| File name: | AnySign_Installer.exe |
| Full analysis: | https://app.any.run/tasks/34a20f9f-177b-4b5e-9352-455a3d401561 |
| Verdict: | Malicious activity |
| Analysis date: | February 01, 2024, 04:33:09 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 9246A902D0B104A3E58FCDB6AD42DA33 |
| SHA1: | C185F670C26DF7E8249B44F49AC35B25DECD5BD4 |
| SHA256: | A850BD4694277893E85B473BDEB0488F834D2D4E1CE3D47486F4BE2AB93F785C |
| SSDEEP: | 98304:tqcX4EPlwSFzZ1l+qrBIaAilD0kn4uwfLWU+cnBEKlrZTNhHFbC0VYMzPTYgtg7o:XJjgDlrdKClXeUBwzMgoO5b+R |
| .exe | | | NSIS - Nullsoft Scriptable Install System (91.9) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (3.3) |
| .exe | | | Win64 Executable (generic) (3) |
| .dll | | | Win32 Dynamic Link Library (generic) (0.7) |
| .exe | | | Win32 Executable (generic) (0.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2014:10:07 06:40:23+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 24064 |
| InitializedDataSize: | 162816 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x30e2 |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.1.2.7 |
| ProductVersionNumber: | 1.1.2.7 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Windows, Latin1 |
| Comments: | Hancomwith AnySign Installer |
| CompanyName: | HANCOM WITH |
| FileDescription: | AnySign Installer |
| FileVersion: | 1.1.2.7 |
| LegalCopyright: | HANCOM WITH Inc. |
| ProductName: | AnySign |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1376 | Any_setup.exe /E /F | C:\Program Files\SoftForum\XecureWeb\AnySign\dll\Any_setup.exe | AnySign_Installer.exe | ||||||||||||
User: admin Company: HANCOM WITH Inc. Integrity Level: HIGH Description: setup Application Exit code: 0 Version: 1, 0, 0, 0 Modules
| |||||||||||||||
| 1380 | "C:\Users\admin\Desktop\AnySign_Installer.exe" | C:\Users\admin\Desktop\AnySign_Installer.exe | — | explorer.exe | |||||||||||
User: admin Company: HANCOM WITH Integrity Level: MEDIUM Description: AnySign Installer Exit code: 3221226540 Version: 1.1.2.7 Modules
| |||||||||||||||
| 2088 | "C:\Users\admin\Desktop\AnySign_Installer.exe" | C:\Users\admin\Desktop\AnySign_Installer.exe | explorer.exe | ||||||||||||
User: admin Company: HANCOM WITH Integrity Level: HIGH Description: AnySign Installer Exit code: 0 Version: 1.1.2.7 Modules
| |||||||||||||||
| 2536 | AnySign4PCLauncher.exe -start | C:\Program Files\SoftForum\XecureWeb\AnySign\dll\AnySign4PCLauncher.exe | AnySign_Installer.exe | ||||||||||||
User: admin Company: HANCOM WITH Inc. Integrity Level: HIGH Description: AnySign For PC Launcher Exit code: 0 Version: 1.1.2.7 Modules
| |||||||||||||||
| 3016 | "C:\Program Files\SoftForum\XecureWeb\AnySign\dll\..\cert\certutil.exe" -L -n "Hancom Secure Root Authority" -d "sql:C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default" | C:\Program Files\SoftForum\XecureWeb\AnySign\cert\certutil.exe | Any_setup.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3084 | "C:\Program Files\SoftForum\XecureWeb\AnySign\cert\certutil.exe" -A -n "Hancom Secure Root Authority" -t "CT,C,C" -i "C:\Program Files\SoftForum\XecureWeb\AnySign\dll\..\cert\ca_cert_sh2.crt" -d "sql:C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles/qldyz51w.default" | C:\Program Files\SoftForum\XecureWeb\AnySign\cert\certutil.exe | Any_setup.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3136 | "C:\Program Files\SoftForum\XecureWeb\AnySign\dll\..\cert\certutil.exe" -L -n "Hancom Secure Root Authority" -d "sql:C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles/qldyz51w.default" | C:\Program Files\SoftForum\XecureWeb\AnySign\cert\certutil.exe | Any_setup.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 255 Modules
| |||||||||||||||
| 3212 | "C:\Program Files\Microsoft Office\Office14\WINWORD.EXE" /n "C:\Users\admin\Desktop\AnySign_Installer.doc" | C:\Program Files\Microsoft Office\Office14\WINWORD.EXE | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Word Exit code: 0 Version: 14.0.6024.1000 Modules
| |||||||||||||||
| 3580 | netsh advfirewall firewall add rule name = "AnySign4PC" dir=in action=allow program="C:\Program Files\SoftForum\XecureWeb\AnySign\dll\AnySign4PC.exe" enable=yes | C:\Windows\System32\netsh.exe | — | Any_setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Network Command Shell Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3612 | AnySign4PCLauncher.exe -install | C:\Program Files\SoftForum\XecureWeb\AnySign\dll\AnySign4PCLauncher.exe | AnySign_Installer.exe | ||||||||||||
User: admin Company: HANCOM WITH Inc. Integrity Level: HIGH Description: AnySign For PC Launcher Exit code: 0 Version: 1.1.2.7 Modules
| |||||||||||||||
| (PID) Process: | (1376) Any_setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (1376) Any_setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (1376) Any_setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (1376) Any_setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (1376) Any_setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyEnable |
Value: 0 | |||
| (PID) Process: | (1376) Any_setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005B010000090000000000000000000000000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (1376) Any_setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings |
| Operation: | write | Name: | ProxyOverride |
Value: localhost | |||
| (PID) Process: | (1376) Any_setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections |
| Operation: | write | Name: | SavedLegacySettings |
Value: 460000005C0100000900000000000000090000006C6F63616C686F7374000000000400000000000000C0E333BBEAB1D3010000000000000000000000000100000002000000C0A8016B000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3580) netsh.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2088) AnySign_Installer.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Classes\CLSID\{C0A026B9-7F93-48d4-9F6E-8D7521B2322F} |
| Operation: | write | Name: | AppID |
Value: {4FBF0B01-907A-4c6d-AE1A-7C6EC9F312D9} | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2088 | AnySign_Installer.exe | C:\Program Files\SoftForum\XecureWeb\AnySign\cert\ca_cert_sh2.crt | text | |
MD5:E7BF64956C2EC9B3C330618FA02DBC37 | SHA256:1DB25F0B2CCCCB639B083E309DFEEE781A447DEE962F6F6BD8AC126A3BED23D1 | |||
| 2088 | AnySign_Installer.exe | C:\Program Files\SoftForum\XecureWeb\AnySign\cert\certutil.exe | executable | |
MD5:F8DA06687FB47CA2C355C38CA2766262 | SHA256:64AD18F4D9BEF01B86E39CA1E774DFA37DB46BC8267453C418DD7F723D6D014C | |||
| 2088 | AnySign_Installer.exe | C:\Program Files\SoftForum\XecureWeb\AnySign\cert\freebl3.dll | executable | |
MD5:F474DD91BB12F230209EC3163CE7E6C4 | SHA256:F63B2CAB4B77AC63A1BECA66872A991E1F8233F2C513D42460DBF28C733B138C | |||
| 2088 | AnySign_Installer.exe | C:\Program Files\SoftForum\XecureWeb\AnySign\cert\msvcr120.dll | executable | |
MD5:034CCADC1C073E4216E9466B720F9849 | SHA256:86E39B5995AF0E042FCDAA85FE2AEFD7C9DDC7AD65E6327BD5E7058BC3AB615F | |||
| 2088 | AnySign_Installer.exe | C:\Program Files\SoftForum\XecureWeb\AnySign\cert\nspr4.dll | executable | |
MD5:BD0E897DBC2DCC0CF1287FFD7C734CF0 | SHA256:2D2096447B366D6640F2670EDB474AB208D8D85B5650DB5E80CC985D1189F911 | |||
| 2088 | AnySign_Installer.exe | C:\Program Files\SoftForum\XecureWeb\AnySign\cert\nss3.dll | executable | |
MD5:54F3932864EED803BD1CB82DF43F0C76 | SHA256:96E068E6162A98D212B57C86B14FC539F1BBDCCD363F68EFD8CDFECC90C699D3 | |||
| 2088 | AnySign_Installer.exe | C:\Program Files\SoftForum\XecureWeb\AnySign\cert\nssckbi.dll | executable | |
MD5:40483977B63FF6382BA0E4FB03198C8B | SHA256:BFA1DE077F19AFC7B21FEB41891B4200A40B4DDA114F483D4EB92FF7A375926D | |||
| 2088 | AnySign_Installer.exe | C:\Program Files\SoftForum\XecureWeb\AnySign\cert\nssdbm3.dll | executable | |
MD5:8CC6A31974A175A65D6C090FEED39F42 | SHA256:F64111FAA9966D7B7859C6467BEDBD64559284B049F55FFADC54DFC50A3A4264 | |||
| 2088 | AnySign_Installer.exe | C:\Program Files\SoftForum\XecureWeb\AnySign\dll\Any_setup.exe | executable | |
MD5:3213C5AAF0DEE5A453B5076F36D95FF5 | SHA256:7B92283DAB96EC6A84E4B42E232CAABAEB3817470718DF6E62024524396B752F | |||
| 2088 | AnySign_Installer.exe | C:\Program Files\SoftForum\XecureWeb\AnySign\cert\smime3.dll | executable | |
MD5:94624BBAB23A92E0A5F90CCE9A5A340D | SHA256:B0104EA7AAA257B111982BD0763C1C47FFF76BD70249F84DCAD834D50444DF1A | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
Process | Message |
|---|---|
Any_setup.exe | "C:\Program Files\SoftForum\XecureWeb\AnySign\dll\..\cert\certutil.exe" -L -n "Hancom Secure Root Authority" -d "sql:C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles/qldyz51w.default" |
Any_setup.exe | -A -n "Hancom Secure Root Authority" -t "CT,C,C" -i "C:\Program Files\SoftForum\XecureWeb\AnySign\dll\..\cert\ca_cert_sh2.crt" -d "sql:C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles/qldyz51w.default" |
Any_setup.exe | "C:\Program Files\SoftForum\XecureWeb\AnySign\dll\..\cert\certutil.exe" -L -n "Hancom Secure Root Authority" -d "sql:C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default" |
Any_setup.exe | netsh advfirewall firewall add rule name = "AnySign4PC" dir=in action=allow program="C:\Program Files\SoftForum\XecureWeb\AnySign\dll\AnySign4PC.exe" enable=yes |
AnySign4PCLauncher.exe |
%s------------------------------------------------
--- Themida Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|
AnySign4PC.exe |
%s------------------------------------------------
--- Themida Professional ---
--- (c)2012 Oreans Technologies ---
------------------------------------------------
|
AnySign4PC.exe | [04:33:25.098625] [0x00000e38] [info] integrity measurement point
|
AnySign4PC.exe | [04:33:25.473625] [0x00000e38] [info] AnySign4PCC Start.
|
AnySign4PC.exe | [04:33:25.473625] [0x00000e38] [info] tls_port listen port : 10531
|
AnySign4PC.exe | [04:33:25.473625] [0x00000e38] [info] no_tls_port listen port : 10530
|