File name: | epson657924eu.exe |
Full analysis: | https://app.any.run/tasks/151907ba-add8-46d7-80af-a5daefc30ae2 |
Verdict: | Malicious activity |
Analysis date: | March 31, 2024, 09:10:47 |
OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
Indicators: | |
MIME: | application/x-dosexec |
File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
MD5: | 03DC52C3D1E3E7A48D802C18C6986E7C |
SHA1: | D018B2FFD19917FA25C9AB37232ECE6997058EA7 |
SHA256: | DCC18B0C9B061DC8AE571A308EE0AC3101C71DA631C59DF3E51ADEE26A92973A |
SSDEEP: | 98304:MxN59OezcFkr8rI2SkQLo8+X3l6OiTekClYrmEp6Crn8H5zKJdmCNJH/9GwdoAeu:NsWai/5ESApAvx |
.exe | | | Win32 Executable MS Visual C++ (generic) (32.1) |
---|---|---|
.exe | | | Win64 Executable (generic) (28.5) |
.exe | | | Winzip Win32 self-extracting archive (generic) (23.7) |
.dll | | | Win32 Dynamic Link Library (generic) (6.7) |
.exe | | | Win32 Executable (generic) (4.6) |
MachineType: | Intel 386 or later, and compatibles |
---|---|
TimeStamp: | 2016:08:05 15:28:38+00:00 |
ImageFileCharacteristics: | No relocs, Executable, 32-bit |
PEType: | PE32 |
LinkerVersion: | 8 |
CodeSize: | 155648 |
InitializedDataSize: | 81920 |
UninitializedDataSize: | - |
EntryPoint: | 0x15fbf |
OSVersion: | 4 |
ImageVersion: | - |
SubsystemVersion: | 4 |
Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
984 | "C:\Program Files\Epson Software\Download Navigator\EPSDNMON.EXE" | C:\Program Files\Epson Software\Download Navigator\EPSDNMON.EXE | — | EPSDNAVI.EXE | |||||||||||
User: admin Company: Seiko Epson Corporation Integrity Level: MEDIUM Description: Epson Software Updater Version: 1.0.2.0 Modules
| |||||||||||||||
1888 | "C:\Windows\System32\msiexec.exe" /i "C:\Users\admin\AppData\Local\Temp\WZSE0.TMP\Data\Setup.msi"/qb | C:\Windows\System32\msiexec.exe | — | Setup.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Windows® installer Exit code: 0 Version: 5.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2292 | run=1 shortcut="C:\Users\admin\AppData\Local\Temp\epson657924eu.exe" | C:\Users\admin\AppData\Local\Temp\18243c\epson657924eu.exe | — | epson657924eu.exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
2340 | "C:\Users\admin\AppData\Local\Temp\epson657924eu.exe" | C:\Users\admin\AppData\Local\Temp\epson657924eu.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
2348 | "C:\Program Files\Epson Software\Download Navigator\EPSDNAVI.EXE" /FIRST | C:\Program Files\EPSON Software\Download Navigator\EPSDNAVI.EXE | Setup.exe | ||||||||||||
User: admin Company: Seiko Epson Corporation Integrity Level: MEDIUM Description: Epson Software Updater Exit code: 0 Version: 4.6.6.0 Modules
| |||||||||||||||
2408 | .\Data\Setup.exe | C:\Users\admin\AppData\Local\Temp\WZSE0.TMP\Data\Setup.exe | — | epson657924eu.exe | |||||||||||
User: admin Company: Seiko Epson Corporation Integrity Level: HIGH Description: Software Updater Installer Exit code: 2147483648 Version: 5.0.0 Modules
| |||||||||||||||
2596 | C:\Windows\system32\vssvc.exe | C:\Windows\System32\VSSVC.exe | — | services.exe | |||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Microsoft® Volume Shadow Copy Service Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
2672 | "C:\Users\admin\AppData\Local\Temp\WZSE0.TMP\Data\EPSDNEUL.EXE" /LO:"7" | C:\Users\admin\AppData\Local\Temp\WZSE0.TMP\Data\EPSDNEUL.EXE | — | Setup.exe | |||||||||||
User: admin Company: Seiko Epson Corporation Integrity Level: HIGH Description: Epson EULA Navi for x86 Exit code: 67698688 Version: 1.0.9.3 Modules
| |||||||||||||||
4044 | "C:\Users\admin\AppData\Local\Temp\epson657924eu.exe" | C:\Users\admin\AppData\Local\Temp\epson657924eu.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
|
(PID) Process: | (2408) Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (2408) Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (2408) Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (2408) Setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (2672) EPSDNEUL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
(PID) Process: | (2672) EPSDNEUL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | IntranetName |
Value: 1 | |||
(PID) Process: | (2672) EPSDNEUL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
(PID) Process: | (2672) EPSDNEUL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
Operation: | write | Name: | AutoDetect |
Value: 0 | |||
(PID) Process: | (2672) EPSDNEUL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Content |
Operation: | write | Name: | CachePrefix |
Value: | |||
(PID) Process: | (2672) EPSDNEUL.EXE | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\5.0\Cache\Cookies |
Operation: | write | Name: | CachePrefix |
Value: Cookie: |
PID | Process | Filename | Type | |
---|---|---|---|---|
4044 | epson657924eu.exe | C:\Users\admin\AppData\Local\Temp\18243c\epson657924eu.exe | executable | |
MD5:— | SHA256:— | |||
2292 | epson657924eu.exe | C:\Users\admin\AppData\Local\Temp\WZSE0.TMP\Data\EPSDNEUL.EXE | executable | |
MD5:— | SHA256:— | |||
2292 | epson657924eu.exe | C:\Users\admin\AppData\Local\Temp\WZSE0.TMP\Data\Setup.exe | executable | |
MD5:— | SHA256:— | |||
2292 | epson657924eu.exe | C:\Users\admin\AppData\Local\Temp\WZSE0.TMP\Data\Setup.msi | — | |
MD5:— | SHA256:— | |||
2292 | epson657924eu.exe | C:\Users\admin\AppData\Local\Temp\WZSE0.TMP\Data\VERINFO.ESI | text | |
MD5:— | SHA256:— | |||
2348 | EPSDNAVI.EXE | C:\ProgramData\EPSON\SoftwareUpdater\EPSDNMON.dat | text | |
MD5:— | SHA256:— |
PID | Process | IP | Domain | ASN | CN | Reputation |
---|---|---|---|---|---|---|
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
— | — | 224.0.0.252:5355 | — | — | — | unknown |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |