| File name: | ePass2003India-Setup.exe |
| Full analysis: | https://app.any.run/tasks/78413ab7-7431-4d3d-89ca-ac596975ff24 |
| Verdict: | Malicious activity |
| Analysis date: | June 06, 2024, 10:51:51 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | F4DC957F0759B4EE14F9674EFB282DEF |
| SHA1: | C54A1E15907E6D8D3BFCDDAAB5B27BC2C8680BEB |
| SHA256: | F325A00690424DA1A2BC2589BB9C6AFDB0484486F1C72166285FF00214774527 |
| SSDEEP: | 98304:srlM5MSM0ny67XfqN3liH8tI79ioEQZrJCi5qGeXBG5OtPnSq2C249iwqax0vmzV:hty+UxH3 |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2009:01:28 19:42:35+00:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 25600 |
| InitializedDataSize: | 431104 |
| UninitializedDataSize: | 16896 |
| EntryPoint: | 0x33e0 |
| OSVersion: | 5 |
| ImageVersion: | - |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 1.1.18.701 |
| ProductVersionNumber: | 1.1.18.701 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Feitian |
| FileDescription: | Feitian Middleware (For ePass2003) |
| FileVersion: | 1.1.18.701 |
| LegalCopyright: | Copyright(C) 2018 Feitian |
| ProductName: | ePass2003 |
| ProductVersion: | 1.1.18.701 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 312 | "C:\Program Files\Internet Explorer\iexplore.exe" SCODEF:1292 CREDAT:275457 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 580 | "C:\Program Files\Windows Media Player\wmpnscfg.exe" | C:\Program Files\Windows Media Player\wmpnscfg.exe | — | explorer.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Windows Media Player Network Sharing Service Configuration Application Exit code: 0 Version: 12.0.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 1136 | "C:\Program Files\Feitian\ePass2003\FirefoxTCS.exe" | C:\Program Files\Feitian\ePass2003\FirefoxTCS.exe | ePass2003India-Setup.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1292 | "C:\Program Files\Internet Explorer\iexplore.exe" http://www.charteredinfo.com/DSC/TokenDrivers/Updates/ePass2003ChangeLog.html | C:\Program Files\Internet Explorer\iexplore.exe | ePass2003India-Setup.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 1432 | "C:\Program Files\Feitian\ePass2003\ePassCertd_2003.exe" | C:\Program Files\Feitian\ePass2003\ePassCertd_2003.exe | — | explorer.exe | |||||||||||
User: admin Company: Feitian Integrity Level: MEDIUM Description: certreg MFC Application Version: 1, 1, 18, 701 Modules
| |||||||||||||||
| 2036 | "C:\Program Files\Feitian\ePass2003\ThunderBirdTCS.exe" | C:\Program Files\Feitian\ePass2003\ThunderBirdTCS.exe | ePass2003India-Setup.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 2348 | "C:\Program Files\Feitian\ePass2003\ePassManager_2003.exe" | C:\Program Files\Feitian\ePass2003\ePassManager_2003.exe | explorer.exe | ||||||||||||
User: admin Company: Feitian Integrity Level: MEDIUM Description: Feitian PKI Manager Application Version: 1, 1, 18, 701 Modules
| |||||||||||||||
| 3976 | "C:\Users\admin\AppData\Local\Temp\ePass2003India-Setup.exe" | C:\Users\admin\AppData\Local\Temp\ePass2003India-Setup.exe | — | explorer.exe | |||||||||||
User: admin Company: Feitian Integrity Level: MEDIUM Description: Feitian Middleware (For ePass2003) Exit code: 3221226540 Version: 1.1.18.701 Modules
| |||||||||||||||
| 4088 | "C:\Users\admin\AppData\Local\Temp\ePass2003India-Setup.exe" | C:\Users\admin\AppData\Local\Temp\ePass2003India-Setup.exe | explorer.exe | ||||||||||||
User: admin Company: Feitian Integrity Level: HIGH Description: Feitian Middleware (For ePass2003) Exit code: 0 Version: 1.1.18.701 Modules
| |||||||||||||||
| (PID) Process: | (4088) ePass2003India-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Feitian\ePass2003 |
| Operation: | write | Name: | Path |
Value: C:\Program Files\Feitian\ePass2003 | |||
| (PID) Process: | (4088) ePass2003India-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Feitian\ePass2003 |
| Operation: | write | Name: | InstallLanguageId |
Value: 1033 | |||
| (PID) Process: | (4088) ePass2003India-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Feitian\ePass2003 |
| Operation: | write | Name: | Version |
Value: 110180701 | |||
| (PID) Process: | (4088) ePass2003India-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\EnterSafe ePass2003 CSP v2.0 |
| Operation: | write | Name: | Image Path |
Value: C:\Windows\system32\eps2003csp11v2_s.dll | |||
| (PID) Process: | (4088) ePass2003India-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\EnterSafe ePass2003 CSP v2.0 |
| Operation: | write | Name: | Type |
Value: 1 | |||
| (PID) Process: | (4088) ePass2003India-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Defaults\Provider\EnterSafe ePass2003 CSP v2.0 |
| Operation: | write | Name: | Signature |
Value: 661FFEC8524565568B3AA1D7C494E366C0217C935F092F8F2DAEC2F7DE27B553382188FE6742F2739EA02DB1F8878F7B0667FDFFF5D42AE98D46D056BA49B6D035EA766A171681B12B424AE91809799D897E3CC445D4D93ADB3F2E0A30FDC330B2D3A245E2E86EDF252CBDE61A46B4240B680309DDAE65BC80D184DC641550130000000000000000 | |||
| (PID) Process: | (4088) ePass2003India-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Calais\SmartCards\ePass2003 |
| Operation: | write | Name: | Crypto Provider |
Value: EnterSafe ePass2003 CSP v2.0 | |||
| (PID) Process: | (4088) ePass2003India-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Calais\SmartCards\ePass2003 |
| Operation: | write | Name: | ATR |
Value: 3B9F958131FE9F006646530500000071DF000006000000 | |||
| (PID) Process: | (4088) ePass2003India-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Cryptography\Calais\SmartCards\ePass2003 |
| Operation: | write | Name: | ATRMask |
Value: FFFFFFFFFFFFFFFFFFFFFFFF000000FFFFFFFFFFFFFF00 | |||
| (PID) Process: | (4088) ePass2003India-Setup.exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\Windows\CurrentVersion\Run |
| Operation: | write | Name: | ePass2003_std |
Value: C:\Program Files\Feitian\ePass2003\ePassCertd_2003.exe | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 4088 | ePass2003India-Setup.exe | C:\Users\admin\AppData\Local\Temp\nsc3C8F.tmp\System.dll | executable | |
MD5:301A9C8739ED3ED955A1BDC472D26F32 | SHA256:6EC9FDE89F067B1807325B05089C3AE4822CE7640D78E6F32DBE52F582DE1D92 | |||
| 4088 | ePass2003India-Setup.exe | C:\Users\admin\AppData\Local\Temp\nsc3C8F.tmp\modern-header.bmp | binary | |
MD5:D8A41AD69B9E0C8C6E09E05CAC3EA2E8 | SHA256:0BA299BFA78E8D29414AB36707C09A0C9281C5A7B9777D155512459B3B57E107 | |||
| 4088 | ePass2003India-Setup.exe | C:\Users\admin\AppData\Local\Temp\nsm54FA.tmp\SetupTool.dll | executable | |
MD5:78779314D8BE9B1B8845101463FD10DD | SHA256:3485C6B584C877C1B0003D59069FA398EDC2797BECD89A0670AEEAB7D33AF718 | |||
| 4088 | ePass2003India-Setup.exe | C:\Program Files\Feitian\ePass2003\uninst.exe | executable | |
MD5:5FCDDE6ED23FE85C62C860619F6424F9 | SHA256:AAE7B93305F1DA5C3E18385B958374FD918DEDEF844F3BD55B28581A0B071DF1 | |||
| 4088 | ePass2003India-Setup.exe | C:\Program Files\Feitian\ePass2003\FirefoxTCS.exe | executable | |
MD5:DE43F8D2D3467BB35D1DFE703F20A64A | SHA256:EC9F5F69DF016C3D1C2CCDD1259AB25982E0EC1891BA480839D6F71019FEB065 | |||
| 4088 | ePass2003India-Setup.exe | C:\Users\admin\AppData\Local\Temp\nsc3C8F.tmp\UserInfo.dll | executable | |
MD5:E47EDD32AA6F55C5E0F3D7807EF7801E | SHA256:4A775A8062DCBD2A960076AF0395C8182523D65AB1BCF3DA3F77F94D31051568 | |||
| 4088 | ePass2003India-Setup.exe | C:\Program Files\Feitian\ePass2003\ThunderBirdTCSun.exe | executable | |
MD5:363D8CC3D466804FF46EA698D93F7B74 | SHA256:55876F8990862F9CCFA22F2C0AC1177E22476B4622D081C2BDAFE0D4457BD6E5 | |||
| 4088 | ePass2003India-Setup.exe | C:\Program Files\Feitian\ePass2003\ePassManager_2003.exe | executable | |
MD5:B9E35A08477F5F394C80775A4FC05B77 | SHA256:D3FC6EA42E4F8ACF7BBC0A600A9B0BF5FE0B8C36727AA4F688446B600938327E | |||
| 4088 | ePass2003India-Setup.exe | C:\Program Files\Feitian\ePass2003\ePassCertd_2003.exe | executable | |
MD5:0A76B56807ED915A58307D0FDFF45E38 | SHA256:3A0ED75C0C69C71DD1A7C3F7EC3B588A327E35FDF97ED0FCA8604C8693106C8D | |||
| 4088 | ePass2003India-Setup.exe | C:\Program Files\Feitian\ePass2003\ThunderBirdTCS.exe | executable | |
MD5:A8553CA285B7D6755B1268A9A478887A | SHA256:4831380BCEA5B6E6DDFB28258016CD4E71F6D3DE4D7ED6363761292C6FC0A221 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
1292 | iexplore.exe | GET | 304 | 2.19.126.163:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?93f97daeb09f546c | unknown | — | — | unknown |
1292 | iexplore.exe | GET | 304 | 2.19.126.137:80 | http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?9065db9d2b164586 | unknown | — | — | unknown |
1292 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D | unknown | — | — | unknown |
312 | iexplore.exe | GET | 301 | 174.141.233.249:80 | http://www.charteredinfo.com/DSC/TokenDrivers/Updates/ePass2003ChangeLog.html | unknown | — | — | unknown |
312 | iexplore.exe | GET | 200 | 104.18.38.233:80 | http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEH1bUSa0droR23QWC7xTDac%3D | unknown | — | — | unknown |
2348 | ePassManager_2003.exe | GET | 301 | 174.141.233.249:80 | http://www.charteredinfo.com/DSCCSP2/TokenDrivers/Version.ini | unknown | — | — | unknown |
312 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAJ0LqoXyo4hxxe7H%2Fz9DKA%3D | unknown | — | — | unknown |
2348 | ePassManager_2003.exe | GET | 301 | 174.141.233.249:80 | http://www.charteredinfo.com/DSCCSP2/TokenDrivers/HyperPKI_HYP2003_Setup.exe | unknown | — | — | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
— | — | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1088 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
312 | iexplore.exe | 174.141.233.249:80 | www.charteredinfo.com | IWEB-AS | US | unknown |
1292 | iexplore.exe | 2.23.209.186:443 | www.bing.com | Akamai International B.V. | GB | unknown |
1292 | iexplore.exe | 2.19.126.163:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
1292 | iexplore.exe | 2.19.126.137:80 | ctldl.windowsupdate.com | Akamai International B.V. | DE | unknown |
1292 | iexplore.exe | 192.229.221.95:80 | ocsp.digicert.com | EDGECAST | US | whitelisted |
2348 | ePassManager_2003.exe | 174.141.233.249:80 | www.charteredinfo.com | IWEB-AS | US | unknown |
Domain | IP | Reputation |
|---|---|---|
www.charteredinfo.com |
| unknown |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
ocsp.usertrust.com |
| whitelisted |
iecvlist.microsoft.com |
| whitelisted |
r20swj13mr.microsoft.com |
| whitelisted |