| File name: | 15342_35965949_be6c151cc94797e2dafbc9000565678da00257421b3d8b355c06050881823f47_cyberjack kartenleser setup mit rechtklick als admin ausführen bc_7_8_10.exe |
| Full analysis: | https://app.any.run/tasks/390afe12-c523-4fd7-a862-664503de4b01 |
| Verdict: | Malicious activity |
| Analysis date: | May 14, 2024, 10:45:17 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 248EE3C92E4F58E0ACAE99BA54890218 |
| SHA1: | 607E66A19C716A0554193D5D66EC3561A5101B4F |
| SHA256: | BE6C151CC94797E2DAFBC9000565678DA00257421B3D8B355C06050881823F47 |
| SSDEEP: | 196608:CoOI8qsnbrlqPtWB6zbR2TgBO9rwK0ivFs:OIGnNe/B2/rL0ii |
| .ax | | | DirectShow filter (37.6) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (v2.x) (11) |
| .exe | | | InstallShield setup (8) |
| .exe | | | Win32 EXE PECompact compressed (generic) (7.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2013:10:02 04:08:55+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 421888 |
| InitializedDataSize: | 389632 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x40181 |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 7.8.10.0 |
| ProductVersionNumber: | 7.8.10.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | REINER SCT |
| FileDescription: | InstallScript Setup Launcher Unicode |
| FileVersion: | 7.8.10 |
| InternalName: | Setup |
| LegalCopyright: | Copyright (c) 2013 Flexera Software LLC. All Rights Reserved. |
| OriginalFileName: | InstallShield Setup.exe |
| ProductName: | cyberJack Base Components |
| ProductVersion: | 7.8.10 |
| InternalBuildNumber: | 133442 |
| ISInternalVersion: | 20.0.496 |
| ISInternalDescription: | InstallScript Setup Launcher Unicode |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 124 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=gpu-process --gpu-preferences=UAAAAAAAAADgAAAYAAAAAAAAAAAAAAAAAABgAAAAAAAwAAAAAAAAAAAAAAAQAAAAAAAAAAAAAAAAAAAAAAAAAEgAAAAAAAAASAAAAAAAAAAYAAAAAgAAABAAAAAAAAAAGAAAAAAAAAAQAAAAAAAAAAAAAAAOAAAAEAAAAAAAAAABAAAADgAAAAgAAAAAAAAACAAAAAAAAAA= --mojo-platform-channel-handle=1312 --field-trial-handle=1332,i,15279215443564931177,7947119790802769850,131072 /prefetch:2 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 524 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --first-renderer-process --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=6 --mojo-platform-channel-handle=2200 --field-trial-handle=1332,i,15279215443564931177,7947119790802769850,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Version: 109.0.1518.115 Modules
| |||||||||||||||
| 904 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4076 --field-trial-handle=1332,i,15279215443564931177,7947119790802769850,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 924 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=chrome.mojom.UtilWin --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=4212 --field-trial-handle=1332,i,15279215443564931177,7947119790802769850,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 936 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4220 --field-trial-handle=1332,i,15279215443564931177,7947119790802769850,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1056 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=renderer --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=2224 --field-trial-handle=1332,i,15279215443564931177,7947119790802769850,131072 /prefetch:1 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1280 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=4220 --field-trial-handle=1332,i,15279215443564931177,7947119790802769850,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1552 | "C:\Program Files\REINER SCT\cyberJack\subinacl.exe" /subdirectories "C:\ProgramData\REINER SCT\*" /grant="S-1-1-0"=F | C:\Program Files\REINER SCT\cyberJack\subinacl.exe | — | 15342_35965949_be6c151cc94797e2dafbc9000565678da00257421b3d8b355c06050881823f47_cyberjack kartenleser setup mit rechtklick als admin ausführen bc_7_8_10.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: SubInAcl Version: 5.2.3790.1180 Modules
| |||||||||||||||
| 1704 | C:\Windows\system32\cjpcsc.exe | C:\Windows\System32\cjpcsc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: REINER SCT Integrity Level: SYSTEM Description: cyberJack PC/SC COM Service Version: 7.8.6.0 Modules
| |||||||||||||||
| 1756 | "C:\Program Files\REINER SCT\cyberJack\cJCC.exe" /TRFREG /S | C:\Program Files\REINER SCT\cyberJack\cJCC.exe | — | 15342_35965949_be6c151cc94797e2dafbc9000565678da00257421b3d8b355c06050881823f47_cyberjack kartenleser setup mit rechtklick als admin ausführen bc_7_8_10.exe | |||||||||||
User: admin Company: REINER SCT Integrity Level: HIGH Description: cyberJack Gerätemanager Exit code: 0 Version: 7.8.6.1 Modules
| |||||||||||||||
| (PID) Process: | (3976) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | failed_count |
Value: 0 | |||
| (PID) Process: | (3976) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 2 | |||
| (PID) Process: | (3976) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: | |||
| (PID) Process: | (3976) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\ThirdParty |
| Operation: | write | Name: | StatusCodes |
Value: 01000000 | |||
| (PID) Process: | (3976) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\BLBeacon |
| Operation: | write | Name: | state |
Value: 1 | |||
| (PID) Process: | (3976) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\EdgeUpdate\ClientState\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062} |
| Operation: | write | Name: | dr |
Value: 1 | |||
| (PID) Process: | (3976) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge\StabilityMetrics |
| Operation: | write | Name: | user_experience_metrics.stability.exited_cleanly |
Value: 0 | |||
| (PID) Process: | (3976) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\LastWasDefault |
| Operation: | write | Name: | S-1-5-21-1302019708-1500728564-335382590-1000 |
Value: 71D8E6FDFD762F00 | |||
| (PID) Process: | (3976) msedge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EdgeUpdate\ClientStateMedium\{56EB18F8-B008-4CBD-B6D2-8C97FE7E9062}\FirstNotDefault |
| Operation: | delete value | Name: | S-1-5-21-1302019708-1500728564-335382590-1000 |
Value: | |||
| (PID) Process: | (3976) msedge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Edge |
| Operation: | write | Name: | UsageStatsInSample |
Value: 1 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3976 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\0037fab4-f90f-4aaf-b7a4-09f7a8b22a9b.tmp | — | |
MD5:— | SHA256:— | |||
| 3976 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RF10c65f.TMP | — | |
MD5:— | SHA256:— | |||
| 3976 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3976 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RF10c68e.TMP | — | |
MD5:— | SHA256:— | |||
| 3976 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3976 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RF10c778.TMP | — | |
MD5:— | SHA256:— | |||
| 3976 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old | — | |
MD5:— | SHA256:— | |||
| 3976 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\Session Storage\LOG.old~RF10c853.TMP | text | |
MD5:C2F5F0CF3799AE7C49D5998928742D2B | SHA256:9A3A3979C14C0FE3187A2054464DB6F42D9C27ACBC6E1863EE24BAEB1A084985 | |||
| 4000 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\CrashpadMetrics.pma~RF10bdd3.TMP | binary | |
MD5:886E82F2CA62ECCCE64601B30592078A | SHA256:E5E13D53601100FF3D6BB71514CBCCC4C73FE9B7EF5E930100E644187B42948E | |||
| 3976 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Crashpad\settings.dat | binary | |
MD5:A6EBC0D32A7B9304824D19DB63B4E37A | SHA256:E991057C2B1718A151C5FD06E1C153F57130D195454A1F94C8C4C20971697093 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
— | — | GET | 302 | 74.125.34.46:80 | http://www.virustotal.com/ | unknown | — | — | unknown |
2032 | msedge.exe | GET | 302 | 2.18.97.227:80 | http://go.microsoft.com/fwlink/?LinkId=57426&Ext=ax | unknown | — | — | unknown |
2032 | msedge.exe | GET | 301 | 88.221.110.226:80 | http://shell.windows.com/fileassoc/fileassoc.asp?Ext=ax | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:138 | — | — | — | unknown |
3976 | msedge.exe | 239.255.255.250:1900 | — | — | — | unknown |
2032 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
2032 | msedge.exe | 2.18.97.227:80 | go.microsoft.com | Akamai International B.V. | FR | unknown |
2032 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
2032 | msedge.exe | 88.221.110.226:80 | shell.windows.com | Akamai International B.V. | DE | unknown |
2032 | msedge.exe | 92.123.104.28:443 | www.bing.com | Akamai International B.V. | DE | unknown |
2032 | msedge.exe | 92.123.104.23:443 | www.bing.com | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
config.edge.skype.com |
| whitelisted |
go.microsoft.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
shell.windows.com |
| whitelisted |
www.bing.com |
| whitelisted |
r.bing.com |
| whitelisted |
th.bing.com |
| whitelisted |
login.microsoftonline.com |
| whitelisted |
aefd.nelreports.net |
| whitelisted |
services.bingapis.com |
| unknown |