| File name: | ICBC_TDR_UShield2_Install(2).exe |
| Full analysis: | https://app.any.run/tasks/35b10575-bbf1-4919-a73a-3c5fdea41784 |
| Verdict: | Malicious activity |
| Analysis date: | December 14, 2023, 10:49:29 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Tags: | |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 288054FE43530B9EAB16F787E13CA262 |
| SHA1: | 4F66A9B41AD8E5DEB737B4583F05273F6916B7D2 |
| SHA256: | F36CFA9854CFF33A7DE38F64187166B2DE8C723FCA9C65AB317F0CCEDBCB2712 |
| SSDEEP: | 98304:guC+oMlWZ/A1vIt2ix2GWKXHP2JVzcIFYG6dYdXq4oJIB7yZJ8brGl9wrwAF32am:pSLP |
| .exe | | | Win32 Executable MS Visual C++ (generic) (42.2) |
|---|---|---|
| .exe | | | Win64 Executable (generic) (37.3) |
| .dll | | | Win32 Dynamic Link Library (generic) (8.8) |
| .exe | | | Win32 Executable (generic) (6) |
| .exe | | | Generic Win/DOS Executable (2.7) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2010:04:10 14:19:31+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 9 |
| CodeSize: | 25600 |
| InitializedDataSize: | 431104 |
| UninitializedDataSize: | 16896 |
| EntryPoint: | 0x354b |
| OSVersion: | 5 |
| ImageVersion: | 6 |
| SubsystemVersion: | 5 |
| Subsystem: | Windows GUI |
| FileVersionNumber: | 2.0.0.128 |
| ProductVersionNumber: | 2.0.0.128 |
| FileFlagsMask: | 0x0000 |
| FileFlags: | (none) |
| FileOS: | Win32 |
| ObjectFileType: | Executable application |
| FileSubtype: | - |
| LanguageCode: | English (U.S.) |
| CharacterSet: | Unicode |
| CompanyName: | Tendyron |
| FileDescription: | Tendyron 193D4 for Industrial and Commercial Bank of China |
| FileVersion: | 2.0.0.128 |
| LegalCopyright: | Copyright(C) 2025 Tendyron |
| ProductName: | Tendyron 193D4 for Industrial and Commercial Bank of China |
| ProductVersion: | 2.0.0.128 |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 644 | "C:\Users\admin\AppData\Local\Temp\nsz6C7.tmp\ns6C58.tmp" C:\Program Files\ICBCEbankTools\Tendyron/res/config_ws_tdr.bat | C:\Users\admin\AppData\Local\Temp\nsz6C7.tmp\ns6C58.tmp | — | ICBC_TDR_UShield2_Install(2).exe | |||||||||||
User: admin Integrity Level: HIGH Exit code: 3221225501 Modules
| |||||||||||||||
| 1988 | C:\Windows\system32\regsvr32.exe /s "C:\Windows\Downloaded Program Files\icbc_tdrusbkey.dll" | C:\Windows\System32\regsvr32.exe | — | ICBC_TDR_UShield2_Install(2).exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2300 | C:\Windows\system32\regsvr32.exe /s "C:\Windows\Downloaded Program Files\icbcgm_tdrusbkey.dll" | C:\Windows\System32\regsvr32.exe | — | ICBC_TDR_UShield2_Install(2).exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Microsoft(C) Register Server Exit code: 0 Version: 6.1.7600.16385 (win7_rtm.090713-1255) Modules
| |||||||||||||||
| 2336 | C:\Windows\system32/D4Ser_ICBC.exe -i -s | C:\Windows\System32\D4Ser_ICBC.exe | — | ICBC_TDR_UShield2_Install(2).exe | |||||||||||
User: admin Company: Tendyron Corporation Integrity Level: HIGH Description: 中国工商银行U盾服务软件 Exit code: 0 Version: 1, 0, 0, 2 Modules
| |||||||||||||||
| 2600 | "C:\Users\admin\AppData\Local\Temp\ICBC_TDR_UShield2_Install(2).exe" | C:\Users\admin\AppData\Local\Temp\ICBC_TDR_UShield2_Install(2).exe | explorer.exe | ||||||||||||
User: admin Company: Tendyron Integrity Level: HIGH Description: Tendyron 193D4 for Industrial and Commercial Bank of China Exit code: 0 Version: 2.0.0.128 Modules
| |||||||||||||||
| 2860 | C:\Windows\system32\D4Ser_ICBC.exe -m | C:\Windows\System32\D4Ser_ICBC.exe | — | D4Ser_ICBC.exe | |||||||||||
User: SYSTEM Company: Tendyron Corporation Integrity Level: SYSTEM Description: 中国工商银行U盾服务软件 Exit code: 0 Version: 1, 0, 0, 2 Modules
| |||||||||||||||
| 2984 | http://www.icbc.com.cn/ | C:\Program Files\Internet Explorer\iexplore.exe | D4Tool_ICBC.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| 3208 | C:\Windows\system32\D4Svr_ICBC.exe installRoot | C:\Windows\System32\D4Svr_ICBC.exe | — | ICBC_TDR_UShield2_Install(2).exe | |||||||||||
User: admin Company: Tendyron Corporation Integrity Level: HIGH Description: 中国工商银行证书注册程序 Exit code: 1 Version: 2, 5, 1, 10 Modules
| |||||||||||||||
| 3264 | "C:\Users\admin\AppData\Local\Temp\ICBC_TDR_UShield2_Install(2).exe" | C:\Users\admin\AppData\Local\Temp\ICBC_TDR_UShield2_Install(2).exe | — | explorer.exe | |||||||||||
User: admin Company: Tendyron Integrity Level: MEDIUM Description: Tendyron 193D4 for Industrial and Commercial Bank of China Exit code: 3221226540 Version: 2.0.0.128 Modules
| |||||||||||||||
| 3288 | "C:\Program Files\Internet Explorer\IEXPLORE.EXE" SCODEF:2984 CREDAT:275457 /prefetch:2 | C:\Program Files\Internet Explorer\iexplore.exe | iexplore.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: HIGH Description: Internet Explorer Exit code: 0 Version: 11.00.9600.16428 (winblue_gdr.131013-1700) Modules
| |||||||||||||||
| (PID) Process: | (2600) ICBC_TDR_UShield2_Install(2).exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | ProxyBypass |
Value: 1 | |||
| (PID) Process: | (2600) ICBC_TDR_UShield2_Install(2).exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | IntranetName |
Value: 1 | |||
| (PID) Process: | (2600) ICBC_TDR_UShield2_Install(2).exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | UNCAsIntranet |
Value: 1 | |||
| (PID) Process: | (2600) ICBC_TDR_UShield2_Install(2).exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap |
| Operation: | write | Name: | AutoDetect |
Value: 0 | |||
| (PID) Process: | (2600) ICBC_TDR_UShield2_Install(2).exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Tendyron\193D4_ICBC |
| Operation: | write | Name: | USBKeyVersion |
Value: 1.0.0.20 | |||
| (PID) Process: | (2600) ICBC_TDR_UShield2_Install(2).exe | Key: | HKEY_LOCAL_MACHINE\SOFTWARE\Tendyron\193D4_ICBC |
| Operation: | write | Name: | GMUSBKeyVersion |
Value: 1.0.0.18 | |||
| (PID) Process: | (2600) ICBC_TDR_UShield2_Install(2).exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\3 |
| Operation: | write | Name: | 2500 |
Value: 0 | |||
| (PID) Process: | (2600) ICBC_TDR_UShield2_Install(2).exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 |
| Operation: | write | Name: | 2500 |
Value: 3 | |||
| (PID) Process: | (3964) D4Svr_ICBC.exe | Key: | HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones\2 |
| Operation: | write | Name: | 2201 |
Value: 3 | |||
| (PID) Process: | (3964) D4Svr_ICBC.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\17F\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 2600 | ICBC_TDR_UShield2_Install(2).exe | C:\Users\admin\AppData\Local\Temp\nsz6C7.tmp\System.dll | executable | |
MD5:959EA64598B9A3E494C00E8FA793BE7E | SHA256:03CD57AB00236C753E7DDEEE8EE1C10839ACE7C426769982365531042E1F6F8B | |||
| 2600 | ICBC_TDR_UShield2_Install(2).exe | C:\Users\admin\AppData\Local\Temp\ICBC_TDR_LOGO.bmp | image | |
MD5:2A86FF2C8874BE3A41BFF4BDC1AEBDA9 | SHA256:A87507783431D112068EA846D368AC6F55B12C1CA12ACC1F37AB0B98598DC63C | |||
| 2600 | ICBC_TDR_UShield2_Install(2).exe | C:\Users\admin\AppData\Local\Temp\nsz6C7.tmp\LangDLL.dll | executable | |
MD5:410A586735F45164C86BDA363AD8446F | SHA256:B15B1FC88D1B56088B2D3738D76772A91FA186A316A3E0A154358820D0FB9005 | |||
| 2600 | ICBC_TDR_UShield2_Install(2).exe | C:\Users\admin\AppData\Local\Temp\nsz6C7.tmp\Splash.dll | executable | |
MD5:0E2B7B4D19A6C9F62D04820AE502C167 | SHA256:8992098E5709AD7D68A8E021B20489338507A48523D8DDA6F5244ADC33A404A4 | |||
| 2600 | ICBC_TDR_UShield2_Install(2).exe | C:\Users\admin\AppData\Local\Temp\nsz6C7.tmp\Plugin_gsyh.dll | executable | |
MD5:742F42337AD1E4CDB097EAE6D5A21C0C | SHA256:4D9DE3EBF01A1362BD318255C46DC11E02155E24BCB1149E18F76DE1726FC59A | |||
| 2600 | ICBC_TDR_UShield2_Install(2).exe | C:\Users\admin\AppData\Local\Temp\nsz6C7.tmp\UserInfo.dll | executable | |
MD5:D16E06C5DE8FB8213A0464568ED9852F | SHA256:728472BA312AE8AF7F30D758AB473E0772477A68FCD1D2D547DAFE6D8800D531 | |||
| 2600 | ICBC_TDR_UShield2_Install(2).exe | C:\Users\admin\AppData\Local\Temp\nsz6C7.tmp\ioSpecial.ini | text | |
MD5:6F98FCDA445825382121E480A64AE24C | SHA256:689A67B30946CBE12DCE92D17207EC0488E850A806BE608E6FB174F853F86B57 | |||
| 2600 | ICBC_TDR_UShield2_Install(2).exe | C:\Users\admin\AppData\Local\Temp\nsz6C7.tmp\modern-wizard.bmp | image | |
MD5:CBE40FD2B1EC96DAEDC65DA172D90022 | SHA256:3AD2DC318056D0A2024AF1804EA741146CFC18CC404649A44610CBF8B2056CF2 | |||
| 2600 | ICBC_TDR_UShield2_Install(2).exe | C:\Program Files\ICBCEbankTools\ICBCEbankPlugin\icbc_TDR_usbkey_edge.json | text | |
MD5:DBFC6F71713AC53FD149835A717577D6 | SHA256:4E641BF6618BA90F098C72DB05474E3F73108CB91D62274BFC17C80E1A01E321 | |||
| 2600 | ICBC_TDR_UShield2_Install(2).exe | C:\Program Files\ICBCEbankTools\Tendyron\unInstall.exe | executable | |
MD5:4BDE6C0AFEAC84EBD1D24BA6CC14DFC9 | SHA256:3795052CD94D671E91C961D53617CBD03F998FCCF745984E1808807879A00925 | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
3288 | iexplore.exe | GET | 302 | 43.152.44.239:80 | http://www.icbc.com.cn/ | unknown | — | — | unknown |
3288 | iexplore.exe | GET | 200 | 163.181.92.236:80 | http://ocsp.digicert.cn/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQoKCsJAnleSoD2J3SoeC9qbEFAqgQUFl5oZ7yWIGLuNkzUZMPpoijWY8ICEASy2xU%2Bq1l7B%2F%2BTDVjs%2FQA%3D | unknown | binary | 471 b | unknown |
3288 | iexplore.exe | GET | 200 | 163.181.92.236:80 | http://ocsp.digicert.cn/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQoKCsJAnleSoD2J3SoeC9qbEFAqgQUFl5oZ7yWIGLuNkzUZMPpoijWY8ICEA2e0lx%2BX9agdMkyYWpNvHU%3D | unknown | binary | 471 b | unknown |
2984 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTrjrydRyt%2BApF3GSPypfHBxR5XtQQUs9tIpPmhxdiuNkHMEWNpYim8S8YCEAzlnDD9eoNTLi0BRrMy%2BWU%3D | unknown | binary | 314 b | unknown |
3288 | iexplore.exe | GET | 200 | 43.152.44.239:80 | http://v.icbc.com.cn/userfiles/Resources/ICBC/licai/information3.png | unknown | image | 441 b | unknown |
3288 | iexplore.exe | GET | 200 | 192.229.221.95:80 | http://ocsp.digicert.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBTBL0V27RVZ7LBduom%2FnYB45SPUEwQU5Z1ZMIJHWMys%2BghUNoZ7OrUETfACEA9bw6F2y3ieICDHiTyBZ7Q%3D | unknown | binary | 1.47 Kb | unknown |
3288 | iexplore.exe | GET | 200 | 163.181.56.214:80 | http://ocsp.dcocsp.cn/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQMO%2FVnZnwG%2FBa1LlDnjADjVWaMsQQURUHjk1RwuOmlt5a8JrFYdUKXPvMCEAhYv1QpDxO33fbPE7HPhKo%3D | unknown | binary | 471 b | unknown |
3288 | iexplore.exe | GET | 200 | 163.181.56.214:80 | http://ocsp.dcocsp.cn/MFEwTzBNMEswSTAJBgUrDgMCGgUABBSAUQYBMq2awn1Rh6Doh%2FsBYgFV7gQUA95QNVbRTLtm8KPiGxvDl7I90VUCEAfVfx8VW73kz4Q3jhf3m5Q%3D | unknown | binary | 471 b | unknown |
3288 | iexplore.exe | GET | 200 | 163.181.56.214:80 | http://ocsp.dcocsp.cn/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQMO%2FVnZnwG%2FBa1LlDnjADjVWaMsQQURUHjk1RwuOmlt5a8JrFYdUKXPvMCEAMY4pjz9EgEG7eFCGRmrtI%3D | unknown | binary | 471 b | unknown |
3288 | iexplore.exe | GET | 200 | 163.181.92.236:80 | http://ocsp.digicert.cn/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQoKCsJAnleSoD2J3SoeC9qbEFAqgQUFl5oZ7yWIGLuNkzUZMPpoijWY8ICEAHX0qy9NcsNJjcJj0vVbFA%3D | unknown | binary | 471 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
2588 | svchost.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
3288 | iexplore.exe | 43.152.44.239:80 | www.icbc.com.cn | ACE | DE | unknown |
3288 | iexplore.exe | 43.152.44.239:443 | www.icbc.com.cn | ACE | DE | unknown |
3288 | iexplore.exe | 93.184.221.240:80 | ctldl.windowsupdate.com | EDGECAST | GB | whitelisted |
3288 | iexplore.exe | 163.181.92.236:80 | ocsp.digicert.cn | Zhejiang Taobao Network Co.,Ltd | DE | unknown |
3288 | iexplore.exe | 60.247.99.191:443 | act.icbc.com.cn | China Networks Inter-Exchange | CN | unknown |
2984 | iexplore.exe | 104.126.37.137:443 | www.bing.com | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
www.icbc.com.cn |
| unknown |
ctldl.windowsupdate.com |
| whitelisted |
ocsp.digicert.cn |
| whitelisted |
v.icbc.com.cn |
| unknown |
act.icbc.com.cn |
| unknown |
api.bing.com |
| whitelisted |
www.bing.com |
| whitelisted |
ocsp.digicert.com |
| whitelisted |
hit.icbc.com.cn |
| unknown |
papi.icbc.com.cn |
| unknown |
Process | Message |
|---|---|
ICBC_TDR_UShield2_Install(2).exe | process name |
ICBC_TDR_UShield2_Install(2).exe | OK |
ICBC_TDR_UShield2_Install(2).exe | Installation prompt for ICBC U-Shield program (Tiandi Rong) |
ICBC_TDR_UShield2_Install(2).exe | The following programs may affect software installation. Do you want to forcibly close them |
ICBC_TDR_UShield2_Install(2).exe | process ID |
ICBC_TDR_UShield2_Install(2).exe | CALCEL |
ICBC_TDR_UShield2_Install(2).exe | D4Token_ICBC.dll |
ICBC_TDR_UShield2_Install(2).exe | GetDllOwnerProcName::param |
ICBC_TDR_UShield2_Install(2).exe | The following programs may affect software installation. Do you want to forcibly close them |
ICBC_TDR_UShield2_Install(2).exe | In GetDllOwnerNameList |