File name:

SecurityScan_Release.exe

Full analysis: https://app.any.run/tasks/4dc64af0-edbe-461e-affc-04ce3e27560a
Verdict: Malicious activity
Analysis date: February 17, 2024, 14:50:08
OS: Windows 7 Professional Service Pack 1 (build: 7601, 32 bit)
Indicators:
MIME: application/x-dosexec
File info: PE32 executable (GUI) Intel 80386, for MS Windows, Nullsoft Installer self-extracting archive
MD5:

6D9D0D2089B6B333AE65C2ED73228AE7

SHA1:

2CFF1EBA46F933DE46AFDD7EA66385966087E505

SHA256:

0CC2B7659F7991C61D05164DFF7D38C8510EFBB71DA7F6B9D51CF03EB3DA8779

SSDEEP:

98304:4GenTcJRkaN1OJv9SMQEawnHqrm5M3tl9yF105+i56e2Xy0yW0h97huD85FpSQeT:65/6lpqavNjOpdsL9gNWtXPEp

ANY.RUN is an interactive service which provides full access to the guest system. Information in this report could be distorted by user actions and is provided for user acknowledgement as it is. ANY.RUN does not guarantee maliciousness or safety of the content.
  • MALICIOUS

    • Drops the executable file immediately after the start

      • SecurityScan_Release.exe (PID: 2844)
      • SecurityScan_Inner.exe (PID: 1824)
    • Registers / Runs the DLL via REGSVR32.EXE

      • SecurityScan_Release.exe (PID: 2844)
    • Create files in the Startup directory

      • SecurityScan_Inner.exe (PID: 1824)
    • Modifies hosts file to block updates

      • SecurityScan_Release.exe (PID: 2844)
    • Antivirus name has been found in the command line (generic signature)

      • McUICnt.exe (PID: 2376)
      • McUICnt.exe (PID: 1380)
      • McUICnt.exe (PID: 3948)
      • McUICnt.exe (PID: 2380)
      • McUICnt.exe (PID: 2136)
  • SUSPICIOUS

    • Reads security settings of Internet Explorer

      • McUICnt.exe (PID: 3948)
      • SecurityScan_Release.exe (PID: 2844)
      • McUICnt.exe (PID: 2244)
      • McUICnt.exe (PID: 2376)
    • Malware-specific behavior (creating "System.dll" in Temp)

      • SecurityScan_Release.exe (PID: 2844)
      • SecurityScan_Inner.exe (PID: 1824)
    • Reads settings of System Certificates

      • SecurityScan_Release.exe (PID: 2844)
      • McUICnt.exe (PID: 2244)
      • McUICnt.exe (PID: 2376)
      • McUICnt.exe (PID: 3948)
    • The process creates files with name similar to system file names

      • SecurityScan_Release.exe (PID: 2844)
      • SecurityScan_Inner.exe (PID: 1824)
    • Executable content was dropped or overwritten

      • SecurityScan_Release.exe (PID: 2844)
      • SecurityScan_Inner.exe (PID: 1824)
    • The process verifies whether the antivirus software is installed

      • SecurityScan_Release.exe (PID: 2844)
      • McUICnt.exe (PID: 3948)
      • SecurityScan_Inner.exe (PID: 1824)
      • regsvr32.exe (PID: 3400)
      • regsvr32.exe (PID: 1572)
      • McCHSvc.exe (PID: 1928)
      • SSScheduler.exe (PID: 2724)
      • McCHSvc.exe (PID: 2100)
      • McUICnt.exe (PID: 2244)
      • McCHSvc.exe (PID: 316)
      • McUICnt.exe (PID: 2376)
      • McUICnt.exe (PID: 1380)
      • McUICnt.exe (PID: 2380)
      • McUICnt.exe (PID: 1652)
      • McUICnt.exe (PID: 1192)
      • McUICnt.exe (PID: 668)
      • McUICnt.exe (PID: 2136)
    • Checks Windows Trust Settings

      • McUICnt.exe (PID: 3948)
      • SecurityScan_Release.exe (PID: 2844)
      • McCHSvc.exe (PID: 2100)
      • McUICnt.exe (PID: 2244)
      • McCHSvc.exe (PID: 316)
      • McUICnt.exe (PID: 2376)
    • Reads the Internet Settings

      • McUICnt.exe (PID: 3948)
      • McUICnt.exe (PID: 2244)
    • Reads Internet Explorer settings

      • McUICnt.exe (PID: 3948)
      • McUICnt.exe (PID: 2244)
    • Reads Microsoft Outlook installation path

      • McUICnt.exe (PID: 3948)
      • McUICnt.exe (PID: 2244)
    • Searches for installed software

      • McUICnt.exe (PID: 3948)
      • McUICnt.exe (PID: 2244)
    • Creates a software uninstall entry

      • SecurityScan_Inner.exe (PID: 1824)
      • SecurityScan_Release.exe (PID: 2844)
    • Creates/Modifies COM task schedule object

      • regsvr32.exe (PID: 1572)
      • regsvr32.exe (PID: 3400)
    • Executes as Windows Service

      • McCHSvc.exe (PID: 2100)
      • McCHSvc.exe (PID: 316)
    • Adds/modifies Windows certificates

      • McUICnt.exe (PID: 2244)
    • Application launched itself

      • McUICnt.exe (PID: 2380)
      • McUICnt.exe (PID: 1380)
      • McUICnt.exe (PID: 2136)
  • INFO

    • Reads the computer name

      • SecurityScan_Release.exe (PID: 2844)
      • McUICnt.exe (PID: 3948)
      • SecurityScan_Inner.exe (PID: 1824)
      • McCHSvc.exe (PID: 1928)
      • McCHSvc.exe (PID: 2100)
      • McUICnt.exe (PID: 2244)
      • McCHSvc.exe (PID: 316)
      • McUICnt.exe (PID: 2376)
    • Checks supported languages

      • SecurityScan_Release.exe (PID: 2844)
      • SecurityScan_Inner.exe (PID: 1824)
      • McCHSvc.exe (PID: 1928)
      • McCHSvc.exe (PID: 2100)
      • SSScheduler.exe (PID: 2724)
      • McUICnt.exe (PID: 2244)
      • McCHSvc.exe (PID: 316)
      • McUICnt.exe (PID: 2376)
      • McUICnt.exe (PID: 1380)
      • McUICnt.exe (PID: 3948)
      • McUICnt.exe (PID: 2380)
      • McUICnt.exe (PID: 1652)
      • McUICnt.exe (PID: 1192)
      • McUICnt.exe (PID: 668)
      • McUICnt.exe (PID: 2136)
    • Process checks computer location settings

      • SecurityScan_Release.exe (PID: 2844)
      • McUICnt.exe (PID: 2244)
    • Reads the machine GUID from the registry

      • SecurityScan_Release.exe (PID: 2844)
      • SecurityScan_Inner.exe (PID: 1824)
      • McCHSvc.exe (PID: 2100)
      • McUICnt.exe (PID: 2244)
      • McUICnt.exe (PID: 2376)
      • McCHSvc.exe (PID: 316)
      • McUICnt.exe (PID: 3948)
    • Create files in a temporary directory

      • SecurityScan_Release.exe (PID: 2844)
      • SecurityScan_Inner.exe (PID: 1824)
    • Reads the software policy settings

      • SecurityScan_Release.exe (PID: 2844)
      • McUICnt.exe (PID: 3948)
      • McCHSvc.exe (PID: 2100)
      • McUICnt.exe (PID: 2244)
      • McCHSvc.exe (PID: 316)
      • McUICnt.exe (PID: 2376)
    • Creates files in the program directory

      • SecurityScan_Release.exe (PID: 2844)
      • McUICnt.exe (PID: 3948)
      • SecurityScan_Inner.exe (PID: 1824)
      • McCHSvc.exe (PID: 2100)
      • SSScheduler.exe (PID: 2724)
      • McUICnt.exe (PID: 2244)
    • Checks proxy server information

      • McUICnt.exe (PID: 3948)
      • McUICnt.exe (PID: 2244)
    • Creates files or folders in the user directory

      • McUICnt.exe (PID: 2244)
    • Manual execution by a user

      • McUICnt.exe (PID: 2376)
      • McUICnt.exe (PID: 1380)
      • McUICnt.exe (PID: 2380)
      • McUICnt.exe (PID: 2136)
Find more information about signature artifacts and mapping to MITRE ATT&CK™ MATRIX at the full report
No Malware configuration.

TRiD

.exe | Win32 Executable MS Visual C++ (generic) (67.4)
.dll | Win32 Dynamic Link Library (generic) (14.2)
.exe | Win32 Executable (generic) (9.7)
.exe | Generic Win/DOS Executable (4.3)
.exe | DOS Executable Generic (4.3)

EXIF

EXE

MachineType: Intel 386 or later, and compatibles
TimeStamp: 2016:12:11 21:50:45+00:00
ImageFileCharacteristics: No relocs, Executable, No line numbers, No symbols, 32-bit
PEType: PE32
LinkerVersion: 6
CodeSize: 24576
InitializedDataSize: 118784
UninitializedDataSize: 1024
EntryPoint: 0x32bf
OSVersion: 4
ImageVersion: 6
SubsystemVersion: 4
Subsystem: Windows GUI
FileVersionNumber: 3.11.717.1
ProductVersionNumber: 3.11.717.1
FileFlagsMask: 0x0000
FileFlags: (none)
FileOS: Win32
ObjectFileType: Executable application
FileSubtype: -
LanguageCode: Chinese (Traditional)
CharacterSet: Windows, Latin1
CompanyName: McAfee, Inc.
FileDescription: McAfee Security Scan Plus Installer
FileVersion: 3.11.717
LegalCopyRight: © McAfee, Inc.
OriginalFileName: SecurityScan_Install.exe
ProductName: McAfee Security Scan Plus
ProductVersion: 3.11
No data.
screenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshotscreenshot
All screenshots are available in the full report
All screenshots are available in the full report
Total processes
66
Monitored processes
18
Malicious processes
8
Suspicious processes
3

Behavior graph

Click at the process to see the details
start securityscan_release.exe mcuicnt.exe no specs securityscan_inner.exe mcchsvc.exe no specs regsvr32.exe no specs regsvr32.exe no specs ssscheduler.exe no specs mcchsvc.exe no specs mcuicnt.exe mcchsvc.exe no specs mcuicnt.exe no specs mcuicnt.exe mcuicnt.exe no specs mcuicnt.exe mcuicnt.exe no specs mcuicnt.exe no specs mcuicnt.exe no specs securityscan_release.exe no specs

Process information

PID
CMD
Path
Indicators
Parent process
316"C:\Program Files\McAfee Security Scan\3.11.717\McCHSvc.exe"C:\Program Files\McAfee Security Scan\3.11.717\McCHSvc.exeservices.exe
User:
SYSTEM
Company:
McAfee, Inc.
Integrity Level:
SYSTEM
Description:
Component Host Service
Exit code:
0
Version:
3,11,717,0
Modules
Images
c:\program files\mcafee security scan\3.11.717\mcchsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
668 /desktopicon /platuiC:\Program Files\McAfee Security Scan\3.11.717\McUICnt.exeMcUICnt.exe
User:
admin
Company:
McAfee, Inc.
Integrity Level:
HIGH
Description:
McAfee
Exit code:
0
Version:
8,3,3037,0
Modules
Images
c:\program files\mcafee security scan\3.11.717\mcuicnt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1192 /desktopicon /platuiC:\Program Files\McAfee Security Scan\3.11.717\McUICnt.exeMcUICnt.exe
User:
admin
Company:
McAfee, Inc.
Integrity Level:
MEDIUM
Description:
McAfee
Exit code:
0
Version:
8,3,3037,0
Modules
Images
c:\program files\mcafee security scan\3.11.717\mcuicnt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1380"C:\Program Files\McAfee Security Scan\3.11.717\McUICnt.exe" C:\Program Files\McAfee Security Scan\3.11.717\McUICnt.exe
explorer.exe
User:
admin
Company:
McAfee, Inc.
Integrity Level:
HIGH
Description:
McAfee
Exit code:
1
Version:
8,3,3037,0
Modules
Images
c:\program files\mcafee security scan\3.11.717\mcuicnt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1572"C:\Windows\system32\regsvr32.exe" /s "C:\Program Files\McAfee Security Scan\3.11.717\McCorePS.dll"C:\Windows\System32\regsvr32.exeSecurityScan_Release.exe
User:
admin
Company:
Microsoft Corporation
Integrity Level:
HIGH
Description:
Microsoft(C) Register Server
Exit code:
0
Version:
6.1.7600.16385 (win7_rtm.090713-1255)
Modules
Images
c:\windows\system32\regsvr32.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\advapi32.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\sechost.dll
c:\windows\system32\rpcrt4.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
1652 /desktopicon /platuiC:\Program Files\McAfee Security Scan\3.11.717\McUICnt.exeMcUICnt.exe
User:
admin
Company:
McAfee, Inc.
Integrity Level:
HIGH
Description:
McAfee
Exit code:
0
Version:
8,3,3037,0
Modules
Images
c:\program files\mcafee security scan\3.11.717\mcuicnt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
1824"C:\Users\admin\AppData\Local\Temp\nsaF510.tmp\\SecurityScan_Inner.exe" /innerC:\Users\admin\AppData\Local\Temp\nsaF510.tmp\SecurityScan_Inner.exe
McUICnt.exe
User:
admin
Company:
McAfee, Inc.
Integrity Level:
HIGH
Description:
McAfee Security Scan Plus Installer
Exit code:
0
Version:
3.11.717
Modules
Images
c:\users\admin\appdata\local\temp\nsaf510.tmp\securityscan_inner.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\shell32.dll
1928"C:\Program Files\McAfee Security Scan\3.11.717\McCHSvc.exe" /ServiceC:\Program Files\McAfee Security Scan\3.11.717\McCHSvc.exeSecurityScan_Inner.exe
User:
admin
Company:
McAfee, Inc.
Integrity Level:
HIGH
Description:
Component Host Service
Exit code:
0
Version:
3,11,717,0
Modules
Images
c:\program files\mcafee security scan\3.11.717\mcchsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2100"C:\Program Files\McAfee Security Scan\3.11.717\McCHSvc.exe"C:\Program Files\McAfee Security Scan\3.11.717\McCHSvc.exeservices.exe
User:
SYSTEM
Company:
McAfee, Inc.
Integrity Level:
SYSTEM
Description:
Component Host Service
Exit code:
0
Version:
3,11,717,0
Modules
Images
c:\program files\mcafee security scan\3.11.717\mcchsvc.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\user32.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
c:\windows\system32\msvcrt.dll
c:\windows\system32\advapi32.dll
2136"C:\Program Files\McAfee Security Scan\3.11.717\McUICnt.exe" C:\Program Files\McAfee Security Scan\3.11.717\McUICnt.exeexplorer.exe
User:
admin
Company:
McAfee, Inc.
Integrity Level:
MEDIUM
Description:
McAfee
Exit code:
1
Version:
8,3,3037,0
Modules
Images
c:\program files\mcafee security scan\3.11.717\mcuicnt.exe
c:\windows\system32\ntdll.dll
c:\windows\system32\kernel32.dll
c:\windows\system32\kernelbase.dll
c:\windows\system32\api-ms-win-core-synch-l1-2-0.dll
c:\windows\system32\shlwapi.dll
c:\windows\system32\gdi32.dll
c:\windows\system32\user32.dll
c:\windows\system32\lpk.dll
c:\windows\system32\usp10.dll
Total events
33 093
Read events
32 867
Write events
194
Delete events
32

Modification events

(PID) Process:(2844) SecurityScan_Release.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(2844) SecurityScan_Release.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates
Operation:delete valueName:9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Value:
(PID) Process:(2844) SecurityScan_Release.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
0F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D80300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB6200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(2844) SecurityScan_Release.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
1400000001000000140000005D6CA352CEFC713CBBC5E21F663C3639FD19D4D70300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB60F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D8200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(2844) SecurityScan_Release.exeKey:HKEY_LOCAL_MACHINE\SOFTWARE\Microsoft\EnterpriseCertificates\Root\Certificates\9F6134C5FA75E4FDDE631B232BE961D6D4B97DB6
Operation:writeName:Blob
Value:
190000000100000010000000BCC80DAA2F98A4692805BFF4CBB372EB0F00000001000000200000009065F32AFC2CFEA7F452D2D6BE94D20C877EFC1C05433D9935696193FDCC05D80300000001000000140000009F6134C5FA75E4FDDE631B232BE961D6D4B97DB61400000001000000140000005D6CA352CEFC713CBBC5E21F663C3639FD19D4D7200000000100000047030000308203433082022BA00302010202147327B7C17D5AE708EF73F1F45A79D78B4E99A29F300D06092A864886F70D01010B05003031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C084469676943657274301E170D3233303932393130353030335A170D3339303530383130353030335A3031310B3009060355040613025553310F300D06035504080C06426F73746F6E3111300F060355040A0C08446967694365727430820122300D06092A864886F70D01010105000382010F003082010A0282010100D91B7A55548F44F3E97C493153B75B055695736B184640D7335A2E6218083B5A1BEE2695209350E57A3EB76FBC604CB3B250DF3D9D0C560D1FBDFE30108D233A3C555100BE1A3F8E543C0B253E06E91B6D5F9CB3A093009BC8B4D3A0EB19DB59E56DA7E3D637847970D6C2AEB4A1FCF3896A7C080FE68759BAA62E6AAA8B7C7CBDA176DDC72F8D259A16D3469E31F19D2959904611D730D7D26FCFED789A0C49698FDFABF3F6727D08C61A073BB11E85C96486D49B0E0D38364C008A5EB964F8813C5DF004F9E76D2F8DB90702D800032674959BF0DF823785419101CEA928A10ACBAE7E48FE19202F3CB7BCF416476D17CB64C5570FCED443BD75D9F2C632FF0203010001A3533051301D0603551D0E041604145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7301F0603551D230418301680145D6CA352CEFC713CBBC5E21F663C3639FD19D4D7300F0603551D130101FF040530030101FF300D06092A864886F70D01010B05000382010100AF2218E4CA18144728FCC76EA14958061522FD4A018BED1A4BFCC5CCE70BC6AE9DF7D3795C9A010D53628E2B6E7C10D6B07E53546235A5EE480E5A434E312154BF1E39AAC27D2C18D4F41CBBECFE4538CEF93EF62C17D187A7F720F4A9478410D09620C9F8B293B5786A5440BC0743B7B7753CF66FBA498B7E083BC267597238DC031B9BB131F997D9B8164AAED0D6E328420E53E1969DA6CD035078179677A7177BB2BF9C87CF592910CD380E8501B92040A39469C782BA383BEAE498C060FCC7C429BC10B7B6B7A0659C9BE03DC13DB46C638CF5E3B22A303726906DC8DD91C64501EBFC282A3A497EC430CACC066EE4BF9C5C8F2F2A05D0C1921A9E3E85E3
(PID) Process:(3948) McUICnt.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Internet Explorer\Main\FeatureControl\FEATURE_BROWSER_EMULATION
Operation:delete valueName:mcuicnt.exe
Value:
(PID) Process:(3948) McUICnt.exeKey:HKEY_CLASSES_ROOT\Local Settings\MuiCache\182\52C64B7E
Operation:writeName:LanguageList
Value:
en-US
(PID) Process:(3948) McUICnt.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings
Operation:writeName:SecureProtocols
Value:
2688
(PID) Process:(3948) McUICnt.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:ProxyBypass
Value:
1
(PID) Process:(3948) McUICnt.exeKey:HKEY_CURRENT_USER\Software\Microsoft\Windows\CurrentVersion\Internet Settings\ZoneMap
Operation:writeName:IntranetName
Value:
1
Executable files
50
Suspicious files
14
Text files
56
Unknown types
3

Dropped files

PID
Process
Filename
Type
2844SecurityScan_Release.exeC:\Users\admin\AppData\Local\Temp\nsaF510.tmp\ftconfig.iniini
MD5:847FF89DB3DB27FB527E6FDE794F81C6
SHA256:428D1891F2D75A22DD6F19E9A7860148BAA65C7C5AFACED9D67BCBDE24420AB8
2844SecurityScan_Release.exeC:\Users\admin\AppData\Local\Temp\nsaF510.tmp\McInstallerStartup.dllexecutable
MD5:282DFB0032A611BAD9C9A52A5AD4BE0E
SHA256:E9CC9804B561BA064C6F3648EFDE46A7E852483A3937581466ACBD9F2FECB304
2844SecurityScan_Release.exeC:\Users\admin\AppData\Local\Temp\nsaF510.tmp\UnInstaller.initext
MD5:A36302870C06E18944D80BBDE27A61C2
SHA256:0E7F8C2D60C8CEBE8E3DCBAB81AD11D23DA3F751ACBD252015FDA3F6DEC417A1
2844SecurityScan_Release.exeC:\Users\admin\AppData\Local\Temp\nsaF510.tmp\x64\McUICnt.exeexecutable
MD5:AF02E9C6329F92478665F8DC2AAA187C
SHA256:EAFE4E6C852F73B2A46D4E993334E2E1FC8841AB9C5F81F0BD42712D84FAD652
2844SecurityScan_Release.exeC:\Users\admin\AppData\Local\Temp\nsaF510.tmp\McCorePS.dllexecutable
MD5:5CCE72309C64B68844D9C81F7525FD3C
SHA256:B0F57E2130F68462573665C493B84E159301992EE7B2935292565554CD99A04E
2844SecurityScan_Release.exeC:\Users\admin\AppData\Local\Temp\nsaF510.tmp\QsLite.dllexecutable
MD5:7751EEE00A12BDE2FB4EF5C4F2E07CA0
SHA256:FF73F761806F47860A07CF4AC7C29C7EA570641ED6C7B5C8345B6B8F64ECB29A
2844SecurityScan_Release.exeC:\Users\admin\AppData\Local\Temp\nsaF510.tmp\McUICnt.exeexecutable
MD5:DBB13335E51B200450B7C79C0430AADA
SHA256:EFE5B9F8CDFA378DBA55143C5E7EEE6922E9590855D2425DA819EF8DB2F7D681
2844SecurityScan_Release.exeC:\Users\admin\AppData\Local\Temp\nsaF510.tmp\mcbrwsr2.dllexecutable
MD5:DB731D2562864A60F331983B3BBD19AD
SHA256:8C659A9D6F0AA06BC34B07625921A4E8B980FAB06B126ED446978C51EADD9774
2844SecurityScan_Release.exeC:\Users\admin\AppData\Local\Temp\nsaF510.tmp\McInstallerRes_LD.dllexecutable
MD5:B042955942C7C3B6F9A903C76E1F8FF4
SHA256:EC1204DF377192E0ACCB9D2D9B9793DD78A3247F9E4469DB22D29089913F8428
2844SecurityScan_Release.exeC:\Users\admin\AppData\Local\Temp\nsaF510.tmp\McInstallerRes.dllexecutable
MD5:D4C834406284ADCF07716049EF7627FA
SHA256:71A2E83B19F664C63BCF13348957DE507A36A989F1370F239D2FCF635867365E
Download PCAP, analyze network streams, HTTP content and a lot more at the full report
HTTP(S) requests
5
TCP/UDP connections
12
DNS requests
7
Threats
0

HTTP requests

PID
Process
Method
HTTP Code
IP
URL
CN
Type
Size
Reputation
2244
McUICnt.exe
GET
304
184.24.77.194:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/disallowedcertstl.cab?1b93dac8b92558bc
unknown
unknown
2244
McUICnt.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFIwUDBOMEwwSjAJBgUrDgMCGgUABBTNMNJMNDqCqx8FcBWK16EHdimS6QQUU3m%2FWqorSs9UgOHYm8Cd8rIDZssCEQCu%2F8JZxQ3BalXFvP7Nih9m
unknown
binary
2.18 Kb
unknown
2244
McUICnt.exe
GET
200
104.18.38.233:80
http://ocsp.comodoca.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBRTtU9uFqgVGHhJwXZyWCNXmVR5ngQUoBEKIz6W8Qfs4q8p74Klf9AwpLQCEDlyRDr5IrdR19NsEN0xNZU%3D
unknown
binary
1.42 Kb
unknown
2244
McUICnt.exe
GET
200
172.64.149.23:80
http://ocsp.usertrust.com/MFEwTzBNMEswSTAJBgUrDgMCGgUABBT54gz5vn%2FXXBb71hRKynhUblJuBgQU0E4ixT1hcgq7J7SSNre6lZ8nMZwCEBgPs0uTL0pLzBTjLvkuOpE%3D
unknown
binary
471 b
unknown
1080
svchost.exe
GET
200
184.24.77.202:80
http://ctldl.windowsupdate.com/msdownload/update/v3/static/trustedr/en/authrootstl.cab?1b8fee253118cbef
unknown
compressed
65.2 Kb
unknown
Download PCAP, analyze network streams, HTTP content and a lot more at the full report

Connections

PID
Process
IP
Domain
ASN
CN
Reputation
4
System
192.168.100.255:137
whitelisted
4
System
192.168.100.255:138
whitelisted
1080
svchost.exe
224.0.0.252:5355
unknown
2844
SecurityScan_Release.exe
142.250.185.206:443
www.google-analytics.com
GOOGLE
US
whitelisted
2244
McUICnt.exe
44.241.52.92:80
updatekeepalive.mcafee.com
AMAZON-02
US
unknown
2244
McUICnt.exe
100.21.175.239:443
liteapps.mcafee.com
AMAZON-02
US
unknown
2244
McUICnt.exe
184.24.77.194:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown
2244
McUICnt.exe
104.18.38.233:80
ocsp.comodoca.com
CLOUDFLARENET
shared
2244
McUICnt.exe
172.64.149.23:80
ocsp.comodoca.com
CLOUDFLARENET
US
unknown
1080
svchost.exe
184.24.77.202:80
ctldl.windowsupdate.com
Akamai International B.V.
DE
unknown

DNS requests

Domain
IP
Reputation
www.google-analytics.com
  • 142.250.185.206
whitelisted
updatekeepalive.mcafee.com
  • 44.241.52.92
  • 44.241.114.176
  • 44.241.78.1
unknown
liteapps.mcafee.com
  • 100.21.175.239
  • 52.89.74.94
  • 52.39.121.146
unknown
ctldl.windowsupdate.com
  • 184.24.77.194
  • 184.24.77.202
whitelisted
ocsp.comodoca.com
  • 104.18.38.233
  • 172.64.149.23
whitelisted
ocsp.usertrust.com
  • 172.64.149.23
  • 104.18.38.233
whitelisted

Threats

No threats detected
No debug info