| File name: | UmsPassGuardEdge.exe |
| Full analysis: | https://app.any.run/tasks/bb0cd6ff-ac4d-4f40-bbf1-9ecaf3e7b58e |
| Verdict: | Malicious activity |
| Analysis date: | December 09, 2021, 09:50:26 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 765515091A17343C9F41081986DA78AB |
| SHA1: | C4A310A4C3FD48E329A3B74AB918204E5E8EDEA7 |
| SHA256: | C4EE79D4B9B114C4D6311F0E289890DAC8CCB049FFC84768281886C789A11B74 |
| SSDEEP: | 98304:fPpoSvGzspkxcIAdMTuIF/3lGBBEaJinodt5UQQQVVrahdYATR/I:XpolzspkxRAmyIF9OiodfGuVrahdYATW |
| .exe | | | NSIS - Nullsoft Scriptable Install System (91.9) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (3.3) |
| .exe | | | Win64 Executable (generic) (3) |
| .dll | | | Win32 Dynamic Link Library (generic) (0.7) |
| .exe | | | Win32 Executable (generic) (0.4) |
| ProductVersion: | 1.0.0.3 |
|---|---|
| ProductName: | 银联商务安全控件 |
| LegalCopyright: | (C) 2018 银联商务有限公司 所有权利保留 |
| FileVersion: | 1.0.0.3 |
| FileDescription: | 银联商务安全控件 |
| CompanyName: | 银联商务有限公司 |
| CharacterSet: | Windows, Chinese (Simplified) |
| LanguageCode: | Chinese (Simplified) |
| FileSubtype: | - |
| ObjectFileType: | Executable application |
| FileOS: | Win32 |
| FileFlags: | (none) |
| FileFlagsMask: | 0x0000 |
| ProductVersionNumber: | 1.0.0.3 |
| FileVersionNumber: | 1.0.0.3 |
| Subsystem: | Windows GUI |
| SubsystemVersion: | 4 |
| ImageVersion: | 6 |
| OSVersion: | 4 |
| EntryPoint: | 0x30b6 |
| UninitializedDataSize: | 1024 |
| InitializedDataSize: | 117760 |
| CodeSize: | 23552 |
| LinkerVersion: | 6 |
| PEType: | PE32 |
| TimeStamp: | 2014:05:11 22:03:30+02:00 |
| MachineType: | Intel 386 or later, and compatibles |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 11-May-2014 20:03:30 |
| Detected languages: |
|
| CompanyName: | 银联商务有限公司 |
| FileDescription: | 银联商务安全控件 |
| FileVersion: | 1.0.0.3 |
| LegalCopyright: | (C) 2018 银联商务有限公司 所有权利保留 |
| ProductName: | 银联商务安全控件 |
| ProductVersion: | 1.0.0.3 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000C8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 5 |
| Time date stamp: | 11-May-2014 20:03:30 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x00005A68 | 0x00005C00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.4187 |
.rdata | 0x00007000 | 0x000011CE | 0x00001200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 5.23558 |
.data | 0x00009000 | 0x0001A7B8 | 0x00000400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 4.87123 |
.ndata | 0x00024000 | 0x00011000 | 0x00000000 | IMAGE_SCN_CNT_UNINITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0 |
.rsrc | 0x00035000 | 0x00004E08 | 0x00005000 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 2.93872 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.26024 | 1013 | UNKNOWN | English - United States | RT_MANIFEST |
103 | 1.5789 | 20 | UNKNOWN | English - United States | RT_GROUP_ICON |
105 | 2.62576 | 492 | UNKNOWN | English - United States | RT_DIALOG |
106 | 2.86626 | 228 | UNKNOWN | English - United States | RT_DIALOG |
111 | 2.9304 | 218 | UNKNOWN | English - United States | RT_DIALOG |
ADVAPI32.dll |
COMCTL32.dll |
GDI32.dll |
KERNEL32.dll |
SHELL32.dll |
USER32.dll |
VERSION.dll |
ole32.dll |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 356 | "C:\Windows\system32\UmsPassGuardNew\UmsPassGuardXInputService.exe" "-install" | C:\Windows\system32\UmsPassGuardNew\UmsPassGuardXInputService.exe | — | UmsPassGuardEdge.exe | |||||||||||
User: admin Company: ???????? Integrity Level: HIGH Description: UmsPassGuardXInputService Exit code: 0 Version: 1.0.1.0 Modules
| |||||||||||||||
| 984 | C:\Windows\system32\UmsPassGuardNew\UmsPassGuardXInput.exe | C:\Windows\system32\UmsPassGuardNew\UmsPassGuardXInput.exe | UmsPassGuardEdge.exe | ||||||||||||
User: admin Company: ???????? Integrity Level: HIGH Description: ???????????? Exit code: 0 Version: 1.0.0.2 Modules
| |||||||||||||||
| 1296 | "C:\Users\admin\AppData\Local\Temp\certmgr.exe" -add "C:\Users\admin\AppData\Local\Temp\mysign.cer" -c -s -r localMachine CA | C:\Users\admin\AppData\Local\Temp\certmgr.exe | — | UmsPassGuardEdge.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2024 | C:\Windows\system32\schtasks.exe /delete /tn "��������ȫ�������" /f | C:\Windows\system32\schtasks.exe | — | UmsPassGuardXInput.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 1 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2596 | "C:\Users\admin\AppData\Local\Temp\UmsPassGuardEdge.exe" | C:\Users\admin\AppData\Local\Temp\UmsPassGuardEdge.exe | — | Explorer.EXE | |||||||||||
User: admin Company: ???????? Integrity Level: MEDIUM Description: ???????? Exit code: 3221226540 Version: 1.0.0.3 Modules
| |||||||||||||||
| 2652 | "C:\Windows\system32\UmsPassGuardNew\UmsPassGuardX.exe" "-s" | C:\Windows\system32\UmsPassGuardNew\UmsPassGuardX.exe | UmsPassGuardEdge.exe | ||||||||||||
User: admin Integrity Level: HIGH Description: UmsPassGuardX Application Exit code: 0 Version: 1.0.0.1 Modules
| |||||||||||||||
| 2764 | C:\Windows\system32\schtasks.exe /create /tn "��������ȫ�������" /tr "C:\Windows\system32\UmsPassGuardNew\UmsPassGuardXInput.exe" /sc onlogon | C:\Windows\system32\schtasks.exe | — | UmsPassGuardXInput.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Manages scheduled tasks Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2900 | "C:\Windows\system32\UmsPassGuardNew\UmsPassGuardXInputService.exe" "-control" "UmsPassGuardXInputService" "start" | C:\Windows\system32\UmsPassGuardNew\UmsPassGuardXInputService.exe | — | UmsPassGuardEdge.exe | |||||||||||
User: admin Company: ???????? Integrity Level: HIGH Description: UmsPassGuardXInputService Exit code: 0 Version: 1.0.1.0 Modules
| |||||||||||||||
| 3160 | "C:\Users\admin\AppData\Local\Temp\certmgr.exe" -add "C:\Users\admin\AppData\Local\Temp\wosign.cer" -c -s -r localMachine Root | C:\Users\admin\AppData\Local\Temp\certmgr.exe | — | UmsPassGuardEdge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: ECM Certificate Manager Exit code: 0 Version: 6.2.9200.16384 (win8_rtm.120725-1247) Modules
| |||||||||||||||
| 3520 | "C:\Users\admin\AppData\Local\Temp\UmsPassGuardEdge.exe" | C:\Users\admin\AppData\Local\Temp\UmsPassGuardEdge.exe | Explorer.EXE | ||||||||||||
User: admin Company: ???????? Integrity Level: HIGH Description: ???????? Exit code: 0 Version: 1.0.0.3 Modules
| |||||||||||||||
| (PID) Process: | (3520) UmsPassGuardEdge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (3520) UmsPassGuardEdge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (3520) UmsPassGuardEdge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (3520) UmsPassGuardEdge.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (3520) UmsPassGuardEdge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\��������ȫ�ؼ�Edge�� |
| Operation: | write | Name: | DisplayName |
Value: ��������ȫ�ؼ�Edge�� | |||
| (PID) Process: | (3520) UmsPassGuardEdge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\��������ȫ�ؼ�Edge�� |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Windows\system32\UmsPassGuardNew\uninst.exe | |||
| (PID) Process: | (3520) UmsPassGuardEdge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\��������ȫ�ؼ�Edge�� |
| Operation: | write | Name: | UninstallString |
Value: C:\Windows\system32\UmsPassGuardNew\uninst.exe | |||
| (PID) Process: | (3520) UmsPassGuardEdge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\��������ȫ�ؼ�Edge�� |
| Operation: | write | Name: | DisplayVersion |
Value: 1.0.0.3 | |||
| (PID) Process: | (3520) UmsPassGuardEdge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\��������ȫ�ؼ�Edge�� |
| Operation: | write | Name: | URLInfoAbout |
Value: | |||
| (PID) Process: | (3520) UmsPassGuardEdge.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\��������ȫ�ؼ�Edge�� |
| Operation: | write | Name: | Publisher |
Value: ������������˾ | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3520 | UmsPassGuardEdge.exe | C:\Users\admin\AppData\Local\Temp\nsaF0BD.tmp\modern-wizard.bmp | image | |
MD5:A957D699231F65542DC112950A31A09E | SHA256:86B35FE74FDCD0ECCB5E464EF9BBF115BEFD64815B1CA81477DA8E13343CE0FC | |||
| 3520 | UmsPassGuardEdge.exe | C:\Windows\system32\UmsPassGuardNew\UmsPassGuardX.exe | executable | |
MD5:CB20B2939DD5631965D79F10EA125136 | SHA256:9581F4A8D75EDC4C9AE41ECAECE73466CEB7D80640D3A1D581BF5EFF67B07427 | |||
| 3520 | UmsPassGuardEdge.exe | C:\Windows\system32\UmsPassGuardNew\UmsPassGuardXInput.exe | executable | |
MD5:906E31FD8C471B197BF6091EB7241952 | SHA256:B53F7EEFD78D20CE82A483075045D4BDAEB7669C16BD4FB4E0ABB33E2C34731E | |||
| 3852 | UmsPassGuardXInputService.exe | C:\Windows\system32\drivers\etc\hosts | text | |
MD5:BEF3035D4CB3502E13CF7FF434AC7F26 | SHA256:D14F79B6813F7855C249305CA79FE5F161528796C07E532EF685498B3AEC2B61 | |||
| 3520 | UmsPassGuardEdge.exe | C:\Users\admin\AppData\Local\Temp\nsaF0BD.tmp\modern-header.bmp | image | |
MD5:2BBA9B4ADAF0DE86CA4B56728F0676ED | SHA256:6D4927B8A6E2C2747F3B25AF1A2F8B0C10ECE75A484B8DA29D6D795654A39830 | |||
| 3520 | UmsPassGuardEdge.exe | C:\Users\admin\AppData\Local\Temp\nsaF0BD.tmp\killer.dll | executable | |
MD5:16205CD992D3B3827573F93AB8923E4E | SHA256:967D66F23CF3D9D3E5A4D6A9C6E366E792A98CC8A293196095B10CD82DA9A695 | |||
| 3520 | UmsPassGuardEdge.exe | C:\Users\admin\AppData\Local\Temp\nsaF0BD.tmp\System.dll | executable | |
MD5:A436DB0C473A087EB61FF5C53C34BA27 | SHA256:75ED40311875312617D6711BAED0BE29FCAEE71031CA27A8D308A72B15A51E49 | |||
| 3520 | UmsPassGuardEdge.exe | C:\Users\admin\AppData\Local\Temp\nsaF0BD.tmp\KillProcDLL.dll | executable | |
MD5:99F345CF51B6C3C317D20A81ACB11012 | SHA256:C2689BA1F66066AFCE85CA6457ECD36370BE0FE351C58422E45EFD0948655C93 | |||
| 3520 | UmsPassGuardEdge.exe | C:\Users\admin\AppData\Local\Temp\wosign.cer | der | |
MD5:252B7527E109B7320981A6FBA6CD1084 | SHA256:FB64C2459B8AE9851DBFFE57D03F9A5DFF98CDC0AD231391E4476868DDDFFF2F | |||
| 984 | UmsPassGuardXInput.exe | C:\Users\admin\AppData\Roaming\Mozilla\Firefox\Profiles\qldyz51w.default\cert_override.txt | text | |
MD5:410B2B692A7638D3503C9CF691CDBD53 | SHA256:9DA8B638DAC263EEB7F94493107597DC086B03E4442D322DC349F3CF55A7EEB1 | |||