| File name: | CrystalDiskMark8_0_5.exe |
| Full analysis: | https://app.any.run/tasks/9176d6e6-1b03-414c-9072-697397fabfe4 |
| Verdict: | Malicious activity |
| Analysis date: | June 29, 2024, 18:31:11 |
| OS: | Windows 10 Professional (build: 19045, 64 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 41976AB5C64F627410B320B11474E108 |
| SHA1: | 71B8E92B16FF827CB215647B8A0CAA4EDD623452 |
| SHA256: | C438C644469C4221FF3014A31196E175F5548F07526ECE87238CB0DAEBC9C119 |
| SSDEEP: | 98304:3+cD4dnzn24qy9N+ppoOBZ3nNE55JgOHnJhOrfLDRRTSqJhaqWWBDue3AtghCv8i:jQMz3Bo9 |
| .exe | | | Inno Setup installer (67.7) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (25.6) |
| .exe | | | Win32 Executable (generic) (2.7) |
| .exe | | | Win16/32 Executable Delphi generic (1.2) |
| .exe | | | Generic Win/DOS Executable (1.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2022:04:14 16:10:23+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741888 |
| InitializedDataSize: | 114688 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 8.0.5.0 |
| ProductVersionNumber: | 8.0.5.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Crystal Dew World |
| FileDescription: | CrystalDiskMark 8 Setup |
| FileVersion: | 8.0.5 |
| LegalCopyright: | Crystal Dew World |
| OriginalFileName: | |
| ProductName: | CrystalDiskMark 8.0.5 |
| ProductVersion: | 8.0.5 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | "C:\Users\admin\AppData\Local\Temp\is-ST99C.tmp\CrystalDiskMark8_0_5.tmp" /SL5="$50284,3181377,857600,C:\Users\admin\AppData\Local\Temp\CrystalDiskMark8_0_5.exe" /SPAWNWND=$302C8 /NOTIFYWND=$40344 | C:\Users\admin\AppData\Local\Temp\is-ST99C.tmp\CrystalDiskMark8_0_5.tmp | CrystalDiskMark8_0_5.exe | ||||||||||||
User: admin Company: Crystal Dew World Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 380 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=2292 -parentBuildID 20240213221259 -prefsHandle 2284 -prefMapHandle 2272 -prefsLen 30537 -prefMapSize 244343 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {792e607c-eac8-4734-8d31-5ef1a1b7d07b} 6708 "\\.\pipe\gecko-crash-server-pipe.6708" 1dbe607f510 socket | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 528 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=renderer --no-appcompat-clear --lang=en-US --js-flags=--ms-user-locale= --device-scale-factor=1 --num-raster-threads=2 --enable-main-frame-before-activation --renderer-client-id=5 --mojo-platform-channel-handle=3612 --field-trial-handle=2360,i,6473513328271628874,5130870996203181561,262144 --variations-seed-version /prefetch:1 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 876 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4624 --field-trial-handle=2344,i,2693761181899779721,10628946322765504373,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1076 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=8396 -childID 14 -isForBrowser -prefsHandle 8440 -prefMapHandle 8444 -prefsLen 31288 -prefMapSize 244343 -jsInitHandle 1540 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {f056077d-409a-4f35-a311-99d470f29d3f} 6708 "\\.\pipe\gecko-crash-server-pipe.6708" 1dbfe7ef4d0 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1112 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=1680 --field-trial-handle=2344,i,2693761181899779721,10628946322765504373,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1124 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4792 --field-trial-handle=2344,i,2693761181899779721,10628946322765504373,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1428 | "C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --no-appcompat-clear --mojo-platform-channel-handle=4692 --field-trial-handle=2344,i,2693761181899779721,10628946322765504373,262144 --variations-seed-version /prefetch:8 | C:\Program Files (x86)\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 122.0.2365.59 Modules
| |||||||||||||||
| 1440 | "C:\Program Files\Mozilla Firefox\firefox.exe" -contentproc --channel=8124 -childID 12 -isForBrowser -prefsHandle 8056 -prefMapHandle 8044 -prefsLen 31288 -prefMapSize 244343 -jsInitHandle 1540 -jsInitLen 235124 -parentBuildID 20240213221259 -win32kLockedDown -appDir "C:\Program Files\Mozilla Firefox\browser" - {2d274947-cb22-4ce8-9546-b448c71afefe} 6708 "\\.\pipe\gecko-crash-server-pipe.6708" 1dbfac1b850 tab | C:\Program Files\Mozilla Firefox\firefox.exe | — | firefox.exe | |||||||||||
User: admin Company: Mozilla Corporation Integrity Level: LOW Description: Firefox Exit code: 0 Version: 123.0 Modules
| |||||||||||||||
| 1916 | "C:\Users\admin\AppData\Local\Temp\CrystalDiskMark8_0_5.exe" /SPAWNWND=$302C8 /NOTIFYWND=$40344 | C:\Users\admin\AppData\Local\Temp\CrystalDiskMark8_0_5.exe | CrystalDiskMark8_0_5.tmp | ||||||||||||
User: admin Company: Crystal Dew World Integrity Level: HIGH Description: CrystalDiskMark 8 Setup Exit code: 0 Version: 8.0.5 Modules
| |||||||||||||||
| (PID) Process: | (116) CrystalDiskMark8_0_5.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: 74000000A120D58852CADA01 | |||
| (PID) Process: | (116) CrystalDiskMark8_0_5.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: ED7B186704B9899A0E514B219C2BB47D41BF7CC085B84F71A48E0F481F946F77 | |||
| (PID) Process: | (116) CrystalDiskMark8_0_5.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (116) CrystalDiskMark8_0_5.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Program Files\CrystalDiskMark8\CdmResource\DiskSpd\DiskSpd64.exe | |||
| (PID) Process: | (116) CrystalDiskMark8_0_5.tmp | Key: | HKEY_CURRENT_USER\SOFTWARE\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFilesHash |
Value: 8B75EDE3F5C489A4A0D95E34A685D87B88F42FE9BC360A2F53A45DB75BCEF212 | |||
| (PID) Process: | (116) CrystalDiskMark8_0_5.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CrystalDiskMark8_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 6.2.1 | |||
| (PID) Process: | (116) CrystalDiskMark8_0_5.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CrystalDiskMark8_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Program Files\CrystalDiskMark8 | |||
| (PID) Process: | (116) CrystalDiskMark8_0_5.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CrystalDiskMark8_is1 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\CrystalDiskMark8\ | |||
| (PID) Process: | (116) CrystalDiskMark8_0_5.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CrystalDiskMark8_is1 |
| Operation: | write | Name: | Inno Setup: Icon Group |
Value: CrystalDiskMark8 | |||
| (PID) Process: | (116) CrystalDiskMark8_0_5.tmp | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\CrystalDiskMark8_is1 |
| Operation: | write | Name: | Inno Setup: User |
Value: admin | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 5460 | CrystalDiskMark8_0_5.exe | C:\Users\admin\AppData\Local\Temp\is-HGA5I.tmp\CrystalDiskMark8_0_5.tmp | executable | |
MD5:A3933043F8DF7802921412E710B11FC7 | SHA256:B1F111A519D8A94E68BF9DEC3DAFE537C5D97ED941E0B932853FC23CE7390E08 | |||
| 116 | CrystalDiskMark8_0_5.tmp | C:\Program Files\CrystalDiskMark8\CdmResource\language\is-C7OBE.tmp | text | |
MD5:F961F7CAD586794DA0CFDB56C4DB467B | SHA256:A85BEB0DFD32347CFEAD6642536C6026138E2F92D9908609756894B4313F85C5 | |||
| 116 | CrystalDiskMark8_0_5.tmp | C:\Users\admin\AppData\Local\Temp\is-DQN68.tmp\_isetup\_setup64.tmp | executable | |
MD5:E4211D6D009757C078A9FAC7FF4F03D4 | SHA256:388A796580234EFC95F3B1C70AD4CB44BFDDC7BA0F9203BF4902B9929B136F95 | |||
| 116 | CrystalDiskMark8_0_5.tmp | C:\Program Files\CrystalDiskMark8\unins000.exe | executable | |
MD5:A3933043F8DF7802921412E710B11FC7 | SHA256:B1F111A519D8A94E68BF9DEC3DAFE537C5D97ED941E0B932853FC23CE7390E08 | |||
| 116 | CrystalDiskMark8_0_5.tmp | C:\Program Files\CrystalDiskMark8\is-97FVT.tmp | executable | |
MD5:A3933043F8DF7802921412E710B11FC7 | SHA256:B1F111A519D8A94E68BF9DEC3DAFE537C5D97ED941E0B932853FC23CE7390E08 | |||
| 1916 | CrystalDiskMark8_0_5.exe | C:\Users\admin\AppData\Local\Temp\is-ST99C.tmp\CrystalDiskMark8_0_5.tmp | executable | |
MD5:A3933043F8DF7802921412E710B11FC7 | SHA256:B1F111A519D8A94E68BF9DEC3DAFE537C5D97ED941E0B932853FC23CE7390E08 | |||
| 116 | CrystalDiskMark8_0_5.tmp | C:\Program Files\CrystalDiskMark8\CdmResource\language\is-HOFSM.tmp | text | |
MD5:F041610EDE5C657FF3C8AF49E5B7D677 | SHA256:5AD05A9E5B299FB59C222644A40368F798FB480785DA9791A94731420839BEEA | |||
| 116 | CrystalDiskMark8_0_5.tmp | C:\Program Files\CrystalDiskMark8\CdmResource\language\Arabic.lang | text | |
MD5:F961F7CAD586794DA0CFDB56C4DB467B | SHA256:A85BEB0DFD32347CFEAD6642536C6026138E2F92D9908609756894B4313F85C5 | |||
| 116 | CrystalDiskMark8_0_5.tmp | C:\Program Files\CrystalDiskMark8\CdmResource\language\is-8U7TE.tmp | text | |
MD5:49C1A9511919BA9ABBB80BA95D341961 | SHA256:52738BBE3026767E63E734D5EEA79ABFAE1DCB617DE4501A4B1033E8FECACC0D | |||
| 116 | CrystalDiskMark8_0_5.tmp | C:\Program Files\CrystalDiskMark8\CdmResource\language\Armenian.lang | text | |
MD5:49C1A9511919BA9ABBB80BA95D341961 | SHA256:52738BBE3026767E63E734D5EEA79ABFAE1DCB617DE4501A4B1033E8FECACC0D | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
5084 | svchost.exe | GET | 200 | 23.48.23.143:80 | http://crl.microsoft.com/pki/crl/products/MicRooCerAut2011_2011_03_22.crl | unknown | — | — | unknown |
5084 | svchost.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/MicSecSerCA2011_2011-10-18.crl | unknown | — | — | unknown |
3040 | OfficeClickToRun.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEApDqVCbATUviZV57HIIulA%3D | unknown | — | — | unknown |
4980 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Product%20Root%20Certificate%20Authority%202018.crl | unknown | — | — | unknown |
4980 | SIHClient.exe | GET | 200 | 184.30.21.171:80 | http://www.microsoft.com/pkiops/crl/Microsoft%20ECC%20Update%20Secure%20Server%20CA%202.1.crl | unknown | — | — | unknown |
5904 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | unknown |
4656 | SearchApp.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAI5PUjXAkJafLQcAAsO18o%3D | unknown | — | — | unknown |
1544 | svchost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | unknown |
6708 | firefox.exe | GET | 200 | 34.107.221.82:80 | http://detectportal.firefox.com/canonical.html | unknown | — | — | unknown |
2488 | backgroundTaskHost.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQ50otx%2Fh0Ztl%2Bz8SiPI7wEWVxDlQQUTiJUIBiV5uNu5g%2F6%2BrkS7QYXjzkCEAn5bsKVVV8kdJ6vHl3O1J0%3D | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
5084 | svchost.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
2672 | RUXIMICS.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
5784 | MoUsoCoreWorker.exe | 51.124.78.146:443 | settings-win.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | NL | whitelisted |
4656 | SearchApp.exe | 104.126.37.177:443 | — | Akamai International B.V. | DE | unknown |
4032 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
5084 | svchost.exe | 23.48.23.143:80 | crl.microsoft.com | Akamai International B.V. | DE | unknown |
5084 | svchost.exe | 184.30.21.171:80 | www.microsoft.com | AKAMAI-AS | DE | unknown |
3040 | OfficeClickToRun.exe | 20.42.65.90:443 | self.events.data.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
3040 | OfficeClickToRun.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
settings-win.data.microsoft.com |
| whitelisted |
crl.microsoft.com |
| whitelisted |
www.microsoft.com |
| whitelisted |
self.events.data.microsoft.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
crystalmark.info |
| whitelisted |
edge.microsoft.com |
| whitelisted |
edge-mobile-static.azureedge.net |
| unknown |
business.bing.com |
| whitelisted |