| File name: | taskbarsystem.exe |
| Full analysis: | https://app.any.run/tasks/7c4ba659-ab23-46ca-85e8-6bf32cdb1ea1 |
| Verdict: | Malicious activity |
| Analysis date: | May 06, 2024, 04:40:51 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 271C0218165E4BE1872C5501D26BFBE5 |
| SHA1: | 344C9253B66C6FF706AB2640F5E3D709F3E94FB4 |
| SHA256: | DB19E6A6BBB3D65B550CCA9367744625F8BFBFA0E51276495E2509B9F491616D |
| SSDEEP: | 98304:CkLXNU62Ejo44/aY6Nc0to0f/R4vjUbyXNjSpnqu8DeM5aW4kiXyGA:NXq62EMT6Nc0to0fCgGEpngDHS5Xw |
| .exe | | | Inno Setup installer (67.7) |
|---|---|---|
| .exe | | | Win32 EXE PECompact compressed (generic) (25.6) |
| .exe | | | Win32 Executable (generic) (2.7) |
| .exe | | | Win16/32 Executable Delphi generic (1.2) |
| .exe | | | Generic Win/DOS Executable (1.2) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2022:04:14 16:10:23+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, Bytes reversed lo, 32-bit, Bytes reversed hi |
| PEType: | PE32 |
| LinkerVersion: | 2.25 |
| CodeSize: | 741888 |
| InitializedDataSize: | 318976 |
| UninitializedDataSize: | - |
| EntryPoint: | 0xb5eec |
| OSVersion: | 6.1 |
| ImageVersion: | 6 |
| SubsystemVersion: | 6.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.0.5.0 |
| ProductVersionNumber: | 1.0.5.0 |
| FileFlagsMask: | 0x003f |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | Neutral |
| CharacterSet: | Unicode |
| Comments: | This installation was built with Inno Setup. |
| CompanyName: | Taskbar system |
| FileDescription: | Taskbar system Setup |
| FileVersion: | 1.0.5.0 |
| LegalCopyright: | Copyright © 2022 Taskbar system |
| OriginalFileName: | |
| ProductName: | Taskbar system |
| ProductVersion: | 1.0.5.0 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 3984 | "C:\Users\admin\AppData\Local\Temp\taskbarsystem.exe" | C:\Users\admin\AppData\Local\Temp\taskbarsystem.exe | explorer.exe | ||||||||||||
User: admin Company: Taskbar system Integrity Level: MEDIUM Description: Taskbar system Setup Exit code: 0 Version: 1.0.5.0 Modules
| |||||||||||||||
| 4000 | "C:\Users\admin\AppData\Local\Temp\is-7DVHO.tmp\taskbarsystem.tmp" /SL5="$20138,5047757,1061888,C:\Users\admin\AppData\Local\Temp\taskbarsystem.exe" | C:\Users\admin\AppData\Local\Temp\is-7DVHO.tmp\taskbarsystem.tmp | taskbarsystem.exe | ||||||||||||
User: admin Company: Taskbar system Integrity Level: MEDIUM Description: Setup/Uninstall Exit code: 0 Version: 51.1052.0.0 Modules
| |||||||||||||||
| 4048 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 4072 | "C:\Users\admin\AppData\Local\Programs\TaskbarSystem\TaskbarSystem.exe" | C:\Users\admin\AppData\Local\Programs\TaskbarSystem\TaskbarSystem.exe | taskbarsystem.tmp | ||||||||||||
User: admin Integrity Level: MEDIUM Description: Taskbar system Version: 1.0.5.0 Modules
| |||||||||||||||
| (PID) Process: | (4000) taskbarsystem.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Owner |
Value: A00F0000A6F296996F9FDA01 | |||
| (PID) Process: | (4000) taskbarsystem.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | SessionHash |
Value: 9939FB433AFF931E2CB6C3CF2900A80B2E883616A7037344CE315C3A19325A55 | |||
| (PID) Process: | (4000) taskbarsystem.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | Sequence |
Value: 1 | |||
| (PID) Process: | (4000) taskbarsystem.tmp | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (4000) taskbarsystem.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFiles0000 |
Value: C:\Users\admin\AppData\Local\Programs\TaskbarSystem\TaskbarSystem.exe | |||
| (PID) Process: | (4000) taskbarsystem.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\RestartManager\Session0000 |
| Operation: | write | Name: | RegFilesHash |
Value: 47959A06D5EE43B962E052C7955AE1C1ABB24CEEB930552FC31B6C33EF146EB7 | |||
| (PID) Process: | (4000) taskbarsystem.tmp | Key: | HKEY_CURRENT_USER\Software\AdjustTask |
| Operation: | write | Name: | version |
Value: 1.0.5.0 | |||
| (PID) Process: | (4000) taskbarsystem.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C40E1200-5BEC-410C-B3C5-F7B475729D42}_is1 |
| Operation: | write | Name: | Inno Setup: Setup Version |
Value: 6.2.1 | |||
| (PID) Process: | (4000) taskbarsystem.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C40E1200-5BEC-410C-B3C5-F7B475729D42}_is1 |
| Operation: | write | Name: | Inno Setup: App Path |
Value: C:\Users\admin\AppData\Local\Programs\TaskbarSystem | |||
| (PID) Process: | (4000) taskbarsystem.tmp | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Uninstall\{C40E1200-5BEC-410C-B3C5-F7B475729D42}_is1 |
| Operation: | write | Name: | InstallLocation |
Value: C:\Users\admin\AppData\Local\Programs\TaskbarSystem\ | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3984 | taskbarsystem.exe | C:\Users\admin\AppData\Local\Temp\is-7DVHO.tmp\taskbarsystem.tmp | executable | |
MD5:CFCA19D69366CFA8BBC1168A74FAA662 | SHA256:7520555F76AF79FD377EEE590EC51454999C276923A1BACF4B8E1B159BDC5DE6 | |||
| 4000 | taskbarsystem.tmp | C:\Users\admin\AppData\Local\Programs\TaskbarSystem\unins000.exe | executable | |
MD5:CFCA19D69366CFA8BBC1168A74FAA662 | SHA256:7520555F76AF79FD377EEE590EC51454999C276923A1BACF4B8E1B159BDC5DE6 | |||
| 4000 | taskbarsystem.tmp | C:\Users\admin\AppData\Local\Programs\TaskbarSystem\TaskbarSystem.exe | executable | |
MD5:EB0FC1BFCBC80673C26A530EB8CAC2DE | SHA256:D6D8EC28E53519D2D538A26CC5405B94C0D8B0206503C769E6CA49055A26A10F | |||
| 4000 | taskbarsystem.tmp | C:\Users\admin\AppData\Local\Programs\TaskbarSystem\sdk.dll | executable | |
MD5:C8BED0E17E74BE803562B4741429C7AB | SHA256:540D324F3719CC86FF523E294B65CCB2F27E2028321C24FB83B41D102EF2FAB6 | |||
| 4000 | taskbarsystem.tmp | C:\Users\admin\AppData\Local\Programs\TaskbarSystem\is-1LRUI.tmp | executable | |
MD5:C8BED0E17E74BE803562B4741429C7AB | SHA256:540D324F3719CC86FF523E294B65CCB2F27E2028321C24FB83B41D102EF2FAB6 | |||
| 4000 | taskbarsystem.tmp | C:\Users\admin\AppData\Local\Temp\Cab7E0B.tmp | compressed | |
MD5:29F65BA8E88C063813CC50A4EA544E93 | SHA256:1ED81FA8DFB6999A9FEDC6E779138FFD99568992E22D300ACD181A6D2C8DE184 | |||
| 4000 | taskbarsystem.tmp | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\Content\77EC63BDA74BD0D0E0426DC8F8008506 | compressed | |
MD5:29F65BA8E88C063813CC50A4EA544E93 | SHA256:1ED81FA8DFB6999A9FEDC6E779138FFD99568992E22D300ACD181A6D2C8DE184 | |||
| 4000 | taskbarsystem.tmp | C:\Users\admin\AppData\Local\Programs\TaskbarSystem\is-5SNC1.tmp | executable | |
MD5:35CBDBE6987B9951D3467DDA2F318F3C | SHA256:E4915F18FD6713EE84F27A06ED1F6F555CDBEBE1522792CF4B4961664550CF83 | |||
| 4000 | taskbarsystem.tmp | C:\Users\admin\AppData\LocalLow\Microsoft\CryptnetUrlCache\MetaData\77EC63BDA74BD0D0E0426DC8F8008506 | binary | |
MD5:693C89C1C31ADF9A882AF325E417ED84 | SHA256:359522798D67AE5436AB820FBBE813F697F2705B914CFBCC38884122D81804AB | |||
| 4000 | taskbarsystem.tmp | C:\Users\admin\AppData\Local\Temp\Tar7E0C.tmp | binary | |
MD5:435A9AC180383F9FA094131B173A2F7B | SHA256:67DC37ED50B8E63272B49A254A6039EE225974F1D767BB83EB1FD80E759A7C34 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
4000 | taskbarsystem.tmp | GET | 200 | 199.232.210.172:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?31d9d57bfb4c63d7 | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4000 | taskbarsystem.tmp | 188.114.96.3:443 | stats.taskbarsystem.com | CLOUDFLARENET | NL | unknown |
4000 | taskbarsystem.tmp | 199.232.210.172:80 | ctldl.windowsupdate.com | FASTLY | US | unknown |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4000 | taskbarsystem.tmp | 188.114.97.3:443 | stats.taskbarsystem.com | CLOUDFLARENET | NL | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4072 | TaskbarSystem.exe | 172.67.223.121:443 | zelotic.art | CLOUDFLARENET | US | unknown |
4072 | TaskbarSystem.exe | 188.114.96.3:443 | stats.taskbarsystem.com | CLOUDFLARENET | NL | unknown |
4072 | TaskbarSystem.exe | 104.16.123.96:443 | www.cloudflare.com | CLOUDFLARENET | — | unknown |
4072 | TaskbarSystem.exe | 104.16.61.8:443 | speed.cloudflare.com | CLOUDFLARENET | — | unknown |
4072 | TaskbarSystem.exe | 142.250.186.164:443 | www.google.com | GOOGLE | US | whitelisted |
Domain | IP | Reputation |
|---|---|---|
stats.taskbarsystem.com |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
track.taskbarsystem.com |
| unknown |
zelotic.art |
| unknown |
www.cloudflare.com |
| whitelisted |
speed.cloudflare.com |
| unknown |
www.google.com |
| whitelisted |