| File name: | CrystalDiskMark8_0_4c.exe |
| Full analysis: | https://app.any.run/tasks/dd457e20-2e0d-4c1f-a95f-073e25a2c1a4 |
| Verdict: | Malicious activity |
| Analysis date: | October 26, 2023, 04:17:33 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | E3B7F7B9B9A98070DC77DE312FD8E163 |
| SHA1: | 9EA824F5A97F69A8CA93A47E277DC3B330AA1769 |
| SHA256: | C50D45A19224DAFAF924BCD0380204904D7DF08706A978821FFDC0AB1A4FF840 |
| SSDEEP: | 49152:uBuZrEUDZHGxfDQlULC84TxPDNO3oSLUfqZ1RJq0Rw65ygFSRmbWm53sDZpnXKAS:okLQVF94nGCSR9wvdm5QXPVVoa |
| .exe | | | Inno Setup installer (67.7) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (25.6) |
| .exe | | | Win32 Executable (generic) (2.7) |
| .exe | | | Win16/32 Executable Delphi generic (1.2) |
| .exe | | | Generic Win/DOS Executable (1.2) |
| ProductVersion: | 8.0.4c |
|---|---|
| ProductName: | CrystalDiskMark 8.0.4c |
| OriginalFileName: | |
| LegalCopyright: | Crystal Dew World |
| FileVersion: | 8.0.4c |
| FileDescription: | CrystalDiskMark 8 Setup |
| CompanyName: | Crystal Dew World |
| Comments: | This installation was built with Inno Setup. |
| CharacterSet: | Unicode |
| LanguageCode: | Neutral |
| FileSubtype: | - |
| ObjectFileType: | Executable application |
| FileOS: | Win32 |
| FileFlags: | (none) |
| FileFlagsMask: | 0x003f |
| ProductVersionNumber: | 8.0.4.0 |
| FileVersionNumber: | 8.0.4.0 |
| Subsystem: | Windows GUI |
| SubsystemVersion: | 6 |
| ImageVersion: | 6 |
| OSVersion: | 6 |
| EntryPoint: | 0xb5eec |
| UninitializedDataSize: | - |
| InitializedDataSize: | 114688 |
| CodeSize: | 741888 |
| LinkerVersion: | 2.25 |
| PEType: | PE32 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| TimeStamp: | 2022:04:14 16:10:23+00:00 |
| MachineType: | Intel 386 or later, and compatibles |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 116 | "C:\Program Files\CrystalDiskMark8\CdmResource\diskspd\diskspd32L.exe" -b1024K -o8 -t1 -W0 -S -w0 -ag -d5 -A2980 -L "C:\CrystalDiskMark001F350B\CrystalDiskMark001F350B.tmp" | C:\Program Files\CrystalDiskMark8\CdmResource\DiskSpd\diskspd32L.exe | — | DiskMark32.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 10893770 Modules
| |||||||||||||||
| 680 | "C:\Program Files\CrystalDiskMark8\CdmResource\diskspd\diskspd32L.exe" -b1024K -o1 -t1 -W0 -S -w0 -ag -d5 -A2980 -L "C:\CrystalDiskMark001F350B\CrystalDiskMark001F350B.tmp" | C:\Program Files\CrystalDiskMark8\CdmResource\DiskSpd\diskspd32L.exe | — | DiskMark32.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 8988590 Modules
| |||||||||||||||
| 920 | "C:\Users\admin\AppData\Local\Temp\is-NAU1J.tmp\CrystalDiskMark8_0_4c.tmp" /SL5="$4036C,3159219,857600,C:\Users\admin\AppData\Local\Temp\CrystalDiskMark8_0_4c.exe" /SPAWNWND=$1800FA /NOTIFYWND=$110168 | C:\Users\admin\AppData\Local\Temp\is-NAU1J.tmp\CrystalDiskMark8_0_4c.tmp | — | CrystalDiskMark8_0_4c.exe | |||||||||||
User: admin Company: Crystal Dew World Integrity Level: HIGH Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 1736 | "C:\Program Files\CrystalDiskMark8\CdmResource\diskspd\diskspd32L.exe" -b1024K -o8 -t1 -W0 -S -w0 -ag -d5 -A2980 -L "C:\CrystalDiskMark001F350B\CrystalDiskMark001F350B.tmp" | C:\Program Files\CrystalDiskMark8\CdmResource\DiskSpd\diskspd32L.exe | — | DiskMark32.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 12272830 Modules
| |||||||||||||||
| 1796 | "C:\Users\admin\AppData\Local\Temp\CrystalDiskMark8_0_4c.exe" | C:\Users\admin\AppData\Local\Temp\CrystalDiskMark8_0_4c.exe | — | explorer.exe | |||||||||||
User: admin Company: Crystal Dew World Integrity Level: MEDIUM Description: CrystalDiskMark 8 Setup Exit code: 0 Version: 8.0.4c Modules
| |||||||||||||||
| 2268 | "C:\Program Files\CrystalDiskMark8\CdmResource\diskspd\diskspd32L.exe" -b1024K -o8 -t1 -W0 -S -w0 -ag -d5 -A2980 -L "C:\CrystalDiskMark001F350B\CrystalDiskMark001F350B.tmp" | C:\Program Files\CrystalDiskMark8\CdmResource\DiskSpd\diskspd32L.exe | — | DiskMark32.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 11360260 Modules
| |||||||||||||||
| 2332 | "C:\Program Files\CrystalDiskMark8\CdmResource\diskspd\diskspd32L.exe" -b1024K -o8 -t1 -W0 -S -w0 -ag -d5 -A2980 -L "C:\CrystalDiskMark001F350B\CrystalDiskMark001F350B.tmp" | C:\Program Files\CrystalDiskMark8\CdmResource\DiskSpd\diskspd32L.exe | — | DiskMark32.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 9776920 Modules
| |||||||||||||||
| 2640 | "C:\Program Files\CrystalDiskMark8\CdmResource\diskspd\diskspd32L.exe" -b1024K -o1 -t1 -W0 -S -w0 -ag -d5 -A2980 -L "C:\CrystalDiskMark001F350B\CrystalDiskMark001F350B.tmp" | C:\Program Files\CrystalDiskMark8\CdmResource\DiskSpd\diskspd32L.exe | — | DiskMark32.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2980 | "C:\Program Files\CrystalDiskMark8\DiskMark32.exe" | C:\Program Files\CrystalDiskMark8\DiskMark32.exe | — | CrystalDiskMark8_0_4c.tmp | |||||||||||
User: admin Company: Crystal Dew World Integrity Level: HIGH Description: CrystalDiskMark 8 Exit code: 0 Version: 8.0.4.0 Modules
| |||||||||||||||
| 3116 | "C:\Users\admin\AppData\Local\Temp\CrystalDiskMark8_0_4c.exe" /SPAWNWND=$1800FA /NOTIFYWND=$110168 | C:\Users\admin\AppData\Local\Temp\CrystalDiskMark8_0_4c.exe | CrystalDiskMark8_0_4c.tmp | ||||||||||||
User: admin Company: Crystal Dew World Integrity Level: HIGH Description: CrystalDiskMark 8 Setup Exit code: 0 Version: 8.0.4c Modules
| |||||||||||||||
| (PID) Process: | (920) CrystalDiskMark8_0_4c.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFilesHash |
Value: D14D5A05AFE346B065D7E94250FA531718D8E8872BA1FCF8330CCF8A3130AB9F | |||
| (PID) Process: | (920) CrystalDiskMark8_0_4c.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | RegFiles0000 |
Value: C:\Program Files\CrystalDiskMark8\CdmResource\DiskSpd\DiskSpd32.exe | |||
| (PID) Process: | (920) CrystalDiskMark8_0_4c.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (920) CrystalDiskMark8_0_4c.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | SessionHash |
Value: D24DE39051A6B9998F486D5B108FA8EE9D2DCB438F1D7FB1307BEAB458471549 | |||
| (PID) Process: | (920) CrystalDiskMark8_0_4c.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete value | Name: | Owner |
Value: 9803000052E1585EC307DA01 | |||
| (PID) Process: | (920) CrystalDiskMark8_0_4c.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | delete key | Name: | (default) |
Value: | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 920 | CrystalDiskMark8_0_4c.tmp | C:\Program Files\CrystalDiskMark8\CdmResource\language\Azeri.lang | text | |
MD5:B8D139490F731EC3C89BEA7380AD42DC | SHA256:CC6807E7C49D342173D4D099DB86B89915538F8950735FC46A0FD9878897672B | |||
| 1796 | CrystalDiskMark8_0_4c.exe | C:\Users\admin\AppData\Local\Temp\is-JG7MU.tmp\CrystalDiskMark8_0_4c.tmp | executable | |
MD5:AC11BBC885637CDF05D351AF6906BFCD | SHA256:CB71DBFFE2622A1CB742B311CD9752EE377CE3942FB5EC093AC91784839B85D9 | |||
| 920 | CrystalDiskMark8_0_4c.tmp | C:\Program Files\CrystalDiskMark8\CdmResource\language\is-8PJF0.tmp | text | |
MD5:B8D139490F731EC3C89BEA7380AD42DC | SHA256:CC6807E7C49D342173D4D099DB86B89915538F8950735FC46A0FD9878897672B | |||
| 920 | CrystalDiskMark8_0_4c.tmp | C:\Program Files\CrystalDiskMark8\is-08EQ0.tmp | executable | |
MD5:AC11BBC885637CDF05D351AF6906BFCD | SHA256:CB71DBFFE2622A1CB742B311CD9752EE377CE3942FB5EC093AC91784839B85D9 | |||
| 920 | CrystalDiskMark8_0_4c.tmp | C:\Program Files\CrystalDiskMark8\CdmResource\language\Arabic.lang | text | |
MD5:F961F7CAD586794DA0CFDB56C4DB467B | SHA256:A85BEB0DFD32347CFEAD6642536C6026138E2F92D9908609756894B4313F85C5 | |||
| 920 | CrystalDiskMark8_0_4c.tmp | C:\Program Files\CrystalDiskMark8\CdmResource\language\is-VQEVE.tmp | text | |
MD5:F961F7CAD586794DA0CFDB56C4DB467B | SHA256:A85BEB0DFD32347CFEAD6642536C6026138E2F92D9908609756894B4313F85C5 | |||
| 920 | CrystalDiskMark8_0_4c.tmp | C:\Program Files\CrystalDiskMark8\CdmResource\language\is-J2NOQ.tmp | text | |
MD5:12E1B050118F6BADC2A3AACF1D8E5146 | SHA256:45C55CEFD212440CC83AD650F4B67994E7B886BB2D96F7A9850BB293917C4E05 | |||
| 920 | CrystalDiskMark8_0_4c.tmp | C:\Program Files\CrystalDiskMark8\CdmResource\language\is-61J7O.tmp | text | |
MD5:F041610EDE5C657FF3C8AF49E5B7D677 | SHA256:5AD05A9E5B299FB59C222644A40368F798FB480785DA9791A94731420839BEEA | |||
| 920 | CrystalDiskMark8_0_4c.tmp | C:\Program Files\CrystalDiskMark8\CdmResource\language\is-REKI8.tmp | text | |
MD5:4E9E19261ECB0A00493888F2103B4E58 | SHA256:8ED1223292B24D4E5DE2E5BEA67B55FB1723EBF57967371B0BE986292FDA590E | |||
| 920 | CrystalDiskMark8_0_4c.tmp | C:\Program Files\CrystalDiskMark8\CdmResource\language\Bulgarian.lang | text | |
MD5:F041610EDE5C657FF3C8AF49E5B7D677 | SHA256:5AD05A9E5B299FB59C222644A40368F798FB480785DA9791A94731420839BEEA | |||
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2656 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |