| File name: | EVCSPNx4Setup.exe |
| Full analysis: | https://app.any.run/tasks/7c0cf8f9-f76d-42b8-af1c-e74d2ce0fe04 |
| Verdict: | Malicious activity |
| Analysis date: | November 27, 2023, 12:22:01 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | C31ED411AFB3AD67BEB19D79CF66D199 |
| SHA1: | 9068A60DFE4876DC696D0886F2C06E4414817D9E |
| SHA256: | BE755E6F46AE0265A8FF0BD71C14842E4DE0C406DA8494038B07688F9CBE0CD9 |
| SSDEEP: | 98304:JWhrVO5Tf+S+PigXvO0z46cJarU/N3gpkq2QBIcUB8rxkmIknYgmmIZOOovUDY3o:u4hzfF |
| .ax | | | DirectShow filter (56.9) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (7.7) |
| .exe | | | Win32 Executable (generic) (1.2) |
| .exe | | | Generic Win/DOS Executable (0.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2018:09:20 12:18:20+02:00 |
| ImageFileCharacteristics: | Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 11 |
| CodeSize: | 431104 |
| InitializedDataSize: | 510976 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x41d17 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.1.2.1 |
| ProductVersionNumber: | 2.1.2.1 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Dynamic link library |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | SoftChain |
| FileDescription: | InstallScript Setup Launcher Unicode |
| FileVersion: | 2.1.2.1 |
| InternalName: | Setup |
| LegalCopyright: | Copyright (c) 2018 Flexera. All Rights Reserved. |
| OriginalFileName: | InstallShield Setup.exe |
| ProductName: | EVCSPNx |
| ProductVersion: | 2.1.2.1 |
| InternalBuildNumber: | 185990 |
| ISInternalVersion: | 24.0.573 |
| ISInternalDescription: | InstallScript Setup Launcher Unicode |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 1064 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2100 | "C:\Windows\System32\control.exe" | C:\Windows\System32\control.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Control Panel Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2252 | "C:\Users\admin\Desktop\EVCSPNx4Setup.exe" | C:\Users\admin\Desktop\EVCSPNx4Setup.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2484 | "C:\Users\admin\AppData\Local\Temp\{903092E7-8BC8-4285-9B12-244EFBDC3AEF}\DotNetInstaller.exe" "C:\Program Files\SoftChain\EVCSPNx\EVCSPNxSvc.exe" | C:\Users\admin\AppData\Local\Temp\{903092E7-8BC8-4285-9B12-244EFBDC3AEF}\DotNetInstaller.exe | — | EVCSPNx4Setup.exe | |||||||||||
User: admin Company: Flexera Software LLC Integrity Level: HIGH Description: DotNetInstaller Exit code: 0 Version: 24.0.0.573 Modules
| |||||||||||||||
| 2520 | "C:\Users\admin\AppData\Local\Temp\{903092E7-8BC8-4285-9B12-244EFBDC3AEF}\DotNetInstaller.exe" "C:\Program Files\SoftChain\EVCSPNx\EVCSPNx.exe" | C:\Users\admin\AppData\Local\Temp\{903092E7-8BC8-4285-9B12-244EFBDC3AEF}\DotNetInstaller.exe | — | EVCSPNx4Setup.exe | |||||||||||
User: admin Company: Flexera Software LLC Integrity Level: HIGH Description: DotNetInstaller Exit code: 0 Version: 24.0.0.573 Modules
| |||||||||||||||
| 2708 | "C:\Windows\system32\rundll32.exe" C:\Windows\system32\shell32.dll,OpenAs_RunDLL "C:\Users\admin\Desktop\EVCSPNx4Setup.exe.ax" | C:\Windows\System32\rundll32.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows host process (Rundll32) Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 3092 | EVCSPNx.exe | C:\Program Files\SoftChain\EVCSPNx\EVCSPNx.exe | — | EVCSPNxSvc.exe | |||||||||||
User: admin Company: Softchain,Inc Integrity Level: MEDIUM Description: EVCSPNx Exit code: 0 Version: 2.1.2.1 Modules
| |||||||||||||||
| 3280 | C:\Users\admin\AppData\Local\Temp\{2944AF09-F658-4F72-AD95-FAEB57682F8D}\EVCSPNx4Setup.exe -package:"C:\Users\admin\Desktop\EVCSPNx4Setup.exe" -no_selfdeleter -IS_temp -media_path:"C:\Users\admin\AppData\Local\Temp\{2944AF09-F658-4F72-AD95-FAEB57682F8D}\Disk1\" -tempdisk1folder:"C:\Users\admin\AppData\Local\Temp\{2944AF09-F658-4F72-AD95-FAEB57682F8D}\" -IS_OriginalLauncher:"C:\Users\admin\AppData\Local\Temp\{2944AF09-F658-4F72-AD95-FAEB57682F8D}\Disk1\EVCSPNx4Setup.exe" | C:\Users\admin\AppData\Local\Temp\{2944AF09-F658-4F72-AD95-FAEB57682F8D}\EVCSPNx4Setup.exe | — | EVCSPNx4Setup.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 3932 | "C:\Program Files\SoftChain\EVCSPNx\EVCSPNxSvc.exe" | C:\Program Files\SoftChain\EVCSPNx\EVCSPNxSvc.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Softchain,Inc Integrity Level: SYSTEM Description: EVCSPNxSvc Exit code: 0 Version: 2.1.2.1 Modules
| |||||||||||||||
| 4028 | "C:\Users\admin\Desktop\EVCSPNx4Setup.exe" | C:\Users\admin\Desktop\EVCSPNx4Setup.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| (PID) Process: | (3280) EVCSPNx4Setup.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Enter) |
Value: 4000000000000000F2B487BA16B0D901C80700002C0A0000D5070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3280) EVCSPNx4Setup.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Enter) |
Value: 4000000000000000F2B487BA16B0D901C80700002C0A0000D0070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3280) EVCSPNx4Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SPP |
| Operation: | write | Name: | LastIndex |
Value: 72 | |||
| (PID) Process: | (3280) EVCSPNx4Setup.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Enter) |
Value: 40000000000000008C62D6BA16B0D901C80700002C0A0000D3070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3280) EVCSPNx4Setup.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppGatherWriterMetadata (Leave) |
Value: 400000000000000064514ABC16B0D901C80700002C0A0000D3070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3280) EVCSPNx4Setup.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppAddInterestingComponents (Enter) |
Value: 400000000000000064514ABC16B0D901C80700002C0A0000D4070000000000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3280) EVCSPNx4Setup.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppAddInterestingComponents (Leave) |
Value: 400000000000000034645DBC16B0D901C80700002C0A0000D4070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3280) EVCSPNx4Setup.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SPP |
| Operation: | write | Name: | SppCreate (Leave) |
Value: 4000000000000000781D5ABD16B0D901C80700002C0A0000D0070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3280) EVCSPNx4Setup.exe | Key: | HKEY_LOCAL_MACHINE\SYSTEM\ControlSet001\services\VSS\Diag\SystemRestore |
| Operation: | write | Name: | SrCreateRp (Leave) |
Value: 4000000000000000781D5ABD16B0D901C80700002C0A0000D5070000010000000000000000000000000000000000000000000000000000000000000000000000 | |||
| (PID) Process: | (3280) EVCSPNx4Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\SystemRestore |
| Operation: | write | Name: | FirstRun |
Value: 0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2252 | EVCSPNx4Setup.exe | C:\Users\admin\AppData\Local\Temp\{2944AF09-F658-4F72-AD95-FAEB57682F8D}\Disk1\data1.hdr | compressed | |
MD5:693D687D70A90F1B9F31521D6F89789A | SHA256:B7CCC7EB3D577DBAF8CFF7716F777CB46C222113A092D3B32D973DD9AE9EFB8D | |||
| 2252 | EVCSPNx4Setup.exe | C:\Users\admin\AppData\Local\Temp\{2944AF09-F658-4F72-AD95-FAEB57682F8D}\Disk1\data1.cab | compressed | |
MD5:D2602838305BADFCD8D5DB28DE0A6250 | SHA256:C95C81D67BF838D188D482D2DE7D840614CCEE248DF386B6197319C468998C73 | |||
| 2252 | EVCSPNx4Setup.exe | C:\Users\admin\AppData\Local\Temp\{2944AF09-F658-4F72-AD95-FAEB57682F8D}\Disk1\ISSetup.dll | executable | |
MD5:9C9F06532BBC96493531AAA57BC0FC57 | SHA256:60EBC86C2DD03056AD48ADC6D2468FD54C548A55D2D305577EB7E079D90AC13F | |||
| 2252 | EVCSPNx4Setup.exe | C:\Users\admin\AppData\Local\Temp\{2944AF09-F658-4F72-AD95-FAEB57682F8D}\Disk1\setup.inx | binary | |
MD5:BBFC9BE91BE38232A39F41E944972747 | SHA256:2FF61B3F0495A68EEBD004441F868CA3CF6E98848948C9E273DB2B095876CC52 | |||
| 2252 | EVCSPNx4Setup.exe | C:\Users\admin\AppData\Local\Temp\{2944AF09-F658-4F72-AD95-FAEB57682F8D}\Disk1\setup.ini | text | |
MD5:3235ED5C06823A555A105B8BEBEEE026 | SHA256:70B726F91F44DF965718D59ED8D0255A232D64646CB91D9507EB93AC0AA3D16B | |||
| 2252 | EVCSPNx4Setup.exe | C:\Users\admin\AppData\Local\Temp\{2944AF09-F658-4F72-AD95-FAEB57682F8D}\EVCSPNx4Setup.exe | executable | |
MD5:85286907A86EBCFF7D1BC45379085239 | SHA256:27D431D80B0300601A5721F8927BC70D00F1767863F8F852F635D42C56535E6D | |||
| 3280 | EVCSPNx4Setup.exe | C:\Users\admin\AppData\Local\Temp\{2944AF09-F658-4F72-AD95-FAEB57682F8D}\0x0412.ini | text | |
MD5:CBA94FC446EE18AF0E46393D50AADB9A | SHA256:333AAD8FDA427FFAE741177FF201DB27E57ADDEB4B6A76F7D412CB994F1D26FD | |||
| 3280 | EVCSPNx4Setup.exe | C:\Users\admin\AppData\Local\Temp\{2944AF09-F658-4F72-AD95-FAEB57682F8D}\ISSetup.dll | executable | |
MD5:9C9F06532BBC96493531AAA57BC0FC57 | SHA256:60EBC86C2DD03056AD48ADC6D2468FD54C548A55D2D305577EB7E079D90AC13F | |||
| 2252 | EVCSPNx4Setup.exe | C:\Users\admin\AppData\Local\Temp\{2944AF09-F658-4F72-AD95-FAEB57682F8D}\setup.ini | text | |
MD5:3235ED5C06823A555A105B8BEBEEE026 | SHA256:70B726F91F44DF965718D59ED8D0255A232D64646CB91D9507EB93AC0AA3D16B | |||
| 3280 | EVCSPNx4Setup.exe | C:\Users\admin\AppData\Local\Temp\{903092E7-8BC8-4285-9B12-244EFBDC3AEF}\{73D38D2B-DB05-4542-8891-041D4EC37304}\setup.inx | binary | |
MD5:BBFC9BE91BE38232A39F41E944972747 | SHA256:2FF61B3F0495A68EEBD004441F868CA3CF6E98848948C9E273DB2B095876CC52 | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |