URL:

http://update.singlewindow.cn/downloads/EportClientSetup_V1.5.14.exe

Full analysis: https://app.any.run/tasks/2cb80658-54d4-46e6-8a71-d636b0f043f9
Verdict: Malicious activity
Threats:

A loader is malicious software that infiltrates devices to deliver malicious payloads. This malware is capable of infecting victims’ computers, analyzing their system information, and installing other types of threats, such as trojans or stealers. Criminals usually deliver loaders through phishing emails and links by relying on social engineering to trick users into downloading and running their executables. Loaders employ advanced evasion and persistence tactics to avoid detection.

Analysis date: January 19, 2020, 02:29:31
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Tags:
loader
Indicators:
MD5:

06C85442E55898F4C872C6656200B36A

SHA1:

CF6BEC2AB8697A6472918609DA2214326D5C0685

SHA256:

0A46373542DB102E7FB453574C68B6F10E4B3E23C95A166244826D1019663495

SSDEEP:

3:N1KLQRAv2JKa1KZss0QgLUtAdA:CU5ozZsPLUydA

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Application was dropped or rewritten from another process

      • EportClientSetup_V1.5.14[1].exe (PID: 3876)
      • EportClientSetup_V1.5.14[1].exe (PID: 1324)
      • DPInst32.exe (PID: 2896)
      • ns5FDC.tmp (PID: 3116)
      • ns62EA.tmp (PID: 2564)
      • ns652D.tmp (PID: 3260)
      • ns6A22.tmp (PID: 1096)
      • ns685B.tmp (PID: 2580)
      • TXRNSecurityCom.exe (PID: 2788)
      • ns6C8D.tmp (PID: 2260)
      • ns6DE5.tmp (PID: 1728)
      • InstallUtil.exe (PID: 3368)
      • RegAsm.exe (PID: 2092)
      • ns6703.tmp (PID: 1404)
      • 02.base_driver.exe (PID: 3388)
      • ActiveXRegGs.exe (PID: 1216)
      • 03.½ð±¨Ë°ÅÌ˰ÎñÊý×ÖÖ¤ÊéÇý¶¯1.1.1.12.exe (PID: 2840)
      • nsF351.tmp (PID: 2348)
      • nsF4A9.tmp (PID: 776)
      • ServiceIoApi.exe (PID: 3864)
      • ServiceIoApi.exe (PID: 3208)
      • SetAccessControl.exe (PID: 2880)
      • CnEport.Pub.WinService.exe (PID: 2860)
      • ns3D33.tmp (PID: 3728)
      • ePass3003_SimpChinese_gfa.exe (PID: 2468)
      • CnEport.Pub.WebSocketServer.exe (PID: 444)
      • nsF815.tmp (PID: 1296)
      • nsEA0.tmp (PID: 388)
      • GFA_certd3003.exe (PID: 2444)
      • SetAccessControl.exe (PID: 4004)
      • SetAccessControl.exe (PID: 600)
      • CertManager.exe (PID: 2160)
      • SetAccessControl.exe (PID: 1916)
      • SetAccessControl.exe (PID: 3676)
    • Loads dropped or rewritten executable

      • EportClientSetup_V1.5.14[1].exe (PID: 3876)
      • InstallUtil.exe (PID: 3368)
      • RegAsm.exe (PID: 2092)
      • TXRNSecurityCom.exe (PID: 2788)
      • 03.½ð±¨Ë°ÅÌ˰ÎñÊý×ÖÖ¤ÊéÇý¶¯1.1.1.12.exe (PID: 2840)
      • SetAccessControl.exe (PID: 2880)
      • CnEport.Pub.WinService.exe (PID: 2860)
      • CnEport.Pub.WebSocketServer.exe (PID: 444)
      • ePass3003_SimpChinese_gfa.exe (PID: 2468)
      • rundll32.exe (PID: 3864)
      • explorer.exe (PID: 352)
      • GFA_certd3003.exe (PID: 2444)
      • SetAccessControl.exe (PID: 3676)
      • SetAccessControl.exe (PID: 600)
      • SetAccessControl.exe (PID: 4004)
      • CertManager.exe (PID: 2160)
      • SetAccessControl.exe (PID: 1916)
    • Downloads executable files from the Internet

      • iexplore.exe (PID: 2700)
    • Changes settings of System certificates

      • RegAsm.exe (PID: 2092)
      • ePass3003_SimpChinese_gfa.exe (PID: 2468)
    • Loads the Task Scheduler COM API

      • schtasks.exe (PID: 3396)
      • schtasks.exe (PID: 1712)
    • Uses Task Scheduler to run other applications

      • ns6703.tmp (PID: 1404)
    • Uses Task Scheduler to autorun other applications

      • ns685B.tmp (PID: 2580)
    • Starts NET.EXE for service management

      • ns6C8D.tmp (PID: 2260)
      • nsF351.tmp (PID: 2348)
      • nsF815.tmp (PID: 1296)
    • Registers / Runs the DLL via REGSVR32.EXE

      • 02.base_driver.tmp (PID: 2536)
    • Changes the autorun value in the registry

      • 03.½ð±¨Ë°ÅÌ˰ÎñÊý×ÖÖ¤ÊéÇý¶¯1.1.1.12.exe (PID: 2840)
      • ePass3003_SimpChinese_gfa.exe (PID: 2468)
  • SUSPICIOUS

    • Executable content was dropped or overwritten

      • iexplore.exe (PID: 2172)
      • EportClientSetup_V1.5.14[1].exe (PID: 3876)
      • TXRNSecurityCom.exe (PID: 2788)
      • 02.base_driver.tmp (PID: 2536)
      • 02.base_driver.exe (PID: 3388)
      • 03.½ð±¨Ë°ÅÌ˰ÎñÊý×ÖÖ¤ÊéÇý¶¯1.1.1.12.exe (PID: 2840)
      • iexplore.exe (PID: 2700)
      • ePass3003_SimpChinese_gfa.exe (PID: 2468)
    • Creates COM task schedule object

      • EportClientSetup_V1.5.14[1].exe (PID: 3876)
      • RegAsm.exe (PID: 2092)
    • Starts application with an unusual extension

      • EportClientSetup_V1.5.14[1].exe (PID: 3876)
      • TXRNSecurityCom.exe (PID: 2788)
      • 03.½ð±¨Ë°ÅÌ˰ÎñÊý×ÖÖ¤ÊéÇý¶¯1.1.1.12.exe (PID: 2840)
    • Reads Internet Cache Settings

      • explorer.exe (PID: 352)
    • Creates files in the Windows directory

      • EportClientSetup_V1.5.14[1].exe (PID: 3876)
      • DPInst32.exe (PID: 2896)
      • 02.base_driver.tmp (PID: 2536)
      • TXRNSecurityCom.exe (PID: 2788)
      • ActiveXRegGs.exe (PID: 1216)
      • 03.½ð±¨Ë°ÅÌ˰ÎñÊý×ÖÖ¤ÊéÇý¶¯1.1.1.12.exe (PID: 2840)
      • CnEport.Pub.WinService.exe (PID: 2860)
      • ePass3003_SimpChinese_gfa.exe (PID: 2468)
    • Adds / modifies Windows certificates

      • RegAsm.exe (PID: 2092)
    • Starts SC.EXE for service management

      • ns6DE5.tmp (PID: 1728)
      • nsF4A9.tmp (PID: 776)
    • Creates files in the program directory

      • TXRNSecurityCom.exe (PID: 2788)
      • 03.½ð±¨Ë°ÅÌ˰ÎñÊý×ÖÖ¤ÊéÇý¶¯1.1.1.12.exe (PID: 2840)
      • ePass3003_SimpChinese_gfa.exe (PID: 2468)
    • Creates files in the user directory

      • TXRNSecurityCom.exe (PID: 2788)
      • CnEport.Pub.WebSocketServer.exe (PID: 444)
      • EportClientSetup_V1.5.14[1].exe (PID: 3876)
    • Removes files from Windows directory

      • 02.base_driver.tmp (PID: 2536)
      • CnEport.Pub.WinService.exe (PID: 2860)
    • Creates a software uninstall entry

      • 03.½ð±¨Ë°ÅÌ˰ÎñÊý×ÖÖ¤ÊéÇý¶¯1.1.1.12.exe (PID: 2840)
      • ePass3003_SimpChinese_gfa.exe (PID: 2468)
      • EportClientSetup_V1.5.14[1].exe (PID: 3876)
    • Starts Internet Explorer

      • explorer.exe (PID: 352)
    • Executed as Windows Service

      • CnEport.Pub.WinService.exe (PID: 2860)
      • ServiceIoApi.exe (PID: 3208)
    • Modifies the open verb of a shell class

      • SetAccessControl.exe (PID: 2880)
    • Uses RUNDLL32.EXE to load library

      • ePass3003_SimpChinese_gfa.exe (PID: 2468)
  • INFO

    • Application launched itself

      • iexplore.exe (PID: 2172)
    • Reads Internet Cache Settings

      • iexplore.exe (PID: 2172)
      • iexplore.exe (PID: 2700)
    • Creates a software uninstall entry

      • 02.base_driver.tmp (PID: 2536)
    • Loads dropped or rewritten executable

      • 02.base_driver.tmp (PID: 2536)
    • Application was dropped or rewritten from another process

      • 02.base_driver.tmp (PID: 2536)
    • Dropped object may contain Bitcoin addresses

      • TXRNSecurityCom.exe (PID: 2788)
      • 03.½ð±¨Ë°ÅÌ˰ÎñÊý×ÖÖ¤ÊéÇý¶¯1.1.1.12.exe (PID: 2840)
    • Changes internet zones settings

      • iexplore.exe (PID: 2172)
    • Creates files in the user directory

      • iexplore.exe (PID: 2172)
      • iexplore.exe (PID: 2700)
    • Manual execution by user

      • GFA_certd3003.exe (PID: 2444)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
106
Monitored processes
52
Malicious processes
22
Suspicious processes
7

Behavior graph

Click at the process to see the details
drop and start drop and start start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start drop and start iexplore.exe iexplore.exe eportclientsetup_v1.5.14[1].exe no specs eportclientsetup_v1.5.14[1].exe ns5fdc.tmp no specs regasm.exe ns62ea.tmp no specs installutil.exe no specs ns652d.tmp no specs dpinst32.exe no specs ns6703.tmp no specs schtasks.exe no specs ns685b.tmp schtasks.exe no specs ns6a22.tmp no specs powercfg.exe no specs txrnsecuritycom.exe ns6c8d.tmp no specs net.exe no specs net1.exe no specs ns6de5.tmp no specs sc.exe no specs 02.base_driver.exe 02.base_driver.tmp regsvr32.exe no specs activexreggs.exe no specs 03.½ð±¨ë°åìë°îñêý×öö¤êéçý¶¯1.1.1.12.exe nsf351.tmp no specs net.exe no specs net1.exe no specs nsf4a9.tmp no specs sc.exe no specs serviceioapi.exe no specs nsf815.tmp no specs net.exe no specs net1.exe no specs serviceioapi.exe no specs nsea0.tmp no specs setaccesscontrol.exe no specs cneport.pub.winservice.exe cneport.pub.websocketserver.exe ns3d33.tmp no specs epass3003_simpchinese_gfa.exe regedit.exe no specs rundll32.exe no specs gfa_certd3003.exe no specs explorer.exe no specs setaccesscontrol.exe no specs setaccesscontrol.exe no specs certmanager.exe setaccesscontrol.exe no specs setaccesscontrol.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
272C:\Windows\system32\net1 start "ServiceIoApi"C:\Windows\system32\net1.exenet.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Net Command
Exit code:
0
Version:
6.1.7601.17514 (win7sp1_rtm.101119-1850)
Modules
Images
c:\windows\system32\net1.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\dsrole.dll
c:\windows\system32\netutils.dll
352C:\Windows\Explorer.EXEC:\Windows\explorer.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
MEDIUM
Description:
Windows Explorer
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\winanr.dll
c:\windows\system32\mswsock.dll
c:\windows\system32\wshtcpip.dll
c:\windows\explorer.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
388"C:\Users\admin\AppData\Local\Temp\nsiFFAA.tmp\nsEA0.tmp" C:\Öйúµç×Ó¿Ú°¶¿Í»§¶Ë¿Ø¼þ\SetAccessControl.exeC:\Users\admin\AppData\Local\Temp\nsiFFAA.tmp\nsEA0.tmpEportClientSetup_V1.5.14[1].exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsiffaa.tmp\nsea0.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
444"C:\Öйúµç×Ó¿Ú°¶¿Í»§¶Ë¿Ø¼þ\CnEport.Pub.WebSocketServer.exe" C:\Öйúµç×Ó¿Ú°¶¿Í»§¶Ë¿Ø¼þ\CnEport.Pub.WebSocketServer.exe
SetAccessControl.exe
User:
admin
Company:
Eport Soft
Integrity Level:
HIGH
Description:
CnEport.Pub.WebSocketServer assembly
Exit code:
0
Version:
2.0.17179.1607
Modules
Images
c:\öð¹úµç×ó¿ú°¶¿í»§¶ë¿ø¼þ\cneport.pub.websocketserver.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
600"C:\Öйúµç×Ó¿Ú°¶¿Í»§¶Ë¿Ø¼þ\SetAccessControl.exe" -restart -iC:\Öйúµç×Ó¿Ú°¶¿Í»§¶Ë¿Ø¼þ\SetAccessControl.exeexplorer.exe
User:
admin
Company:
Eport Soft
Integrity Level:
MEDIUM
Description:
CnEport.Pub.SetAccessControl assembly
Exit code:
0
Version:
2.0.17179.1607
Modules
Images
c:\öð¹úµç×ó¿ú°¶¿í»§¶ë¿ø¼þ\setaccesscontrol.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\mscoree.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\microsoft.net\framework\v4.0.30319\mscoreei.dll
776"C:\Users\admin\AppData\Local\Temp\nsdF330.tmp\nsF4A9.tmp" sc delete ServiceIoApiC:\Users\admin\AppData\Local\Temp\nsdF330.tmp\nsF4A9.tmp03.½ð±¨Ë°ÅÌ˰ÎñÊý×ÖÖ¤ÊéÇý¶¯1.1.1.12.exe
User:
admin
Integrity Level:
HIGH
Exit code:
1060
Modules
Images
c:\users\admin\appdata\local\temp\nsdf330.tmp\nsf4a9.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1096"C:\Users\admin\AppData\Local\Temp\nsiFFAA.tmp\ns6A22.tmp" powercfg.exe /H offC:\Users\admin\AppData\Local\Temp\nsiFFAA.tmp\ns6A22.tmpEportClientSetup_V1.5.14[1].exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsiffaa.tmp\ns6a22.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\usp10.dll
c:\windows\system32\advapi32.dll
1216"C:\Windows\system32\ActiveXRegGs.exe"C:\Windows\system32\ActiveXRegGs.exe02.base_driver.tmp
User:
admin
Integrity Level:
HIGH
Description:
ActiveXReg Microsoft 基础类应用程序
Exit code:
0
Version:
1, 0, 0, 1
Modules
Images
c:\windows\system32\activexreggs.exe
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\mfc42.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1296"C:\Users\admin\AppData\Local\Temp\nsdF330.tmp\nsF815.tmp" net start "ServiceIoApi"C:\Users\admin\AppData\Local\Temp\nsdF330.tmp\nsF815.tmp03.½ð±¨Ë°ÅÌ˰ÎñÊý×ÖÖ¤ÊéÇý¶¯1.1.1.12.exe
User:
admin
Integrity Level:
HIGH
Exit code:
0
Modules
Images
c:\users\admin\appdata\local\temp\nsdf330.tmp\nsf815.tmp
c:\systemroot\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
1324"C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\EportClientSetup_V1.5.14[1].exe" C:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\EportClientSetup_V1.5.14[1].exeiexplore.exe
User:
admin
Integrity Level:
MEDIUM
Exit code:
3221226540
Modules
Images
c:\users\admin\appdata\local\microsoft\windows\temporary internet files\content.ie5\lh043oam\eportclientsetup_v1.5.14[1].exe
c:\systemroot\system32\ntdll.dll
Total events
5 218
Read events
4 555
Write events
652
Delete events
11

Modification events

(PID) Process:(352) explorer.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\12B\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2172) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main
Operation:writeName:CompatibilityFlags
Value:
0
(PID) Process:(2172) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:UNCAsIntranet
Value:
0
(PID) Process:(2172) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:AutoDetect
Value:
1
(PID) Process:(2172) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Zones
Operation:writeName:SecuritySafe
Value:
1
(PID) Process:(2172) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:ProxyEnable
Value:
0
(PID) Process:(2172) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\Connections
Operation:writeName:SavedLegacySettings
Value:
4600000092000000010000000000000000000000000000000000000000000000C0E333BBEAB1D301000000000000000000000000020000001700000000000000FE800000000000007D6CB050D9C573F70B000000000000006D00330032005C004D00530049004D004700330032002E0064006C000100000004AA400014AA4000040000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000000002000000C0A8016400000000000000000000000000000000000000000800000000000000805D3F00983740000008000002000000000000600000002060040000B8A94000020000008802000060040000B8A9400004000000F8010000B284000088B64000B84B400043003A000000000000000000000000000000000000000000
(PID) Process:(2172) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Recovery\Active
Operation:writeName:{8F42A7EB-3A63-11EA-AB41-5254004A04AF}
Value:
0
(PID) Process:(2172) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Type
Value:
4
(PID) Process:(2172) iexplore.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Ext\Stats\{2670000A-7350-4F3C-8081-5663EE0C6C49}\iexplore
Operation:writeName:Count
Value:
2
Executable files
152
Suspicious files
42
Text files
171
Unknown types
26

Dropped files

PID
Process
Filename
Type
2172iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\favicon[1].ico
MD5:
SHA256:
2172iexplore.exeC:\Users\admin\AppData\LocalLow\Microsoft\Internet Explorer\Services\search_{0633EE93-D776-472f-A0FF-E1416B8B2E3A}.ico
MD5:
SHA256:
2172iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFA0D0B9B7D4DFA6CB.TMP
MD5:
SHA256:
2172iexplore.exeC:\Users\admin\AppData\Local\Temp\~DFD8A89B4B8E2C8ECA.TMP
MD5:
SHA256:
2172iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Internet Explorer\Recovery\Active\RecoveryStore.{8F42A7EB-3A63-11EA-AB41-5254004A04AF}.dat
MD5:
SHA256:
2700iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Low\Content.IE5\index.datdat
MD5:2A58402D0B0E34AC8F9BE1823EA6DFF9
SHA256:83C061B918F1DEA49E60EA0497C13266A543E552AA9CFB2830A06AA6AE830523
2172iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\Temporary Internet Files\Content.IE5\LH043OAM\EportClientSetup_V1.5.14[1].exeexecutable
MD5:ED8B63CB5F442A7277F245957BEBAB65
SHA256:539E7F98D052CF4718819EAC2D1A24D9CBD26A553784054903F5BB8ED4707253
2700iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\index.datdat
MD5:483D957AFD74885C4BB87BC0301FF27C
SHA256:5D47616FCD4C4C4049DD48786B0CCBE2C8D3CA0E3EF667865EEC2D97D98330B9
2700iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\Low\History.IE5\MSHist012020011920200120\index.datdat
MD5:AF9F7167B47DF0F467B6002490766F52
SHA256:FD555FE9C503A9333D069CE11F4A1548F913D20DB07026FC932D70C92623A3C3
2172iexplore.exeC:\Users\admin\AppData\Local\Microsoft\Windows\History\History.IE5\MSHist012020011920200120\index.datdat
MD5:890F541F7629CA4BFCEF2903B50B80D9
SHA256:C04E807C362D489F7F6BCE559DD6D43D8E9A22CC18C098B4A4D825DED2D15B1F
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
7
TCP/UDP connections
10
DNS requests
8
Threats
1

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2700
iexplore.exe
GET
200
119.188.140.34:80
http://update.singlewindow.cn/downloads/EportClientSetup_V1.5.14.exe
CN
executable
25.0 Mb
malicious
2860
CnEport.Pub.WinService.exe
GET
200
23.37.43.27:80
http://sv.symcd.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBQe6LNDJdqx%2BJOp7hVgTeaGFJ%2FCQgQUljtT8Hkzl699g%2B8uK8zKt4YecmYCEDsEtihb1nP2kWB5qXnxDjE%3D
NL
der
1.57 Kb
shared
2860
CnEport.Pub.WinService.exe
GET
200
23.37.43.27:80
http://s2.symcb.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBS56bKHAoUD%2BOyl%2B0LhPg9JxyQm4gQUf9Nlp8Ld7LvwMAnzQzn6Aq8zMTMCED141%2Fl2SWCyYX308B7Khio%3D
NL
der
1.71 Kb
whitelisted
GET
200
151.101.2.133:80
http://secure.globalsign.com/cacert/gsorganizationvalsha2g2r1.crt
US
der
1.11 Kb
whitelisted
GET
200
151.101.2.133:80
http://ocsp2.globalsign.com/gsorganizationvalsha2g2/ME0wSzBJMEcwRTAJBgUrDgMCGgUABBQMnk2cPe3vhNiR6XLHz4QGvBl7BwQUlt5h8b0cFilTHMDMfTuDAEDmGnwCDBpz8AvUX4bk6C%2BZww%3D%3D
US
der
1.54 Kb
whitelisted
2092
RegAsm.exe
GET
200
93.184.221.240:80
http://www.download.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab
US
compressed
57.4 Kb
whitelisted
2172
iexplore.exe
GET
200
204.79.197.200:80
http://www.bing.com/favicon.ico
US
image
237 b
whitelisted
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
2700
iexplore.exe
119.188.140.34:80
update.singlewindow.cn
CHINA UNICOM China169 Backbone
CN
suspicious
2172
iexplore.exe
204.79.197.200:80
www.bing.com
Microsoft Corporation
US
whitelisted
2860
CnEport.Pub.WinService.exe
23.37.43.27:80
s2.symcb.com
Akamai Technologies, Inc.
NL
whitelisted
151.101.2.133:80
secure.globalsign.com
Fastly
US
malicious
444
CnEport.Pub.WebSocketServer.exe
23.37.43.27:80
s2.symcb.com
Akamai Technologies, Inc.
NL
whitelisted
444
CnEport.Pub.WebSocketServer.exe
93.184.220.29:80
s1.symcb.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted
2092
RegAsm.exe
93.184.221.240:80
www.download.windowsupdate.com
MCI Communications Services, Inc. d/b/a Verizon Business
US
whitelisted

DNS requests

Domain
IP
Reputation
www.bing.com
  • 204.79.197.200
  • 13.107.21.200
whitelisted
update.singlewindow.cn
  • 119.188.140.34
  • 124.163.207.47
malicious
www.download.windowsupdate.com
  • 93.184.221.240
whitelisted
s2.symcb.com
  • 23.37.43.27
whitelisted
sv.symcd.com
  • 23.37.43.27
shared
s1.symcb.com
  • 93.184.220.29
whitelisted
secure.globalsign.com
  • 151.101.2.133
  • 151.101.66.133
  • 151.101.130.133
  • 151.101.194.133
whitelisted
ocsp2.globalsign.com
  • 151.101.2.133
  • 151.101.66.133
  • 151.101.130.133
  • 151.101.194.133
whitelisted

Threats

PID
Process
Class
Message
2700
iexplore.exe
Potential Corporate Privacy Violation
ET POLICY PE EXE or DLL Windows file download HTTP
Process
Message
CertManager.exe
SKF Process P11 Start
CertManager.exe
SKF Process P11
CertManager.exe
SKF Process P11 End
CertManager.exe
SKF Process! WTHW