| File name: | hMailServer-5.6.8-B2574.exe |
| Full analysis: | https://app.any.run/tasks/11b51051-a2de-4002-b9aa-ea9d9fc28865 |
| Verdict: | Malicious activity |
| Analysis date: | February 19, 2024, 11:54:50 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | C8444C5EE87FC53003ECD6443209CA93 |
| SHA1: | 395CC0AFC3A1F4737BC42AC0FED1E747572D4CA0 |
| SHA256: | B7239676CD5EB9F21BF49C9AE170E7004B8ABECB7EEA08108930866A37D72659 |
| SSDEEP: | 98304:Y9peoM9NSmjBQEn1JjiSrS9q1tejXoAR4uEmkj2pfeGAOSIatAJqFT8IpWlEv7Fh:pANlS |
| .exe | | | Inno Setup installer (71.1) |
|---|---|---|
| .exe | | | Win32 Executable Delphi generic (9.1) |
| .scr | | | Windows screen saver (8.4) |
| .dll | | | Win32 Dynamic Link Library (generic) (4.2) |
| .exe | | | Win32 Executable (generic) (2.9) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 1992:06:19 22:22:17+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 40448 |
| InitializedDataSize: | 17920 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xa5f8 |
| OSVersion: | 1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 0.0.0.0 |
| ProductVersionNumber: | 0.0.0.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | |
| FileDescription: | hMailServer Setup |
| FileVersion: | |
| LegalCopyright: | Copyright © 2008 |
| ProductName: | hMailServer |
| ProductVersion: |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 296 | "C:\Windows\system32\net.exe" START hMailServer | C:\Windows\System32\net.exe | — | hMailServer-5.6.8-B2574.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Net Command Exit code: 2 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 764 | "C:\Program Files\hMailServer\Bin\hMailAdmin.exe" | C:\Program Files\hMailServer\Bin\hMailAdmin.exe | — | hMailServer-5.6.8-B2574.tmp | |||||||||||
User: admin Company: Halvar Information Integrity Level: MEDIUM Description: Administrator Exit code: 0 Version: 5.0.0.0 Modules
| |||||||||||||||
| 1824 | "C:\Program Files\hMailServer\Bin\hMailServer.exe" RunAsService | C:\Program Files\hMailServer\Bin\hMailServer.exe | — | services.exe | |||||||||||
User: SYSTEM Company: hMailServer Integrity Level: SYSTEM Description: hMailServer Exit code: 0 Version: 1.0 Modules
| |||||||||||||||
| 2376 | "C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe" /noconfig /fullpaths @"C:\Users\admin\AppData\Local\Temp\fs3f0yko.cmdline" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\csc.exe | hMailAdmin.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Visual C# Command Line Compiler Exit code: 0 Version: 8.0.50727.5483 (Win7SP1GDR.050727-5400) Modules
| |||||||||||||||
| 2420 | "C:\Program Files\hMailServer\Bin\hMailServer.exe" /Register | C:\Program Files\hMailServer\Bin\hMailServer.exe | — | hMailServer-5.6.8-B2574.tmp | |||||||||||
User: admin Company: hMailServer Integrity Level: HIGH Description: hMailServer Exit code: 0 Version: 1.0 Modules
| |||||||||||||||
| 2444 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\is-HVAPO.tmp\SSCERuntime-ENU.msi" /qn | C:\Windows\System32\msiexec.exe | — | hMailServer-5.6.8-B2574.tmp | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2584 | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe /NOLOGO /READONLY /MACHINE:IX86 "/OUT:C:\Users\admin\AppData\Local\Temp\RES898F.tmp" "c:\Users\admin\AppData\Local\Temp\CSC898E.tmp" | C:\Windows\Microsoft.NET\Framework\v2.0.50727\cvtres.exe | — | csc.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft® Resource File To COFF Object Conversion Utility Exit code: 0 Version: 8.00.50727.5003 (Win7SP1GDR.050727-5400) Modules
| |||||||||||||||
| 2752 | "C:\Users\admin\AppData\Local\Temp\is-3GME3.tmp\hMailServer-5.6.8-B2574.tmp" /SL5="$19013E,4066654,56832,C:\Users\admin\AppData\Local\Temp\hMailServer-5.6.8-B2574.exe" /SPAWNWND=$1A01BC /NOTIFYWND=$E0170 | C:\Users\admin\AppData\Local\Temp\is-3GME3.tmp\hMailServer-5.6.8-B2574.tmp | hMailServer-5.6.8-B2574.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.52.0.0 Modules
| |||||||||||||||
| 2756 | "C:\Program Files\hMailServer\Bin\DBSetupQuick.exe" password:12345 | C:\Program Files\hMailServer\Bin\DBSetupQuick.exe | — | hMailServer-5.6.8-B2574.tmp | |||||||||||
User: admin Company: HI Integrity Level: HIGH Description: DBSetupQuick Exit code: 0 Version: 1.0.0.0 Modules
| |||||||||||||||
| 2964 | "C:\Users\admin\AppData\Local\Temp\hMailServer-5.6.8-B2574.exe" /SPAWNWND=$1A01BC /NOTIFYWND=$E0170 | C:\Users\admin\AppData\Local\Temp\hMailServer-5.6.8-B2574.exe | hMailServer-5.6.8-B2574.tmp | ||||||||||||
User: admin Company: Integrity Level: HIGH Description: hMailServer Setup Exit code: 0 Version: Modules
| |||||||||||||||
| (PID) Process: | (2752) hMailServer-5.6.8-B2574.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: C00A00002E92EA772A63DA01 | |||
| (PID) Process: | (2752) hMailServer-5.6.8-B2574.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: 50C41C9B072EBB84CA9AF75A411B43DE6C6A7CDAE3161C82538EBAD7B598CFA2 | |||
| (PID) Process: | (2752) hMailServer-5.6.8-B2574.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (2752) hMailServer-5.6.8-B2574.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Windows\system32\atl70.dll | |||
| (PID) Process: | (2752) hMailServer-5.6.8-B2574.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFilesHash |
Value: CB48151EFFE7053461321D6DC5C3D5DD338B2391A8A629CC762B4588EFB0DDBD | |||
| (PID) Process: | (2752) hMailServer-5.6.8-B2574.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\hMailServer_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 5.5.4 (a) | |||
| (PID) Process: | (2752) hMailServer-5.6.8-B2574.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\hMailServer_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files\hMailServer | |||
| (PID) Process: | (2752) hMailServer-5.6.8-B2574.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\hMailServer_is1 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\hMailServer\ | |||
| (PID) Process: | (2752) hMailServer-5.6.8-B2574.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\hMailServer_is1 |
| Operation: | write | Name: | Inno Setup: Icon Group |
Value: hMailServer | |||
| (PID) Process: | (2752) hMailServer-5.6.8-B2574.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\hMailServer_is1 |
| Operation: | write | Name: | Inno Setup: User |
Value: admin | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2752 | hMailServer-5.6.8-B2574.tmp | C:\Users\admin\AppData\Local\Temp\is-HVAPO.tmp\_isetup\_shfoldr.dll | executable | |
MD5:92DC6EF532FBB4A5C3201469A5B5EB63 | SHA256:9884E9D1B4F8A873CCBD81F8AD0AE257776D2348D027D811A56475E028360D87 | |||
| 2752 | hMailServer-5.6.8-B2574.tmp | C:\Program Files\hMailServer\unins000.exe | executable | |
MD5:DF679C1A9B6C251B7F9FB2E8F17BEFEF | SHA256:24B9DDBA6424CCB901ABDA25E7F5B0106867CF8F3CC7295CCBEBCFF7B55FB731 | |||
| 2964 | hMailServer-5.6.8-B2574.exe | C:\Users\admin\AppData\Local\Temp\is-3GME3.tmp\hMailServer-5.6.8-B2574.tmp | executable | |
MD5:1305181DE520F125AEABF85DC24A89D6 | SHA256:0E19765B89A1A29AFEE09810DCB3EC5CC7C66053947BE8F1AEBDBB7C801DFEAF | |||
| 3672 | hMailServer-5.6.8-B2574.exe | C:\Users\admin\AppData\Local\Temp\is-P95RG.tmp\hMailServer-5.6.8-B2574.tmp | executable | |
MD5:1305181DE520F125AEABF85DC24A89D6 | SHA256:0E19765B89A1A29AFEE09810DCB3EC5CC7C66053947BE8F1AEBDBB7C801DFEAF | |||
| 2752 | hMailServer-5.6.8-B2574.tmp | C:\Users\admin\AppData\Local\Temp\is-HVAPO.tmp\is-R1OHQ.tmp | executable | |
MD5:81802B011FA0F84E62C3967101E756D3 | SHA256:9E1594BC762F10109EB08334DFC889982FB3F2BDC6F585A80BC58037F9242DAF | |||
| 2752 | hMailServer-5.6.8-B2574.tmp | C:\Program Files\hMailServer\Bin\License.rtf | text | |
MD5:67DA419790DB8E161B6F566B42277A85 | SHA256:97EEB485005171627A6A0A115F42282049D8FF55C8DE394C70000AA5BF973614 | |||
| 2752 | hMailServer-5.6.8-B2574.tmp | C:\Users\admin\AppData\Local\Temp\is-HVAPO.tmp\SSCERuntime-ENU.msi | executable | |
MD5:81802B011FA0F84E62C3967101E756D3 | SHA256:9E1594BC762F10109EB08334DFC889982FB3F2BDC6F585A80BC58037F9242DAF | |||
| 2752 | hMailServer-5.6.8-B2574.tmp | C:\Windows\system32\is-69SDC.tmp | executable | |
MD5:48B5F0B89C1F354E366CA716D763B9A7 | SHA256:6E4F674619F5AB33190C9B841D31E06A7451ADDE41BDCD9D39461E7F924DDA67 | |||
| 2752 | hMailServer-5.6.8-B2574.tmp | C:\Program Files\hMailServer\Bin\libcrypto-1_1.dll | executable | |
MD5:8A284A5D0C7BBB549EB829173D7D3D5A | SHA256:1FE1681A2A56047BE2E299A574457BC2A2444C545F342CFE011BF542D2407618 | |||
| 2752 | hMailServer-5.6.8-B2574.tmp | C:\Windows\System32\atl70.dll | executable | |
MD5:48B5F0B89C1F354E366CA716D763B9A7 | SHA256:6E4F674619F5AB33190C9B841D31E06A7451ADDE41BDCD9D39461E7F924DDA67 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |