File name:

SecurityScan_Release.exe

Full analysis: https://app.any.run/tasks/4dc64af0-edbe-461e-affc-04ce3e27560a
Verdict: Malicious activity
Analysis date: February 17, 2024, 14:50:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

6D9D0D2089B6B333AE65C2ED73228AE7

SHA1:

2CFF1EBA46F933DE46AFDD7EA66385966087E505

SHA256:

0CC2B7659F7991C61D05164DFF7D38C8510EFBB71DA7F6B9D51CF03EB3DA8779

SSDEEP:

98304:4GenTcJRkaN1OJv9SMQEawnHqrm5M3tl9yF105+i56e2Xy0yW0h97huD85FpSQeT:65/6lpqavNjOpdsL9gNWtXPEp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • SecurityScan_Release.exe (PID: 2844)
      • SecurityScan_Inner.exe (PID: 1824)
    • Antivirus name has been found in the command line (generic signature)

      • McUICnt.exe (PID: 3948)
      • McUICnt.exe (PID: 2376)
      • McUICnt.exe (PID: 1380)
      • McUICnt.exe (PID: 2380)
      • McUICnt.exe (PID: 2136)
    • Create files in the Startup directory

      • SecurityScan_Inner.exe (PID: 1824)
    • Registers / Runs the DLL via REGSVR32.EXE

      • SecurityScan_Release.exe (PID: 2844)
    • Modifies hosts file to block updates

      • SecurityScan_Release.exe (PID: 2844)
  • SUSPICIOUS

    • Malware-specific behavior (creating "System.dll" in Temp)

      • SecurityScan_Release.exe (PID: 2844)
      • SecurityScan_Inner.exe (PID: 1824)
    • The process creates files with name similar to system file names

      • SecurityScan_Release.exe (PID: 2844)
      • SecurityScan_Inner.exe (PID: 1824)
    • Executable content was dropped or overwritten

      • SecurityScan_Release.exe (PID: 2844)
      • SecurityScan_Inner.exe (PID: 1824)
    • The process verifies whether the antivirus software is installed

      • SecurityScan_Release.exe (PID: 2844)
      • McUICnt.exe (PID: 3948)
      • SecurityScan_Inner.exe (PID: 1824)
      • McCHSvc.exe (PID: 1928)
      • regsvr32.exe (PID: 3400)
      • regsvr32.exe (PID: 1572)
      • SSScheduler.exe (PID: 2724)
      • McCHSvc.exe (PID: 2100)
      • McUICnt.exe (PID: 2244)
      • McCHSvc.exe (PID: 316)
      • McUICnt.exe (PID: 2376)
      • McUICnt.exe (PID: 1380)
      • McUICnt.exe (PID: 2380)
      • McUICnt.exe (PID: 1652)
      • McUICnt.exe (PID: 668)
      • McUICnt.exe (PID: 2136)
      • McUICnt.exe (PID: 1192)
    • Reads settings of System Certificates

      • SecurityScan_Release.exe (PID: 2844)
      • McUICnt.exe (PID: 3948)
      • McUICnt.exe (PID: 2244)
      • McUICnt.exe (PID: 2376)
    • Reads security settings of Internet Explorer

      • McUICnt.exe (PID: 3948)
      • SecurityScan_Release.exe (PID: 2844)
      • McUICnt.exe (PID: 2244)
      • McUICnt.exe (PID: 2376)
    • Checks Windows Trust Settings

      • McUICnt.exe (PID: 3948)
      • SecurityScan_Release.exe (PID: 2844)
      • McUICnt.exe (PID: 2244)
      • McCHSvc.exe (PID: 2100)
      • McCHSvc.exe (PID: 316)
      • McUICnt.exe (PID: 2376)
    • Reads Microsoft Outlook installation path

      • McUICnt.exe (PID: 3948)
      • McUICnt.exe (PID: 2244)
    • Reads the Internet Settings

      • McUICnt.exe (PID: 3948)
      • McUICnt.exe (PID: 2244)
    • Reads Internet Explorer settings

      • McUICnt.exe (PID: 3948)
      • McUICnt.exe (PID: 2244)
    • Creates a software uninstall entry

      • SecurityScan_Inner.exe (PID: 1824)
      • SecurityScan_Release.exe (PID: 2844)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 3400)
      • regsvr32.exe (PID: 1572)
    • Searches for installed software

      • McUICnt.exe (PID: 3948)
      • McUICnt.exe (PID: 2244)
    • Executes as Windows Service

      • McCHSvc.exe (PID: 2100)
      • McCHSvc.exe (PID: 316)
    • Adds/modifies Windows certificates

      • McUICnt.exe (PID: 2244)
    • Application launched itself

      • McUICnt.exe (PID: 2380)
      • McUICnt.exe (PID: 1380)
      • McUICnt.exe (PID: 2136)
  • INFO

    • Reads the computer name

      • SecurityScan_Release.exe (PID: 2844)
      • McUICnt.exe (PID: 3948)
      • SecurityScan_Inner.exe (PID: 1824)
      • McCHSvc.exe (PID: 1928)
      • McCHSvc.exe (PID: 2100)
      • McUICnt.exe (PID: 2244)
      • McCHSvc.exe (PID: 316)
      • McUICnt.exe (PID: 2376)
    • Checks supported languages

      • SecurityScan_Release.exe (PID: 2844)
      • McUICnt.exe (PID: 3948)
      • McCHSvc.exe (PID: 1928)
      • McCHSvc.exe (PID: 2100)
      • SSScheduler.exe (PID: 2724)
      • SecurityScan_Inner.exe (PID: 1824)
      • McUICnt.exe (PID: 2244)
      • McUICnt.exe (PID: 2376)
      • McCHSvc.exe (PID: 316)
      • McUICnt.exe (PID: 1380)
      • McUICnt.exe (PID: 1652)
      • McUICnt.exe (PID: 2380)
      • McUICnt.exe (PID: 668)
      • McUICnt.exe (PID: 2136)
      • McUICnt.exe (PID: 1192)
    • Create files in a temporary directory

      • SecurityScan_Release.exe (PID: 2844)
      • SecurityScan_Inner.exe (PID: 1824)
    • Reads the machine GUID from the registry

      • SecurityScan_Release.exe (PID: 2844)
      • McUICnt.exe (PID: 3948)
      • SecurityScan_Inner.exe (PID: 1824)
      • McCHSvc.exe (PID: 2100)
      • McUICnt.exe (PID: 2244)
      • McCHSvc.exe (PID: 316)
      • McUICnt.exe (PID: 2376)
    • Creates files in the program directory

      • SecurityScan_Release.exe (PID: 2844)
      • McUICnt.exe (PID: 3948)
      • SecurityScan_Inner.exe (PID: 1824)
      • SSScheduler.exe (PID: 2724)
      • McCHSvc.exe (PID: 2100)
      • McUICnt.exe (PID: 2244)
    • Process checks computer location settings

      • SecurityScan_Release.exe (PID: 2844)
      • McUICnt.exe (PID: 2244)
    • Reads the software policy settings

      • SecurityScan_Release.exe (PID: 2844)
      • McUICnt.exe (PID: 3948)
      • McCHSvc.exe (PID: 2100)
      • McUICnt.exe (PID: 2244)
      • McCHSvc.exe (PID: 316)
      • McUICnt.exe (PID: 2376)
    • Checks proxy server information

      • McUICnt.exe (PID: 3948)
      • McUICnt.exe (PID: 2244)
    • Creates files or folders in the user directory

      • McUICnt.exe (PID: 2244)
    • Manual execution by a user

      • McUICnt.exe (PID: 2376)
      • McUICnt.exe (PID: 1380)
      • McUICnt.exe (PID: 2380)
      • McUICnt.exe (PID: 2136)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:12:11 21:50:45+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24576
InitializedDataSize: 118784
UninitializedDataSize: 1024
EntryPoint: 0x32bf
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.11.717.1
ProductVersionNumber: 3.11.717.1
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Traditional)
CharacterSet: Windows, Latin1
CompanyName: McAfee, Inc.
FileDescription: McAfee Security Scan Plus Installer
FileVersion: 3.11.717
LegalCopyRight: © McAfee, Inc.
OriginalFileName: SecurityScan_Install.exe
ProductName: McAfee Security Scan Plus
ProductVersion: 3.11
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
66
Monitored processes
18
Malicious processes
8
Suspicious processes
3

Behavior graph

Click at the process to see the details
start securityscan_release.exe mcuicnt.exe no specs securityscan_inner.exe mcchsvc.exe no specs regsvr32.exe no specs regsvr32.exe no specs ssscheduler.exe no specs mcchsvc.exe no specs mcuicnt.exe mcchsvc.exe no specs mcuicnt.exe no specs mcuicnt.exe mcuicnt.exe no specs mcuicnt.exe mcuicnt.exe no specs mcuicnt.exe no specs mcuicnt.exe no specs securityscan_release.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
316"C:\Program Files\McAfee Security Scan\3.11.717\McCHSvc.exe"C:\Program Files\McAfee Security Scan\3.11.717\McCHSvc.exeservices.exe
User:
SYSTEM
Company:
McAfee, Inc.
Integrity Level:
SYSTEM
Description:
Component Host Service
Exit code:
0
Version:
3,11,717,0
Modules
Images
c:\program files\mcafee security scan\3.11.717\mcchsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
668 /desktopicon /platuiC:\Program Files\McAfee Security Scan\3.11.717\McUICnt.exeMcUICnt.exe
User:
admin
Company:
McAfee, Inc.
Integrity Level:
HIGH
Description:
McAfee
Exit code:
0
Version:
8,3,3037,0
Modules
Images
c:\program files\mcafee security scan\3.11.717\mcuicnt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1192 /desktopicon /platuiC:\Program Files\McAfee Security Scan\3.11.717\McUICnt.exeMcUICnt.exe
User:
admin
Company:
McAfee, Inc.
Integrity Level:
MEDIUM
Description:
McAfee
Exit code:
0
Version:
8,3,3037,0
Modules
Images
c:\program files\mcafee security scan\3.11.717\mcuicnt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1380"C:\Program Files\McAfee Security Scan\3.11.717\McUICnt.exe" C:\Program Files\McAfee Security Scan\3.11.717\McUICnt.exe
explorer.exe
User:
admin
Company:
McAfee, Inc.
Integrity Level:
HIGH
Description:
McAfee
Exit code:
1
Version:
8,3,3037,0
Modules
Images
c:\program files\mcafee security scan\3.11.717\mcuicnt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1572"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\McAfee Security Scan\3.11.717\McCorePS.dll"C:\Windows\System32\regsvr32.exeSecurityScan_Release.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1652 /desktopicon /platuiC:\Program Files\McAfee Security Scan\3.11.717\McUICnt.exeMcUICnt.exe
User:
admin
Company:
McAfee, Inc.
Integrity Level:
HIGH
Description:
McAfee
Exit code:
0
Version:
8,3,3037,0
Modules
Images
c:\program files\mcafee security scan\3.11.717\mcuicnt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1824"C:\Users\admin\AppData\Local\Temp\nsaF510.tmp\\SecurityScan_Inner.exe" /innerC:\Users\admin\AppData\Local\Temp\nsaF510.tmp\SecurityScan_Inner.exe
McUICnt.exe
User:
admin
Company:
McAfee, Inc.
Integrity Level:
HIGH
Description:
McAfee Security Scan Plus Installer
Exit code:
0
Version:
3.11.717
Modules
Images
c:\users\admin\appdata\local\temp\nsaf510.tmp\securityscan_inner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1928"C:\Program Files\McAfee Security Scan\3.11.717\McCHSvc.exe" /ServiceC:\Program Files\McAfee Security Scan\3.11.717\McCHSvc.exeSecurityScan_Inner.exe
User:
admin
Company:
McAfee, Inc.
Integrity Level:
HIGH
Description:
Component Host Service
Exit code:
0
Version:
3,11,717,0
Modules
Images
c:\program files\mcafee security scan\3.11.717\mcchsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2100"C:\Program Files\McAfee Security Scan\3.11.717\McCHSvc.exe"C:\Program Files\McAfee Security Scan\3.11.717\McCHSvc.exeservices.exe
User:
SYSTEM
Company:
McAfee, Inc.
Integrity Level:
SYSTEM
Description:
Component Host Service
Exit code:
0
Version:
3,11,717,0
Modules
Images
c:\program files\mcafee security scan\3.11.717\mcchsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2136"C:\Program Files\McAfee Security Scan\3.11.717\McUICnt.exe" C:\Program Files\McAfee Security Scan\3.11.717\McUICnt.exeexplorer.exe
User:
admin
Company:
McAfee, Inc.
Integrity Level:
MEDIUM
Description:
McAfee
Exit code:
1
Version:
8,3,3037,0
Modules
Images
c:\program files\mcafee security scan\3.11.717\mcuicnt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
33 093
Read events
32 867
Write events
194
Delete events
32

Modification events

(PID) Process:(2844) SecurityScan_Release.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2844) SecurityScan_Release.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates
Operation:delete valueName:9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Value:
(PID) Process:(2844) SecurityScan_Release.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
0F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D80300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB6200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(2844) SecurityScan_Release.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
1400000001000000140000005D6CA352CEFC713CBBC5E21F663C3639FD19D4D70300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB60F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D8200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(2844) SecurityScan_Release.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
190000000100000010000000BCC80DAA2F98A4692805BFF4CBB372EB0F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D80300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB61400000001000000140000005D6CA352CEFC713CBBC5E21F663C3639FD19D4D7200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(3948) McUICnt.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
Operation:delete valueName:mcuicnt.exe
Value:
(PID) Process:(3948) McUICnt.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3948) McUICnt.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:SecureProtocols
Value:
2688
(PID) Process:(3948) McUICnt.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3948) McUICnt.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
50
Suspicious files
14
Text files
56
Unknown types
3

Dropped files

PID
Process
Filename
Type
2844SecurityScan_Release.exeC:\Users\admin\AppData\Local\Temp\nsaF510.tmp\ftconfig.iniini
MD5:847FF89DB3DB27FB527E6FDE794F81C6
SHA256:428D1891F2D75A22DD6F19E9A7860148BAA65C7C5AFACED9D67BCBDE24420AB8
2844SecurityScan_Release.exeC:\ProgramData\McAfee Security Scan\ftstate.initext
MD5:D70FF1BE42206B8B72A50BF344BB52BA
SHA256:AA08FD4A30F96D0851C26C4A5381C3AFCA79F16E059DF6CAEABF0F51E96A1682
2844SecurityScan_Release.exeC:\Users\admin\AppData\Local\Temp\nsaF510.tmp\McUICnt.exeexecutable
MD5:DBB13335E51B200450B7C79C0430AADA
SHA256:EFE5B9F8CDFA378DBA55143C5E7EEE6922E9590855D2425DA819EF8DB2F7D681
2844SecurityScan_Release.exeC:\Users\admin\AppData\Local\Temp\nsaF510.tmp\mcbrwsr2.dllexecutable
MD5:DB731D2562864A60F331983B3BBD19AD
SHA256:8C659A9D6F0AA06BC34B07625921A4E8B980FAB06B126ED446978C51EADD9774
2844SecurityScan_Release.exeC:\Users\admin\AppData\Local\Temp\nsaF510.tmp\McInstallerRes.dllexecutable
MD5:D4C834406284ADCF07716049EF7627FA
SHA256:71A2E83B19F664C63BCF13348957DE507A36A989F1370F239D2FCF635867365E
2844SecurityScan_Release.exeC:\Users\admin\AppData\Local\Temp\nsaF510.tmp\SecurityScan_Inner.exeexecutable
MD5:7850F7FCA6E6B78ACD1540C34E6E200D
SHA256:9C6F484FAC147AFC30589199351682F0201165EEEA67A2B12359FAF323BB316B
2844SecurityScan_Release.exeC:\Users\admin\AppData\Local\Temp\nsaF510.tmp\McUtil.dllexecutable
MD5:928A59074986EA6EA145EBBA3FA399E1
SHA256:5B13C0DDEB8B6CF125D06007F865C5A8272FAD42B1726A13D408A9DA2A1E8374
2844SecurityScan_Release.exeC:\Users\admin\AppData\Local\Temp\nsaF510.tmp\McInstallerRes_LD.dllexecutable
MD5:B042955942C7C3B6F9A903C76E1F8FF4
SHA256:EC1204DF377192E0ACCB9D2D9B9793DD78A3247F9E4469DB22D29089913F8428
2844SecurityScan_Release.exeC:\ProgramData\McAfee\MCLOGS\PartnerCustom\SecurityScan_Release\SecurityScan_Release000.logtext
MD5:1893828ECE8FED6B716061BFAC1D6428
SHA256:B306A5993A593ADE4B03D3C587589C3498BF3853F1F4076DE1A25C918AED49F6
2844SecurityScan_Release.exeC:\Users\admin\AppData\Local\Temp\nsaF510.tmp\InstallHelp\SecurityScanner32.dllexecutable
MD5:DF56172ABC961D42E9F5D63324F108D6
SHA256:4E4507C249EA21846E9ECF6761167661C7F8D23638FA462BD71CF1CED0A6E6B2
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
12
DNS requests
7
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2244
McUICnt.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
binary
1.42 Kb
unknown
2244
McUICnt.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT54gz5vn%2FXXBb71hRKynhUblJuBgQU0E4ixT1hcgq7J7SSNre6lZ8nMZwCEBgPs0uTL0pLzBTjLvkuOpE%3D
unknown
binary
471 b
unknown
1080
svchost.exe
GET
200
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?1b8fee253118cbef
unknown
compressed
65.2 Kb
unknown
2244
McUICnt.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEQCu%2F8JZxQ3BalXFvP7Nih9m
unknown
binary
2.18 Kb
unknown
2244
McUICnt.exe
GET
304
184.24.77.194:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?1b93dac8b92558bc
unknown
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2844
SecurityScan_Release.exe
142.250.185.206:443
www.google-analytics.com
GOOGLE
US
whitelisted
2244
McUICnt.exe
44.241.52.92:80
updatekeepalive.mcafee.com
AMAZON-02
US
unknown
2244
McUICnt.exe
100.21.175.239:443
liteapps.mcafee.com
AMAZON-02
US
unknown
2244
McUICnt.exe
184.24.77.194:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2244
McUICnt.exe
104.18.38.233:80
ocsp.comodoca.com
CLOUDFLARENET
shared
2244
McUICnt.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
unknown
1080
svchost.exe
184.24.77.202:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
www.google-analytics.com
  • 142.250.185.206
whitelisted
updatekeepalive.mcafee.com
  • 44.241.52.92
  • 44.241.114.176
  • 44.241.78.1
unknown
liteapps.mcafee.com
  • 100.21.175.239
  • 52.89.74.94
  • 52.39.121.146
unknown
ctldl.windowsupdate.com
  • 184.24.77.194
  • 184.24.77.202
whitelisted
ocsp.comodoca.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
ocsp.usertrust.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted

Threats

No threats detected
No debug info