| File name: | vtuploader2.2.exe |
| Full analysis: | https://app.any.run/tasks/ea82ebef-56c5-4e11-9842-7d19040adaf0 |
| Verdict: | Malicious activity |
| Analysis date: | December 21, 2023, 07:40:59 |
| OS: | Windows 7 Professional Service Pack 1 (build: 7601, 32 bit) |
| Indicators: | |
| MIME: | application/x-dosexec |
| File info: | PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive |
| MD5: | 43CD42FE47AF2256E4414264F49AF1A8 |
| SHA1: | 3CCBBFFFD0DA76F72DD99AC39AFCFDFACD5F16E2 |
| SHA256: | 0918FA4B22D3E212A13FA449A5A7B5C3EC97759DD87DB6D281F387B1570E13C9 |
| SSDEEP: | 3072:fVGnJGXX4ftqRjLnohZR2NyDxHUSUIUyAUw5TmpAREl7j3:fVG4XX4ftqBLohjD9UXyAUtiO3 |
| .exe | | | NSIS - Nullsoft Scriptable Install System (91.9) |
|---|---|---|
| .exe | | | Win32 Executable MS Visual C++ (generic) (3.3) |
| .exe | | | Win64 Executable (generic) (3) |
| .dll | | | Win32 Dynamic Link Library (generic) (0.7) |
| .exe | | | Win32 Executable (generic) (0.4) |
| MachineType: | Intel 386 or later, and compatibles |
|---|---|
| TimeStamp: | 2013:07:14 22:09:51+02:00 |
| ImageFileCharacteristics: | No relocs, Executable, No line numbers, No symbols, 32-bit |
| PEType: | PE32 |
| LinkerVersion: | 6 |
| CodeSize: | 24064 |
| InitializedDataSize: | 164864 |
| UninitializedDataSize: | 1024 |
| EntryPoint: | 0x310b |
| OSVersion: | 4 |
| ImageVersion: | 6 |
| SubsystemVersion: | 4 |
| Subsystem: | Windows GUI |
PID | CMD | Path | Indicators | Parent process | |||||||||||
|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|---|
| 124 | "C:\Users\admin\AppData\Local\Temp\vtuploader2.2.exe" | C:\Users\admin\AppData\Local\Temp\vtuploader2.2.exe | — | explorer.exe | |||||||||||
User: admin Integrity Level: MEDIUM Exit code: 3221226540 Modules
| |||||||||||||||
| 240 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=network.mojom.NetworkService --lang=en-US --service-sandbox-type=none --mojo-platform-channel-handle=1452 --field-trial-handle=1400,i,10887003169258338175,1460430763858349375,131072 /prefetch:3 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | msedge.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 480 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=unzip.mojom.Unzipper --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=2436 --field-trial-handle=1400,i,10887003169258338175,1460430763858349375,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 604 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.virustotal.com/gui/file/2700b2db390c0bf2c77a4b167fcbdfd71deda98e53d024badc60eea074772d15/detection/f-2700b2db390c0bf2c77a4b167fcbdfd71deda98e53d024badc60eea074772d15-1703144542 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | VirusTotalUploader2.2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 948 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.virustotal.com/gui/file/db070207da72d5b3c22b378f919aea383ce5214bed3aaca90a34f81325255903/detection/f-db070207da72d5b3c22b378f919aea383ce5214bed3aaca90a34f81325255903-1703144541 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | VirusTotalUploader2.2.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 1264 | "C:\Users\admin\AppData\Local\Temp\vtuploader2.2.exe" | C:\Users\admin\AppData\Local\Temp\vtuploader2.2.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: HIGH Exit code: 0 Modules
| |||||||||||||||
| 1768 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --single-argument https://www.virustotal.com/gui/file/f7c1c5b44b73e2d39aca4a85df03c11e1c3db74c22f34e1c0d560bd3a13a7d56/detection/f-f7c1c5b44b73e2d39aca4a85df03c11e1c3db74c22f34e1c0d560bd3a13a7d56-1703144539 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | VirusTotalUploader2.2.exe | ||||||||||||
User: admin Company: Microsoft Corporation Integrity Level: MEDIUM Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2016 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=data_decoder.mojom.DataDecoderService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=5584 --field-trial-handle=1400,i,10887003169258338175,1460430763858349375,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2060 | "C:\Program Files\Microsoft\Edge\Application\msedge.exe" --type=utility --utility-sub-type=storage.mojom.StorageService --lang=en-US --service-sandbox-type=service --mojo-platform-channel-handle=1676 --field-trial-handle=1400,i,10887003169258338175,1460430763858349375,131072 /prefetch:8 | C:\Program Files\Microsoft\Edge\Application\msedge.exe | — | msedge.exe | |||||||||||
User: admin Company: Microsoft Corporation Integrity Level: LOW Description: Microsoft Edge Exit code: 0 Version: 109.0.1518.115 Modules
| |||||||||||||||
| 2172 | "C:\Program Files\VirusTotalUploader2\VirusTotalUploader2.2.exe" | C:\Program Files\VirusTotalUploader2\VirusTotalUploader2.2.exe | explorer.exe | ||||||||||||
User: admin Integrity Level: MEDIUM Exit code: 0 Modules
| |||||||||||||||
| (PID) Process: | (2172) VirusTotalUploader2.2.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
| Operation: | write | Name: | NodeSlots |
Value: 020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202 | |||
| (PID) Process: | (2172) VirusTotalUploader2.2.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
| Operation: | write | Name: | MRUListEx |
Value: 06000000000000000B0000000100000002000000070000000C0000000D0000000A0000000900000008000000030000000500000004000000FFFFFFFF | |||
| (PID) Process: | (2172) VirusTotalUploader2.2.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0 |
| Operation: | write | Name: | MRUListEx |
Value: 020000000000000001000000040000000500000003000000FFFFFFFF | |||
| (PID) Process: | (2172) VirusTotalUploader2.2.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
| Operation: | write | Name: | MRUListEx |
Value: 0100000006000000000000000B00000002000000070000000C0000000D0000000A0000000900000008000000030000000500000004000000FFFFFFFF | |||
| (PID) Process: | (2172) VirusTotalUploader2.2.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0\1 |
| Operation: | write | Name: | MRUListEx |
Value: 090000000A000000010000000800000007000000060000000500000004000000030000000000000002000000FFFFFFFF | |||
| (PID) Process: | (2172) VirusTotalUploader2.2.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU |
| Operation: | write | Name: | NodeSlots |
Value: 02020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202020202 | |||
| (PID) Process: | (2172) VirusTotalUploader2.2.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E |
| Operation: | write | Name: | LanguageList |
Value: en-US | |||
| (PID) Process: | (2172) VirusTotalUploader2.2.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0 |
| Operation: | write | Name: | MRUListEx |
Value: 010000000200000000000000040000000500000003000000FFFFFFFF | |||
| (PID) Process: | (2172) VirusTotalUploader2.2.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\BagMRU\1\0 |
| Operation: | write | Name: | MRUListEx |
Value: 040000000100000002000000000000000500000003000000FFFFFFFF | |||
| (PID) Process: | (2172) VirusTotalUploader2.2.exe | Key: | HKEY_CLASSES_ROOT\Local Settings\Software\Microsoft\Windows\Shell\Bags\223\ComDlg\{5C4F28B5-F869-4E84-8E60-F11DB97C5CC7} |
| Operation: | write | Name: | Mode |
Value: 4 | |||
PID | Process | Filename | Type | |
|---|---|---|---|---|
| 1768 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old~RFf1851.TMP | — | |
MD5:— | SHA256:— | |||
| 1768 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\commerce_subscription_db\LOG.old | — | |
MD5:— | SHA256:— | |||
| 1264 | vtuploader2.2.exe | C:\ProgramData\Microsoft\Windows\Start Menu\Programs\VirusTotal Uploader 2.2\Uninstall.lnk | binary | |
MD5:4B8EC546307336AA1B11D2050D23D6C4 | SHA256:1FEDDE05FE3ABEEB77D247FAB95DB8C698810CE34257C9DC68E034C02647D573 | |||
| 1768 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RFf1861.TMP | — | |
MD5:— | SHA256:— | |||
| 1768 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old | — | |
MD5:— | SHA256:— | |||
| 1768 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\EdgePushStorageWithConnectTokenAndKey\LOG.old~RFf1870.TMP | — | |
MD5:— | SHA256:— | |||
| 1264 | vtuploader2.2.exe | C:\Users\admin\AppData\Roaming\Microsoft\Windows\SendTo\VirusTotal.lnk | binary | |
MD5:C102CCCD0B7529C0B978E23115DACF33 | SHA256:66AD152B212A841B88291E3893954AB88B9C200F222C4F39AC609E3A831E46CE | |||
| 1264 | vtuploader2.2.exe | C:\Users\admin\Desktop\VirusTotal Uploader 2.2.lnk | binary | |
MD5:C62F2B94384D3FBCBC30FF1184B1A8DC | SHA256:9E26593E434585A640020548859D1B92DA187FAD4791D4C1B36AA419B962DEE8 | |||
| 1264 | vtuploader2.2.exe | C:\Users\Administrator\Desktop\VirusTotal Uploader 2.2.lnk | binary | |
MD5:C62F2B94384D3FBCBC30FF1184B1A8DC | SHA256:9E26593E434585A640020548859D1B92DA187FAD4791D4C1B36AA419B962DEE8 | |||
| 1768 | msedge.exe | C:\Users\admin\AppData\Local\Microsoft\Edge\User Data\Default\LOG.old~RFf190d.TMP | — | |
MD5:— | SHA256:— | |||
PID | Process | Method | HTTP Code | IP | URL | CN | Type | Size | Reputation |
|---|---|---|---|---|---|---|---|---|---|
2172 | VirusTotalUploader2.2.exe | GET | 200 | 74.125.34.46:80 | http://www.virustotal.com/vtapi/v2/file/report?apikey=f25133d9068704c23335fc39a7351828fa80c5dde894d731d5450cf8ab8569e8&resource=e0858f48b5b15bca371658f215ec512ff5b163a2 | unknown | binary | 168 b | unknown |
2172 | VirusTotalUploader2.2.exe | POST | 200 | 74.125.34.46:80 | http://www.virustotal.com/vtapi/v2/file/scan | unknown | binary | 636 b | unknown |
2172 | VirusTotalUploader2.2.exe | GET | 200 | 74.125.34.46:80 | http://www.virustotal.com/vtapi/v2/file/report?apikey=f25133d9068704c23335fc39a7351828fa80c5dde894d731d5450cf8ab8569e8&resource=834f368c376ce77e5284ebf141a924ab7ad30813 | unknown | binary | 168 b | unknown |
2172 | VirusTotalUploader2.2.exe | GET | 200 | 74.125.34.46:80 | http://www.virustotal.com/vtapi/v2/file/report?apikey=f25133d9068704c23335fc39a7351828fa80c5dde894d731d5450cf8ab8569e8&resource=ed888aeae66e46c5a8b426f8d6ddb63f0fc12a0c | unknown | binary | 168 b | unknown |
2172 | VirusTotalUploader2.2.exe | POST | 200 | 74.125.34.46:80 | http://www.virustotal.com/vtapi/v2/file/scan | unknown | binary | 636 b | unknown |
2172 | VirusTotalUploader2.2.exe | GET | 200 | 74.125.34.46:80 | http://www.virustotal.com/vtapi/v2/file/report?apikey=f25133d9068704c23335fc39a7351828fa80c5dde894d731d5450cf8ab8569e8&resource=c0c2cd95ad1255222c0fa74630f77f031b6036dc | unknown | binary | 168 b | unknown |
2172 | VirusTotalUploader2.2.exe | POST | 200 | 74.125.34.46:80 | http://www.virustotal.com/vtapi/v2/file/scan | unknown | binary | 636 b | unknown |
2172 | VirusTotalUploader2.2.exe | POST | 200 | 74.125.34.46:80 | http://www.virustotal.com/vtapi/v2/file/scan | unknown | binary | 636 b | unknown |
PID | Process | IP | Domain | ASN | CN | Reputation |
|---|---|---|---|---|---|---|
4 | System | 192.168.100.255:138 | — | — | — | whitelisted |
4 | System | 192.168.100.255:137 | — | — | — | whitelisted |
1080 | svchost.exe | 224.0.0.252:5355 | — | — | — | unknown |
2172 | VirusTotalUploader2.2.exe | 74.125.34.46:80 | www.virustotal.com | GOOGLE | US | whitelisted |
1768 | msedge.exe | 239.255.255.250:1900 | — | — | — | whitelisted |
240 | msedge.exe | 74.125.34.46:443 | www.virustotal.com | GOOGLE | US | whitelisted |
240 | msedge.exe | 13.107.42.16:443 | config.edge.skype.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | whitelisted |
240 | msedge.exe | 20.105.95.163:443 | nav-edge.smartscreen.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | IE | unknown |
240 | msedge.exe | 204.79.197.239:443 | edge.microsoft.com | MICROSOFT-CORP-MSN-AS-BLOCK | US | unknown |
240 | msedge.exe | 2.19.120.29:443 | www.bing.com | Akamai International B.V. | DE | unknown |
Domain | IP | Reputation |
|---|---|---|
www.virustotal.com |
| whitelisted |
config.edge.skype.com |
| whitelisted |
nav-edge.smartscreen.microsoft.com |
| whitelisted |
edge.microsoft.com |
| whitelisted |
data-edge.smartscreen.microsoft.com |
| whitelisted |
www.bing.com |
| whitelisted |
www.recaptcha.net |
| whitelisted |
www.gstatic.com |
| whitelisted |
www.googletagmanager.com |
| whitelisted |
region1.analytics.google.com |
| whitelisted |
Process | Message |
|---|---|
msedge.exe | [1221/074221.717:ERROR:exception_handler_server.cc(527)] ConnectNamedPipe: The pipe is being closed. (0xE8)
|
msedge.exe | [1221/074223.150:ERROR:exception_handler_server.cc(527)] ConnectNamedPipe: The pipe is being closed. (0xE8)
|