| download: | mail.exe |
| Full analysis: | https://app.any.run/tasks/fccddc78-effa-4132-bcbd-881b74bf1173 |
| Verdict: | Malicious activity |
| Analysis date: | March 21, 2019, 15:31:57 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows |
| MD5: | 4ED3D1E96628A31DCED4A04A3F2E7AB1 |
| SHA1: | A19915DCDC8F81E24CD2C80AA6F4A94DF525EA4A |
| SHA256: | E7456269063FB02ED13722FE583F2A9DF6EB3DDC3438A7F63F817E22701AFEE3 |
| SSDEEP: | 786432:oLAC6Dk6XMz/kdg6VIk9agHhkFDKcIIZv1qAbrP+o18:osC6XMzurVl9NHhcKcboAb6t |
| .exe | | | Win32 Executable (generic) (52.9) |
|---|---|---|
| .exe | | | Generic Win/DOS Executable (23.5) |
| .exe | | | DOS Executable Generic (23.5) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2019:03:04 10:33:26+01:00 |
| PEType: | PE32 |
| LinkerVersion: | 14 |
| CodeSize: | 10752 |
| InitializedDataSize: | 29684736 |
| UninitializedDataSize: | - |
| EntryPoint: | 0x2329 |
| OSVersion: | 5.1 |
| ImageVersion: | - |
| SubsystemVersion: | 5.1 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 4.12.2.1001 |
| ProductVersionNumber: | 4.12.2.1001 |
| FileFlagsMask: | 0x0017 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | NetEase(Hangzhou) Network Co. Ltd. |
| FileDescription: | 网易邮箱大师安装程序 |
| FileVersion: | 4.12.2.1001 |
| InternalName: | mini_installer |
| LegalCopyright: | Copyright (C) 2019 NetEase. All rights reserved. |
| ProductName: | 网易邮箱大师安装程序 |
| ProductVersion: | 4.12.2.1001 |
| CompanyShortName: | NetEase |
| ProductShortName: | 网易邮箱大师安装程序 |
| OfficialBuild: | - |
| Architecture: | IMAGE_FILE_MACHINE_I386 |
|---|---|
| Subsystem: | IMAGE_SUBSYSTEM_WINDOWS_GUI |
| Compilation Date: | 04-Mar-2019 09:33:26 |
| Detected languages: |
|
| Debug artifacts: |
|
| CompanyName: | NetEase(Hangzhou) Network Co. Ltd. |
| FileDescription: | 网易邮箱大师安装程序 |
| FileVersion: | 4.12.2.1001 |
| InternalName: | mini_installer |
| LegalCopyright: | Copyright (C) 2019 NetEase. All rights reserved. |
| ProductName: | 网易邮箱大师安装程序 |
| ProductVersion: | 4.12.2.1001 |
| CompanyShortName: | NetEase |
| ProductShortName: | 网易邮箱大师安装程序 |
| Official Build: | 0 |
| Magic number: | MZ |
|---|---|
| Bytes on last page of file: | 0x0090 |
| Pages in file: | 0x0003 |
| Relocations: | 0x0000 |
| Size of header: | 0x0004 |
| Min extra paragraphs: | 0x0000 |
| Max extra paragraphs: | 0xFFFF |
| Initial SS value: | 0x0000 |
| Initial SP value: | 0x00B8 |
| Checksum: | 0x0000 |
| Initial IP value: | 0x0000 |
| Initial CS value: | 0x0000 |
| Overlay number: | 0x0000 |
| OEM identifier: | 0x0000 |
| OEM information: | 0x0000 |
| Address of NE header: | 0x000000E8 |
| Signature: | PE |
|---|---|
| Machine: | IMAGE_FILE_MACHINE_I386 |
| Number of sections: | 6 |
| Time date stamp: | 04-Mar-2019 09:33:26 |
| Pointer to Symbol Table: | 0x00000000 |
| Number of symbols: | 0 |
| Size of Optional Header: | 0x00E0 |
| Characteristics: |
|
Name | Virtual Address | Virtual Size | Raw Size | Charateristics | Entropy |
|---|---|---|---|---|---|
.text | 0x00001000 | 0x000029C0 | 0x00002A00 | IMAGE_SCN_CNT_CODE, IMAGE_SCN_MEM_EXECUTE, IMAGE_SCN_MEM_READ | 6.05921 |
.data | 0x00004000 | 0x0000035C | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ, IMAGE_SCN_MEM_WRITE | 0.220113 |
.idata | 0x00005000 | 0x00000670 | 0x00000800 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 4.41893 |
.gfids | 0x00006000 | 0x00000004 | 0x00000200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 0.0203931 |
.rsrc | 0x00007000 | 0x01C4E130 | 0x01C4E200 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_READ | 7.99955 |
.reloc | 0x01C56000 | 0x00000258 | 0x00000400 | IMAGE_SCN_CNT_INITIALIZED_DATA, IMAGE_SCN_MEM_DISCARDABLE, IMAGE_SCN_MEM_READ | 4.56314 |
Title | Entropy | Size | Codepage | Language | Type |
|---|---|---|---|---|---|
1 | 5.30502 | 1003 | UNKNOWN | English - United States | RT_MANIFEST |
2 | 4.27613 | 2216 | UNKNOWN | English - United States | RT_ICON |
3 | 3.07864 | 1384 | UNKNOWN | English - United States | RT_ICON |
4 | 7.95961 | 15986 | UNKNOWN | English - United States | RT_ICON |
5 | 4.37789 | 38056 | UNKNOWN | English - United States | RT_ICON |
6 | 4.43517 | 26600 | UNKNOWN | English - United States | RT_ICON |
7 | 4.44045 | 21640 | UNKNOWN | English - United States | RT_ICON |
8 | 4.46174 | 16936 | UNKNOWN | English - United States | RT_ICON |
9 | 4.65933 | 9640 | UNKNOWN | English - United States | RT_ICON |
10 | 4.8588 | 4264 | UNKNOWN | English - United States | RT_ICON |
ADVAPI32.dll |
KERNEL32.dll |
SHELL32.dll (delay-loaded) |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 428 | "C:\Program Files\Netease\MailMaster\Application\mailmaster.exe" --type=utility --channel="2240.0.469226891\1185698437" --lang=en-US --no-sandbox --lang=zh-CN --log-file="C:\Users\admin\AppData\Local\Netease\MailMaster\logs\web.log" --product-version="Chrome/49.0.2623.110 MailMasterPC/4.12.2.1001" /prefetch:8 | C:\Program Files\Netease\MailMaster\Application\mailmaster.exe | mailmaster.exe | ||||||||||||
User: admin Company: NetEase(Hangzhou) Network Co. Ltd. Integrity Level: MEDIUM Description: 网易邮箱大师 Exit code: 0 Version: 4.12.2.1001 Modules
| |||||||||||||||
| 872 | C:\Windows\system32\svchost.exe -k netsvcs | C:\Windows\System32\svchost.exe | services.exe | ||||||||||||
User: SYSTEM Company: Microsoft Corporation Integrity Level: SYSTEM Description: Host Process for Windows Services Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1588 | "C:\Users\admin\AppData\Local\Temp\CR_0DD30.tmp\setup.exe" --install-archive="C:\Users\admin\AppData\Local\Temp\CR_0DD30.tmp\MAILMASTER.PACKED.7Z" --verbose-logging --mini_installer="C:\Users\admin\AppData\Local\Temp\mail.exe" --run-as-admin --system-level | C:\Users\admin\AppData\Local\Temp\CR_0DD30.tmp\setup.exe | setup.exe | ||||||||||||
User: admin Company: NetEase(Hangzhou) Network Co. Ltd. Integrity Level: HIGH Description: 网易邮箱大师安装程序 Exit code: 62 Version: 4.12.2.1001 Modules
| |||||||||||||||
| 1624 | "C:\Users\admin\AppData\Local\Temp\CR_0DD30.tmp\setup.exe" --install-archive="C:\Users\admin\AppData\Local\Temp\CR_0DD30.tmp\MAILMASTER.PACKED.7Z" --verbose-logging --mini_installer="C:\Users\admin\AppData\Local\Temp\mail.exe" | C:\Users\admin\AppData\Local\Temp\CR_0DD30.tmp\setup.exe | mail.exe | ||||||||||||
User: admin Company: NetEase(Hangzhou) Network Co. Ltd. Integrity Level: MEDIUM Description: 网易邮箱大师安装程序 Exit code: 0 Version: 4.12.2.1001 Modules
| |||||||||||||||
| 2240 | "C:\Program Files\Netease\MailMaster\Application\mailmaster.exe" --setup-first-run | C:\Program Files\Netease\MailMaster\Application\mailmaster.exe | setup.exe | ||||||||||||
User: admin Company: NetEase(Hangzhou) Network Co. Ltd. Integrity Level: MEDIUM Description: 网易邮箱大师 Exit code: 0 Version: 4.12.2.1001 Modules
| |||||||||||||||
| 3936 | "C:\Users\admin\AppData\Local\Temp\mail.exe" | C:\Users\admin\AppData\Local\Temp\mail.exe | explorer.exe | ||||||||||||
User: admin Company: NetEase(Hangzhou) Network Co. Ltd. Integrity Level: MEDIUM Description: 网易邮箱大师安装程序 Exit code: 0 Version: 4.12.2.1001 Modules
| |||||||||||||||
| (PID) Process: | (1624) setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 0 | |||
| (PID) Process: | (1624) setup.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 1 | |||
| (PID) Process: | (872) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1302019708-1500728564-335382590-1000 |
| Operation: | write | Name: | RefCount |
Value: 3 | |||
| (PID) Process: | (872) svchost.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows NT\CurrentVersion\ProfileList\S-1-5-21-1302019708-1500728564-335382590-1000 |
| Operation: | write | Name: | RefCount |
Value: 2 | |||
| (PID) Process: | (1588) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Netease\Mailmaster\Update\ClientState\{5B513460-F99B-4E9C-93EE-22F86FE2B1A8} |
| Operation: | write | Name: | UninstallString |
Value: C:\Program Files\Netease\MailMaster\Application\4.12.2.1001\Installer\setup.exe | |||
| (PID) Process: | (1588) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Netease\Mailmaster\Update\ClientState\{5B513460-F99B-4E9C-93EE-22F86FE2B1A8} |
| Operation: | write | Name: | UninstallArguments |
Value: --uninstall --verbose-logging --system-level --verbose-logging | |||
| (PID) Process: | (1588) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MailMaster |
| Operation: | write | Name: | DisplayName |
Value: 网易邮箱大师 | |||
| (PID) Process: | (1588) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MailMaster |
| Operation: | write | Name: | UninstallString |
Value: "C:\Program Files\Netease\MailMaster\Application\4.12.2.1001\Installer\setup.exe" --uninstall --verbose-logging --system-level --verbose-logging | |||
| (PID) Process: | (1588) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MailMaster |
| Operation: | write | Name: | InstallLocation |
Value: C:\Program Files\Netease\MailMaster\Application | |||
| (PID) Process: | (1588) setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Uninstall\MailMaster |
| Operation: | write | Name: | DisplayIcon |
Value: C:\Program Files\Netease\MailMaster\Application\mailmaster.exe,0 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 3936 | mail.exe | C:\Users\admin\AppData\Local\Temp\CR_0DD30.tmp\MAILMASTER.PACKED.7Z | — | |
MD5:— | SHA256:— | |||
| 3936 | mail.exe | C:\Users\admin\AppData\Local\Temp\CR_0DD30.tmp\SETUP.EX_ | — | |
MD5:— | SHA256:— | |||
| 1588 | setup.exe | C:\Program Files\Netease\MailMaster\Temp\source1588_22085\mailmaster.7z | — | |
MD5:— | SHA256:— | |||
| 1588 | setup.exe | C:\Program Files\Netease\MailMaster\Temp\source1588_22085\MailMaster-bin\4.12.2.1001\icudtl.dat | — | |
MD5:— | SHA256:— | |||
| 1588 | setup.exe | C:\Program Files\Netease\MailMaster\Temp\source1588_22085\MailMaster-bin\4.12.2.1001\libcef.dll | — | |
MD5:— | SHA256:— | |||
| 3936 | mail.exe | C:\Users\admin\AppData\Local\Temp\CR_0DD30.tmp\setup.exe | executable | |
MD5:— | SHA256:— | |||
| 1588 | setup.exe | C:\Program Files\Netease\MailMaster\Temp\source1588_22085\MailMaster-bin\4.12.2.1001\libegl.dll | executable | |
MD5:— | SHA256:— | |||
| 1588 | setup.exe | C:\Program Files\Netease\MailMaster\Temp\source1588_22085\MailMaster-bin\4.12.2.1001\d3dcompiler_47.dll | executable | |
MD5:8D5695F0B0A0330FE07802E4F3576B15 | SHA256:A3A79C73A56E0C0E192E3A8FAE32EEAA1F9F0F7B42FA86C92B6A737196D261C4 | |||
| 1588 | setup.exe | C:\Program Files\Netease\MailMaster\Temp\source1588_22085\MailMaster-bin\4.12.2.1001\data\translation.bin | binary | |
MD5:15F6F21869DBA8414B14A0BAEC7FCCFC | SHA256:9CAB6B0925E4F79CB5ABBE0A741D99C1724FAD6EDC514661CDECBC9C48AD9E8A | |||
| 872 | svchost.exe | C:\Windows\appcompat\programs\RecentFileCache.bcf | txt | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2240 | mailmaster.exe | GET | — | 123.58.182.105:80 | http://update.client.163.com/apptrack/confinfo/searchbyappid.do?appid=10&appver=4.12.2 | CN | — | — | whitelisted |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
2240 | mailmaster.exe | 103.129.252.32:9800 | lbs.client.163.com | — | — | unknown |
2240 | mailmaster.exe | 123.125.50.97:443 | appconf.mail.163.com | China Unicom Beijing Province Network | CN | unknown |
2240 | mailmaster.exe | 123.58.182.105:80 | client.mail.163.com | Guangzhou NetEase Computer System Co., Ltd. | CN | unknown |
2240 | mailmaster.exe | 103.129.252.31:9800 | lbs.client.163.com | — | — | unknown |
2240 | mailmaster.exe | 103.129.252.31:8080 | lbs.client.163.com | — | — | unknown |
2240 | mailmaster.exe | 123.58.182.103:443 | client.mail.163.com | Guangzhou NetEase Computer System Co., Ltd. | CN | unknown |
Domain | IP | Reputation |
|---|---|---|
lbs.client.163.com |
| unknown |
client.mail.163.com |
| unknown |
update.client.163.com |
| whitelisted |
appconf.mail.163.com |
| malicious |
PID | Process | Class | Message |
|---|---|---|---|
2240 | mailmaster.exe | Generic Protocol Command Decode | SURICATA STREAM CLOSEWAIT FIN out of window |
Process | Message |
|---|---|
setup.exe | [1624:1016:0321/153333:1037625:VERBOSE1:setup_main.cpp(109)] Command Line: "C:\Users\admin\AppData\Local\Temp\CR_0DD30.tmp\setup.exe" --install-archive="C:\Users\admin\AppData\Local\Temp\CR_0DD30.tmp\MAILMASTER.PACKED.7Z" --verbose-logging --mini_installer="C:\Users\admin\AppData\Local\Temp\mail.exe"
|
setup.exe | [1624:1016:0321/153333:1037625:VERBOSE1:install_util.cpp(169)] Windows NT 6.1 SP1
|
setup.exe | [1588:888:0321/153334:1038671:VERBOSE1:setup_main.cpp(109)] Command Line: "C:\Users\admin\AppData\Local\Temp\CR_0DD30.tmp\setup.exe" --install-archive="C:\Users\admin\AppData\Local\Temp\CR_0DD30.tmp\MAILMASTER.PACKED.7Z" --verbose-logging --mini_installer="C:\Users\admin\AppData\Local\Temp\mail.exe" --run-as-admin --system-level
|
setup.exe | [1588:888:0321/153334:1038671:VERBOSE1:install_util.cpp(169)] Windows NT 6.1 SP1
|
setup.exe | [1588:888:0321/153334:1038671:INFO:install_service.cpp(163)] Checking Install path: C:\Program Files\Neteasewith install type: 1(1.new 2.down 3.eq 4.up)
|
setup.exe | [1588:888:0321/153334:1038687:INFO:disk_util.cpp(33)] current path is match free space requirementC:\Program Files\Netease
|
setup.exe | [1588:888:0321/153334:1038687:INFO:install_service.cpp(168)] Disk space is enough to install: C:\Program Files\Netease
|
setup.exe | [1588:888:0321/153420:1084593:INFO:setup_window.cpp(219)] checking install path: C:\Program Files\Netease
|
setup.exe | [1588:2844:0321/153420:1084593:VERBOSE1:setup.cpp(662)] multi install is 0
|
setup.exe | [1588:2844:0321/153420:1084593:VERBOSE1:setup.cpp(665)] system install is 1
|