0.14071.0 |
| FileVersionNumber: | 2.0.14071.0 |
| Subsystem: | Windows GUI |
| SubsystemVersion: | 5.1 |
| ImageVersion: | - |
| OSVersion: | 5.1 |
| EntryPoint: | 0x173b |
| UninitializedDataSize: | - |
| InitializedDataSize: | 44032 |
| CodeSize: | 133632 |
| LinkerVersion: | 14.12 |
| PEType: | PE32 |
| TimeStamp: | 2018:01:15 09:24:50+01:00 |
| MachineType: | Intel 386 or later, and compatibles |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 15-Jan-2018 08:24:50 |
| Detected languages: |
|
| Debug artifacts: |
|
| CompanyName: | Компания КРИПТО-ПРО |
| FileDescription: | Установщик КриптоПро ЭЦП Browser plug-in |
| FileVersion: | 2.0.14071.0 |
| InternalName: | cadespluginsetup |
| LegalCopyright: | © Компания КРИПТО-ПРО. Все права защищены. |
| OriginalFilename: | cadespluginsetup.exe |
| ProductName: | Подсистема усовершенствованной ЭЦП |
| ProductVersion: | 2.0.14071.0 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0060 |
| Pages in file: | 0x0001 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000D8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 15-Jan-2018 08:24:50 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00020836 | 0x00020A00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.38779 |
.rdata | 0x00022000 | 0x000055D6 | 0x00005600 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.10944 |
.data | 0x00028000 | 0x00002F80 | 0x00000A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 5.20616 |
.rsrc | 0x0002B000 | 0x00002978 | 0x00002A00 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.04687 |
.reloc | 0x0002E000 | 0x00002054 | 0x00002200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 6.60089 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.16261 | 1970 | Latin 1 / Western European | English - United States | RT_MANIFEST |
2 | 3.02666 | 296 | Latin 1 / Western European | English - United States | RT_ICON |
3 | 3.90563 | 2216 | Latin 1 / Western European | English - United States | RT_ICON |
4 | 3.2389 | 744 | Latin 1 / Western European | English - United States | RT_ICON |
101 | 2.73443 | 62 | Latin 1 / Western European | Russian - Russia | RT_GROUP_ICON |
IDR_MAIN | 2.64576 | 62 | Latin 1 / Western European | English - United States | RT_GROUP_ICON |
ADVAPI32.dll |
GDI32.dll |
KERNEL32.dll |
OLEAUT32.dll |
SHELL32.dll |
USER32.dll |
msvcrt.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1288 | "C:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.14071\Setup.exe" | C:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.14071\Setup.exe | — | cadesplugin.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2340 | C:\Windows\system32\vssvc.exe | C:\Windows\system32\vssvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft� Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3240 | "C:\Windows\system32\msiexec.exe" /i "C:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.14071\cadescom\cadescom-win32.msi" /Lv! "C:\Users\admin\AppData\Local\Temp\cadescom-win32.msi_2021-08-05-21-23-23.log" REBOOT=R /qb ADDNPCADES=1 | C:\Windows\system32\msiexec.exe | — | Setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows� installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3284 | C:\Windows\system32\MsiExec.exe -Embedding 5286ADA181387127056C0EAAC1A7B685 E Global\MSI0000 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows� installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3452 | C:\Windows\system32\msiexec.exe /V | C:\Windows\system32\msiexec.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Windows� installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3500 | C:\Windows\system32\MsiExec.exe -Embedding E12E43DB1803A8B20FA517DDCFDE38E9 | C:\Windows\system32\MsiExec.exe | — | msiexec.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows� installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3880 | "C:\Users\admin\AppData\Local\Temp\cadesplugin.exe" | C:\Users\admin\AppData\Local\Temp\cadesplugin.exe | — | Explorer.EXE | |||||||||||
User: admin Company: Crypto-Pro LLC Integrity Level: MEDIUM Description: CryptoPro CAdES Browser plug-in Setup Bootstrapper Exit code: 3221226540 Version: 2.0.14071.0 Modules
| |||||||||||||||
| 3892 | "C:\Users\admin\AppData\Local\Temp\cadesplugin.exe" | C:\Users\admin\AppData\Local\Temp\cadesplugin.exe | Explorer.EXE | ||||||||||||
User: admin Company: Crypto-Pro LLC Integrity Level: HIGH Description: CryptoPro CAdES Browser plug-in Setup Bootstrapper Exit code: 0 Version: 2.0.14071.0 Modules
| |||||||||||||||
| (PID) Process: | (3892) cadesplugin.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3892) cadesplugin.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3892) cadesplugin.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3892) cadesplugin.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3452) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 400000000000000081B45FBD378AD7017C0D0000E80A0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3452) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 400000000000000081B45FBD378AD7017C0D0000E80A0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3452) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 67 | |||
| (PID) Process: | (3452) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 4000000000000000DD4DBABD378AD7017C0D0000E80A0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3452) msiexec.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\VssapiPublisher |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 400000000000000037B0BCBD378AD7017C0D0000F80A0000E803000001000000000000000000000094085C44DBA4874A9E65B0749D60F59F0000000000000000 | |||
| (PID) Process: | (2340) vssvc.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\ASR Writer |
| Operation: | write | Name: | IDENTIFY (Enter) |
Value: 400000000000000053FECABD378AD70124090000C0080000E8030000010000000100000000000000000000000000000000000000000000000000000000000000 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3892 | cadesplugin.exe | C:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.14071\cadescom\Program Files 64\Crypto Pro\CAdES Browser Plug-in\Mini CSP\config | text | |
MD5:14A8FA2E498B8E2922CC96B06EDF0EEA | SHA256:C037EC3DB40EBB7DF91A6476ED36C67AFE22610B33C3EF53B531DACE6682F6AC | |||
| 3892 | cadesplugin.exe | C:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.14071\cadescom\program files\Crypto Pro\CAdES Browser Plug-in\Mini CSP\license | text | |
MD5:C72A9CC7E20B29DDE02CF4BE03994453 | SHA256:275C4440203665C736AF429954F6CDD532C54ED39153C5A6A3D5E3FCAF231F2C | |||
| 3892 | cadesplugin.exe | C:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.14071\cadescom\Program Files 64\Crypto Pro\CAdES Browser Plug-in\Mini CSP\license | text | |
MD5:C72A9CC7E20B29DDE02CF4BE03994453 | SHA256:275C4440203665C736AF429954F6CDD532C54ED39153C5A6A3D5E3FCAF231F2C | |||
| 3892 | cadesplugin.exe | C:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.14071\cadescom\program files\Crypto Pro\CAdES Browser Plug-in\CryptoPro.PKI.TSP.Client.manifest | xml | |
MD5:B48EE6AC971335D38B661220AAEEBC32 | SHA256:465FB15C3FD9C641C2D34A42068FC8F8FF23513CE92B352BDF7DA6248C67DF7F | |||
| 3892 | cadesplugin.exe | C:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.14071\cadescom\program files\Crypto Pro\CAdES Browser Plug-in\System32\GroupPolicy\Adm\CadesPlugin.adm | text | |
MD5:42F6C02BB2DBBE7BF68583B826611B53 | SHA256:A883F0F01A6A64FA218BB0BDC8F656D7A1AEC92C32DF30197259ED5A2E5E7C12 | |||
| 3892 | cadesplugin.exe | C:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.14071\cadescom\program files\Crypto Pro\CAdES Browser Plug-in\CryptoPro.PKI.OCSP.manifest | xml | |
MD5:DCED02A3200875C9DF0423FEB284622F | SHA256:8BE163B70C29E9A12F20E03B9AE90EC43CDFFBB1516ED1408E58333101C76C3A | |||
| 3892 | cadesplugin.exe | C:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.14071\cadescom\program files\Crypto Pro\CAdES Browser Plug-in\CryptoPro.PKI.TSP.manifest | xml | |
MD5:064E4C234DB62EDCB8F146136B4A7FC3 | SHA256:E1612B377A9148A884F2E027368666F102BA67CD5D2C7B0C8FC417DE08F8A9D4 | |||
| 3892 | cadesplugin.exe | C:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.14071\cadescom\program files\Crypto Pro\CAdES Browser Plug-in\CryptoPro.PKI.CAdES.manifest | xml | |
MD5:4F02D41E84F013DA79D77D33B26DB23B | SHA256:280612D99D8615E1D4D2734CB6BA5A410739415BF2CBDB0325A2FE412721B354 | |||
| 3892 | cadesplugin.exe | C:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.14071\cadescom\Common\Crypto Pro\Shared\certenroll.tlb | tlb | |
MD5:C5F19773AD7DF6FED26F4163B6FB0DBD | SHA256:B979755CF204F89405C48783E8825A982632578AC1E8A4D586CB14699C7DA85F | |||
| 3892 | cadesplugin.exe | C:\ProgramData\Crypto Pro\Installer Cache\CADESCOM_2.0.14071\cadescom\Common64\Crypto Pro\Shared\capicom.tlb | tlb | |
MD5:9D3A14EF42821A4CDD5F80484E4C9E27 | SHA256:879F18D4E7A1A0C08EC75C29F417C2A2917E81820A5A22F41DBDB652C0674A41 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
1360 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | Microsoft Corporation | GB | whitelisted |
— | — | 20.73.194.208:443 | — | — | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |